[{"data":1,"prerenderedAt":468},["ShallowReactive",2],{"uc-reg-apra-cps-230":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","asia-pacific","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",false,true,[14,53,84,101,136,150,170,196,210,228,241,257,270,290,305,319,335,352,365,378,390,404,418,437,449],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":23,"patterns":26,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":35,"publicEvidenceCount":36,"organizations":37,"bestGrade":40,"headline":41,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":52},"account-and-card-servicing-agent","AI agent for account and card servicing","Account and card servicing","An AI agent that resolves routine account and card requests end to end, such as balances, statements, card blocks and replacements, PIN resets and limit changes, across app, web, messaging and phone, and hands anything sensitive or unusual to a human with the full context.","published",[21,22],"banking","payments",[24,25],"customer-service","operations",[27,28,29,30],"conversational-agent","voice-agent","agentic-workflow","rag-knowledge-assistant","customer-facing","supervised-agent","mainstream","front-office",4,2,[38,39],"Commonwealth Bank of Australia","DBS Bank","B",{"kpi":42,"label":43,"unit":44,"n":36,"nUpTo":45,"kind":46,"value":47,"qualifier":48,"claimant":49,"organization":39,"vendorReported":11},"containment-rate","Containment rate","percent",0,"reported",90,"approximately","organization","2026-09-27","limited","Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.",{"slug":54,"title":55,"shortTitle":56,"definition":57,"status":19,"industries":58,"functions":62,"patterns":65,"audience":69,"autonomy":70,"adoptionStage":71,"segment":72,"evidenceCount":36,"publicEvidenceCount":36,"organizations":73,"bestGrade":40,"headline":76,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":83},"complaints-handling-agent","AI agent for complaints recognition, investigation and response","Complaints handling","An AI agent that recognizes when a customer interaction is a complaint, logs it against the regulatory definition, classifies its root cause and severity, gathers the evidence, drafts the acknowledgement and the response for a human handler to approve, and tracks every statutory deadline until the case is closed.",[59,21,22,60,61],"cross-industry","insurance","telecommunications",[63,24,64],"case-management","regulatory-compliance",[66,67,68,29,30],"classification-and-routing","summarization","content-generation","employee-facing","copilot","early-adopters","middle-office",[74,75],"Lloyds Banking Group","NatWest Group",{"kpi":77,"label":78,"unit":79,"n":80,"nUpTo":45,"kind":46,"value":81,"qualifier":48,"claimant":49,"organization":74,"vendorReported":11},"time-saved-per-task","Time saved per task","minutes",1,5,"context-dependent","Complaint handling is not listed in Annex III, so internal classification and drafting for a handler who decides is minimal risk. Where the agent talks to customers to take the complaint, Article 50(1) requires telling them they are dealing with AI. Only a system that also assessed creditworthiness or priced life and health insurance (Annex III point 5(b) or 5(c)) would be high risk for that part.",{"slug":85,"title":86,"shortTitle":87,"definition":88,"status":19,"industries":89,"functions":90,"patterns":94,"audience":69,"autonomy":70,"adoptionStage":71,"segment":96,"evidenceCount":36,"publicEvidenceCount":36,"organizations":97,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":100},"credit-memo-drafting-agent","AI agent for corporate credit analysis and credit memo drafting","Credit underwriting and memos","An AI agent that gathers a corporate borrower's documents and data, spreads the financials into the bank's template, calculates ratios and covenant headroom, pulls bureau and news information, and drafts a committee ready credit memo in which every figure links to its source, for the relationship and credit teams to challenge, complete and sign.",[21],[91,92,93],"lending-and-credit","underwriting","risk-management",[95,29,30,68],"document-processing","specialized-businesses",[98,39],"Banestes",null,"Annex III point 5(b) makes AI used to evaluate the creditworthiness of natural persons high risk. Credit analysis of companies is outside that point, but the tier can change when the same system evaluates the creditworthiness of natural persons, such as sole traders, partners who