Regulatory guide

EU AI Act governance for high-risk AI systems

The EU AI Act regulates artificial intelligence by risk. This guide summarises the four risk tiers, why AML, fraud and credit-scoring models are usually high-risk, and the governance obligations that follow — conformity assessment, human oversight, a Fundamental Rights Impact Assessment, documentation and logging.

What the EU AI Act is, and who it applies to

The EU AI Act is the Union's horizontal framework for artificial intelligence. Rather than regulating a sector, it regulates AI systems by the risk they pose to health, safety and fundamental rights, and it places obligations on the operators of those systems — principally the provider that develops or places a system on the market, and the deployer that puts it into use.

For regulated financial businesses the Act is directly relevant because the models they already run for anti-money-laundering, fraud detection, transaction monitoring and creditworthiness assessment tend to fall into the high-risk tier. That means the same systems that support compliance decisions become subject to AI governance duties in their own right — layered on top of AMLA, the AML Rulebook, MiCA and DORA.

The four risk tiers

Unacceptable risk

A narrow set of practices — such as certain social scoring and manipulative or exploitative uses — is prohibited outright. These systems may not be placed on the EU market at all.

High risk

Systems used in sensitive contexts, including creditworthiness assessment and many AML, fraud-detection and risk-scoring models in financial services, are permitted but carry the heaviest obligations: risk management, data governance, documentation, logging, human oversight and conformity assessment.

Limited risk

Systems that interact with people or generate content carry transparency duties — users should know they are dealing with an AI system or with AI-generated or manipulated output.

Minimal risk

The majority of AI uses fall here and face no specific obligations under the Act beyond existing law, though voluntary codes of conduct are encouraged.

Core high-risk obligations

Conformity assessment

Before a high-risk system is placed on the market, the provider must demonstrate conformity with the Act’s requirements and keep the assessment current as the system changes.

Human oversight

High-risk systems must be designed so people can effectively oversee them — understand the output, interpret it correctly, decide not to use it, and intervene or stop it. Automated output must remain reviewable by a competent human.

Fundamental Rights Impact Assessment (FRIA)

Certain deployers of high-risk systems must assess the impact on fundamental rights before use — the affected people, the risks of harm, and the mitigation and oversight measures in place.

Technical documentation and record-keeping

Providers must maintain technical documentation describing the system, its purpose, data and performance, kept up to date so authorities can assess conformity.

Logging and traceability

High-risk systems must automatically record events over their lifetime so decisions can be traced and monitored, supporting post-market monitoring and investigation.

Data governance and accuracy

Training, validation and testing data must meet quality criteria, and systems must reach appropriate levels of accuracy, robustness and cybersecurity for their intended purpose.

How ReguShield helps

ReguShield is Compliance Intelligence Infrastructure. For AI governance it maps a business's AI-driven compliance activity against the EU AI Act obligations that apply, and produces decision-support a responsible owner can stand behind. ReguShield is itself deterministic and explainable by design, and it makes no claim of regulator certification or approval.

  • Obligation mapping — connects high-risk obligations — human oversight, documentation, logging, FRIA — to the systems and owners responsible for them.
  • Inherent and residual risk scoring — scores exposure before and after governance controls, so the effect of each control is visible.
  • Control-effectiveness assessment — gauges how well oversight and governance controls reduce inherent risk, and surfaces the remaining gaps.
  • Evidence lifecycle and audit lineage — ties documentation and evidence to each obligation and preserves the lineage of what was reviewed, when, and by whom.
  • Explainable decision support — every AI-assisted conclusion traces back to the signal and the rule behind it, keeping a human oversight step meaningful; the analysis is on-demand and deterministic, not a black box.
  • Board-ready executive reporting — produces governance reporting suitable for boards and supervisory scrutiny, with the reasoning attached.

Frequently asked

How does the EU AI Act classify AI systems?

The Act takes a risk-based approach with four tiers: unacceptable risk (prohibited practices), high risk (permitted but heavily regulated), limited risk (transparency duties), and minimal risk (no specific obligations). The obligations that attach to a system depend on the tier it falls into and the role of the operator — provider or deployer.

Are AML and fraud-detection models high-risk?

Models used for creditworthiness assessment and for many AML, fraud-detection and financial risk-scoring purposes are typically treated as high-risk because they materially affect people’s access to services and their rights. Providers and deployers of such systems face the full set of high-risk obligations, including conformity assessment, human oversight, documentation and logging.

What is a Fundamental Rights Impact Assessment (FRIA)?

A FRIA is an assessment certain deployers of high-risk AI systems must carry out before putting a system into use. It identifies the categories of people affected, the specific risks of harm to fundamental rights, the human-oversight measures in place, and the steps to take if a risk materialises. It complements, and can build on, an existing data-protection impact assessment.

What does 'human oversight' require in practice?

High-risk systems must be built so a competent person can understand the system’s output, interpret it correctly, choose not to rely on it, and intervene or stop the system. In compliance terms, an AI risk score or recommendation is an input to a human decision-maker who retains final judgement — not an automatic determination.

Do I need conformity assessment and technical documentation?

For high-risk systems, yes. Providers must complete a conformity assessment, maintain technical documentation covering the system’s purpose, data and performance, and keep automatic logs to support traceability. These records must be kept current so authorities can verify conformity throughout the system’s lifecycle.

ReguShield provides compliance decision-support — not legal advice; final decisions require human review and sign-off.

View the guided demoTrust CenterBack to Resources