AI Credit Scoring Rules Tighten in France as EU Deadline Shifts

France’s data protection authority has put AI credit scoring rules at the centre of its supervision of consumer lending, publishing a formal recommendation in May 2026 that tells banks, credit institutions and intermediaries how creditworthiness assessments must work when algorithms drive the decision. The move lands in an unusual regulatory moment: the EU AI Act classifies credit scoring as high-risk, but the obligations attached to that classification were postponed weeks before they were due to take effect, leaving data protection law carrying the weight for the next eighteen months.

The CNIL published its recommendation on assessing solvency in credit applications on 7 May 2026, after a public consultation the previous year and discussions with the banking members of its compliance club. It replaces AU-005, the single authorisation issued in 2008 that governed the area before the GDPR.

How France polices AI credit scoring rules today

The recommendation applies to private organisations that grant credit and to banking and payment services intermediaries. It covers consumer credit and mortgage credit governed by the French Consumer Code, and focuses on processing carried out to evaluate whether an applicant can repay.

Four themes run through the text. Data must be limited to what is relevant and strictly necessary. Past repayment incidents may be considered, but the recommendation specifies which data are relevant and strengthens what applicants must be told about how that history affects a new application. Retention periods are set for application data and records of past defaults. And the conditions under which a decision may rest on fully automated processing are spelled out, with safeguards of transparency, human intervention and explainability.

The final version also settled a legal basis question. Because the Consumer Code obliges lenders to assess solvency, institutions may ground the processing in legal obligation under Article 6 of the GDPR rather than relying on consent or legitimate interest.

The CNIL published an accompanying verification checklist for data protection officers and compliance teams, and said it will check compliance through its future inspection work. Credit scoring does not appear among its announced priority inspection themes for 2026, which are recruitment, the single electoral register and sports federations.

Automated loan application terminal, the kind of channel covered by AI credit scoring rules in Europe

The court rulings that reshaped automated lending decisions

The recommendation is built on two judgments of the Court of Justice of the European Union.

In Case C-634/21, decided in December 2023, the Court found that generating a probability value about a person’s ability to service a loan can itself constitute an automated individual decision within the meaning of Article 22 of the GDPR, where the recipient of that score draws on it in a determining way. The scoring entity, not only the lender acting on the score, is therefore in scope.

Case C-203/22, decided in February 2025, addressed what a data subject is entitled to know about the logic involved. The CNIL’s reading is precise and worth stating plainly: applicants have a right to an explanation after the decision, and the institution must make sure they understand their individual situation. That does not mean handing over a copy of the algorithm. It means a concise and comprehensible account of the mechanism that produced the outcome.

Why the AI Act’s documentation duties slipped to 2027

Annex III, point 5(b) of the EU AI Act classifies AI systems used to evaluate the creditworthiness of natural persons, or to establish their credit score, as high-risk. That classification carries a substantial package: risk management, data governance, technical documentation under Article 11, transparency towards deployers, human oversight, accuracy and robustness requirements, and registration in the EU database.

Those obligations were originally due from 2 August 2026. They no longer are. Regulation (EU) 2026/1744, the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, moving standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. The Article 50 transparency duties were not deferred and applied on schedule.

The practical effect for lenders is a sequencing problem rather than a reprieve. Technical documentation for a scoring model is not produced at the end; it depends on records of training data, validation results, performance monitoring and design choices captured while the model is built and run. Firms treating December 2027 as the start date will be reconstructing evidence retrospectively.

Meanwhile the GDPR obligations bind now, and they are not thin. Article 22, the transparency duties, data minimisation and the right to an explanation apply to automated scoring today, with or without the AI Act layered on top.

Who supervises what, and where the gaps are

France has not finished designating its AI Act authorities. A scheme published by the French directorates for enterprise and for competition, consumer affairs and fraud control proposes a decentralised model in which the DGCCRF serves as coordinating market surveillance authority and single point of contact under Article 70, with sectoral regulators including the CNIL and Arcom covering specific use cases. The proposal awaits adoption.

France is not unusual. Member states had to designate market surveillance and notifying authorities by 2 August 2025. As of mid-2026, on the Future of Life Institute’s tracker, nine had designated both, twelve had partial arrangements and six had designated neither.

Under the AI Omnibus, national authorities retain competence over AI systems used by financial institutions, so credit scoring supervision stays national.