are personally liable or personal guarantors. Design the scope explicitly and document it.",{"slug":102,"title":103,"shortTitle":104,"definition":105,"status":19,"industries":106,"functions":110,"patterns":111,"audience":31,"autonomy":32,"adoptionStage":33,"segment":34,"evidenceCount":112,"publicEvidenceCount":113,"organizations":114,"bestGrade":40,"headline":130,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":135},"first-line-contact-centre-agent","AI agent for first line contact centre service","First line contact centre","An AI agent that answers the first line of inbound customer contact on phone, chat and messaging, resolves general and routine questions end to end in the customer's own language, and routes everything complex, sensitive or regulated to the right human team with the context attached.",[59,21,22,61,107,108,109],"travel-and-hospitality","retail-and-ecommerce","wealth-and-asset-management",[24],[27,28,30,66],25,18,[115,116,117,118,119,38,120,121,122,123,124,75,125,126,127,128,129],"Air India","Airbnb","Bank of America","Bank of the Philippine Islands","BT Group","Ingka Group","JetBlue","Klarna","Lufthansa Group","Mobily","Pegasus Airlines","Telkomsel","Together Credit Union","Vodafone Germany","Vodafone",{"kpi":42,"label":43,"unit":44,"n":131,"nUpTo":45,"kind":132,"value":133,"qualifier":134,"claimant":99,"organization":99,"vendorReported":11},7,"median",47,"exact","An AI system that interacts directly with people must be designed so that they know they are dealing with AI, unless that is obvious from the context (Article 50(1)). It is not high risk under Annex III as long as it does not evaluate eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness (point 5(b)), risk and pricing for life and health insurance (point 5(c)) or emergency calls (point 5(d)). This holds only if emotion or vulnerability signals are inferred from what the customer says (text or transcript content), not from voice or other biometric features; an agent that infers emotion from a caller's voice is an emotion recognition system (Article 3(39)), which is high risk under Annex III point 1(c) and triggers the deployer disclosure duty in Article 50(3).",{"slug":137,"title":138,"shortTitle":139,"definition":140,"status":19,"industries":141,"functions":142,"patterns":143,"audience":31,"autonomy":32,"adoptionStage":71,"segment":96,"evidenceCount":81,"publicEvidenceCount":36,"organizations":144,"bestGrade":40,"headline":145,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":149},"corporate-client-servicing-assistant","AI assistant for corporate and commercial client servicing","Corporate client servicing","A conversational assistant inside the corporate banking portal, app and messaging channels that answers finance and treasury teams' servicing questions, such as payment status, balances, cut off times, fees and how to submit an instruction, resolves routine requests end to end and hands the rest to a service specialist who has an AI copilot.",[21,22],[24,25],[27,30,29,67],[117,39],{"kpi":146,"label":147,"unit":44,"n":80,"nUpTo":45,"kind":46,"value":148,"qualifier":134,"claimant":49,"organization":117,"vendorReported":11},"contact-deflection","Contact deflection",16,"A chatbot that interacts with people at client companies must disclose that it is AI (Article 50). It does not evaluate creditworthiness or decide on access to an essential service (Annex III point 5), so it is not high risk.",{"slug":151,"title":152,"shortTitle":153,"definition":154,"status":19,"industries":155,"functions":158,"patterns":162,"audience":69,"autonomy":70,"adoptionStage":71,"evidenceCount":163,"publicEvidenceCount":81,"organizations":164,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":169},"procurement-contract-review","AI assistant for procurement and supplier contract review","Procurement and contract review","An assistant for procurement and vendor management that reads supplier contracts and proposals, extracts the key terms, flags deviations from the organization's standard positions, drafts requests for proposal and evaluation matrices, and prepares negotiation positions, with a procurement or legal owner approving every conclusion.",[59,21,156,108,157],"government","manufacturing",[159,160,161],"procurement","legal","finance-and-accounting",[95,30,68,29],6,[165,166,167,168],"General Services Administration","Administration for Children and Families","Internal Revenue Service","Walmart","Contract