[{"data":1,"prerenderedAt":2833},["ShallowReactive",2],{"uc-reg-eu-ai-act":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"eu-ai-act","EU AI Act","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",false,true,[14,55,78,104,120,136,154,168,192,207,226,245,266,294,313,329,347,360,380,397,415,435,446,463,478,496,514,529,544,554,564,576,590,605,621,636,652,671,685,699,714,733,754,766,786,802,816,829,841,854,868,879,895,906,919,933,945,959,972,988,1002,1017,1034,1049,1061,1073,1090,1107,1120,1133,1146,1161,1175,1193,1208,1220,1233,1249,1261,1275,1290,1301,1312,1325,1338,1356,1374,1387,1402,1419,1432,1445,1456,1471,1486,1498,1511,1524,1539,1553,1567,1581,1592,1604,1617,1629,1645,1657,1667,1681,1695,1710,1727,1739,1752,1768,1780,1795,1809,1823,1836,1849,1859,1869,1884,1899,1914,1925,1940,1956,1968,1986,1998,2010,2022,2033,2046,2058,2075,2086,2101,2113,2124,2140,2151,2164,2177,2189,2202,2216,2230,2245,2259,2273,2286,2299,2313,2324,2334,2345,2358,2371,2386,2401,2417,2430,2445,2458,2468,2483,2496,2509,2521,2534,2545,2558,2568,2580,2592,2602,2614,2627,2638,2654,2670,2682,2697,2710,2723,2736,2746,2758,2769,2783,2796,2808,2820],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":22,"patterns":25,"audience":30,"autonomy":31,"adoptionStage":32,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":35,"bestGrade":41,"headline":42,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":54},"autonomous-network-operations","Agentic AI for autonomous, intent based network operations","Autonomous network operations","AI agents that run closed loops over a telecom network: they take an intent from the operator (for example a latency or availability target for a service), observe the network, diagnose deviations and execute corrective actions across radio, transport and core, within guardrails set by engineers and with human approval for major changes.","published",[21],"telecommunications",[23,24],"network-operations","it-and-engineering",[26,27,28,29],"agentic-workflow","anomaly-detection","prediction-and-scoring","classification-and-routing","back-office","supervised-agent","emerging","network",6,[36,37,38,39,40],"Deutsche Telekom","du","KDDI","stc Group","Telstra","B",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"processing-time-reduction","Cycle time reduction","percent",1,0,"reported",95,"at-least","organization","2026-09-26","context-dependent","Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk; Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. Loops that only optimise performance or capacity are usually not safety components, but a loop that protects physical integrity or life safety services can be, so operators should assess each closed loop and document the outcome.",{"slug":56,"title":57,"shortTitle":58,"definition":59,"status":19,"industries":60,"functions":62,"patterns":64,"audience":67,"autonomy":68,"adoptionStage":32,"evidenceCount":69,"publicEvidenceCount":69,"organizations":70,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":77},"academic-advising-assistant","AI academic advising assistant for course selection and degree requirements","Academic advising assistant","An AI assistant that answers students' questions about degree requirements, course selection, prerequisites and majors, grounded in the institution's own catalog and advising documents, so students get quick answers to routine questions and are directed to a human advisor for anything that needs judgment, is time sensitive, or falls outside what the assistant can see.",[61],"education",[63],"customer-service",[65,66],"conversational-agent","rag-knowledge-assistant","customer-facing","assist",3,[71,72,73],"Elon University","Harvard College","University of Utah",null,"2026-09-28","limited","An assistant that answers informational questions about courses and requirements, without deciding admission, assigning students to an institution, or evaluating learning outcomes, falls under the transparency duty of Article 50: students must be told they are talking to AI. It would move toward Annex III point 3 (education and vocational training) if it were used to determine access or admission to an institution or programme (point 3(a)), or to evaluate learning outcomes, including when those outcomes are used to steer the learning process (point 3(b)).",{"slug":79,"title":80,"shortTitle":81,"definition":82,"status":19,"industries":83,"functions":86,"patterns":88,"audience":67,"autonomy":31,"adoptionStage":90,"segment":91,"evidenceCount":92,"publicEvidenceCount":93,"organizations":94,"bestGrade":41,"headline":97,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":103},"account-and-card-servicing-agent","AI agent for account and card servicing","Account and card servicing","An AI agent that resolves routine account and card requests end to end, such as balances, statements, card blocks and replacements, PIN resets and limit changes, across app, web, messaging and phone, and hands anything sensitive or unusual to a human with the full context.",[84,85],"banking","payments",[63,87],"operations",[65,89,26,66],"voice-agent","mainstream","front-office",4,2,[95,96],"Commonwealth Bank of Australia","DBS Bank",{"kpi":98,"label":99,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":100,"qualifier":101,"claimant":51,"organization":96,"vendorReported":11},"containment-rate","Containment rate",90,"approximately","2026-09-27","Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.",{"slug":105,"title":106,"shortTitle":107,"definition":108,"status":19,"industries":109,"functions":111,"patterns":113,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":115,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":119},"apartment-leasing-and-resident-service-agent","AI agent for apartment leasing inquiries and resident service","Leasing and resident service agent","An AI agent that answers rental prospects and residents by chat, text, email and phone for a property manager: it answers questions about apartments and policies, books tours, takes maintenance requests, sends renewal and payment reminders, and hands anything that needs judgment to leasing or service staff.",[110],"real-estate",[63,112,87],"sales",[65,89,26,66],"early-adopters",[116,117,118],"Asset Living","AvalonBay Communities","Equity Residential","An agent that answers questions, books tours and takes requests falls under the transparency duty of Article 50. It becomes high risk under Annex III point 5(b) if it evaluates the creditworthiness of applicants, for example in tenant screening, and under point 5(a) if a public body uses it to decide eligibility for social housing or other public assistance.",{"slug":121,"title":122,"shortTitle":123,"definition":124,"status":19,"industries":125,"functions":126,"patterns":127,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":46,"publicEvidenceCount":46,"organizations":128,"bestGrade":41,"headline":130,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":135},"atm-and-self-service-device-assistance","AI agent for ATM and self service device assistance","ATM and device assistance","An AI agent that helps customers with problems at or around ATMs and other self service devices, such as a withdrawal that did not pay out, a retained card, a blocked PIN or finding a working machine with cash, over the app, chat or phone, and that opens and tracks the claim or hands it to a person when it cannot be resolved.",[84],[63,87],[65,89,26],[129],"NatWest Group",{"kpi":131,"label":132,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":133,"qualifier":134,"claimant":51,"organization":129,"vendorReported":11},"customer-satisfaction-uplift","Satisfaction uplift",150,"exact","A customer facing assistant must tell people they are interacting with an AI system unless that is obvious (Article 50(1)). It does not evaluate creditworthiness (Annex III point 5(b)) or eligibility for public assistance benefits (point 5(a)), so it is not high risk; biometric verification whose sole purpose is to confirm identity is excluded from Annex III point 1(a).",{"slug":137,"title":138,"shortTitle":139,"definition":140,"status":19,"industries":141,"functions":145,"patterns":146,"audience":67,"autonomy":147,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":148,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":153},"branch-and-appointment-booking-agent","AI agent for branch finding and appointment booking","Branch and appointment booking","A conversational agent that finds the nearest suitable location, checks opening hours and which services it offers, books an in person or video appointment with the right specialist, and records the reason for the visit so staff are prepared. In banking it answers \"where is my nearest branch\" and books the mortgage or business banker; the same job exists in retail, healthcare and property.",[142,84,143,144,110],"cross-industry","retail-and-ecommerce","healthcare",[63,112],[65,26,66,89],"autonomous",[149,150,151,152],"Bank of America","Best Buy","Hemominas","MOGUL.sg","Article 50(1): people must be told they are interacting with an AI system unless that is obvious. Finding locations and booking appointments does not fall under any Annex III category. If a healthcare version starts to triage patients by urgency, or a public body uses it to decide eligibility for a public service, reassess it against Annex III point 5.",{"slug":155,"title":156,"shortTitle":157,"definition":158,"status":19,"industries":159,"functions":160,"patterns":162,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":92,"publicEvidenceCount":69,"organizations":164,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":167},"card-dispute-and-chargeback-intake","AI agent for card dispute intake","Card dispute intake","A customer facing AI agent that handles the \"I do not recognise this charge\" moment: it finds the transaction, separates suspected fraud from merchant disputes and simple confusion, explains the customer's rights and timelines, collects the details and evidence the rules require, and opens a correctly classified dispute case for the operations team.",[84,85],[63,161,87],"fraud-prevention",[65,89,29,163,26],"document-processing",[95,165,166],"Klarna","Visa","A customer facing assistant must tell people they are interacting with an AI system (Article 50(1)). It triages and opens cases but does not evaluate creditworthiness (Annex III point 5(b), which in any case excludes systems used to detect financial fraud) or decide access to an essential service, so it is not high risk under Annex III.",{"slug":169,"title":170,"shortTitle":171,"definition":172,"status":19,"industries":173,"functions":175,"patterns":178,"audience":181,"autonomy":182,"adoptionStage":114,"segment":183,"evidenceCount":93,"publicEvidenceCount":93,"organizations":184,"bestGrade":41,"headline":186,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":191},"complaints-handling-agent","AI agent for complaints recognition, investigation and response","Complaints handling","An AI agent that recognizes when a customer interaction is a complaint, logs it against the regulatory definition, classifies its root cause and severity, gathers the evidence, drafts the acknowledgement and the response for a human handler to approve, and tracks every statutory deadline until the case is closed.",[142,84,85,174,21],"insurance",[176,63,177],"case-management","regulatory-compliance",[29,179,180,26,66],"summarization","content-generation","employee-facing","copilot","middle-office",[185,129],"Lloyds Banking Group",{"kpi":187,"label":188,"unit":189,"n":46,"nUpTo":47,"kind":48,"value":190,"qualifier":101,"claimant":51,"organization":185,"vendorReported":11},"time-saved-per-task","Time saved per task","minutes",5,"Complaint handling is not listed in Annex III, so internal classification and drafting for a handler who decides is minimal risk. Where the agent talks to customers to take the complaint, Article 50(1) requires telling them they are dealing with AI. Only a system that also assessed creditworthiness or priced life and health insurance (Annex III point 5(b) or 5(c)) would be high risk for that part.",{"slug":193,"title":194,"shortTitle":195,"definition":196,"status":19,"industries":197,"functions":198,"patterns":202,"audience":181,"autonomy":182,"adoptionStage":114,"segment":203,"evidenceCount":93,"publicEvidenceCount":93,"organizations":204,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":206},"credit-memo-drafting-agent","AI agent for corporate credit analysis and credit memo drafting","Credit underwriting and memos","An AI agent that gathers a corporate borrower's documents and data, spreads the financials into the bank's template, calculates ratios and covenant headroom, pulls bureau and news information, and drafts a committee ready credit memo in which every figure links to its source, for the relationship and credit teams to challenge, complete and sign.",[84],[199,200,201],"lending-and-credit","underwriting","risk-management",[163,26,66,180],"specialized-businesses",[205,96],"Banestes","Annex III point 5(b) makes AI used to evaluate the creditworthiness of natural persons high risk. Credit analysis of companies is outside that point, but the tier can change when the same system evaluates the creditworthiness of natural persons, such as sole traders, partners who are personally liable or personal guarantors. Design the scope explicitly and document it.",{"slug":208,"title":209,"shortTitle":210,"definition":211,"status":19,"industries":212,"functions":213,"patterns":215,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":92,"publicEvidenceCount":92,"organizations":217,"bestGrade":41,"headline":222,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":225},"device-and-connectivity-troubleshooting-agent","AI agent for device and connectivity troubleshooting on voice and chat","Device and connectivity troubleshooting","An AI agent that diagnoses and fixes a customer's broadband, mobile, TV or device problem by conversation on the phone or in chat, running line tests and remote resets through the operator's systems, guiding the customer step by step, and booking an engineer or handing over to a technician when the fault needs a person.",[21],[63,214],"field-service",[65,89,26,66,216],"computer-vision",[218,219,220,221],"Singtel","Virgin Media O2","Vodafone Germany","Vodafone",{"kpi":98,"label":99,"unit":45,"n":69,"nUpTo":47,"kind":223,"value":224,"qualifier":134,"claimant":74,"organization":74,"vendorReported":11},"median",70,"A customer facing troubleshooting agent must tell people they are interacting with AI unless that is obvious (Article 50). It is not high risk as long as it is not used as a safety component in the management and operation of critical digital infrastructure (Annex III, point 2); running line tests and resets for one customer's service does not make it one.",{"slug":227,"title":228,"shortTitle":229,"definition":230,"status":19,"industries":231,"functions":233,"patterns":235,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":93,"publicEvidenceCount":93,"organizations":236,"bestGrade":239,"headline":240,"lastVerified":75,"indexable":12,"euAiActTier":243,"euAiActBasis":244},"performance-review-drafting-agent","AI agent for drafting employee performance reviews","Performance review drafting","An assistant that gathers an employee's work history, goals and peer feedback from the systems a manager already uses, and drafts a first version of the performance review for the manager to edit, rewrite or reject, so the manager starts from a grounded summary instead of a blank form and a stack of six months of context to recall from memory.",[142,232],"technology",[234],"human-resources",[180,179,26],[237,238],"Case Status","Rho","C",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":241,"qualifier":134,"claimant":242,"organization":237,"vendorReported":12},84,"vendor","high","Annex III point 4(b) lists AI systems intended to monitor and evaluate the performance and behaviour of workers as high risk. Synthesising an employee's work history and feedback into a performance evaluation is very plausibly profiling of a natural person under GDPR Article 4(4), which expressly covers analysing or predicting a person's \"performance at work\". Article 6(3)'s last subparagraph makes an Annex III system high risk regardless of the derogations whenever it performs such profiling, so a tool built this way is high risk by default however much the manager edits the output. The derogations in Article 6(3), including a narrow procedural task or improving the result of a previously completed human activity, do not fit drafting an evaluation from scratch; the closest is point (d), a preparatory task ahead of a human assessment, which only has a chance of applying to a design that avoids profiling altogether, for example one that only surfaces raw facts without synthesising a judgement. Where that derogation is argued, the documentation duty under Article 6(4) falls on the provider of the system, and only on the deploying organization when it builds the tool itself. Because the tool is high risk by default, Article 26(7) requires informing affected workers and their representatives before it is put into use in the workplace, whatever the tool's output is used for; using the same system's output directly in pay, promotion or termination decisions removes any doubt and triggers the full high risk regime. Annex III's high risk obligations apply from 2 December 2027.",{"slug":246,"title":247,"shortTitle":248,"definition":249,"status":19,"industries":250,"functions":254,"patterns":256,"audience":67,"autonomy":31,"adoptionStage":114,"segment":257,"evidenceCount":69,"publicEvidenceCount":93,"organizations":258,"bestGrade":239,"headline":261,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":265},"collections-and-hardship-agent","AI agent for early collections and hardship support","Collections and hardship agent","A voice and messaging agent that contacts customers in early arrears and answers their inbound calls, takes payments and sets up payment arrangements within preapproved rules, and recognises signs of hardship or vulnerability so those customers go straight to a trained person.",[142,84,85,21,251,252,253],"energy-and-utilities","automotive","professional-services",[255,63],"collections-and-recovery",[89,65,26,29],"lending",[259,260],"Day Knight & Associates","SameDay Auto Finance",{"kpi":262,"label":263,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":264,"qualifier":134,"claimant":242,"organization":260,"vendorReported":12},"cost-reduction","Cost reduction",75,"A customer facing collections agent must disclose that it is AI (Article 50). It is not listed in Annex III as long as it applies preapproved arrangement rules and does not itself evaluate creditworthiness; an affordability model that decides who gets which arrangement for individuals should be assessed separately against Annex III point 5(b).",{"slug":267,"title":268,"shortTitle":269,"definition":270,"status":19,"industries":271,"functions":274,"patterns":275,"audience":67,"autonomy":31,"adoptionStage":90,"segment":91,"evidenceCount":276,"publicEvidenceCount":277,"organizations":278,"bestGrade":41,"headline":290,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":293},"first-line-contact-centre-agent","AI agent for first line contact centre service","First line contact centre","An AI agent that answers the first line of inbound customer contact on phone, chat and messaging, resolves general and routine questions end to end in the customer's own language, and routes everything complex, sensitive or regulated to the right human team with the context attached.",[142,84,85,21,272,143,273],"travel-and-hospitality","wealth-and-asset-management",[63],[65,89,66,29],25,18,[279,280,149,281,282,95,283,284,165,285,286,129,287,288,289,220,221],"Air India","Airbnb","Bank of the Philippine Islands","BT Group","Ingka Group","JetBlue","Lufthansa Group","Mobily","Pegasus Airlines","Telkomsel","Together Credit Union",{"kpi":98,"label":99,"unit":45,"n":291,"nUpTo":47,"kind":223,"value":292,"qualifier":134,"claimant":74,"organization":74,"vendorReported":11},7,47,"An AI system that interacts directly with people must be designed so that they know they are dealing with AI, unless that is obvious from the context (Article 50(1)). It is not high risk under Annex III as long as it does not evaluate eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness (point 5(b)), risk and pricing for life and health insurance (point 5(c)) or emergency calls (point 5(d)). This holds only if emotion or vulnerability signals are inferred from what the customer says (text or transcript content), not from voice or other biometric features; an agent that infers emotion from a caller's voice is an emotion recognition system (Article 3(39)), which is high risk under Annex III point 1(c) and triggers the deployer disclosure duty in Article 50(3).",{"slug":295,"title":296,"shortTitle":297,"definition":298,"status":19,"industries":299,"functions":300,"patterns":302,"audience":67,"autonomy":31,"adoptionStage":114,"segment":301,"evidenceCount":190,"publicEvidenceCount":190,"organizations":303,"bestGrade":41,"headline":309,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":312},"claims-first-notice-of-loss-agent","AI agent for first notice of loss claims intake","First notice of loss agent","An AI agent that takes the first notice of loss from a policyholder by phone, chat or app, identifies the policy, collects the facts of the incident and the evidence the claim type needs, opens the claim in the claims system and tells the customer what happens next, handing complex, injured or vulnerable claimants to a human handler.",[174],[301,63],"claims",[65,89,26,163],[304,305,306,307,308],"DOMCURA","Hippo","Lemonade","Progressive","Travelers",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":100,"qualifier":134,"claimant":242,"organization":304,"vendorReported":12},"accuracy","Accuracy","A customer facing intake agent must be designed so that people know they are interacting with AI (Article 50(1)). Claims intake and claims handling are not listed in Annex III: point 5(c) covers risk assessment and pricing in life and health insurance, not claims. One design choice changes this: detecting distress by inferring emotions from the caller's voice is emotion recognition based on biometric data, which is high risk under Annex III point 1(c) and needs disclosure under Article 50(3). Detecting vulnerability from what the caller says does not. The limited tier assumes that design: every handover signal on this page (injury, distress, anger, vulnerability) is detected from the words of the conversation, and inferring emotions from the voice itself is out of scope.",{"slug":314,"title":315,"shortTitle":316,"definition":317,"status":19,"industries":318,"functions":319,"patterns":320,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":34,"organizations":321,"bestGrade":41,"headline":324,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":328},"flight-disruption-and-rebooking-agent","AI agent for flight disruption and rebooking","Flight disruption and rebooking","An AI agent that tells passengers proactively when their flight is delayed, cancelled or misconnected, explains why, and lets them rebook, request a refund or voucher, or claim care such as meals and hotels in one conversation on app, messaging, web or phone, within the airline's reaccommodation rules and passenger rights, handing complex itineraries and upset customers to a human with the context attached.",[272],[63,87],[65,89,26,180],[279,322,284,285,287,323],"Delta Air Lines","United Airlines",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":327,"qualifier":134,"claimant":242,"organization":279,"vendorReported":12},"automation-rate","Automation rate",97,"A customer facing assistant must tell people they are interacting with AI (Article 50). It is not a high risk use under Annex III: it applies the airline's reaccommodation rules and does not decide on access to an essential public service or on creditworthiness.",{"slug":330,"title":331,"shortTitle":332,"definition":333,"status":19,"industries":334,"functions":335,"patterns":336,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":190,"publicEvidenceCount":190,"organizations":337,"bestGrade":41,"headline":342,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":346},"fraud-alert-confirmation","AI agent for fraud alert confirmation with cardholders","Fraud alert confirmation","A customer facing AI agent that contacts the cardholder as soon as the fraud engine flags a card transaction, in the channel they actually respond to, verifies them, asks whether they made the transaction and acts on the answer: releasing the block so a retry succeeds, or freezing the card and starting the fraud claim.",[84,85],[161,63],[65,89,26],[338,95,339,340,341],"Capital One","Macquarie Bank","Revolut","Westpac",{"kpi":343,"label":344,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":345,"qualifier":134,"claimant":51,"organization":95,"vendorReported":11},"fraud-loss-reduction","Fraud loss reduction",76,"Confirming flagged transactions with cardholders is not listed in Annex III, and point 5(b) expressly excludes AI used to detect financial fraud from the creditworthiness category, so the system is not high risk. An agent that messages or calls customers must tell them they are dealing with AI under Article 50(1), and synthetic voice output must be marked as AI generated under Article 50(2).",{"slug":348,"title":349,"shortTitle":350,"definition":351,"status":19,"industries":352,"functions":353,"patterns":354,"audience":181,"autonomy":31,"adoptionStage":114,"segment":183,"evidenceCount":69,"publicEvidenceCount":93,"organizations":355,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":359},"fraud-alert-triage","AI agent for fraud alert triage","Fraud alert triage","An AI agent that works the fraud alert queue behind the scenes as the analyst's first pass, without contacting the customer: it enriches each alert with customer, device and payment context, closes clear false positives under documented rules, merges duplicates, and routes genuine risk to an analyst with a drafted rationale.",[84,85],[161,87],[26,29,179,28],[356,357],"Coast","SEB","minimal","Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.",{"slug":361,"title":362,"shortTitle":363,"definition":364,"status":19,"industries":365,"functions":367,"patterns":368,"audience":181,"autonomy":31,"adoptionStage":114,"segment":370,"evidenceCount":69,"publicEvidenceCount":69,"organizations":371,"bestGrade":41,"headline":375,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":379},"freight-dispatch-and-load-matching-agent","AI agent for freight dispatch and load matching","Freight dispatch and load matching","An AI agent that does the coordination work behind moving a truckload: reading an emailed quote request and replying with a price, ranking which loads to show which carriers, matching pickup and delivery details to an open dock appointment slot, and chasing the exceptions, so a broker's or carrier's own staff plan lanes and handle disputes instead of typing quotes and making appointment calls.",[366],"logistics-and-transportation",[87],[26,369,163,28],"recommendation-and-personalization","freight-brokerage",[372,373,374],"C.H. Robinson","J.B. Hunt Transport Services","Uber Freight",{"kpi":376,"label":377,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":378,"qualifier":134,"claimant":51,"organization":374,"vendorReported":11},"conversion-rate-uplift","Conversion uplift",12,"Article 50(1) applies whenever the agent interacts directly with a shipper or carrier, for example replying to a quote email or confirming an appointment: the recipient must be able to tell they are dealing with an AI system, unless this is obvious from the context. Article 50(2) is a separate duty on the provider: the generated quote or confirmation text itself must be marked in a machine readable format as artificially generated, and that duty does not apply only where the system performs an assistive function for standard editing or does not substantially alter input data the deployer supplied. Whether dispatch is high risk depends on who is being ranked. Matching freight capacity and pricing a quote for a shipper is not a listed Annex III use. But allocating loads or tasks based on an individual's behaviour in a work related relationship is Annex III point 4(b), so a deployment that ranks or assigns work to a named driver or owner operator based on their own behaviour, for example an asset carrier's employed drivers or a platform ranking owner operators on their clicks, saves and booking history, needs a fresh assessment against that point even though the reference design here scores capacity and price, not a person.",{"slug":381,"title":382,"shortTitle":383,"definition":384,"status":19,"industries":385,"functions":386,"patterns":388,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":389,"bestGrade":239,"headline":394,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":396},"inbound-lead-qualification-agent","AI agent for inbound lead qualification and meeting booking","Inbound lead qualification","An AI agent that engages inbound prospects the moment they arrive on the website, chat, messaging or the sales phone line, answers their first questions, qualifies them against the organization's criteria, and books a meeting or hands a ready conversation to the right salesperson, with the context written into the CRM.",[142,232,252,84],[112,387],"marketing",[65,89,29,26],[390,391,392,393],"8x8","CarMax","Rocket Mortgage","SUSE",{"kpi":376,"label":377,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":395,"qualifier":134,"claimant":242,"organization":390,"vendorReported":12},19,"A customer facing sales agent must make clear that people are talking to an AI system, unless that is obvious (Article 50(1)). Qualifying and routing prospects is not an Annex III use. It becomes high risk where the same system takes on an Annex III task, for example evaluating the creditworthiness of natural persons (Annex III point 5(b)) or assessing risk and pricing for life or health insurance (point 5(c)); those decisions then need the high risk controls.",{"slug":398,"title":399,"shortTitle":400,"definition":401,"status":19,"industries":402,"functions":403,"patterns":404,"audience":67,"autonomy":31,"adoptionStage":114,"segment":405,"evidenceCount":34,"publicEvidenceCount":34,"organizations":406,"bestGrade":41,"headline":412,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":414},"insurance-policy-servicing-agent","AI agent for insurance policy servicing","Policy servicing agent","An AI agent that answers policyholders' coverage questions from their own policy documents and completes routine policy changes and document requests (address and vehicle changes, adding a named driver or item, payment method updates, certificates and proof of cover) across chat, messaging and phone, and hands anything complex or sensitive to a human with the context.",[174],[63,87],[65,89,66,26],"policy-administration",[407,306,408,409,410,411],"LAQO","Nsure.com","Sun Life","Waterdrop","Zurich Insurance (Hong Kong)",{"kpi":98,"label":99,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":413,"qualifier":50,"claimant":51,"organization":306,"vendorReported":11},50,"A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1), applicable from 2 August 2026). It is not high risk as long as it does not carry out risk assessment and pricing in relation to natural persons in life and health insurance (Annex III point 5(c)).",{"slug":416,"title":417,"shortTitle":418,"definition":419,"status":19,"industries":420,"functions":421,"patterns":422,"audience":181,"autonomy":31,"adoptionStage":90,"evidenceCount":423,"publicEvidenceCount":34,"organizations":424,"bestGrade":41,"headline":430,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":434},"it-service-desk-resolution-agent","AI agent for IT service desk resolution","IT service desk resolution","An AI agent in Microsoft Teams, Slack or the intranet that takes the high volume IT support queue, such as password and MFA resets, account unlocks, VPN, device and software requests, and resolves common requests by acting in the identity and IT service management systems, handing the rest to the right resolver group with the context attached.",[142,84,232,143,144],[24,87],[65,26,66,29],8,[425,149,426,427,428,429],"7-Eleven Vietnam","Equinix","IBM","Mercari US","Vituity",{"kpi":431,"label":432,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":433,"qualifier":134,"claimant":242,"organization":428,"vendorReported":12},"employee-adoption","Employee adoption",94,"Article 50(1) requires an assistant that talks with people to make clear they are interacting with AI, unless that is obvious from the context. It is not listed in Annex III. The agent does allocate work, but it routes tickets to resolver and assignment groups based on the content of the request, not to individual workers based on their behaviour or personal traits or characteristics, so Annex III point 4(b) does not apply. It also does not decide on recruitment, promotion, credit or access to essential services. Any use that assigns work to individual analysts, or monitors and evaluates them from their behaviour or performance (including through the agent's logs), would need its own assessment.",{"slug":436,"title":437,"shortTitle":438,"definition":439,"status":19,"industries":440,"functions":441,"patterns":442,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":93,"publicEvidenceCount":46,"organizations":443,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":445},"network-outage-communication-agent","AI agent for network outage detection and customer communication","Outage communication","An AI agent that turns network alarms into a clear picture of which customers are affected by an outage and why, tells them proactively by message, app or phone with a cause and an estimated fix time, answers their questions during the incident, and updates them until service is restored.",[21],[63,23,214],[27,29,180,65,89],[444],"Comcast","The customer facing agent is limited risk with an Article 50 duty to disclose AI. AI used as a safety component in the management and operation of critical digital infrastructure is high risk under Annex III point 2, so the classification depends on whether the detection part acts on the network or only informs people.",{"slug":447,"title":448,"shortTitle":449,"definition":450,"status":19,"industries":451,"functions":452,"patterns":453,"audience":67,"autonomy":31,"adoptionStage":90,"evidenceCount":190,"publicEvidenceCount":190,"organizations":454,"bestGrade":41,"headline":458,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":462},"order-status-and-returns-agent","AI agent for order status, delivery changes and returns","Order status and returns","An AI agent that answers \"where is my order\", changes delivery details and arranges returns, exchanges and refunds end to end for online and omnichannel shoppers, by reading and writing to the order, carrier and returns systems within the retailer's policy, and hands exceptions such as damaged goods, disputes and upset customers to a person.",[142,143,85],[63,87],[65,26,89,66],[455,150,165,456,457],"BARK","Next","Sun & Ski Sports",{"kpi":459,"label":460,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":461,"qualifier":134,"claimant":242,"organization":455,"vendorReported":12},"customer-satisfaction","Customer satisfaction",98,"A customer facing service agent must disclose that the customer is interacting with AI (Article 50). It is not high risk: it does not decide on access to essential services, credit or employment.",{"slug":464,"title":465,"shortTitle":466,"definition":467,"status":19,"industries":468,"functions":470,"patterns":471,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":92,"organizations":472,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":477},"outbound-reminder-and-confirmation-agent","AI agent for outbound reminders and confirmations by voice and messaging","Outbound reminders and confirmations","An AI agent that contacts customers about something they already booked or ordered (an appointment, a delivery, a reservation or a service visit) to remind them, confirm attendance and let them cancel or move it in the same conversation, by phone, SMS, WhatsApp or email. It is operational service outreach, not marketing: nothing is sold, and success is measured in kept appointments and reused slots, not in conversion.",[142,144,469],"government",[63,87],[89,65,26,28],[473,474,475,476],"Sheffield Children's NHS Foundation Trust","University Hospitals Coventry and Warwickshire NHS Trust","U.S. Department of Veterans Affairs","WellSpan Health","People must be told they are interacting with an AI system, and synthetic voice or text must be identifiable as such (Article 50). Reminding people of existing bookings and disclosure alone are limited risk. A missed appointment score used by or for a public authority to grant, reduce, revoke or reclaim access to healthcare or other essential public assistance and services, for example deciding who is offered funded transport, can fall within Annex III point 5(a), and profiling of natural persons within Annex III rules out the Article 6(3) exemption. Using the score only to decide who gets extra reminders or support does not by itself place it outside Annex III when that support is itself the assistance being granted.",{"slug":479,"title":480,"shortTitle":481,"definition":482,"status":19,"industries":483,"functions":484,"patterns":485,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":486,"publicEvidenceCount":291,"organizations":487,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":495},"outbound-sales-prospecting-agent","AI agent for outbound sales prospecting and personalized outreach","Outbound sales prospecting","An AI agent that researches target accounts and contacts, drafts personalized outbound outreach (emails, LinkedIn messages and call scripts) from the campaign, the prospect's context and the sales goals, and sequences the follow ups, with a sales development rep approving or sending every message.",[142,232,253],[112,387],[180,26,369,28],9,[488,489,490,491,492,493,494],"A-LIGN","ANS","Dun & Bradstreet","Lumen Technologies","Merge","Oyster","Unifonic","Drafting outreach that a rep reviews and sends as their own message is typically minimal risk. If the agent holds conversations with prospects itself, for example by replying to emails or calling, people must be told they are interacting with AI (Article 50, limited risk). It is not an Annex III use case.",{"slug":497,"title":498,"shortTitle":499,"definition":500,"status":19,"industries":501,"functions":502,"patterns":503,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":190,"organizations":504,"bestGrade":41,"headline":510,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":513},"parcel-tracking-and-delivery-exception-agent","AI agent for parcel tracking and delivery exceptions","Parcel tracking and delivery exceptions","An AI agent that answers \"where is my parcel\" and resolves delivery exceptions for parcel carriers and postal operators, such as missed deliveries, redelivery or a change of address or pickup point, delays, customs holds and lost or damaged parcel claims, on chat, messaging and phone, and hands disputes and claims above set limits to a human with the tracking history attached.",[366],[63,87],[65,89,26,29],[505,506,507,508,509],"Chronopost","DPD Deutschland","DPD UK","Evri","PostNL",{"kpi":511,"label":512,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":413,"qualifier":134,"claimant":51,"organization":508,"vendorReported":11},"contact-deflection","Contact deflection","Article 50(1): an assistant that talks directly with recipients must be designed so they know they are interacting with an AI system, unless that is obvious from the context. It is not high risk: explaining tracking, changing a delivery and taking in a parcel claim fall under none of the Annex III areas (it does not decide on public assistance benefits, creditworthiness, insurance pricing or employment), and it involves no practice prohibited by Article 5.",{"slug":515,"title":516,"shortTitle":517,"definition":518,"status":19,"industries":519,"functions":520,"patterns":521,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":486,"publicEvidenceCount":34,"organizations":522,"bestGrade":41,"headline":526,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":528},"patient-appointment-scheduling-and-reminders-agent","AI agent for patient appointment scheduling, reminders and no show reduction","Patient scheduling and reminders","An AI agent that books, moves and cancels patient appointments by phone and messaging while following the provider's scheduling rules (referral, triage level, clinician and visit type, preparation), confirms and reminds patients in two way conversations, predicts who is likely to miss an appointment, and offers freed slots to patients on the waiting list. Unlike a general branch and appointment booking agent, it writes into the electronic health record and must respect clinical constraints, so anything clinical goes to staff.",[144],[63,87],[89,65,28,26],[523,524,525,473,474,476],"Audibel","Howard Brown Health","Mid and South Essex NHS Foundation Trust",{"kpi":98,"label":99,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":242,"organization":524,"vendorReported":12},30,"Booking, rescheduling and reminders carry transparency duties: patients must be told they are dealing with AI (Article 50(1)). It becomes high risk if a public authority, or a provider acting on its behalf, uses it to evaluate eligibility for healthcare services (Annex III point 5(a)), or if it acts as an emergency healthcare patient triage system (Annex III point 5(d)). Clinical triage may also make it a medical device, which is high risk under Article 6(1) when the device needs a notified body assessment. Keep the agent to scheduling and use risk scores only to offer support.",{"slug":530,"title":531,"shortTitle":532,"definition":533,"status":19,"industries":534,"functions":535,"patterns":536,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":423,"publicEvidenceCount":291,"organizations":537,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":543},"agentic-payment-initiation","AI agent for payment initiation within a customer mandate","Agentic payment initiation","An AI agent that initiates and completes payments or purchases on a customer's behalf, within a mandate the customer set in advance (spending caps, allowed merchants or categories, a tokenized credential and rules for when to ask for confirmation), and then confirms and reconciles every transaction it made.",[85,84,143],[63,112,87],[26,65],[96,538,539,540,541,542,166],"ING","Majid Al Futtaim","PayPal","Banco Santander","Ulta Beauty","A customer facing agent must make clear that people are dealing with AI, unless that is obvious from the context (Article 50). Initiating payments within a customer's mandate is not listed in Annex III. It becomes high risk if the same agent evaluates creditworthiness, for example by deciding on a buy now pay later or credit line at checkout (Annex III point 5(b)).",{"slug":545,"title":546,"shortTitle":547,"definition":548,"status":19,"industries":549,"functions":550,"patterns":551,"audience":67,"autonomy":147,"adoptionStage":90,"segment":91,"evidenceCount":423,"publicEvidenceCount":69,"organizations":552,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":553},"offers-and-rewards-agent","AI agent for personalized offers and rewards","Offers and rewards","A customer facing AI agent for banks and card issuers that picks the offer, reward or loyalty action most relevant to each customer at each moment from their transactions and context, delivers it in the app, in messaging or through a colleague, and helps the customer understand, track and redeem rewards in conversation. Unlike campaign personalization, it works inside the customer's own account and loyalty relationship, one moment at a time.",[84,85],[387,112,63],[369,28,65],[149,95,96],"Ranking offers is generally minimal risk and the conversational part carries the Article 50 transparency duty. Using AI to evaluate creditworthiness for a credit offer is high risk (Annex III point 5(b)), and Article 5 prohibits techniques that exploit vulnerabilities due to a person's social or economic situation to distort their behaviour in a harmful way.",{"slug":555,"title":556,"shortTitle":557,"definition":558,"status":19,"industries":559,"functions":560,"patterns":561,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":69,"publicEvidenceCount":69,"organizations":562,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":563},"proactive-outbound-engagement-agent","AI agent for proactive customer outreach, activation and retention","Proactive outreach and activation","An AI agent that holds the conversation when a bank reaches out first to change something about the customer's account or products, triggered by an event or a campaign: low balance and fee avoidance alerts, payment and renewal reminders, card activation, dormant account reactivation and offers the customer already qualifies for, over messaging or voice, while the bank's own systems decide who is contacted and why. Reminders about appointments and deliveries the customer booked, and the in app coach the customer opens, are separate use cases.",[84,85],[387,112,63],[65,89,26,369],[149,338,95],"A customer facing agent must disclose that it is AI (Article 50(1)). It stays out of Annex III as long as eligibility for credit offers is decided upstream by the bank's own, separately governed credit processes; if the agent itself assessed creditworthiness it would be high risk under point 5(b).",{"slug":565,"title":566,"shortTitle":567,"definition":568,"status":19,"industries":569,"functions":570,"patterns":571,"audience":67,"autonomy":31,"adoptionStage":32,"evidenceCount":93,"publicEvidenceCount":93,"organizations":572,"bestGrade":239,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":76,"euAiActBasis":575},"public-transit-passenger-information-agent","AI agent for public transit passenger information and disruption reporting","Transit passenger information agent","An AI agent on a public transport operator's website, app or messaging channel that answers riders' real time questions (\"when is my bus coming\", \"why is my train delayed\") from live service data, takes a structured report when something is wrong on board or at a station, and flags urgent or safety related reports for fast human follow up, in the rider's own language.",[366],[63,87],[65,29],[573,574],"Chicago Transit Authority","NJ Transit","Article 50(1): riders must be told they are dealing with an AI system, unless that is obvious from the context. Answering trip questions and logging reports is not a listed Annex III use; it would need a fresh assessment if the same agent decided eligibility for a reduced fare, a concession or paratransit access, which touches access to an essential public service.",{"slug":577,"title":578,"shortTitle":579,"definition":580,"status":19,"industries":581,"functions":582,"patterns":585,"audience":181,"autonomy":182,"adoptionStage":114,"segment":91,"evidenceCount":69,"publicEvidenceCount":69,"organizations":586,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":589},"source-of-wealth-diligence","AI agent for source of wealth due diligence in private banking","Source of wealth diligence","An AI agent that reads a prospective private client's documents, extracts and corroborates how their wealth was built, checks plausibility against benchmarks and external sources, and drafts the source of wealth and enhanced due diligence narrative for the relationship manager and compliance analyst, who decide on the risk rating and the relationship.",[273,84],[583,584],"onboarding-and-kyc","financial-crime-compliance",[163,26,180,179],[587,588],"Bank of Singapore","Deutsche Bank","Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.",{"slug":591,"title":592,"shortTitle":593,"definition":594,"status":19,"industries":595,"functions":596,"patterns":597,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":92,"publicEvidenceCount":92,"organizations":598,"bestGrade":41,"headline":600,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":604},"bill-explanation-and-billing-dispute-agent","AI agent for telecom bill explanation and billing disputes","Bill explanation and disputes","An AI agent that explains a customer's telecom bill line by line, in plain language and on any channel, answers why a charge changed or appeared, corrects clear errors within set limits and opens a billing dispute with the evidence attached when a human has to decide.",[21],[63,176],[65,66,26,89],[282,286,599,221],"Verizon",{"kpi":601,"label":602,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":603,"qualifier":134,"claimant":51,"organization":221,"vendorReported":11},"first-contact-resolution","First contact resolution",60,"A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1)). Explaining bills, correcting clear errors and opening disputes are not listed in Annex III. The tier changes only if the system is also used to evaluate customers' creditworthiness, for example to set credit limits, which Annex III point 5(b) lists as high risk.",{"slug":606,"title":607,"shortTitle":608,"definition":609,"status":19,"industries":610,"functions":612,"patterns":614,"audience":30,"autonomy":31,"adoptionStage":114,"segment":30,"evidenceCount":93,"publicEvidenceCount":93,"organizations":615,"bestGrade":239,"headline":618,"lastVerified":75,"indexable":12,"euAiActTier":243,"euAiActBasis":620},"travel-and-expense-audit-agent","AI agent for travel and expense report audit","Travel and expense audit","An AI agent that checks every travel and expense report line against policy, receipts and prior submissions instead of a small manual sample, flags duplicates, altered receipts and policy violations with the evidence attached, and auto approves the clean majority so auditors spend their time on the reports that are genuinely risky.",[142,611,232],"pharma-and-life-sciences",[613],"finance-and-accounting",[163,27,29,26],[616,617],"Databricks","Takeda",{"kpi":325,"label":326,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":619,"qualifier":134,"claimant":242,"organization":616,"vendorReported":12},72,"Annex III point 4(b) covers AI systems intended to monitor and evaluate the performance and behaviour of persons in a work related relationship. Scoring every line against the employee's own submission history, and instrumenting a repeat flag rate by employee, is that kind of behavioural evaluation, so this design falls under Annex III. The only carve out, Article 6(3), lets a narrow procedural or preparatory task escape high risk with a documented assessment, but the last subparagraph of Article 6(3) removes that carve out whenever the system performs profiling of natural persons. Scoring lines against an individual employee's history is profiling, so the carve out is not available here: keeping a human auditor as the actual decision maker on any personnel action is a required control, not an exit from Annex III.",{"slug":622,"title":623,"shortTitle":624,"definition":625,"status":19,"industries":626,"functions":627,"patterns":628,"audience":67,"autonomy":31,"adoptionStage":32,"segment":301,"evidenceCount":69,"publicEvidenceCount":93,"organizations":630,"bestGrade":41,"headline":633,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":635},"travel-insurance-claims-and-assistance-agent","AI agent for travel insurance claims and assistance","Travel insurance claims and assistance","An AI agent that helps insured travellers around the clock and in their own language: it answers cover questions, takes claims for delays, cancellations, lost baggage and medical costs, reads the receipts and certificates they upload, settles simple claims within set limits, and connects medical emergencies and complex cases to the assistance team at once.",[174,272],[301,63],[65,89,163,26,629],"translation",[631,632],"Allianz Partners","General Insurance Association of Singapore",{"kpi":325,"label":326,"unit":45,"n":47,"nUpTo":46,"kind":48,"value":224,"qualifier":634,"claimant":51,"organization":631,"vendorReported":11},"up-to","A customer facing agent must disclose that it is AI (Article 50), unless this is obvious from the context. Travel insurance claims handling is not listed in Annex III; point 5(c) covers risk assessment and pricing in life and health insurance, not the handling of claims. Handing a traveller who reports a medical emergency to the assistance team is not the classification of emergency calls or the patient triage in point 5(d), as long as the agent only hands over and does not set medical priorities. Claim decisions based solely on automated processing are subject to GDPR Article 22 (and its UK equivalent), and medical data is special category data under Article 9.",{"slug":637,"title":638,"shortTitle":639,"definition":640,"status":19,"industries":641,"functions":642,"patterns":643,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":190,"organizations":644,"bestGrade":41,"headline":650,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":651},"utility-billing-and-move-agent","AI agent for utility billing, payments, meter readings and move in or move out","Utility billing and home moves","An AI agent for energy and water customers that explains bills and tariffs, takes meter readings, sets up or changes payments, and handles move in and move out (final reads, closing one account and opening the next), across phone, messaging, email and the app, while anyone in payment difficulty, in a vulnerable situation or with a complaint is handed to a person.",[251],[63,87],[65,89,26,66],[645,646,647,648,649],"Aydem Energy","Dubai Electricity and Water Authority","EDF","Octopus Energy","Pacific Gas and Electric Company",{"kpi":98,"label":99,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":264,"qualifier":134,"claimant":51,"organization":645,"vendorReported":11},"A customer service agent for bills, readings and moves falls under the transparency duty for systems that interact with people (Article 50(1)): customers must be told they are talking to AI. If the agent assesses creditworthiness, for example to set a deposit when a new customer moves in, that part falls under Annex III point 5(b) and is high risk; keep credit decisions in separately governed systems. The agent is not a safety component in the operation of the gas, water or electricity supply (Annex III point 2), so safety reports such as a gas smell go straight to the emergency line rather than being handled by the agent.",{"slug":653,"title":654,"shortTitle":655,"definition":656,"status":19,"industries":657,"functions":658,"patterns":660,"audience":181,"autonomy":182,"adoptionStage":90,"evidenceCount":69,"publicEvidenceCount":69,"organizations":662,"bestGrade":41,"headline":666,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":670},"ambient-clinical-documentation","AI ambient scribe for clinical documentation","Ambient clinical documentation","An AI scribe that listens, with the patient's consent, to the conversation between a clinician and a patient and drafts the clinical note, and often the letter or after visit summary, for the clinician to review, edit and sign in the health record. It documents; it does not diagnose or decide on treatment.",[144],[87,659],"knowledge-management",[661,179,180],"speech-analytics",[663,664,665],"Great Ormond Street Hospital for Children NHS Foundation Trust","Kaiser Permanente","US Department of Veterans Affairs, Veterans Health Administration",{"kpi":667,"label":668,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":669,"qualifier":134,"claimant":51,"organization":663,"vendorReported":11},"handling-time-reduction","Handling time reduction",8.2,"A scribe that only transcribes and summarises for a clinician to review is not listed in Annex III and is usually minimal risk, although the provider of a system that generates text can still owe the Article 50(2) duty to mark output as AI generated, unless an exception such as an assistive function for standard editing applies. If the product qualifies as medical device software under the EU Medical Device Regulation and needs a notified body assessment, for example because it suggests diagnoses or treatment, it becomes high risk under Article 6(1) and Annex I. Health data in audio and notes falls under GDPR Article 9 in every case.",{"slug":672,"title":673,"shortTitle":674,"definition":675,"status":19,"industries":676,"functions":677,"patterns":679,"audience":30,"autonomy":68,"adoptionStage":114,"segment":680,"evidenceCount":93,"publicEvidenceCount":93,"organizations":681,"bestGrade":239,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":684},"smart-meter-analytics","AI analytics for smart meter and AMI data","Smart meter analytics","AI that turns the flood of readings from smart electricity, gas and water meters into usable information: it monitors meter and network health at scale, estimates which appliances drive a household's usage from the meter signal alone, flags unusual consumption, and targets efficiency and electrification programmes at the customers who will benefit most, instead of a utility treating every meter and every customer the same way.",[251],[87,678],"analytics-and-reporting",[27,28],"metering-and-billing",[682,683],"Consolidated Edison (Con Edison)","Southern California Gas Company (SoCalGas)","Annex III point 2 covers AI systems intended to be used as a safety component in the management and operation of critical digital infrastructure and the supply of water, gas, heating or electricity. Meter health prioritisation and usage disaggregation for programme targeting are not intended as safety components, so they stay outside that scope regardless of whether a person reviews the output. The tier would instead be high risk if the same kind of analytics were intended as a safety component in network operation or supply, for example directly controlling grid or metering protection systems; a human in the loop is then an Article 14 obligation for that high risk system, not a way to fall outside the category.",{"slug":686,"title":687,"shortTitle":688,"definition":689,"status":19,"industries":690,"functions":692,"patterns":693,"audience":67,"autonomy":147,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":694,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":698},"publisher-archive-answer-engine","AI answer engine for readers built on a publisher's own journalism","Publisher archive answer engine","A generative AI search and answer tool on a publisher's own site or app that answers readers' questions only from that publisher's published journalism and archive, cites the articles it used, and declines to answer when its own reporting does not cover the question.",[691],"media-and-entertainment",[63],[66,65,179],[695,696,697],"Financial Times","TIME","The Washington Post","Article 50(1) requires that readers know they are interacting with AI. Article 50(4) requires deployers to disclose AI generated text published to inform the public on matters of public interest, unless the content has undergone human review or editorial control and a person holds editorial responsibility. Whether answers generated on demand for a single reader count as text published to inform the public is open to interpretation, but they are rarely reviewed before readers see them, so the conservative choice is to label them.",{"slug":700,"title":701,"shortTitle":702,"definition":703,"status":19,"industries":704,"functions":705,"patterns":707,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":190,"publicEvidenceCount":190,"organizations":708,"bestGrade":41,"headline":712,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":713},"business-connectivity-quoting-and-service-assistant","AI assistant for B2B telecom quoting, sales and service","B2B quoting and service","An AI assistant that serves business customers of a telecom operator and the sellers who look after them: it answers product, pricing and contract questions, prepares configurations and quotes for connectivity, mobile fleets and devices, drafts responses to tenders, and handles routine service requests and fault tickets, with a sales or service specialist approving anything binding.",[21],[112,63,706],"product-and-pricing",[65,66,26,369,180],[491,709,710,599,711],"SoftBank Corp.","Telefónica España","Vodafone Business",{"kpi":98,"label":99,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":224,"qualifier":134,"claimant":51,"organization":709,"vendorReported":11},"Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Quoting, sales support and service for business customers are not listed in Annex III. The use would become high risk under Annex III point 5(b) only if the assistant itself evaluated the creditworthiness of a natural person, such as a sole trader, to decide whether to offer a contract.",{"slug":715,"title":716,"shortTitle":717,"definition":718,"status":19,"industries":719,"functions":720,"patterns":722,"audience":67,"autonomy":182,"adoptionStage":114,"evidenceCount":291,"publicEvidenceCount":291,"organizations":723,"bestGrade":41,"headline":731,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":732},"benefits-eligibility-and-application-assistant","AI assistant for benefits eligibility questions and applications","Benefits eligibility and application assistant","An AI assistant that helps people understand which public benefits and grants may apply to them, explains the rules and documents in plain language, guides them through the application and checks it for completeness, while the eligibility decision stays with the agency's rules and caseworkers.",[469],[721,176,63],"citizen-services",[65,66,89,163],[724,725,726,727,728,729,730],"Department for Work and Pensions","Federal Student Aid (U.S. Department of Education)","Federal Emergency Management Agency","Gemeente Nissewaard","Leeds City Council","Région Provence-Alpes-Côte d'Azur (Région Sud)","YoungWilliams",{"kpi":310,"label":311,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":327,"qualifier":134,"claimant":51,"organization":724,"vendorReported":11},"Annex III point 5(a) makes AI high risk when it is used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, or to grant, reduce, revoke or reclaim them. An assistant that only explains rules and guides applications carries the Article 50 transparency duties (limited risk); one that screens or scores eligibility falls under point 5(a), and a public body deploying it must carry out a fundamental rights impact assessment first (Article 27).",{"slug":734,"title":735,"shortTitle":736,"definition":737,"status":19,"industries":738,"functions":739,"patterns":740,"audience":67,"autonomy":31,"adoptionStage":90,"evidenceCount":741,"publicEvidenceCount":486,"organizations":742,"bestGrade":41,"headline":752,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":753},"citizen-information-assistant","AI assistant for citizen information and government services","Citizen information assistant","An AI assistant that answers residents' and businesses' questions about government services in plain language, grounded only in official guidance with links to the source, points them to the right online service or office, and hands anything personal, urgent or outside its content to a human with the context attached.",[469],[721,63,659],[66,65,89,29],11,[743,744,745,746,747,748,749,750,751],"Abu Dhabi Government (TAMM)","Driver and Vehicle Licensing Agency","Estonian Information System Authority (RIA)","Foreign, Commonwealth and Development Office","Gemeente Tilburg","Government Digital Service","Government of the City of Buenos Aires","Madrid Destino","Montgomery County Government",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":345,"qualifier":50,"claimant":51,"organization":746,"vendorReported":11},"An information assistant must tell people they are interacting with AI (Article 50). It is not high risk as long as it does not evaluate eligibility for public assistance benefits or services (Annex III point 5(a)); an assistant that starts to pre assess eligibility should be reassessed.",{"slug":755,"title":756,"shortTitle":757,"definition":758,"status":19,"industries":759,"functions":760,"patterns":761,"audience":67,"autonomy":31,"adoptionStage":114,"segment":203,"evidenceCount":190,"publicEvidenceCount":93,"organizations":762,"bestGrade":41,"headline":763,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":765},"corporate-client-servicing-assistant","AI assistant for corporate and commercial client servicing","Corporate client servicing","A conversational assistant inside the corporate banking portal, app and messaging channels that answers finance and treasury teams' servicing questions, such as payment status, balances, cut off times, fees and how to submit an instruction, resolves routine requests end to end and hands the rest to a service specialist who has an AI copilot.",[84,85],[63,87],[65,66,26,179],[149,96],{"kpi":511,"label":512,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":764,"qualifier":134,"claimant":51,"organization":149,"vendorReported":11},16,"A chatbot that interacts with people at client companies must disclose that it is AI (Article 50). It does not evaluate creditworthiness or decide on access to an essential service (Annex III point 5), so it is not high risk.",{"slug":767,"title":768,"shortTitle":769,"definition":770,"status":19,"industries":771,"functions":773,"patterns":775,"audience":181,"autonomy":182,"adoptionStage":114,"segment":91,"evidenceCount":190,"publicEvidenceCount":92,"organizations":776,"bestGrade":41,"headline":781,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":785},"deal-sourcing-and-due-diligence-assistant","AI assistant for deal sourcing and M&A due diligence","Deal sourcing and due diligence","An AI assistant that screens the market for acquisition or investment targets, builds company profiles, and speeds up due diligence by reading data room documents, extracting key terms and risks and drafting the investment or diligence memo, for the deal team to verify and decide.",[772,273,253],"capital-markets",[678,774,201],"legal",[163,179,66,26,28],[777,778,779,780],"Datasite","EQT","Freshfields","Rogo",{"kpi":782,"label":783,"unit":45,"n":47,"nUpTo":46,"kind":48,"value":784,"qualifier":634,"claimant":242,"organization":777,"vendorReported":12},"productivity-gain","Productivity gain",80,"Decision support for professional investors and advisers about companies is not a use listed in Annex III and is not a practice prohibited by Article 5. The users are deal professionals who know they are working with an AI tool, and no consumer interacts with it, so the Article 50(1) duty to disclose an AI interaction has little practical effect. Article 50(2) is different: a firm that builds the assistant itself, including on a platform such as Blits.ai and putting it into service under its own name, is the provider of that system and must mark generated text in a machine readable format, unless the system only performs an assistive function for standard editing or does not substantially alter the input data or its semantics, which may cover extraction and redaction. A firm that instead licenses a vendor product, such as Datasite or Rogo, should confirm that the vendor meets this duty. Obligations are otherwise general: AI literacy for the deal team under Article 4 and, where personal data in the data room is processed, the GDPR.",{"slug":787,"title":788,"shortTitle":789,"definition":790,"status":19,"industries":791,"functions":792,"patterns":793,"audience":67,"autonomy":68,"adoptionStage":114,"segment":203,"evidenceCount":92,"publicEvidenceCount":92,"organizations":795,"bestGrade":41,"headline":800,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":801},"developer-api-integration-assistant","AI assistant for developers integrating a company's APIs","API integration assistant","An AI assistant on a developer portal and in its documentation that answers integration questions, recommends the right endpoints, helps debug connections and generates sample calls, grounded in the API catalogue, reference docs and test material, so clients and partners integrate faster with fewer support tickets.",[142,84,85,232],[24,63,583],[66,65,794],"code-generation",[796,797,798,799],"CircleCI","Mapbox","monday.com","U.S. Bank",{"kpi":511,"label":512,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":51,"organization":797,"vendorReported":11},"A chatbot that interacts with developers must disclose that it is AI (Article 50). Code generation for integration is not listed in Annex III.",{"slug":803,"title":804,"shortTitle":805,"definition":806,"status":19,"industries":807,"functions":808,"patterns":809,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":34,"publicEvidenceCount":69,"organizations":810,"bestGrade":239,"headline":813,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":815},"digital-onboarding-assistant","AI assistant for digital account onboarding and KYC","Digital onboarding","A customer facing AI assistant that guides a new applicant, a person or a small merchant, through a digital account, card or relationship application: it collects and checks identity and supporting documents, orchestrates the know your customer and anti money laundering checks, prefills what it can and sends only the unclear cases to a human reviewer with a summary. The ownership research for complex corporate clients is a separate back office job.",[84,85,273],[583,112,63],[65,163,216,26],[811,588,812],"Albo","M-DAQ Global",{"kpi":782,"label":783,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":242,"organization":812,"vendorReported":12},"multiplier","The conversational assistant falls under the Article 50 transparency duty. Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from the Annex III biometric category. The system becomes high risk when the same journey assesses creditworthiness or a credit score of a natural person, for example for a credit card or overdraft (Annex III point 5(b)).",{"slug":817,"title":818,"shortTitle":819,"definition":820,"status":19,"industries":821,"functions":822,"patterns":823,"audience":181,"autonomy":31,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":69,"organizations":824,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":828},"employee-onboarding-assistant","AI assistant for employee onboarding","Employee onboarding assistant","An assistant that guides each new employee from signed contract through the first months: it answers first week questions in plain language, tracks the personal onboarding checklist, triggers the paperwork, equipment, access and training steps in the systems that own them, and keeps the manager and HR informed of what is still open.",[142,469,253,144],[234,659],[65,66,26],[825,826,827],"American Addiction Centers","KPMG","U.S. Department of Agriculture","Answering onboarding questions and orchestrating provisioning is limited risk: under Article 50(1) the assistant must be designed so that employees are told they are interacting with AI, unless that is obvious. It becomes high risk under Annex III point 4(b) if it is used to make decisions on the terms or termination of the work relationship, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate new hires' performance or behaviour, for example to judge probation.",{"slug":830,"title":831,"shortTitle":832,"definition":833,"status":19,"industries":834,"functions":835,"patterns":836,"audience":181,"autonomy":182,"adoptionStage":32,"segment":91,"evidenceCount":93,"publicEvidenceCount":93,"organizations":837,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":840},"goal-based-financial-planning-assistant","AI assistant for goal based financial planning","Goal based planning","An AI assistant that turns a client's goals into projections and what if scenarios using a rules based planning engine, explains the trade offs in plain language and prepares the plan for an advisor to validate, with every assumption disclosed and reproducible.",[273,84],[112,63,706],[65,180,26],[838,839],"CIMB Niaga","Vanguard","Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).",{"slug":842,"title":843,"shortTitle":844,"definition":845,"status":19,"industries":846,"functions":847,"patterns":848,"audience":181,"autonomy":31,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":92,"organizations":849,"bestGrade":41,"headline":851,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":853},"hr-and-policy-assistant","AI assistant for HR and policy questions","HR and policy assistant","An employee self service assistant that answers questions on leave, pay and tax forms, benefits, expenses, travel and conduct policies from the organization's own HR documents, personalized to the employee's country and role, and starts simple HR transactions such as leave requests or employment letters in the HR system.",[142,84,232,144],[234,659],[66,65,26],[149,427,850,429],"Turing",{"kpi":431,"label":432,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":852,"qualifier":134,"claimant":51,"organization":427,"vendorReported":11},99,"Answering policy questions and starting routine requests is limited risk, with the Article 50 duty to disclose AI. It becomes high risk under Annex III point 4 if it is used to make or support decisions on recruitment, promotion, termination, allocating tasks based on individual behaviour or personal traits, or the monitoring and evaluation of workers; an employer deploying it then must also inform workers' representatives and the affected workers before use (Article 26(7)). Sensitive topic detection should work on what the employee writes: inferring emotions of people in the workplace from biometric data such as voice or facial expressions is prohibited under Article 5(1)(f), except for medical or safety reasons.",{"slug":855,"title":856,"shortTitle":857,"definition":858,"status":19,"industries":859,"functions":860,"patterns":861,"audience":181,"autonomy":68,"adoptionStage":114,"segment":862,"evidenceCount":190,"publicEvidenceCount":190,"organizations":863,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":867},"insurance-broker-and-agent-assistant","AI assistant for insurance brokers and agents","Broker and agent assistant","An AI assistant for tied agents, independent brokers, advisors and the insurer's own distribution staff that answers product, underwriting and process questions from approved sources, prepares personalized customer engagement and follow ups, validates and prioritizes leads, and drafts meeting notes and emails, so producers spend more time with customers.",[174],[112,659],[66,369,180,179],"distribution",[864,865,409,410,866],"Manulife","Prudential plc","Zurich Insurance Group","An employee facing assistant for knowledge answers and drafting is not listed in Annex III and is minimal risk. A lead qualification agent that talks to customers must tell them they are dealing with AI (Article 50). Using performance insights to monitor and evaluate individual agents, or to allocate leads based on their behaviour or traits, is high risk under Annex III point 4(b), and any component that does risk assessment or pricing of life or health insurance for individuals is high risk under Annex III point 5(c).",{"slug":869,"title":870,"shortTitle":871,"definition":872,"status":19,"industries":873,"functions":874,"patterns":875,"audience":181,"autonomy":182,"adoptionStage":32,"segment":91,"evidenceCount":93,"publicEvidenceCount":93,"organizations":876,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":878},"suitability-assessment-assistant","AI assistant for investment suitability assessment and reports","Suitability assessment","An AI assistant that checks whether a proposed product or portfolio fits a client's risk tolerance, objectives, knowledge, experience and financial situation against the firm's rules, flags mismatches, and drafts the suitability rationale and report for the advisor to confirm, while hard rule failures are decided by deterministic checks, not by the model.",[273,84],[177,112,201],[26,180,29],[877,839],"Morgan Stanley","Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.",{"slug":880,"title":881,"shortTitle":882,"definition":883,"status":19,"industries":884,"functions":886,"patterns":888,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":190,"organizations":889,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":894},"procurement-contract-review","AI assistant for procurement and supplier contract review","Procurement and contract review","An assistant for procurement and vendor management that reads supplier contracts and proposals, extracts the key terms, flags deviations from the organization's standard positions, drafts requests for proposal and evaluation matrices, and prepares negotiation positions, with a procurement or legal owner approving every conclusion.",[142,84,469,143,885],"manufacturing",[887,774,613],"procurement",[163,66,180,26],[890,891,892,893],"General Services Administration","Administration for Children and Families","Internal Revenue Service","Walmart","Contract review and sourcing are not among the Annex III high risk uses, so an internal assistant that makes no decisions about natural persons is minimal risk (with the Article 4 AI literacy duty). If a negotiation bot chats directly with supplier staff, Article 50(1) applies and it must tell them they are dealing with an AI system, unless that is obvious from the context. Public authorities using AI in procurement should still check national public procurement rules on transparency and equal treatment of bidders.",{"slug":896,"title":897,"shortTitle":898,"definition":899,"status":19,"industries":900,"functions":901,"patterns":902,"audience":181,"autonomy":182,"adoptionStage":32,"segment":203,"evidenceCount":46,"publicEvidenceCount":46,"organizations":903,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":905},"shariah-compliance-screening","AI assistant for Shariah compliance screening and review","Shariah compliance screening","An AI assistant that screens Islamic financing contracts, deal structures and investments for Shariah compliance risks such as riba, gharar and exposure to prohibited activities, retrieves the relevant standards and fatwas, drafts the Shariah review documentation and flags issues for the Shariah board, which keeps sole authority over any ruling.",[84,273,174],[177,774,706],[66,163,29,180],[904],"Zoya","An internal assistant that screens contracts for compliance with Shariah standards is not listed in Annex III: it assesses contracts, structures and securities, not the creditworthiness of natural persons (Annex III point 5(b)). If a customer facing version answers product questions, it must disclose that people are interacting with an AI system under Article 50(1). National Islamic finance regulators set their own Shariah governance expectations.",{"slug":907,"title":908,"shortTitle":909,"definition":910,"status":19,"industries":911,"functions":912,"patterns":913,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":914,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":918},"student-enrollment-and-services-assistant","AI assistant for student enrollment and student services","Student enrollment assistant","An AI assistant that answers admitted and current students' questions about admissions, financial aid, registration, housing and deadlines by text message and web chat, sends timely reminders for the tasks each student still has to complete, and hands personal or complex cases to staff.",[61],[63,87],[65,66,29],[915,916,917],"Adelphi University","Austin Peay State University","Georgia State University","An assistant that answers questions and sends reminders falls under the transparency duty of Article 50. It becomes high risk under Annex III point 3(a) if it is used to determine access or admission or to assign students to institutions, and under point 3(c) if it assesses the level of education a student will receive. Keep admission and placement decisions with staff.",{"slug":920,"title":921,"shortTitle":922,"definition":923,"status":19,"industries":924,"functions":925,"patterns":926,"audience":67,"autonomy":31,"adoptionStage":90,"evidenceCount":92,"publicEvidenceCount":92,"organizations":927,"bestGrade":41,"headline":930,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":932},"tax-questions-and-filing-assistant","AI assistant for tax questions and filing support","Tax questions and filing assistant","An AI assistant that answers taxpayers' questions about taxes, deadlines, refunds and payments, lets authenticated taxpayers check their status or set up a payment plan within set rules, and guides them through filing, while assessments, penalties and disputes stay with the tax authority's staff and systems.",[469],[721,63,613],[65,89,66,29],[928,929,892],"ClearTax","HM Revenue and Customs",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":931,"qualifier":134,"claimant":51,"organization":929,"vendorReported":11},83.03,"A taxpayer assistant must tell people they are interacting with an AI system (Article 50). It is not listed in Annex III as long as it only informs and applies fixed rules. It becomes high risk under Annex III point 5(a) if it evaluates eligibility for, or grants, reduces, revokes or reclaims, public assistance benefits (which can include benefits paid through the tax system). Recital 59 says systems used for administrative proceedings by tax and customs authorities are not high risk law enforcement systems; audit selection and risk scoring are covered on a separate page.",{"slug":934,"title":935,"shortTitle":936,"definition":937,"status":19,"industries":938,"functions":939,"patterns":940,"audience":67,"autonomy":31,"adoptionStage":32,"segment":91,"evidenceCount":69,"publicEvidenceCount":69,"organizations":941,"bestGrade":41,"headline":943,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":944},"order-to-activation-and-esim-onboarding-assistant","AI assistant for telecom order to activation and eSIM onboarding","Order to activation and eSIM onboarding","An AI assistant that takes a new or existing customer from order to a working service: it collects and checks the order details, guides number porting, eSIM download or SIM activation and installation appointments, tracks the order and fixes or escalates the step that is stuck, on messaging, app, web or phone.",[21],[112,583,63,87],[65,26,29,163],[942,218,599],"Reliance Jio",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":345,"qualifier":134,"claimant":51,"organization":218,"vendorReported":11},"A customer facing assistant must disclose that it is AI (Article 50). Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from remote biometric identification in Annex III point 1(a); creditworthiness assessment of individuals (Annex III point 5(b)) would be high risk and belongs in a separate governed process.",{"slug":946,"title":947,"shortTitle":948,"definition":949,"status":19,"industries":950,"functions":951,"patterns":952,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":486,"publicEvidenceCount":486,"organizations":953,"bestGrade":41,"headline":957,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":958},"plan-upgrade-and-sales-assistant","AI assistant for telecom plan upgrades, add ons and sales","Plan upgrade and sales assistant","An AI assistant that helps existing and prospective customers choose, compare and buy the right mobile, broadband or TV plan, device or extra, in the app, in messaging, on the phone or through a human advisor, using the customer's usage and eligibility and the operator's current offers, and that completes the order or passes a ready quote to a person.",[21],[112,63,387],[369,65,66,89,26],[942,286,954,218,955,956,599,219,221],"Orange France","T-Mobile","Telenet",{"kpi":376,"label":377,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":264,"qualifier":134,"claimant":242,"organization":956,"vendorReported":12},"A sales assistant is limited risk with an Article 50 duty to disclose AI. If it assesses the creditworthiness of individuals for devices on credit, that part is high risk under Annex III point 5(b), so keep credit decisions in the existing governed process. Selling that uses manipulative or deceptive techniques, or exploits a customer's age, disability or economic situation, to materially distort a purchase decision in a way likely to cause significant harm is prohibited under Article 5(1)(a) and (b).",{"slug":960,"title":961,"shortTitle":962,"definition":963,"status":19,"industries":964,"functions":965,"patterns":966,"audience":181,"autonomy":68,"adoptionStage":114,"segment":91,"evidenceCount":69,"publicEvidenceCount":69,"organizations":968,"bestGrade":239,"headline":970,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":971},"retail-store-and-kiosk-assistant","AI assistant for telecom retail stores, from associate copilot to digital human kiosk","Retail store and kiosk assistant","An AI assistant for telecom shops that gives store associates quick, sourced answers on plans, promotions, devices and the customer's account during the conversation, and that can also greet and serve customers directly on an in store screen or kiosk, sometimes as a digital human, handing them to an associate when they are ready to buy or need help.",[21],[112,63,659],[66,967,65,369],"digital-human",[969,36,955],"Bouygues Telecom",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":134,"claimant":242,"organization":969,"vendorReported":12},"A digital human or kiosk that talks to customers must be designed so that they are told they are interacting with an AI system (Article 50(1)). An associate copilot over product content is not listed in Annex III and is minimal risk. Inferring the emotions of employees at work is prohibited (Article 5(1)(f)); emotion recognition of customers by camera is high risk under Annex III point 1(c), biometric categorisation by sensitive or protected attributes is high risk under Annex III point 1(b), and categorisation that infers race, political opinions, religion or sexual orientation is prohibited under Article 5(1)(g). Both need separate legal review.",{"slug":973,"title":974,"shortTitle":975,"definition":976,"status":19,"industries":977,"functions":978,"patterns":980,"audience":181,"autonomy":68,"adoptionStage":114,"segment":203,"evidenceCount":190,"publicEvidenceCount":190,"organizations":981,"bestGrade":41,"headline":986,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":987},"treasury-cash-flow-forecasting","AI cash flow forecasting for corporate treasury","Treasury cash forecasting","Machine learning and conversational analytics, offered by some banks inside their cash management platforms, that categorise a company's cash flows, forecast positions across accounts and currencies, and answer treasurers' questions in plain language, so the treasury team decides on funding and idle balances with better information and less spreadsheet work.",[84,142,366,143,885],[979,613,678],"treasury",[28,29,65,26],[982,149,983,984,985],"Amtrak","Domino's Pizza","JPMorgan Chase","Prysmian",{"kpi":782,"label":783,"unit":45,"n":93,"nUpTo":46,"kind":48,"value":100,"qualifier":101,"claimant":51,"organization":984,"vendorReported":11},"Forecasting a company's cash flows is not listed in Annex III and makes no decision about a natural person, so the forecasting model itself carries no obligations beyond AI literacy (Article 4). The conversational layer interacts directly with treasury staff, so under Article 50(1) they must be informed that they are dealing with an AI system unless that is obvious from the context. Without a conversational layer the use case is minimal risk.",{"slug":989,"title":990,"shortTitle":991,"definition":992,"status":19,"industries":993,"functions":994,"patterns":995,"audience":30,"autonomy":31,"adoptionStage":114,"segment":257,"evidenceCount":92,"publicEvidenceCount":92,"organizations":996,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1001},"sme-cash-flow-underwriting","AI cash flow underwriting for small business loans","SME cash flow underwriting","An underwriting engine that assesses a small business's repayment capacity from live bank transactions, point of sale and payment flows, receivables and accounting data instead of audited accounts, and returns a decision recommendation with the evidence and reasons behind it.",[84],[199,200,201],[28,163,26,65],[997,998,999,1000],"MYbank","National Australia Bank","OakNorth Bank","Sumitomo Mitsui Banking Corporation","Annex III point 5(b) makes AI systems that evaluate the creditworthiness of natural persons or establish their credit score high risk. Scoring a company is outside that point, but a sole trader is a natural person, and a model that also assesses the personal credit of owners, partners or guarantors evaluates natural persons. The tier therefore depends on who the borrower is and whose creditworthiness the model assesses.",{"slug":1003,"title":1004,"shortTitle":1005,"definition":1006,"status":19,"industries":1007,"functions":1008,"patterns":1009,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1010,"bestGrade":41,"headline":1014,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1016},"clinical-trial-patient-matching","AI clinical trial patient matching and prescreening","Clinical trial patient matching","AI that reads structured data and clinical notes in the health record, compares each patient with the inclusion and exclusion criteria of open clinical trials, and gives research staff and treating clinicians a ranked list of likely eligible patients with the evidence for each criterion, so that people confirm eligibility and invite the patient.",[144,611],[87,678],[163,29],[1011,1012,1013],"Cleveland Clinic","Mount Sinai Health System","Yale Cancer Center",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1015,"qualifier":134,"claimant":51,"organization":1011,"vendorReported":11},100,"Prescreening for research that staff verify is not listed in Annex III and is usually minimal risk. The Article 2(6) exclusion covers only systems developed and put into service for the sole purpose of scientific research and development, so an operational recruitment tool used across a health system usually falls inside the Act. If the software recommends trials to a clinician as a treatment option for an individual patient, it may qualify as medical device software under the Medical Device Regulation; where that needs a notified body assessment, it is high risk under Article 6(1). Processing health records for research falls under GDPR Article 9 and national research rules.",{"slug":1018,"title":1019,"shortTitle":1020,"definition":1021,"status":19,"industries":1022,"functions":1023,"patterns":1024,"audience":181,"autonomy":182,"adoptionStage":90,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1025,"bestGrade":41,"headline":1031,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1033},"developer-coding-assistant","AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[142,84,772,232,253],[24],[794],[1026,1027,149,1028,1029,1030],"Accenture","ANZ","Citi","CME Group","Meta",{"kpi":782,"label":783,"unit":45,"n":69,"nUpTo":47,"kind":223,"value":1032,"qualifier":134,"claimant":74,"organization":74,"vendorReported":11},20,"A coding assistant used by developers is not a prohibited practice under Article 5 and is not listed in Annex III. Developers know they are working with an AI tool, so the Article 50 disclosure duty has no practical effect for the deploying organization, and the marking of generated content under Article 50(2) falls on the tool's provider. What remains is AI literacy (Article 4). Using an AI system to monitor or evaluate individual developers' performance would fall under Annex III point 4(b), and the software the assistant helps build may itself fall under the Act.",{"slug":1035,"title":1036,"shortTitle":1037,"definition":1038,"status":19,"industries":1039,"functions":1040,"patterns":1041,"audience":181,"autonomy":68,"adoptionStage":114,"segment":1042,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1043,"bestGrade":41,"headline":1046,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":1048},"hospital-bed-and-staff-capacity-command-center","AI command center for hospital bed and staff capacity planning","Hospital capacity command center","An AI powered operations center that predicts patient admissions, discharges and transfers across a hospital or health system, and helps a team of coordinators sitting in one room sequence real time bed assignments, staffing levels and patient moves, so patients get into the right bed faster and existing capacity is used fully without adding beds.",[144],[87,678],[28,29,27],"hospital operations",[1044,1045],"Humber River Health","Johns Hopkins Medicine",{"kpi":43,"label":44,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1047,"qualifier":134,"claimant":51,"organization":1045,"vendorReported":11},38,"The tier depends on what the system is scoped to do. A design limited to occupancy and discharge forecasting and to sequencing bed assignments for patients already admitted is operational decision support for hospital logistics, outside Annex III. Annex III point 5(d) covers AI used \"to dispatch, or to establish priority in the dispatching of, emergency first response services\", including medical aid and emergency healthcare patient triage systems. On a plain reading, that point can apply when a system dispatches, or sets the priority of dispatching, ambulance or critical care transport itself (work similar to what the Johns Hopkins center's Lifeline transport staff do for helicopter and ambulance transfers), or when it assesses the clinical urgency of an emergency patient, that is, triage. Sequencing which already admitted ED patient gets the next ward bed, and deciding whether to accept an inter hospital transfer request on capacity grounds, are not listed activities under 5(d) as written; whether either counts as dispatching or triage in a given deployment is a case by case legal question, not a settled fact, and should be assessed with counsel before relying on this tier. For public hospitals, Annex III point 5(a) (access to essential public services, including healthcare) can also be relevant. Scoping the system to bed sequencing and transfer acceptance only, and keeping every ambulance dispatch and ED triage decision with clinical staff outside the AI's recommendation, is what keeps a deployment in the lower tier.",{"slug":1050,"title":1051,"shortTitle":1052,"definition":1053,"status":19,"industries":1054,"functions":1055,"patterns":1056,"audience":181,"autonomy":182,"adoptionStage":114,"segment":203,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1057,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1060},"client-briefing-and-call-report-copilot","AI copilot for corporate client briefings and call reports","Client briefing and call reports","An AI copilot for relationship managers, mainly in corporate and commercial banking, whose main job is preparation: before a client meeting it assembles a briefing pack from filings, news, internal notes, product holdings and upcoming maturities, and afterwards it turns the banker's notes into a structured call report and CRM update. Unlike a meeting notetaker, which centres on capturing the conversation, it centres on the credit and cross sell context around the meeting; wealth advisor tools that also prepare meetings overlap with it. The banker reviews every output.",[84,273,772],[112,659],[66,179,180,26],[149,1058,1059],"Scotiabank","Standard Chartered","Bankers interact with the copilot directly, but Article 50(1) does not bite here: it requires telling people they are dealing with an AI system unless that is obvious to a reasonably well informed person, and an internal tool that is openly presented and labelled as an AI assistant meets that bar by design. The copilot never interacts with the client. Article 50(2) marking of generated text falls on the provider of the system, including a bank that builds it in house, but the copilot turns a banker's own notes into a call report, an assistive function for standard editing of the banker's input that does not substantially alter it, so the Article 50(2) exception applies and no machine readable marking is required. It is not an Annex III use: credit context about corporate clients is not the creditworthiness assessment of natural persons in Annex III point 5(b), so it falls outside the high risk tier. If a deployment starts to score individuals for credit, the tier changes. AI literacy duties under Article 4 still apply. If meeting capture is used, recording and transcription rules under data protection law apply separately.",{"slug":1062,"title":1063,"shortTitle":1064,"definition":1065,"status":19,"industries":1066,"functions":1067,"patterns":1068,"audience":181,"autonomy":182,"adoptionStage":32,"segment":33,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1069,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1072},"field-technician-copilot-and-dispatch","AI copilot for field technicians and dispatch optimization","Field technician copilot and dispatch","AI that decides whether a fault needs a site visit at all, predicts what work and parts a job will need, helps plan and update appointments, and gives technicians on site guided diagnosis and instant answers from manuals and past jobs, so more jobs are fixed on the first visit.",[21],[214,87,63],[28,66,65,29],[1070,1071],"nbn","Openreach","Triage and a knowledge copilot for technicians are normally minimal risk. Annex III point 4(b) lists AI systems that allocate tasks based on individual behaviour or personal traits, or that monitor and evaluate the performance and behaviour of workers, as high risk, so dispatch systems that do this need the full high risk controls, and under Article 26(7) employers must inform workers' representatives and the affected workers before using them. A conversational assistant that answers customers directly carries the Article 50 duty to tell people they are dealing with AI.",{"slug":1074,"title":1075,"shortTitle":1076,"definition":1077,"status":19,"industries":1078,"functions":1079,"patterns":1080,"audience":181,"autonomy":31,"adoptionStage":114,"segment":1081,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1082,"bestGrade":239,"headline":1085,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":1089},"hotel-revenue-management-copilot","AI copilot for hotel revenue management","Hotel revenue management copilot","An employee facing AI system that forecasts demand for a hotel or portfolio by date, room type and segment, recommends or automatically adjusts room prices and availability controls within limits a revenue manager sets, and scores group and event enquiries for true profitability, so a small revenue team can run pricing that used to need daily manual adjustment in the property management system.",[272],[706,678],[28,26],"revenue-management",[1083,1084],"Hôtel Swexan","RIMC Hotels & Resorts Group",{"kpi":1086,"label":1087,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1088,"qualifier":134,"claimant":242,"organization":1083,"vendorReported":12},"revenue-uplift","Revenue uplift",33,"A demand forecasting and pricing tool used by hotel staff is not listed in Annex III and is not a system that decides on a natural person's access to an essential service; it prices a hotel room, not a person. It is not customer facing, so the Article 50 transparency duty for conversational AI does not apply. The AI literacy obligation on staff who use AI systems (Article 4) still applies.",{"slug":1091,"title":1092,"shortTitle":1093,"definition":1094,"status":19,"industries":1095,"functions":1096,"patterns":1097,"audience":181,"autonomy":182,"adoptionStage":114,"segment":1098,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1099,"bestGrade":41,"headline":1105,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1106},"insurance-pricing-and-actuarial-copilot","AI copilot for insurance pricing and actuarial analysis","Pricing and actuarial copilot","AI that speeds up the work of pricing and actuarial teams, from automated, transparent risk and demand model building to natural language analysis of rate filings, experience data and reserving diagnostics, while actuaries select the models, sign off the rates and own the professional judgment.",[174],[706,201,678],[28,794,26,179],"pricing",[1100,1101,1102,1103,1104],"Accelerant Holdings","Europ Assistance","Generali France","Kinsale Capital Group","MAIF",{"kpi":782,"label":783,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":190,"qualifier":134,"claimant":51,"organization":1102,"vendorReported":11},"Pricing and risk assessment of natural persons for life and health insurance is high risk under Annex III point 5(c). Pricing for property and casualty products, and actuarial analysis that does not price individuals, are not listed, although supervisors still expect sound model governance.",{"slug":1108,"title":1109,"shortTitle":1110,"definition":1111,"status":19,"industries":1112,"functions":1113,"patterns":1114,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":69,"organizations":1115,"bestGrade":41,"headline":1117,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1119},"marketing-content-compliance-copilot","AI copilot for marketing content with compliance pre review","Marketing content and compliance","A copilot that drafts campaign copy, product explainers and social posts on brand and in the customer's language from approved product facts, then runs a first pass compliance check against advertising rules and required disclosures, flagging unsupported claims and missing warnings before a human in marketing compliance approves publication.",[142,84,174,85,273,611],[387,177,774],[180,66,29,629],[1116,984,165],"Ally Financial",{"kpi":782,"label":783,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1118,"qualifier":134,"claimant":51,"organization":1116,"vendorReported":11},34,"An internal drafting and review aid that makes no decisions about people. Article 50 transparency duties apply to generated content: providers must mark synthetic content, and deployers must disclose deep fake images, audio or video. Personalized targeting of individuals is governed mainly by data protection and consumer law rather than the AI Act.",{"slug":1121,"title":1122,"shortTitle":1123,"definition":1124,"status":19,"industries":1125,"functions":1126,"patterns":1127,"audience":181,"autonomy":182,"adoptionStage":32,"segment":1128,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1129,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":1132},"model-risk-validation-copilot","AI copilot for model risk validation and monitoring","Model risk validation","A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.",[84,174,772,273],[201,177],[26,163,180,27],"second-line",[1130,1059,1131],"European Central Bank (ECB Banking Supervision)","United Overseas Bank (UOB)","A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.",{"slug":1134,"title":1135,"shortTitle":1136,"definition":1137,"status":19,"industries":1138,"functions":1139,"patterns":1140,"audience":181,"autonomy":182,"adoptionStage":114,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1141,"bestGrade":41,"headline":1144,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1145},"network-fault-triage-copilot","AI copilot for network operations centre fault triage","NOC fault triage copilot","AI in the network operations centre (NOC) that correlates alarms and performance data from radio, transport, core and fixed networks into a small number of probable faults, ranks them by customer impact, proposes the likely root cause and fix from runbooks, vendor documentation and past tickets, and routes the ticket to the right team, while an engineer decides what to change.",[21],[23,87],[27,29,66,179,26],[1142,36,38,1143,40,221],"Bell Canada","Orange",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"The main test is Annex III point 2, which lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk. A copilot that prepares diagnoses for engineers who decide every change is normally not such a safety component, and is then minimal risk. The tier rises when the system is designed to protect the safe operation of the network, for example by acting on it automatically to prevent or contain outages. Article 6(3) can exempt an Annex III system that only performs a preparatory task to an assessment and poses no significant risk of harm, provided the provider documents that assessment and registers the system.",{"slug":1147,"title":1148,"shortTitle":1149,"definition":1150,"status":19,"industries":1151,"functions":1152,"patterns":1153,"audience":181,"autonomy":68,"adoptionStage":114,"segment":1154,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1155,"bestGrade":41,"headline":1159,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1160},"plant-operator-and-maintenance-copilot","AI copilot for plant operators and maintenance technicians","Plant operator and maintenance copilot","A generative AI assistant for the people who run and repair machines in plants, workshops and service centres: it answers fault and procedure questions from equipment manuals, fault reports, shift logs and live machine data, in the technician's language, with links to the sources, so faults are diagnosed faster and expert knowledge is not lost when experienced staff retire.",[885,252],[87,659],[66,65,179,629],"production",[1156,1157,1158],"BMW Group","Georgia-Pacific","Textron Aviation",{"kpi":187,"label":188,"unit":189,"n":47,"nUpTo":46,"kind":48,"value":277,"qualifier":634,"claimant":242,"organization":1158,"vendorReported":12},"Article 50(1): staff must know they