What to watch over the coming months

Three dates shape the next phase. November 2026 brings the French legal authorisation for fully automated consumer credit decisions into application. December 2026 ends the AI Act’s marking grace period for generative systems already on the market. December 2027 is when the Annex III high-risk package, including Article 11 documentation, finally applies to credit scoring.

In between, the signal to watch is inspection activity. The CNIL has said it will verify compliance through its ordinary control work rather than a dedicated campaign, which means enforcement is more likely to surface through complaint-driven investigations and sanctions than through an announced sweep. Applicants refused credit by an automated process now have a clearly articulated right to an explanation, and complaints are the mechanism most likely to test it.

Lenders operating across borders face a further complication: the supervisory map differs by member state, so the same model may be examined by a data protection authority in one country and a market surveillance body in another. The same documentary discipline applies to anyone assembling financial evidence for regulated processes, a point covered in our guide to proof of funds requirements in the UK, Canada and Australia.

Questions readers are asking about automated lending

What did the CNIL publish on credit scoring in 2026?

On 7 May 2026 it published a recommendation on assessing creditworthiness in credit applications. It applies to private lenders and to banking and payment services intermediaries, covers consumer and mortgage credit under the French Consumer Code, and replaces the pre-GDPR authorisation known as AU-005.

Is credit scoring classified as high-risk under the EU AI Act?

Yes. Annex III, point 5(b) covers AI systems used to evaluate the creditworthiness of natural persons or establish their credit score. The obligations attached to that classification, including the Article 11 technical documentation duty, now apply from 2 December 2027.

What did the Court of Justice decide about automated credit decisions?

In Case C-634/21 the Court held that producing a probability score can itself amount to an automated decision under Article 22 of the GDPR where the score plays a determining role. Case C-203/22 addressed the right to an explanation of the logic involved.

Do applicants have a right to see the algorithm?

No. The CNIL is explicit that the right to an explanation does not mean handing over a copy of the algorithm. Institutions must give a concise, comprehensible explanation that lets the applicant understand their individual situation.

Which authority supervises AI systems in France?

France has not completed its designation. A published scheme proposes a decentralised model with the DGCCRF as coordinating market surveillance authority and single point of contact, and the CNIL and Arcom among sectoral authorities.

What changes for French lenders in November 2026?

The recommendation anticipates a legal authorisation, applying from November 2026, for fully automated decisions on consumer credit, together with the safeguards attached to it.

Related reading on European regulators acting against financial platforms is available in our coverage of the Noones shutdown and EU sanctions on user funds.

EU AI Act Transparency Rules Bite as High-Risk Deadline Slips

The EU AI Act transparency rules became enforceable across the European Union on 2 August 2026, requiring companies to tell people when they are dealing with a machine, to mark AI-generated audio, images, video and text in a machine-readable format, and to label deepfakes. The same date had long been billed as the moment the Act’s heavier obligations for high-risk systems would bite. That did not happen. A separate regulation adopted weeks earlier pushed those duties back by more than a year, leaving Europe with a narrower set of requirements that are nonetheless binding right now.

The distinction matters, because the two tracks are often described together and they have now separated. Disclosure duties apply today, to any provider or deployer within scope, regardless of how the underlying system is classified. The documentation, risk management and human oversight obligations attached to high-risk classification do not.

What the EU AI Act transparency rules actually require

Article 50 of the Act sets out three groups of duties, and none of them depend on a risk classification.

First, providers of AI systems designed to interact directly with people, such as chatbots and virtual assistants, must ensure that individuals are informed they are interacting with an AI system, unless that is obvious from the context to a reasonably well-informed person.

Second, providers of systems that generate synthetic audio, image, video or text must mark the outputs in a machine-readable format that allows them to be detected as artificially generated or manipulated. Deployers who produce or manipulate content that constitutes a deepfake of real persons, places or events must disclose that the content is artificial. A parallel duty applies to AI-generated or manipulated text published to inform the public on matters of public interest.

Third, deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them and process any personal data in line with EU data protection law. Narrow exceptions apply where such systems are permitted by law to detect, prevent or investigate criminal offences.

Breaches fall under Article 99(4), which provides for administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. Enforcement sits with national competent authorities rather than with Brussels.

Two supporting instruments arrived shortly before the deadline. The European Commission adopted final guidelines on transparency obligations on 20 July 2026. A voluntary Code of Practice on Transparency of AI-generated Content, published in June, was confirmed by the Commission and the AI Board as an adequate route to demonstrating compliance; the Commission has said roughly 190 organisations had signed it by the end of July. Signing creates no new legal duty and does not displace the obligation in the Regulation itself.

