
AI Act readiness for a retail bank
Year:
2026
Service:
AI Governance & EU AI Act
Industry:
Banking
Team:
4 specialists, 12 weeks (typical)
Reference scenario: an EU retail bank builds its AI inventory, classifies credit scoring as high-risk under Annex III and plans controls and documentation against the amended AI Act timeline, with high-risk duties applying from 2 December 2027.
Introduction
This scenario follows a mid-sized retail and SME bank that operates in two EU Member States, one of them Poland. It uses machine learning in credit decisions, fraud detection and anti-money-laundering monitoring, and generative AI in a customer assistant and in staff tools.
The bank had planned its AI Act programme around 2 August 2026. Then Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the high-risk obligations for Annex III systems to 2 December 2027. The board asks a fair question: can the programme stop?
Our answer is a 12-week engagement that re-plans the work rather than pausing it: a complete AI inventory, a defensible classification of every system, and a control and documentation roadmap tied to the dates that are law today.

Challenge
The delay is real and binding, but it is not a repeal. Prohibited practices and the AI literacy duty have applied since 2 February 2025, and obligations for general-purpose AI models since 2 August 2025. The Article 50 transparency duties have applied since 2 August 2026, so the bank's customer assistant must already make clear that people are dealing with an AI system. DORA has applied since 17 January 2025 and pulls AI systems and AI vendors into ICT risk management.
The baseline is weak. Analysis cited by the Cloud Security Alliance finds that over half of organisations lack a systematic AI inventory and that 40 percent of the AI systems examined could not be clearly classified.
In the scenario the bank has three partial lists: in model risk, in IT and in procurement. None covers AI embedded in vendor products. Classification was attempted by legal alone. Two reference points are still moving: the Commission's final guidelines on high-risk classification are announced for the end of 2026, and EN 18286 is published but not yet cited in the Official Journal.
Solution
The work is organised in three moves.
Re-plan, do not pause. The roadmap is rebuilt against 2 December 2027 for Annex III systems, with what applies now (Article 50, AI literacy, DORA) at the front.
Classify with engineers in the room. Legal, model risk and engineering assess each system together against Annex III and Article 6(3) and store the reasoning as a decision record. Creditworthiness assessment of natural persons is classified as high-risk. Records are flagged for review once the Commission adopts its final guidelines.
Tie records to running systems. The registry is connected to the model deployment pipeline, so each record points to the version in production.
What is delivered in the scenario:
An AI system registry with 64 entries, including vendor-embedded AI, each with owner, purpose and the bank's role as provider or deployer
A classification decision record for every entry
A gap analysis against Articles 9 to 17 where the bank is provider and Article 26 where it is deployer
Annex IV technical documentation templates, piloted on the credit scoring model
A quality management system outline designed against EN 18286 and aligned with ISO/IEC 42001
Logging and human oversight design, with at least six months of log retention on the deployer side
A bias testing protocol built on the new Article 4a, which allows special categories of personal data to be processed for bias detection and correction where strictly necessary and with safeguards
One incident workflow for AI serious-incident reporting and DORA reporting
For the Polish operations the roadmap notes that individual opinions from Poland's AI supervisor, KRiBSI, become available on 28 October 2026.

Result
The engagement closes with a board paper and a set of working assets. Programme measures are set as targets, not reported as results:
Target: 100 percent of AI systems inventoried and classified, each with a decision record
Target: complete Annex IV technical documentation for every high-risk system by mid-2027, leaving time for an internal audit before 2 December 2027
Target: a regulator's information request answered from the registry within five working days
The bank owns the registry, the decision records, the documentation templates, a control library mapped to DORA and its model risk policy, and a dated roadmap. It also owns a watch list of what is not settled yet: the final classification guidelines, the Official Journal citation of EN 18286, and final Commission guidance on serious incident reporting.
This is governance and engineering support, not legal advice. The bank's own counsel signs off each classification.

