Regulation
ISO/IEC 42001 and AI use cases
The international management system standard for AI.
Read the source text (ISO and IEC)High risk under the EU AI Act
Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.
- AI agent for drafting employee performance reviews
Annex III point 4(b) lists AI systems intended to monitor and evaluate the performance and behaviour of workers as high risk. Synthesising an employee's work history and feedback into a performance evaluation is very plausibly profiling of a natural person under GDPR Article 4(4), which expressly covers analysing or predicting a person's "performance at work". Article 6(3)'s last subparagraph makes an Annex III system high risk regardless of the derogations whenever it performs such profiling, so a tool built this way is high risk by default however much the manager edits the output. The derogations in Article 6(3), including a narrow procedural task or improving the result of a previously completed human activity, do not fit drafting an evaluation from scratch; the closest is point (d), a preparatory task ahead of a human assessment, which only has a chance of applying to a design that avoids profiling altogether, for example one that only surfaces raw facts without synthesising a judgement. Where that derogation is argued, the documentation duty under Article 6(4) falls on the provider of the system, and only on the deploying organization when it builds the tool itself. Because the tool is high risk by default, Article 26(7) requires informing affected workers and their representatives before it is put into use in the workplace, whatever the tool's output is used for; using the same system's output directly in pay, promotion or termination decisions removes any doubt and triggers the full high risk regime. Annex III's high risk obligations apply from 2 December 2027.
- AI for benefit fraud and error detection in social security
Annex III point 5(a): AI systems used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, or to grant, reduce, revoke or reclaim them. A fundamental rights impact assessment (Article 27) is required before a public body deploys it. A design that scores people over time on their social behaviour or personal characteristics and leads to unrelated or disproportionate detrimental treatment would fall under the Article 5(1)(c) prohibition on social scoring.
- AI for recruitment screening and interview scheduling
Annex III point 4(a) lists AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications and to evaluate candidates. Screening, ranking and scoring applications is therefore high risk. A component limited to a narrow procedural task, such as booking interview slots or answering process questions, can fall outside the high risk category under Article 6(3), but only if it does not materially influence the outcome and does not profile people, and that assessment must be documented (Article 6(4)). Deployers of the high risk part must follow the instructions for use, assign competent human oversight, keep logs, inform workers' representatives and inform candidates that a high risk system is used (Article 26). An organization that builds its own screening system becomes its provider, with conformity assessment duties. The chatbot part also carries the Article 50 disclosure duty.
- AI prioritization of radiology and imaging worklists
Article 6(1) and Annex I: software that analyzes a medical image to detect or prioritize a disease finding is itself, or is a safety component of, a device in scope of the EU Medical Device Regulation, and typically needs a notified body conformity assessment as software as a medical device (the FDA's AI Enabled Medical Device List shows US market authorization for devices in this category, listing authorized stroke triage devices from Viz.ai and Aidoc's BriefCase triage devices), which makes it high risk under the EU AI Act regardless of Annex III. The radiologist's own diagnostic read stays a human decision; the AI narrows and reorders the queue. Annex I high risk classification under Article 6(1) applies from 2 August 2028 (Article 113(c)); until then, Article 4 (AI literacy obligations) and Article 5 (prohibited practices), which bind the hospital as a deployer, already apply.
- AI quality and compliance monitoring of every customer interaction
Scoring individual agents' interactions to monitor and evaluate their performance and behaviour falls under Annex III point 4(b), employment and worker management. The Article 6(3) exception does not apply where the system profiles natural persons. Inferring agents' emotions is prohibited under Article 5(1)(f), except for medical or safety reasons. Inferring customers' emotions from their voice is emotion recognition on biometric data: high risk under Annex III point 1(c), and Article 50(3) requires informing the people exposed to it. Analytics that only aggregate interaction themes without evaluating individuals can fall outside the high risk category.
- AI scoring of essays and written answers in assessments
Annex III point 3(b): AI systems intended to be used to evaluate learning outcomes in educational and vocational training institutions at all levels are high risk. Scoring that determines access to an institution or the level of education a student will receive is also covered by points 3(a) and 3(c). Schools and exam bodies that use such a system have the deployer obligations of Article 26.
- AI summarization of medical evidence for life and health underwriting
Annex III point 5(c): AI intended for risk assessment and pricing in relation to natural persons in life and health insurance. Article 6(3) exempts some purely preparatory tasks, but never a system that profiles natural persons. Extracting an applicant's health conditions and mapping them to the underwriting manual evaluates their health, which is profiling, so treat the system as high risk. Under the timeline as amended, the obligations for Annex III high risk systems apply from 2 December 2027, and Article 27 requires deployers of point 5(c) systems to assess the impact on fundamental rights before first use.
- AI support for emergency call triage (112 and 911)
Annex III point 5(d): AI systems intended to evaluate and classify emergency calls or to dispatch or set priority for emergency first response services (police, fire, medical aid) are high risk. Pure transcription that performs a narrow procedural or preparatory task may fall outside it under the Article 6(3) exceptions, but alerts that influence triage are in scope. An AI agent that speaks with callers directly, for example on a non emergency line, must also tell them they are interacting with AI (Article 50).
Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- Agentic AI for autonomous, intent based network operations
Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk; Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. Loops that only optimise performance or capacity are usually not safety components, but a loop that protects physical integrity or life safety services can be, so operators should assess each closed loop and document the outcome.
- AI agent for source of wealth due diligence in private banking
Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.