review and sourcing are not among the Annex III high risk uses, so an internal assistant that makes no decisions about natural persons is minimal risk (with the Article 4 AI literacy duty). If a negotiation bot chats directly with supplier staff, Article 50(1) applies and it must tell them they are dealing with an AI system, unless that is obvious from the context. Public authorities using AI in procurement should still check national public procurement rules on transparency and equal treatment of bidders.",{"slug":171,"title":172,"shortTitle":173,"definition":174,"status":19,"industries":175,"functions":179,"patterns":181,"audience":69,"autonomy":70,"adoptionStage":33,"evidenceCount":163,"publicEvidenceCount":163,"organizations":183,"bestGrade":40,"headline":189,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":195},"developer-coding-assistant","AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[59,21,176,177,178],"capital-markets","technology","professional-services",[180],"it-and-engineering",[182],"code-generation",[184,185,117,186,187,188],"Accenture","ANZ","Citi","CME Group","Meta",{"kpi":190,"label":191,"unit":44,"n":192,"nUpTo":45,"kind":132,"value":193,"qualifier":134,"claimant":99,"organization":99,"vendorReported":11},"productivity-gain","Productivity gain",3,20,"minimal","A coding assistant used by developers is not a prohibited practice under Article 5 and is not listed in Annex III. Developers know they are working with an AI tool, so the Article 50 disclosure duty has no practical effect for the deploying organization, and the marking of generated content under Article 50(2) falls on the tool's provider. What remains is AI literacy (Article 4). Using an AI system to monitor or evaluate individual developers' performance would fall under Annex III point 4(b), and the software the assistant helps build may itself fall under the Act.",{"slug":197,"title":198,"shortTitle":199,"definition":200,"status":19,"industries":201,"functions":202,"patterns":203,"audience":204,"autonomy":32,"adoptionStage":71,"segment":96,"evidenceCount":192,"publicEvidenceCount":192,"organizations":205,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":209},"trade-document-examination","AI examination of trade documents under letters of credit and collections","Trade document examination","AI that reads the full document presentation under a letter of credit or collection (bill of lading, commercial invoice, packing list, certificates), extracts and cross checks the data, tests it against the instructions and the ICC rules (for letters of credit, the credit terms, UCP 600 and ISBP), and lists discrepancies by severity with the rule cited, so qualified examiners focus on the genuine exceptions.",[21],[25,64],[95,66,29,67],"back-office",[206,207,208],"ANZ, HSBC and Lloyds Banking Group","Rand Merchant Bank","Stanbic Bank Uganda","Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.",{"slug":211,"title":212,"shortTitle":213,"definition":214,"status":19,"industries":215,"functions":216,"patterns":217,"audience":204,"autonomy":32,"adoptionStage":71,"segment":204,"evidenceCount":192,"publicEvidenceCount":36,"organizations":218,"bestGrade":221,"headline":222,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":227},"account-servicing-execution","AI for back office account servicing execution","Account servicing execution","AI that executes the servicing requests that land in operations queues, such as address and mandate changes, standing instructions, beneficiary updates, reissues, payoff and reference letters and loan maintenance, by reading the request, checking it against policy and entitlements, and preparing or making the change in core systems under dual control.",[21,60,109],[25,91],[29,95,66],[219,220],"Banco Supervielle","SS&C Technologies","C",{"kpi":223,"label":224,"unit":44,"n":36,"nUpTo":45,"kind":46,"value":225,"qualifier":134,"claimant":226,"organization":220,"vendorReported":12},"processing-time-reduction","Cycle time reduction",95,"vendor","The tier depends on how the system is built. It stays minimal when the agent only executes changes approved by a person and any letter comes from a fixed template, since executing servicing changes is not listed in Annex III. It moves to limited risk when the same system talks to customers directly (the Article 50 transparency duty, described on the customer facing servicing page) or when generative AI drafts the confirmation or