AML & AI Act classification

Orientation for obliged entities using AI in KYC, monitoring, and credit workflows — plus proposed timeline changes under the Digital Omnibus.

Financial institutions and other obliged entities increasingly use AI across AML/CFT workflows. The EU AI Act classifies systems by risk tier — independent of, but alongside, AML Package obligations. Use these examples as orientation; final classification depends on intended purpose, outputs, and how the system influences decisions.

Risk tiers at a glance

Unacceptable risk

Banned — Art. 5

High risk

Permitted with conformity requirements — Ch. III

Limited risk

Transparency obligations — Art. 50

Minimal risk

No AI Act obligations — voluntary codes encouraged

Common AML & financial AI uses

Illustrative mapping for compliance and onboarding teams — not legal advice.

Social scoring for client reliability or AML risk

Unacceptable risk

Scoring based on general behaviour, political views, or lifestyle rather than strictly financial or AML-relevant data.

Art. 5(1)(c) prohibits social scoring that leads to unjustified or disproportionate treatment. A financial-reliability score built on non-financial behaviour falls in this category.

Creditworthiness and insurance pricing AI

High risk

Models that evaluate creditworthiness or price life and health insurance.

Annex III §5(b)(c) explicitly lists credit scoring and insurance pricing as high-risk — conformity assessment, documentation, and oversight apply from the Annex III application date.

Fraud detection (distinct from credit scoring)

Minimal risk

Transaction or application fraud detection that does not determine creditworthiness or insurance terms.

Annex III §5 carves out fraud detection from the credit-scoring high-risk category. Other law (AML, consumer credit, GDPR) may still apply, but not this Annex III bucket.

Formal document completeness checks

Minimal risk

Verifying required fields are present and documents meet format rules — without assessing content or making risk decisions.

Rule-based or AI-assisted formal validation that does not materially influence access to essential services is typically minimal risk. Risk rises once the system scores or decides eligibility.

Transaction monitoring and anomaly detection

Minimal risk

ML models that flag unusual patterns, reduce false positives, or prioritise alerts for AML analysts.

AML transaction monitoring is not listed in Annex III. Deployers still need vendor due diligence, GDPR/DPIA where personal data is processed, and AML governance — but not automatic high-risk AI Act conformity for the monitoring layer itself.

Remote biometric identity verification (KYC onboarding)

High risk

Facial matching or liveness checks to verify identity during remote customer onboarding.

Remote biometric identification and categorisation are high-risk under Annex III §1 (subject to strict conditions). Real-time identification in public spaces is separately restricted under Art. 5.

OCR / NLP for KYC document extraction

Minimal risk

Extracting and structuring data from identity documents or corporate filings.

Data extraction without automated eligibility or risk decisions is usually minimal risk. If outputs feed high-risk scoring or biometric matching, classify the downstream system instead.

Client-facing AML or support chatbots

Limited risk

AI that interacts with customers without making high-risk eligibility decisions.

Art. 50 requires users to know they are interacting with AI. Limited-risk transparency duties apply even when the underlying AML process is not Annex III high-risk.

Principles for dual compliance

  • Classify each AI system (or materially distinct model) on its own — a minimal-risk OCR step can feed a high-risk biometric or credit workflow.
  • Fraud detection is carved out from credit-scoring high-risk, but credit models and insurance pricing are explicitly in Annex III §5.
  • Social scoring for reliability or AML risk based on non-financial behaviour is prohibited under Art. 5 — not merely high-risk.
  • AML/CFT obligations under the AML Package run in parallel; AI Act classification does not replace sector AML rules, DPIAs, or outsourcing controls.

Digital Omnibus — proposed AI Act timeline changes

COM(2025) 836 proposes a stop-the-clock mechanism: high-risk obligations would apply only once harmonised standards and official guidelines are available, with backstop dates if those instruments are delayed.

Under negotiation between the European Parliament and the Council (Feb 2026).

Proposed backstop dates

  • Annex III high-risk use cases 2 December 2027 if standards delayed (statutory 2 August 2026)
  • Annex I product-safety embedded AI 2 August 2028 if standards delayed (statutory 2 August 2027)

Other proposed changes

  • AI literacy: binding employer obligation softened toward member-state encouragement.
  • EU database registration simplified for providers exempted from high-risk classification.
  • Single entry point proposed for cybersecurity incident reporting across digital rules.
Read COM(2025) 836 on EUR-Lex

This site continues to show statutory dates from Regulation (EU) 2024/1689 until the Omnibus is adopted. Check the AI Office implementation page for live legislative updates.