- AI ambient scribe for clinical documentation
A scribe that only transcribes and summarises for a clinician to review is not listed in Annex III and is usually minimal risk, although the provider of a system that generates text can still owe the Article 50(2) duty to mark output as AI generated, unless an exception such as an assistive function for standard editing applies. If the product qualifies as medical device software under the EU Medical Device Regulation and needs a notified body assessment, for example because it suggests diagnoses or treatment, it becomes high risk under Article 6(1) and Annex I. Health data in audio and notes falls under GDPR Article 9 in every case.
- AI assistant for benefits eligibility questions and applications
Annex III point 5(a) makes AI high risk when it is used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, or to grant, reduce, revoke or reclaim them. An assistant that only explains rules and guides applications carries the Article 50 transparency duties (limited risk); one that screens or scores eligibility falls under point 5(a), and a public body deploying it must carry out a fundamental rights impact assessment first (Article 27).
- AI assistant for digital account onboarding and KYC
The conversational assistant falls under the Article 50 transparency duty. Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from the Annex III biometric category. The system becomes high risk when the same journey assesses creditworthiness or a credit score of a natural person, for example for a credit card or overdraft (Annex III point 5(b)).
- AI assistant for employee onboarding
Answering onboarding questions and orchestrating provisioning is limited risk: under Article 50(1) the assistant must be designed so that employees are told they are interacting with AI, unless that is obvious. It becomes high risk under Annex III point 4(b) if it is used to make decisions on the terms or termination of the work relationship, to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate new hires' performance or behaviour, for example to judge probation.
- AI assistant for goal based financial planning
Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).
- AI assistant for HR and policy questions
Answering policy questions and starting routine requests is limited risk, with the Article 50 duty to disclose AI. It becomes high risk under Annex III point 4 if it is used to make or support decisions on recruitment, promotion, termination, allocating tasks based on individual behaviour or personal traits, or the monitoring and evaluation of workers; an employer deploying it then must also inform workers' representatives and the affected workers before use (Article 26(7)). Sensitive topic detection should work on what the employee writes: inferring emotions of people in the workplace from biometric data such as voice or facial expressions is prohibited under Article 5(1)(f), except for medical or safety reasons.
- AI assistant for insurance brokers and agents
An employee facing assistant for knowledge answers and drafting is not listed in Annex III and is minimal risk. A lead qualification agent that talks to customers must tell them they are dealing with AI (Article 50). Using performance insights to monitor and evaluate individual agents, or to allocate leads based on their behaviour or traits, is high risk under Annex III point 4(b), and any component that does risk assessment or pricing of life or health insurance for individuals is high risk under Annex III point 5(c).
- AI assistant for investment suitability assessment and reports
Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.
- AI assistant for procurement and supplier contract review
Contract review and sourcing are not among the Annex III high risk uses, so an internal assistant that makes no decisions about natural persons is minimal risk (with the Article 4 AI literacy duty). If a negotiation bot chats directly with supplier staff, Article 50(1) applies and it must tell them they are dealing with an AI system, unless that is obvious from the context. Public authorities using AI in procurement should still check national public procurement rules on transparency and equal treatment of bidders.
- AI command center for hospital bed and staff capacity planning
The tier depends on what the system is scoped to do. A design limited to occupancy and discharge forecasting and to sequencing bed assignments for patients already admitted is operational decision support for hospital logistics, outside Annex III. Annex III point 5(d) covers AI used "to dispatch, or to establish priority in the dispatching of, emergency first response services", including medical aid and emergency healthcare patient triage systems. On a plain reading, that point can apply when a system dispatches, or sets the priority of dispatching, ambulance or critical care transport itself (work similar to what the Johns Hopkins center's Lifeline transport staff do for helicopter and ambulance transfers), or when it assesses the clinical urgency of an emergency patient, that is, triage. Sequencing which already admitted ED patient gets the next ward bed, and deciding whether to accept an inter hospital transfer request on capacity grounds, are not listed activities under 5(d) as written; whether either counts as dispatching or triage in a given deployment is a case by case legal question, not a settled fact, and should be assessed with counsel before relying on this tier. For public hospitals, Annex III point 5(a) (access to essential public services, including healthcare) can also be relevant. Scoping the system to bed sequencing and transfer acceptance only, and keeping every ambulance dispatch and ED triage decision with clinical staff outside the AI's recommendation, is what keeps a deployment in the lower tier.
- AI copilot for insurance pricing and actuarial analysis
Pricing and risk assessment of natural persons for life and health insurance is high risk under Annex III point 5(c). Pricing for property and casualty products, and actuarial analysis that does not price individuals, are not listed, although supervisors still expect sound model governance.
- AI copilot for network operations centre fault triage
The main test is Annex III point 2, which lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk. A copilot that prepares diagnoses for engineers who decide every change is normally not such a safety component, and is then minimal risk. The tier rises when the system is designed to protect the safe operation of the network, for example by acting on it automatically to prevent or contain outages. Article 6(3) can exempt an Annex III system that only performs a preparatory task to an assessment and poses no significant risk of harm, provided the provider documents that assessment and registers the system.
- AI copilot for underwriting risk assessment
For commercial property and casualty lines the copilot is not listed in Annex III. Used for risk assessment of natural persons in life or health insurance it falls under Annex III point 5(c) and is high risk, with risk management, data governance, logging and human oversight duties, and deployers must carry out a fundamental rights impact assessment under Article 27.
- AI document intelligence for unstructured forms and documents
Classifying documents and extracting data for a person or process to use is usually minimal risk. Even inside an Annex III area, a system that only performs a narrow procedural task, such as splitting and classifying documents, can fall outside the high risk category under Article 6(3); the provider must document that assessment and register the system (Article 6(4) and Article 49(2)). The picture changes when extraction materially influences decisions in Annex III areas, such as eligibility for public assistance benefits (point 5(a)), creditworthiness (point 5(b)) or asylum, visa and residence permit applications (point 7), where the whole system must be assessed as potentially high risk. The Article 6(3) exception never applies when the system performs profiling of natural persons.
