What the EU AI Act really requires of financial service institutions, and what to do now

AI is now woven into nearly every part of how financial institutions operate. It supports fraud detection, shapes credit decisions, powers customer experience, guides collections, and helps associates work more efficiently. For many organisations, this has happened faster than AI governance frameworks have evolved.
That is exactly the gap the EU AI Act is designed to close. The Act is the world's first comprehensive legal framework for AI, and it asks organisations to do something deceptively simple: know where AI is operating, understand the risk it carries, and be able to show that it is being managed responsibly.
The Act applies a risk-based framework. So, what an organisation should do depends on the AI use case, its role as a provider / deployer and whether the system is prohibited, high-risk, subject to transparency requirements, or outside of those categories.
Not every AI system is treated in the same way. Certain uses may fall within the Act’s high-risk categories, while other uses may be subject to transparency requirements instead. Therefore, classification should be performed by use case, not by technology or sector alone.
In this article, we’ll take a practical look at where the AI blind spots tend to hide within banks and financial institutions, how to bring unseen AI into view, what meaningful human oversight really requires, and where to start if your organisation is still building that picture.
Where the AI blind spots hide
The biggest blind spots are rarely the obvious AI applications. Most leadership teams know about their chatbot or the generative AI tool associates are testing. What they may not see is the AI that has gradually become part of the wider technology estate.
This "hidden AI," may be AI functionality the organisation didn’t procure as a standalone initiative, and it may have been introduced through a platform update. That can leave an organisation without a clear owner, or a consolidated view of how the technology affects customers and associates. Third -party provision doesn’t remove the need for an organistaion to determine its own roles and responsibilities.
AI has scaled faster than most governance frameworks were built to track, but once you can see where AI is operating, everything else becomes more manageable.
From "where did we put AI?" to "where is AI influencing an outcome?"
My advice is to start with visibility, not blanket restriction. There is rarely a need to pause every system that may contain AI, unless there are suspected prohibited practices, or it is creating material customer or employee harm, as these should be escalated immediately and where appropriate, suspended pending a review.
To pause every system would be disruptive and, in most cases, unnecessary. A more productive approach is to examine your business processes and customer journeys and look for the points at which technology generates content, makes predictions, classifies information, recommends an action, or influences a decision.
I often encourage leaders to stop asking, "Where did we put AI?" and start asking, "Where is AI influencing an outcome?" That change in language shifts the focus from products and vendors to the effect the technology has on the business and the people it serves.
The longer-term goal is a living AI inventory connected to procurement, technology governance and change management, so you identify new AI capabilities as you introduce them, not discover them months later. TTEC Digital’s six-point checklist is designed to support this process.
What meaningful human oversight really looks like
For a system where AI is classed “high risk,” the Act requires effective, meaningful, human oversight that is appropriate to the risk, and context of use. Where AI is classed as “low-risk,” existing financial, data privacy or internal company rules may still require similar guardrails.
A policy document or an annual approval meeting is a helpful starting point, but oversight truly comes alive when it is built into day-to-day operations through monitoring, clear escalation routes, regular performance reviews, and named accountability.
Consider an AI agent that identifies potentially fraudulent activity, prioritises collections cases, or recommends a course of action. It is worth asking whether your organisation can confidently explain:
- Who reviews unusual or disputed outcomes?
- What information does that person have?
- Is there sufficient time, information, competence, and authority to intervene?
- Can an associate genuinely change the outcome?
- Can the reviewer disregard, reverse, or escalate an output?
- Can the operation be safely stopped when necessary?
- How are errors or unexpected patterns investigated? Are overrides and exceptions recorded and reviewed?
The aim is to make sure associates feel genuinely empowered to challenge a recommendation, not just able to see it.
The first practical step: own the inventory
A recent TTEC Digital research report, “The great CX reset,” reinforced what we see in client work: many leaders still cannot see where AI is operating across their customer experience.
That is a common starting point, and it is one you can change.
The first step is to appoint a senior executive to own the AI inventory, supported by a cross-functional team spanning technology, risk, legal, procurement, operations, data and customer experience. Rather than mapping everything at once, it often helps to begin with the customer and associate journeys where AI is most likely to influence people, experiences, or important decisions.
At TTEC Digital, we can help clients map journeys, review the supporting technology estate and identify where AI generates content, makes predictions, recommends actions or influences outcomes. Once that visibility is in place, leaders can strengthen oversight, identify value, and adopt AI more confidently and responsibly.
Watch the webinar: The EU AI Act is coming for CX. Are you ready?
TTEC Digital's Georgi Georgiev, Amanda Panks, and Wayne Kay discussion the biggest compliance questions facing CX teams, where organisations are most exposed, and the steps you can take now to strengthen AI governance before enforcement intensifies.

Amanda specialises in delivering complex customer experience (CX) and digital transformation projects, as well as consulting high-profile clients on challenging issues within contact centre environments.