Regulation
FCA Consumer Duty and AI use cases
UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.
Read the source text (Financial Conduct Authority)High risk under the EU AI Act
Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.
- AI credit scoring with alternative data for thin file applicants
Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).
- AI quality and compliance monitoring of every customer interaction
Scoring individual agents' interactions to monitor and evaluate their performance and behaviour falls under Annex III point 4(b), employment and worker management. The Article 6(3) exception does not apply where the system profiles natural persons. Inferring agents' emotions is prohibited under Article 5(1)(f), except for medical or safety reasons. Inferring customers' emotions from their voice is emotion recognition on biometric data: high risk under Annex III point 1(c), and Article 50(3) requires informing the people exposed to it. Analytics that only aggregate interaction themes without evaluating individuals can fall outside the high risk category.
Depends on design under the EU AI Act
The tier depends on how the system is used, for example whether it decides on access to an essential service.
- AI agent for complaints recognition, investigation and response
Complaint handling is not listed in Annex III, so internal classification and drafting for a handler who decides is minimal risk. Where the agent talks to customers to take the complaint, Article 50(1) requires telling them they are dealing with AI. Only a system that also assessed creditworthiness or priced life and health insurance (Annex III point 5(b) or 5(c)) would be high risk for that part.
- AI agent for personalized offers and rewards
Ranking offers is generally minimal risk and the conversational part carries the Article 50 transparency duty. Using AI to evaluate creditworthiness for a credit offer is high risk (Annex III point 5(b)), and Article 5 prohibits techniques that exploit vulnerabilities due to a person's social or economic situation to distort their behaviour in a harmful way.
- AI assistant for goal based financial planning
Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).
- AI assistant for insurance brokers and agents
An employee facing assistant for knowledge answers and drafting is not listed in Annex III and is minimal risk. A lead qualification agent that talks to customers must tell them they are dealing with AI (Article 50). Using performance insights to monitor and evaluate individual agents, or to allocate leads based on their behaviour or traits, is high risk under Annex III point 4(b), and any component that does risk assessment or pricing of life or health insurance for individuals is high risk under Annex III point 5(c).
- AI assistant for investment suitability assessment and reports
Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.
- AI copilot for insurance pricing and actuarial analysis
Pricing and risk assessment of natural persons for life and health insurance is high risk under Annex III point 5(c). Pricing for property and casualty products, and actuarial analysis that does not price individuals, are not listed, although supervisors still expect sound model governance.
- AI drafted explanations for credit declines and adverse actions
The drafting assistant does not assess creditworthiness, so on its own it is not the Annex III point 5(b) credit scoring system. It helps the lender meet the Article 86 right of affected people to a clear and meaningful explanation of decisions based on such a high risk system. If it is built into the scoring system it shares that system's high risk obligations; as a separate drafting tool its tier depends on its design and on how its output is reviewed. The follow up chat assistant must tell customers they are dealing with an AI system (Article 50).
- AI financial wellbeing coach in the banking app
The conversational assistant carries the Article 50 transparency duty: customers must be told they are interacting with an AI system. The system becomes high risk if it is used to evaluate the creditworthiness of natural persons or establish their credit score (Annex III point 5(b)). Article 5(1)(b) prohibits AI that exploits vulnerabilities due to a person's specific social or economic situation to materially distort their behaviour in a way that causes, or is reasonably likely to cause, significant harm.
- AI for application and identity fraud detection
Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.
- AI for back office account servicing execution
The tier depends on how the system is built. It stays minimal when the agent only executes changes approved by a person and any letter comes from a fixed template, since executing servicing changes is not listed in Annex III. It moves to limited risk when the same system talks to customers directly (the Article 50 transparency duty, described on the customer facing servicing page) or when generative AI drafts the confirmation or letter text: the provider of that generative function, the bank if it builds the system, then carries the Article 50(2) duty to mark the generated content in a machine readable way, unless the output only gets an assistive role or standard editing that does not substantially alter the input data. An AI system used to evaluate the creditworthiness of natural persons, for example to decide on a loan restructuring, is high risk under Annex III point 5(b); keep that assessment outside this agent, which only executes the decided change.