letter text: the provider of that generative function, the bank if it builds the system, then carries the Article 50(2) duty to mark the generated content in a machine readable way, unless the output only gets an assistive role or standard editing that does not substantially alter the input data. An AI system used to evaluate the creditworthiness of natural persons, for example to decide on a loan restructuring, is high risk under Annex III point 5(b); keep that assessment outside this agent, which only executes the decided change.",{"slug":229,"title":230,"shortTitle":231,"definition":232,"status":19,"industries":233,"functions":234,"patterns":236,"audience":204,"autonomy":32,"adoptionStage":71,"segment":204,"evidenceCount":192,"publicEvidenceCount":36,"organizations":237,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":240},"chargeback-and-representment","AI for chargeback and representment operations","Chargeback and representment","AI that runs the dispute engine room for issuers, acquirers and merchants: it maps each dispute to the network reason code, gathers the matching evidence, assembles a network compliant chargeback or representment package, drafts the rebuttal, tracks every deadline and processes pre dispute alerts so a refund can be issued before a chargeback lands.",[22,21,108],[25,235,24],"fraud-prevention",[29,95,68,66],[238,239],"GitHub","Visa","Dispute processing between issuers, acquirers and merchants is not listed in Annex III. It is not an evaluation of creditworthiness or credit scoring under Annex III point 5(b), and because cardholders do not interact with the system directly, the Article 50(1) transparency duty for AI that talks to people does not apply. Article 50(2) marking of generated text is a duty of the provider of the AI system that generates it, which includes an institution that builds its own dispute drafting agent and puts it into service under its own name. A drafted rebuttal built from attached case evidence performs an assistive function for standard editing of that evidence and does not substantially alter the underlying input, so it falls under the Article 50(2) exception and does not need machine readable marking. With that point checked, the tier stays minimal. A customer facing intake agent is assessed separately.",{"slug":242,"title":243,"shortTitle":244,"definition":245,"status":19,"industries":246,"functions":247,"patterns":248,"audience":204,"autonomy":32,"adoptionStage":250,"segment":251,"evidenceCount":192,"publicEvidenceCount":192,"organizations":252,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":256},"continuous-controls-testing","AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[59,21,60,176,156],[93,64,25],[29,95,249,66],"anomaly-detection","emerging","second-line",[253,254,255],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation","Testing controls over transactions and systems is not an Annex III use. Controls that monitor and evaluate individual employees' behaviour, such as trading or access conduct, can fall under Annex III point 4(b), so the design decides the tier.",{"slug":258,"title":259,"shortTitle":260,"definition":261,"status":19,"industries":262,"functions":263,"patterns":265,"audience":204,"autonomy":70,"adoptionStage":250,"segment":204,"evidenceCount":80,"publicEvidenceCount":80,"organizations":266,"bestGrade":40,"headline":99,"lastVerified":268,"indexable":12,"euAiActTier":194,"euAiActBasis":269},"fee-and-interest-leakage-detection","AI for fee and interest leakage detection","Fee and interest leakage","An independent verification layer that recomputes what each fee, FX margin, spread and interest charge should have been under the contract and pricing tables, compares it with what was actually billed, and surfaces overcharges and undercharges account by account for correction, customer remediation and revenue recovery.",[21,22,59],[161,264,64,25],"product-and-pricing",[249,29,30],[267],"State Bank of India","2026-09-28","Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.",{"slug":271,"title":272,"shortTitle":273,"definition":274,"status":19,"industries":275,"functions":276,"patterns":277,"audience":204,"autonomy":32,"adoptionStage":33,"segment":204,"evidenceCount":163,"publicEvidenceCount":163,"organizations":278,"bestGrade":40,"headline":285,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":289},"correspondence-triage-and-routing","AI for inbound correspondence triage and