Regulation
MiFID II and AI use cases
Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.
Read the source text (European Union)Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI assistant for goal based financial planning
Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).
- AI assistant for investment suitability assessment and reports
Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.
- AI for market abuse surveillance alert triage
Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).
- AI generated client portfolio reports and commentary
Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.
- AI next best action prompts for wealth advisors
Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.
- AI portfolio drift monitoring and rebalancing proposals
Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.
- AI summaries of investment research and the house view
Summarizing research for staff is not an Annex III use and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. It is minimal for a purchased internal tool with no client or public facing exposure. Article 50 transparency applies when the firm builds the generating system itself, which brings the Article 50(2) duty to mark synthetic text in a machine readable format; when the assistant is offered to clients as a chatbot, which brings the Article 50(1) duty to tell them they are interacting with AI; or when AI generated text is published to inform the public on matters of public interest, which brings the Article 50(4) disclosure duty unless the text has gone through human review or editorial control and a person holds editorial responsibility for it.
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI copilot for marketing content with compliance pre review
An internal drafting and review aid that makes no decisions about people. Article 50 transparency duties apply to generated content: providers must mark synthetic content, and deployers must disclose deep fake images, audio or video. Personalized targeting of individuals is governed mainly by data protection and consumer law rather than the AI Act.
- AI knowledge assistant for wealth advisors and relationship managers
Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant labelled as AI; Article 50(2) requires providers of systems that generate text to mark the output as AI generated in a machine readable way. Helping advisors find information is not an Annex III use and not a prohibited practice under Article 5. It would become high risk only if the system were used to evaluate the creditworthiness of clients (point 5(b)) or to evaluate or make decisions about advisors (point 4(b)). If the assistant were opened to clients, they would have to be told they are dealing with AI.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI meeting notes and CRM update for wealth advisors
Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.