- AI for claims triage and straight through processing
Claims handling as such is not listed in Annex III. The same system becomes high risk when it is also used for risk assessment and pricing of natural persons in life and health insurance (point 5(c)), or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim essential public assistance benefits and services, including healthcare services (point 5(a)). Otherwise the tier is minimal, so the design and the operator decide. Decisions on claims based solely on automated processing are also subject to Article 22 of the GDPR and the UK GDPR.
- AI for inbound correspondence triage and routing
It depends on where the system runs. Classifying and routing a bank's or insurer's correspondence is not a use listed in Annex III, so it is minimal risk: the AI literacy duty of Article 4 applies, and the Article 50 duty to tell people they are dealing with AI does not, because the system does not interact with the sender. Used by or for a public authority in a benefits process covered by Annex III point 5(a), the provider can treat it as not high risk only while it performs a narrow procedural or preparatory task under Article 6(3); the provider must then document that assessment before it goes live (Article 6(4)) and register the system in the EU database (Article 49(2)). If the system evaluates eligibility for benefits or profiles the people who write in, it is high risk, so those judgements stay with people.
- AI for insurance claims fraud detection
Claims fraud detection by an insurer is not listed in Annex III, and point 5(b) explicitly excludes AI systems used to detect financial fraud from the credit scoring category. Point 5(c) covers only risk assessment and pricing in life and health insurance, so a fraud model becomes high risk when it also feeds those decisions, or when it is used by or on behalf of a public authority to grant, reduce, revoke or reclaim public assistance benefits (point 5(a)). Profiling and automated decisions remain subject to GDPR, including Article 22 where a claim is refused on a decision based solely on automated processing.
- AI for insurance renewal processing and customer retention
Renewal intake for commercial lines and outreach are not listed in Annex III. Renewal risk assessment or pricing for life or health insurance of natural persons is high risk under point 5(c), and so is a lapse score that feeds those decisions; a lapse score used only to decide who gets a service call is not listed. Customer facing renewal assistants carry the Article 50(1) duty to tell people they are interacting with an AI system, unless that is obvious from the context.
- AI generated client portfolio reports and commentary
Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.
- AI home loan assistant with pre qualification
Answering questions and giving indicative estimates from published rules is limited risk with an Article 50(1) disclosure that the customer is talking to an AI system. If the assistant evaluates an individual's creditworthiness to decide or filter access to a loan, it falls under Annex III point 5(b) and is high risk.
- AI marketing personalization at scale
Most personalization and content generation is minimal risk. Providers of systems that generate synthetic audio, image, video or text content must mark the output as artificially generated, and deployers must disclose deep fakes (Article 50(2) and 50(4)). Personalization that deploys manipulative or deceptive techniques, or exploits vulnerabilities due to age, disability or a specific social or economic situation, in a way that causes or is reasonably likely to cause significant harm, is prohibited under Article 5(1)(a) and (b). Using AI to assess creditworthiness or to price life and health insurance is high risk under Annex III point 5(b) and 5(c) and belongs on its own page. Outside the AI Act, the FCA Consumer Duty applies only to FCA regulated firms (the financial services slice of this use case), and the Telephone Consumer Protection Act applies only to campaigns delivered by call or text message in the US.
- AI next best action prompts for wealth advisors
Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.
- AI recommendations for loan restructuring and hardship arrangements
Recommending restructuring terms for individuals involves assessing their ability to pay, which can amount to evaluating the creditworthiness of natural persons under Annex III point 5(b). Human approval alone does not remove that: the Article 6(3) exception covers only systems that do not materially influence the decision, such as a narrow procedural or preparatory task, and never applies when the system profiles natural persons. A tool that only assembles the case file can fall under the exception; restructuring for companies is outside point 5(b).
- AI roleplay training for customer conversations
Used only for practice and feedback, the simulator is limited risk. Article 50 requires that people know they are interacting with AI unless that is obvious from the context, as it usually is in a training session, and the provider must mark synthetic voice or text output as AI generated in a machine readable format. It becomes high risk under Annex III point 4(b) if its scores are used to evaluate the performance of workers or to decide on their promotion or termination, and can fall under point 3(b) when a vocational training institution uses it to evaluate learning outcomes. Inferring trainees' emotions from voice or face in the workplace is prohibited under Article 5(1)(f), except for medical or safety reasons.