routing","Correspondence triage and routing","AI that sorts inbound correspondence before anyone answers it: it takes every inbound letter, email, upload and secure message into one intake, identifies what it is, extracts the key fields, links it to the right customer and account, sets priority and routes it to the right team or workflow, replacing the manual sorting desk.",[59,21,60,156],[25,24,63],[66,95,67],[279,280,281,282,283,284],"Ecclesia Group","Encova Insurance","Loadsure","The Master Trust Bank of Japan","Travelers","U.S. Department of Veterans Affairs",{"kpi":286,"label":287,"unit":44,"n":80,"nUpTo":45,"kind":46,"value":288,"qualifier":134,"claimant":226,"organization":283,"vendorReported":12},"accuracy","Accuracy",91,"It depends on where the system runs. Classifying and routing a bank's or insurer's correspondence is not a use listed in Annex III, so it is minimal risk: the AI literacy duty of Article 4 applies, and the Article 50 duty to tell people they are dealing with AI does not, because the system does not interact with the sender. Used by or for a public authority in a benefits process covered by Annex III point 5(a), the provider can treat it as not high risk only while it performs a narrow procedural or preparatory task under Article 6(3); the provider must then document that assessment before it goes live (Article 6(4)) and register the system in the EU database (Article 49(2)). If the system evaluates eligibility for benefits or profiles the people who write in, it is high risk, so those judgements stay with people.",{"slug":291,"title":292,"shortTitle":293,"definition":294,"status":19,"industries":295,"functions":296,"patterns":297,"audience":69,"autonomy":70,"adoptionStage":71,"evidenceCount":163,"publicEvidenceCount":81,"organizations":298,"bestGrade":40,"headline":303,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":304},"aiops-incident-triage","AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[59,21,177,61,22],[180,25,93],[249,66,67,30,29],[299,188,300,301,302],"Google","Microsoft","Mizuho Financial Group","TD Bank",{"kpi":286,"label":287,"unit":44,"n":192,"nUpTo":45,"kind":132,"value":47,"qualifier":134,"claimant":99,"organization":99,"vendorReported":11},"An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.",{"slug":306,"title":307,"shortTitle":308,"definition":309,"status":19,"industries":310,"functions":311,"patterns":312,"audience":204,"autonomy":32,"adoptionStage":71,"segment":204,"evidenceCount":35,"publicEvidenceCount":35,"organizations":313,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":318},"ledger-and-payment-reconciliation","AI for ledger and payment reconciliation","Ledger and payment reconciliation","AI that matches entries across nostro and vostro statements, card and scheme settlement files, the general ledger and suspense accounts, proposes matches and clearing journals, and routes only the genuine breaks to an operator with a plain language explanation.",[21,22,176,59,109,156],[161,25],[29,249,95],[314,315,316,317],"Comrade Trustee Services","Ginnie Mae","National Bank of Greece (Cyprus)","World Food Programme","Matching entries between internal financial records is not a use listed in Annex III and is not a practice prohibited by Article 5. Operators knowingly use an internal AI tool, so no Article 50(1) disclosure is needed. If a generative model drafts the explanations or journals, the provider of that system may have to mark its output as AI generated under Article 50(2). The AI literacy duty of Article 4 applies to the bank as deployer.",{"slug":320,"title":321,"shortTitle":322,"definition":323,"status":19,"industries":324,"functions":326,"patterns":327,"audience":69,"autonomy":70,"adoptionStage":71,"evidenceCount":163,"publicEvidenceCount":81,"organizations":328,"bestGrade":40,"headline":332,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":334},"legacy-code-modernization","AI for legacy code modernization","Legacy code modernization","AI that reads legacy code such as COBOL, PL/I or old Java, explains what each program does, maps its data flows and dependencies, drafts the equivalent modern code or specification, and generates the regression tests needed to prove the new system behaves like the old one.",[59,21,176,325,177],"automotive",[180],[182,67,29],[116,329,299,330,331],"Amazon","Morgan Stanley","Toyota Motor Europe",{"kpi":223,"label":224,"unit":44,"n":80,"nUpTo":45,"kind":46,"value":333,"qualifier":48,"claimant":49,"organization":299,"vendorReported":11},50,"Tools