The European Union's AI Act, approved in July 2024 and fully implemented through 2025, classifies AI systems into four risk levels. In banking, several interactions fall under high risk: they require risk management, data governance, human oversight, and audits. It will set the reference for LATAM and the US.
Introduction and opportunities of artificial intelligence Inevitably, like every other industry, banking is not immune to the accelerated adoption of generative artificial intelligence over the past few years. This technology brings major promises of opportunities to capture, one of them being its potential applications in customer service, where three main points stand out: Cost efficiency and scalability Innovation and acceleration of digital transformation processes Improved service levels, customer retention, and transactions Artificial intelligence as a tool and methodology as the differentiator Over time, the solutions offering these services have evolved, adopting different ways of working and achieving greater or lesser success when facing different scenarios. For example, the Delto approach with its “Skill Growth Strategy” methodology starts from the premise of achieving limiting control over what generative AI can (and cannot) resolve, building up from less to more, and it shines when facing complex cases or sensitive information. Likewise, there are other solutions that start from a base of fewer restrictions, better suited for cases where more freedom can be given (or is even a requirement) so that the AI can interact, create, or make mistakes without major consequences. Therefore, as we can deduce, different industries have different complexities, different margins of error, and different consequences, which must be addressed differently even when using the same tool. Regulation of artificial intelligence is catching up Recapping the previous paragraphs: first, we found a tool that opened up a world of possibilities; second, we understood that this tool must be carefully adapted depending on the characteristics of the problem to solve. Third, adapting in turn to this technological disruption, regulation and laws arrive to set the guidelines and requirements for the coming years in the use of these kinds of solutions. Today, the global reference—or at least for the Western world—on government regulation is the AI Act drafted by the European Commission of the European Union, which was approved in July 2024 and will be 100% implemented throughout 2025. While the United States also has a 2023 statement with recommendations and an executive order issued by the White House , these are far more limited and primitive than the one drafted by the European Union. In short, the AI Act will likely be, in the coming years, the source of inspiration and reference for regulations across every country in Latin America and the United States. As a summary, the AI Act takes a risk-based approach to regulating systems with AI components, based on the risk that interacting with them poses to the end user. This classification consists of the following levels: Unacceptable risk High risk Low risk Minimal risk The criteria for classifying the scale are detailed in the document and we will not go deeper into them in this note; we will leave additional resources further on. What matters for this article is understanding that, beyond the risk classification, this entails a great deal of work surrounding the system, which obviously grows in complexity as the risk increases. This is important because of the nature of the information and interactions that are part of banking activity, some of which may be considered potentially high risk. It is key to understand that the high-risk classification is not meant to limit the use of AI systems for whatever one wants to do (that is what the unacceptable category is for); rather, the system must be surrounded by certain requirements, standards, and protocols that properly support it in order to operate while minimizing the potential risk. As a reference, in the AI Act, at the regulatory level for high-risk cases, the following stand out as requirements: Establish a risk management and failure-mitigation system Carry out data governance, ensuring that training, validation, and testing datasets are relevant, sufficiently representative, and, as far as possible, free of errors and complete in line with the intended purpose. Produce technical documentation to demonstrate proper functioning and provide authorities with the information needed to assess the system. Design the system so that it logs user activity and can trace interactions when necessary. Provide instructions for use to those in charge of deployment to enable compliance on their part. Design the system so that people can carry out oversight activities and execute mitigation protocols. Design and test the system to reach adequate levels of accuracy, robustness, and cybersecurity. Establish a quality management system to ensure all of the above is met. In the case of the European Union, all of this is audited by the authorities to verify that it is in fact being met. Conclusion: how could this impact the banking industry going forward? As with everything related to regulations and laws, these movements across different countries are slow, but we can certainly expect that it is only a matter of time before similar legislation is applied in LATAM and the US. Given the nature of the banking industry, it would be prudent to start adapting the solutions being implemented to meet these requirements—especially since they are also practices that bring us closer to delivering a better solution for end customers and taking greater care of the experience. On our side, at Delto we are combining all these requirements with our working methodology to meet this type of requirement from the outset, aiming to deliver the best possible service and also to get ahead of these regulations. This way, beyond ensuring we have a robust solution, we save ourselves the possibility of having to replace, retire, or rebuild a solution from scratch due to a regulatory update on the horizon. We strongly recommend analyzing this aspect in detail when choosing to embark on a project to incorporate generative artificial intelligence for customer service. These are questions that, if we ask them today, will likely save us a lot of pain and money in the near future. If you would like to learn about Delto and our solution, you can book a meeting with us by clicking here
What is the AI Act and why does it matter for banks? It is the European Union's AI regulation, approved in July 2024 and fully implemented throughout 2025. It classifies systems by the risk they pose to the end user. It matters because several banking interactions can fall into the high-risk category, and because it will be the reference for future regulation in LATAM and the United States.
What does the AI Act require from a high-risk AI system? Eight requirements: a risk management and failure-mitigation system, data governance, technical documentation, user activity logging, instructions for use, human oversight, adequate levels of accuracy and cybersecurity, and a quality management system. In the EU, authorities audit it.
How should banks in LATAM prepare before regulation arrives? By adapting AI solutions today to meet these requirements from the start. Doing so avoids having to replace or rebuild the system when a regulatory update lands, and it improves the customer experience. At Delto we combine these requirements with our Skill Growth Strategy methodology to stay ahead.