- Conversational AI for insurance quote and buy
The conversational layer carries the Article 50 transparency duty. If the system assesses risk or sets prices for life or health insurance of natural persons, that part is high risk under Annex III point 5(c); pricing for property and casualty products is not listed.
- Conversational AI for loan application intake
Explaining products and capturing an application is limited risk with an Article 50 disclosure. If the assistant evaluates creditworthiness or filters applicants on its own assessment, it falls under Annex III point 5(b) and becomes high risk, so keep the decision in the governed credit process.
- Real time AI assist for contact centre agents
As a pure assist tool for agents it is minimal risk; the customer does not interact with the AI. It becomes high risk under Annex III point 4(b) if its data is used to monitor and evaluate individual agents' performance, and inferring agents' emotions at work is prohibited under Article 5(1)(f).
Limited risk (transparency) under the EU AI Act
People must be told they are dealing with AI, and generated content must be identifiable (Article 50).
- AI agent for account and card servicing
Article 50(1): people must be informed that they are interacting with an AI system, unless that is obvious from the context. Servicing existing accounts and cards is not an Annex III use. It would become high risk under Annex III point 5(b) if the agent itself evaluated the creditworthiness of a natural person, for example to decide a credit limit increase.
- AI agent for ATM and self service device assistance
A customer facing assistant must tell people they are interacting with an AI system unless that is obvious (Article 50(1)). It does not evaluate creditworthiness (Annex III point 5(b)) or eligibility for public assistance benefits (point 5(a)), so it is not high risk; biometric verification whose sole purpose is to confirm identity is excluded from Annex III point 1(a).
- AI agent for card dispute intake
A customer facing assistant must tell people they are interacting with an AI system (Article 50(1)). It triages and opens cases but does not evaluate creditworthiness (Annex III point 5(b), which in any case excludes systems used to detect financial fraud) or decide access to an essential service, so it is not high risk under Annex III.
- AI agent for early collections and hardship support
A customer facing collections agent must disclose that it is AI (Article 50). It is not listed in Annex III as long as it applies preapproved arrangement rules and does not itself evaluate creditworthiness; an affordability model that decides who gets which arrangement for individuals should be assessed separately against Annex III point 5(b).
- AI agent for first line contact centre service
An AI system that interacts directly with people must be designed so that they know they are dealing with AI, unless that is obvious from the context (Article 50(1)). It is not high risk under Annex III as long as it does not evaluate eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness (point 5(b)), risk and pricing for life and health insurance (point 5(c)) or emergency calls (point 5(d)). This holds only if emotion or vulnerability signals are inferred from what the customer says (text or transcript content), not from voice or other biometric features; an agent that infers emotion from a caller's voice is an emotion recognition system (Article 3(39)), which is high risk under Annex III point 1(c) and triggers the deployer disclosure duty in Article 50(3).
- AI agent for first notice of loss claims intake
A customer facing intake agent must be designed so that people know they are interacting with AI (Article 50(1)). Claims intake and claims handling are not listed in Annex III: point 5(c) covers risk assessment and pricing in life and health insurance, not claims. One design choice changes this: detecting distress by inferring emotions from the caller's voice is emotion recognition based on biometric data, which is high risk under Annex III point 1(c) and needs disclosure under Article 50(3). Detecting vulnerability from what the caller says does not. The limited tier assumes that design: every handover signal on this page (injury, distress, anger, vulnerability) is detected from the words of the conversation, and inferring emotions from the voice itself is out of scope.
- AI agent for fraud alert confirmation with cardholders
Confirming flagged transactions with cardholders is not listed in Annex III, and point 5(b) expressly excludes AI used to detect financial fraud from the creditworthiness category, so the system is not high risk. An agent that messages or calls customers must tell them they are dealing with AI under Article 50(1), and synthetic voice output must be marked as AI generated under Article 50(2).
- AI agent for insurance policy servicing
A customer facing assistant must be designed so that people know they are interacting with AI (Article 50(1), applicable from 2 August 2026). It is not high risk as long as it does not carry out risk assessment and pricing in relation to natural persons in life and health insurance (Annex III point 5(c)).