- AI drafting of clinical study reports and regulatory documents
Drafting regulated documents for expert review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the sponsor's role under Article 50. A sponsor that deploys a third party drafting tool has no specific AI Act obligations beyond AI literacy: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which clinical study reports and regulatory submissions are not. For that sponsor the tier is minimal. A sponsor that builds its own generating system, as Merck (a proprietary platform) and Novo Nordisk (NovoScribe) did, is its provider under Article 50(2) and must mark the synthetic text in a machine readable format, unless the exemption for an assistive function for standard editing applies; drafting whole report sections goes beyond that exemption, so for that sponsor the tier is limited. Quality expectations come from medicines regulation and EMA guidance: the EMA reflection paper expects close human supervision and quality review when AI drafts medicinal product information documents, and makes the clinical trial sponsor, marketing authorisation applicant or holder, or manufacturer responsible for ensuring that models and data pipelines are fit for purpose and meet GxP standards and EMA guidelines.
- AI financial wellbeing coach in the banking app
The conversational assistant carries the Article 50 transparency duty: customers must be told they are interacting with an AI system. The system becomes high risk if it is used to evaluate the creditworthiness of natural persons or establish their credit score (Annex III point 5(b)). Article 5(1)(b) prohibits AI that exploits vulnerabilities due to a person's specific social or economic situation to materially distort their behaviour in a way that causes, or is reasonably likely to cause, significant harm.
- AI for business onboarding (KYB) and beneficial ownership discovery
Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.
- AI for claims triage and straight through processing
Claims handling as such is not listed in Annex III. The same system becomes high risk when it is also used for risk assessment and pricing of natural persons in life and health insurance (point 5(c)), or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim essential public assistance benefits and services, including healthcare services (point 5(a)). Otherwise the tier is minimal, so the design and the operator decide. Decisions on claims based solely on automated processing are also subject to Article 22 of the GDPR and the UK GDPR.
- AI for continuous controls testing and control self assessment
Testing controls over transactions and systems is not an Annex III use. Controls that monitor and evaluate individual employees' behaviour, such as trading or access conduct, can fall under Annex III point 4(b), so the design decides the tier.
- AI for court and case file summarization
Annex III point 8(a) makes AI high risk when it is intended to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts. Tools for prosecutors fall under point 6(c) if they evaluate the reliability of evidence, and tools that assist the examination of asylum, visa or residence applications fall under point 7(c). Under Article 6(3) a system that only performs a narrow procedural task or a preparatory task, such as organising a file or transcribing and summarising it for the person who decides, may not be high risk, but the provider must document that assessment (Article 6(4)). Summaries of internal legal advice for government lawyers, as Amsterdam plans, are generally outside Annex III.
- AI for creating employee training and eLearning content
Generating training content is not listed in Annex III. Providers of tools that generate synthetic audio, image, video or text content must mark the output as AI generated (with an exception for assistive editing that does not substantially alter the source), and deployers must disclose deep fakes, such as an avatar or voice that resembles a real person and would falsely appear authentic (Article 50(2) and (4), with the definition in Article 3(60)). If the same system evaluates learning outcomes or decides access to training that affects a person's work, Annex III point 3 (education and vocational training) and point 4 (employment) must be checked, and those parts can be high risk.
- AI for eDiscovery and disclosure document review
Document review for a party in civil litigation or an internal investigation is not listed in Annex III, so it is usually minimal risk. It becomes high risk where a law enforcement authority uses AI to evaluate the reliability of evidence in the investigation or prosecution of criminal offences (Annex III point 6(c)), or where a judicial authority uses it to research and interpret facts and law (point 8(a)). Prosecutors and investigators should classify each use against those points.
- AI for health insurance prior authorization and claims adjudication support
Annex III point 5(a) makes AI high risk when it is used by or on behalf of public authorities to evaluate eligibility for essential public assistance benefits and services, including healthcare services, or to grant, reduce or revoke them, which can cover statutory health schemes run by or for public bodies. Point 5(c) covers risk assessment and pricing in life and health insurance, not claim review. A copilot for a private insurer's claim review, where people decide, is usually outside Annex III; for public schemes, Article 6(3) may exempt a system that only performs a preparatory task, unless it profiles natural persons. GDPR rules on health data (Article 9) and on solely automated decisions (Article 22) apply in every case.
- AI for immigration and visa applications, from applicant questions to case preparation
Annex III point 7(c) makes AI high risk when it assists public authorities in examining applications for asylum, visas or residence permits, including assessing the reliability of evidence. Applicant facing information assistants that give general guidance fall under the Article 50 transparency duties (limited risk). Evidence classification, routing and interview support used in the examination are likely high risk, unless the provider documents under Article 6(3) that a component only performs a narrow procedural or preparatory task. That exception never applies to a system that profiles natural persons, which matters for routing on personal attributes or risk profiles.
- AI for insurance claims fraud detection
Claims fraud detection by an insurer is not listed in Annex III, and point 5(b) explicitly excludes AI systems used to detect financial fraud from the credit scoring category. Point 5(c) covers only risk assessment and pricing in life and health insurance, so a fraud model becomes high risk when it also feeds those decisions, or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim public assistance benefits (point 5(a)). Profiling and automated decisions remain subject to GDPR, including Article 22 where a claim is refused on a decision based solely on automated processing.
- AI for market abuse surveillance alert triage
Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).
