08/31/2026, 11.47

EU AI Act: Brussels Tightens Grip on Banking and Global Tech

The European Commission moves to regulate high-risk AI in banking via BBVA and launches a global supervisory team to monitor OpenAI and DeepSeek.
Key points
  • The European Commission held its first official meeting with a bank, BBVA, to define high-risk AI classifications.
  • A new specialized supervisory team has been launched to monitor global AI firms, including OpenAI and DeepSeek.
  • Requirements for high-risk AI applications may be delayed until late 2027 to allow for industry adjustment.
  • The EU is pursuing technological sovereignty to compete with US and Chinese AI dominance.

The European Union is transitioning from the theoretical drafting of the AI Act to a phase of aggressive enforcement and sector-specific calibration. In a series of strategic moves, Brussels has begun targeting the financial sector for precise regulatory definitions while simultaneously deploying a global watchdog to monitor the world's most powerful AI laboratories. This dual approach signals that the EU is no longer just setting a general framework but is now drilling down into how artificial intelligence fundamentally alters high-stakes industries like banking.

The BBVA precedent and banking AI

In a landmark move for the financial sector, the European Commission recently held its first official meeting with a commercial bank to discuss the practical application of the AI Act. The encounter took place in June with representatives from BBVA at the headquarters of the department responsible for digital policy. This meeting, conducted with Thierry Boulangé, the acting head of unit for the Directorate-General for Communications Networks, Content and Technology, marks a shift toward industry-led regulatory refinement.

The discussions focused on two critical pillars: establishing a consistent definition of AI systems across all EU member states and drafting guidelines for what constitutes a high-risk classification. For banks, the distinction between a standard automation tool and a high-risk AI system is not merely academic; it determines the level of transparency, documentation, and human oversight required by law. While the Commission had previously met with the Association of German Banks in January, the BBVA session represents a more direct engagement with a specific institutional player to test the friction between banking operations and legislative requirements.

Supervising the global AI giants

While the EU works on sector-specific nuances, it is simultaneously casting a wide net over the global tech landscape. As of August 2026, the European Union has activated a specialized supervisory team designed to monitor AI companies worldwide. This team is specifically tasked with overseeing entities such as OpenAI and DeepSeek, ensuring that their models do not violate EU standards regarding generated content, security risks, or fundamental rights.

This supervisory mechanism is a core component of the EU's broader strategy for technological sovereignty. By creating a dedicated team to detect non-compliance, Brussels aims to reduce the risks associated with the rapid deployment of generative AI while attempting to foster a domestic industry capable of competing with the hegemony of the United States and China. The focus is not on immediate guilt—as no company has been declared culpable yet—but on establishing a permanent state of surveillance to prevent systemic failures or rights violations.

A strategic delay for high-risk systems

Despite the push for stricter oversight, the European Commission has recognized that the industry may not be ready for the full weight of the AI Act. Henna Virkkunen, the Executive Vice President for Technological Sovereignty, Security, and Democracy, has proposed a significant extension for certain requirements. Specifically, the mandates governing the use of high-risk AI technology may not be fully implemented until the end of 2027.

This delay suggests a pragmatic realization within the Commission: the gap between legislative ambition and technical feasibility is wide. By pushing back the deadlines, the EU is granting firms more time to align their internal governance with the complex requirements of the Act. Furthermore, the Executive has shown a willingness to be more flexible regarding the use of data for training AI models, acknowledging that overly restrictive data laws could stifle the very innovation the EU hopes to cultivate to remain competitive.

Defining the legal boundaries of risk

The current friction in Brussels centers on the definition of legal concepts that could disrupt the operational flow of the private sector. The meetings with financial institutions are intended to prevent a fragmented application of the law, where a system deemed high-risk in Spain might be viewed differently in Germany or France. This consistency is vital for any multinational corporation operating within the Single Market.