that analyze, document and translate code are not prohibited practices under Article 5 and are not listed in Annex III, so no high risk obligations apply to the tooling. Engineers and analysts know they are working with an AI tool, including when they query the documentation through a chat assistant, so the Article 50 disclosure duty has no practical effect for the deploying organization. What remains is AI literacy for the staff who use it (Article 4). If the system being modernized is itself an AI system in an Annex III area (for example creditworthiness assessment, point 5(b)), its new version still has to meet the high risk requirements.",{"slug":336,"title":337,"shortTitle":338,"definition":339,"status":19,"industries":340,"functions":341,"patterns":342,"audience":204,"autonomy":32,"adoptionStage":250,"segment":204,"evidenceCount":36,"publicEvidenceCount":36,"organizations":343,"bestGrade":40,"headline":346,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":351},"payment-investigations-and-exceptions","AI for payment investigations and exceptions","Payment investigations and exceptions","AI that works the payments that fall out of straight through processing: it reads the failure, repairs or enriches the message, drafts the ISO 20022 or SWIFT investigation, chases the counterparty bank and proposes a return, recall or correction, while an operator approves anything that moves money.",[21,22],[25,24],[29,95,66,68],[344,345],"BNY","JPMorgan Chase",{"kpi":347,"label":348,"unit":44,"n":80,"nUpTo":45,"kind":46,"value":349,"qualifier":350,"claimant":49,"organization":344,"vendorReported":11},"automation-rate","Automation rate",10,"at-least","Handling payment exceptions is not a use listed in Annex III and is not a prohibited practice under Article 5. If the agent interacts directly with customers, for example in a chat about the case, Article 50(1) requires that they are told they are interacting with an AI system.",{"slug":353,"title":354,"shortTitle":355,"definition":356,"status":19,"industries":357,"functions":358,"patterns":360,"audience":69,"autonomy":70,"adoptionStage":250,"segment":204,"evidenceCount":36,"publicEvidenceCount":36,"organizations":361,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":364},"regulatory-report-assembly","AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[21,60,176,22],[64,161,359],"financial-crime-compliance",[29,249,68,67],[362,363],"Board of Governors of the Federal Reserve System","National Credit Union Administration","Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.",{"slug":366,"title":367,"shortTitle":368,"definition":369,"status":19,"industries":370,"functions":371,"patterns":372,"audience":69,"autonomy":70,"adoptionStage":71,"segment":251,"evidenceCount":35,"publicEvidenceCount":35,"organizations":373,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":377},"vendor-due-diligence","AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[59,21,60,156,22],[159,93,64],[95,30,29,67],[374,167,375,376],"U.S. Department of Justice","U.S. Department of Agriculture","U.S. Trade and Development Agency","Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.",{"slug":379,"title":380,"shortTitle":381,"definition":382,"status":19,"industries":383,"functions":384,"patterns":386,"audience":31,"autonomy":70,"adoptionStage":250,"segment":96,"evidenceCount":36,"publicEvidenceCount":36,"organizations":387,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":389},"corporate-account-onboarding-orchestration","AI orchestration of corporate account opening and channel setup","Corporate onboarding operations","An AI agent that runs the operational setup of a corporate client after the due diligence has been approved: it reads mandates, board resolutions and signatory documents, prepares accounts, users, roles and payment entitlements for approval, configures channel access, and chases outstanding items with the client, turning a manual setup that passes between several teams into a tracked, guided flow.",[21],[385,25],"onboarding-and-kyc",[29,95,27,68],[186,388],"Standard Chartered","Operational setup of accounts and entitlements for corporate clients is not listed in Annex III and makes no decision about a natural person's access to a service or creditworthiness. The agent chases documents directly with client staff, so Article 50(1) applies: the provider must design the