Regulation
Australian Scams Prevention Framework and AI use cases
Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.
Read the source text (Australian Treasury)Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI for telecom fraud detection (SIM swap, IRSF and Wangiri)
Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI scam intervention for instant payments
Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI spam and scam call blocking for mobile and landline subscribers
Scoring, blocking and labelling calls is not listed in Annex III, is not a prohibited practice under Article 5, and the system does not interact with people or generate content, so Article 50 does not apply. A conversational scambaiting agent such as O2's Daisy talks to callers with a synthetic voice, which raises separate Article 50 transparency questions and should be assessed on its own.