The focus on high-risk classification is particularly sensitive because it triggers the most stringent obligations of the AI Act. For a bank, an AI system used for credit scoring or risk assessment could easily fall into this category, requiring rigorous auditing and a level of explainability that current black-box models often struggle to provide. The collaboration between the Commission and banks is an attempt to find a middle ground where safety does not kill efficiency.

The creation of a specialized team to monitor global firms like OpenAI and DeepSeek marks the transition of the AI Act from a regional guideline to a global regulatory benchmark.

The pursuit of technological sovereignty

The overarching goal of these maneuvers is the reduction of dependency on non-EU technology. By regulating the giants of the US and China, the EU is creating a protected environment where European firms can develop AI that is compliant by design. This strategy is not just about safety; it is an economic play. The EU wants to ensure that the next generation of AI tools is built on European values of privacy and transparency, potentially turning regulatory compliance into a competitive advantage for local firms.

The integration of these policies is visible in how the Commission is balancing the banking discussions with the broader enforcement actions against global tech labs. It is a two-pronged approach: refining the rules for the domestic industry while policing the imports from the global market.

Global implications for US and UK enterprises

For entrepreneurs and executives in the USA and UK, the EU's current trajectory serves as a critical warning and a roadmap. While the US currently maintains a more fragmented, sector-specific approach to AI regulation and the UK has leaned toward a pro-innovation, non-statutory framework, the EU's AI Act is effectively becoming a global standard due to the Brussels Effect.

Any US or UK company providing AI services to the European market must now prepare for a regime of active supervision. The launch of the specialized team to monitor OpenAI and DeepSeek proves that the EU will not hesitate to scrutinize foreign firms. For global businesses, this means that internal AI governance must be designed to meet the highest common denominator—the EU standard—to avoid the risk of sanctions or market exclusion. The potential delay of high-risk requirements until 2027 provides a window of opportunity for international firms to audit their systems and adjust their data training pipelines before the full weight of the law descends.

FAQ

Q: Which bank was the first to officially meet with the EU regarding AI? A: BBVA was the first bank to hold an official meeting with the European Commission to discuss the AI Act's application in the banking sector. Q: Which global AI companies are being monitored by the new EU team? A: The new supervisory team is specifically tasked with monitoring global firms, including OpenAI and DeepSeek. Q: When will the requirements for high-risk AI systems be fully implemented? A: The European Commission has proposed delaying these specific requirements until the end of 2027. Q: What is the primary goal of the EU's new AI supervisory team? A: The team aims to detect non-compliance regarding AI-generated content, security risks, and threats to fundamental rights.

Sources: Economiadigital, Expansion, Elimparcial ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Printable version
CLOSE X
See also
Visa Launches Autonomous AI Security Harness for Auto-Patching Code
Visa releases the Visa Vulnerability Agentic Harness (VVAH), an open-source AI system that finds and patches production code vulnerabilities without h…
02/09/2026 17:48
OpenAI Pauses Astra: The First AI to Hit Critical Cyber Risk
OpenAI suspends Astra development after the model potentially reached the Critical cybersecurity threshold, capable of autonomous zero-day exploit cre…
01/09/2026 11:13
AI Judges: LM Studio Bionic and the Shift in Model Evaluation
LM Studio Bionic introduces a layered judge system for shell commands, highlighting the broader industry shift toward LLM-as-a-judge for AI safety.
31/08/2026 18:26
Microsoft Edge Vulnerability and the Rise of Bug Bounty Intelligence
A critical flaw in Microsoft Edge highlights the danger of NTFS directory junctions. Explore how bug bounty write-ups are reshaping corporate security…
31/08/2026 17:45
OpenAI's Mac Fleet: A Strategic Shift Toward AI Agents
OpenAI has reportedly acquired tens of thousands of Mac minis and Mac Studios to train AI agents using reinforcement learning and Apple silicon's unif…
31/08/2026 15:07


In evidenza
Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now

ISCRIVITI A GLACOM.NEWS

I dossier su AI, tech e business che contano, nella tua email. Gratis.