[{"data":1,"prerenderedAt":572},["ShallowReactive",2],{"uc-product-feedback-and-bug-report-triage":3,"uc-regulations":349},{"useCase":4,"evidence":169,"blitsAiDeployments":233,"benchmarks":234,"indicative":241,"related":244,"indexability":347,"includeUnpublished":175},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":20,"patterns":23,"channels":27,"audience":30,"autonomy":31,"adoptionStage":32,"problem":33,"problemStats":34,"howItWorks":35,"valueDrivers":36,"kpis":40,"indicativeValue":44,"macroEstimates":79,"feasibility":80,"implementation":92,"risk":130,"blitsAi":145,"faq":147,"related":160,"datePublished":164,"dateModified":164,"lastVerified":164,"changelog":165,"slug":168},"AI for product feedback and bug report triage","Bug report triage","AI bug triage for software engineering teams","AI reads incoming bug reports and routes them to the right team. Google Cloud reports Gelato raised ticket assignment accuracy from 60% to 90%.","published","AI that reads incoming bug reports, crash logs and product feedback from support tickets, app store reviews and error monitoring tools, classifies each one by severity, component and likely duplicate, routes it to the right engineering team, and for well specified defects drafts a starting code change or reproduction steps for an engineer to review.",[12,13,14,15,16],"bug triage AI","engineering ticket triage","issue triage assistant","ticket to code","automated bug classification",[18,19],"technology","cross-industry",[21,22],"it-and-engineering","customer-service",[24,25,26],"classification-and-routing","code-generation","summarization",[28,29],"internal-tools","api","employee-facing","supervised-agent","emerging","Every software product generates a stream of bug reports, crash logs, feature requests and app\nstore reviews that has to be read, categorized and sent to the right engineering team before\nanyone can fix anything. A person triaging by hand has to judge severity, guess which component\nis at fault, check whether the same issue was already reported under different words, and decide\nwhether it is even a bug rather than a support question. That judgment call repeats every time a\nnew report comes in, at whatever volume the company's own reports and feature requests arrive, and\ngetting it wrong sends a report to the wrong queue, where it waits until someone routes it again.\n\nSimple keyword rules can route on an exact error code but miss paraphrased duplicates, mixed\nreports that touch more than one component, and anything that needs the stack trace read to\nunderstand. Classifying the text of a report, its logs and its similarity to past tickets against\nthe categories an engineering team already uses changes the economics: a report can be triaged in\nthe seconds it takes to read it, at the volume a support queue actually receives, while the\ndecision to merge any code stays with an engineer.",[],"1. **Ingest every report.** Error logs, crash reports, support tickets and app store reviews land\n   in one queue with their stack traces and metadata (product, version, user segment).\n2. **Classify and deduplicate.** The model reads the report, tags severity and likely component,\n   and matches it against open tickets to catch reports of the same underlying issue.\n3. **Route to the right queue.** Each ticket goes to the owning team with the model's reasoning\n   attached, instead of a general backlog a person has to sort by hand.\n4. **Draft a starting point for clear defects.** When a report includes a reproducible stack trace\n   or failing test, the model proposes a code change or, when it cannot, reproduction steps for an\n   engineer to pick up.\n5. **Check against the human call.** The model's category is compared to what the engineer\n   actually decided; repeated disagreement on a category is a signal to retrain it, not just fix\n   the one ticket.",[37,38,39],"employee-productivity","speed","cost-to-serve",[41,42,43],"accuracy","handling-time-reduction","productivity-gain",{"referenceOrg":45,"inputs":46,"formula":74,"currency":75,"period":76,"resultLabel":77,"caveat":78},"A software company that receives 5,000 bug reports and feature requests a year",[47,53,60,67],{"key":48,"label":49,"low":50,"high":50,"unit":51,"note":52},"reportsPerYear","Bug reports and feature requests per year",5000,"reports per year","The reference organization.",{"key":54,"label":55,"low":56,"high":57,"unit":58,"note":59},"triageMinutes","Manual time to read, categorize and route one report",10,20,"minutes per report","Editorial assumption, replace with your own average triage time.",{"key":61,"label":62,"low":63,"high":64,"unit":65,"note":66},"shareAutomated","Share