- AI agent for payment initiation within a customer mandate
A customer facing agent must make clear that people are dealing with AI, unless that is obvious from the context (Article 50). Initiating payments within a customer's mandate is not listed in Annex III. It becomes high risk if the same agent evaluates creditworthiness, for example by deciding on a buy now pay later or credit line at checkout (Annex III point 5(b)).
- AI agent for proactive customer outreach, activation and retention
A customer facing agent must disclose that it is AI (Article 50(1)). It stays out of Annex III as long as eligibility for credit offers is decided upstream by the bank's own, separately governed credit processes; if the agent itself assessed creditworthiness it would be high risk under point 5(b).
- AI agent for travel insurance claims and assistance
A customer facing agent must disclose that it is AI (Article 50), unless this is obvious from the context. Travel insurance claims handling is not listed in Annex III; point 5(c) covers risk assessment and pricing in life and health insurance, not the handling of claims. Handing a traveller who reports a medical emergency to the assistance team is not the classification of emergency calls or the patient triage in point 5(d), as long as the agent only hands over and does not set medical priorities. Claim decisions based solely on automated processing are subject to GDPR Article 22 (and its UK equivalent), and medical data is special category data under Article 9.
- AI copilot for marketing content with compliance pre review
An internal drafting and review aid that makes no decisions about people. Article 50 transparency duties apply to generated content: providers must mark synthetic content, and deployers must disclose deep fake images, audio or video. Personalized targeting of individuals is governed mainly by data protection and consumer law rather than the AI Act.
- AI for drafting customer letters and outbound notices
Drafting letters for human approval is not listed in Annex III. The decision the letter communicates may come from a separate high risk system, such as credit scoring (Annex III point 5(b)) or a public body's eligibility decision on benefits (point 5(a)); the drafting tool does not make that decision. Article 50(2) requires the provider of an AI system that generates text to mark the output as artificially generated, which puts this on the limited risk (transparency) tier; this includes an organization that builds its own drafting tool. Article 50(2) does not apply where the AI has only an assistive function for standard editing and does not substantially alter the input data or the semantics of the output.
- AI for photo based damage assessment in insurance claims
Assessing damage to vehicles or property for property and casualty claims is not listed in Annex III, which covers insurance only for risk assessment and pricing of natural persons in life and health insurance (point 5(c)). Article 50(1) transparency duties apply when the customer interacts directly with the AI, for example a guided photo journey that returns an AI estimate or offer, or a chat agent. A purely internal repairer estimate review with no customer interaction is minimal. A settlement or refusal decided solely by automated processing can fall under GDPR Article 22.
- AI reply drafting for customer email and support tickets
A drafting copilot whose output an agent reviews and sends falls under the transparency tier at most. When replies are sent without human review, customers interact with the AI system directly, and Article 50(1) requires that they are informed unless this is obvious from the context. Article 50(2) separately requires the provider of a system that generates text to mark its output in a machine readable format as artificially generated, whether or not a person reviews the draft. It becomes high risk only if it is used for a purpose listed in Annex III, such as evaluating eligibility for public benefits or creditworthiness (point 5), or evaluating the performance of the agents who use it (point 4).
- AI scam intervention for instant payments
Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.
Minimal risk under the EU AI Act
No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.
- AI agent for fraud alert triage
Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.
- AI for complaints root cause and systemic issue analysis
Analysing complaints in aggregate to find causes is not listed in Annex III, is not a practice prohibited by Article 5 and does not decide on individuals. It does not interact with the public, so the disclosure duty in Article 50(1) does not apply; the machine readable marking of generated text in Article 50(2) is a duty of the provider of the generative model or system that writes the summaries. If the same system decided individual complaint outcomes or redress, or its themes were used to evaluate the performance of individual complaint handlers (Annex III point 4), that design would need its own assessment.
- AI for fee and interest leakage detection
Verifying charges against contracts is not listed in Annex III and is not a practice prohibited by Article 5. The system is internal, so the Article 50(1) duty to tell people they are dealing with AI does not arise; the Article 50(2) duty to mark generated text, such as the discrepancy explanations, falls on the provider of the generative model or system. It supports, but does not take, decisions about individual customers; remediation decisions stay with people.
- AI for money mule account and network detection
Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.
- AI meeting notes and CRM update for wealth advisors
Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.
- Real time fraud scoring for card and instant payments
Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.