In June 2024, as the European Union prepared for the entry into force of the Artificial Intelligence Act, the European Commission launched a targeted consultation on the use of AI in the financial sector.
The consultation was designed to gather practical input from financial institutions, consumer organisations and other market participants on how AI was being developed and deployed across financial services.
Its purpose went beyond identifying promising technologies.
The Commission wanted to understand how AI was already being used, where benefits and barriers were emerging, what risks required closer attention and how the new AI Act would interact with the existing body of EU financial-services regulation.
The consultation closed in September 2024.
But the questions it raised have become more, rather than less, relevant as financial institutions move from preparing for the AI Act to implementing it in practice.
Why the Commission consulted the financial sector
Financial services were already among the sectors experiencing rapid adoption of artificial intelligence when the consultation opened.
AI was being explored or deployed across activities including:
- credit assessment;
- risk analysis;
- fraud detection;
- anti-money laundering;
- customer service;
- robo-advice;
- regulatory compliance;
- personal financial management;
- insurance;
- sustainable-finance applications; and
- other data-intensive financial processes.
The Commission therefore sought input from organisations that were already providing, developing or using AI systems in financial services, as well as consumer organisations and other stakeholders affected by those systems.
The objective was to obtain a practical view of how AI operates within the financial sector rather than relying solely on abstract assumptions about the technology.
The consultation was about implementation, not only policy
The Commission expressly linked the consultation to implementation of the AI Act within the financial sector.
That distinction matters.
Financial institutions do not operate under the AI Act in isolation.
Banks, insurers, investment firms and other regulated entities already operate within extensive sector-specific frameworks governing matters such as:
- governance;
- risk management;
- consumer protection;
- outsourcing;
- operational resilience;
- prudential requirements;
- anti-money laundering;
- data protection; and
- supervisory accountability.
The practical challenge is therefore not simply to determine what the AI Act requires.
It is to understand how those requirements interact with the existing financial-services acquis.
The 2024 consultation was designed to help the Commission understand those overlaps, identify potential practical difficulties and improve the effective implementation of the relevant legal frameworks.
What AI use cases were under review?
The consultation asked stakeholders about a broad range of AI applications in financial services.
These included use cases such as:
- risk assessment;
- credit scoring;
- robo-advice;
- fraud detection;
- anti-money laundering;
- regulatory compliance;
- customer service;
- personal-finance management;
- sustainable finance; and
- other applications being developed or planned by financial institutions.
This broad scope reflected an important reality.
The regulatory significance of AI depends heavily on the context in which the system is used.
Two systems may rely on similar underlying technology while creating very different regulatory consequences because of their purpose, users, affected individuals and role within the financial institution.
Some financial-sector AI uses are classified as high-risk
The final AI Act identifies specific financial-sector use cases within its high-risk framework.
These include AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, subject to the exclusions and conditions in the Regulation.
The AI Act also identifies AI systems intended to be used for risk assessment and pricing in relation to natural persons in life and health insurance.
The significance of those classifications is that organisations cannot assess AI compliance merely by asking whether AI is being used somewhere within the business.
They need to identify the purpose of each system and determine whether that use falls within a regulated category.
For financial institutions, this makes AI inventory and use-case classification an essential part of implementation.
Bias, transparency and accountability remain central concerns
The original consultation highlighted issues such as bias, transparency and accountability.
Those questions remain particularly important in financial services because AI systems may affect decisions concerning access to credit, insurance pricing, fraud controls, customer interactions or other economically significant outcomes.
Financial institutions therefore need to consider not only model performance but also the broader governance environment surrounding the system.
Depending on the use case, relevant considerations may include:
- data quality;
- representativeness;
- human oversight;
- explainability and transparency;
- documentation;
- auditability;
- decision escalation;
- monitoring after deployment; and
- interaction with data-protection obligations.
The AI Act and GDPR should not automatically be treated as interchangeable frameworks.
They regulate different issues.
But where AI systems process personal data, the organisation may need to implement both AI governance and data-protection requirements in a coordinated manner.
How the Commission structured the consultation
The targeted consultation was divided into three broad parts.
Part 1: General questions on AI development
The Commission sought information about market developments, adoption and the broader use of AI within financial services.
Part 2: Specific financial-services use cases
Stakeholders were asked about concrete applications of AI and the benefits, risks and practical challenges associated with those uses.
Part 3: The AI Act and the financial sector
The final section focused directly on implementation of the AI Act and its interaction with the existing financial regulatory framework.
That structure remains useful today as a practical way of organising an institution’s own AI implementation work:
first identify where AI is being used,
then understand the use case,
then determine which regulatory obligations apply.
From consultation questions to AI governance
For a financial institution, the questions raised in the 2024 consultation can be translated into a practical governance exercise.
The organisation should be able to identify:
- which AI systems are currently used or being developed;
- the purpose of each system;
- whether the organisation is acting as provider, deployer or another regulated actor;
- whether the use case falls within a high-risk category;
- which financial-services rules already govern the relevant activity;
- whether personal data is involved;
- which governance and oversight controls are required;
- what documentation must be maintained;
- how the system will be monitored after deployment; and
- who is accountable internally for regulatory compliance.
The result should not be a standalone “AI policy” detached from the institution’s existing governance structure.
AI compliance needs to connect with the organisation’s established risk, compliance, data, cybersecurity, operational-resilience and supervisory frameworks.
The AI Act and financial regulation need to be read together
One of the most important features of the Commission’s 2024 initiative was its focus on the relationship between the AI Act and the existing financial-services acquis.
That approach remains essential.
A financial institution using AI for credit, insurance, compliance, fraud prevention or customer-facing processes may already be subject to sector-specific governance and supervisory requirements.
The introduction of the AI Act does not necessarily replace those requirements.
It creates another regulatory layer that needs to be mapped onto the existing framework.
Effective implementation therefore requires a combined analysis of:
- the AI Act;
- applicable financial-services legislation;
- supervisory expectations;
- data-protection requirements;
- operational-resilience requirements; and
- the institution’s own governance model.
The objective should be regulatory integration rather than parallel compliance programmes that operate independently of one another.
Why the 2024 consultation still matters
The consultation itself is now closed.
Its continuing relevance lies in the implementation questions it identified.
The Commission was already asking financial institutions to explain:
- how AI is actually being used;
- what benefits organisations expect;
- what barriers are slowing adoption;
- where risks arise;
- how existing financial regulation interacts with AI; and
- what practical support may be needed to implement the AI Act.
Those are the same questions financial institutions need to answer internally.
The transition from consultation to implementation therefore changes the audience, but not the underlying problem.
In 2024, the Commission was asking the market how AI regulation should work in practice.
By 2026, firms increasingly need to demonstrate how their own AI governance makes that practical implementation possible.
From regulatory consultation to operational readiness
The European Commission’s 2024 consultation captured an important moment in the development of AI regulation for financial services.
The AI Act had been agreed, but institutions and regulators were still working through what implementation would mean across a heavily regulated sector.
The core issues raised then remain relevant now:
- identifying AI use cases;
- understanding risk;
- mapping overlapping regulatory frameworks;
- ensuring accountability;
- protecting customers and fundamental rights; and
- translating legal requirements into governance processes that work in practice.
For financial institutions, AI implementation should therefore begin with a clear picture of where AI is being used and how each use interacts with the organisation’s existing regulatory obligations.
The compliance challenge is not simply to add the AI Act to a list of applicable laws.
It is to integrate AI governance into the regulatory architecture the institution already operates.

