The EU AI Act's high-risk system obligations took effect on August 2, 2026. Two days later, France's CNIL moved. According to the AI regulation tracking site Cubbbix, the French data protection authority issued formal information requests to 14 financial institutions operating credit scoring algorithms, demanding the Article 11 technical documentation package required for all high-risk AI deployments. Three of those institutions asked for time extensions. CNIL denied every request, citing the two-year window companies had to prepare since the Act passed in 2024.
Credit scoring AI was never going to get a soft start. It is one of the most consequential automated decision systems in European financial life -- used to approve or deny mortgages, consumer credit, and business loans for millions of people each year. It has been classified as high-risk since the AI Act was adopted. And CNIL, which spent May 2026 publishing a detailed credit scoring recommendation to prepare the market, apparently decided that the period for preparation was over.
TL;DR: France's CNIL issued documentation requests to 14 financial institutions on August 4, 2026, demanding Article 11 technical documentation for credit scoring AI. Three institutions asked for extensions. CNIL denied all three, citing the two-year preparation window. The enforcement action is the clearest early signal of how aggressive national competent authorities intend to be with high-risk AI systems -- and credit scoring is the use case they chose first.
Why credit scoring was targeted first
The EU AI Act's Annex III lists the categories of AI systems classified as high-risk. Point 5(b) is explicit: AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are high-risk, except for AI systems used for fraud detection.
That classification was not new in August 2026. It has been in the regulation since it was adopted. Financial institutions have had two years to read it, understand it, and prepare. CNIL chose credit scoring as its opening enforcement target for reasons that are fairly obvious in retrospect.
First, credit scoring AI is ubiquitous. Every significant French bank, insurance company offering consumer credit, and major lending platform uses some form of algorithmic credit assessment. The enforcement action reached 14 institutions at once, creating immediate market-wide pressure.
Second, CNIL had already done the groundwork. On May 7, 2026, the authority published a formal recommendation on the use of personal data in creditworthiness assessment. The recommendation was not vague guidance -- it set specific requirements: banks must collect only data strictly necessary for solvency assessment, rejected credit application files must not be retained in active databases for longer than six months, and any borrower who receives an automated credit refusal has the right to request human review of that decision.
The August enforcement action is not a surprise inspection. It is the next logical step after the May recommendation. CNIL told the market what it expected. Then it checked.
What Article 11 technical documentation requires
The documentation request is not a form to fill out. It is a compliance artifact that can run to several hundred pages for a production credit model.
Article 11 of the EU AI Act, read alongside Annex IV, specifies what the technical documentation must contain:
A general description of the AI system -- its intended purpose, the population it will be used on, and the decisions it is designed to support. For a credit scoring model, this means documenting the use cases where the model applies (mortgage origination, personal loan underwriting, revolving credit), the customer segments it covers, and any known limitations.
A detailed description of the system's elements and development process -- the training methodology, the training data, how the data was collected and processed, quality measures applied, and how protected characteristics were handled. This is where most institutions face the most exposure: old models trained on datasets assembled before GDPR and AI Act requirements were in place may lack the documentation trail the regulation requires.
Information about training data -- including the data sources, the distribution of the training set, the steps taken to ensure data quality, and how bias risks were assessed. Institutions using third-party credit bureau data will need to document the provenance of that data and their understanding of its characteristics.
Performance metrics and accuracy benchmarks -- the model's performance on key metrics across demographic groups. The EU AI Act requires that performance be assessed not just in aggregate but across the relevant demographic sub-populations who will be affected by the system.
Risk management system documentation -- the risk identification process, the mitigations in place, the residual risks that have been accepted, and the monitoring processes that will catch degradation in production. This must connect to an actual post-market monitoring system, not just a paper description of one.
The extension denial and what it signals
Three institutions requested time extensions before responding to CNIL's August 4 information requests. CNIL denied them.
The denial is not a technicality. It is an enforcement posture decision. Regulators use early enforcement actions to establish norms. If CNIL had granted extensions in week one of active enforcement, it would have signaled that the two-year preparation timeline was notional -- that institutions would continue to receive accommodation after the deadline passed. By denying extensions and citing the preparation window explicitly, CNIL is signaling the opposite: the deadline was real, and the regulator expects institutions to have done the work.
This will have downstream effects. French banks and lenders that receive documentation requests in Q3 and Q4 will not be able to point to the August institutions and say that extensions were standard. The expectation has been set.
