Regulation
PSD2 and AI use cases
Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.
Read the source text (European Union)Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI agent for complaints recognition, investigation and response
Complaint handling is not listed in Annex III, so internal classification and drafting for a handler who decides is minimal risk. Where the agent talks to customers to take the complaint, Article 50(1) requires telling them they are dealing with AI. Only a system that also assessed creditworthiness or priced life and health insurance (Annex III point 5(b) or 5(c)) would be high risk for that part.
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI agent for account and card servicing
Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.
- AI agent for ATM and self service device assistance
A customer facing assistant must tell people they are interacting with an AI system unless that is obvious (Article 50(1)). It does not evaluate creditworthiness (Annex III point 5(b)) or eligibility for public assistance benefits (point 5(a)), so it is not high risk; biometric verification whose sole purpose is to confirm identity is excluded from Annex III point 1(a).
- AI agent for card dispute intake
A customer facing assistant must tell people they are interacting with an AI system (Article 50(1)). It triages and opens cases but does not evaluate creditworthiness (Annex III point 5(b), which in any case excludes systems used to detect financial fraud) or decide access to an essential service, so it is not high risk under Annex III.
- AI agent for fraud alert confirmation with cardholders
Confirming flagged transactions with cardholders is not listed in Annex III, and point 5(b) expressly excludes AI used to detect financial fraud from the creditworthiness category, so the system is not high risk. An agent that messages or calls customers must tell them they are dealing with AI under Article 50(1), and synthetic voice output must be marked as AI generated under Article 50(2).
- AI agent for payment initiation within a customer mandate
A customer facing agent must make clear that people are dealing with AI, unless that is obvious from the context (Article 50). Initiating payments within a customer's mandate is not listed in Annex III. It becomes high risk if the same agent evaluates creditworthiness, for example by deciding on a buy now pay later or credit line at checkout (Annex III point 5(b)).
- AI scam intervention for instant payments
Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI agent for fraud alert triage
Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.
- AI for payment investigations and exceptions
Handling payment exceptions is not a use listed in Annex III and is not a prohibited practice under Article 5. If the agent interacts directly with customers, for example in a chat about the case, Article 50(1) requires that they are told they are interacting with an AI system.
- Real time fraud scoring for card and instant payments
Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.