- AI for mobile network planning and capacity optimization
Forecasting demand, ranking congested cells and recommending investments is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and Recital 55 ties this to the digital infrastructure in the Annex to Directive (EU) 2022/2557, which includes providers of public electronic communications networks. Recital 55 defines such safety components as systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property and that are not necessary for the system to function. Closed loop parameter optimisation on the live radio network is high risk only when it serves in that role, for example a loop whose purpose is to protect emergency call availability, so each automated loop should be assessed against point 2 and the outcome documented. Loops that only optimise performance or capacity are usually not safety components.
- AI for permit and licence application processing
Permit and licence decisions are not listed as such in Annex III, so officer decision support is usually minimal risk, and an assistant that talks to applicants carries the Article 50 transparency duty. The exceptions are permits in an Annex III area: examining applications for visas and residence permits (point 7) and evaluating eligibility for essential public assistance benefits and services (point 5(a)) are high risk. Solely automated decisions with legal or similarly significant effects on a person fall under GDPR Article 22 whatever the tier.
- AI for pharmacovigilance adverse event case intake
Internal intake, extraction and coding for review by safety staff is not listed in Annex III and is usually minimal risk. A public facing reporting assistant must tell people they are talking to an AI under Article 50. The main obligations come from pharmacovigilance law and good pharmacovigilance practices, which require validated, inspectable processes, and from GDPR rules on health data.
- AI for predictive network maintenance in telecom
Scoring failure risk and planning maintenance is normally minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall within that infrastructure. Recital 55 limits safety components to systems that directly protect the physical integrity of the infrastructure or the health and safety of persons and property, and excludes components used solely for cybersecurity. An operator whose automated actions meet that test must treat the system as high risk.
- AI for radio access network energy optimization
Optimizing energy use is normally minimal risk. Under Article 6(2), Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure as high risk, and public electronic communications networks fall under that infrastructure. Recital 55 limits safety components to systems that directly protect the infrastructure or the health and safety of persons, so an optimizer is not high risk by default, but a design in which it could affect emergency service availability should be assessed against point 2.
- AI for risk based inspection prioritization in food safety, workplace and environmental regulation
Prioritizing inspections of businesses and premises is not a use listed in Annex III, so such a system is usually not high risk. The assessment changes when it scores natural persons, such as individual licensed professionals or sole traders, and the inspectorate acts as a law enforcement authority: assessing the risk that a person offends, or profiling persons in the detection or investigation of criminal offences, is high risk under Annex III point 6 (d) and (e), and predicting that a person will commit a criminal offence based solely on profiling is prohibited by Article 5(1)(d). GDPR applies wherever sole traders, home based businesses or named professionals are scored.
- AI for security alert triage and investigation in the SOC
Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.
- AI for settlement fail prediction and post trade exception management
Predicting settlement fails and handling post trade exceptions between professional market participants is not a use listed in Annex III and is not a prohibited practice under Article 5, so the tier depends on how the agent communicates. While an operator reviews and sends every message, the system is minimal risk: the messages are the firm's own correspondence and the firm as deployer owes AI literacy for staff (Article 4). Once the agent sends queries or chasers to counterparty or custodian staff itself, as the playbook recommends for routine information requests, it interacts directly with natural persons and Article 50(1) requires telling the recipients they are dealing with an AI system. In both designs the provider of the text generating system must mark its output as AI generated in a machine readable format under Article 50(2). Model risk and operational resilience controls apply on top.
- AI for tax compliance risk scoring and audit selection
Risk selection for administrative tax audits is not listed in Annex III, and Recital 59 says systems used by tax and customs authorities in administrative proceedings should not be treated as high risk law enforcement systems. Use in criminal tax investigations (Annex III point 6, law enforcement), or evaluating the eligibility of natural persons for public assistance benefits run through the tax system (Annex III point 5(a)), can make it high risk. When individuals are scored in administrative tax work, the GDPR applies, including its profiling rules (Member States may restrict some rights for taxation matters under Article 23). Article 22 applies when a decision with legal or similarly significant effect is taken solely by the model. Criminal investigations fall outside the GDPR and under the Law Enforcement Directive (EU) 2016/680 instead.
- AI for voice of the customer and feedback analysis
Classifying and summarizing text feedback is minimal risk. The tier changes if the system infers emotions from customers' voices or faces in calls or video: emotion recognition based on biometric data is listed as high risk in Annex III point 1(c) and triggers the Article 50(3) duty to inform the people exposed. Analysing feedback from employees to evaluate individual workers moves it towards Annex III point 4(b), and emotion recognition in the workplace is prohibited by Article 5(1)(f), except for medical or safety reasons.
- AI generated client portfolio reports and commentary
Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.
- AI internal talent marketplace for matching employees to projects, roles and mentors
Annex III point 4 lists AI used for the recruitment or selection of natural persons (4(a)) and AI used to make decisions affecting promotion, or to allocate tasks based on individual behaviour, personal traits or characteristics (4(b)). A marketplace that ranks employees for internal roles or allocates projects on the basis of inferred traits is therefore high risk. Recommending learning content or mentors to an employee who chooses freely is usually not. Deployers of the high risk part must inform workers' representatives and the affected employees before use (Article 26).
- AI legal research and drafting assistant for lawyers
Research and drafting support for lawyers in firms and companies is not listed in Annex III, so it is normally minimal risk with AI literacy duties. Annex III point 8(a) makes it high risk when a judicial authority, or someone on its behalf, uses AI to research and interpret facts and the law and to apply the law to a concrete set of facts, or when it is used in a similar way in alternative dispute resolution, so a deployment for courts, tribunals or arbitration needs its own classification.