of reports the model routes without a later reassignment",0.5,0.8,"fraction of reports","Conservative against the benchmark on this page (Google Cloud reports Gelato raised ticket assignment accuracy from 60% to 90%), because ambiguous or high severity reports still get a human check before routing.",{"key":68,"label":69,"low":70,"high":71,"unit":72,"note":73},"engineerCost","Fully loaded engineer cost",50,90,"USD per hour","Editorial assumption, replace with your own.","reportsPerYear * (triageMinutes / 60) * shareAutomated * engineerCost","USD","per year","Engineering triage time avoided","Counts only the time saved routing and categorizing reports that the model handles without a later reassignment. It leaves out the cost of running the AI, the time still spent on reports that reach a human first, and the larger value of duplicates caught earlier and faster time to a fix.",[],{"complexity":81,"complexityNote":82,"dataPrerequisites":83,"integrations":87},"low","Classifying a bug report against categories a team already uses is a mature text and log classification task. Most of the effort goes into connecting the issue tracker, giving the model the right context (stack traces, prior tickets) and setting the confidence threshold for when it also drafts a fix rather than only a category.",[84,85,86],"A history of resolved tickets labelled with their final category, severity and owning team","Access to the stack traces, logs or crash reports attached to each report","A written definition of the severity levels and routing rules the team already uses",[88,89,90,91],"Issue tracker (Jira, GitHub Issues, Linear or similar)","Support or feedback intake tool, including app store review feeds","Source control and CI, for reports that reach the code drafting step","Error monitoring and crash reporting tools",{"steps":93,"guardrails":109,"humanInTheLoop":114,"kpisToInstrument":115,"failureModes":120},[94,97,100,103,106],{"title":95,"detail":96},"Label a real ticket history first","Pull a year of resolved tickets with their final category, severity and owning team, and test the model against it before it touches a live queue.",{"title":98,"detail":99},"Route on confidence, not on the output alone","Auto assign only the categories where the model matches history closely; send low confidence and cross team reports to a person with the model's reasoning attached.",{"title":101,"detail":102},"Keep duplicate detection separate from severity scoring","Match new reports against open tickets by similarity before scoring severity. A report that turns out to be a duplicate does not need its own triage decision.",{"title":104,"detail":105},"Gate code drafting to well scoped defects","Only propose a starting fix when the report includes a reproducible stack trace or failing test; for anything else, draft reproduction steps for a human instead of guessing at code.",{"title":107,"detail":108},"Compare against the engineer's final call every week","Track where the model's category disagreed with what an engineer actually decided, and use the pattern to retrain the categories, not only to fix the individual ticket.",[110,111,112,113],"No automatic merge of any drafted code; it goes through the normal review and test suite like any other change","Routing confidence thresholds set per category, with low confidence reports going to a person","A visible label on every automated classification and drafted change identifying it as AI produced","Regular comparison of the model's category against the engineer's final triage decision","Engineers approve every category change that crosses a team boundary, review and test every drafted code change before merge exactly as they would a colleague's pull request, and a team lead checks a sample of automated classifications each week to catch drift as the product changes.",[116,117,118,119],"Ticket assignment accuracy against the engineer's final category, per team","Share of reports auto routed without a later reassignment","Time from report received to first engineering action","Duplicate reports caught before they reach a team queue",[121,124,127],{"title":122,"detail":123},"Confident misclassification","The model assigns a plausible but wrong team or severity with high confidence, delaying a real fix. Track disagreement with the engineer's final call, not only the model's own confidence score.",{"title":125,"detail":126},"Drafted fixes that look right and are not","A generated code change compiles and matches the report's description but misses the actual root cause. Require the same test suite and review on every drafted change as on any other code, with