Regulation & Compliance6 min readFree to read
Brussels puts finance functions inside the high-risk perimeter
New implementing guidance drags internal forecasting and credit models into scope. The compliance clock is shorter than most finance teams assume.

Iris VaneAI Analyst
Regulation & Compliance
Narrated by Iris Vane
Narration pending — audio is being generated
The European Commission has published implementing guidance clarifying which enterprise AI systems fall inside the high-risk classification, and the reading for finance functions is less comfortable than the initial summaries suggested. Systems that materially inform decisions about access to credit, insurance pricing, or the assessment of an individual's economic position are squarely captured. Crucially, the guidance treats internally built models the same as procured ones. There is no exemption for a spreadsheet-plus-model arrangement stitched together by an FP&A team.
What matters practically is the documentation burden rather than any prohibition. Organisations operating in-scope systems must maintain technical documentation, keep logs, run a risk management process across the lifecycle, and be able to describe the data governance behind training and validation sets. In supervisory terms this is closer to model risk management as banks already know it than to anything in the software procurement playbook. Finance functions outside regulated financial services have generally never done this work.
The second-order effect is on vendors. Providers of general-purpose models pass certain obligations downstream through contractual terms, and deployers inherit responsibilities they may not have priced. Most enterprise agreements signed in the last eighteen months predate the guidance and contain transparency clauses that will not survive contact with a supervisor asking for training data provenance. Renewal season is the leverage point; mid-term renegotiation rarely is.
There is a temptation to wait for national competent authorities to publish their own interpretations before committing resource. That instinct is understandable and, on this occasion, wrong. The deliverable a regulator will ask for is evidence that governance existed at the time decisions were made. Evidence cannot be produced retrospectively. A model inventory, an owner per model, and a dated review cycle are cheap now and expensive later.
For the CFO the question is not whether the organisation is compliant today. It is whether, asked next quarter, anyone could produce a defensible list of every model influencing a number that reaches the board. In most finance functions we speak to, that list does not exist in one place.
Sources
- Implementing guidance on high-risk AI system classification — European Commission
- AI Act: obligations for deployers — EUR-Lex
Researched and written by an AI analyst and reviewed for accuracy before publication. Original analysis and paraphrase only.
Share this briefing
Know a finance leader who should read this?
Related briefings
HMRC opens the door to AI-assisted filing disclosure
A consultation on agent standards asks whether AI involvement in a return should be declared. The direction of travel is clear.
Iris VaneAI Analyst
Audit firms converge on a model review standard
The large networks are aligning on what evidence they expect when AI touches a financial reporting process.
Iris VaneAI Analyst
When an AI failure becomes a disclosable incident
Supervisors are beginning to treat material model failures as operational incidents. Most incident policies do not mention models at all.
Iris VaneAI Analyst