- AI meeting summarization and action items
Transcribing and summarizing meetings for the participants is minimal risk. It becomes high risk under Annex III point 4(b) if transcripts are analysed to monitor or evaluate individual workers' performance or behaviour, and inferring participants' emotions from their voices or faces at work is prohibited by Article 5(1)(f). Recording and transcription also need a lawful basis and clear information to participants under GDPR.
- AI next best action prompts for wealth advisors
Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.
- AI portfolio drift monitoring and rebalancing proposals
Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.
- AI predictive maintenance for freight rail rolling stock
A system that flags a wheel or railcar for a qualified inspector to confirm is advisory and usually minimal risk. Under Article 6(1) it is high risk when both conditions hold: the same detection logic is built into a safety component of rolling stock or track equipment (or is itself such a product) covered by Directive (EU) 2016/797 on the interoperability of the rail system, which sits in Annex I Section B, for example if a flag were wired to trigger an automatic stop or speed restriction without a human check, and that directive requires a third party conformity assessment of the product. Under Article 2(2), as amended by Regulation (EU) 2026/1744, a high risk system of that kind is not subject to the full AI Act: only Article 6(1), Article 60a and Articles 102 to 112 apply directly, and Articles 57, 58 and 59 apply only so far as the high risk requirements have been integrated into the interoperability directive. The substantive high risk requirements reach the system through that directive instead, which Article 106 of the AI Act amends to require rail delegated and implementing acts to take those requirements into account.
- AI predictive maintenance for industrial and energy assets
A system that advises engineers on the condition of equipment is usually minimal risk. Annex III point 2 lists AI systems intended as safety components in the management and operation of critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; if predictive maintenance acts on protection or control in a utility network, it can become high risk. Article 6(1) can also apply when the AI is a safety component of machinery or another product covered by Annex I legislation and that product must undergo a third party conformity assessment.
- AI quality inspection on the production line
Inspecting products is not an Annex III use, so a system that only judges parts, welds or assemblies is usually minimal risk. Two designs change that. Under Article 6(1) it is high risk when both conditions hold: it is a safety component of a product (or itself a product) covered by the Union harmonisation legislation in Annex I, and that law requires a third party conformity assessment of the product. For a production line the relevant product laws are the Machinery Regulation (EU) 2023/1230 and, for cars, the vehicle type approval regulations. Since the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the Machinery Regulation into Annex I Section B, where the vehicle type approval regulations already sat. Article 6(1) still classifies such a safety component as high risk, but under Article 2(2) only Article 6(1), Article 60a and Articles 102 to 112 of the AI Act apply directly. The requirements reach the system through the sectoral law instead: delegated acts amending Annex III of the Machinery Regulation, and type approval for vehicles. The AI Act rules for Article 6(1) high risk systems apply from 2 August 2028. An inspection system on the assembly line is usually not a safety component of the product it inspects. If it monitors and evaluates the performance and behaviour of individual workers, for example by scoring who made an assembly error, it falls under Annex III point 4(b) and is high risk. Keep the output about the unit, not the person.
- AI roleplay training for customer conversations
Used only for practice and feedback, the simulator is limited risk. Article 50 requires that people know they are interacting with AI unless that is obvious from the context, as it usually is in a training session, and the provider must mark synthetic voice or text output as AI generated in a machine readable format. It becomes high risk under Annex III point 4(b) if its scores are used to evaluate the performance of workers or to decide on their promotion or termination, and can fall under point 3(b) when a vocational training institution uses it to evaluate learning outcomes. Inferring trainees' emotions from voice or face in the workplace is prohibited under Article 5(1)(f), except for medical or safety reasons.
- AI sales call coaching and CRM update
Summaries, CRM suggestions and follow up drafts that the seller reviews are not an Annex III use and are minimal risk. Using call analysis to monitor and evaluate the performance and behaviour of individual sellers, or to allocate leads to sellers based on their behaviour or personal traits, is high risk under Annex III point 4(b). Inferring sellers' emotions from their voice is prohibited in the workplace by Article 5(1)(f). Emotion recognition applied to customers' voices is high risk under Annex III point 1(c), and Article 50(3) requires deployers to inform the people exposed to it.
- AI summaries of investment research and the house view
Summarizing research for staff is not an Annex III use and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. It is minimal for a purchased internal tool with no client or public facing exposure. Article 50 transparency applies when the firm builds the generating system itself, which brings the Article 50(2) duty to mark synthetic text in a machine readable format; when the assistant is offered to clients as a chatbot, which brings the Article 50(1) duty to tell them they are interacting with AI; or when AI generated text is published to inform the public on matters of public interest, which brings the Article 50(4) disclosure duty unless the text has gone through human review or editorial control and a person holds editorial responsibility for it.
- AI system and model inventory with shadow AI discovery
Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.
- AI translation and interpretation for multilingual public services
Assistants that talk with residents must tell people they are interacting with AI (Article 50(1)), and AI generated text published to inform the public on matters of public interest must be disclosed unless it has had human review under editorial responsibility (Article 50(4)). Internal translation that neither talks with people nor is published carries no specific obligation. Translation can also sit inside an Annex III process, such as examining asylum, visa or residence permit applications (point 7(c)) or evaluating emergency calls and dispatching emergency services (point 5(d)). Whether the translation component is itself high risk depends on its intended purpose (Article 6(3) exempts systems that only perform a narrow procedural task); either way it should be governed with that high risk process.
- AI tutor that coaches students through problems
A tutor that only converses with students falls under the transparency duty of Article 50. It becomes high risk under Annex III point 3(b) when it evaluates learning outcomes, including when those outcomes are used to steer a student's learning process, and under point 3(c) when it assesses the level of education a student should receive. Inferring students' emotions is prohibited in education institutions under Article 5(1)(f).