are interacting with an AI system, unless that is obvious from the context. Answering maintenance questions is not an Annex III use. It would become high risk under Annex III point 4(b) if the usage data were used to monitor and evaluate the performance of individual workers, so keep usage analytics aggregated.",{"slug":1162,"title":1163,"shortTitle":1164,"definition":1165,"status":19,"industries":1166,"functions":1167,"patterns":1168,"audience":181,"autonomy":182,"adoptionStage":32,"segment":183,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1169,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":1174},"suspicious-activity-report-drafting","AI copilot for SAR and STR narrative drafting","SAR and STR drafting","Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.",[84,85],[584,176],[180,179,66,26],[1170,1171,1172,1173],"Finshark","BMO and Amalgamated Bank","Nexo","Uphold","Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.",{"slug":1176,"title":1177,"shortTitle":1178,"definition":1179,"status":19,"industries":1180,"functions":1181,"patterns":1182,"audience":181,"autonomy":182,"adoptionStage":114,"segment":200,"evidenceCount":423,"publicEvidenceCount":423,"organizations":1183,"bestGrade":41,"headline":1191,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1192},"underwriting-risk-assessment-copilot","AI copilot for underwriting risk assessment","Underwriting risk assessment copilot","A copilot that assembles everything relevant to a risk (the submission, loss history, internal guidelines, third party data and public information), highlights exposures and gaps against the insurer's underwriting guidelines and drafts the underwriting narrative or referral note, while the underwriter makes and signs every decision.",[174],[200,201],[66,179,180,26],[1100,1184,1185,1186,1187,1188,1189,1190],"American International Group","Arch Capital Group","Bowhead Specialty","Generali Global Corporate & Commercial","Hiscox","Skyward Specialty Insurance Group","Zurich North America",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":413,"qualifier":134,"claimant":242,"organization":1187,"vendorReported":12},"For commercial property and casualty lines the copilot is not listed in Annex III. Used for risk assessment of natural persons in life or health insurance it falls under Annex III point 5(c) and is high risk, with risk management, data governance, logging and human oversight duties, and deployers must carry out a fundamental rights impact assessment under Article 27.",{"slug":1194,"title":1195,"shortTitle":1196,"definition":1197,"status":19,"industries":1198,"functions":1199,"patterns":1200,"audience":30,"autonomy":31,"adoptionStage":114,"segment":257,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1201,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":243,"euAiActBasis":1207},"alternative-data-credit-scoring","AI credit scoring with alternative data for thin file applicants","Alternative data credit scoring","A machine learning credit model that adds consumer permissioned alternative data, such as bank account cash flow, rent, utility and telco payments or ecosystem data, to credit bureau data, so a lender can assess applicants with thin or no credit files and return a decision with specific reasons.",[84,85],[199,200,201],[28,163,65],[1202,1203,1204,1205,1206],"Atlanticus","Golden 1 Credit Union","GXS Bank","Patelco Credit Union","Upstart Network","Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).",{"slug":1209,"title":1210,"shortTitle":1211,"definition":1212,"status":19,"industries":1213,"functions":1214,"patterns":1215,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1216,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1219},"airline-operations-control-decision-support","AI decision support for airline operations control and disruption recovery","Airline operations control","Decision support in an airline's operations control center that watches the day's operation, predicts where weather, delays, crew limits or technical problems will break the plan, and proposes recovery options across aircraft, crew and passengers, such as retiming flights, swapping aircraft or holding a connection, with the cost and passenger impact of each, for controllers to approve.",[272],[87],[28],[1217,1218],"American Airlines","Swiss International Air Lines","Recommending schedule, aircraft and passenger recovery plans to controllers is not listed in Annex III. Annex III point 4(b) covers AI used to make decisions affecting terms of work relationships, to allocate tasks based on individual behavior or personal traits or characteristics, or to monitor and evaluate the performance and behavior of workers. A design that reassigns individual crew members on such grounds, or that scores controllers or crew on their performance, falls in that category; one that works on flights, aircraft and crew legality and qualifications alone is less likely to, although assigning duties by qualification can still touch terms of work. The tool is not itself a safety component of an aircraft or other product regulated under Regulation (EU) 2018/1139, which Annex I Section B lists, so that route to high risk does not normally apply. Decisions that affect flight safety stay under aviation safety regulation and the airline's approved procedures; keep crew legality and maintenance limits as hard rules outside the model.",{"slug":1221,"title":1222,"shortTitle":1223,"definition":1224,"status":19,"industries":1225,"functions":1226,"patterns":1227,"audience":30,"autonomy":31,"adoptionStage":90,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1228,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1232},"retail-demand-forecasting-and-replenishment","AI demand forecasting and automated replenishment for retail","Demand forecasting and replenishment","Machine learning that forecasts demand for every item in every store or fulfillment center, day by day, from sales history, promotions, prices, weather and local events, and turns the forecast into automatic store and warehouse orders within limits set by planners, who handle the exceptions.",[143],[87,678],[28,27],[1229,1230,1231,893],"Albert Heijn","Morrisons","One Stop","Forecasting product demand and ordering stock is not listed in Annex III. It would become high risk under Annex III point 4(b) only if the same system allocated tasks to employees based on their individual behavior or personal traits, or monitored and evaluated their performance, for example scheduling store staff by individual productivity. GDPR applies only when loyalty or customer level data feeds the forecasts; item and store aggregates on their own are not personal data.",{"slug":1234,"title":1235,"shortTitle":1236,"definition":1237,"status":19,"industries":1238,"functions":1239,"patterns":1240,"audience":30,"autonomy":31,"adoptionStage":90,"evidenceCount":291,"publicEvidenceCount":190,"organizations":1241,"bestGrade":41,"headline":1247,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1248},"intelligent-document-processing","AI document intelligence for unstructured forms and documents","Intelligent document processing","AI that takes documents in any format, such as scanned forms, PDFs, photos, emails and handwritten notes, splits and classifies them, extracts the required fields with a confidence score, validates them against business rules and source systems, and sends only the uncertain cases to a person before the data enters the downstream process.",[142,469,252,885],[87,176,613],[163,216,29],[1242,1243,1244,1245,1246],"Ancine","Pupuk Indonesia","U.S. Immigration and Customs Enforcement","U.S. Citizenship and Immigration Services","Volvo Group",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":100,"qualifier":50,"claimant":242,"organization":1242,"vendorReported":12},"Classifying documents and extracting data for a person or process to use is usually minimal risk. Even inside an Annex III area, a system that only performs a narrow procedural task, such as splitting and classifying documents, can fall outside the high risk category under Article 6(3); the provider must document that assessment and register the system (Article 6(4) and Article 49(2)). The picture changes when extraction materially influences decisions in Annex III areas, such as eligibility for public assistance benefits (point 5(a)), creditworthiness (point 5(b)) or asylum, visa and residence permit applications (point 7), where the whole system must be assessed as potentially high risk. The Article 6(3) exception never applies when the system performs profiling of natural persons.",{"slug":1250,"title":1251,"shortTitle":1252,"definition":1253,"status":19,"industries":1254,"functions":1255,"patterns":1256,"audience":181,"autonomy":182,"adoptionStage":32,"segment":257,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1257,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1260},"adverse-action-explanations","AI drafted explanations for credit declines and adverse actions","Adverse action explanations","An assistant that turns the reason codes of a credit model into an accurate, specific and readable explanation of a decline, reduced limit or repricing for the customer, and a matching internal rationale for the file, without adding any reason the model did not produce.",[84,85],[199,177,63],[180,66,65],[1258,1259],"Discover Financial Services","Wells Fargo","The drafting assistant does not assess creditworthiness, so on its own it is not the Annex III point 5(b) credit scoring system. It helps the lender meet the Article 86 right of affected people to a clear and meaningful explanation of decisions based on such a high risk system. If it is built into the scoring system it shares that system's high risk obligations; as a separate drafting tool its tier depends on its design and on how its output is reviewed. The follow up chat assistant must tell customers they are dealing with an AI system (Article 50).",{"slug":1262,"title":1263,"shortTitle":1264,"definition":1265,"status":19,"industries":1266,"functions":1267,"patterns":1268,"audience":181,"autonomy":182,"adoptionStage":32,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1269,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1274},"civil-servant-drafting-copilot","AI drafting copilot for civil servants for correspondence, briefings and ministerial replies","Civil servant drafting copilot","A generative AI assistant that drafts replies to correspondence from the public and elected representatives, briefings, submissions and summaries for civil servants, grounded in the department's approved lines, policy documents and case data, with the official editing and approving every word before it is sent or cleared.",[469],[721,659,176],[180,66,179],[1270,1271,1272,1273,748],"Cabinet Office (Government Communication Service)","Crown Prosecution Service","Department for Education","Department for Science, Innovation and Technology (Incubator for Artificial Intelligence)","An internal drafting assistant that an official reviews is not listed in Annex III. Article 50(4) requires disclosure of AI generated text published to inform the public on matters of public interest, unless it has undergone human review and a person holds editorial responsibility, which this design provides. If the tool is used to evaluate eligibility for public assistance benefits or services rather than to draft, Annex III point 5(a) can apply.",{"slug":1276,"title":1277,"shortTitle":1278,"definition":1279,"status":19,"industries":1280,"functions":1281,"patterns":1282,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1283,"bestGrade":41,"headline":1286,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1289},"clinical-and-regulatory-document-drafting","AI drafting of clinical study reports and regulatory documents","Clinical and regulatory document drafting","Generative AI that drafts clinical study reports and other regulated documents, such as protocols, patient materials and submission modules, from the trial's statistical tables, listings and figures and from approved template text, for medical writers to verify, edit and approve before anything is submitted to a regulator.",[611],[177,87],[180,66,163],[1284,1285],"Merck & Co.","Novo Nordisk",{"kpi":1287,"label":1288,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":413,"qualifier":134,"claimant":51,"organization":1284,"vendorReported":11},"error-reduction","Error reduction","Drafting regulated documents for expert review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the sponsor's role under Article 50. A sponsor that deploys a third party drafting tool has no specific AI Act obligations beyond AI literacy: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which clinical study reports and regulatory submissions are not. For that sponsor the tier is minimal. A sponsor that builds its own generating system, as Merck (a proprietary platform) and Novo Nordisk (NovoScribe) did, is its provider under Article 50(2) and must mark the synthetic text in a machine readable format, unless the exemption for an assistive function for standard editing applies; drafting whole report sections goes beyond that exemption, so for that sponsor the tier is limited. Quality expectations come from medicines regulation and EMA guidance: the EMA reflection paper expects close human supervision and quality review when AI drafts medicinal product information documents, and makes the clinical trial sponsor, marketing authorisation applicant or holder, or manufacturer responsible for ensuring that models and data pipelines are fit for purpose and meet GxP standards and EMA guidelines.",{"slug":1291,"title":1292,"shortTitle":1293,"definition":1294,"status":19,"industries":1295,"functions":1296,"patterns":1297,"audience":181,"autonomy":68,"adoptionStage":114,"segment":257,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1298,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1300},"credit-early-warning-monitoring","AI early warning and covenant monitoring for loan portfolios","Credit early warning and covenants","A monitoring system that tracks covenant tests and borrower reporting across a loan book, reads financials, filings and news, and combines them with payment and sector signals to flag borrowers whose credit is deteriorating, with the evidence and a suggested next step for the relationship manager.",[84],[201,199],[27,163,26,179],[999,1299,1000],"PNC Financial Services","Monitoring the credit of companies is not listed in Annex III. Where the same system evaluates the creditworthiness of natural persons, such as sole traders or personal guarantors, it falls under Annex III point 5(b) and is high risk; because that evaluation profiles natural persons, the Article 6(3) exemption does not apply.",{"slug":1302,"title":1303,"shortTitle":1304,"definition":1305,"status":19,"industries":1306,"functions":1307,"patterns":1308,"audience":181,"autonomy":68,"adoptionStage":90,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1309,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1311},"enterprise-knowledge-search","AI enterprise knowledge search for employees","Enterprise knowledge search","An assistant that lets any employee ask a question in plain language and get a synthesized answer from the organization's own policies, procedures, product manuals and research, with citations to the source documents and only from documents the employee is allowed to see.",[142,84,273,174,469,253],[659,87,63],[66,65,179],[149,877,1310,1259],"SIGNAL IDUNA","Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant. The system would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)) or making decisions on or evaluating workers (point 4(b)).",{"slug":1313,"title":1314,"shortTitle":1315,"definition":1316,"status":19,"industries":1317,"functions":1318,"patterns":1319,"audience":30,"autonomy":31,"adoptionStage":114,"segment":203,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1320,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1324},"trade-document-examination","AI examination of trade documents under letters of credit and collections","Trade document examination","AI that reads the full document presentation under a letter of credit or collection (bill of lading, commercial invoice, packing list, certificates), extracts and cross checks the data, tests it against the instructions and the ICC rules (for letters of credit, the credit terms, UCP 600 and ISBP), and lists discrepancies by severity with the rule cited, so qualified examiners focus on the genuine exceptions.",[84],[87,177],[163,29,26,179],[1321,1322,1323],"ANZ, HSBC and Lloyds Banking Group","Rand Merchant Bank","Stanbic Bank Uganda","Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.",{"slug":1326,"title":1327,"shortTitle":1328,"definition":1329,"status":19,"industries":1330,"functions":1331,"patterns":1332,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":423,"publicEvidenceCount":34,"organizations":1333,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1337},"financial-wellbeing-coach","AI financial wellbeing coach in the banking app","Financial wellbeing coach","An in app AI assistant that the customer opens to understand their own money: it uses the customer's transaction data to explain their spending, forecast upcoming bills and cash flow, set and track savings goals and answer money questions in plain language, staying on the guidance side of the line between guidance and regulated financial advice.",[84],[63,387],[65,369,28,26],[149,95,1334,1335,1336,341],"Hyundai Card","Royal Bank of Canada","Starling Bank","The conversational assistant carries the Article 50 transparency duty: customers must be told they are interacting with an AI system. The system becomes high risk if it is used to evaluate the creditworthiness of natural persons or establish their credit score (Annex III point 5(b)). Article 5(1)(b) prohibits AI that exploits vulnerabilities due to a person's specific social or economic situation to materially distort their behaviour in a way that causes, or is reasonably likely to cause, significant harm.",{"slug":1339,"title":1340,"shortTitle":1341,"definition":1342,"status":19,"industries":1343,"functions":1344,"patterns":1345,"audience":181,"autonomy":31,"adoptionStage":114,"segment":183,"evidenceCount":423,"publicEvidenceCount":423,"organizations":1346,"bestGrade":41,"headline":1351,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1355},"aml-alert-triage","AI for AML transaction monitoring alert triage","AML alert triage","Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.",[84,85],[584],[28,27,26,179],[1347,1171,1348,1172,1349,1350,1131,1173],"Australia Post","HSBC","Ratepay","Shift4",{"kpi":1352,"label":1353,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1354,"qualifier":134,"claimant":242,"organization":1350,"vendorReported":12},"false-positive-reduction","False positive reduction",86,"AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.",{"slug":1357,"title":1358,"shortTitle":1359,"definition":1360,"status":19,"industries":1361,"functions":1362,"patterns":1363,"audience":30,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1364,"bestGrade":41,"headline":1369,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1373},"application-and-identity-fraud-detection","AI for application and identity fraud detection","Application and identity fraud","AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.",[84,85,142,469,21],[161,583,199],[163,27,216,28],[1365,1366,1367,724,1368,40],"BCU","Close Brothers Motor Finance","CNG Holdings","Payoneer",{"kpi":1370,"label":1371,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":1372,"qualifier":134,"claimant":51,"organization":724,"vendorReported":11},"detection-rate-improvement","Detection improvement",2.5,"Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.",{"slug":1375,"title":1376,"shortTitle":1377,"definition":1378,"status":19,"industries":1379,"functions":1380,"patterns":1381,"audience":30,"autonomy":31,"adoptionStage":114,"segment":30,"evidenceCount":69,"publicEvidenceCount":93,"organizations":1382,"bestGrade":239,"headline":1385,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1386},"account-servicing-execution","AI for back office account servicing execution","Account servicing execution","AI that executes the servicing requests that land in operations queues, such as address and mandate changes, standing instructions, beneficiary updates, reissues, payoff and reference letters and loan maintenance, by reading the request, checking it against policy and entitlements, and preparing or making the change in core systems under dual control.",[84,174,273],[87,199],[26,163,29],[1383,1384],"Banco Supervielle","SS&C Technologies",{"kpi":43,"label":44,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":49,"qualifier":134,"claimant":242,"organization":1384,"vendorReported":12},"The tier depends on how the system is built. It stays minimal when the agent only executes changes approved by a person and any letter comes from a fixed template, since executing servicing changes is not listed in Annex III. It moves to limited risk when the same system talks to customers directly (the Article 50 transparency duty, described on the customer facing servicing page) or when generative AI drafts the confirmation or letter text: the provider of that generative function, the bank if it builds the system, then carries the Article 50(2) duty to mark the generated content in a machine readable way, unless the output only gets an assistive role or standard editing that does not substantially alter the input data. An AI system used to evaluate the creditworthiness of natural persons, for example to decide on a loan restructuring, is high risk under Annex III point 5(b); keep that assessment outside this agent, which only executes the decided change.",{"slug":1388,"title":1389,"shortTitle":1390,"definition":1391,"status":19,"industries":1392,"functions":1393,"patterns":1394,"audience":30,"autonomy":68,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1395,"bestGrade":41,"headline":1400,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":1401},"benefit-fraud-and-error-detection","AI for benefit fraud and error detection in social security","Benefit fraud and error detection","Risk models that help a social security or benefits agency decide which claims, payments and recipients to check for fraud or error, so that caseworkers verify the riskiest cases first, while every decision on entitlement stays with a person and the model is tested for fairness before and during use.",[469],[161,721,176],[28,27],[1396,724,1397,1398,1399],"Centers for Medicare and Medicaid Services","Gemeente Rotterdam","U.S. Department of the Treasury, Bureau of the Fiscal Service","Uitvoeringsinstituut Werknemersverzekeringen (UWV)",{"kpi":1370,"label":1371,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":1372,"qualifier":134,"claimant":51,"organization":724,"vendorReported":11},"Annex III point 5(a): AI systems used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, or to grant, reduce, revoke or reclaim them. A fundamental rights impact assessment (Article 27) is required before a public body deploys it. A design that scores people over time on their social behaviour or personal characteristics and leads to unrelated or disproportionate detrimental treatment would fall under the Article 5(1)(c) prohibition on social scoring.",{"slug":1403,"title":1404,"shortTitle":1405,"definition":1406,"status":19,"industries":1407,"functions":1408,"patterns":1409,"audience":30,"autonomy":147,"adoptionStage":114,"segment":1410,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1411,"bestGrade":239,"headline":1414,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":1418},"building-energy-optimization","AI for building HVAC and energy optimization","Building energy optimization","AI that continuously predicts a building's heating, cooling and ventilation needs and adjusts setpoints, equipment sequencing and start times in real time through the existing building management system, instead of following fixed schedules, so the building uses less energy without a person retuning it by hand.",[110,142],[87],[28],"hvac-optimization",[1412,1413],"Cammeby's International","Loyola University Chicago",{"kpi":1415,"label":1416,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1417,"qualifier":134,"claimant":242,"organization":1412,"vendorReported":12},"energy-savings","Energy savings",15.8,"Optimizing HVAC equipment is not listed in Annex III. Point 2 covers AI safety components in the management and operation of critical infrastructure such as the supply of water, gas, heating or electricity, and a building's own HVAC controller does not manage infrastructure at that level. The system also does not decide credit, employment, access to essential services or another high risk use. Under Article 6(1), an AI system that is a safety component of a product covered by Annex I harmonisation legislation, such as the Machinery Regulation, and that needs third party conformity assessment, would be high risk regardless of Annex III; this is why the guardrails on this page keep the AI out of fire, life safety and code required ventilation sequences rather than letting it override them.",{"slug":1420,"title":1421,"shortTitle":1422,"definition":1423,"status":19,"industries":1424,"functions":1425,"patterns":1426,"audience":30,"autonomy":31,"adoptionStage":32,"segment":203,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1427,"bestGrade":239,"headline":1430,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1431},"business-onboarding-and-ubo-discovery","AI for business onboarding (KYB) and beneficial ownership discovery","Business onboarding and UBO","An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.",[84,85,772],[583,584],[163,26,29,179],[1428,1429,812],"BNY","Incore Bank",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":276,"qualifier":134,"claimant":51,"organization":1428,"vendorReported":11},"Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.",{"slug":1433,"title":1434,"shortTitle":1435,"definition":1436,"status":19,"industries":1437,"functions":1438,"patterns":1439,"audience":30,"autonomy":31,"adoptionStage":114,"segment":30,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1440,"bestGrade":239,"headline":1443,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":1444},"cash-application-and-remittance-matching","AI for cash application and remittance matching","Cash application and remittance matching","AI that reads remittance advices in many formats, matches incoming customer payments to open receivable invoices, proposes deduction and short pay reason codes from prior resolutions, and routes only the genuine exceptions to a cash application analyst, so the accounts receivable sub ledger clears itself for the clean majority of payments.",[142,885,143,144,366],[613],[163,26,27,29],[1441,1442],"Keurig Dr Pepper","ResMed",{"kpi":325,"label":326,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":461,"qualifier":134,"claimant":242,"organization":1441,"vendorReported":12},"Matching a company's own incoming payments to its own open invoices is a back office finance operation. It is not listed in Annex III and does not decide a natural person's creditworthiness or eligibility for a service, so it is minimal risk and the AI literacy duty of Article 4 applies. Using deduction or payment behaviour to score an individual sole trader's creditworthiness would need a fresh risk assessment.",{"slug":1446,"title":1447,"shortTitle":1448,"definition":1449,"status":19,"industries":1450,"functions":1451,"patterns":1452,"audience":30,"autonomy":31,"adoptionStage":114,"segment":30,"evidenceCount":69,"publicEvidenceCount":93,"organizations":1453,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1455},"chargeback-and-representment","AI for chargeback and representment operations","Chargeback and representment","AI that runs the dispute engine room for issuers, acquirers and merchants: it maps each dispute to the network reason code, gathers the matching evidence, assembles a network compliant chargeback or representment package, drafts the rebuttal, tracks every deadline and processes pre dispute alerts so a refund can be issued before a chargeback lands.",[85,84,143],[87,161,63],[26,163,180,29],[1454,166],"GitHub","Dispute processing between issuers, acquirers and merchants is not listed in Annex III. It is not an evaluation of creditworthiness or credit scoring under Annex III point 5(b), and because cardholders do not interact with the system directly, the Article 50(1) transparency duty for AI that talks to people does not apply. Article 50(2) marking of generated text is a duty of the provider of the AI system that generates it, which includes an institution that builds its own dispute drafting agent and puts it into service under its own name. A drafted rebuttal built from attached case evidence performs an assistive function for standard editing of that evidence and does not substantially alter the underlying input, so it falls under the Article 50(2) exception and does not need machine readable marking. With that point checked, the tier stays minimal. A customer facing intake agent is assessed separately.",{"slug":1457,"title":1458,"shortTitle":1459,"definition":1460,"status":19,"industries":1461,"functions":1462,"patterns":1463,"audience":30,"autonomy":31,"adoptionStage":114,"segment":301,"evidenceCount":486,"publicEvidenceCount":291,"organizations":1464,"bestGrade":41,"headline":1468,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1470},"claims-triage-and-straight-through-processing","AI for claims triage and straight through processing","Claims triage and STP","AI that reads each new insurance claim and its documents, scores its complexity, cover questions, fraud and recovery signals, sends it to the right handling path and handler, and settles simple, low risk claims end to end within set limits without a person touching them.",[174],[301,87],[29,28,163,26,179],[1465,631,1188,306,1466,1467,308],"Admiral Seguros","Sedgwick","Tokio Marine & Nichido Fire Insurance",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":46,"kind":48,"value":1469,"qualifier":101,"claimant":51,"organization":306,"vendorReported":11},55,"Claims handling as such is not listed in Annex III. The same system becomes high risk when it is also used for risk assessment and pricing of natural persons in life and health insurance (point 5(c)), or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim essential public assistance benefits and services, including healthcare services (point 5(a)). Otherwise the tier is minimal, so the design and the operator decide. Decisions on claims based solely on automated processing are also subject to Article 22 of the GDPR and the UK GDPR.",{"slug":1472,"title":1473,"shortTitle":1474,"definition":1475,"status":19,"industries":1476,"functions":1477,"patterns":1478,"audience":30,"autonomy":31,"adoptionStage":114,"segment":200,"evidenceCount":486,"publicEvidenceCount":486,"organizations":1479,"bestGrade":41,"headline":1484,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1485},"commercial-underwriting-submission-triage","AI for commercial underwriting submission intake and triage","Underwriting submission triage","AI that reads incoming broker submissions for commercial insurance (emails, applications, schedules of values, loss runs and supplements), extracts the risk data into a structured record, checks clearance and appetite, enriches the risk with internal and third party data and ranks it, so underwriters open a complete, prioritized file instead of an inbox.",[174],[200,87],[163,29,28,26],[1184,1480,1481,1187,1188,1103,1482,1483,1189],"AXIS Capital","CNA Financial","Markel","Paragon Insurance Group",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":461,"qualifier":101,"claimant":51,"organization":1483,"vendorReported":11},"Intake and triage for commercial insurance is not listed in Annex III, which covers risk assessment and pricing of natural persons in life and health insurance. It moves up to high risk only if the same pipeline is used to assess or price life or health cover for individuals.",{"slug":1487,"title":1488,"shortTitle":1489,"definition":1490,"status":19,"industries":1491,"functions":1492,"patterns":1493,"audience":30,"autonomy":182,"adoptionStage":32,"segment":1128,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1494,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1497},"complaints-root-cause-analysis","AI for complaints root cause and systemic issue analysis","Complaints root cause analysis","AI that reads the free text of complaints across all channels, clusters them into themes, separates systemic causes from one off events, links each theme to the product, process or control behind it and routes the insight to the owner who can fix it, with a human validating every root cause and every remediation.",[142,84,174,85,21,469],[177,63,678],[29,179,26,66],[1396,1495,1496],"Board of Governors of the Federal Reserve System","Federal Trade Commission","Analysing complaints in aggregate to find causes is not listed in Annex III, is not a practice prohibited by Article 5 and does not decide on individuals. It does not interact with the public, so the disclosure duty in Article 50(1) does not apply; the machine readable marking of generated text in Article 50(2) is a duty of the provider of the generative model or system that writes the summaries. If the same system decided individual complaint outcomes or redress, or its themes were used to evaluate the performance of individual complaint handlers (Annex III point 4), that design would need its own assessment.",{"slug":1499,"title":1500,"shortTitle":1501,"definition":1502,"status":19,"industries":1503,"functions":1504,"patterns":1505,"audience":30,"autonomy":31,"adoptionStage":32,"segment":1128,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1506,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1510},"continuous-controls-testing","AI for continuous controls testing and control self assessment","Continuous controls testing","AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.",[142,84,174,772,469],[201,177,87],[26,163,27,29],[1507,1508,1509],"Federal Deposit Insurance Corporation","U.S. Department of the Interior","Pension Benefit Guaranty Corporation","Testing controls over transactions and systems is not an Annex III use. Controls that monitor and evaluate individual employees' behaviour, such as trading or access conduct, can fall under Annex III point 4(b), so the design decides the tier.",{"slug":1512,"title":1513,"shortTitle":1514,"definition":1515,"status":19,"industries":1516,"functions":1517,"patterns":1518,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1519,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1523},"court-and-case-file-summarization","AI for court and case file summarization","Case file summarization","AI that condenses court filings, case files, evidence recordings and earlier decisions into structured summaries, chronologies and draft case reports with references to the source pages, so that judges, prosecutors, tribunal staff and government lawyers find what matters faster, while the person responsible reads the underlying material