Regulation (EU) 2026/1744, the AI Omnibus, was published on 24 July and entered into force on 27 July. It moved the main high-risk requirements for standalone systems covered by Annex III of the EU AI Act from 2 August 2026 to 2 December 2027. EU-facing teams gained 16 months, but the extension did not suspend duties that already apply.
For finance, Annex III covers AI used to evaluate the creditworthiness of natural persons or establish a credit score, except systems used to detect financial fraud. It also covers AI used to assess risk and price life and health insurance. Annex I systems moved from 2 August 2027 to 2 August 2028, but that is a defined product-safety route, not a later date for loans or policies simply because they are regulated. Article 50 transparency duties have applied since 2 August 2026, subject to the limited grace period for specified pre-existing marking systems.
The UK decision starts with overlap, not equivalence
Clarqo’s analysis is that the extension changes programme sequencing, not the minimum control base. That is a budgeting conclusion drawn from the gap between the delayed EU conformity timetable and UK supervisory frameworks that remain in force. It is not a claim that every UK bank had built a deadline-specific programme around 2 August 2026.
The EU exposure can still arise from Britain. The Act’s territorial scope includes providers and deployers established in a third country when the output produced by their AI system is used in the EU. A UK-headquartered group therefore needs to identify which models serve EU businesses, customers or decisions before deciding which work can move.
In Britain, the FCA says it does not plan an additional AI rulebook. It applies existing frameworks, including the Consumer Duty and senior-management accountability, when firms use AI. The PRA’s SS1/23 model-risk principles apply to regulated UK-incorporated banks, building societies and PRA-designated investment firms with internal-model approval for regulatory capital calculations.
Those regimes do not convert every EU AI Act control into a direct UK requirement. They do mean that several disciplines overlap with UK supervisory expectations. Model identification, accountable ownership, independent validation and monitoring of customer outcomes remain useful even when an EU conformity deadline moves.
Keep now: the reusable control spine
UK financial groups should keep funding four parts of the programme.
- Inventory and classification. Maintain one map of models, owners, uses, customers and jurisdictions. Mark whether each system is UK-only, produces outputs used in the EU, or supports an Annex III use case. Revisit financial-crime tools rather than treating all of them as high-risk, because the creditworthiness category expressly excludes fraud detection.
- Ownership and accountability. Keep named business and risk owners, approval records and escalation routes. These are the mechanisms through which a firm can show who accepted a model’s limits and who must act when customer outcomes deteriorate.
- Validation and outcomes testing. Continue independent challenge, performance thresholds, drift monitoring and testing for harmful customer effects. This work supports risk management under PRA and FCA frameworks even where no EU conformity assessment is yet due.
- Incident, change and supplier handling. Preserve logging, material-change gates, third-party evidence, incident escalation and customer-remediation routes. Deferring those controls would create operating risk now, not merely compliance risk in 2027.
Public disclosures show why the distinction matters. Lloyds Banking Group says its AI Assurance Framework covers internal and external systems across their lifecycle and aligns, where relevant, with the EU AI Act, UK AI assurance guidance and ISO 42001. That supports the existence of reusable controls. It does not prove Lloyds, or UK finance generally, budgeted a programme against the old Annex III date.
HSBC Continental Europe’s 2025 annual report says more sophisticated AI modelling creates model risk that must be managed in compliance with the EU AI Act. That establishes an EU operating exposure within a UK-headquartered group. It does not establish a deadline-specific UK budget. The evidence supports maintaining a control spine, not inventing a sector-wide sunk-cost figure.
Rephase the standard-dependent finish
The extension has value where technical specifications remain unsettled. A group acting as an AI provider can rephase final standards mapping, standard-dependent technical documentation and execution of conformity-assessment work tied specifically to the delayed high-risk requirements. A deployer can re-sequence final supplier-evidence gates and contract changes that depend on the same specifications. Scoping, ownership and evidence collection should continue, so the programme does not face a compressed rebuild in 2027.
Programme leaders should divide spending into three tranches:
- Duties already live: fund applicable prohibited-practice, general-purpose AI and Article 50 work to the current timetable.
- Reusable UK and EU controls: keep inventories, governance, validation, monitoring and incident handling in delivery now.
- Delayed Annex III conformity tasks: rephase only the work whose content or timing depends on final standards, guidance or the December 2027 legal date.
The boundary should be recorded model by model. A customer-facing chatbot may already need an Article 50 disclosure while a credit-scoring engine has longer for the full high-risk regime. A fraud-detection model may fall outside the specific creditworthiness classification but still require controls under financial-services rules and the firm’s own risk framework.
The European Banking Authority found that the AI Act is complementary to existing banking and payments law, with no significant contradictions, while noting that firms must integrate the frameworks. Moving one EU layer therefore does not move the sectoral obligations beneath it.
The practical UK decision is not whether to stop or continue an undifferentiated AI Act project. It is which deliverables still reduce present risk and which are premature attempts to finish a conformity package. Firms that keep the control spine and move only the standard-dependent finish can use the 16 months without weakening accountability on either side of the Channel.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.