Regulation
PCI DSS and AI use cases
Security standard for any system that stores, processes or transmits cardholder data.
Read the source text (PCI Security Standards Council)High risk under the EU AI Act
Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.
- AI quality and compliance monitoring of every customer interaction
Scoring individual agents' interactions to monitor and evaluate their performance and behaviour falls under Annex III point 4(b), employment and worker management. The Article 6(3) exception does not apply where the system profiles natural persons. Inferring agents' emotions is prohibited under Article 5(1)(f), except for medical or safety reasons. Inferring customers' emotions from their voice is emotion recognition on biometric data: high risk under Annex III point 1(c), and Article 50(3) requires informing the people exposed to it. Analytics that only aggregate interaction themes without evaluating individuals can fall outside the high risk category.
Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI for back office account servicing execution
The tier depends on how the system is built. It stays minimal when the agent only executes changes approved by a person and any letter comes from a fixed template, since executing servicing changes is not listed in Annex III. It moves to limited risk when the same system talks to customers directly (the Article 50 transparency duty, described on the customer facing servicing page) or when generative AI drafts the confirmation or letter text: the provider of that generative function, the bank if it builds the system, then carries the Article 50(2) duty to mark the generated content in a machine readable way, unless the output only gets an assistive role or standard editing that does not substantially alter the input data. An AI system used to evaluate the creditworthiness of natural persons, for example to decide on a loan restructuring, is high risk under Annex III point 5(b); keep that assessment outside this agent, which only executes the decided change.
- AI for merchant underwriting and risk monitoring
Assessing businesses and detecting fraud is not an Annex III use as such, and Annex III point 5(b) excludes systems used to detect financial fraud. If the system evaluates the creditworthiness of a natural person, for example a sole trader applying to accept payments, it can fall under Annex III point 5(b), which covers evaluating the creditworthiness of natural persons or establishing their credit score, and be high risk. Keep credit assessment of individuals separate or treat it as a high risk system.
- AI for security alert triage and investigation in the SOC
Triage of phishing, endpoint, network and cloud alerts for an organization's own cyber defence is not listed in Annex III. Recital 55 of the AI Act says that components intended to be used solely for cybersecurity purposes should not qualify as safety components, so the agent does not fall under Annex III point 2 (critical infrastructure), and for this scope the tier is minimal. The design changes that when the agent triages identity, data loss prevention, insider risk or user behaviour alerts in a way that scores or monitors individual employees: monitoring and evaluating the behaviour of persons in a work relationship falls under Annex III point 4(b), so that scope needs its own high risk assessment before it goes live. The Article 50(1) duty to disclose AI interaction does not apply because it is obvious to a reasonably well informed analyst that they are working with an AI agent. An operator that lets AI act autonomously on network or operational technology controls should assess that design separately, and reading employees' emails and sign in data remains subject to data protection law.
- Conversational AI for insurance quote and buy
The conversational layer carries the Article 50 transparency duty. If the system assesses risk or sets prices for life or health insurance of natural persons, that part is high risk under Annex III point 5(c); pricing for property and casualty products is not listed.
- Real time AI assist for contact centre agents
As a pure assist tool for agents it is minimal risk; the customer does not interact with the AI. It becomes high risk under Annex III point 4(b) if its data is used to monitor and evaluate individual agents' performance, and inferring agents' emotions at work is prohibited under Article 5(1)(f).
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI agent for account and card servicing
Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.
- AI agent for ATM and self service device assistance
A customer facing assistant must tell people they are interacting with an AI system unless that is obvious (Article 50(1)). It does not evaluate creditworthiness (Annex III point 5(b)) or eligibility for public assistance benefits (point 5(a)), so it is not high risk; biometric verification whose sole purpose is to confirm identity is excluded from Annex III point 1(a).
- AI agent for card dispute intake
A customer facing assistant must tell people they are interacting with an AI system (Article 50(1)). It triages and opens cases but does not evaluate creditworthiness (Annex III point 5(b), which in any case excludes systems used to detect financial fraud) or decide access to an essential service, so it is not high risk under Annex III.
- AI agent for early collections and hardship support
A customer facing collections agent must disclose that it is AI (Article 50). It is not listed in Annex III as long as it applies preapproved arrangement rules and does not itself evaluate creditworthiness; an affordability model that decides who gets which arrangement for individuals should be assessed separately against Annex III point 5(b).
- AI agent for flight disruption and rebooking
A customer facing assistant must tell people they are interacting with AI (Article 50). It is not a high risk use under Annex III: it applies the airline's reaccommodation rules and does not decide on access to an essential public service or on creditworthiness.
- AI agent for fraud alert confirmation with cardholders
Confirming flagged transactions with cardholders is not listed in Annex III, and point 5(b) expressly excludes AI used to detect financial fraud from the creditworthiness category, so the system is not high risk. An agent that messages or calls customers must tell them they are dealing with AI under Article 50(1), and synthetic voice output must be marked as AI generated under Article 50(2).
- AI agent for insurance policy servicing
A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1), applicable from 2 August 2026). It is not high risk as long as it does not carry out risk assessment and pricing in relation to natural persons in life and health insurance (Annex III point 5(c)).
- AI agent for order status, delivery changes and returns
A customer facing service agent must disclose that the customer is interacting with AI (Article 50). It is not high risk: it does not decide on access to essential services, credit or employment.
- AI agent for payment initiation within a customer mandate
A customer facing agent must make clear that people are dealing with AI, unless that is obvious from the context (Article 50). Initiating payments within a customer's mandate is not listed in Annex III. It becomes high risk if the same agent evaluates creditworthiness, for example by deciding on a buy now pay later or credit line at checkout (Annex III point 5(b)).
- AI agent for telecom bill explanation and billing disputes
A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1)). Explaining bills, correcting clear errors and opening disputes are not listed in Annex III. The tier changes only if the system is also used to evaluate customers' creditworthiness, for example to set credit limits, which Annex III point 5(b) lists as high risk.
- AI travel and hotel booking concierge
A customer facing assistant must tell people they are interacting with AI unless that is obvious from the context (Article 50(1), applicable from 2 August 2026). Recommending and booking travel is not listed in Annex III, so it is not high risk; consumer protection law on price transparency and fair commercial practices still applies to what it says.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI for chargeback and representment operations
Dispute processing between issuers, acquirers and merchants is not listed in Annex III. It is not an evaluation of creditworthiness or credit scoring under Annex III point 5(b), and because cardholders do not interact with the system directly, the Article 50(1) transparency duty for AI that talks to people does not apply. Article 50(2) marking of generated text is a duty of the provider of the AI system that generates it, which includes an institution that builds its own dispute drafting agent and puts it into service under its own name. A drafted rebuttal built from attached case evidence performs an assistive function for standard editing of that evidence and does not substantially alter the underlying input, so it falls under the Article 50(2) exception and does not need machine readable marking. With that point checked, the tier stays minimal. A customer facing intake agent is assessed separately.
- AI for software vulnerability triage and remediation
Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.
- Real time fraud scoring for card and instant payments
Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.