- AI vegetation management for power lines
Annex III point 2 makes AI systems high risk when they are intended as safety components in the management and operation of the supply of electricity. Recital 55 defines such components as systems used to directly protect the physical integrity of critical infrastructure or the health and safety of persons and property. A system that only feeds a multi year trimming plan, which vegetation planners review and approve before crews act, informs maintenance rather than directly protecting the network, and is then usually minimal risk. The assessment changes when the design acts directly on protection, for example when vegetation risk scores automatically trigger fire risk protection settings or switch lines off without a person deciding; such a system should be assessed as a possible safety component. Standard GDPR duties apply where imagery shows private property or people.
- Dynamic AML customer risk rating with machine learning
An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI agent for first notice of loss claims intake
A customer facing intake agent must be designed so that people know they are interacting with AI (Article 50(1)). Claims intake and claims handling are not listed in Annex III: point 5(c) covers risk assessment and pricing in life and health insurance, not claims. One design choice changes this: detecting distress by inferring emotions from the caller's voice is emotion recognition based on biometric data, which is high risk under Annex III point 1(c) and needs disclosure under Article 50(3). Detecting vulnerability from what the caller says does not. The limited tier assumes that design: every handover signal on this page (injury, distress, anger, vulnerability) is detected from the words of the conversation, and inferring emotions from the voice itself is out of scope.
- AI agent for IT service desk resolution
Article 50(1) requires an assistant that talks with people to make clear they are interacting with AI, unless that is obvious from the context. It is not listed in Annex III. The agent does allocate work, but it routes tickets to resolver and assignment groups based on the content of the request, not to individual workers based on their behaviour or personal traits or characteristics, so Annex III point 4(b) does not apply. It also does not decide on recruitment, promotion, credit or access to essential services. Any use that assigns work to individual analysts, or monitors and evaluates them from their behaviour or performance (including through the agent's logs), would need its own assessment.
- AI agent for travel insurance claims and assistance
A customer facing agent must disclose that it is AI (Article 50), unless this is obvious from the context. Travel insurance claims handling is not listed in Annex III; point 5(c) covers risk assessment and pricing in life and health insurance, not the handling of claims. Handing a traveller who reports a medical emergency to the assistance team is not the classification of emergency calls or the patient triage in point 5(d), as long as the agent only hands over and does not set medical priorities. Claim decisions based solely on automated processing are subject to GDPR Article 22 (and its UK equivalent), and medical data is special category data under Article 9.
- AI assistant for citizen information and government services
An information assistant must tell people they are interacting with AI (Article 50). It is not high risk as long as it does not evaluate eligibility for public assistance benefits or services (Annex III point 5(a)); an assistant that starts to pre assess eligibility should be reassessed.
- AI assistant for developers integrating a company's APIs
A chatbot that interacts with developers must disclose that it is AI (Article 50). Code generation for integration is not listed in Annex III.
- AI assistant for tax questions and filing support
A taxpayer assistant must tell people they are interacting with an AI system (Article 50). It is not listed in Annex III as long as it only informs and applies fixed rules. It becomes high risk under Annex III point 5(a) if it evaluates eligibility for, or grants, reduces, revokes or reclaims, public assistance benefits (which can include benefits paid through the tax system). Recital 59 says systems used for administrative proceedings by tax and customs authorities are not high risk law enforcement systems; audit selection and risk scoring are covered on a separate page.
- AI copilot for marketing content with compliance pre review
An internal drafting and review aid that makes no decisions about people. Article 50 transparency duties apply to generated content: providers must mark synthetic content, and deployers must disclose deep fake images, audio or video. Personalized targeting of individuals is governed mainly by data protection and consumer law rather than the AI Act.
- AI copilot for plant operators and maintenance technicians
Article 50(1): staff must know they are interacting with an AI system, unless that is obvious from the context. Answering maintenance questions is not an Annex III use. It would become high risk under Annex III point 4(b) if the usage data were used to monitor and evaluate the performance of individual workers, so keep usage analytics aggregated.
- AI enterprise knowledge search for employees
Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant. The system would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)) or making decisions on or evaluating workers (point 4(b)).
- AI for drafting customer letters and outbound notices
Drafting letters for human approval is not listed in Annex III. The decision the letter communicates may come from a separate high risk system, such as credit scoring (Annex III point 5(b)) or a public body's eligibility decision on benefits (point 5(a)); the drafting tool does not make that decision. Article 50(2) requires the provider of an AI system that generates text to mark the output as artificially generated, which puts this on the limited risk (transparency) tier; this includes an organization that builds its own drafting tool. Article 50(2) does not apply where the AI has only an assistive function for standard editing and does not substantially alter the input data or the semantics of the output.
- AI for non emergency service requests and 311 routing
A 311 assistant must disclose that it is AI (Article 50). It is not high risk while it only informs and creates service cases. If it evaluates or classifies emergency calls or sets dispatch priority for police, fire or medical services, it falls under Annex III point 5(d) and becomes high risk.
- AI for photo based damage assessment in insurance claims
Assessing damage to vehicles or property for property and casualty claims is not listed in Annex III, which covers insurance only for risk assessment and pricing of natural persons in life and health insurance (point 5(c)). Article 50(1) transparency duties apply when the customer interacts directly with the AI, for example a guided photo journey that returns an AI estimate or offer, or a chat agent. A purely internal repairer estimate review with no customer interaction is minimal. A settlement or refusal decided solely by automated processing can fall under GDPR Article 22.
