Module 2 of the free EU AI Act Fundamentals course: the four risk tiers, Annex I vs Annex III, and the carve-outs that keep fraud detection, KYC matching and algorithmic trading out of the high-risk regime.

Everything expensive in the AI Act follows from classification. Get it right and a large AI estate can carry a modest compliance load. Get it wrong in the cautious direction and you will build a conformity assessment for a chatbot; get it wrong in the other and you will operate a high-risk system without one.

There are four tiers.

Tier 1 — Prohibited (Art. 5)

Eight practices are banned outright. They have been in force since 2 February 2025. The ones a commercial organisation could plausibly stumble into:

The Digital Omnibus added one more: non-consensual intimate imagery / nudification, applying from 2 December 2026.

Breaching Art. 5 carries the top penalty band: €35 million or 7% of worldwide annual turnover, whichever is higher.

Tier 2 — High-risk (Art. 6, Annexes I and III)

Two doors lead into high-risk, and they are not equivalent.

Annex I — the system is a safety component of a product already covered by EU harmonisation law (machinery, medical devices, lifts, toys, and so on). This route applies from 2 August 2028. Financial entities rarely enter here.

Annex III — the system falls into one of eight listed use-case areas. This route applies from 2 December 2027 (deferred by the Digital Omnibus). This is the door that matters for finance, and the exclusions written into it are the whole point of this module.

The carve-outs that decide most cases

Annex III 5(b) — creditworthiness. In scope: evaluating the creditworthiness of natural persons or establishing their credit score. That covers consumer lending, BNPL, retail margin lending, and crypto lending to individuals.

It explicitly excludes AI systems used to detect financial fraud. So transaction monitoring, AML screening and fraud models are not high-risk. This is the most common scoping error in the sector, and it runs in the expensive direction: firms classify their fraud stack as high-risk and take on Art. 8–15 obligations that were never owed.

It also covers natural persons only. SME and corporate credit scoring is not listed.

Annex III point 1 — biometrics. In scope: remote biometric identification, biometric categorisation by sensitive attributes, emotion recognition.

It excludes biometric verification whose sole purpose is confirming a person is who they claim to be. A KYC selfie matched 1:1 against a document photo is verification, not identification. It is out. (GDPR Art. 9 still governs the biometric data itself — a different regime, still binding.)

Annex III point 4 — employment. Recruitment, CV screening, promotion and termination decisions, task allocation, monitoring and evaluation of performance.

This is the point that actually catches most financial entities — as employers, not as banks. A CV-screening tool in HR is high-risk in a bank exactly as it is in a bakery.

Annex III 5(c) — insurance. Risk assessment and pricing in life and health insurance for natural persons. Non-life claims triage is not listed.

What is not in Annex III at all

Algorithmic trading and robo-advice appear nowhere. They are governed by MiFID II Art. 17 and RTS 6 (Delegated Regulation (EU) 2017/589), and by the ESMA statement of 30 May 2024 on AI in investment services. That is a real regulatory burden — it is simply not this one.

The Art. 6(3) filter

Even inside an Annex III area, a system is not high-risk if it does not pose a significant risk of harm — because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs preparatory work.

The filter has a catch: profiling of natural persons always makes it high-risk, no exceptions. And if you rely on the filter you must document the assessment before placing the system on the market and register it in the EU database. It is a genuine off-ramp, not a shrug.

Tier 3 — Transparency (Art. 50)

Applies whatever the risk tier. In force 2 August 2026 — not deferred by the Omnibus, which makes it the next real deadline for most organisations.

Your customer chatbot is not high-risk. It is caught by Art. 50, and the deadline is closer.

Tier 4 — Minimal risk

Everything else. No obligations under the Act — except Art. 4 AI literacy, which applies to providers and deployers across the board, whatever the tier.

The honest map for a financial entity

Use case Tier Why
Transaction fraud detection Minimal Annex III 5(b) excludes fraud detection
AML / sanctions screening Minimal Not an Annex III use case
KYC 1:1 selfie match Minimal Point 1 excludes verification
Consumer credit scoring High-risk Annex III 5(b)
SME / corporate scoring Minimal 5(b) is natural persons only
Algorithmic trading Minimal (under the AI Act) Not in Annex III; MiFID II / RTS 6 govern
CV screening High-risk Annex III point 4
Employee performance monitoring High-risk Annex III point 4
Customer chatbot Transparency Art. 50(1)
Life / health insurance pricing High-risk Annex III 5(c)

Check yourself

  1. Your AML model scores every transaction. Which tier?Minimal. Annex III 5(b) excludes fraud detection, and AML is not otherwise listed. Art. 4 literacy still applies.
  2. HR uses a CV-ranking tool. You are a bank. Which tier?High-risk, Annex III point 4. Your sector is irrelevant; you are acting as an employer.
  3. Your chatbot answers balance questions. When is the deadline?2 August 2026, Art. 50(1). Earlier than the high-risk regime, and not deferred.
  4. You rely on Art. 6(3) to say your Annex III system is not high-risk. What must you do? — Document the assessment before market placement and register the system in the EU database. And check it does not profile natural persons, which would void the filter.

Previous: Module 1 — What the Act regulates · Next: Module 3 — Obligations by role →

Frequently Asked Questions

No. Annex III point 5(b) covers AI used to evaluate the creditworthiness of natural persons or establish their credit score, and it explicitly EXCLUDES AI systems used to detect financial fraud. Transaction monitoring, AML screening and fraud models are therefore outside the high-risk regime — though Art. 4 AI literacy still applies, and Art. 50 may apply if output is shown to customers.

No. Annex III point 1 covers remote biometric identification systems. It excludes AI used for biometric verification whose sole purpose is confirming that a person is who they claim to be — which is exactly what a 1:1 KYC selfie-to-document match does. It is not high-risk under the AI Act, though GDPR Art. 9 still governs the biometric data.

Algorithmic trading and robo-advice appear nowhere in Annex III. They are governed by MiFID II Art. 17 and RTS 6 (Delegated Regulation (EU) 2017/589), and by the ESMA statement of 30 May 2024 on the use of AI in investment services. The AI Act's high-risk obligations do not attach to them.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.