Regulation

UK APP scam reimbursement rules and AI use cases

Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.

Read the source text (Payment Systems Regulator)

Limited risk (transparency) under the EU AI Act

People must be told they are dealing with AI, and generated content must be identifiable (Article 50).

  • AI scam intervention for instant payments

    Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.

Minimal risk under the EU AI Act

No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.

  • AI agent for fraud alert triage

    Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.

  • AI for money mule account and network detection

    Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.

  • Real time fraud scoring for card and instant payments

    Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.