AI & Compliance
The EU AI Act Quietly Split Fraud Detection and AML Into Two Different Risk Categories
Two AI systems can look almost identical — score a transaction, flag it, route it for review — and sit in completely different regulatory categories under the EU AI Act, for a reason that has nothing to do with how they work and everything to do with what they're labelled for.
July 26, 2026 · 9 min read
Annex III of the EU AI Act lists the categories of AI system that count as “high-risk” — the classification that triggers the Act’s heaviest obligations: a documented risk management system, human oversight built into the design, and a conformity assessment before deployment. AI systems used to assess a natural person’s creditworthiness or credit score are named explicitly. So, by extension, are a lot of systems a bank might reasonably call “fraud and risk scoring.” Except the Act carves one specific thing back out: AI intended to be used for financial fraud detection is excluded from the high-risk category, provided detecting fraud is the system’s main intended purpose.
That exception sounds like it should cover most of what a financial-crime team runs. It doesn’t, and the European Commission has said so directly: the fraud detection exception is to be interpreted narrowly, and — critically — it does not extend to AI systems used for anti-money laundering or counter-terrorist-financing checks.
Why this distinction is bigger than it looks
Sit with what that actually means operationally. A transaction-scoring model built to catch card fraud or account-takeover fraud can plausibly sit outside the Act’s high-risk regime, because catching fraud is its stated purpose. The moment a materially similar model is deployed, or repurposed, or dual-labelled to also flag transactions for AML review, it loses the exception — not because the underlying technology changed, but because the purpose did. Two systems with near-identical architectures, trained on overlapping data, doing recognizably similar scoring, can land in entirely different compliance regimes depending on how the deployer describes what the system is for.
For a compliance function that’s been quietly running one shared detection model across both fraud and AML use cases — which is common, because the underlying transaction-anomaly problem genuinely overlaps — this is not a paperwork nuance. High-risk classification under the Act means Article 9 risk management, Article 14 human oversight designed into the system rather than bolted on after, and a conformity assessment, all applying in full once the relevant provisions take effect from 2 August 2026. A system that was fine to deploy quietly as “fraud detection” needs the full high-risk treatment the moment its actual use includes AML screening, regardless of what it was originally procured as.
The part most teams will get wrong first
The natural failure mode isn’t ignorance of the Act — most compliance functions know the EU AI Act exists and know credit scoring is high-risk. It’s assuming the fraud detection exception is broad enough to cover “anything that scores a transaction for risk,” when the Commission has specifically narrowed it to systems whose main intended purpose is fraud detection, and specifically excluded AML/CFT from riding along on that exception. A model doing double duty needs to be evaluated against its AML use on its own terms, not inherit an exemption earned by its fraud-detection framing.
The practical question worth asking about every transaction-scoring or alert-generation system currently in production, or in procurement: what is this system’s stated intended purpose, does its actual use match that purpose exactly, and if AML or CFT screening is any part of what it actually does, has it been assessed against the full high-risk obligations rather than assumed to travel under the fraud detection exception. For firms operating in or serving EU markets, that assessment has a hard date attached to it. For UK firms watching from outside direct EU AI Act scope, it’s still the clearest indication yet of how a major regulator has chosen to draw the line between fraud and AML AI — a distinction the FCA’s own principles-based approach hasn’t required UK firms to make explicit, but one worth making internally regardless, because it’s the right question independent of which regulator is asking it.