Skip to content
A bank's operations floor seen through a glazed wall from a lit corridor, with market charts on screens high on the far wall.

YOUR PEOPLE ALREADY USE AI

You can know every AI you run.

You get one inventory of every AI system in the firm within weeks, each one classified and owned. After that you can answer the next request from evidence, and most of the list will carry no heavy requirements.

THE EVIDENCE

Your supervisor already measured this.

The EU AI Act is EU law, supervised nationally. When the Swedish Financial Supervisory Authority (Finansinspektionen) surveyed its own market and reported in December 2024, 84 percent of firms said their employees use generative AI at work, and 32 percent had a policy for it.

Nearly a third of reported AI use cases had not yet been risk-classified at all.

And the supervisor's own conclusion was blunt: it is very likely that the sector will be operating inside the high-risk categories once the rules apply in full.

Read those numbers together and the finding is uncomfortable. The most compliance-mature sector in the economy is running its newest technology largely outside its own control frameworks. Not because anyone decided that. Because everyone assumed the existing machinery had it covered.

WHERE THE FRAMEWORKS DON'T MEET

Three traps, all made of experience.

01

The absorption trap.

"Our regulatory stack absorbs this." It doesn't. DORA asks whether a technology failure can disrupt your operation. The AI rules ask whether the system can harm the individual in front of it. Same technology, different questions, and neither framework answers the other's.

02

The DPIA trap.

"Our data protection assessments cover it." They help, and they are not the same instrument. For the finance use cases on the high-risk list, a fundamental rights impact assessment is required of every deployer, private ones included. Your data protection impact assessment (DPIA) is the starting material, not the answer.

03

The vendor trap.

"It's the vendor's system, so it's the vendor's problem." The provider carries provider duties. You carry deployer duties: knowing what you run, overseeing it, logging it, and answering for how it treats your customers. An inventory you don't have is a duty you can't meet.

WHAT IS ACTUALLY HIGH-RISK

Exactly two things. And a long list of nothing.

The high-risk list names exactly two financial use cases: creditworthiness assessment of private individuals, and risk assessment and pricing in life and health insurance. That is where the heavy requirements land, from 2 December 2027.

Just as important is what is not there. Fraud detection is explicitly carved out. Anti-money laundering (AML) monitoring is not on the list. General insurance, home, motor, commercial, is not on the list.

Credit assessment of companies is not on the list. Neither is fund management, asset management or payment services. A mortgage scoring model is in scope. The transaction monitoring beside it is not.

Half our job in this sector is telling you what you can stop worrying about. The other half is making sure the two things that remain are handled like the supervised activities they are about to become.

FOUR STEPS THAT START WITH THE LIST

What to do, in order.

01

Inventory and classify.

You cannot govern what you haven't listed, and in the Swedish survey a third of what is running was unclassified. The AI Readiness Assessment settles what you have, what category it sits in, and what that triggers. Most of the list will calm you.

02

Close the transparency gaps.

Customer-facing chatbots and generated content carry disclosure duties that apply broadly, not just to high-risk systems. A small, fast, fixed-price review: the gap list and the fix plan. Weeks, not months.

03

Start the runway where it matters.

If private-individual credit scoring or life and health pricing is in your product chain, the heavy requirements are yours. Risk management, the impact assessment as a working process, documentation built for an audit. The head start, never the panic.

04

Write the policy people actually follow.

84 and 32 are the same finding: your people already use AI, mostly without rules. In a sector built on client confidentiality, an unworkable policy doesn't stop usage. It hides it.

OUR POSITION

In Sweden, your market supervisor for this is the one you already know. That is good news, and a reason to be ready before they ask.

PROOF

Delivered where audits are normal.

Our regulated-environment delivery spans pharmaceutical and medtech brands and Swedish state agencies, work where documentation, audit trails and accountability are conditions of entry. The consultant who leads your engagement is the person who delivered it.

QUESTIONS

Before you assume DORA is enough.

DORA and the EU AI Act regulate the same systems but answer different questions, so one does not replace the other. What the AI Act adds is four things: a classification of what you actually run, the transparency duties in Article 50 from 2 August 2026, your own deployer duties also for systems bought from a vendor, and for the two financial use cases in Annex III a fundamental rights impact assessment that your data protection impact assessment does not replace. Supervision sits with Finansinspektionen, the authority you already know.

Yes, creditworthiness assessment of private individuals is one of the Annex III use cases under the EU AI Act and therefore high-risk. The high-risk requirements apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I. Corporate credit assessment is not on the list, and fraud detection is explicitly carved out. The classification is usually quick, and for most of your portfolio the answer is calming.

Risk assessment and pricing in life and health insurance is high-risk under Annex III of the EU AI Act, with requirements from 2 December 2027. General insurance, home, motor and commercial, is not on the list, and neither is claims handling as such. The dividing line runs through the actuary's models: the insurance risk model for life and health is in scope, the case handling beside it usually is not.

Yes, the EU AI Act applies to asset management and payment services, but more lightly than to the two high-risk use cases. Fund management, asset management and payment services are not on the Annex III list, so the high-risk requirements from 2 December 2027 probably do not reach you. The AI literacy duty in Article 4 has applied since 2 February 2025 regardless of risk level, and the transparency duties in Article 50 from 2 August 2026. In practice your heaviest AI question becomes model risk, third-party risk and internal control.

No, responsibility for the EU AI Act's duties is shared when the system sits with the vendor. The provider carries provider duties, you carry the deployer's: inventory, oversight of use, logging, and answering for outcomes toward your customers. Both sets apply at once, and yours cannot be outsourced. Third-party risk under DORA takes you part of the way, but it asks about operational disruption, not about how the system treats the individual customer.

Generative AI in your employees' own work triggers three things. The AI literacy duty in Article 4 of the EU AI Act has applied since 2 February 2025 and covers everyone who uses AI at work. The use belongs in the inventory, including where the tool arrived built into software you already had. And the GDPR applies as usual to whatever is typed into it. In the Swedish supervisor's survey, 84 percent of firms said their employees use generative AI while 32 percent had a policy for it. The gap between those numbers is the real exposure, and it closes with a policy people can follow, not with a ban.

Supervision of the EU AI Act in Sweden runs through authorities you already know. Finansinspektionen supervises the financial sector, and the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) covers AI that processes personal data. The duties themselves have been arriving on a fixed calendar since 2 February 2025, so the practical question is not who asks but whether you can show what you run and how it is classified.

Your model risk and internal control framework is not enough on its own for the EU AI Act. It is the right starting point, but it gives no presumption of conformity: no harmonised standards under the AI Act have been published yet, and ISO/IEC 42001 is not a harmonised standard. While they are missing, compliance is demonstrated with your own documentation. We build it inside our AI governance work, so that it can follow the standards when they are published and holds up in a review by Finansinspektionen.

Know what you run. Before you're asked.

One conversation settles the two questions your supervisor will eventually ask: what AI you actually run, and which duties it carries. And if your existing stack genuinely covers you, that is the answer you will get.