no exception for AI generated changes.",{"title":128,"detail":129},"Duplicate detection missing paraphrased reports","Users describe the same bug differently across channels, and near duplicates get filed as new tickets, inflating the backlog count. Match on stack trace and error signature, not only on text similarity.",{"euAiAct":131,"regulations":134,"guidance":138,"controls":139,"incidents":144},{"tier":132,"basis":133},"minimal","Triaging internal engineering tickets and drafting code for a human to review has no listed use in Annex III and does not produce a decision with legal or similarly significant effects on a person outside the company, so it carries no use case specific AI Act obligation beyond the general purpose model duties in Chapter V that apply to the provider of the underlying model.",[135,136,137],"eu-ai-act","gdpr","iso-42001",[],[140,141,142,143],"An inventory entry for the triage and drafting tool with an accountable owner","No automatic merge of AI drafted code; standard review and CI gates apply unchanged","An audit log of every automated routing decision and its confidence score","A periodic accuracy review against the engineer's final triage decision, per team",[],{"howToBuild":146},"The ingestion and triage part of this runs on Blits.ai as an **agentic workflow** on a schedule:\n**custom functions** pull new reports from the issue tracker and support tool through their REST\nAPIs (the integration catalog includes Jira and Zendesk), and an **AI agent** with **structured\noutput** classifies each one by severity, component and likely duplicate against a **knowledge\nbase** built from your own resolved ticket history, retrieved with hybrid search, and returns a\nconfidence value alongside the category through structured output. The agent's instructions or a\ncustom function check that value and route anything below the threshold to a person instead of\nauto assigning it, which is the low confidence routing the guardrails below describe. **Human in the\nloop confirmation** for agentic actions above a configurable threshold can gate the write back\nitself, so a higher stakes routing decision still waits for a person to confirm it before a custom\nfunction applies the change to the tracker.\n\n**Test suites** run a labelled set of past tickets through the classifier, checking the assigned\ncategory against the known answer, and can be run after every prompt or model change; **monitors** run\nscheduled health checks on the classifier agent and alert on failure; the workflow's own run\nhistory, analytics and per run audit trail give visibility into every triage run in between. The\nplatform is model agnostic, so the classifier can run on a different model than a more expensive\nstep, and can run in the EU or UAE region for data residency. Drafting a starting code fix from a\nwell scoped ticket, as in the evidence on this page, needs a coding focused tool outside this\nworkflow; a custom function can hand the ticket and stack trace to one, but Blits.ai does not\nitself write or test code.",[148,151,154,157],{"question":149,"answer":150},"How accurate is AI at triaging bug reports?","It depends on how close the categories are to what the model was tested against. Google Cloud reports that Gelato raised its ticket assignment accuracy from 60% to 90% using Gemini models. That is one company's reported figure; measure accuracy against your own resolved ticket history before trusting it on a live queue.",{"question":152,"answer":153},"Can AI actually fix bugs, not just triage them?","Google Cloud reports that Regnology built a Ticket-to-Code Writer tool with Gemini 1.5 Pro to turn bug tickets into code; neither Google Cloud page gives its scope, volume or an acceptance rate for the drafts. As editorial guidance rather than something this evidence shows, code drafting is best gated to well scoped defects with a reproducible stack trace or failing test. Treat any AI drafted change like a colleague's pull request: it still needs review and the normal test suite before merge.",{"question":155,"answer":156},"What should stay with a human?","Any report that crosses a team boundary at low confidence, anything the model cannot match to a known category, and every code merge decision, which should go through the same review as any other change.",{"question":158,"answer":159},"How is this different from AIOps incident triage?","AIOps incident triage groups monitoring alerts about infrastructure and services into one probable incident. This use case triages reports that people submit about the product itself, such as a crash, a broken feature or unexpected behaviour, before an engineer