It also means the institutions that were contacted need to produce documentation they may not have. Under the EU AI Act, a high-risk AI system cannot be deployed without the Article 11 documentation being in place before deployment. For models that have been in production for years, the documentation does not exist as a maintained artifact -- it has to be reconstructed. That reconstruction is expensive and time-consuming, and CNIL has just indicated it is not willing to give more time for it.
What is not covered by the national authority enforcement
CNIL's jurisdiction runs against deployers under Article 26 and against EU-established providers under Articles 11-17. Providers established outside the EU are primarily subject to enforcement by the European AI Office at the EU level, not by CNIL directly.
This matters for the structure of the enforcement landscape. A French bank deploying a credit scoring model from a US vendor has two distinct enforcement relationships: the bank is subject to CNIL as deployer (Article 26 obligations), and the US vendor's compliance with the provider obligations is primarily a matter for the AI Office and any authorized representative the vendor has appointed in the EU.
For banks that have purchased credit scoring systems from third-party vendors -- which is common in the French market -- the documentation obligations do not disappear because the vendor built the model. The deployer has to maintain documentation of the risk assessment, the human oversight measures, the logging and monitoring, and the transparency notices provided to credit applicants. None of that can be delegated entirely to the vendor.
Compliance checklist for credit scoring AI deployers
If your organization uses algorithmic credit assessment in any EU market, these are the immediate actions:
1. Confirm your Annex III classification. Credit scoring is classified at point 5(b). If your system assesses creditworthiness of natural persons, it is high-risk. This is not a judgment call -- it is a statutory classification.
2. Locate or reconstruct your Article 11 documentation. If you have a maintained technical documentation package for your credit model, pull it and assess whether it meets Annex IV's requirements. If you do not have a maintained package, start the reconstruction now. A request from CNIL could arrive at any time.
3. Audit your training data documentation. The Annex IV requirement for training data documentation is specific. You need to know where your training data came from, how it was preprocessed, what bias mitigation steps were taken, and what the distribution of the training set looked like. If any part of this is undocumented, that gap needs to be closed.
4. Review your human oversight implementation under Article 14. Credit scoring decisions that result in automatic refusal must have a human review path available on request. The CNIL May 2026 recommendation reinforced this. Document how the human review path works, who conducts it, and how requests are tracked.
5. Implement Article 12 logging if you have not already. High-risk systems must log the inputs and outputs necessary to enable post-market monitoring and to reconstruct decisions in the event of an incident or regulatory inquiry. Legacy credit systems often lack this logging. Retrofitting it into production is a non-trivial infrastructure project -- start it now.
6. Brief your third-party vendors. If your credit scoring model is supplied by a third party, send them a formal request for their Article 11 documentation. You need it to fulfill your deployer obligations. Put the request in writing and note the date -- that documentation is part of your due diligence record.
7. Map your post-market monitoring system. Article 72 requires deployers to report serious incidents to national authorities within 15 days. You need a defined incident classification process, a reporting pathway to CNIL, and someone with responsibility for making those reports.
What comes next
The 14 institutions contacted on August 4 are not the end of the process. They are the start of it. CNIL has the authority to inspect systems, request additional documentation, issue corrective orders, and impose fines. The outcomes of these initial requests -- whether institutions produce compliant documentation, partial documentation, or no documentation at all -- will shape the next phase of enforcement.
For the broader market, the signal is clear: credit scoring AI is being enforced now. The EU AI Act's high-risk regime is not a future compliance exercise. It is the current one. The institutions that have maintained Article 11 documentation packages for their production models will handle this period in a controlled way. Those that have not will spend Q3 and Q4 in an expensive reconstruction exercise under regulatory scrutiny.
CNIL's denial of extension requests suggests the regulator has decided that sympathy for late preparation is not part of its enforcement posture for this cycle. That posture is worth taking seriously.
Related Reading
- EU AI Act Annex III: High-Risk AI System Classification Explained
- EU AI Act Enforcement Starts August 2: What to Do This Week
- EU AI Act Annex IV Technical Documentation: Complete Guide
- National Competent Authorities and EU AI Act Enforcement
- Fintech AI Governance: CFPB, FCRA, and Fair Lending Compliance 2026
- CNIL and Agentic AI: GDPR Persistent Memory Compliance 2026