and makes every legal judgment.",[469],[774,176],[179,163,66],[1271,1520,1521,1522],"U.S. Department of Justice","Gemeente Amsterdam","Supremo Tribunal Federal","Annex III point 8(a) makes AI high risk when it is intended to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts. Tools for prosecutors fall under point 6(c) if they evaluate the reliability of evidence, and tools that assist the examination of asylum, visa or residence applications fall under point 7(c). Under Article 6(3) a system that only performs a narrow procedural task or a preparatory task, such as organising a file or transcribing and summarising it for the person who decides, may not be high risk, but the provider must document that assessment (Article 6(4)). Summaries of internal legal advice for government lawyers, as Amsterdam plans, are generally outside Annex III.",{"slug":1525,"title":1526,"shortTitle":1527,"definition":1528,"status":19,"industries":1529,"functions":1530,"patterns":1531,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1532,"bestGrade":41,"headline":1537,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1538},"training-content-generation","AI for creating employee training and eLearning content","Training content creation","Generative AI that helps learning and development teams turn source material such as procedures, product documentation and policies into training: course outlines, lesson text, quizzes, narration, avatar videos and translations, which instructional designers and subject matter experts review before publishing.",[142,469,232,885],[234,659],[180,629,179],[1533,892,1534,1535,1536],"Carlsberg Group","U.S. Marshals Service","Veterans Benefits Administration","Zoom",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":100,"qualifier":134,"claimant":242,"organization":1536,"vendorReported":12},"Generating training content is not listed in Annex III. Providers of tools that generate synthetic audio, image, video or text content must mark the output as AI generated (with an exception for assistive editing that does not substantially alter the source), and deployers must disclose deep fakes, such as an avatar or voice that resembles a real person and would falsely appear authentic (Article 50(2) and (4), with the definition in Article 3(60)). If the same system evaluates learning outcomes or decides access to training that affects a person's work, Annex III point 3 (education and vocational training) and point 4 (employment) must be checked, and those parts can be high risk.",{"slug":1540,"title":1541,"shortTitle":1542,"definition":1543,"status":19,"industries":1544,"functions":1545,"patterns":1546,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1547,"bestGrade":41,"headline":1551,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1552},"customs-classification-and-declaration","AI for customs classification and declaration preparation","Customs classification and declarations","AI that reads what is being shipped (the commercial invoice, the product data and sometimes a photo), proposes the tariff classification code with its reasoning and a confidence score, drafts the customs declaration with value, origin and parties, and sends only uncertain or high risk entries to a licensed customs specialist before filing.",[366,143,142],[87,177],[29,163,26,216],[1548,1549,1550],"DHL Express","United Parcel Service","ZLS Zoll und Logistikservice GmbH",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":100,"qualifier":134,"claimant":51,"organization":1549,"vendorReported":11},"The classification and declaration work in the back office is minimal risk: classifying goods and preparing customs declarations is not listed in Annex III, which covers border control only where AI assesses natural persons (point 7). If the design adds a shipper facing assistant that asks for missing information in chat or by email, that assistant is limited risk and carries the transparency duty of Article 50 (people must know they are dealing with AI). The obligations that matter most come from customs law: the declarant stays responsible for the accuracy of the declaration whatever tool prepared it.",{"slug":1554,"title":1555,"shortTitle":1556,"definition":1557,"status":19,"industries":1558,"functions":1559,"patterns":1560,"audience":181,"autonomy":182,"adoptionStage":114,"segment":30,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1561,"bestGrade":41,"headline":1564,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":1566},"outbound-notice-drafting","AI for drafting customer letters and outbound notices","Outbound notice drafting","AI that drafts the letters and notices operations must send at scale, such as arrears notices, decline letters, complaint responses, servicing confirmations and product change notices, from case data and approved templates and clauses, in the customer's language, for a person to approve where the notice is regulated.",[142,84,174,469,144,273],[87,63,255,177,301],[180,66,629],[1562,1188,1563,1384],"Acentra Health","Health Resources and Services Administration",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":276,"qualifier":134,"claimant":242,"organization":1565,"vendorReported":12},"SS&C GIDS and RS","Drafting letters for human approval is not listed in Annex III. The decision the letter communicates may come from a separate high risk system, such as credit scoring (Annex III point 5(b)) or a public body's eligibility decision on benefits (point 5(a)); the drafting tool does not make that decision. Article 50(2) requires the provider of an AI system that generates text to mark the output as artificially generated, which puts this on the limited risk (transparency) tier; this includes an organization that builds its own drafting tool. Article 50(2) does not apply where the AI has only an assistive function for standard editing and does not substantially alter the input data or the semantics of the output.",{"slug":1568,"title":1569,"shortTitle":1570,"definition":1571,"status":19,"industries":1572,"functions":1573,"patterns":1574,"audience":181,"autonomy":182,"adoptionStage":90,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1575,"bestGrade":41,"headline":1578,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1580},"ediscovery-and-disclosure-document-review","AI for eDiscovery and disclosure document review","eDiscovery document review","AI that sorts, prioritises and codes large collections of emails, chats and files for relevance, issues and legal privilege in litigation, investigations and regulatory requests, so that lawyers review the documents most likely to matter and can show the court how the rest were handled.",[142,253,469],[774,176],[29,163,179],[1520,1496,1576,1577],"Purpose Legal","Serious Fraud Office",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1579,"qualifier":134,"claimant":242,"organization":1576,"vendorReported":12},85,"Document review for a party in civil litigation or an internal investigation is not listed in Annex III, so it is usually minimal risk. It becomes high risk where a law enforcement authority uses AI to evaluate the reliability of evidence in the investigation or prosecution of criminal offences (Annex III point 6(c)), or where a judicial authority uses it to research and interpret facts and law (point 8(a)). Prosecutors and investigators should classify each use against those points.",{"slug":1582,"title":1583,"shortTitle":1584,"definition":1585,"status":19,"industries":1586,"functions":1587,"patterns":1588,"audience":30,"autonomy":182,"adoptionStage":32,"segment":30,"evidenceCount":46,"publicEvidenceCount":46,"organizations":1589,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":1591},"fee-and-interest-leakage-detection","AI for fee and interest leakage detection","Fee and interest leakage","An independent verification layer that recomputes what each fee, FX margin, spread and interest charge should have been under the contract and pricing tables, compares it with what was actually billed, and surfaces overcharges and undercharges account by account for correction, customer remediation and revenue recovery.",[84,85,142],[613,706,177,87],[27,26,66],[1590],"State Bank of India","Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.",{"slug":1593,"title":1594,"shortTitle":1595,"definition":1596,"status":19,"industries":1597,"functions":1598,"patterns":1599,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1600,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":1603},"freedom-of-information-request-processing","AI for freedom of information request processing","Freedom of information requests","AI that helps a public body handle freedom of information and open government requests: logging and clarifying requests, spotting duplicates, searching and deduplicating the records in scope, proposing redactions with the exemption that applies, and drafting the response letter, with an FOI officer deciding what is released.",[469],[721,774,176],[163,29,180],[1520,1601,1602,1508],"U.S. Food and Drug Administration, Center for Drug Evaluation and Research","Provincie Noord-Holland","Tools that support staff in searching, deduplicating and proposing redactions are not listed in Annex III (point 5(a) covers eligibility for public assistance benefits and services, not access to documents), and every release decision stays with an officer. A public facing request assistant that talks to requesters would carry the Article 50(1) transparency duty.",{"slug":1605,"title":1606,"shortTitle":1607,"definition":1608,"status":19,"industries":1609,"functions":1610,"patterns":1611,"audience":181,"autonomy":182,"adoptionStage":114,"segment":301,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1612,"bestGrade":41,"headline":1615,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1616},"health-prior-authorization-and-claims-adjudication","AI for health insurance prior authorization and claims adjudication support","Health prior authorization and adjudication","AI that reads prior authorization requests, medical claims and appeals with their clinical and billing documents, extracts diagnoses, treatments and costs, checks them against the policy and published clinical criteria, and prepares a summary and recommendation for a clinician or adjudicator, who makes every adverse decision.",[174,144],[301,176,87],[163,179,66,29,180],[1562,1613,1396,1614,864],"AdvanceCare","ICICI Lombard",{"kpi":667,"label":668,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":413,"qualifier":101,"claimant":242,"organization":1562,"vendorReported":12},"Annex III point 5(a) makes AI high risk when it is used by or on behalf of public authorities to evaluate eligibility for essential public assistance benefits and services, including healthcare services, or to grant, reduce or revoke them, which can cover statutory health schemes run by or for public bodies. Point 5(c) covers risk assessment and pricing in life and health insurance, not claim review. A copilot for a private insurer's claim review, where people decide, is usually outside Annex III; for public schemes, Article 6(3) may exempt a system that only performs a preparatory task, unless it profiles natural persons. GDPR rules on health data (Article 9) and on solely automated decisions (Article 22) apply in every case.",{"slug":1618,"title":1619,"shortTitle":1620,"definition":1621,"status":19,"industries":1622,"functions":1623,"patterns":1624,"audience":67,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1625,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1628},"immigration-and-visa-application-assistant","AI for immigration and visa applications, from applicant questions to case preparation","Immigration and visa application assistant","AI that helps applicants understand immigration and visa requirements and submit complete applications, and helps immigration staff prepare cases by extracting form data, classifying evidence, routing applications and supporting interviews, while every grant or refusal is decided by an officer against the immigration rules.",[469],[721,176,87],[65,163,29,629],[1626,1627,1244,1245],"Home Office (Visa, Status and Information Services)","U.S. Department of State (Bureau of Consular Affairs)","Annex III point 7(c) makes AI high risk when it assists public authorities in examining applications for asylum, visas or residence permits, including assessing the reliability of evidence. Applicant facing information assistants that give general guidance fall under the Article 50 transparency duties (limited risk). Evidence classification, routing and interview support used in the examination are likely high risk, unless the provider documents under Article 6(3) that a component only performs a narrow procedural or preparatory task. That exception never applies to a system that profiles natural persons, which matters for routing on personal attributes or risk profiles.",{"slug":1630,"title":1631,"shortTitle":1632,"definition":1633,"status":19,"industries":1634,"functions":1635,"patterns":1636,"audience":30,"autonomy":31,"adoptionStage":90,"segment":30,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1637,"bestGrade":41,"headline":1642,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1644},"correspondence-triage-and-routing","AI for inbound correspondence triage and routing","Correspondence triage and routing","AI that sorts inbound correspondence before anyone answers it: it takes every inbound letter, email, upload and secure message into one intake, identifies what it is, extracts the key fields, links it to the right customer and account, sets priority and routes it to the right team or workflow, replacing the manual sorting desk.",[142,84,174,469],[87,63,176],[29,163,179],[1638,1639,1640,1641,308,475],"Ecclesia Group","Encova Insurance","Loadsure","The Master Trust Bank of Japan",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1643,"qualifier":134,"claimant":242,"organization":308,"vendorReported":12},91,"It depends on where the system runs. Classifying and routing a bank's or insurer's correspondence is not a use listed in Annex III, so it is minimal risk: the AI literacy duty of Article 4 applies, and the Article 50 duty to tell people they are dealing with AI does not, because the system does not interact with the sender. Used by or for a public authority in a benefits process covered by Annex III point 5(a), the provider can treat it as not high risk only while it performs a narrow procedural or preparatory task under Article 6(3); the provider must then document that assessment before it goes live (Article 6(4)) and register the system in the EU database (Article 49(2)). If the system evaluates eligibility for benefits or profiles the people who write in, it is high risk, so those judgements stay with people.",{"slug":1646,"title":1647,"shortTitle":1648,"definition":1649,"status":19,"industries":1650,"functions":1651,"patterns":1652,"audience":30,"autonomy":68,"adoptionStage":90,"segment":301,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1653,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1656},"claims-fraud-detection","AI for insurance claims fraud detection","Claims fraud detection","AI that scores every insurance claim for fraud from first notice of loss onwards, combining claim, policy, document, image and network data to find suspicious claims, organised rings and inflated losses, and sends each alert with its reasons to a claims handler or special investigations unit for review.",[174],[301,161],[27,28,163,216,29],[1654,1655,632,306,1467],"Assurant","AXA Switzerland","Claims fraud detection by an insurer is not listed in Annex III, and point 5(b) explicitly excludes AI systems used to detect financial fraud from the credit scoring category. Point 5(c) covers only risk assessment and pricing in life and health insurance, so a fraud model becomes high risk when it also feeds those decisions, or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim public assistance benefits (point 5(a)). Profiling and automated decisions remain subject to GDPR, including Article 22 where a claim is refused on a decision based solely on automated processing.",{"slug":1658,"title":1659,"shortTitle":1660,"definition":1661,"status":19,"industries":1662,"functions":1663,"patterns":1664,"audience":30,"autonomy":182,"adoptionStage":32,"segment":862,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1665,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1666},"insurance-renewal-and-retention","AI for insurance renewal processing and customer retention","Renewal and retention","AI that prepares and runs the renewal cycle: it digitizes renewal submissions and changes in risk for underwriters, flags policies at risk of lapsing or leaving, prepares the renewal conversation and answers customers' renewal questions, while renewal prices stay governed by the insurer's pricing rules and fair value obligations.",[174],[200,63,112],[28,163,65,369],[1188,408,866],"Renewal intake for commercial lines and outreach are not listed in Annex III. Renewal risk assessment or pricing for life or health insurance of natural persons is high risk under point 5(c), and so is a lapse score that feeds those decisions; a lapse score used only to decide who gets a service call is not listed. Customer facing renewal assistants carry the Article 50(1) duty to tell people they are interacting with an AI system, unless that is obvious from the context.",{"slug":1668,"title":1669,"shortTitle":1670,"definition":1671,"status":19,"industries":1672,"functions":1673,"patterns":1674,"audience":30,"autonomy":31,"adoptionStage":114,"segment":30,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1675,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1680},"ledger-and-payment-reconciliation","AI for ledger and payment reconciliation","Ledger and payment reconciliation","AI that matches entries across nostro and vostro statements, card and scheme settlement files, the general ledger and suspense accounts, proposes matches and clearing journals, and routes only the genuine breaks to an operator with a plain language explanation.",[84,85,772,142,273,469],[613,87],[26,27,163],[1676,1677,1678,1679],"Comrade Trustee Services","Ginnie Mae","National Bank of Greece (Cyprus)","World Food Programme","Matching entries between internal financial records is not a use listed in Annex III and is not a practice prohibited by Article 5. Operators knowingly use an internal AI tool, so no Article 50(1) disclosure is needed. If a generative model drafts the explanations or journals, the provider of that system may have to mark its output as AI generated under Article 50(2). The AI literacy duty of Article 4 applies to the bank as deployer.",{"slug":1682,"title":1683,"shortTitle":1684,"definition":1685,"status":19,"industries":1686,"functions":1687,"patterns":1688,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":190,"organizations":1689,"bestGrade":41,"headline":1693,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1694},"legacy-code-modernization","AI for legacy code modernization","Legacy code modernization","AI that reads legacy code such as COBOL, PL/I or old Java, explains what each program does, maps its data flows and dependencies, drafts the equivalent modern code or specification, and generates the regression tests needed to prove the new system behaves like the old one.",[142,84,772,252,232],[24],[794,179,26],[280,1690,1691,877,1692],"Amazon","Google","Toyota Motor Europe",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":413,"qualifier":101,"claimant":51,"organization":1691,"vendorReported":11},"Tools that analyze, document and translate code are not prohibited practices under Article 5 and are not listed in Annex III, so no high risk obligations apply to the tooling. Engineers and analysts know they are working with an AI tool, including when they query the documentation through a chat assistant, so the Article 50 disclosure duty has no practical effect for the deploying organization. What remains is AI literacy for the staff who use it (Article 4). If the system being modernized is itself an AI system in an Annex III area (for example creditworthiness assessment, point 5(b)), its new version still has to meet the high risk requirements.",{"slug":1696,"title":1697,"shortTitle":1698,"definition":1699,"status":19,"industries":1700,"functions":1701,"patterns":1702,"audience":181,"autonomy":182,"adoptionStage":114,"segment":1128,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1703,"bestGrade":41,"headline":1708,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1709},"market-abuse-surveillance-triage","AI for market abuse surveillance alert triage","Market abuse surveillance","AI that helps surveillance analysts triage market abuse and conduct alerts, such as spoofing, layering, wash trades, ramping and insider dealing, by gathering the trade, order, news and communications context, explaining in plain language what triggered each alert and drafting the investigation narrative for the analyst to disposition.",[772,84,273],[177,584],[27,26,179,29],[1704,588,1705,1706,1707],"Commodity Futures Trading Commission","Japan Exchange Group","Nasdaq","U.S. Securities and Exchange Commission",{"kpi":667,"label":668,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1088,"qualifier":101,"claimant":51,"organization":1706,"vendorReported":11},"Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).",{"slug":1711,"title":1712,"shortTitle":1713,"definition":1714,"status":19,"industries":1715,"functions":1716,"patterns":1717,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1718,"bestGrade":41,"headline":1722,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1726},"merchant-underwriting-and-risk-monitoring","AI for merchant underwriting and risk monitoring","Merchant underwriting and monitoring","AI that helps acquirers, payment facilitators and software platforms with embedded payments decide which merchants to accept and on what terms, by checking what a business really sells and how risky it is at onboarding, and then watches every active merchant for changes in behaviour, ranking the few that need an analyst so fraud, prohibited trade and credit losses are caught early.",[85,232,84],[583,161,201],[28,27,29,179,26],[1719,1720,166,1721],"Airwallex","Tekmetric","Weave Communications",{"kpi":1723,"label":1724,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1725,"qualifier":101,"claimant":242,"organization":1721,"vendorReported":12},"alert-volume-reduction","Alert volume reduction",89,"Assessing businesses and detecting fraud is not an Annex III use as such, and Annex III point 5(b) excludes systems used to detect financial fraud. If the system evaluates the creditworthiness of a natural person, for example a sole trader applying to accept payments, it can fall under Annex III point 5(b), which covers evaluating the creditworthiness of natural persons or establishing their credit score, and be high risk. Keep credit assessment of individuals separate or treat it as a high risk system.",{"slug":1728,"title":1729,"shortTitle":1730,"definition":1731,"status":19,"industries":1732,"functions":1733,"patterns":1734,"audience":181,"autonomy":31,"adoptionStage":114,"segment":33,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1735,"bestGrade":41,"headline":1737,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1738},"network-planning-and-capacity-optimization","AI for mobile network planning and capacity optimization","Network planning and capacity","Machine learning that forecasts where and when a mobile network will run out of capacity, recommends where to add cells, spectrum or hardware, and continuously tunes radio parameters so existing capacity carries more traffic, with planners approving investments and major changes.",[21],[23,678],[28,369,27,26],[36,1736,39,710,221],"NTT DOCOMO",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":49,"qualifier":50,"claimant":51,"organization":36,"vendorReported":11},"Forecasting demand, ranking congested cells and recommending investments is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property and that are not necessary for the system to function. Closed loop parameter optimisation on the live radio network is high risk only when it serves in that role, for example a loop whose purpose is to protect emergency call availability, so each automated loop should be assessed against point 2 and the outcome documented. Loops that only optimise performance or capacity are usually not safety components.",{"slug":1740,"title":1741,"shortTitle":1742,"definition":1743,"status":19,"industries":1744,"functions":1745,"patterns":1746,"audience":30,"autonomy":182,"adoptionStage":114,"segment":183,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1747,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1751},"mule-network-detection","AI for money mule account and network detection","Mule network detection","Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.",[84,85],[161,584],[27,28,26,179],[1748,1749,1750],"BigPay","ANZ, Commonwealth Bank, NAB, Suncorp Bank and Westpac (BioCatch Trust Australia)","Reserve Bank Innovation Hub (Reserve Bank of India)","Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.",{"slug":1753,"title":1754,"shortTitle":1755,"definition":1756,"status":19,"industries":1757,"functions":1758,"patterns":1759,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":291,"publicEvidenceCount":291,"organizations":1760,"bestGrade":41,"headline":1766,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":1767},"non-emergency-service-request-routing","AI for non emergency service requests and 311 routing","Non emergency service request routing","An AI agent on a city's 311 style phone, chat and messaging channels that answers routine municipal questions, takes service requests such as potholes, missed collections or broken street lights with the right location and details, creates the case in the work order system and routes anything urgent or complex to the right team.",[469],[721,63,176],[65,89,29,26],[743,1761,1762,1763,751,1764,1765],"London Borough of Barnet","City of Kelowna","Galt Police Department","Newcastle City Council","Rio de Janeiro City Data Office (Escritório de Dados)",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":784,"qualifier":134,"claimant":242,"organization":1762,"vendorReported":12},"A 311 assistant must disclose that it is AI (Article 50). It is not high risk while it only informs and creates service cases. If it evaluates or classifies emergency calls or sets dispatch priority for police, fire or medical services, it falls under Annex III point 5(d) and becomes high risk.",{"slug":1769,"title":1770,"shortTitle":1771,"definition":1772,"status":19,"industries":1773,"functions":1774,"patterns":1775,"audience":30,"autonomy":31,"adoptionStage":32,"segment":30,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1776,"bestGrade":41,"headline":1777,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1779},"payment-investigations-and-exceptions","AI for payment investigations and exceptions","Payment investigations and exceptions","AI that works the payments that fall out of straight through processing: it reads the failure, repairs or enriches the message, drafts the ISO 20022 or SWIFT investigation, chases the counterparty bank and proposes a return, recall or correction, while an operator approves anything that moves money.",[84,85],[87,63],[26,163,29,180],[1428,984],{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1778,"qualifier":50,"claimant":51,"organization":1428,"vendorReported":11},10,"Handling payment exceptions is not a use listed in Annex III and is not a prohibited practice under Article 5. If the agent interacts directly with customers, for example in a chat about the case, Article 50(1) requires that they are told they are interacting with an AI system.",{"slug":1781,"title":1782,"shortTitle":1783,"definition":1784,"status":19,"industries":1785,"functions":1786,"patterns":1787,"audience":181,"autonomy":182,"adoptionStage":114,"segment":183,"evidenceCount":291,"publicEvidenceCount":291,"organizations":1788,"bestGrade":41,"headline":1793,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1794},"pep-and-adverse-media-screening","AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[84,85,273],[584,583],[66,179,29,629],[588,1348,1789,1790,1791,1792,1058],"Mashreq","OCBC","Santander UK","Save the Children",{"kpi":667,"label":668,"unit":45,"n":46,"nUpTo":46,"kind":48,"value":603,"qualifier":50,"claimant":242,"organization":1792,"vendorReported":12},"Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.",{"slug":1796,"title":1797,"shortTitle":1798,"definition":1799,"status":19,"industries":1800,"functions":1801,"patterns":1802,"audience":181,"autonomy":182,"adoptionStage":32,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1803,"bestGrade":41,"headline":1807,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1808},"permit-and-licence-application-processing","AI for permit and licence application processing","Permit and licence application processing","AI that helps applicants submit complete permit and licence applications and helps officers process them, by answering questions about requirements, checking applications for missing or inconsistent information, pulling the relevant policies, history and constraints, and drafting reports, while the grant or refusal stays with a named officer or a published rule.",[469],[721,176,177],[163,26,66,65],[1804,728,1805,827,1806],"Intellectual Property Office","U.S. Fish and Wildlife Service","West Berkshire Council",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1579,"qualifier":50,"claimant":51,"organization":728,"vendorReported":11},"Permit and licence decisions are not listed as such in Annex III, so officer decision support is usually minimal risk, and an assistant that talks to applicants carries the Article 50 transparency duty. The exceptions are permits in an Annex III area: examining applications for visas and residence permits (point 7) and evaluating eligibility for essential public assistance benefits and services (point 5(a)) are high risk. Solely automated decisions with legal or similarly significant effects on a person fall under GDPR Article 22 whatever the tier.",{"slug":1810,"title":1811,"shortTitle":1812,"definition":1813,"status":19,"industries":1814,"functions":1815,"patterns":1816,"audience":30,"autonomy":31,"adoptionStage":32,"segment":183,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1817,"bestGrade":41,"headline":1820,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":1822},"perpetual-kyc","AI for perpetual KYC and event driven customer due diligence","Perpetual KYC","AI that keeps each customer's due diligence file current by replacing calendar driven KYC reviews with continuous, event driven refreshes: it watches for trigger events such as a change of ownership, address, behaviour or a new adverse finding, refreshes the file automatically where it can, and involves an analyst only when something material has changed. The risk rating itself and the first file for a new business client are separate use cases.",[84,85,273],[583,584],[26,163,66,179],[588,1818,984,1790,1819],"First National Bank of Omaha (FNBO)","Origin Bank",{"kpi":262,"label":263,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1821,"qualifier":134,"claimant":51,"organization":984,"vendorReported":11},40,"Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.",{"slug":1824,"title":1825,"shortTitle":1826,"definition":1827,"status":19,"industries":1828,"functions":1829,"patterns":1830,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1831,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1835},"adverse-event-case-intake","AI for pharmacovigilance adverse event case intake","Adverse event case intake","AI that takes in adverse event reports about medicines, vaccines and devices from calls, emails, forms, literature and partner files, decides whether each is a valid case, flags seriousness, extracts and codes the case data into the safety database format, and routes it to drug safety professionals, who review medical content and regulatory reporting.",[611,469],[177,176,87],[163,29,65],[1832,1601,1833,1834],"Bayer","U.S. Food and Drug Administration","Pfizer","Internal intake, extraction and coding for review by safety staff is not listed in Annex III and is usually minimal risk. A public facing reporting assistant must tell people they are talking to an AI under Article 50. The main obligations come from pharmacovigilance law and good pharmacovigilance practices, which require validated, inspectable processes, and from GDPR rules on health data.",{"slug":1837,"title":1838,"shortTitle":1839,"definition":1840,"status":19,"industries":1841,"functions":1842,"patterns":1843,"audience":67,"autonomy":31,"adoptionStage":114,"segment":301,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1844,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1848},"photo-based-damage-assessment","AI for photo based damage assessment in insurance claims","Photo damage assessment","Computer vision that assesses damage from photos or video of a vehicle or property taken by the policyholder, a repairer or an adjuster, identifies the damaged parts and the repair or replace decision, produces or checks the repair estimate, and flags total losses and inconsistencies for a person to review.",[174],[301],[216,28,26],[1465,1845,1846,1847,1467],"Covéa","Foyer","PZU","Assessing damage to vehicles or property for property and casualty claims is not listed in Annex III, which covers insurance only for risk assessment and pricing of natural persons in life and health insurance (point 5(c)). Article 50(1) transparency duties apply when the customer interacts directly with the AI, for example a guided photo journey that returns an AI estimate or offer, or a chat agent. A purely internal repairer estimate review with no customer interaction is minimal. A settlement or refusal decided solely by automated processing can fall under GDPR Article 22.",{"slug":1850,"title":1851,"shortTitle":1852,"definition":1853,"status":19,"industries":1854,"functions":1855,"patterns":1856,"audience":181,"autonomy":182,"adoptionStage":32,"segment":1128,"evidenceCount":69,"publicEvidenceCount":69,"organizations":1857,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":1858},"policy-drafting-and-gap-analysis","AI for policy drafting and policy gap analysis","Policy drafting and gaps","An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.",[142,84,174,772,469],[177,774,659],[66,180,163,179],[1507,891,1563],"Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.",{"slug":1860,"title":1861,"shortTitle":1862,"definition":1863,"status":19,"industries":1864,"functions":1865,"patterns":1866,"audience":30,"autonomy":31,"adoptionStage":114,"segment":33,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1867,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1868},"predictive-network-maintenance","AI for predictive network maintenance in telecom","Predictive network maintenance","Machine learning that spots the early signs of network failure, such as degrading cells, faulty customer equipment, ageing hardware or planned digging near fibre, and triggers a preventive fix, a remote reset or a targeted intervention