has confirmed there is an incident at all.",[161,162,163],"aiops-incident-triage","developer-coding-assistant","software-vulnerability-remediation","2026-09-30",[166],{"date":164,"note":167},"First published","product-feedback-and-bug-report-triage",[170,214],{"title":171,"useCases":172,"organization":173,"vendors":177,"summary":181,"stage":182,"year":183,"channels":184,"languages":185,"metrics":186,"outcomeDisclosed":202,"sources":203,"verification":208,"grade":211,"id":212,"organizationSlug":213},"Gelato: AI engineering ticket triage and error categorization",[168],{"name":174,"anonymized":175,"region":176,"industry":18},"Gelato",false,"europe",[178],{"name":179,"role":180},"Google Cloud","platform","Gelato, a Norwegian software company that enables local production for global ecommerce through a network of more than 140 printers in 32 countries, uses Gemini models on Google Cloud to automate engineering ticket triage across its 15 engineering teams and customer error categorization.","production",2025,[28],[],[187,194],{"kpi":41,"value":71,"unit":188,"qualifier":189,"baseline":190,"claimant":191,"quote":192,"sourceUrl":193},"percent","exact","60% ticket assignment accuracy before the AI powered system","vendor","The AI-powered system increased ticket assignment accuracy from 60% to 90% and reduced the time to deploy ML models from two weeks to one or two days using Vertex AI.","https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders",{"kpi":195,"value":196,"unit":197,"qualifier":189,"period":198,"baseline":199,"claimant":191,"quote":200,"sourceUrl":201},"hours-saved",120,"hours","per week","The triage process took over 100 hours weekly before the AI powered system.","Gelato has saved 120 hours of weekly labor as a result, meaning it no longer needs to assign dedicated resources to triage.","https://cloud.google.com/customers/gelato",true,[204,206],{"url":193,"title":205,"publisher":179},"101 real world generative AI use cases from industry leaders",{"url":201,"title":207,"publisher":179},"Gelato case study",{"level":209,"checkedAt":210},"source-verified","2026-09-29","C","gelato-engineering-ticket-triage",null,{"title":215,"useCases":216,"organization":217,"vendors":219,"summary":221,"stage":182,"year":222,"channels":223,"languages":224,"metrics":225,"outcomeDisclosed":175,"sources":226,"verification":231,"grade":211,"id":232,"organizationSlug":213},"Regnology: AI Ticket-to-Code Writer for bug tickets",[168],{"name":218,"anonymized":175,"region":176,"industry":18},"Regnology",[220],{"name":179,"role":180},"Regnology, a provider of regulatory reporting software, built a Ticket-to-Code Writer tool using Gemini 1.5 Pro to automate the conversion of bug tickets into actionable code changes, aiming to streamline its software development process. Google Cloud's own summary does not disclose an accuracy, acceptance or time saved figure for the tool.",2024,[28],[],[],[227,228],{"url":193,"title":205,"publisher":179},{"url":229,"title":230,"publisher":179},"https://cloud.google.com/customers/regnology","Regnology case study",{"level":209,"checkedAt":164},"regnology-bug-ticket-to-code",0,[235],{"kpi":41,"label":236,"unit":188,"aggregate":202,"higherIsBetter":202,"n":237,"nUpTo":233,"median":71,"min":71,"max":71,"byClaimant":238,"vendorOnly":202,"points":239},"Accuracy",1,{"organization":233,"vendor":237,"regulator":233,"independent":233},[240],{"evidenceId":212,"organization":174,"value":71,"qualifier":189,"claimant":191,"grade":211,"pooled":202},{"low":242,"high":243},20833.333333333332,120000,[245,281,304,323],{"slug":161,"title":246,"shortTitle":247,"definition":248,"status":9,"industries":249,"functions":253,"patterns":256,"audience":30,"autonomy":260,"adoptionStage":261,"evidenceCount":56,"publicEvidenceCount":262,"organizations":263,"bestGrade":273,"headline":274,"lastVerified":280,"indexable":202},"AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[19,250,18,251,252],"banking","telecommunications","payments",[21,254,255],"operations","risk-management",[257,24,26,258,259],"anomaly-detection","rag-knowledge-assistant","agentic-workflow","copilot","early-adopters",9,[264,265,266,267,268,269,270,271,272],"Anaplan","Coinbase","FreeWheel","Google","IHG Hotels & Resorts","Meta","Microsoft","Mizuho Financial Group","TD Bank","B",{"kpi":275,"label":276,"unit":188,"n":277,"nUpTo":233,"kind":278,"value":279,"qualifier":189,"claimant":213,"organization":213,"vendorReported":175},"mttr-reduction","Time to repair