What problem does it solve?
A customs administration sees a declaration for every container, truck and parcel that crosses its border, but can physically inspect or scan only a small fraction of them without stopping trade. The traditional answer is fixed rules: flag anything from a listed country, anything over a value threshold, anything in a sensitive tariff line. Rules catch what they are written for and miss what they are not, they age as smuggling and invoice fraud patterns shift, and every officer hour spent opening a container that turns out clean is an hour not spent on the one that is not.
The fraud is not only physical. A shipment can be declared at the right tariff line but the wrong value, so importers under pay duty, or the invoice can be split, mislabelled or routed through a chain of related suppliers to break the pattern a simple rule would catch. Indian Customs describes the underlying data problem: overseas supplier details arrive in free text on the declaration, with the same supplier recorded under different spellings and addresses, particularly when that supplier ships to multiple importers across the country, so without cleaning and matching that data first, a risk engine cannot see that one high risk supplier behind many importers, or that one importer's declared values are drifting away from what the same product from the same supplier has cost everyone else.
How does it work?
- Clean and match the underlying data. Supplier names and addresses and free text goods descriptions arrive inconsistent across declarations. Natural language processing standardizes them, then clustering and string similarity models group the variants that are really the same supplier or the same product, so the same trader cannot look like many small ones.
- Score every declaration. Models trained on past seizures, audits and confirmed fraud rank the risk that a shipment carries prohibited goods, is misclassified or is undervalued, alongside rules and watchlists that still catch what regulation requires every time.
- Check the value against history. For declared value specifically, a model compares the item level price on this declaration with historical prices for the same product from the same supplier, and flags a shipment whose price has drifted from that pattern.
- Map the network. Supply chain network analytics link importers, suppliers, customs brokers and ports of entry so an officer can see when a new importer sits behind an already high risk supplier or broker, not only whether this one declaration looks unusual on its own.
- Route the outcome. Low risk declarations clear without an officer looking at them; flagged ones generate an alert with the supporting evidence for a specific action: document review, scanning or physical inspection.
- Feed enforcement back in. Confirmed seizures, misclassifications and undervaluations update the risk profile of the entities involved, so the next declaration from the same network starts from a higher risk score.
- Audience
- Back office
- Autonomy
- Supervised agent
- Adoption
- Early adopters
- Channels
- Internal tools, API and system to system
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Risk and loss reduction, Compliance quality, Lower cost to serve, Speed and cycle time.
Indicative value
A national customs administration processing 5 million import declarations a year
USD 1.5 million to USD 31.3 million
Unnecessary inspection cost avoided per year
How this is calculated
Formula: declarations * flaggedShare * falsePositiveCut * costPerReview. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Import declarations per year declarations, declarations per year | 5,000,000 | 5,000,000 | The reference administration. |
| Share of declarations flagged for physical inspection or detailed review today flaggedShare, fraction of declarations | 0.02 | 0.05 | Editorial assumption for a rule based baseline. Replace with your own inspection rate. |
| Share of those flags avoided by better targeting, at the same or better detection falsePositiveCut, fraction of flagged declarations | 0.1 | 0.25 | Editorial assumption, replace with your own pilot results. CBP's own federal AI use case inventory entries describe these models as evaluating and prioritizing shipments for review "while maintaining efficient cargo processing operations", and Indian Customs reports its risk models are evaluated on false positive rate, but neither discloses a percentage. |
| Cost of a physical inspection or detailed document review costPerReview, USD per declaration reviewed | 150 | 500 | Editorial assumption covering officer time, scanning and, for a share of cases, demurrage while a container waits. Replace with your own cost. |
What it leaves out: Counts only reviews avoided at an unchanged or better detection rate; it leaves out the value of the duty, tax and seizures a better targeted model finds that a rule based one would miss, the cost of building and validating the models, and any change in trade facilitation revenue from faster clearance.
Who already uses it?
2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Indian Customs (Central Board of Indirect Taxes and Customs)
India · Government and public sector · 2025
Indian Customs built an integrated, AI and machine learning powered risk management system. It codifies overseas suppliers and item descriptions with unsupervised machine learning so the same supplier and product can be matched across declarations, then runs a suite of models on top, including a "Machine Learning-based Valuation Model" that compares a shipment's declared value with historical declarations for the same product from the same supplier in real time, a supply chain network analytics tool, and predictive targeting of high risk suppliers. The models generate daily alerts and decision support for front line officers and were credited with supporting seizures including roughly 294 kg of heroin at Nhava Sheva Port and about 883 kg of methamphetamine in a maritime import consignment.