One narrow carve-out survives. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2). Everything else applied on the day.

Why the high-risk deadline moved to December 2027

The instrument responsible is Regulation (EU) 2026/1744, known as the AI Omnibus. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July, days before the deadline it amended.

The central change is timing. Obligations for standalone high-risk systems listed in Annex III, which cover recruitment, credit scoring, education, law enforcement, border control and critical infrastructure, now apply from 2 December 2027. High-risk AI embedded in products already regulated under Annex I product safety legislation, such as medical devices and lifts, applies from 2 August 2028.

The Omnibus made other adjustments. The AI literacy duty in Article 4 was softened, database registration was streamlined for systems assessed as not high-risk, and the post-market monitoring template became voluntary guidance. It also added a prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, carrying fines of up to 35 million euros or 7 percent of worldwide turnover from 2 December 2026.

Governance shifted too. The European AI Office, rather than national regulators, now holds direct supervisory authority over AI systems built on general-purpose AI models by the same provider, and over AI features embedded in very large online platforms designated under the Digital Services Act.

Chatbot conversation on a smartphone screen, the kind of system covered by the EU AI Act transparency rules

Who is actually enforcing the new duties

Enforcement depends on national authorities, and the map is incomplete. Member states were required under Article 70 to designate a market surveillance authority and a notifying authority by 2 August 2025. Many did not.

According to the AI Act implementation tracker maintained by the Future of Life Institute, updated in June 2026, nine member states had designated both authorities, twelve had pending legislative proposals or had appointed only one, and six had designated neither. Fundamental rights authorities under Article 77 are in better shape: all 27 member states have published those.

France illustrates the pattern. A published scheme proposes a decentralised model, with the DGCCRF acting as coordinating market surveillance authority and single point of contact and sectoral regulators handling specific use cases. It has not completed its passage. Germany’s federal cabinet adopted a draft AI market surveillance bill in February 2026 naming the Bundesnetzagentur, but that text still requires approval by both chambers.

The obligations therefore bind companies everywhere in the single market from 2 August 2026, while the machinery for policing them is uneven. The Regulation is directly applicable, and where authorities exist they can act, so early enforcement is likely to be concentrated in the jurisdictions that finished their preparations.

Companies running customer-facing assistants are among the most immediately exposed, since chatbot disclosure is the simplest duty to check and the easiest to fail. Our earlier reporting on AI customer support on WhatsApp and Instagram sets out how quickly those tools have spread through small businesses.

The road ahead for AI compliance in Europe

The next fixed date is 2 December 2026. The marking grace period for pre-existing generative systems ends, so legacy tools must carry machine-readable provenance signals, and the new prohibition on nudification tools and CSAM-generating systems begins to apply at the Act’s highest penalty level.

After that, 2 August 2027 is the deadline for member states to establish AI regulatory sandboxes. Commission guidance on post-market monitoring is due by 2 September 2027. The deferred Annex III high-risk obligations arrive on 2 December 2027, and the Annex I obligations on 2 August 2028.

For businesses outside Europe, the reach is the familiar one. The Act applies to providers placing systems on the EU market and to deployers established in the Union, wherever the developer sits. A chatbot built anywhere that serves European users falls within scope.

Common questions about the new obligations

Which EU AI Act obligations became enforceable on 2 August 2026?

The transparency duties in Article 50. Providers of AI systems that interact directly with people must make clear users are dealing with a machine unless it is obvious from context. Providers and deployers of systems generating synthetic audio, image, video or text must mark those outputs in a machine-readable format, and deployers must disclose deepfakes of real people, places or events.

Did the high-risk AI system rules take effect on the same date?

No. Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026 and moved the obligations for standalone high-risk systems listed in Annex III to 2 December 2027. High-risk AI embedded in products regulated under Annex I moves to 2 August 2028.

What are the penalties for breaching the transparency duties?

Article 99(4) sets administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. National competent authorities enforce them.

Is there a grace period for existing generative AI systems?

A narrow one. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation in Article 50(2). The other duties applied immediately.

Does signing the Code of Practice guarantee compliance?

No. The Code is voluntary and creates no new legal duties. The Commission and the AI Board have confirmed it is adequate for demonstrating compliance with Article 50, so following it is a recognised route, but the obligation sits in the Regulation itself.

For related coverage of how European regulators are applying digital and financial rules in practice, see our report on the Noones shutdown and the handling of user funds under EU sanctions.