- AI for RFP, tender and sales proposal response drafting
Drafting bid responses for staff to review is not listed in Annex III, and the buyer receives the seller's own document rather than interacting with an AI system, so the high risk tier and the Article 50(1) duty towards the buyer do not apply. Staff who chat with the agent must know it is an AI system, which an internal tool labelled as an AI assistant meets by design. Article 50(2) does apply to the drafting itself: the provider of a system that generates text must mark its output in a machine readable format as artificially generated, whether or not a person reviews the draft, unless the system only performs an assistive function for standard editing. A seller that uses a third party drafting tool relies on that tool's provider for the marking; a seller that builds its own agent that generates proposal text, as GroupeActive did with Witivio on Copilot Studio, can be the provider and then carries the duty itself. AI literacy under Article 4 applies in both cases, and the seller remains responsible for every statement in the submitted response.
- AI knowledge assistant for wealth advisors and relationship managers
Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant labelled as AI; Article 50(2) requires providers of systems that generate text to mark the output as AI generated in a machine readable way. Helping advisors find information is not an Annex III use and not a prohibited practice under Article 5. It would become high risk only if the system were used to evaluate the creditworthiness of clients (point 5(b)) or to evaluate or make decisions about advisors (point 4(b)). If the assistant were opened to clients, they would have to be told they are dealing with AI.
- AI regulatory horizon scanning and obligation mapping
An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.
- Generative AI voice assistant in the car
Article 50(1): people must be informed that they are interacting with an AI system unless that is obvious from the context. Article 50(2): synthetic audio output must be marked as artificially generated. A cabin assistant for comfort, media, navigation and knowledge questions is not an Annex III use. It would move towards the high risk regime if it became a safety component of the vehicle: vehicle type approval legislation is listed in Annex I Section B, and under Article 2(2) the high risk requirements reach those products only through the amendments the AI Act makes to that legislation. Keep driving and safety functions out of its reach.
- Governed text to SQL analytics assistant
Article 50(1) requires providers to design AI systems that interact directly with people so that those people are informed they are dealing with AI, unless this is obvious from the context, as it usually is for an internal assistant. An analytics assistant that makes no decisions about people is not a prohibited practice under Article 5 and is not listed in Annex III. It would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)).
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI agent for cloud cost optimization and FinOps
An internal tool that optimizes infrastructure spend and makes no decision about a natural person, so the default case falls outside Annex III. The relevant Annex III entry to check against is point 2, AI safety components in the management and operation of critical digital infrastructure: a cost agent stays outside it as long as its policy keeps it to cost actions (rightsizing, commitment purchases, idle cleanup) rather than acting as a safety component of the infrastructure itself. The Akamai deployment on this page shows the scope can extend to core production infrastructure, so an operator should confirm this against its own policy rather than assume it.
- AI agent for data quality monitoring and observability
An internal data engineering tool that flags anomalies in pipelines and tables; it is not a use listed in Annex III and makes no decision about a natural person. If the monitored data feeds a high risk system, such as a credit or employment decision, the AI Act obligations attach to that downstream system, not to this monitoring layer.
- AI agent for fraud alert triage
Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.
- AI assistant for Shariah compliance screening and review
An internal assistant that screens contracts for compliance with Shariah standards is not listed in Annex III: it assesses contracts, structures and securities, not the creditworthiness of natural persons (Annex III point 5(b)). If a customer facing version answers product questions, it must disclose that people are interacting with an AI system under Article 50(1). National Islamic finance regulators set their own Shariah governance expectations.
- AI coding assistant for software developers
A coding assistant used by developers is not a prohibited practice under Article 5 and is not listed in Annex III. Developers know they are working with an AI tool, so the Article 50 disclosure duty has no practical effect for the deploying organization, and the marking of generated content under Article 50(2) falls on the tool's provider. What remains is AI literacy (Article 4). Using an AI system to monitor or evaluate individual developers' performance would fall under Annex III point 4(b), and the software the assistant helps build may itself fall under the Act.
- AI copilot for corporate client briefings and call reports
Bankers interact with the copilot directly, but Article 50(1) does not bite here: it requires telling people they are dealing with an AI system unless that is obvious to a reasonably well informed person, and an internal tool that is openly presented and labelled as an AI assistant meets that bar by design. The copilot never interacts with the client. Article 50(2) marking of generated text falls on the provider of the system, including a bank that builds it in house, but the copilot turns a banker's own notes into a call report, an assistive function for standard editing of the banker's input that does not substantially alter it, so the Article 50(2) exception applies and no machine readable marking is required. It is not an Annex III use: credit context about corporate clients is not the creditworthiness assessment of natural persons in Annex III point 5(b), so it falls outside the high risk tier. If a deployment starts to score individuals for credit, the tier changes. AI literacy duties under Article 4 still apply. If meeting capture is used, recording and transcription rules under data protection law apply separately.
- AI copilot for model risk validation and monitoring
A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.
- AI copilot for SAR and STR narrative drafting
Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.
- AI drafting copilot for civil servants for correspondence, briefings and ministerial replies
An internal drafting assistant that an official reviews is not listed in Annex III. Article 50(4) requires disclosure of AI generated text published to inform the public on matters of public interest, unless it has undergone human review and a person holds editorial responsibility, which this design provides. If the tool is used to evaluate eligibility for public assistance benefits or services rather than to draft, Annex III point 5(a) can apply.
- AI examination of trade documents under letters of credit and collections
Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.
- AI for AML transaction monitoring alert triage
AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.
- AI for commercial underwriting submission intake and triage
Intake and triage for commercial insurance is not listed in Annex III, which covers risk assessment and pricing of natural persons in life and health insurance. It moves up to high risk only if the same pipeline is used to assess or price life or health cover for individuals.
