The EU AI Act and Market-Surveillance Providers: A Practical Guide

The EU AI Act introduces new obligations for AI systems used in financial market monitoring. We examine the classification framework, transparency requirements, and what they mean for RegTech platforms.

By BlueLedger Legal ยท 15 min read

The EU AI Act and Financial Services

The European Union's Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024. It establishes a broad framework for artificial intelligence. Providers and deployers should consult the current text, guidance and qualified counsel rather than treating this educational summary as a compliance determination.

This article outlines questions that market-surveillance technology providers may need to consider. Application depends on the system, role, use case and current legal guidance.

Primary source: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Risk Classification Framework

The EU AI Act uses risk categories and obligations that depend on the system and use case. Confirm the current categories and dates in the official text.

Where Does Market Surveillance AI Fall?

AI systems used for financial market monitoring occupy an interesting position in the classification framework:

**Possible high-risk questions.** The Act contains high-risk use cases, while the classification of a particular market-surveillance workflow depends on its role and use. Do not infer a classification from a product label alone.

**Other obligations.** Systems that interact with people or generate content may have different transparency obligations. The actual obligation depends on the system and deployment context.

The distinction is significant because high-risk systems face substantially more demanding requirements, including conformity assessments, technical documentation, quality management systems, and post-market monitoring obligations.

Key Obligations for Market Surveillance Providers

Transparency Requirements (Article 13)

The Act includes transparency duties for relevant systems. The applicable duty should be checked against the current text:

- **Disclosure of AI use.** Users must be informed that they are interacting with an AI system. - **Explainability.** The system's outputs must be interpretable by the humans who rely on them. - **Limitations disclosure.** Known limitations, accuracy levels, and potential failure modes must be documented and communicated.

For a market-surveillance provider, a prudent review asks how a signal or score was generated, which sources informed it and what limitations are documented. This article is not a certification that any system satisfies those questions.

Data Governance (Article 10)

High-risk AI systems must meet strict data governance standards:

- Training data must be relevant, representative, and free from errors. - Data bias must be identified and mitigated. - Data provenance and lineage must be documented.

For surveillance systems trained on historical market data, this requires documenting the sources, time periods, and market conditions represented in training datasets - as well as any known gaps or biases.

Human Oversight (Article 14)

High-risk systems must be designed to allow effective human oversight. This includes:

- The ability for human operators to understand the system's capabilities and limitations. - The ability to override or reverse the system's outputs. - The ability to intervene promptly when necessary, where the system and use case require it.

This principle is consistent with an evidence-led design direction: outputs should remain inputs to human review, not autonomous conclusions. Any confidence scores, evidence chains or methodology documentation must be verified for the specific release before being relied upon.

Human oversight is a design consideration, not proof that a system satisfies a legal obligation or reduces regulatory risk.

Conformity Assessment (Article 43)

High-risk systems must undergo conformity assessment before being placed on the market. This may involve:

- Self-assessment against harmonized standards (once published). - Third-party assessment by a notified body for certain categories. - Technical documentation including system architecture, training methodology, and performance metrics.

Practical Steps for Compliance

For RegTech and market surveillance providers, we recommend the following approach:

**1. Classify your system.** Engage qualified counsel to assess the current classification and obligations. The boundary is use-case-specific and guidance can change.

**2. Document the basis.** Maintain the architecture, training data, performance measures and limitations needed for the applicable obligations and review process.

**3. Build explainability into the architecture.** Retroactive explainability is difficult and often incomplete. Design your system from the ground up to produce interpretable outputs with clear methodology attribution.

**4. Implement human oversight by design.** Ensure that a system's outputs are presented as inputs to human decision-making, not as autonomous conclusions. This can support governance, but it does not by itself establish regulatory compliance or eliminate risk.

Human oversight is a design consideration, not proof that a system satisfies a legal obligation or reduces regulatory risk.

**5. Monitor regulatory developments.** The EU AI Act is a framework regulation that will be supplemented by delegated acts, harmonized standards, and guidance from the AI Office. Stay current with these developments as they emerge.

Timeline

The Act includes phased dates. Verify each milestone against the official text and current guidance:

| Date | Milestone | |------|-----------| | February 2, 2025 | Prohibitions on unacceptable-risk AI systems take effect | | August 2, 2025 | Obligations for general-purpose AI models take effect | | August 2, 2026 | Full application of high-risk AI system requirements | | August 2, 2027 | Extended deadline for certain high-risk systems embedded in existing regulated products |

BlueLedger's Approach

For a provider, a responsible product direction may include:

- **Explainability-oriented outputs** with source references, limitation disclosures and a clear review boundary. - **Methodology documentation** for each detection method and signal type that is actually deployed. - **Human review** so outputs inform decisions rather than trigger autonomous conclusions. - **Audit records** that document data sources, processing steps and output provenance where implemented.

The design practices above can support responsible review, but they do not establish compliance for BlueLedger or another provider.

*This article is for informational purposes only and does not constitute legal advice. Organizations should consult qualified legal counsel regarding their specific compliance obligations under the EU AI Act.*