The EU AI Act and the Future of Financial Services in Cyprus: What CySEC-Regulated Firms Should Prepare For

The European Union’s (the “EU”) Artificial Intelligence Act (the “AI Act”) is the world’s first comprehensive AI law, establishing a harmonised framework for the development, deployment and use of artificial intelligence across the EU.

The AI Act adopts a risk-based approach, categorising AI systems according to the potential risks they pose to individuals, markets and fundamental rights. Certain practices are prohibited outright, while others are classified as “high-risk” and become subject to extensive governance, documentation, oversight and monitoring requirements creating a regulatory shift beyond technology.

While the AI Act’s general application date is 2 August 2026, the application of the principal obligations in Chapter III, Sections 1–3 has been deferred for certain high-risk AI systems: those classified as high-risk under Article 6(2) and Annex III will generally be subject to these obligations from 2 December 2027, while Article 6(1) and Annex I high-risk systems are subject to a later date of 2 August 2028.

Nevertheless, the AI Act does not operate in isolation. It sits alongside, and interacts with, an already dense cross-sectoral regulatory framework, including DORA, MiFID II, GDPR, CRR/CRD and PSD2/PSD3. As a result, firms should increasingly view AI not merely as a technological tool, but as a regulatory compliance matter requiring governance, oversight and risk management.

Among the Annex III high-risk use cases, the following may be particularly relevant to financial institutions:

  1. Creditworthiness Assessment: AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, except those AI systems used for detecting financial fraud
  2. Insurance Premium and Coverage: AI systems intended for risk assessment and pricing in relation to life and health insurance for natural persons;
  3. Biometric Identification: AI systems used for remote biometric identification, excluding those systems used for the verification that a specific natural person is who they claim to be, and systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics, as well as systems used for emotion recognition;

AML/KYC systems are not, as such, expressly identified as high-risk AI systems under Annex III. Their classification should therefore be assessed on a case-by-case basis, taking into account the system’s specific functionality, intended purpose and manner of deployment, including whether it falls within another AI Act category or is subject to other applicable provisions of the AI Act.

Depending on whether an institution is a provider (develops or commissions AI systems) or a deployer of AI systems, obligations will differ substantially. Most regulated entities (i.e. CIFs, AIFMs, EMIs, CASPs, etc.) will primarily sit on the deployer side, relying on third-party tools. However, the provider/deployer analysis must be performed on a system-by-system basis, particularly where a firm puts its name or trademark on a high-risk AI system, substantially modifies it, or changes its intended purpose.

A Sector Under Multiple Pressures

Cyprus hosts a large concentration of investment firms and fintech firms, many already using AI across onboarding, customer support, profiling, monitoring, trading, and internal processes. CySEC has already begun gathering information on AI adoption among regulated entities. In Circular C709 of 3 June 2025, CySEC distributed an ESMA survey assessing AI adoption in the securities sector, including firms’ AI strategies and policies, investment levels and specific use cases, with particular reference to issues such as materiality, security and explainability.

In practice, regulatory exposure may arise not only from sophisticated in-house AI programmes but also from the cumulative use of multiple third-party AI-enabled tools, including customer-service and onboarding applications, where firms may not have centralised visibility over their functionality, data flows or regulatory classification.

Depending on the use case, a single AI-driven onboarding or client assessment tool may trigger the AI Act’s high-risk obligations, MiFID II conduct requirements, GDPR’s rules on automated decision-making, and DORA’s oversight of the supplying vendor, all for one system rather than five separate projects. This raises several interrelated practical compliance implications for organisations, which will require centralised governance oversight to remain compliant across each sector.

As financial institutions prepare for the full application of the AI Act, the following key considerations should be taken into account:

  • Inventory all AI systems and assess their classification and applicable obligations under the AI Act, prioritising use cases involving creditworthiness, insurance, biometric technologies and other systems that may materially affect individuals;
  • Confirm provider or deployer status for each system, as this will affect their obligations under the AI Act;
  • Align AI Act governance with existing DORA, ICT risk-management, outsourcing and third-party risk-management frameworks, where relevant, to avoid fragmented controls and unnecessary duplication;
  • Review AI vendor contracts to ensure these provide documentation conformity, instructions for use, logging access, incident notification commitments, updated obligations and audit rights;
  • Ensure qualified human oversight is in place for high-risk use cases, with qualified staff given the authority, tools, and time to genuinely review AI outputs before any consequential decision is made;
  • Assess whether registration in the EU database is required, including in the case of providers of relevant high-risk AI systems and, where applicable, deployers falling within the categories specified by the AI Act.

To conclude, the EU AI Act is not simply a technology regulation. For European financial supervision, it signals a broader evolution towards continuous oversight, increased accountability and data-centric governance. It is organisational readiness. Firms must understand where AI is used, establish governance frameworks, strengthen oversight mechanisms and align AI deployment with existing cross-sectoral regulations and resulting obligations. For CySEC-regulated firms, the challenge will be identifying, governing and evidencing control over the growing number of AI-enabled systems embedded within day-to-day operations.

Author:

Anna Kyriacou

Licensing Consultant

AMF Global Ltd

 

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Readers are advised to seek professional legal advice in relation to their particular circumstances.