Annex III point 5(b) of the EU AI Act (Regulation (EU) 2024/1689) makes creditworthiness assessment and credit scoring high-risk, “with the exception of AI systems used to detect financial fraud.” Recital 58 goes further still: AI systems that Union law provides for to detect fraud in the offering of financial services, and for prudential purposes to calculate the capital requirements of credit institutions and insurance undertakings, aren’t considered high-risk under the Regulation at all. And Recital 42 keeps a specific category of entity-level risk analytics — assessing the likelihood of financial fraud by undertakings based on suspicious transactions — outside the Article 5(1)(d) prohibition on profiling-based crime prediction entirely. Three separate carve-outs, each with its own precise wording, and most AML-focused content hasn’t caught up with any of them.
The three carve-outs, stated plainly
If your system detects financial fraud rather than scoring a natural person’s creditworthiness, and it doesn’t profile individuals to do it, there’s a good chance none of the high-risk machinery in this Regulation reaches it. Each of the three routes there has its own source and its own precise limits, worth taking one at a time.
The Annex III 5(b) exception
This one sits in the operative Annex itself, not a recital — the fraud carve-out is written directly into the same provision that otherwise makes credit scoring and creditworthiness assessment high-risk, rather than added as separate interpretive commentary. That placement matters: an Annex carve-out has the same legal weight as the rule it modifies, not the softer interpretive status of recital text.
Recital 58
Recital 58 adds two more categories, both carrying a real limiting condition. Fraud-detection systems are excluded only where Union law itself provides for that detection function — this isn’t a blanket exemption for any anti-fraud tool a firm builds on its own initiative, but specifically for systems built to satisfy a fraud-detection obligation that Union law already imposes, such as under the anti-money-laundering framework or payment services rules. Separately, and rarely mentioned in AML-focused guidance at all, systems used for prudential purposes to calculate the capital requirements of credit institutions and insurance undertakings are excluded too.
Recital 42
Article 5(1)(d) prohibits assessing or predicting the risk that a natural person will commit a criminal offence, based solely on profiling that person or assessing their personality traits and characteristics. Recital 42 clarifies what that prohibition doesn’t reach: risk analyses that aren’t based on profiling natural persons or their personality traits at all. The recital gives two concrete examples — AI systems using risk analysis to assess the likelihood of financial fraud by undertakings based on suspicious transactions, and risk analysis tools predicting the likelihood of drug or illegal-goods finds by customs authorities based on known smuggling routes. Entity-level and pattern-level analysis sits outside the prohibition by design; the ban is aimed squarely at profiling people.
Where every carve-out collapses
Two triggers end all three exceptions at once, and they’re worth holding in mind as a single test rather than three separate ones.
The first is the moment a system’s output actually scores a natural person’s creditworthiness. The Annex III 5(b) exception protects fraud detection specifically — it was never an exemption for creditworthiness scoring, so a tool that starts life detecting fraud but feeds into an actual credit decision about an individual has walked into the very category the carve-out exists to carve around.
The second is profiling itself. Article 6(3) is explicit and leaves no room to argue around it: any Annex III system also used to profile natural persons is always high-risk, with no exemption available regardless of what else the system does. An alert-triage model that ranks individual customers by their behavioural traits is not the same artefact as one that scores the suspiciousness of an entity’s transactions, even if both get called “fraud detection” internally. The label doesn’t decide the outcome; what the model actually measures does.
Why the vendor material is behind
Hawk’s 2024 whitepaper on the AI Act put it carefully, and honestly, for the moment it was written: whether AI in AML and fraud prevention would count as high-risk “still needs to be determined,” with “initial indications” suggesting it might not be, and official interpretive guidelines expected to settle the question. That hedging was reasonable at the time. It just isn’t accurate anymore — the final text answered this directly, in the Annex itself, and never needed separate guidelines to do it. Content written in that earlier window of genuine uncertainty is still circulating as though the uncertainty never resolved.
What you still owe even when you’re out
Falling outside Annex III doesn’t mean falling outside the Act entirely. Article 4 AI literacy applies to all AI regardless of risk tier, with no carve-out for fraud-detection systems. Article 50 transparency duties apply if the system interacts directly with people — a customer-facing fraud alert, for instance. And the Article 5 prohibitions never depended on risk classification in the first place; a system that did profile individuals to predict criminal behaviour would face Article 5(1)(d) regardless of anything Annex III says about fraud detection.
Frequently asked questions
Is sanctions screening high-risk?
Generally not, on the same logic Recital 42 sets out for fraud analytics — screening names and entities against watchlists doesn’t itself assess a natural person’s creditworthiness or predict individual criminal behaviour through personality profiling. That reading holds only as long as the screening stays at the entity or transaction level; layering in behavioural profiling of individuals changes the analysis.
Is our alert-triage model in scope?
Test it against the same two triggers. A model scoring transaction or entity-level suspicious-activity patterns sits inside the carve-outs described here. A model that ranks or scores individual customers based on their profiled behaviour or personality traits doesn’t, regardless of how the function is labelled internally.
What about AML models that also feed credit decisions?
Once that model’s output feeds an actual creditworthiness or credit-scoring decision about a natural person, you’re inside Annex III 5(b)’s core high-risk category rather than its fraud-detection exception. The exception protects fraud detection; it doesn’t follow the model downstream into a different use.
Does the Omnibus change Annex III 5(b)?
Not as far as the current record shows. The Digital Omnibus reform’s substantive changes concentrate on Annex III and Annex I timing, the registration duty, and the safety-component definition — nothing in what’s been reported touches the individual category carve-outs within Annex III itself.
Who decides — us or our national supervisor?
You make the initial classification call, the same self-assessment pattern that runs throughout Article 6. Your national financial supervisor — the authority Recital 158 designates as the market surveillance authority for regulated financial institutions — retains the ordinary power to review that classification afterward and require correction if it disagrees.
