Search
Choose a style
Dark
Light
Time to read: 5 min

EU AI Act delay provides breathing space for payments firms

European flag with "Ai Act" text, concept for regulation of AI tools (EU AI Act)
EU AI Act - Editorial credit: RaffMaster / Shutterstock.com

A delay on high‑risk AI obligations may come as a relief to some payments firms around the EU AI Act, but GPAI enforcement powers mean they can’t take their foot off the gas.

The European Union’s AI (EU AI) Act has entered a new phase, with transparency rules now in effect and regulators gaining stronger enforcement powers.

Financial institutions have embedded AI into nearly every aspect of their services, whether through AI chatbots in customer service or tools that identify fraud through suspicious patterns. 

Emerging developments such as agentic commerce are set to push the tech further into financial services, creating the need for automated systems to support processes such as Know Your Agent and anti-money laundering (AML) checks.

However, these innovations may face more friction in Europe as the market takes a tougher stance on AI adoption than others. 

Jeremy Brown, Investment Principal at Anthemis
Jeremy Brown, Investment Principal at Anthemis

The new rules, announced on 2 August 2026, require companies using certain AI systems to comply with new requirements to make AI-generated content easier to identify and ensure users know when they are interacting with the technology rather than a person.

For the payments and financial services sector, the key updates are the introduction of general‑purpose AI (GPAI) model enforcement powers, new training data transparency requirements and the delay to high-risk AI deadlines.

Jeremy Brown, Investment Principal at Anthemis, tells Payment Expert that the latest developments provide businesses with greater regulatory certainty, but Europe faces a challenge in balancing AI governance with its competitiveness.

He adds that Europe’s more rules-based approach to AI will now be tested against other markets, particularly around whether the region can continue attracting investment and innovation while maintaining strong oversight.

“Compared to markets like the US, Europe has taken a more rules-based approach to AI. Much like how the EU set the global benchmark for data privacy through GDPR, the question now is whether it can do the same for AI without sacrificing competitiveness,” he adds.

GPAI enforcement puts AI providers under scrutiny

Following the update, the European AI Office now has additional powers around GPAI models, allowing it to request documentation, access and evaluate models, require corrective measures and issue fines of up to €15m or 3% of global annual turnover.

GPAI models are systems designed to perform a wide range of tasks, such as OpenAI’s ChatGPT, which recently partnered with Revolut to offer ChatGPT Go to millions of its retail customers. 

Under the agreement, Revolut users can access higher usage limits, more uploads, document analysis, image generation and memory features for up to 12 months depending on their plan.

While payments and financial firms may not be deploying ChatGPT directly into decision‑making systems, the partnership shows how GPAI tools are entering financial ecosystems. 

As these models come under greater EU oversight, firms using or embedding third-party AI will need to pay closer attention to the compliance standards of the providers, particularly around training data transparency, documentation and risk management.

This is becoming more important as GPAI systems are integrated into agentic commerce, where AI tools research purchases, organise tasks and assist users in making decisions. 

Regulators are expected to scrutinise how agentic systems influence consumer behaviour, initiate actions and interact with financial products. 

Training data transparency creates new expectations

Another important change for payments companies is the introduction of training data transparency requirements for GPAI developers.

Under the EU AI Act, providers of GPAI models must publish “sufficiently detailed summaries” of the datasets used to train their systems, which aims to give businesses using these models a better understanding of how they have been developed, including the types of data involved and whether copyrighted material has been used.

Payments firms will need to assess how models have been trained and whether they introduce risks around areas such as bias, data quality or decision-making processes.

This will become an important part of vendor assessments and AI governance as banks, payment service providers and fintechs integrate the tech into areas such as customer onboarding, fraud prevention, compliance and customer service.

EU AI Act delays high-risk rules

Part of the update was an announcement that there is a delay to high-risk AI obligations, giving financial companies more time to prepare for stricter requirements. 

Under the new timeline for the EU AI Act, high-risk AI systems must comply by December 2027, while high-risk AI embedded in regulated products has been pushed to August 2028.

The extensions seek to give companies more time to align with emerging standards and build the governance processes needed for high-risk AI use cases, including areas such as credit scoring, AML monitoring and biometric verification.

Adrian Congiu, VP Head of Product Management at Mambu
Adrian Congiu, VP Head of Product Management at Mambu

Additional time could provide an opportunity to bolster AI governance frameworks, modernise legacy systems and ensure the necessary controls are in place before the requirements take effect.

However, Adrian Congiu, VP Head of Product Management at Mambu, warns that the delay should not be viewed as a reason to slow down AI adoption.

“The implementation delay gives banks more time to prepare. It doesn’t compel AI developers to slow down. Financial institutions should use this window to modernise the technology foundations that trustworthy AI depends on,” Congiu tells Payment Expert.

He adds that effective AI governance requires firms to show where data came from, how decisions were reached and who is accountable when something goes wrong.

“AI governance is, at the end of the day, an architectural challenge – and trustworthy AI depends on foundations that many organisations have struggled to modernise,” Congiu states.

While the regulatory framework will continue to be changed, Congiu believes financial institutions should not wait for further guidance before building their AI capabilities.

“The EU AI Act won’t be the last word on AI governance. Standards are still being developed, guidance will evolve and AI itself won’t stand still. However, financial institutions shouldn’t wait to be pushed by regulation,” he states.

Subscribe to our newsletter