- AI for complaints root cause and systemic issue analysis
Analysing complaints in aggregate to find causes is not listed in Annex III, is not a practice prohibited by Article 5 and does not decide on individuals. It does not interact with the public, so the disclosure duty in Article 50(1) does not apply; the machine readable marking of generated text in Article 50(2) is a duty of the provider of the generative model or system that writes the summaries. If the same system decided individual complaint outcomes or redress, or its themes were used to evaluate the performance of individual complaint handlers (Annex III point 4), that design would need its own assessment.
- AI for freedom of information request processing
Tools that support staff in searching, deduplicating and proposing redactions are not listed in Annex III (point 5(a) covers eligibility for public assistance benefits and services, not access to documents), and every release decision stays with an officer. A public facing request assistant that talks to requesters would carry the Article 50(1) transparency duty.
- AI for IT incident triage and root cause analysis (AIOps)
An internal tool that supports engineers on IT incidents; it is not a use listed in Annex III and makes no decisions about people. Annex III point 2 covers AI used as a safety component in the management and operation of critical digital infrastructure, and recital 55 limits safety components to systems that directly protect the physical integrity of that infrastructure or the health and safety of persons and property. A triage copilot that proposes causes and fixes to engineers does not normally do that, but operators of critical digital infrastructure (cloud, data centers, telecom networks) should confirm this for their own design.
- AI for ledger and payment reconciliation
Matching entries between internal financial records is not a use listed in Annex III and is not a practice prohibited by Article 5. Operators knowingly use an internal AI tool, so no Article 50(1) disclosure is needed. If a generative model drafts the explanations or journals, the provider of that system may have to mark its output as AI generated under Article 50(2). The AI literacy duty of Article 4 applies to the bank as deployer.
- AI for legacy code modernization
Tools that analyze, document and translate code are not prohibited practices under Article 5 and are not listed in Annex III, so no high risk obligations apply to the tooling. Engineers and analysts know they are working with an AI tool, including when they query the documentation through a chat assistant, so the Article 50 disclosure duty has no practical effect for the deploying organization. What remains is AI literacy for the staff who use it (Article 4). If the system being modernized is itself an AI system in an Annex III area (for example creditworthiness assessment, point 5(b)), its new version still has to meet the high risk requirements.
- AI for policy drafting and policy gap analysis
Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.
- AI for public consultation response analysis
Organising and summarising consultation responses for analysts does not decide on individuals and is not listed in Annex III, so no high risk obligations apply. If AI generated text is published to inform the public on matters of public interest without human review and editorial responsibility, Article 50(4) requires disclosure.
- AI for software vulnerability triage and remediation
Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.
- AI for subrogation opportunity detection
Detecting recovery opportunities against third parties and other insurers is not listed in Annex III: point 5(c) covers only risk assessment and pricing of natural persons in life and health insurance, and the system does not decide on a natural person's access to a service. It is an internal tool that does not converse with the public or publish generated content, so the deployer transparency duties of Article 50 do not apply. Personal data in claim files, including data about the third party, is still subject to GDPR.
- AI for supervisory exam and information request responses
Drafting regulatory correspondence for human approval is not an Annex III use. The main risks are confidentiality and accuracy, which are handled by supervisory information rules, data protection law and internal controls.
- AI for supplier invoice processing in accounts payable
Processing supplier invoices is not an Annex III use case, is not a practice prohibited by Article 5 and does not involve decisions about natural persons, so it is minimal risk and the AI literacy duty of Article 4 applies. Approvers who ask questions in chat use an internal tool they know is AI; if that is not obvious to the people using it, the provider must also inform them that they are interacting with an AI system (Article 50(1)).
- AI for support knowledge article generation and maintenance
Drafting internal or public help content that a person reviews and publishes is not a prohibited practice under Article 5 and is not listed in Annex III, so it is minimal risk. The articles are not a direct AI interaction, and the Article 50(4) disclosure for AI generated text published to inform the public does not apply where a person reviews the text and holds editorial responsibility. The Article 50 transparency duties do apply to chatbots that later answer customers from the articles.
- AI for third party and vendor risk due diligence
Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.
- AI meeting notes and CRM update for wealth advisors
Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.
- AI native platform for drug target discovery and molecule design
Target scoring and molecule generation are not a safety component of an Annex I product and are not one of the Annex III high risk areas (Article 6), so they do not become high risk on that route. Insofar as the platform and its training are themselves scientific research and development, activity that stays there falls outside the Regulation entirely under the Article 2(6) research exclusion. The resulting drug candidate is separately regulated as a medicine, not as an AI system, through the normal pharmaceutical approval pathway; conventional preclinical and clinical testing validates the AI's outputs before anything reaches a patient.
- AI spend classification and spend analytics for procurement
Classifying the organization's own purchase lines into categories is not listed in Annex III and is used internally by procurement staff, so no specific obligations apply beyond AI literacy. The data can still contain personal data, for example in purchasing card and expense lines, which brings GDPR duties. Using the classified card and expense lines to monitor or evaluate individual employees would move the system towards Annex III point 4 (employment and worker management) and a high risk assessment.
- AI that turns requirements into user stories, acceptance criteria and test cases
An internal assistant that drafts requirements artifacts and test cases for engineers is not listed in Annex III and does not interact with the public, so no specific obligations apply beyond AI literacy (Article 4). The system under test may itself fall under the Act.
- Generative AI copilot for internal audit
An internal drafting and analysis assistant for auditors that makes no decisions about natural persons. It would need reassessment if used to evaluate individual employees' behaviour or performance, which falls under Annex III point 4(b).