Buyer signal · AI & finance
Proof changes when the buyer is a bank.
What enterprise AI buyers need to believe before a compelling demo becomes a credible purchase.
The demo goes beautifully. The head of financial crime is engaged, the numbers land, someone asks about the roadmap, which is always a good sign. Six weeks later the deal is sitting with second-line risk and nobody has replied to an email in eleven days.
That demo did its job. It convinced the person who will use the product. The purchase requires convincing a set of people who will never watch it, and who assess evidence for a living.
Who is actually in the room
For an AI product entering a bank, the people who can stop you are model risk and validation, ICT third-party risk, compliance, procurement, and whoever holds personal accountability for the AI framework. That last role is now close to universal: the Bank of England and FCA found that 84% of surveyed firms had an accountable person for their AI framework.
None of those functions is hostile. They have a different job. Yours is to make a case; theirs is to establish whether the case survives being taken apart. They work from documents, and if the documents do not exist, the answer defaults to no by inertia rather than by decision.
The dates just moved. The evidence did not.
This is the live piece of news for anyone selling AI into European financial institutions, and it is being widely misread.
The EU AI Act set 2 August 2026 as the day the high-risk regime began to bite, which included creditworthiness assessment and credit scoring of individuals under Annex III. By late 2025 the supporting machinery was visibly behind: harmonised standards from the European standards bodies were unfinished, guidance was still in draft, and several member states had not resourced their market surveillance authorities.
So the Commission proposed an amendment in November 2025, and it is now law. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July, three days later, on urgency grounds because the original deadline was days away.
What it changed, precisely:
- Obligations for stand-alone high-risk systems under Annex III move from 2 August 2026 to 2 December 2027.
- High-risk AI embedded in products already covered by EU product safety law under Annex I moves to 2 August 2028.
- The Article 50 transparency obligations stay where they were and apply from 2 August 2026. Chatbot disclosure, deepfake labelling, notices for emotion recognition and the disclosure duty on certain AI-generated public-interest text are all unaffected. Machine-readable marking of AI-generated content under Article 50(2) gets until 2 December 2026 for systems already on the market.
If your product touches retail credit decisions, you have gained sixteen months of runway. Spend it building the file, because the requirements themselves did not change by a word. Neither did the bank’s own rules.
The bank’s model risk framework is fifteen years older than the AI Act
American supervisors published SR 11-7 in April 2011, jointly with the OCC. It requires a model inventory, independent validation with genuine effective challenge, documentation sufficient for a third party to reconstruct the work, and ongoing performance monitoring. It applies whether the model was built in-house or bought, and the institution stays accountable either way. Supervisory frameworks in Europe and the UK run on the same logic.
That is the point most vendors miss when a regulatory deadline slips. Your buyer’s validation team was asking these questions in 2015 and will ask them in 2028. Brussels moving a date does not remove a question from their template.
Under DORA you are already an entry in a register
DORA has applied directly across EU financial entities since 17 January 2025, and it reframes what a software vendor is. You are a line in your customer’s register of information, describing the contractual arrangement, whether it supports a critical or important function, where the data sits, and who your own subcontractors are.
Articles 28 to 30 push specific terms into the contract: audit and access rights, incident cooperation, service levels tied to resilience, exit arrangements that can actually be executed. Concentration and substitutability get assessed, so “who else could do this if you failed” becomes a question you should be able to answer without flinching.
The oversight regime is live at the top of the market too. On 18 November 2025 the three European Supervisory Authorities designated the first critical ICT third-party providers, a list of nineteen firms now under direct EU-level oversight. Most vendors will never be designated. It does not matter, because the obligations reach you through your customer’s contract regardless.
What the questionnaire will look like in 2027
The Financial Stability Board published a consultation on 10 June 2026 setting out twelve sound practices for responsible AI adoption by financial institutions. Four cover organisation-wide governance, six cover the development and deployment lifecycle, and the last two cover cyber, ICT and third-party risk. Comments closed on 22 July and the final report is expected in October.
It is not binding, and it does not need to be. Documents like this get lifted into supervisory expectations and then into vendor due diligence questionnaires with a lag of roughly a year. Read it now and you will recognise the questions you get asked next year.
The pack you should have before the first demo
- Model documentation written for an independent reviewer, covering design choices, training data provenance, known limitations and the population the model was built for.
- Performance on data resembling the buyer’s, with a stated baseline. A percentage improvement without the comparator it improved on gets discounted to zero.
- Drift and monitoring, including what triggers an alert, who receives it, and what the bank is expected to do next.
- The human control design. Only 2% of AI use cases in the BoE survey were fully autonomous, while 55% involved some automated decision-making. Show where a person intervenes and what they see when they do.
- Third-party and subcontractor map, because your dependencies become their concentration risk. The same survey found the top three providers accounted for 73%, 44% and 33% of all reported cloud, model and data providers, which is exactly why this gets asked.
- Exit and portability, described concretely enough to satisfy someone who has to write an exit plan.
- Incident support commitments that align with the reporting clocks the bank is held to.
Building that pack is a quarter of work for most vendors and it converts directly into cycle time. It is also reusable, which is more than can be said for most launch collateral.
The gap worth attacking
One number from the BoE and FCA survey should be on the wall of every AI vendor selling into this sector. Forty-six percent of firms reported only partial understanding of the AI technologies they use, against 34% claiming complete understanding, and the regulators put that down largely to third-party models. A third of all use cases were third-party implementations, roughly double the share two years earlier. The fourth edition of that survey closed to responses at the end of July 2026, so a fresher figure is coming.
Nearly half the market has bought something it cannot fully explain, in a sector where explaining things is a legal obligation and a named individual carries it. Vendors are still selling accuracy into that gap. The ones who sell explainability instead will get paid more for it, and they will get through procurement faster, which in a twelve-month sales cycle is the bigger prize.
Sources
- Bank of England & FCA84% of surveyed firms had an accountable person
- EUR-LexEU AI Act
- EUR-LexRegulation (EU) 2026/1744
- Federal ReserveSR 11-7
- EUR-LexDORA
- European Banking Authoritydesignated the first critical ICT third-party providers
- Financial Stability Boardtwelve sound practices for responsible AI adoption