With that step, the compliance burden shifts from artificial intelligence (AI) developers alone to banks, insurers, payments companies and other financial institutions deploying customer-facing AI systems. Enforcement will primarily fall to national authorities, with the European AI Office retaining oversight responsibilities for specified general-purpose AI systems. Under the Act, AI systems used to evaluate consumer creditworthiness or establish credit scores generally are classified as high-risk, per Eur-Lex, as are AI systems used in underwriting and pricing life and health insurance. Once those provisions become applicable, financial institutions deploying high-risk AI systems will face significantly broader governance obligations. The result is likely to make AI governance another core element of financial regulatory compliance rather than a standalone technology initiative.