before customers lose service.",[21],[23,214,87],[27,28,26],[38,1143,710,40,599,221],"Scoring failure risk and planning maintenance is normally minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall within that infrastructure. Recital 55 limits safety components to systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. An operator whose automated actions meet that test must treat the system as high risk.",{"slug":1870,"title":1871,"shortTitle":1872,"definition":1873,"status":19,"industries":1874,"functions":1875,"patterns":1876,"audience":30,"autonomy":182,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1877,"bestGrade":41,"headline":1881,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":1883},"public-consultation-response-analysis","AI for public consultation response analysis","Consultation response analysis","AI that reads every free text response to a public consultation or rulemaking comment period, proposes themes, maps each response to the themes that officials have validated, flags duplicates, campaign letters and responses that need special attention, and produces counts and summaries for the analysts who write the government's response.",[469],[721,678],[179,29,180],[1878,1495,1879,1273,1880],"Centers for Disease Control and Prevention","Department for Transport","U.S. Department of Transportation, Office of the Secretary",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1882,"qualifier":50,"claimant":51,"organization":1879,"vendorReported":11},92,"Organising and summarising consultation responses for analysts does not decide on individuals and is not listed in Annex III, so no high risk obligations apply. If AI generated text is published to inform the public on matters of public interest without human review and editorial responsibility, Article 50(4) requires disclosure.",{"slug":1885,"title":1886,"shortTitle":1887,"definition":1888,"status":19,"industries":1889,"functions":1890,"patterns":1891,"audience":30,"autonomy":147,"adoptionStage":114,"segment":33,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1892,"bestGrade":41,"headline":1897,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1898},"ran-energy-optimization","AI for radio access network energy optimization","RAN energy optimization","Machine learning that predicts traffic per cell and puts radio carriers, cells and hardware components into sleep modes when demand is low, then wakes them before users notice, so a mobile network uses less electricity without losing coverage or quality.",[21],[23],[28],[282,1893,1894,1895,1896],"Indosat Ooredoo Hutchison","O2 Telefónica Germany","Safaricom","Telefónica",{"kpi":1415,"label":1416,"unit":45,"n":47,"nUpTo":46,"kind":48,"value":423,"qualifier":634,"claimant":51,"organization":1896,"vendorReported":11},"Optimizing energy use is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall under that infrastructure. Recital 55 limits safety components to systems that directly protect the infrastructure or the health and safety of persons, so an optimizer is not high risk by default, but a design in which it could affect emergency service availability should be assessed against point 2.",{"slug":1900,"title":1901,"shortTitle":1902,"definition":1903,"status":19,"industries":1904,"functions":1905,"patterns":1906,"audience":67,"autonomy":182,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":190,"organizations":1907,"bestGrade":41,"headline":1912,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":1913},"recruitment-screening-and-interview-scheduling","AI for recruitment screening and interview scheduling","Recruitment screening and scheduling","AI that answers candidates' questions, collects applications in conversation, schedules interviews and, where the organization chooses, assesses applications against the job requirements for a recruiter, who makes every selection decision. In the EU, the screening part is a high risk AI system under Annex III point 4 of the AI Act.",[142,469,272,253],[234],[65,29,28,26],[1908,1909,1244,1910,1911],"Chipotle Mexican Grill","Gojob","Mastercard","Trace3",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":100,"qualifier":101,"claimant":51,"organization":1910,"vendorReported":11},"Annex III point 4(a) lists AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications and to evaluate candidates. Screening, ranking and scoring applications is therefore high risk. A component limited to a narrow procedural task, such as booking interview slots or answering process questions, can fall outside the high risk category under Article 6(3), but only if it does not materially influence the outcome and does not profile people, and that assessment must be documented (Article 6(4)). Deployers of the high risk part must follow the instructions for use, assign competent human oversight, keep logs, inform workers' representatives and inform candidates that a high risk system is used (Article 26). An organization that builds its own screening system becomes its provider, with conformity assessment duties. The chatbot part also carries the Article 50 disclosure duty.",{"slug":1915,"title":1916,"shortTitle":1917,"definition":1918,"status":19,"industries":1919,"functions":1920,"patterns":1921,"audience":181,"autonomy":182,"adoptionStage":32,"segment":30,"evidenceCount":93,"publicEvidenceCount":93,"organizations":1922,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1924},"regulatory-report-assembly","AI for regulatory report assembly","Regulatory report assembly","AI that assembles periodic and data driven regulatory filings and returns, such as prudential and statistical returns, threshold and transaction reports and disclosure packs, by pulling data into the regulator's schema, validating it, reconciling figures to source, explaining movements against prior periods and drafting commentary, before a named officer reviews and submits. Narratives for individual suspicious activity cases are a separate use case.",[84,174,772,85],[177,613,584],[26,27,180,179],[1495,1923],"National Credit Union Administration","Not an Article 5 practice and not listed in Annex III: the system prepares filings for authorities and makes no decision on the credit, insurance, employment or access to services of a natural person. It is an internal tool whose users know they are working with AI, and drafted text that ends up in public disclosures passes human review under a named person's editorial responsibility, which takes it outside the Article 50(4) deployer disclosure duty. The system still drafts variance commentary and plain language explanations of validation failures from underlying data, rather than lightly editing existing text, so the assistive function for standard editing exception does not fit. The bank that builds or operates the system is then the provider and carries the Article 50(2) duty to mark that generated text in a machine readable way as artificially generated, which has applied since 2 August 2026. The AI literacy duty of Article 4 also applies.",{"slug":1926,"title":1927,"shortTitle":1928,"definition":1929,"status":19,"industries":1930,"functions":1931,"patterns":1932,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1933,"bestGrade":239,"headline":1938,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":1939},"rfp-and-proposal-response-drafting","AI for RFP, tender and sales proposal response drafting","RFP and proposal drafting","AI that helps sales and bid teams answer requests for proposal, tenders, security questionnaires and sales proposals: it breaks the request into questions and requirements, retrieves approved answers and past proposals, drafts the response and a compliance matrix, and routes open points to subject matter experts, with a proposal manager reviewing everything before submission.",[142,253,232],[112,659],[180,66,163],[1934,1935,1936,1937],"GroupeActive","Industrialized Construction Group","Microsoft","Verdantas",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":784,"qualifier":134,"claimant":242,"organization":1935,"vendorReported":12},"Drafting bid responses for staff to review is not listed in Annex III, and the buyer receives the seller's own document rather than interacting with an AI system, so the high risk tier and the Article 50(1) duty towards the buyer do not apply. Staff who chat with the agent must know it is an AI system, which an internal tool labelled as an AI assistant meets by design. Article 50(2) does apply to the drafting itself: the provider of a system that generates text must mark its output in a machine readable format as artificially generated, whether or not a person reviews the draft, unless the system only performs an assistive function for standard editing. A seller that uses a third party drafting tool relies on that tool's provider for the marking; a seller that builds its own agent that generates proposal text, as GroupeActive did with Witivio on Copilot Studio, can be the provider and then carries the duty itself. AI literacy under Article 4 applies in both cases, and the seller remains responsible for every statement in the submitted response.",{"slug":1941,"title":1942,"shortTitle":1943,"definition":1944,"status":19,"industries":1945,"functions":1946,"patterns":1947,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":34,"organizations":1948,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1955},"inspection-prioritization","AI for risk based inspection prioritization in food safety, workplace and environmental regulation","Inspection prioritization","Models that predict which premises, operators or activities are most likely to be non compliant, so that inspectors in food safety, workplace safety, environmental and other regulation spend their visits where the risk is highest, ideally with inspectors choosing the visits and random inspections testing the model.",[469],[201,176,177],[28,27],[1949,1950,1951,1952,1953,1954],"Care Quality Commission","Driver and Vehicle Standards Agency","U.S. Environmental Protection Agency, Office of Enforcement and Compliance Assurance","Food Standards Agency","Nederlandse Arbeidsinspectie","Nederlandse Voedsel- en Warenautoriteit (NVWA)","Prioritizing inspections of businesses and premises is not a use listed in Annex III, so such a system is usually not high risk. The assessment changes when it scores natural persons, such as individual licensed professionals or sole traders, and the inspectorate acts as a law enforcement authority: assessing the risk that a person offends, or profiling persons in the detection or investigation of criminal offences, is high risk under Annex III point 6 (d) and (e), and predicting that a person will commit a criminal offence based solely on profiling is prohibited by Article 5(1)(d). GDPR applies wherever sole traders, home based businesses or named professionals are scored.",{"slug":1957,"title":1958,"shortTitle":1959,"definition":1960,"status":19,"industries":1961,"functions":1962,"patterns":1963,"audience":30,"autonomy":31,"adoptionStage":114,"segment":183,"evidenceCount":291,"publicEvidenceCount":291,"organizations":1964,"bestGrade":41,"headline":1966,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":1967},"sanctions-screening-adjudication","AI for sanctions screening alert adjudication","Sanctions screening adjudication","AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.",[84,85],[584],[29,28,26],[1965,1818,1348,1789,1349,1059,1131],"AJ Bell",{"kpi":1352,"label":1353,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":603,"qualifier":134,"claimant":51,"organization":1131,"vendorReported":11},"Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.",{"slug":1969,"title":1970,"shortTitle":1971,"definition":1972,"status":19,"industries":1973,"functions":1974,"patterns":1976,"audience":181,"autonomy":31,"adoptionStage":114,"evidenceCount":291,"publicEvidenceCount":291,"organizations":1977,"bestGrade":41,"headline":1984,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1985},"security-alert-triage-and-investigation","AI for security alert triage and investigation in the SOC","Security alert triage","An AI agent in the security operations centre that picks up each new alert or user reported phishing email, gathers the evidence from the SIEM, endpoint, identity and threat intelligence tools, gives a verdict with its reasoning and a draft incident summary, and closes clear false positives while an analyst approves every containment action.",[142,144,232,469,253],[1975,24],"security-operations",[26,29,179,66],[1978,1979,1980,1981,1982,1983,1244],"Avanade","Federal Housing Finance Agency","Human Managed","SEP2","St. Luke's University Health Network","TÜV SÜD",{"kpi":782,"label":783,"unit":45,"n":69,"nUpTo":47,"kind":223,"value":603,"qualifier":134,"claimant":74,"organization":74,"vendorReported":11},"Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.",{"slug":1987,"title":1988,"shortTitle":1989,"definition":1990,"status":19,"industries":1991,"functions":1992,"patterns":1993,"audience":30,"autonomy":182,"adoptionStage":114,"segment":30,"evidenceCount":92,"publicEvidenceCount":92,"organizations":1994,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":1997},"settlement-fail-prediction-and-exception-management","AI for settlement fail prediction and post trade exception management","Settlement fail prediction","AI that scores each pending securities settlement instruction for its likelihood of failing, names the probable cause (unmatched instruction, wrong settlement details, lack of securities or cash), and helps operations teams work the exceptions and counterparty queries before the intended settlement date, so fewer trades fail and fewer late settlement penalties are paid.",[772,84,273],[87,201],[28,29,26,180],[1428,1995,1996],"Clearstream","Euroclear","Predicting settlement fails and handling post trade exceptions between professional market participants is not a use listed in Annex III and is not a prohibited practice under Article 5, so the tier depends on how the agent communicates. While an operator reviews and sends every message, the system is minimal risk: the messages are the firm's own correspondence and the firm as deployer owes AI literacy for staff (Article 4). Once the agent sends queries or chasers to counterparty or custodian staff itself, as the playbook recommends for routine information requests, it interacts directly with natural persons and Article 50(1) requires telling the recipients they are dealing with an AI system. In both designs the provider of the text generating system must mark its output as AI generated in a machine readable format under Article 50(2). Model risk and operational resilience controls apply on top.",{"slug":1999,"title":2000,"shortTitle":2001,"definition":2002,"status":19,"industries":2003,"functions":2004,"patterns":2005,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2006,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2009},"software-vulnerability-remediation","AI for software vulnerability triage and remediation","Vulnerability remediation","AI that takes security findings from scanners, fuzzers and bug reports, filters out duplicates and false positives, reproduces and ranks the real ones, and drafts a code fix with a test for each, which a developer reviews and merges through the normal change process.",[142,232,144],[1975,24],[794,26,29],[1691,2007,2008],"Labelbox","PatientPoint","Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.",{"slug":2011,"title":2012,"shortTitle":2013,"definition":2014,"status":19,"industries":2015,"functions":2016,"patterns":2017,"audience":30,"autonomy":68,"adoptionStage":114,"segment":301,"evidenceCount":92,"publicEvidenceCount":93,"organizations":2018,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2021},"subrogation-opportunity-detection","AI for subrogation opportunity detection","Subrogation detection","AI that reads open and closed claims to find cases where a third party is wholly or partly liable, estimates liability and the recoverable amount under the applicable negligence and recovery rules, and sends scored recovery opportunities with their reasons to the subrogation team.",[174],[301,255],[29,28,163,179],[2019,2020],"Central Insurance","Elephant Insurance","Detecting recovery opportunities against third parties and other insurers is not listed in Annex III: point 5(c) covers only risk assessment and pricing of natural persons in life and health insurance, and the system does not decide on a natural person's access to a service. It is an internal tool that does not converse with the public or publish generated content, so the deployer transparency duties of Article 50 do not apply. Personal data in claim files, including data about the third party, is still subject to GDPR.",{"slug":2023,"title":2024,"shortTitle":2025,"definition":2026,"status":19,"industries":2027,"functions":2028,"patterns":2029,"audience":181,"autonomy":182,"adoptionStage":32,"segment":1128,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2030,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2032},"supervisory-exam-response-assembly","AI for supervisory exam and information request responses","Exam response assembly","An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.",[84,174,772,85],[177,774,176],[66,180,163,26],[2031,726],"U.S. Department of Homeland Security","Drafting regulatory correspondence for human approval is not an Annex III use. The main risks are confidentiality and accuracy, which are handled by supervisory information rules, data protection law and internal controls.",{"slug":2034,"title":2035,"shortTitle":2036,"definition":2037,"status":19,"industries":2038,"functions":2039,"patterns":2040,"audience":30,"autonomy":31,"adoptionStage":90,"segment":30,"evidenceCount":190,"publicEvidenceCount":92,"organizations":2041,"bestGrade":41,"headline":2044,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2045},"supplier-invoice-processing","AI for supplier invoice processing in accounts payable","Supplier invoice processing","AI that captures supplier invoices from any format, extracts header and line data, matches them to purchase orders and goods receipts, proposes tax and cost centre coding, flags duplicates and suspected fraud, and routes them for approval and posting, leaving only exceptions to accounts payable staff.",[142,84,469,143,251],[613,887],[163,26,27,29],[1507,2042,1244,2043],"Kingfisher","Veolia",{"kpi":782,"label":783,"unit":45,"n":46,"nUpTo":46,"kind":48,"value":784,"qualifier":134,"claimant":51,"organization":2042,"vendorReported":11},"Processing supplier invoices is not an Annex III use case, is not a practice prohibited by Article 5 and does not involve decisions about natural persons, so it is minimal risk and the AI literacy duty of Article 4 applies. Approvers who ask questions in chat use an internal tool they know is AI; if that is not obvious to the people using it, the provider must also inform them that they are interacting with an AI system (Article 50(1)).",{"slug":2047,"title":2048,"shortTitle":2049,"definition":2050,"status":19,"industries":2051,"functions":2052,"patterns":2053,"audience":181,"autonomy":182,"adoptionStage":32,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2054,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2057},"support-knowledge-article-generation","AI for support knowledge article generation and maintenance","Knowledge article generation","AI that drafts knowledge base articles from resolved tickets, cases and conversations, detects questions the knowledge base does not answer and articles that are outdated or contradict each other, and proposes new or revised articles for a knowledge owner to review and publish.",[142,469,252],[659,63,24],[180,179,29],[1878,892,2055,2056],"U.S. National Science Foundation","Rivian","Drafting internal or public help content that a person reviews and publishes is not a prohibited practice under Article 5 and is not listed in Annex III, so it is minimal risk. The articles are not a direct AI interaction, and the Article 50(4) disclosure for AI generated text published to inform the public does not apply where a person reviews the text and holds editorial responsibility. The Article 50 transparency duties do apply to chatbots that later answer customers from the articles.",{"slug":2059,"title":2060,"shortTitle":2061,"definition":2062,"status":19,"industries":2063,"functions":2064,"patterns":2065,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":423,"publicEvidenceCount":291,"organizations":2067,"bestGrade":41,"headline":2073,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":2074},"synthetic-test-data-generation","AI for synthetic test data generation","Synthetic test data generation","AI that generates realistic synthetic datasets, such as customers, transactions, documents and conversations, which keep the structure and statistical properties of production data without containing real personal data, so teams can test software, train and validate models and run demos safely.",[142,84,144,174],[24,678],[2066,180],"synthetic-data-generation",[2068,2069,892,984,2070,2071,2072],"Boomi","Financial Conduct Authority","Kin Insurance","Merkur Versicherung AG","Patterson Dental",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":264,"qualifier":134,"claimant":242,"organization":2072,"vendorReported":12},"A generator of synthetic tabular test data is not listed in Annex III and does not interact with people, so it is minimal risk with only the AI literacy duty of Article 4. When the system generates synthetic text, images, audio or video, such as documents or conversation transcripts, Article 50(2) requires its provider to mark the output in a machine readable format as artificially generated. When synthetic data is used to train, validate or test a high risk system, such as credit scoring, it falls under that system's data governance duties in Article 10.",{"slug":2076,"title":2077,"shortTitle":2078,"definition":2079,"status":19,"industries":2080,"functions":2081,"patterns":2082,"audience":30,"autonomy":68,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2083,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2085},"tax-compliance-risk-scoring","AI for tax compliance risk scoring and audit selection","Tax compliance risk scoring","Models that score tax returns, taxpayers and transactions for the risk of error, underreporting or fraud, so that a tax administration spends its audit and compliance capacity where the risk is highest, with an officer deciding every compliance action and the selection itself monitored for fairness.",[469],[201,176,161],[28,27],[2084,929,892],"Belastingdienst","Risk selection for administrative tax audits is not listed in Annex III, and Recital 59 says systems used by tax and customs authorities in administrative proceedings should not be treated as high risk law enforcement systems. Use in criminal tax investigations (Annex III point 6, law enforcement), or evaluating the eligibility of natural persons for public assistance benefits run through the tax system (Annex III point 5(a)), can make it high risk. When individuals are scored in administrative tax work, the GDPR applies, including its profiling rules (Member States may restrict some rights for taxation matters under Article 23). Article 22 applies when a decision with legal or similarly significant effect is taken solely by the model. Criminal investigations fall outside the GDPR and under the Law Enforcement Directive (EU) 2016/680 instead.",{"slug":2087,"title":2088,"shortTitle":2089,"definition":2090,"status":19,"industries":2091,"functions":2092,"patterns":2093,"audience":30,"autonomy":31,"adoptionStage":90,"segment":183,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2094,"bestGrade":41,"headline":2097,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2100},"churn-prediction-and-retention-offers","AI for telecom churn prediction and retention offers","Churn prediction and retention","AI for telecom operators that scores each subscriber's risk of leaving from usage, service, billing and contact signals, explains the likely reason, and chooses the next best retention action, such as fixing a problem, adjusting a plan or making an offer, delivered through the app, messaging, an agent or an advisor within approved offer budgets.",[21],[387,63,112,678],[28,369,65],[2095,956,219,2096],"Etisalat","Vodafone UK",{"kpi":2098,"label":2099,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1032,"qualifier":134,"claimant":242,"organization":956,"vendorReported":12},"churn-reduction","Churn reduction","Churn scoring and offer selection for marketing are not listed in Annex III, so a back office design that only scores customers and prompts human advisors is minimal risk, with no specific obligations. When an AI agent delivers the offer to the customer in chat, messaging or voice, the system is limited risk: Article 50 requires telling customers they are dealing with AI. A design that used manipulative techniques or exploited vulnerabilities to keep customers from leaving could fall under the Article 5 prohibitions. GDPR rules on profiling and the right to object to direct marketing (Article 21) apply in full.",{"slug":2102,"title":2103,"shortTitle":2104,"definition":2105,"status":19,"industries":2106,"functions":2107,"patterns":2108,"audience":30,"autonomy":31,"adoptionStage":114,"segment":2109,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2110,"bestGrade":41,"headline":2111,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2112},"telecom-fraud-detection","AI for telecom fraud detection (SIM swap, IRSF and Wangiri)","Telecom fraud detection","AI that protects the operator's own network, revenue and numbers from fraud: it watches call, messaging, roaming and account activity to detect SIM swap and port out takeovers, international revenue share fraud (IRSF) and Wangiri one ring scams, blocks or flags them in real time, and shares risk signals with banks and other businesses that rely on the phone number for security. Scam calls aimed at subscribers are handled by call blocking.",[21],[161,23,1975],[27,28,29],"customer-protection",[40,221],{"kpi":1370,"label":1371,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":51,"organization":221,"vendorReported":11},"Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.",{"slug":2114,"title":2115,"shortTitle":2116,"definition":2117,"status":19,"industries":2118,"functions":2119,"patterns":2120,"audience":181,"autonomy":182,"adoptionStage":114,"segment":1128,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2121,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2123},"vendor-due-diligence","AI for third party and vendor risk due diligence","Vendor due diligence","AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.",[142,84,174,469,85],[887,201,177],[163,66,26,179],[1520,892,827,2122],"U.S. Trade and Development Agency","Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.",{"slug":2125,"title":2126,"shortTitle":2127,"definition":2128,"status":19,"industries":2129,"functions":2130,"patterns":2131,"audience":30,"autonomy":182,"adoptionStage":90,"evidenceCount":190,"publicEvidenceCount":190,"organizations":2132,"bestGrade":41,"headline":2138,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2139},"customer-feedback-analysis","AI for voice of the customer and feedback analysis","Customer feedback analysis","AI that reads every piece of free text customer feedback, such as survey verbatims, NPS comments, reviews, social posts, chat and call transcripts, and turns it into themes, sentiment, drivers and suggested actions that a named owner can act on, so the organization hears all of its customers instead of a sample.",[142,143,469,885],[63,387,678],[29,179,661],[2133,2134,2135,2136,2137],"U.S. Department of Housing and Urban Development","Majid Al Futtaim Retail","Mattel","SBF Group","U.S. Social Security Administration",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":241,"qualifier":134,"claimant":242,"organization":2136,"vendorReported":12},"Classifying and summarizing text feedback is minimal risk. The tier changes if the system infers emotions from customers' voices or faces in calls or video: emotion recognition based on biometric data is listed as high risk in Annex III point 1(c) and triggers the Article 50(3) duty to inform the people exposed. Analysing feedback from employees to evaluate individual workers moves it towards Annex III point 4(b), and emotion recognition in the workplace is prohibited by Article 5(1)(f), except for medical or safety reasons.",{"slug":2141,"title":2142,"shortTitle":2143,"definition":2144,"status":19,"industries":2145,"functions":2146,"patterns":2147,"audience":30,"autonomy":182,"adoptionStage":114,"segment":183,"evidenceCount":69,"publicEvidenceCount":93,"organizations":2148,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2150},"portfolio-reporting-and-commentary","AI generated client portfolio reports and commentary","Portfolio commentary","AI that drafts each client's periodic portfolio commentary and report narrative (performance, attribution, what drove returns, positioning and outlook) in plain language and in the client's language, where every figure comes from the portfolio system of record and a reviewer approves the text before delivery.",[273,84],[678,63,87],[180,179,629],[877,2149],"Quilter","Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.",{"slug":2152,"title":2153,"shortTitle":2154,"definition":2155,"status":19,"industries":2156,"functions":2157,"patterns":2158,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2159,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2163},"home-loan-assistant-and-prequalification","AI home loan assistant with pre qualification","Home loan assistant","A customer facing assistant that answers home loan questions (rates, loan to value, fees, the documents needed), runs indicative affordability and borrowing estimates from the bank's published rules, and books the customer with a mortgage specialist, grounded in the bank's current, versioned product and policy documents.",[84,110],[199,112,63],[66,65,89],[2160,2161,2162],"Figure","Loft","Safe Rate","Answering questions and giving indicative estimates from published rules is limited risk with an Article 50(1) disclosure that the customer is talking to an AI system. If the assistant evaluates an individual's creditworthiness to decide or filter access to a loan, it falls under Annex III point 5(b) and is high risk.",{"slug":2165,"title":2166,"shortTitle":2167,"definition":2168,"status":19,"industries":2169,"functions":2170,"patterns":2171,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2172,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2176},"internal-talent-marketplace-matching","AI internal talent marketplace for matching employees to projects, roles and mentors","Internal talent marketplace","An internal platform that uses AI to infer employees' skills and interests and recommend short term projects, open roles, mentors and learning to them, while showing managers which employees fit an opportunity, so that work is staffed from inside before hiring or contracting externally.",[142,885,85,469],[234],[369,28],[2173,1910,2174,2175],"Federal Bureau of Prisons","Schneider Electric","Unilever","Annex III point 4 lists AI used for the recruitment or selection of natural persons (4(a)) and AI used to make decisions affecting promotion, or to allocate tasks based on individual behaviour, personal traits or characteristics (4(b)). A marketplace that ranks employees for internal roles or allocates projects on the basis of inferred traits is therefore high risk. Recommending learning content or mentors to an employee who chooses freely is usually not. Deployers of the high risk part must inform workers' representatives and the affected employees before use (Article 26).",{"slug":2178,"title":2179,"shortTitle":2180,"definition":2181,"status":19,"industries":2182,"functions":2183,"patterns":2184,"audience":181,"autonomy":68,"adoptionStage":90,"segment":91,"evidenceCount":34,"publicEvidenceCount":34,"organizations":2185,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":2188},"wealth-advisor-knowledge-assistant","AI knowledge assistant for wealth advisors and relationship managers","Advisor knowledge assistant","A conversational assistant that answers a wealth advisor's or relationship manager's questions in seconds from the firm's own research, house view, product documentation and policies, with every answer linked to the source document so the advisor can check it before using it with a client.",[273,84],[659,112,63],[66,65],[149,1028,984,877,2186,2187],"UBS","Yes Bank","Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant labelled as AI; Article 50(2) requires providers of systems that generate text to mark the output as AI generated in a machine readable way. Helping advisors find information is not an Annex III use and not a prohibited practice under Article 5. It would become high risk only if the system were used to evaluate the creditworthiness of clients (point 5(b)) or to evaluate or make decisions about advisors (point 4(b)). If the assistant were opened to clients, they would have to be told they are dealing with AI.",{"slug":2190,"title":2191,"shortTitle":2192,"definition":2193,"status":19,"industries":2194,"functions":2195,"patterns":2196,"audience":181,"autonomy":31,"adoptionStage":114,"segment":2197,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2198,"bestGrade":239,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":2201},"lease-abstraction","AI lease abstraction for commercial real estate","Lease abstraction","AI that reads a commercial lease, amendment or letter of intent and extracts the key terms, such as parties, dates, rent, escalations, options and renewal notices, into structured data, so a property owner, occupier or brokerage does not retype every clause by hand into its lease administration and portfolio systems.",[110],[87,774],[163,26,66],"lease-administration",[2199,2200],"Cushman & Wakefield","JLL (Jones Lang LaSalle)","Extraction alone is minimal risk: reading and structuring the terms of a commercial contract does not decide credit, employment, insurance, biometric identification or another use listed in Annex III, so it carries only the Article 4 AI literacy duty. The conversational assistant that lets employees ask questions about a lease adds Article 50(1): people who interact directly with it must be told they are dealing with an AI system, unless that is obvious from the context, as it usually is for an internal tool.",{"slug":2203,"title":2204,"shortTitle":2205,"definition":2206,"status":19,"industries":2207,"functions":2208,"patterns":2209,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2210,"bestGrade":41,"headline":2213,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2215},"legal-research-and-drafting-assistant","AI legal research and drafting assistant for lawyers","Legal research and drafting","A generative AI assistant for lawyers in firms, legal departments and public bodies that finds and summarises case law, legislation and internal know how, answers legal questions with citations and drafts first versions of memos, briefings, letters and filings, which a lawyer verifies and signs off.",[253,142,469],[774,659],[66,180,179,163],[2211,2212,1520,1707],"A&O