Law / European Union

AI Act, Article 6(2) and Annex III, point 5(b) (creditworthiness and credit-scoring systems: provider duties)

Regulation (EU) 2024/1689, Article 6(2) and Annex III, point 5(b)

An AI risk obligations rule binding public and private bodies.

How the hook was established
express
What makes it apply
Market targeting, Place of effect
Obligation class
Governance, DPIA
Audit expectation
on_request
Who audits it
Regulator
Where the report goes
Produced on request

As of .

What it requires

  • This duty takes effect on (Article 113, as amended by Regulation (EU) 2026/1744) for a high-risk AI system classified under Article 6(2) and Annex III, the only classification point 5(b) reaches, so the later date of for one classified under Article 6(1) and Annex I adds no system to it; a system already placed on the market or put into service before its date is reached only once its design changes significantly, or by if it is intended for use by public authorities.
  • It reaches you if you are the provider of an AI system intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, other than one used for the purpose of detecting financial fraud: Article 6(2) makes it a high-risk AI system, and you are its provider if you develop it, or have it developed, and place it on the market or put it into service under your own name or trademark.
  • Ensure the system complies with the requirements of Chapter III, Section 2: risk management (Article 9), data and data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency and instructions for use (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15).
  • Indicate your name, registered trade name or registered trade mark and the address at which you can be contacted on the system or, where that is not possible, on its packaging or its accompanying documentation.
  • Have a quality management system in place that complies with Article 17, and keep the documentation referred to in Article 18.
  • Keep the logs the system automatically generates, to the extent they are under your control, as Article 19 requires.
  • Before you place the system on the market or put it into service, have it undergo the conformity assessment procedure of Article 43; for a point 5 system that is the procedure based on internal control in Annex VI, with no notified body.
  • Draw up an EU declaration of conformity (Article 47), affix the CE marking (Article 48) and register yourself and the system in the EU database (Article 49(1)).
  • If you consider or have reason to consider that the system is not in conformity with the Regulation, take the necessary corrective actions and provide the information Article 20 requires.
  • Demonstrate the system's conformity with the requirements of Section 2 when a national competent authority makes a reasoned request.
  • Ensure the system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882.

If you get it wrong

Private right of actionNo

Penalty structure

Article 99(4)(a): non-compliance with the obligations of providers under Article 16 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. The provider of a point 5(b) system carries the Article 16 obligations because Article 6(2) classifies the system as high-risk. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.

Rule
Lower of for SME
As of
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
3

What it makes you log

Logging duty

Article 16, point (e), names the keeping of the logs automatically generated by a high-risk AI system, to the extent they are under the provider's control, by reference to Article 19. It does not itself create the logging capability, set a retention period or say what the logs must contain, and it does not say who may see them; capability and content are Article 12's, retention is Article 19's and access to a provider's logs is Article 21(2)'s, each on its own row.

Kind
Explicit
As of
Provision
Article 16, point (e)
Trigger
high_risk_systems

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Annex III, point 5(b), lists AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud. Under Article 6(2), the AI systems referred to in Annex III are considered high-risk, in addition to those referred to in Article 6(1).

A provider is a natural or legal person, public authority, agency or other body that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Article 16 obliges the provider of a high-risk AI system to ensure that the system complies with the requirements set out in Section 2 and to have a quality management system in place that complies with Article 17.

Article 16 also obliges the provider to keep the documentation referred to in Article 18 and, when under its control, the logs referred to in Article 19, and to ensure that the system undergoes the relevant conformity assessment procedure referred to in Article 43 before it is placed on the market or put into service.

Article 16 further obliges the provider to draw up an EU declaration of conformity, to affix the CE marking, to comply with the registration obligations referred to in Article 49(1), to take the necessary corrective actions and provide information as required in Article 20, and to demonstrate the conformity of the system with the Section 2 requirements upon a reasoned request of a national competent authority.

For an AI system referred to in points 2 to 8 of Annex III, which includes point 5(b), Article 43(2) requires the provider to follow the conformity assessment procedure based on internal control referred to in Annex VI, which does not provide for the involvement of a notified body.

Notwithstanding the Article 6(3) derogation, an AI system referred to in Annex III is always considered high-risk where it performs profiling of natural persons, so the derogation cannot take a point 5(b) system out of the high-risk class if the system performs that profiling. Profiling means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.

Recital 58 adds that AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services and for prudential purposes to calculate credit institutions' and insurance undertakings' capital requirements should not be considered to be high-risk under the Regulation.

Annex III classification under Article 6(2) and the Article 16 obligations of the provider sit in Chapter III, Sections 1 and 3, so they take effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744) wrote into Article 113: for a system classified as high-risk under Article 6(2) and Annex III.

The later date of for a system classified under Article 6(1) and Annex I brings no further system within a point 5(b) classification, which sits in Annex III.

Under Article 111(2), as the Digital Omnibus on AI rewrote it, the Regulation reaches the operators of a high-risk AI system placed on the market or put into service before the date Chapter III applies only if, from that date, the system's design changes significantly; in any case, the providers and deployers of a high-risk AI system intended to be used by public authorities must take the necessary steps to comply with the Regulation's requirements and obligations by .

When LexLint raises it

When your app profile says your app provides financial services or makes high-risk automated decisions.

Back to the example  ·  Lint your app