Regulation
APRA CPS 230 and AI use cases
Australian operational risk standard covering critical operations and material service providers.
Read the source text (Australian Prudential Regulation Authority)Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI agent for complaints recognition, investigation and response
Complaint handling is not listed in Annex III, so internal classification and drafting for a handler who decides is minimal risk. Where the agent talks to customers to take the complaint, Article 50(1) requires telling them they are dealing with AI. Only a system that also assessed creditworthiness or priced life and health insurance (Annex III point 5(b) or 5(c)) would be high risk for that part.
- AI agent for corporate credit analysis and credit memo drafting
Annex III point 5(b) makes AI used to evaluate the creditworthiness of natural persons high risk. Credit analysis of companies is outside that point, but the tier can change when the same system evaluates the creditworthiness of natural persons, such as sole traders, partners who are personally liable or personal guarantors. Design the scope explicitly and document it.
- AI assistant for procurement and supplier contract review
Contract review and sourcing are not among the Annex III high risk uses, so an internal assistant that makes no decisions about natural persons is minimal risk (with the Article 4 AI literacy duty). If a negotiation bot chats directly with supplier staff, Article 50(1) applies and it must tell them they are dealing with an AI system, unless that is obvious from the context. Public authorities using AI in procurement should still check national public procurement rules on transparency and equal treatment of bidders.
- AI for back office account servicing execution
The tier depends on how the system is built. It stays minimal when the agent only executes changes approved by a person and any letter comes from a fixed template, since executing servicing changes is not listed in Annex III. It moves to limited risk when the same system talks to customers directly (the Article 50 transparency duty, described on the customer facing servicing page) or when generative AI drafts the confirmation or letter text: the provider of that generative function, the bank if it builds the system, then carries the Article 50(2) duty to mark the generated content in a machine readable way, unless the output only gets an assistive role or standard editing that does not substantially alter the input data. An AI system used to evaluate the creditworthiness of natural persons, for example to decide on a loan restructuring, is high risk under Annex III point 5(b); keep that assessment outside this agent, which only executes the decided change.
- AI for continuous controls testing and control self assessment
Testing controls over transactions and systems is not an Annex III use. Controls that monitor and evaluate individual employees' behaviour, such as trading or access conduct, can fall under Annex III point 4(b), so the design decides the tier.
- AI for inbound correspondence triage and routing
It depends on where the system runs. Classifying and routing a bank's or insurer's correspondence is not a use listed in Annex III, so it is minimal risk: the AI literacy duty of Article 4 applies, and the Article 50 duty to tell people they are dealing with AI does not, because the system does not interact with the sender. Used by or for a public authority in a benefits process covered by Annex III point 5(a), the provider can treat it as not high risk only while it performs a narrow procedural or preparatory task under Article 6(3); the provider must then document that assessment before it goes live (Article 6(4)) and register the system in the EU database (Article 49(2)). If the system evaluates eligibility for benefits or profiles the people who write in, it is high risk, so those judgements stay with people.
- AI portfolio drift monitoring and rebalancing proposals
Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.
- AI system and model inventory with shadow AI discovery
Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI agent for account and card servicing
Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.
- AI agent for first line contact centre service
An AI system that interacts directly with people must be designed so that they know they are dealing with AI, unless that is obvious from the context (Article 50(1)). It is not high risk under Annex III as long as it does not evaluate eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness (point 5(b)), risk and pricing for life and health insurance (point 5(c)) or emergency calls (point 5(d)). This holds only if emotion or vulnerability signals are inferred from what the customer says (text or transcript content), not from voice or other biometric features; an agent that infers emotion from a caller's voice is an emotion recognition system (Article 3(39)), which is high risk under Annex III point 1(c) and triggers the deployer disclosure duty in Article 50(3).
- AI assistant for corporate and commercial client servicing
A chatbot that interacts with people at client companies must disclose that it is AI (Article 50). It does not evaluate creditworthiness or decide on access to an essential service (Annex III point 5), so it is not high risk.
- AI for regulatory report assembly
Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.
- AI orchestration of corporate account opening and channel setup
Operational setup of accounts and entitlements for corporate clients is not listed in Annex III and makes no decision about a natural person's access to a service or creditworthiness. The agent chases documents directly with client staff, so Article 50(1) applies: the provider must design the system so that they are informed that they are interacting with an AI system, unless that is obvious from the context. A purely internal version without client contact would be minimal risk.
- AI regulatory horizon scanning and obligation mapping
An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.
- AI scam intervention for instant payments
Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI coding assistant for software developers
A coding assistant used by developers is not a prohibited practice under Article 5 and is not listed in Annex III. Developers know they are working with an AI tool, so the Article 50 disclosure duty has no practical effect for the deploying organization, and the marking of generated content under Article 50(2) falls on the tool's provider. What remains is AI literacy (Article 4). Using an AI system to monitor or evaluate individual developers' performance would fall under Annex III point 4(b), and the software the assistant helps build may itself fall under the Act.
- AI examination of trade documents under letters of credit and collections
Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.
- AI for chargeback and representment operations
Dispute processing between issuers, acquirers and merchants is not listed in Annex III. It is not an evaluation of creditworthiness or credit scoring under Annex III point 5(b), and because cardholders do not interact with the system directly, the Article 50(1) transparency duty for AI that talks to people does not apply. Article 50(2) marking of generated text is a duty of the provider of the AI system that generates it, which includes an institution that builds its own dispute drafting agent and puts it into service under its own name. A drafted rebuttal built from attached case evidence performs an assistive function for standard editing of that evidence and does not substantially alter the underlying input, so it falls under the Article 50(2) exception and does not need machine readable marking. With that point checked, the tier stays minimal. A customer facing intake agent is assessed separately.
- AI for fee and interest leakage detection
Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.
- AI for IT incident triage and root cause analysis (AIOps)
An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.
- AI for ledger and payment reconciliation
Matching entries between internal financial records is not a use listed in Annex III and is not a practice prohibited by Article 5. Operators knowingly use an internal AI tool, so no Article 50(1) disclosure is needed. If a generative model drafts the explanations or journals, the provider of that system may have to mark its output as AI generated under Article 50(2). The AI literacy duty of Article 4 applies to the bank as deployer.
- AI for legacy code modernization
Tools that analyze, document and translate code are not prohibited practices under Article 5 and are not listed in Annex III, so no high risk obligations apply to the tooling. Engineers and analysts know they are working with an AI tool, including when they query the documentation through a chat assistant, so the Article 50 disclosure duty has no practical effect for the deploying organization. What remains is AI literacy for the staff who use it (Article 4). If the system being modernized is itself an AI system in an Annex III area (for example creditworthiness assessment, point 5(b)), its new version still has to meet the high risk requirements.
- AI for payment investigations and exceptions
Handling payment exceptions is not a use listed in Annex III and is not a prohibited practice under Article 5. If the agent interacts directly with customers, for example in a chat about the case, Article 50(1) requires that they are told they are interacting with an AI system.
- AI for third party and vendor risk due diligence
Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.
- Real time fraud scoring for card and instant payments
Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.