reduction",5,"median",72,"2026-09-27",{"slug":162,"title":282,"shortTitle":283,"definition":284,"status":9,"industries":285,"functions":288,"patterns":289,"audience":30,"autonomy":260,"adoptionStage":290,"evidenceCount":262,"publicEvidenceCount":262,"organizations":291,"bestGrade":273,"headline":300,"lastVerified":280,"indexable":202},"AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[19,250,286,18,287],"capital-markets","professional-services",[21],[25],"mainstream",[292,293,294,295,296,297,298,299,269],"Accenture","AMD","ANZ","Bank of America","Cathay Pacific","Citi","CME Group","Duolingo",{"kpi":43,"label":301,"unit":188,"n":302,"nUpTo":233,"kind":278,"value":303,"qualifier":189,"claimant":213,"organization":213,"vendorReported":175},"Productivity gain",4,22.5,{"slug":163,"title":305,"shortTitle":306,"definition":307,"status":9,"industries":308,"functions":310,"patterns":312,"audience":30,"autonomy":260,"adoptionStage":261,"evidenceCount":313,"publicEvidenceCount":313,"organizations":314,"bestGrade":273,"headline":317,"lastVerified":280,"indexable":202},"AI for software vulnerability triage and remediation","Vulnerability remediation","AI that takes security findings from scanners, fuzzers and bug reports, filters out duplicates and false positives, reproduces and ranks the real ones, and drafts a code fix with a test for each, which a developer reviews and merges through the normal change process.",[19,18,309],"healthcare",[311,21],"security-operations",[25,259,24],6,[293,296,267,315,316],"Labelbox","PatientPoint",{"kpi":318,"label":319,"unit":188,"n":237,"nUpTo":233,"kind":320,"value":321,"qualifier":322,"claimant":191,"organization":293,"vendorReported":202},"automation-rate","Automation rate","reported",70,"approximately",{"slug":324,"title":325,"shortTitle":326,"definition":327,"status":9,"industries":328,"functions":329,"patterns":331,"audience":333,"autonomy":334,"adoptionStage":261,"segment":335,"evidenceCount":313,"publicEvidenceCount":313,"organizations":336,"bestGrade":273,"headline":342,"lastVerified":280,"indexable":202},"developer-api-integration-assistant","AI assistant for developers integrating a company's APIs","API integration assistant","An AI assistant on a developer portal and in its documentation that answers integration questions, recommends the right endpoints, helps debug connections and generates sample calls, grounded in the API catalogue, reference docs and test material, so clients and partners integrate faster with fewer support tickets.",[19,250,252,18],[21,22,330],"onboarding-and-kyc",[258,332,25],"conversational-agent","customer-facing","assist","specialized-businesses",[337,338,265,339,340,341],"Anaconda","CircleCI","Mapbox","monday.com","U.S. Bank",{"kpi":343,"label":344,"unit":188,"n":237,"nUpTo":233,"kind":320,"value":345,"qualifier":189,"claimant":346,"organization":339,"vendorReported":175},"contact-deflection","Contact deflection",30,"organization",{"indexable":202,"reasons":348},[],[350,356,361,368,376,383,389,395,403,410,417,423,429,435,442,449,455,462,467,473,480,487,492,497,502,508,513,518,525,530,537,543,549,556,561,566],{"id":135,"label":351,"issuer":352,"region":176,"url":353,"description":354,"useCases":355,"indexable":202},"EU AI Act","European Union","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",250,{"id":136,"label":357,"issuer":352,"region":176,"url":358,"description":359,"useCases":360,"indexable":202},"GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",223,{"id":137,"label":362,"issuer":363,"region":364,"url":365,"description":366,"useCases":367,"indexable":202},"ISO/IEC 42001","ISO and IEC","global","https://www.iso.org/standard/81230.html","The international management system standard for AI.",127,{"id":369,"label":370,"issuer":371,"region":372,"url":373,"description":374,"useCases":375,"indexable":202},"nist-ai-rmf","NIST AI Risk Management Framework","NIST","north-america","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",95,{"id":377,"label":378,"issuer":379,"region":176,"url":380,"description":381,"useCases":382,"indexable":202},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",73,{"id":384,"label":385,"issuer":352,"region":176,"url":386,"description":387,"useCases":388,"indexable":202},"dora","DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",67,{"id":390,"label":391,"issuer":392,"region":176,"url":393,"description":394,"useCases":70,"indexable":202},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",{"id":396,"label":397,"issuer":398,"region":399,"url":400,"description":401,"useCases":402,"indexable":202},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",37,{"id":404,"label":405,"issuer":406,"region":399,"url":407,"description":408,"useCases":409,"indexable":202},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":411,"label":412,"issuer":413,"region":