Some payments and crypto firms may have read July news and moved the EU AI Act down their compliance to-do list. The Digital Omnibus on AI, Regulation (EU) 2026/1744 pushed the compliance deadline for high risk AI systems from 2 August 2026 to 2 December 2027, a 16-month reprieve. However, the delay only covers the obligations that were actually deferred. Firms using AI in fraud prevention, onboarding or financial crime controls should not treat this as a reason to pause their implementation work. 

What actually moved, and what did not 

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers application of Chapter III, Sections 1 to 3 of the AI Act until: 

  • 2 December 2027 for high risk systems classified under Article 6(2) and Annex III; and  
  • 2 August 2028 for those classified under Article 6(1), including certain safety-component systems under Annex I. 

Article 50 did not move. The transparency duties, covering disclosure of AI interactions and labelling of AI-generated content, took effect on 2 August 2026 regardless of risk tier. 

For a firm running AI-assisted fraud detection, transaction monitoring, or automated onboarding decisions, two separate clocks are now running. One has significant new runway. The other never stopped. 

The classification question firms should not skip 

This is not a reason to shelve classification work. Classification determines which parts of the AI Act apply and underpins every downstream procurement, governance and implementation decision. 

An AI-driven transaction monitoring engine that influences whether a firm ends a customer relationship or files a report can fall within Annex III’s treatment of risk-scoring systems, depending on exactly what the model does and how the firm uses its outputs. A system, however, does not become high risk merely because its output may lead to an alert, investigation, or customer exit. 

Instead, firms should ask whether the system’s intended purpose brings it within a specific Annex III category based on the system’s actual function, not on a vendor’s product description. A “fraud detection” label says nothing about how the AI Act treats a tool. What matters is the output it produces and how that output affects the customer. 

Systems that fall outside the high risk category are not outside the AI Act altogether. Prohibited-practice rules, transparency requirements, AI literacy measures and other horizontal obligations may still apply.  

Why the vendor does not answer this for you 

A vendor stating that its product is “AI Act compliant” does not mean the customer firm has met its own obligations. 

The AI Act distinguishes between roles such as provider, deployer, importer and distributor. The obligations that apply to a firm depends on its role and, in some cases, on whether it has changed the system, placed it on the market under its own name, or substantially modified it. 

A firm acting as a deployer of a high risk system carries its own duties. It must use the system as instructed, assign competent human oversight, monitor its operation, retain any logs under its control, and escalate specified risks or serious incidents. 

Even where a provider completes a conformity assessment, that does not remove the deployer’s own responsibilities. 

Aligning AI Governance with AML and DORA 

The AI Act sits alongside existing AML and operational resilience obligations. Whether or not an AI-enabled tool qualifies as a high risk AI system, firms should still understand how it works, how its outputs influence decisions, what data it uses, the role of human oversight, and how related third party providers are governed.  

EU financial entities should also fold AI governance into their DORA framework, covering ICT risk management, operational resilience testing, change management and third party risk oversight. A documented AI inventory and classification register supports both AI Act compliance and wider AML and DORA governance. 

What to do with the extra time 

Treat the deferral as a resourcing gift, not a reason to stop. Firms in scope should use the window to: 

  • Create and classify an AI inventory: Document all AI-enabled use cases and assess each against the AI Act, recording the rationale behind the classification. 
  • Address obligations that apply now: Review whether Article 5, Article 50, or other current obligations apply. 
  • Clarify governance and accountability: Ensure meaningful human oversight, and document how AI outputs are challenged, reviewed and escalated. 
  • Integrate AI into existing control frameworks: Align AI governance with AML controls, outsourcing oversight, data protection processes and, where applicable, DORA ICT risk management arrangements. 
  • Monitor changes to existing systems: Maintain records of significant modifications and reassess classification where system functionality or use changes over time. 

What we are seeing in practice 

The firms furthest ahead are the ones that started a use case register before the Omnibus landed and kept adding to it. Strikingly, many firms still cannot say how many AI-assisted decisions touch a customer relationship, let alone where each one sits in the business. 

Take a mid-sized e-money institution using a third party transaction monitoring platform, where the vendor has recently added an AI-driven risk scoring layer to prioritise alerts. On the surface, this looks like a vendor question. In practice, the firm is the deployer, and it is the firm’s job to understand how that scoring layer decides which alerts a human analyst sees first, whether the model’s weighting has ever deprioritised a case incorrectly, and how the firm would evidence that if a supervisor asked.  

The tool sits with a vendor; the obligation sits with the firm. Firms that blur that distinction are the ones most likely to assume they are covered when they are not. 

Where guidance is still catching up 

Guidance from the European Commission and the AI Office on Annex III classification thresholds is still developing, and harmonised standards from European standardisation bodies are not yet finalised for every high risk category. That gap is part of why the deferral exists. Firms should treat the lack of finalised guidance as a reason to start building their own classification logic now, rather than a reason to wait. A firm that has already mapped its own use cases against the current draft thresholds will find it considerably easier to adjust when the final technical standards land.  

How fscom can help 

fscom Compliance Maturity Specialists™ supports payment firms, e-money institutions and crypto-asset firms in classifying AI use cases against the AI Act, reviewing governance and human oversight arrangements, and aligning AI-related controls with existing financial crime and Consumer Duty frameworks. Whether you are working through Annex III classification for the first time or checking a governance framework you built before the Omnibus landed, we can help you find out where you actually stand. 

Get in touch to discuss an AI classification and governance review.