No outcome disclosed.
U.S. Customs and Border Protection
United States · Government and public sector · 2023
CBP's own entries in the U.S. government's federal AI use case inventory describe three machine learning models that score cargo shipments and the entities behind them. Illicit Trade, live since July 2023, scores inbound cargo shipments for the risk that they violate trade regulations and sends its results to the Automated Targeting System for review. Cargo Security Assessment Model, live since December 2011, returns high risk shipments for narcotics smuggling threats as a rule hit an officer reviews and can act on. Trade Entity Risk Model, live since July 2025, builds a risk profile for each importer, supplier and trading partner from historical transactions, relationships and compliance history and feeds that score into CBP's other threat models. All three draw on data from the Automated Commercial Environment, the system that carries import and export declarations.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Years of past declarations with the outcome (cleared, inspected, seized, reassessed) recorded
- Reference price and classification data to compare a declared value or tariff line against
- A cleaned, matched register of suppliers, importers and customs brokers
- Watchlists and rules the administration is legally required to apply regardless of the model
Systems to integrate
- National customs declaration and single window system
- Scanning and imaging equipment at ports and border crossings
- External trade and reference price data
- Case management for the officers who act on flagged declarations
- International risk and enforcement information exchange (for example the WCO Customs Enforcement Network or the EU's Customs Risk Management System)
Complexity: High
The data work is the hard part: entity and product matching across inconsistent, free text declaration data must be solid before any risk score is trustworthy, and the models sit inside a national customs single window that already carries legal weight for every clearance decision.
- 1
Fix entity and product matching first
Before scoring risk, clean and cluster supplier names, addresses and item descriptions so the same trader and the same product are recognised across every declaration. Every later model depends on this.
- 2
Keep the required rules and watchlists in place
Add scoring and anomaly detection alongside, not instead of, the checks the administration is legally required to run on every declaration.
- 3
Start with the highest volume, best labelled risk
Undervaluation against a known product and supplier history is easier to validate than contraband detection. Launch there, build the evidence base, then extend.
- 4
Validate against confirmed outcomes, not alerts
Train and test on declarations with a confirmed audit, seizure or reassessment outcome, not on which declarations were previously flagged, or the model relearns the old rules' blind spots.
- 5
Give officers the evidence, not just a score
An alert should carry the historical prices, the network links and the specific reason it was raised, so the officer can act quickly and the decision is defensible on review.
- 6
Run in parallel before any auto clearance changes
Score live declarations while the existing process still runs unchanged, compare outcomes for a full cycle, and only then let the model's low risk band clear without review.
Guardrails
- No declaration on a required watchlist or sanctions list clears without the checks regulation demands
- Every flag carries the evidence and reason an officer can review, not only a score
- Independent sampling of declarations the model cleared without review, at a rate that can detect drift
- Fairness testing against nationality, country of origin and importer size, given the risk that a risk model concentrates stops on a protected or politically sensitive group
- Model inventory entry, validation and a documented parallel run before any auto clearance threshold changes
KPIs to instrument
- Detection rate (confirmed contraband, misclassification or undervaluation found) before and after, on a held out period
- False positive rate, meaning flagged declarations that clear on review, before and after
- Revenue recovered from confirmed undervaluation or misclassification cases the model surfaced
- Time from declaration to clearance for the unflagged majority
- Error rate found by independent sampling of declarations cleared without review
Human in the loop
An officer reviews and decides every flagged declaration; the model routes and prioritises, it does not detain, seize or clear on its own. A senior officer or risk manager sets and owns the thresholds that decide what counts as low enough risk to clear without review, and reviews the sampling results.
Common failure modes
- Matching that merges the wrong entities
- Overly aggressive supplier or product matching can merge two different traders into one risk profile, or split one trader into many. Validate matches against known groupings before trusting the risk scores built on them.
- Learning the old rules' blind spots
- A model trained only on what was previously flagged repeats the patterns the old rules already caught and misses what they missed. Include confirmed outcomes found through audits, tip offs and other administrations' alerts, not only past flags.
