Signal 01
What the guidance covers
The latest guidance clarifies how the EU AI Act's risk tiers apply to common finance-team AI uses. Most of what finance teams use AI for today — research synthesis, drafting, variance analysis, document summarisation — continues to sit in a lower-risk category than automated decisions that directly affect a customer, like credit scoring or automated eligibility determinations.
That distinction matters for scope, not for care: lower-risk classification reduces the formal compliance burden, but it doesn't change the practical need to review AI-generated output before it informs a real decision.
Signal 02
What's changed in practice
The clearest practical shift is on documentation. Guidance increasingly expects teams to be able to show, if asked, what a given AI-assisted output was used for and that a human reviewed it before it was acted on — even for lower-risk uses. That's a process and record-keeping change more than a technology change.
Teams building AI into a recurring workflow — a monthly reporting cycle, a research process — are the ones most likely to need to formalise this, since ad hoc, one-off use is easier to justify after the fact than a process running every month.
Signal 03
What finance and compliance teams should check
Two practical steps: first, map which AI-assisted processes are recurring versus one-off, since recurring processes are the ones worth documenting properly. Second, confirm that a human review step is actually built into each recurring process, not just assumed — this is the single most common gap we see.
This is a summary of publicly available guidance, not legal advice — teams should confirm applicability with qualified counsel for their specific jurisdiction and use case.