Technology · Digital regulation
EU AI Act gives banks two years to fix foundations for agentic systems
The regulation entered force in August 2024 but phased compliance deadlines stretch to 2027. The real challenge is not the rulebook but whether legacy cores can support AI that acts, not just summarises.
Two years after the EU AI Act entered into force, the conversation inside European banking has shifted. The regulation is no longer a distant horizon; it is a fixed calendar. High-risk AI systems used for credit scoring, risk assessment and fraud detection must comply by August 2027. Yet the institutions furthest advanced in their preparations are not celebrating regulatory readiness. They are worrying about whether the technology underneath their compliance programmes can actually deliver what the Act demands: explainability, accountability and human oversight over systems that act autonomously.
The compliance calendar is not the constraint
The Act's phased implementation gives banks a preparation window that runs roughly to mid-2027 for most high-risk financial services use cases. That sounds like ample time. In practice, the deadline that matters is not the one printed in the Official Journal. It is the point at which a bank's core infrastructure can support the audit trails, real-time data access and orchestration layers that trustworthy AI requires. If that point arrives after the regulatory deadline, the institution faces a choice between non-compliance and switching off capabilities it has already sold to customers and supervisors.
The European Banking Authority has signalled that supervisory expectations will evolve alongside the technology. In its 2024 report on AI in financial services, the EBA noted that governance frameworks must address the full lifecycle of AI models, from development through deployment to decommissioning. The European Central Bank, which directly supervises the euro area's largest banks, has incorporated AI risk into its thematic reviews. Neither supervisor has published a final checklist. Both have made clear that the checklist, when it arrives, will not be static.
Governance is an architecture problem, not a paperwork exercise
Treating AI governance as a documentation exercise is tempting. It lets compliance teams produce model cards, risk assessments and oversight committees without touching the systems that actually move money. But the Act's requirements for traceability and human oversight become exponentially harder when AI moves from generating insights to executing actions. An agent that investigates a suspicious transaction, queries the customer master file, checks sanctions lists and initiates a hold does so across multiple systems in seconds. A surface-level log that records the decision and the model version will not satisfy a supervisor asking which data record was accessed at which millisecond, by which component, under whose authority.
This is where the architecture of most European banks breaks down. Core banking platforms built in the 1990s and 2000s were designed for batch processing, nightly reconciliations and human-initiated transactions. They expose data through fragile interfaces, if at all. They do not maintain immutable audit trails at the level of individual field reads. They cannot enforce fine-grained access controls on a per-agent basis. When an AI agent needs to orchestrate a workflow across the core, the payments engine, the CRM and the document management system, the integration layer becomes the bottleneck and the blind spot.
From generative summaries to agentic execution
Most current banking AI pilots sit in the generative category: summarising regulatory filings, drafting customer responses, coding assistance. These are valuable but they are also safe. The model outputs text; a human reviews it; the risk is contained. The next wave is agentic. Systems that plan multi-step tasks, call APIs, write to databases and trigger downstream processes. The ECB's Financial Stability Review has already flagged the potential for autonomous agents to amplify operational risk if guardrails fail. For that transition to happen safely, banks need four foundations that most do not yet possess: real-time access to structured data, API-first connectivity between systems, orchestration layers that enforce policy at runtime, and audit trails granular enough to reconstruct any agent decision after the fact.
Human oversight must be designed into the workflow, not bolted on as an approval queue. The Act requires that high-risk systems allow for human intervention. In an agentic context, that means the architecture must support checkpoints where a person can inspect the agent's reasoning, the data it relied on, and the action it proposes before execution. Legacy cores with synchronous, screen-scraped interfaces cannot provide that latency budget. The oversight either becomes a rubber stamp or a bottleneck that defeats the purpose of automation.
Legacy modernisation without the big bang
The instinct when faced with this gap is to launch a core replacement programme. European banking history is littered with multi-year, multi-billion-euro transformations that delivered late, over budget and with reduced functionality. The alternative is progressive modernisation: wrapping the existing core with an API layer, building a data fabric that exposes clean, versioned datasets, and deploying cloud-native orchestration and governance tools alongside the mainframe. This lets banks move use cases to the new layer one by one, proving value and de-risking the migration.
Digital-native banks such as N26, Bunq and Revolut built their stacks this way from day one. Traditional institutions cannot replicate that history, but they can adopt the same pattern. Specialist technology partners now provide the composable components, identity, ledger, compliance, orchestration, that would otherwise require internal engineering teams of a size few European banks can afford or retain. The pragmatic path is to buy the plumbing and build the differentiation.
The preparation window as a strategic asset
Regulation is usually framed as a drag on innovation. In this case, the two-year implementation delay creates a rare alignment. The work required to satisfy the Act, clean data, composable services, real-time connectivity, explainability, auditability, is exactly the work required to adopt whatever AI capability proves useful next year or the year after. Banks that treat the deadline as a finish line will build the minimum viable compliance layer and find themselves rebuilding when the first agentic use case lands. Banks that treat it as a foundation will be the ones able to say yes to the next capability without a two-year integration project.
Sources
Organisations
European Union · European Banking Authority · European Central Bank