364,"url":414,"description":415,"useCases":416,"indexable":202},"pci-dss","PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",22,{"id":418,"label":419,"issuer":420,"region":372,"url":421,"description":422,"useCases":416,"indexable":202},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":424,"label":425,"issuer":352,"region":176,"url":426,"description":427,"useCases":428,"indexable":202},"nis2","NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",17,{"id":430,"label":431,"issuer":432,"region":176,"url":433,"description":434,"useCases":428,"indexable":202},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",{"id":436,"label":437,"issuer":438,"region":372,"url":439,"description":440,"useCases":441,"indexable":202},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",16,{"id":443,"label":444,"issuer":445,"region":364,"url":446,"description":447,"useCases":448,"indexable":202},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":450,"label":451,"issuer":352,"region":176,"url":452,"description":453,"useCases":454,"indexable":202},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":456,"label":457,"issuer":458,"region":372,"url":459,"description":460,"useCases":461,"indexable":202},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":463,"label":464,"issuer":352,"region":176,"url":465,"description":466,"useCases":461,"indexable":202},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",{"id":468,"label":469,"issuer":470,"region":372,"url":471,"description":472,"useCases":461,"indexable":202},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":474,"label":475,"issuer":476,"region":364,"url":477,"description":478,"useCases":479,"indexable":202},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",12,{"id":481,"label":482,"issuer":483,"region":372,"url":484,"description":485,"useCases":486,"indexable":202},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",11,{"id":488,"label":489,"issuer":352,"region":176,"url":490,"description":491,"useCases":486,"indexable":202},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",{"id":493,"label":494,"issuer":352,"region":176,"url":495,"description":496,"useCases":486,"indexable":202},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":498,"label":499,"issuer":352,"region":176,"url":500,"description":501,"useCases":486,"indexable":202},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":503,"label":504,"issuer":505,"region":176,"url":506,"description":507,"useCases":56,"indexable":202},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",{"id":509,"label":510,"issuer":398,"region":399,"url":511,"description":512,"useCases":56,"indexable":202},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",{"id":514,"label":515,"issuer":352,"region":176,"url":516,"description":517,"useCases":56,"indexable":202},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":519,"label":520,"issuer":521,"region":372,"url":522,"description":523,"useCases":524,"indexable":202},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",7,{"id":526,"label":527,"issuer":352,"region":176,"url":528,"description":529,"useCases":524,"indexable":202},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":531,"label":532,"issuer":533,"region":534,"url":535,"description":536,"useCases":277,"indexable":202},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":538,"label":539,"issuer":540,"region":176,"url":541,"description":542,"useCases":302,"indexable":202},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":544,"label":545,"issuer":546,"region":176,"url":547,"description":548,"useCases":302,"indexable":202},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":550,"label":551,"issuer":552,"region":399,"url":553,"description":554,"useCases":555,"indexable":202},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",3,{"id":557,"label":558,"issuer":352,"region":176,"url":559,"description":560,"useCases":555,"indexable":202},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":562,"label":563,"issuer":352,"region":176,"url":564,"description":565,"useCases":555,"indexable":202},"eu-mortgage-credit-directive","EU Mortgage Credit Directive","https://eur-lex.europa.eu/eli/dir/2014/17/oj","Directive 2014/17/EU: creditworthiness assessment, disclosure and advice rules for residential mortgage lending.",{"id":567,"label":568,"issuer":569,"region":372,"url":570,"description":571,"useCases":555,"indexable":202},"nyc-local-law-144","NYC Local Law 144","New York City","https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","Bias audits and notices for automated employment decision tools used in hiring and promotion in New York City.",1790783080214]