Skip to main content

Is AI fraud detection high-risk under the EU AI Act?

The system being classified

You provide a system that flags fraudulent payment transactions for a bank's review. It does not score anyone's creditworthiness.

Verdict

Minimal risk

No mandatory product obligations beyond AI literacy. Voluntary codes of conduct recommended; keep your inventory current.

2 applicable obligations
Maximum fine tier: No Article 99 fine tier attaches directly to this classification's obligations
Key date: No dated obligations pending — AI literacy (Art. 4) applies since 2 February 2025; keep the inventory current

This is the classification of the configuration described above, not of your system. One different answer can move it — which is exactly what the comparison further down shows, and what the free assessment settles in about ten minutes.

What produced this verdict

These are the entire inputs. The engine is deterministic, so these answers always produce the verdict above.

Scope and role

  • · Provider — you build it or place it on the market under your name
  • · Placed on the EU market, or output used in the EU

What applies, and from when (2)

Every entry cites the article it comes from and the date it binds. That second column is the part most summaries of the Omnibus get wrong.

ArticleObligationBinding from
Art. 4
AI literacy
Ensure staff dealing with AI systems have a sufficient level of AI literacy (training records recommended).
2 February 2025
Best practice
AI system inventory
Maintain a central register of all AI systems in use, their purpose, risk tier and owner.
Good practice

What would change this verdict

Each row below is the same scenario with one answer changed, re-run through the same engine. These are not predictions about your system; they are what our classifier returns when that single fact differs. Where one change to the scenario necessarily moves a second answer with it, the row says which, and why.

The same model also informs lending decisions

Becomes high-risk system

The exclusion is for fraud detection. Once the output feeds creditworthiness evaluation, Annex III point 5(b) applies to it.

  • Obligations: 214 (+12)
  • Key date changes to 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus)

Customers can query the decision through a chat interface

Becomes limited risk — transparency duties

Article 50 attaches to the interface independently of the tier, and its date has already passed.

  • Obligations: 23 (+1)
  • Key date changes to Article 50 transparency duties apply since 2 August 2026; GPAI duties since 2 August 2025

Your system is not this system

The assessment asks the same questions this page answered for a generic configuration, and produces the verdict, the gap list and the 30-day plan for yours. Ten minutes, free, no sign-up, and it runs entirely in your browser — your answers never reach us.

Classify your own system →

Other configurations

Produced by rule set 1.6.1, legal state 2026-08-05. The engine is deterministic and contains no language model in the verdict path, and every rule is published at /methodology for you to audit.

AnnexWise is preparation software, not legal advice. This page classifies a described configuration; it is not an opinion on any particular organisation or system.