- Risk scores that concentrate on a nationality or origin
- A model can reproduce or amplify bias present in past enforcement data. Test the score's distribution across nationality, country of origin and importer size, and set a review trigger if it concentrates on one group beyond what the confirmed outcome rate justifies.
- Clearance thresholds set to a savings target
- Widening the clear without review band to save inspection cost, rather than from validated detection performance, quietly raises the risk of missed contraband or fraud. Set thresholds from the parallel run's confirmed outcomes.
What are the risks and rules?
EU AI Act
Depends on design
Not listed by name in Annex III. Recital 59 says AI systems used by tax and customs authorities in administrative proceedings should not be classified as high risk law enforcement systems; this covers the revenue, misclassification and valuation side of the risk targeting on this page. Contraband and narcotics targeting that leads to seizures sits nearer criminal enforcement: Annex III point 6 (law enforcement) can apply where customs acts in criminal enforcement and the system profiles a natural person, for example building a case around a seizure such as the heroin and methamphetamine finds Indian Customs describes. Annex III point 7(b) covers risk assessment of natural persons entering the Union; it does not apply here, since this use case scores goods, consignments and trading entities, not natural persons. Where a natural person is profiled, GDPR's profiling rules apply; Article 22 covers a decision based solely on automated processing that produces a legal or similarly significant effect, which this use case's human in the loop design (an officer decides every flagged case) is intended to keep out of scope on its own, a separate GDPR question from AI Act classification. Criminal customs investigations fall under the Law Enforcement Directive (EU) 2016/680 instead of the GDPR.
Rules that apply
Guidance
- Regulation (EU) 2024/1689 (AI Act), Recital 59 (European Union, Europe). Systems intended for administrative proceedings by tax and customs authorities should not be classified as high risk law enforcement systems.
- EU Customs Risk Management Framework (CRMF) (European Commission, Taxation and Customs Union, Europe). Describes the EU's common risk criteria, which customs authorities use to target shipments for control, and the Customs Risk Management System (CRMS2), which helps customs authorities share that risk information and communicate on risk management and control issues; together the risk based approach this use case automates.
Controls to put in place
- Model inventory entry with an accountable owner, separate from the rules and watchlists still applied to every declaration
- Fairness monitoring of flag rates by nationality, country of origin and importer size
- Independent sampling of declarations cleared without review, with a threshold that triggers a review of the model
- Audit trail linking every flag to the evidence and the officer's decision
Frequently asked questions
- Does AI replace customs officers' decisions?
- No, in the deployments on this page it routes and prioritises. CBP's own AI use case inventory describes models that score cargo shipments and send high risk results to the Automated Targeting System for review by operational personnel, and Indian Customs describes models that proactively flag high risk consignments and generate daily alerts and machine generated instructions for front line customs officers. For Indian Customs, an officer decides every flagged case; the model decides which consignments reach an officer at all. That is how this pattern generally works: the model routes and prioritises, an officer acts.
- What does AI add to a rule based customs risk system?
- Two things a fixed rule set struggles with: matching the same supplier or product across inconsistent, free text declaration data, and comparing a declared value against the actual history of that product from that supplier rather than a flat threshold. Indian Customs built supplier and description codification first, then built its valuation model and other risk models on top of it. Rules and watchlists stay in place for what regulation requires every time.
- Is this an Annex III high risk system under the EU AI Act?
- Not automatically. Recital 59 keeps risk targeting and valuation checks used in administrative customs proceedings out of Annex III's law enforcement category. It can become high risk under Annex III point 6 where customs acts in criminal enforcement and the system profiles a natural person, for example around a seizure case. Annex III point 7(b) covers risk assessment of natural persons entering a Member State; it does not apply to this use case, which scores goods, consignments and trading entities, not natural persons. Where a natural person is profiled, GDPR's profiling rules and Article 22 apply, separately from AI Act classification, and criminal investigations fall under the Law Enforcement Directive (EU) 2016/680 instead.
How to cite this page
Blits.ai AI Use Case Library, "AI for customs risk targeting, container selection and valuation checks", last verified 29 September 2026, https://www.blits.ai/ai-use-cases/customs-risk-targeting-and-container-selection. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 30 September 2026: First published