Shearman","Ashurst Perkins Coie",{"kpi":782,"label":783,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2214,"qualifier":101,"claimant":51,"organization":2212,"vendorReported":11},45,"Research and drafting support for lawyers in firms and companies is not listed in Annex III, so it is normally minimal risk with AI literacy duties. Annex III point 8(a) makes it high risk when a judicial authority, or someone on its behalf, uses AI to research and interpret facts and the law and to apply the law to a concrete set of facts, or when it is used in a similar way in alternative dispute resolution, so a deployment for courts, tribunals or arbitration needs its own classification.",{"slug":2217,"title":2218,"shortTitle":2219,"definition":2220,"status":19,"industries":2221,"functions":2222,"patterns":2223,"audience":181,"autonomy":31,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2224,"bestGrade":239,"headline":2228,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2229},"marketing-and-product-content-localization","AI localization of marketing, product and web content","Content localization","AI that translates and adapts an organization's commercial content, such as campaigns, emails, product pages, help content and websites, for each market and language, using the brand's glossary, style guide and past approved translations, and routes the output to human linguists and local marketers for review in proportion to how visible and risky the content is.",[142,143,253,885],[387],[629,180],[2225,2226,2227],"Bosch Digital","Lionbridge","Swarovski",{"kpi":43,"label":44,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":1778,"qualifier":134,"claimant":242,"organization":2227,"vendorReported":12},"Translating and adapting commercial content is not an Annex III use and makes no decisions about people. When an organization uses a third party translation or generation tool, the use is minimal risk for the organization: the Article 50(2) duty to mark generated text in a machine readable way falls on the provider of that system, and beyond AI literacy no specific deployer obligations apply. When an organization builds and operates its own generating system and puts it into service under its own name, it is the provider and must mark the output, unless the exception for systems that only assist standard editing or do not substantially alter the input or its semantics applies. A faithful translation may fall within that exception; transcreation that rewrites the message for a market alters the semantics and is less likely to. Article 50(4) covers deepfakes and text published to inform the public on matters of public interest, not marketing translations. Consumer protection and advertising rules apply to the translated text as to the original.",{"slug":2231,"title":2232,"shortTitle":2233,"definition":2234,"status":19,"industries":2235,"functions":2236,"patterns":2237,"audience":30,"autonomy":31,"adoptionStage":90,"evidenceCount":423,"publicEvidenceCount":291,"organizations":2238,"bestGrade":41,"headline":2243,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2244},"personalized-marketing-at-scale","AI marketing personalization at scale","Marketing personalization at scale","AI that runs marketing campaigns at the level of the individual: it decides for each customer which product, offer, message or content to show next across email, app, web and paid media, and generates the matching copy and creative variants within brand and compliance rules. It is the marketing team's engine across many campaigns and channels, not an agent that converses with the customer.",[142,272,691,143,84],[387,112],[369,28,180],[1690,2239,95,2240,2241,2227,2242],"Catchtable","Radisson Hotel Group","Square Enix","Virgin Voyages",{"kpi":376,"label":377,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":242,"organization":2239,"vendorReported":12},"Most personalization and content generation is minimal risk. Providers of systems that generate synthetic audio, image, video or text content must mark the output as artificially generated, and deployers must disclose deep fakes (Article 50(2) and 50(4)). Personalization that deploys manipulative or deceptive techniques, or exploits vulnerabilities due to age, disability or a specific social or economic situation, in a way that causes or is reasonably likely to cause significant harm, is prohibited under Article 5(1)(a) and (b). Using AI to assess creditworthiness or to price life and health insurance is high risk under Annex III point 5(b) and 5(c) and belongs on its own page. Outside the AI Act, the FCA Consumer Duty applies only to FCA regulated firms (the financial services slice of this use case), and the Telephone Consumer Protection Act applies only to campaigns delivered by call or text message in the US.",{"slug":2246,"title":2247,"shortTitle":2248,"definition":2249,"status":19,"industries":2250,"functions":2251,"patterns":2252,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2253,"bestGrade":41,"headline":2256,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2258},"medical-coding-automation","AI medical coding for clinical encounters","Medical coding automation","AI that reads the clinical documentation of an encounter and assigns the diagnosis and procedure codes (such as ICD-10, CPT and HCPCS) needed for billing and reporting, either as suggestions for a certified coder or autonomously for encounters it can code with high confidence, sending the rest to coders with the reasons.",[144],[613,87],[29,163],[2254,665,2255],"Mass General Brigham","Your Health",{"kpi":310,"label":311,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2257,"qualifier":134,"claimant":51,"organization":2255,"vendorReported":11},98.3,"Assigning billing and statistical codes from clinical documentation is not listed in Annex III and does not decide on a person's access to care, so no specific AI Act obligations apply beyond AI literacy. Health data processing falls under GDPR Article 9, and in the United States under HIPAA and the payment integrity rules of public payers. Minimal under the AI Act does not mean low stakes: the Veterans Health Administration classifies its computer assisted coding deployment on this page as high impact in the 2025 US federal AI use case inventory, even though coders select every code.",{"slug":2260,"title":2261,"shortTitle":2262,"definition":2263,"status":19,"industries":2264,"functions":2265,"patterns":2266,"audience":181,"autonomy":182,"adoptionStage":90,"segment":91,"evidenceCount":34,"publicEvidenceCount":34,"organizations":2267,"bestGrade":41,"headline":2270,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2272},"client-meeting-notes-and-crm-update","AI meeting notes and CRM update for wealth advisors","Advisor meeting notes","An AI notetaker for wealth advisors that turns a client advice meeting, recorded with the client's consent, into the file note, follow up message and CRM record the firm needs to evidence its advice; unlike a general meeting summarizer, its output becomes part of the regulated client record. It drafts a structured note with the client's goals, circumstances, decisions and action items, and writes it into the CRM once the advisor has approved it.",[273,84],[112,177,87],[179,661,26,180],[149,2268,877,2149,357,2269],"Commerzbank","UniSuper",{"kpi":782,"label":783,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2271,"qualifier":134,"claimant":242,"organization":357,"vendorReported":12},15,"Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.",{"slug":2274,"title":2275,"shortTitle":2276,"definition":2277,"status":19,"industries":2278,"functions":2279,"patterns":2280,"audience":181,"autonomy":182,"adoptionStage":90,"evidenceCount":190,"publicEvidenceCount":190,"organizations":2281,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2285},"meeting-summarization-and-action-items","AI meeting summarization and action items","Meeting summaries and action items","AI that summarizes internal and operational meetings, such as team, project, board and case meetings: it transcribes an online or in person meeting with the participants' knowledge and produces a summary, decisions and action items with owners and dates for the organizer to check and share. It is the general purpose tool; client advice meetings and sales calls, which feed a regulated record or a sales pipeline, have their own pages.",[142,469,232,253],[659,87],[179,661],[2282,2283,2284,1911,748],"U.S. Department of Labor","Ministry of Justice","Softcat","Transcribing and summarizing meetings for the participants is minimal risk. It becomes high risk under Annex III point 4(b) if transcripts are analysed to monitor or evaluate individual workers' performance or behaviour, and inferring participants' emotions from their voices or faces at work is prohibited by Article 5(1)(f). Recording and transcription also need a lawful basis and clear information to participants under GDPR.",{"slug":2287,"title":2288,"shortTitle":2289,"definition":2290,"status":19,"industries":2291,"functions":2292,"patterns":2293,"audience":30,"autonomy":182,"adoptionStage":114,"segment":2294,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2295,"bestGrade":239,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":2298},"media-archive-metadata-tagging","AI metadata tagging and indexing for media archives","Media archive metadata tagging","AI that watches and listens to a broadcaster's or publisher's video and audio archive and generates rich, structured metadata, such as what is shown, who appears, spoken content, on screen text, logos and objects, so that content makers can find and reuse footage through natural language search instead of relying on the sparse, inconsistent tags an archive accumulated by hand over decades.",[691],[659,87],[216,661,29],"content operations",[2296,2297],"Australian Broadcasting Corporation","Radiotelevisión Española (RTVE)","Cataloguing objects, scenes, logos and spoken content is not listed in Annex III and is typically minimal risk. Annex III point 1(a) covers remote biometric identification: the automated, one to many matching of a person's face or voice, without their active involvement and typically at a distance, against a reference database of identified individuals to establish who they are, in so far as its use is permitted under relevant Union or national law; it excludes one to one biometric verification. A feature that recognises and names a specific person in archive footage by comparing them against such a database meets that definition and is high risk, while grouping similar looking footage without assigning an identity does not. Article 6(3) lets a provider assess a listed system itself as not high risk when it performs only a narrow procedural task, but that derogation is unlikely to cover a system whose purpose is naming an individual, so treat person recognition as high risk by default. Point 1(b) covers biometric categorisation, inferring a sensitive or protected attribute from a person's face or voice. RTVE's 2025 contract specifies speaker gender identification as a feature; whether that counts as a protected attribute under point 1(b) is contested, since Recital 54 ties that category to attributes protected under GDPR Article 9(1), and sex or gender is not listed there. Treat gender inference from voice as potentially high risk and apply the same governance the organization uses for other biometric systems until that question is settled.",{"slug":2300,"title":2301,"shortTitle":2302,"definition":2303,"status":19,"industries":2304,"functions":2305,"patterns":2306,"audience":181,"autonomy":182,"adoptionStage":114,"segment":2307,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2308,"bestGrade":41,"headline":2311,"lastVerified":75,"indexable":12,"euAiActTier":358,"euAiActBasis":2312},"ai-drug-discovery-platform","AI native platform for drug target discovery and molecule design","AI drug discovery platform","An AI native research platform that prioritizes disease targets from biological data, generates and optimizes candidate drug molecules computationally, and predicts their properties before a chemist synthesizes and tests them, so a pharmaceutical or biotech company reaches a validated preclinical candidate with far fewer molecules made and tested than a conventional medicinal chemistry program.",[611],[87,678],[28,180],"drug discovery",[2309,2310],"Insilico Medicine","Recursion Pharmaceuticals",{"kpi":43,"label":44,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":603,"qualifier":101,"claimant":51,"organization":2309,"vendorReported":11},"Target scoring and molecule generation are not a safety component of an Annex I product and are not one of the Annex III high risk areas (Article 6), so they do not become high risk on that route. Insofar as the platform and its training are themselves scientific research and development, activity that stays there falls outside the Regulation entirely under the Article 2(6) research exclusion. The resulting drug candidate is separately regulated as a medicine, not as an AI system, through the normal pharmaceutical approval pathway; conventional preclinical and clinical testing validates the AI's outputs before anything reaches a patient.",{"slug":2314,"title":2315,"shortTitle":2316,"definition":2317,"status":19,"industries":2318,"functions":2319,"patterns":2320,"audience":181,"autonomy":68,"adoptionStage":114,"segment":91,"evidenceCount":190,"publicEvidenceCount":190,"organizations":2321,"bestGrade":41,"headline":2322,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2323},"next-best-action-for-advisors","AI next best action prompts for wealth advisors","Advisor next best action","An AI engine for wealth advisors, not customers, that scans an advisor's whole book and surfaces a short, ranked list of client specific prompts, such as idle cash, a maturing deposit, a concentration to review, a life event or an early sign of attrition, each with the reasoning and data behind it, for the advisor to act on or dismiss.",[273,84],[112,387,678],[369,28,180],[838,1028,984,877,2186],{"kpi":431,"label":432,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":784,"qualifier":134,"claimant":51,"organization":2186,"vendorReported":11},"Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.",{"slug":2325,"title":2326,"shortTitle":2327,"definition":2328,"status":19,"industries":2329,"functions":2330,"patterns":2331,"audience":67,"autonomy":182,"adoptionStage":32,"segment":203,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2332,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":2333},"corporate-account-onboarding-orchestration","AI orchestration of corporate account opening and channel setup","Corporate onboarding operations","An AI agent that runs the operational setup of a corporate client after the due diligence has been approved: it reads mandates, board resolutions and signatory documents, prepares accounts, users, roles and payment entitlements for approval, configures channel access, and chases outstanding items with the client, turning a manual setup that passes between several teams into a tracked, guided flow.",[84],[583,87],[26,163,65,180],[1028,1059],"Operational setup of accounts and entitlements for corporate clients is not listed in Annex III and makes no decision about a natural person's access to a service or creditworthiness. The agent chases documents directly with client staff, so Article 50(1) applies: the provider must design the system so that they are informed that they are interacting with an AI system, unless that is obvious from the context. A purely internal version without client contact would be minimal risk.",{"slug":2335,"title":2336,"shortTitle":2337,"definition":2338,"status":19,"industries":2339,"functions":2340,"patterns":2341,"audience":30,"autonomy":182,"adoptionStage":32,"segment":183,"evidenceCount":92,"publicEvidenceCount":69,"organizations":2342,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2344},"portfolio-drift-monitoring-and-rebalancing","AI portfolio drift monitoring and rebalancing proposals","Drift and rebalancing","Continuous monitoring of every client portfolio against its mandate or model, which detects drift beyond agreed bands and prepares a tax aware, low turnover rebalancing proposal with its rationale for an advisor or portfolio manager to approve before any trade is placed.",[273,84],[87,201,678],[27,26,28,180],[877,2343,839],"SimCorp","Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.",{"slug":2346,"title":2347,"shortTitle":2348,"definition":2349,"status":19,"industries":2350,"functions":2351,"patterns":2352,"audience":181,"autonomy":68,"adoptionStage":114,"segment":2353,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2354,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":2357},"freight-rail-rolling-stock-predictive-maintenance","AI predictive maintenance for freight rail rolling stock","Rail rolling stock predictive maintenance","Machine vision and machine learning that inspect freight railcar wheels, bearings and other running gear as trains pass wayside sensors and camera portals at track speed, learn what a healthy wheel or a healthy reading looks like, and flag the ones that need attention before a crack, an overheating bearing or a worn wheel causes a service failure or a derailment.",[366],[87,214],[216,27,28],"mechanical-and-safety",[2355,2356],"BNSF Railway","Norfolk Southern","A system that flags a wheel or railcar for a qualified inspector to confirm is advisory and usually minimal risk. Under Article 6(1) it is high risk when both conditions hold: the same detection logic is built into a safety component of rolling stock or track equipment (or is itself such a product) covered by Directive (EU) 2016/797 on the interoperability of the rail system, which sits in Annex I Section B, for example if a flag were wired to trigger an automatic stop or speed restriction without a human check, and that directive requires a third party conformity assessment of the product. Under Article 2(2), as amended by Regulation (EU) 2026/1744, a high risk system of that kind is not subject to the full AI Act: only Article 6(1), Article 60a and Articles 102 to 112 apply directly, and Articles 57, 58 and 59 apply only so far as the high risk requirements have been integrated into the interoperability directive. The substantive high risk requirements reach the system through that directive instead, which Article 106 of the AI Act amends to require rail delegated and implementing acts to take those requirements into account.",{"slug":2359,"title":2360,"shortTitle":2361,"definition":2362,"status":19,"industries":2363,"functions":2364,"patterns":2365,"audience":181,"autonomy":68,"adoptionStage":114,"segment":2366,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2367,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2370},"industrial-asset-predictive-maintenance","AI predictive maintenance for industrial and energy assets","Industrial predictive maintenance","Machine learning that learns the normal behaviour of industrial and energy equipment from sensor and process data, flags early signs of degradation weeks or months before a failure, and turns them into prioritised maintenance work, so plants and utilities plan repairs instead of reacting to breakdowns.",[251,885],[87,214],[27,28],"asset-management",[2368,1157,2369],"Duke Energy","Shell","A system that advises engineers on the condition of equipment is usually minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; if predictive maintenance acts on protection or control in a utility network, it can become high risk. Article 6(1) can also apply when the AI is a safety component of machinery or another product covered by Annex I legislation and that product must undergo a third party conformity assessment.",{"slug":2372,"title":2373,"shortTitle":2374,"definition":2375,"status":19,"industries":2376,"functions":2377,"patterns":2378,"audience":181,"autonomy":68,"adoptionStage":90,"segment":2379,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2380,"bestGrade":41,"headline":2383,"lastVerified":75,"indexable":12,"euAiActTier":243,"euAiActBasis":2385},"radiology-worklist-triage","AI prioritization of radiology and imaging worklists","Radiology worklist triage","An AI system that analyzes a medical image immediately after a scan, flags time sensitive findings such as a brain bleed, a stroke causing large vessel occlusion or a pulmonary embolism, and reorders the radiologist's worklist and notifies the care team so the most urgent cases are read and acted on first, while a radiologist confirms every finding before it changes a patient's treatment.",[144],[87],[216,29,27],"emergency and inpatient imaging",[2381,2382],"Adventist Health + Rideout","Sheba Medical Center",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2384,"qualifier":101,"claimant":242,"organization":2381,"vendorReported":12},44,"Article 6(1) and Annex I: software that analyzes a medical image to detect or prioritize a disease finding is itself, or is a safety component of, a device in scope of the EU Medical Device Regulation, and typically needs a notified body conformity assessment as software as a medical device (the FDA's AI Enabled Medical Device List shows US market authorization for devices in this category, listing authorized stroke triage devices from Viz.ai and Aidoc's BriefCase triage devices), which makes it high risk under the EU AI Act regardless of Annex III. The radiologist's own diagnostic read stays a human decision; the AI narrows and reorders the queue. Annex I high risk classification under Article 6(1) applies from 2 August 2028 (Article 113(c)); until then, Article 4 (AI literacy obligations) and Article 5 (prohibited practices), which bind the hospital as a deployer, already apply.",{"slug":2387,"title":2388,"shortTitle":2389,"definition":2390,"status":19,"industries":2391,"functions":2392,"patterns":2393,"audience":30,"autonomy":31,"adoptionStage":90,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2394,"bestGrade":41,"headline":2397,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2400},"product-content-and-catalog-enrichment","AI product content and catalog enrichment for online retail","Product content and catalog enrichment","AI that writes and repairs product content at catalog scale: it drafts titles, descriptions and image alt text, and extracts missing attributes such as color, size and material from supplier text and product images, then checks its own output before the content is published to the store and to search engines. A human owns the rules, the quality thresholds and the exceptions.",[143,142],[387,87],[180,216,29],[1690,2395,2396,893],"eBay","Etsy",{"kpi":2398,"label":2399,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1821,"qualifier":134,"claimant":51,"organization":1690,"vendorReported":11},"quality-score-uplift","Quality score uplift","Writing product content and extracting catalog attributes is not an Annex III use and makes no decisions about people. When a retailer uses a third party generator, the use is minimal risk for the retailer: the Article 50(2) duty to mark generated text in a machine readable way falls on the provider of that system. When a retailer builds and operates its own generating system and puts it into service under its own name, it is the provider and must mark the output, unless the exception for systems that only assist standard editing or do not substantially alter the input applies. Article 50(4) covers text published to inform the public on matters of public interest, not product listings. Consumer protection law applies to what the listing says in every case.",{"slug":2402,"title":2403,"shortTitle":2404,"definition":2405,"status":19,"industries":2406,"functions":2407,"patterns":2408,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":190,"organizations":2409,"bestGrade":239,"headline":2415,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":2416},"call-quality-and-compliance-monitoring","AI quality and compliance monitoring of every customer interaction","Call quality and compliance","Automated quality assurance that transcribes and scores every customer interaction, voice and chat, against the organization's own rubric, checking required disclosures and script adherence, flagging conduct and mis selling risk, and surfacing coaching opportunities, instead of the small sample a human QA team can review.",[142,84,174,251,21,143],[63,177,87],[661,29,179],[2410,2411,2412,2413,2414],"British Gas","Central Bank","DoorDash","Oportun","VitalityHealth",{"kpi":2398,"label":2399,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":1778,"qualifier":101,"claimant":242,"organization":2410,"vendorReported":12},"Scoring individual agents' interactions to monitor and evaluate their performance and behaviour falls under Annex III point 4(b), employment and worker management. The Article 6(3) exception does not apply where the system profiles natural persons. Inferring agents' emotions is prohibited under Article 5(1)(f), except for medical or safety reasons. Inferring customers' emotions from their voice is emotion recognition on biometric data: high risk under Annex III point 1(c), and Article 50(3) requires informing the people exposed to it. Analytics that only aggregate interaction themes without evaluating individuals can fall outside the high risk category.",{"slug":2418,"title":2419,"shortTitle":2420,"definition":2421,"status":19,"industries":2422,"functions":2423,"patterns":2424,"audience":181,"autonomy":31,"adoptionStage":114,"segment":1154,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2425,"bestGrade":41,"headline":2428,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2429},"production-line-quality-inspection","AI quality inspection on the production line","Production quality inspection","AI that inspects every unit on a production line, from camera images, sound or machine process data, to find defects, missing parts and wrong variants in real time, and routes the few anomalies it flags to a quality inspector instead of relying on manual sampling at the end of the line.",[885,252],[87],[216,27,2066,26],[2426,1156,2427],"Audi","Pegatron",{"kpi":262,"label":263,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":291,"qualifier":134,"claimant":242,"organization":2427,"vendorReported":12},"Inspecting products is not an Annex III use, so a system that only judges parts, welds or assemblies is usually minimal risk. Two designs change that. Under Article 6(1) it is high risk when both conditions hold: it is a safety component of a product (or itself a product) covered by the Union harmonisation legislation in Annex I, and that law requires a third party conformity assessment of the product. For a production line the relevant product laws are the Machinery Regulation (EU) 2023/1230 and, for cars, the vehicle type approval regulations. Since the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the Machinery Regulation into Annex I Section B, where the vehicle type approval regulations already sat. Article 6(1) still classifies such a safety component as high risk, but under Article 2(2) only Article 6(1), Article 60a and Articles 102 to 112 of the AI Act apply directly. The requirements reach the system through the sectoral law instead: delegated acts amending Annex III of the Machinery Regulation, and type approval for vehicles. The AI Act rules for Article 6(1) high risk systems apply from 2 August 2028. An inspection system on the assembly line is usually not a safety component of the product it inspects. If it monitors and evaluates the performance and behaviour of individual workers, for example by scoring who made an assembly error, it falls under Annex III point 4(b) and is high risk. Keep the output about the unit, not the person.",{"slug":2431,"title":2432,"shortTitle":2433,"definition":2434,"status":19,"industries":2435,"functions":2436,"patterns":2437,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2438,"bestGrade":239,"headline":2442,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2444},"sales-quote-and-estimate-generation","AI quote and estimate generation from customer requirements","Quote and estimate generation","AI that turns what a customer sends, such as a product list, a drawing, a roof photo or a request for quotation, into a draft quote: it reads the input, matches items to the catalog, calculates quantities and applies the organization's price rules, and hands the draft to a seller or estimator who checks and sends it.",[142,885,251,143],[112,706],[163,26,216],[2439,2440,2441],"DeAcero","Enpal","The ODP Corporation",{"kpi":667,"label":668,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2443,"qualifier":134,"claimant":242,"organization":2440,"vendorReported":12},87.5,"Drafting business quotes for a seller to review is not an Annex III use and does not interact with the customer as an AI system. It would need a fresh assessment if the system set individual consumer prices or terms in areas such as credit or insurance, where Annex III point 5 can apply.",{"slug":2446,"title":2447,"shortTitle":2448,"definition":2449,"status":19,"industries":2450,"functions":2451,"patterns":2452,"audience":30,"autonomy":147,"adoptionStage":90,"segment":2453,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2454,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":2457},"content-recommendation-and-personalization","AI recommendation and personalization engine for streaming and media","Content recommendation and personalization","A recommendation system that decides, for each individual viewer or listener, what to show next on a home page, in search or in a personalized playlist, learned from that person's own viewing or listening history, ratings and context, and continuously updated as new content is added and behavior changes. It ranks the catalog's own content; it is not the marketing engine that decides which offers or campaigns to send, which is a separate use case in this library.",[691],[387,678],[369,28],"content discovery",[2455,2456],"Netflix, Inc.","Spotify","Recommendation and personalization systems are not listed in Annex III, so most deployments are minimal risk under the EU AI Act. They become a compliance question elsewhere: manipulative or deceptive techniques that materially distort a person's behavior in a way that causes significant harm, or that exploit vulnerabilities linked to age, disability or a specific social or economic situation, are a prohibited practice under Article 5(1)(a) and (b), which is relevant to recommendation systems that target children. A decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on a person falls under GDPR Article 22, though routine content ranking rarely meets that bar on its own.",{"slug":2459,"title":2460,"shortTitle":2461,"definition":2462,"status":19,"industries":2463,"functions":2464,"patterns":2465,"audience":181,"autonomy":182,"adoptionStage":32,"segment":257,"evidenceCount":93,"publicEvidenceCount":46,"organizations":2466,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2467},"loan-restructuring-recommendations","AI recommendations for loan restructuring and hardship arrangements","Restructuring recommendations","An assistant that assembles a stressed borrower's position, tests restructuring options such as a term extension, rate relief, payment holiday or due date change against policy and affordability, and recommends the best fit with a written rationale for a person to approve.",[84],[255,199,201],[26,66,163,369],[95],"Recommending restructuring terms for individuals involves assessing their ability to pay, which can amount to evaluating the creditworthiness of natural persons under Annex III point 5(b). Human approval alone does not remove that: the Article 6(3) exception covers only systems that do not materially influence the decision, such as a narrow procedural or preparatory task, and never applies when the system profiles natural persons. A tool that only assembles the case file can fall under the exception; restructuring for companies is outside point 5(b).",{"slug":2469,"title":2470,"shortTitle":2471,"definition":2472,"status":19,"industries":2473,"functions":2474,"patterns":2475,"audience":181,"autonomy":182,"adoptionStage":90,"evidenceCount":34,"publicEvidenceCount":34,"organizations":2476,"bestGrade":41,"headline":2481,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":2482},"email-and-ticket-reply-drafting","AI reply drafting for customer email and support tickets","Email and ticket reply drafting","A copilot for asynchronous service work that drafts the reply to an incoming customer email, message or ticket once it has reached an agent: it summarizes the request, pulls the relevant customer data and approved knowledge, and drafts a reply in the organization's tone and the customer's language for the agent to check, edit and send. Live calls and chats, and the sorting of the inbox itself, are separate use cases.",[142,469,84,21,232],[63,87],[180,179,66,29],[1878,2477,2478,2479,2480,850],"First National Bank","HYPE","Nomad eSIM","Transportation Security Administration",{"kpi":43,"label":44,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":413,"qualifier":101,"claimant":242,"organization":2478,"vendorReported":12},"A drafting copilot whose output an agent reviews and sends falls under the transparency tier at most. When replies are sent without human review, customers interact with the AI system directly, and Article 50(1) requires that they are informed unless this is obvious from the context. Article 50(2) separately requires the provider of a system that generates text to mark its output in a machine readable format as artificially generated, whether or not a person reviews the draft. It becomes high risk only if it is used for a purpose listed in Annex III, such as evaluating eligibility for public benefits or creditworthiness (point 5), or evaluating the performance of the agents who use it (point 4).",{"slug":2484,"title":2485,"shortTitle":2486,"definition":2487,"status":19,"industries":2488,"functions":2489,"patterns":2490,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2491,"bestGrade":41,"headline":2493,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":2495},"conversation-roleplay-training","AI roleplay training for customer conversations","Conversation roleplay training","A training simulator in which generative AI plays a realistic customer, by voice or text, so service, sales and crisis staff can rehearse difficult conversations as often as they need before they handle live ones, and receive structured feedback against the organization's own standards.",[142,84,174,21,469,144],[234,63,112],[65,89,180],[149,2492,475],"GoHealth",{"kpi":376,"label":377,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":2494,"qualifier":134,"claimant":242,"organization":2492,"vendorReported":12},21,"Used only for practice and feedback, the simulator is limited risk. Article 50 requires that people know they are interacting with AI unless that is obvious from the context, as it usually is in a training session, and the provider must mark synthetic voice or text output as AI generated in a machine readable format. It becomes high risk under Annex III point 4(b) if its scores are used to evaluate the performance of workers