Europe's automated loan decision is getting a human-review route before the AI rulebook
A consumer-credit right starts on 20 November 2026, while high-risk AI credit-scoring duties are scheduled for December 2027. They overlap, but they are not the same rule.

A loan refusal can arrive in seconds. A screen says no, the process ends and the applicant may never see whether a human considered the file. In the European Union, that black-box moment is about to acquire a second route.
From 20 November 2026, national measures implementing the EU's revised Consumer Credit Directive must apply. When a covered creditworthiness assessment uses automated processing of personal data, the consumer must be able to request human intervention from the creditor.
That phrase is more specific than a general right to speak to customer service. Article 18 sets out three parts. The consumer can request a clear and comprehensible explanation of the assessment, including the logic and risks in the automated processing and its significance and effects on the decision. The consumer can express their own point of view. They can also request a review of both the creditworthiness assessment and the decision on granting credit.
None of that creates a right to borrow. A human review can uphold a refusal. The directive does not say that a lender must reveal source code, ignore affordability or approve a borderline application. It creates a route for explanation and reconsideration where an automated assessment has helped decide whether the obligations are likely to be repaid.
The wording matters because the directive does not reserve this protection for systems marketed as artificial intelligence. It applies when the creditworthiness assessment involves automated processing of personal data. A conventional scoring model or rules engine can therefore matter even if nobody puts an AI label on it.
The assessment itself is also constrained. The directive says creditors should use relevant and accurate information about income, expenses and other financial and economic circumstances, proportionate to the nature, duration, value and risk of the credit. It excludes special-category personal data from that assessment and says social networks must not be treated as an external information source.
Credit history can be part of the picture, but Article 18 says the assessment must not rest exclusively on it. If a database leads to rejection, Article 19 adds a free notice about the result, the database consulted and the categories of data considered.
A rejected application has its own notice rule. The creditor must inform the consumer without delay. Where relevant, it must say that the assessment was based on automated processing, explain the right to human assessment and describe the procedure for contesting the decision. The practical object to look for is therefore not a generic promise of responsible AI, but a named route back into the lender's decision process.
The revised directive has a broader scope than the framework it replaces. The European Commission highlights credit below the former EUR 200 floor and deferred-payment schemes commonly abbreviated as BNPL. That makes the human-review provision relevant beyond a traditional unsecured bank loan.
There are boundaries. The directive generally excludes credit secured by a mortgage, credit used to acquire land or a building and agreements above EUR 100,000. Certain interest-free deferred payments supplied directly by a retailer or service provider can also sit outside the scope when the detailed conditions are met. National law supplies the working implementation, regulator and complaint route, so a product label alone cannot settle whether a particular agreement is covered.
This is why the November date should not be flattened into "all loan algorithms become appealable". The protection attaches to covered consumer credit, automated personal-data processing and the national measures that implement the directive. It is broad enough to matter, but not universal.
The current wave of AI Act announcements can make the timetable look simpler than it is. On 2 August 2026, new AI transparency rules began to apply and the European Commission's AI Office and national authorities gained enforcement powers for provisions already in force. Those changes include disclosure around chatbots and synthetic content. They do not mean every high-risk AI duty began on that day.
The AI Act lists systems used to evaluate a person's creditworthiness or establish a credit score as high-risk, except systems used to detect financial fraud. The Commission's current enforcement timetable says the rules for Annex III high-risk systems apply from 2 December 2027.
The two regimes therefore meet at automated lending, but from different directions. The Consumer Credit Directive governs the creditor-consumer relationship and creates an explanation, response and review route from November 2026. The AI Act imposes system-level duties on providers and deployers of qualifying high-risk AI, on its own later timetable. An automated credit process can engage the first rule without necessarily being an AI system. A credit-scoring AI can eventually engage both.
That distinction is the useful part of the calendar. "AI rules are here" is too broad, while "AI credit rules are delayed" misses the nearer consumer-credit right. For a person facing an automated refusal, the first concrete change is not a label on the model. It is the ability to ask what shaped the assessment, put their account of the facts into the process and have the decision reviewed by the creditor.
A second route is not a guaranteed exit. It is still a meaningful change to a screen that once looked final.
Editorial note. This article is for general information only and is not personal financial, credit, lending, data-protection, regulatory or legal advice. Sona News does not know any reader's finances, application, agreement, country, eligibility or legal position. Coverage, procedures, regulators and remedies depend on the product and the national law implementing EU rules. Check current official information in the relevant country and seek appropriately authorised professional guidance where needed before acting on an individual case.
Sources
- EUR-Lex: Directive (EU) 2023/2225 on credit agreements for consumers. Extracted 10 August 2026. Verified Article 2 scope and exclusions; Article 18's creditworthiness inputs, automated-processing explanation, viewpoint and review rights, rejection notice and credit-history limit; Article 19 database notice; Article 48 application from 20 November 2026
- EUR-Lex: Consumer credit agreements (2023). Extracted 10 August 2026. Verified the plain-language scope summary, exclusions, creditworthiness duties, national implementation deadline and 20 November 2026 application date
- European Commission: Consumer Credit. Extracted 10 August 2026. Verified that the revised directive extends to credit below the former EUR 200 threshold and buy now, pay later schemes, alongside standard information and sustainable-repayment checks
- European Commission: Consumer Protection in Financial Services. Extracted 10 August 2026. Verified the November 2026 application date and the Commission's summary of automated creditworthiness human-intervention rights
- EUR-Lex: Regulation (EU) 2024/1689, AI Act, Annex III 5(b). Extracted 10 August 2026. Verified the high-risk listing for AI used to evaluate natural persons' creditworthiness or establish a credit score, with the financial-fraud exception
- European Commission: The enforcement framework of the AI Act. Updated 7 August 2026 and extracted 10 August 2026. Verified the 2 August 2026 enforcement milestone and the current 2 December 2027 date for Annex III high-risk AI-system rules
Help us improve
Was this article useful?
One anonymous tap helps Sona improve future reporting, headlines and source context.
Up next

The planned replacement for the Lifetime ISA would remove the withdrawal charge and delay the bonus until a home purchase. Its bonus rate, annual limit and property cap are not settled.
Continue reading