system so that they are informed that they are interacting with an AI system, unless that is obvious from the context. A purely internal version without client contact would be minimal risk.",{"slug":391,"title":392,"shortTitle":393,"definition":394,"status":19,"industries":395,"functions":396,"patterns":398,"audience":204,"autonomy":70,"adoptionStage":250,"segment":72,"evidenceCount":35,"publicEvidenceCount":192,"organizations":400,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":403},"portfolio-drift-monitoring-and-rebalancing","AI portfolio drift monitoring and rebalancing proposals","Drift and rebalancing","Continuous monitoring of every client portfolio against its mandate or model, which detects drift beyond agreed bands and prepares a tax aware, low turnover rebalancing proposal with its rationale for an advisor or portfolio manager to approve before any trade is placed.",[109,21],[25,93,397],"analytics-and-reporting",[249,29,399,68],"prediction-and-scoring",[330,401,402],"SimCorp","Vanguard","Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.",{"slug":405,"title":406,"shortTitle":407,"definition":408,"status":19,"industries":409,"functions":411,"patterns":412,"audience":69,"autonomy":413,"adoptionStage":71,"segment":414,"evidenceCount":35,"publicEvidenceCount":36,"organizations":415,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":51,"euAiActBasis":417},"regulatory-horizon-scanning","AI regulatory horizon scanning and obligation mapping","Regulatory horizon scanning","An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.",[59,21,60,22,109,410,156],"pharma-and-life-sciences",[64,160,93],[66,95,30,67,29],"assist","compliance",[416,166],"Financial Conduct Authority","An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.",{"slug":419,"title":420,"shortTitle":421,"definition":422,"status":19,"industries":423,"functions":424,"patterns":425,"audience":31,"autonomy":32,"adoptionStage":71,"segment":34,"evidenceCount":163,"publicEvidenceCount":163,"organizations":426,"bestGrade":40,"headline":431,"lastVerified":435,"indexable":12,"euAiActTier":51,"euAiActBasis":436},"scam-payment-interception","AI scam intervention for instant payments","Scam payment interception","AI that talks to the customer when they are about to authorise an instant payment that looks like a scam: it combines the payee check and the risk score, asks targeted questions about the payment in plain language, explains the specific scam pattern, and holds, delays or escalates the payment to a human specialist when the risk stays high. Unlike fraud scoring, which stops payments the customer did not make, it protects customers from payments they are being manipulated into making.",[21,22],[235,24],[27,399,29,28],[38,427,428,429,129,430],"Mastercard","Revolut","Starling Bank","Westpac",{"kpi":432,"label":433,"unit":44,"n":36,"nUpTo":45,"kind":46,"value":434,"qualifier":134,"claimant":226,"organization":429,"vendorReported":12},"detection-rate-improvement","Detection improvement",300,"2026-09-26","Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.",{"slug":438,"title":439,"shortTitle":440,"definition":441,"status":19,"industries":442,"functions":443,"patterns":444,"audience":69,"autonomy":70,"adoptionStage":71,"evidenceCount":35,"publicEvidenceCount":35,"organizations":445,"bestGrade":40,"headline":99,"lastVerified":50,"indexable":12,"euAiActTier":82,"euAiActBasis":448},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[59,21,60,156,157],[93,64,180],[29,95,30,66],[362,446,447,374],"Office of Management and Budget","Unilever","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",{"slug":450,"title":451,"shortTitle":452,"definition":453,"status":19,"industries":454,"functions":455,"patterns":456,"audience":204,"autonomy":457,"adoptionStage":33,"segment":72,"evidenceCount":458,"publicEvidenceCount":458,"organizations":459,"bestGrade":40,"headline":463,"lastVerified":50,"indexable":12,"euAiActTier":194,"euAiActBasis":467},"real-time-fraud-scoring","Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[21,22],[235],[399,249],"autonomous",9,[460,38,427,75,461,428,462,239],"ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Pay.UK","Stripe",{"kpi":464,"label":465,"unit":44,"n":192,"nUpTo":45,"kind":132,"value":466,"qualifier":134,"claimant":49,"organization":99,"vendorReported":11},"fraud-loss-reduction","Fraud loss reduction",30,"Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.",1790598319320]