or to decide on their promotion or termination, and can fall under point 3(b) when a vocational training institution uses it to evaluate learning outcomes. Inferring trainees' emotions from voice or face in the workplace is prohibited under Article 5(1)(f), except for medical or safety reasons.",{"slug":2497,"title":2498,"shortTitle":2499,"definition":2500,"status":19,"industries":2501,"functions":2502,"patterns":2503,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2504,"bestGrade":239,"headline":2507,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2508},"sales-call-coaching-and-crm-update","AI sales call coaching and CRM update","Sales call coaching and CRM update","AI for sales teams that analyses sales calls and meetings against the team's own sales method to coach sellers and their managers, and writes the call summary, next steps and opportunity updates into the CRM for the seller to confirm. Its purpose is winning deals and building selling skill, not the regulated advice record or general meeting notes.",[142,21,885,174],[112],[661,179,180],[2505,491,2506,866],"Hughes Network Systems","Sandvik Coromant",{"kpi":187,"label":188,"unit":189,"n":46,"nUpTo":46,"kind":48,"value":69,"qualifier":134,"claimant":51,"organization":2506,"vendorReported":11},"Summaries, CRM suggestions and follow up drafts that the seller reviews are not an Annex III use and are minimal risk. Using call analysis to monitor and evaluate the performance and behaviour of individual sellers, or to allocate leads to sellers based on their behaviour or personal traits, is high risk under Annex III point 4(b). Inferring sellers' emotions from their voice is prohibited in the workplace by Article 5(1)(f). Emotion recognition applied to customers' voices is high risk under Annex III point 1(c), and Article 50(3) requires deployers to inform the people exposed to it.",{"slug":2510,"title":2511,"shortTitle":2512,"definition":2513,"status":19,"industries":2514,"functions":2515,"patterns":2516,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":34,"publicEvidenceCount":34,"organizations":2517,"bestGrade":41,"headline":2518,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":2520},"scam-payment-interception","AI scam intervention for instant payments","Scam payment interception","AI that talks to the customer when they are about to authorise an instant payment that looks like a scam: it combines the payee check and the risk score, asks targeted questions about the payment in plain language, explains the specific scam pattern, and holds, delays or escalates the payment to a human specialist when the risk stays high. Unlike fraud scoring, which stops payments the customer did not make, it protects customers from payments they are being manipulated into making.",[84,85],[161,63],[65,28,26,89],[95,1910,340,1336,221,341],{"kpi":1370,"label":1371,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":2519,"qualifier":134,"claimant":242,"organization":1336,"vendorReported":12},300,"Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.",{"slug":2522,"title":2523,"shortTitle":2524,"definition":2525,"status":19,"industries":2526,"functions":2527,"patterns":2528,"audience":30,"autonomy":31,"adoptionStage":90,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2529,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":2533},"automated-scoring-of-written-responses","AI scoring of essays and written answers in assessments","Essay and written answer scoring","AI that scores students' essays and short written answers against a rubric, trained on responses scored by human raters, with human raters rescoring a sample of responses and every response the engine is unsure about. In hybrid programmes such as Texas, a human score is the score of record whenever a human scores a response.",[61,469],[87],[29,28],[2530,2531,2532],"ETS","Massachusetts Department of Elementary and Secondary Education","Texas Education Agency","Annex III point 3(b): AI systems intended to be used to evaluate learning outcomes in educational and vocational training institutions at all levels are high risk. Scoring that determines access to an institution or the level of education a student will receive is also covered by points 3(a) and 3(c). Schools and exam bodies that use such a system have the deployer obligations of Article 26.",{"slug":2535,"title":2536,"shortTitle":2537,"definition":2538,"status":19,"industries":2539,"functions":2540,"patterns":2541,"audience":30,"autonomy":31,"adoptionStage":32,"segment":203,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2542,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2544},"trade-finance-crime-screening","AI screening of trade finance transactions for trade based money laundering","Trade crime screening","AI that screens every trade finance transaction for financial crime risk: it checks parties, vessels and ports against sanctions and watchlists, tests goods descriptions against dual use and controlled goods lists, compares unit prices with benchmarks for over or under invoicing, and reads trade documents and messages for laundering red flags, then prepares a case narrative for a human investigator.",[84],[584,87],[163,27,29,179],[1321,1323,2543],"United Bank Limited","Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.",{"slug":2546,"title":2547,"shortTitle":2548,"definition":2549,"status":19,"industries":2550,"functions":2551,"patterns":2552,"audience":67,"autonomy":147,"adoptionStage":114,"evidenceCount":1778,"publicEvidenceCount":190,"organizations":2553,"bestGrade":41,"headline":2556,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":2557},"conversational-shopping-assistant","AI shopping assistant for product discovery and recommendations","Conversational shopping assistant","A conversational assistant on a retailer's site or app that answers product questions, compares items and recommends products from the retailer's own catalog for a need, project or occasion described in the shopper's own words, grounded in product data, reviews and stock, and hands the shopper to a basket, a store or a human expert.",[142,143],[112,387,63],[65,369,66,26],[1690,2554,457,893,2555],"Lowe's","Zalando",{"kpi":376,"label":377,"unit":814,"n":46,"nUpTo":47,"kind":48,"value":69,"qualifier":134,"claimant":242,"organization":457,"vendorReported":12},"A shopping assistant interacts directly with people, so under Article 50(1) shoppers must be informed that they are dealing with an AI system unless that is obvious. It is not listed in Annex III, so it is not high risk. Manipulative or deceptive techniques that materially distort a shopper's behaviour and cause significant harm are prohibited under Article 5(1)(a), which matters for how persuasion and urgency are designed.",{"slug":2559,"title":2560,"shortTitle":2561,"definition":2562,"status":19,"industries":2563,"functions":2564,"patterns":2565,"audience":67,"autonomy":147,"adoptionStage":90,"segment":2109,"evidenceCount":190,"publicEvidenceCount":190,"organizations":2566,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":2567},"spam-and-scam-call-blocking","AI spam and scam call blocking for mobile and landline subscribers","Spam and scam call blocking","AI in the operator's network that protects subscribers from unwanted calls: it analyses incoming calls in real time, blocks known fraudulent calls, and labels suspected scam, spam and spoofed calls on the customer's screen before they answer, so subscribers can decide whether to pick up. Fraud against the operator itself, such as SIM swap or revenue share fraud, is a separate use case.",[21],[161,63],[27,29,28],[1142,282,40,219],"Scoring, blocking and labelling calls is not listed in Annex III, is not a prohibited practice under Article 5, and the system does not interact with people or generate content, so Article 50 does not apply. A conversational scambaiting agent such as O2's Daisy talks to callers with a synthetic voice, which raises separate Article 50 transparency questions and should be assessed on its own.",{"slug":2569,"title":2570,"shortTitle":2571,"definition":2572,"status":19,"industries":2573,"functions":2574,"patterns":2575,"audience":30,"autonomy":31,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2576,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2579},"procurement-spend-classification","AI spend classification and spend analytics for procurement","Spend classification","AI that reads purchase orders, invoices, card transactions and contracts and assigns each line of spend to a category in the organization's taxonomy, and to the right supplier, so that procurement can see what is bought, from whom and where to consolidate or negotiate.",[142,469,885,144],[887,613,678],[29,163,179],[2577,892,827,2578],"U.S. General Services Administration","Veterans Health Administration","Classifying the organization's own purchase lines into categories is not listed in Annex III and is used internally by procurement staff, so no specific obligations apply beyond AI literacy. The data can still contain personal data, for example in purchasing card and expense lines, which brings GDPR duties. Using the classified card and expense lines to monitor or evaluate individual employees would move the system towards Annex III point 4 (employment and worker management) and a high risk assessment.",{"slug":2581,"title":2582,"shortTitle":2583,"definition":2584,"status":19,"industries":2585,"functions":2586,"patterns":2587,"audience":181,"autonomy":182,"adoptionStage":114,"segment":91,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2588,"bestGrade":41,"headline":2589,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2591},"investment-research-summarization","AI summaries of investment research and the house view","Research summaries","An AI assistant that condenses long research reports, overnight market moves and the house view into short, sourced briefings for advisors and analysts, answers \"what is our view on X\" on demand, and adapts approved research for different client segments and languages, with every figure traced to the original research.",[273,772,84],[678,112,659],[179,66,180,629],[1028,588,877,2186],{"kpi":187,"label":188,"unit":189,"n":47,"nUpTo":46,"kind":48,"value":2590,"qualifier":634,"claimant":51,"organization":588,"vendorReported":11},120,"Summarizing research for staff is not an Annex III use and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. It is minimal for a purchased internal tool with no client or public facing exposure. Article 50 transparency applies when the firm builds the generating system itself, which brings the Article 50(2) duty to mark synthetic text in a machine readable format; when the assistant is offered to clients as a chatbot, which brings the Article 50(1) duty to tell them they are interacting with AI; or when AI generated text is published to inform the public on matters of public interest, which brings the Article 50(4) disclosure duty unless the text has gone through human review or editorial control and a person holds editorial responsibility for it.",{"slug":2593,"title":2594,"shortTitle":2595,"definition":2596,"status":19,"industries":2597,"functions":2598,"patterns":2599,"audience":181,"autonomy":182,"adoptionStage":114,"segment":200,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2600,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":2601},"life-underwriting-medical-record-summarization","AI summarization of medical evidence for life and health underwriting","Life underwriting medical summaries","AI that reads the medical evidence behind a life or health insurance application (attending physician statements, electronic health records, lab results and disclosures), turns it into a structured, cited summary of conditions, treatments and dates, and maps it to the insurer's underwriting manual so an underwriter can decide faster and more consistently.",[174],[200],[163,179,66],[864,865],"Annex III point 5(c): AI intended for risk assessment and pricing in relation to natural persons in life and health insurance. Article 6(3) exempts some purely preparatory tasks, but never a system that profiles natural persons. Extracting an applicant's health conditions and mapping them to the underwriting manual evaluates their health, which is profiling, so treat the system as high risk. Under the timeline as amended, the obligations for Annex III high risk systems apply from 2 December 2027, and Article 27 requires deployers of point 5(c) systems to assess the impact on fundamental rights before first use.",{"slug":2603,"title":2604,"shortTitle":2605,"definition":2606,"status":19,"industries":2607,"functions":2608,"patterns":2609,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2610,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":243,"euAiActBasis":2613},"emergency-call-triage-support","AI support for emergency call triage (112 and 911)","Emergency call triage support","AI that supports emergency call takers and dispatchers during 112 and 911 calls, with live transcription, translation, summaries, location cues and alerts for critical conditions such as cardiac arrest, while the call taker keeps every triage and dispatch decision.",[469,144],[721,87],[661,629,179,28],[2611,2612,1763],"Baltimore City 911 (Emergency Communications)","Copenhagen Emergency Medical Services","Annex III point 5(d): AI systems intended to evaluate and classify emergency calls or to dispatch or set priority for emergency first response services (police, fire, medical aid) are high risk. Pure transcription that performs a narrow procedural or preparatory task may fall outside it under the Article 6(3) exceptions, but alerts that influence triage are in scope. An AI agent that speaks with callers directly, for example on a non emergency line, must also tell them they are interacting with AI (Article 50).",{"slug":2615,"title":2616,"shortTitle":2617,"definition":2618,"status":19,"industries":2619,"functions":2620,"patterns":2621,"audience":181,"autonomy":31,"adoptionStage":90,"segment":257,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2622,"bestGrade":41,"headline":74,"lastVerified":75,"indexable":12,"euAiActTier":53,"euAiActBasis":2626},"property-valuation-support","AI support for property valuation and appraisal","Property valuation support","AI, most often an automated valuation model, that estimates a property's market value from comparable sales, property characteristics and location data, and either offers to replace a full appraisal within set limits or gives a professional valuer a first pass estimate, the closest comparable sales and a reliability score, so the valuer's time goes to the properties that need a person's judgment.",[110,84,469],[199,176,87],[28,29],[2623,2624,2625],"Fannie Mae","Riverside County Assessor-County Clerk-Recorder","Valuation Office Agency","An automated valuation model values the collateral, not the person, so it is not itself listed in Annex III; the EU Mortgage Credit Directive treats property valuation (Article 19) and the creditworthiness assessment of the borrower (Article 18) as separate steps, and Article 18(3) says the creditworthiness assessment must not be based predominantly on the value of the property exceeding the amount of credit, or on an assumption that the property's value will increase. The valuation becomes relevant to Annex III point 5(b), creditworthiness assessment of natural persons, only where its output is built into a separate system that evaluates the borrower's creditworthiness, and whether that happens depends on how the lender designs the credit decision, not on the valuation model itself.",{"slug":2628,"title":2629,"shortTitle":2630,"definition":2631,"status":19,"industries":2632,"functions":2633,"patterns":2634,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":92,"publicEvidenceCount":92,"organizations":2635,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2637},"ai-model-inventory","AI system and model inventory with shadow AI discovery","AI model inventory","A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.",[142,84,174,469,885],[201,177,24],[26,163,66,29],[1495,2636,2175,1520],"Office of Management and Budget","Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.",{"slug":2639,"title":2640,"shortTitle":2641,"definition":2642,"status":19,"industries":2643,"functions":2644,"patterns":2645,"audience":181,"autonomy":182,"adoptionStage":32,"evidenceCount":34,"publicEvidenceCount":190,"organizations":2646,"bestGrade":41,"headline":2651,"lastVerified":52,"indexable":12,"euAiActTier":358,"euAiActBasis":2653},"requirements-to-test-case-generation","AI that turns requirements into user stories, acceptance criteria and test cases","Requirements to test cases","AI that reads product requirements, specifications or recorded sessions, checks them for gaps, ambiguity and contradictions, and drafts structured user stories, acceptance criteria and test cases (for example in Gherkin) that QA engineers review, with each item traced back to the requirement it covers.",[232,469,84,142],[24],[180,163],[2647,2648,2649,2650,475],"BrowserStack","Continental AG","LTIMindtree","National Aeronautics and Space Administration",{"kpi":43,"label":44,"unit":45,"n":46,"nUpTo":46,"kind":48,"value":2652,"qualifier":134,"claimant":242,"organization":2649,"vendorReported":12},67,"An internal assistant that drafts requirements artifacts and test cases for engineers is not listed in Annex III and does not interact with the public, so no specific obligations apply beyond AI literacy (Article 4). The system under test may itself fall under the Act.",{"slug":2655,"title":2656,"shortTitle":2657,"definition":2658,"status":19,"industries":2659,"functions":2660,"patterns":2661,"audience":30,"autonomy":182,"adoptionStage":90,"evidenceCount":34,"publicEvidenceCount":190,"organizations":2662,"bestGrade":239,"headline":2668,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":2669},"audio-and-video-transcription-and-captioning","AI transcription, subtitles and captions for audio and video","Transcription and captioning","AI that transcribes recorded audio and video, such as podcasts, broadcasts, lessons, interviews and hearings, in several languages, separates the speakers and produces timed transcripts, subtitles and captions for a human editor to check, delivered as files for publishing or the archive.",[691,61,142],[87,659],[661,629,180],[2663,2664,2665,2666,2667],"Ateme","Comeen","Pacers Sports & Entertainment","Sveriges Television (SVT)","Warner Bros. Discovery",{"kpi":262,"label":263,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":413,"qualifier":134,"claimant":242,"organization":2667,"vendorReported":12},"Transcription and captioning are not listed in Annex III and are not a prohibited practice under Article 5, so the tier depends on how captions are published. Article 50(4) requires deployers to disclose AI generated or manipulated text published to inform the public on matters of public interest, such as news captions, unless it has undergone human review or editorial control and someone holds editorial responsibility, so the editor step keeps most deployments outside this duty. The provider duty to mark output in Article 50(2) does not apply where the system does not substantially alter the input or its semantics, which fits same language transcription better than translated subtitles. Unreviewed news captions or subtitles should therefore be disclosed as automatic.",{"slug":2671,"title":2672,"shortTitle":2673,"definition":2674,"status":19,"industries":2675,"functions":2676,"patterns":2677,"audience":67,"autonomy":182,"adoptionStage":114,"evidenceCount":423,"publicEvidenceCount":423,"organizations":2678,"bestGrade":41,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":53,"euAiActBasis":2681},"public-service-translation","AI translation and interpretation for multilingual public services","Public service translation","AI that translates government content, documents and conversations between officials and the public, in writing and in real time speech, so people can use public services in their own language, with human translators and interpreters reviewing what carries legal or safety weight.",[469],[721,63,87],[629,65,661,163],[2611,2679,2680,726,892,750,751,1627],"Delaware County","European Commission","Assistants that talk with residents must tell people they are interacting with AI (Article 50(1)), and AI generated text published to inform the public on matters of public interest must be disclosed unless it has had human review under editorial responsibility (Article 50(4)). Internal translation that neither talks with people nor is published carries no specific obligation. Translation can also sit inside an Annex III process, such as examining asylum, visa or residence permit applications (point 7(c)) or evaluating emergency calls and dispatching emergency services (point 5(d)). Whether the translation component is itself high risk depends on its intended purpose (Article 6(3) exempts systems that only perform a narrow procedural task); either way it should be governed with that high risk process.",{"slug":2683,"title":2684,"shortTitle":2685,"definition":2686,"status":19,"industries":2687,"functions":2688,"patterns":2689,"audience":67,"autonomy":31,"adoptionStage":114,"evidenceCount":34,"publicEvidenceCount":190,"organizations":2690,"bestGrade":41,"headline":2695,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":2696},"travel-and-hotel-booking-concierge","AI travel and hotel booking concierge","Travel and hotel booking concierge","A customer facing AI assistant that turns an open travel question into a concrete trip by searching live inventory for flights, hotels, rentals, cruises and activities, comparing options and answering questions about the property and the booking, then completes or hands off the booking and supports the traveller with changes and questions before and during the stay.",[272],[112,63],[65,369,66,26],[280,2691,2692,2693,2694],"Booking.com","Holland America Line","Priceline","Trip.com",{"kpi":325,"label":326,"unit":45,"n":46,"nUpTo":47,"kind":48,"value":527,"qualifier":134,"claimant":51,"organization":2691,"vendorReported":11},"A customer facing assistant must tell people they are interacting with AI unless that is obvious from the context (Article 50(1), applicable from 2 August 2026). Recommending and booking travel is not listed in Annex III, so it is not high risk; consumer protection law on price transparency and fair commercial practices still applies to what it says.",{"slug":2698,"title":2699,"shortTitle":2700,"definition":2701,"status":19,"industries":2702,"functions":2703,"patterns":2704,"audience":67,"autonomy":68,"adoptionStage":32,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2705,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2709},"ai-tutor-for-students","AI tutor that coaches students through problems","AI tutor for students","An AI tutor that works with a student on course material in a conversation, asking questions and giving hints instead of handing over answers, grounded in the course content and set up by the school or teacher, with limits on use and a clear route to a human teacher.",[61],[63],[65,66],[2706,2707,2708],"Hamilton County Schools","Harvard University","World Bank","A tutor that only converses with students falls under the transparency duty of Article 50. It becomes high risk under Annex III point 3(b) when it evaluates learning outcomes, including when those outcomes are used to steer a student's learning process, and under point 3(c) when it assesses the level of education a student should receive. Inferring students' emotions is prohibited in education institutions under Article 5(1)(f).",{"slug":2711,"title":2712,"shortTitle":2713,"definition":2714,"status":19,"industries":2715,"functions":2716,"patterns":2717,"audience":181,"autonomy":182,"adoptionStage":114,"segment":2718,"evidenceCount":93,"publicEvidenceCount":93,"organizations":2719,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2722},"power-line-vegetation-management","AI vegetation management for power lines","Power line vegetation management","AI that analyses satellite, aerial or lidar imagery of the land along power lines to estimate where and how fast vegetation will grow into the lines or fall onto them, and turns that into a risk based trimming and hazard tree removal plan, replacing fixed trimming cycles and manual patrols.",[251],[23,214],[216,28],"grid",[2720,2721],"Entergy","National Grid","Annex III point 2 makes AI systems high risk when they are intended as safety components in the management and operation of the supply of electricity. Recital 55 defines such components as systems used to directly protect the physical integrity of critical infrastructure or the health and safety of persons and property. A system that only feeds a multi year trimming plan, which vegetation planners review and approve before crews act, informs maintenance rather than directly protecting the network, and is then usually minimal risk. The assessment changes when the design acts directly on protection, for example when vegetation risk scores automatically trigger fire risk protection settings or switch lines off without a person deciding; such a system should be assessed as a possible safety component. Standard GDPR duties apply where imagery shows private property or people.",{"slug":2724,"title":2725,"shortTitle":2726,"definition":2727,"status":19,"industries":2728,"functions":2729,"patterns":2730,"audience":67,"autonomy":147,"adoptionStage":114,"evidenceCount":190,"publicEvidenceCount":92,"organizations":2731,"bestGrade":239,"headline":74,"lastVerified":52,"indexable":12,"euAiActTier":76,"euAiActBasis":2735},"ai-visitor-and-tour-guide","AI visitor and tour guide for cities, museums and events","Visitor and tour guide","A location and context aware AI guide, often spoken, that tells visitors of cities, museums, heritage sites and events the stories behind what is around them and answers their questions in their own language, grounded in the organization's curated content and in the visitor's position or the object they scan.",[272,691,469],[63,387,659],[66,65,89,216,629],[2732,2733,750,2734],"Art Basel","Bloomberg Connects","National Gallery Singapore","A visitor facing assistant must make clear that people are interacting with AI (Article 50), and synthetic speech should be identifiable as AI generated. It is not high risk. It would change if the camera feature were used to identify or categorise visitors by biometric data, which a guide does not need: remote biometric identification, biometric categorisation and emotion recognition are high risk under Annex III point 1, and biometric categorisation that infers sensitive traits is prohibited under Article 5.",{"slug":2737,"title":2738,"shortTitle":2739,"definition":2740,"status":19,"industries":2741,"functions":2742,"patterns":2743,"audience":67,"autonomy":31,"adoptionStage":114,"segment":862,"evidenceCount":46,"publicEvidenceCount":46,"organizations":2744,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2745},"conversational-insurance-quote-and-buy","Conversational AI for insurance quote and buy","Conversational quote and buy","A customer facing AI agent that sells insurance directly in a conversation: it asks the rating questions in plain language, explains cover options, returns a price from the insurer's rating engine, handles objections and takes payment to bind the policy, with a licensed human available for advice and anything outside its limits.",[174],[112,63],[65,26,369,89],[306],"The conversational layer carries the Article 50 transparency duty. If the system assesses risk or sets prices for life or health insurance of natural persons, that part is high risk under Annex III point 5(c); pricing for property and casualty products is not listed.",{"slug":2747,"title":2748,"shortTitle":2749,"definition":2750,"status":19,"industries":2751,"functions":2752,"patterns":2753,"audience":67,"autonomy":31,"adoptionStage":114,"segment":91,"evidenceCount":34,"publicEvidenceCount":190,"organizations":2754,"bestGrade":239,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2757},"conversational-loan-application-intake","Conversational AI for loan application intake","Loan application intake","A conversational assistant on web, app, messaging or voice that explains loan products, captures the application through dialogue in the customer's language, checks documents and basic eligibility rules, and hands a complete, structured application to origination, without making the credit decision.",[84],[199,112,63],[65,163,66,89],[2755,2160,185,2756,392],"Absa Bank","Oper Credits","Explaining products and capturing an application is limited risk with an Article 50 disclosure. If the assistant evaluates creditworthiness or filters applicants on its own assessment, it falls under Annex III point 5(b) and becomes high risk, so keep the decision in the governed credit process.",{"slug":2759,"title":2760,"shortTitle":2761,"definition":2762,"status":19,"industries":2763,"functions":2764,"patterns":2765,"audience":30,"autonomy":31,"adoptionStage":114,"segment":183,"evidenceCount":46,"publicEvidenceCount":46,"organizations":2766,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2768},"dynamic-customer-risk-rating","Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[84,85,273],[584,201],[28,27],[2767],"bunq","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",{"slug":2770,"title":2771,"shortTitle":2772,"definition":2773,"status":19,"industries":2774,"functions":2775,"patterns":2776,"audience":181,"autonomy":182,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2777,"bestGrade":239,"headline":2781,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2782},"internal-audit-copilot","Generative AI copilot for internal audit","Internal audit copilot","A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.",[142,84,174,469,772,273],[201,177,613],[66,179,180,163,27],[2778,2779,2780],"Banco Bradesco","British Columbia Investment Management Corporation","XP Inc.",{"kpi":667,"label":668,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":1469,"qualifier":134,"claimant":242,"organization":2778,"vendorReported":12},"An internal drafting and analysis assistant for auditors that makes no decisions about natural persons. It would need reassessment if used to evaluate individual employees' behaviour or performance, which falls under Annex III point 4(b).",{"slug":2784,"title":2785,"shortTitle":2786,"definition":2787,"status":19,"industries":2788,"functions":2789,"patterns":2790,"audience":67,"autonomy":147,"adoptionStage":114,"segment":2791,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2792,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":2795},"in-car-ai-voice-assistant","Generative AI voice assistant in the car","In car voice assistant","A voice assistant built into the vehicle that uses a large language model to hold a natural conversation with the driver and passengers, controls comfort, navigation and media functions, answers questions about the car and the world, and keeps the vehicle's own commands and data under the car maker's control.",[252],[63,706],[89,65,66,26],"connected-car",[1156,2793,2794],"Mercedes-Benz Group","Volkswagen","Article 50(1): people must be informed that they are interacting with an AI system unless that is obvious from the context. Article 50(2): synthetic audio output must be marked as artificially generated. A cabin assistant for comfort, media, navigation and knowledge questions is not an Annex III use. It would move towards the high risk regime if it became a safety component of the vehicle: vehicle type approval legislation is listed in Annex I Section B, and under Article 2(2) the high risk requirements reach those products only through the amendments the AI Act makes to that legislation. Keep driving and safety functions out of its reach.",{"slug":2797,"title":2798,"shortTitle":2799,"definition":2800,"status":19,"industries":2801,"functions":2802,"patterns":2803,"audience":181,"autonomy":68,"adoptionStage":114,"evidenceCount":69,"publicEvidenceCount":69,"organizations":2804,"bestGrade":41,"headline":74,"lastVerified":102,"indexable":12,"euAiActTier":76,"euAiActBasis":2807},"governed-text-to-sql-analytics","Governed text to SQL analytics assistant","Governed SQL analytics","An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.",[142,84,174,143,232,611],[678,24],[65,794,66],[1832,2805,2806],"LinkedIn","Uber Technologies","Article 50(1) requires providers to design AI systems that interact directly with people so that those people are informed they are dealing with AI, unless this is obvious from the context, as it usually is for an internal assistant. An analytics assistant that makes no decisions about people is not a prohibited practice under Article 5 and is not listed in Annex III. It would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)).",{"slug":2809,"title":2810,"shortTitle":2811,"definition":2812,"status":19,"industries":2813,"functions":2814,"patterns":2815,"audience":181,"autonomy":68,"adoptionStage":90,"evidenceCount":291,"publicEvidenceCount":190,"organizations":2816,"bestGrade":41,"headline":2818,"lastVerified":102,"indexable":12,"euAiActTier":53,"euAiActBasis":2819},"live-agent-assist","Real time AI assist for contact centre agents","Live agent assist","A real time copilot for human contact centre agents during a live call or chat: it transcribes the conversation as it happens, surfaces the relevant knowledge and next step, drafts responses, and writes the after call summary and CRM notes, while the agent stays in control of what is said and done.",[142,84,174,21,144,143,232],[63,87],[661,66,179,180],[96,2817,2413,357,1310],"Definity",{"kpi":782,"label":783,"unit":45,"n":93,"nUpTo":47,"kind":48,"value":2271,"qualifier":134,"claimant":242,"organization":2817,"vendorReported":12},"As a pure assist tool for agents it is minimal risk; the customer does not interact with the AI. It becomes high risk under Annex III point 4(b) if its data is used to monitor and evaluate individual agents' performance, and inferring agents' emotions at work is prohibited under Article 5(1)(f).",{"slug":2821,"title":2822,"shortTitle":2823,"definition":2824,"status":19,"industries":2825,"functions":2826,"patterns":2827,"audience":30,"autonomy":147,"adoptionStage":90,"segment":183,"evidenceCount":486,"publicEvidenceCount":486,"organizations":2828,"bestGrade":41,"headline":2831,"lastVerified":102,"indexable":12,"euAiActTier":358,"euAiActBasis":2832},"real-time-fraud-scoring","Real time fraud scoring for card and instant payments","Real time fraud scoring","Machine learning that decides in milliseconds, without any conversation, how likely each card authorization and account to account payment is to be fraudulent, combining behavioural, device and network signals, so the bank can approve, challenge or block a payment before the money leaves. Working the resulting alerts and talking to the customer about them are separate use cases.",[84,85],[161],[28,27],[1749,95,1910,129,2829,340,2830,166],"Pay.UK","Stripe",{"kpi":343,"label":344,"unit":45,"n":69,"nUpTo":47,"kind":223,"value":527,"qualifier":134,"claimant":51,"organization":74,"vendorReported":11},"Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.",1790598318950]