By use case · Written by Yobel Tzegai · Last checked 9 October 2026

Is AI fraud detection high-risk under the EU AI Act?

AI fraud detection under the EU AI Act: excepted from Annex III’s credit point and named nowhere else in it, but limited by the Article 5 profiling ban.

Check your AI systems, freeBook a 30-minute walkthrough

The answer, in detail

Where a fraud use usually sits
UseUsual outcomeProvisionWhat would change it
Flagging suspicious payments or transactionsNot high-riskPoint 5(b) of Annex III, which excepts detecting financial fraudUsing the same system to evaluate creditworthiness
Detecting insurance claims fraudNot listed in Annex IIIAnnex III, which does not list itRisk assessment and pricing for life or health cover, point 5(c)
Predicting a person will commit fraud from their profile aloneProhibitedArticle 5(1), first subparagraph, point (d)Supporting a human assessment based on objective and verifiable facts
Profiling by or for law enforcement authoritiesHigh-riskPoint 6(e) of Annex IIINot a private company’s own use

What does the credit point except?

Detecting financial fraud, by name. A system that both scores creditworthiness and flags fraud is still in point 5(b) for the scoring. AI credit scoring under the EU AI Act takes that side.

When does fraud AI become prohibited?

What applies to every use?

Your customer asks. You answer with proof.

  1. 1List every AI system

    Add the AI you use. Each system gets a role, a risk class and the article it rests on.

    Live
  2. 2Attach the proof

    Link each duty to a file and the page it stands on: a policy, a log setting, a training record.

    Live
  3. 3Answer their questionnaire

    Answering a customer's questionnaire inside the app, from the proof you already linked.

    Coming soon

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • AI inventory Every AI system you build or use, with its owner and risk class
  • AI literacy (Article 4) Records who was trained on what and when, against the Article 4 duty to support AI literacy, which applies whatever your risk level
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Domain-specific guidance Not supported Guidance written for one sector.

What is live today

Checked against the app on 8 October 2026
Starter

€499 a month

Prices exclude VAT.

  • Up to 20 AI systems
  • Every duty, deadline and article
  • Evidence and the audit log
  • Your first system is free, with no end date
Check your AI systems, free

All plans

Questions

Does the fraud exception cover anti-money-laundering screening?

The text names detecting financial fraud, inside point 5(b) on creditworthiness. Whether a given screening system detects fraud or does something else is a question of its intended purpose. A system that predicts a person will offend based solely on profiling is prohibited whatever its label (Article 5(1), first subparagraph, point (d)).

Do we still need to record a fraud model?

Yes, as one of your AI systems with its intended purpose, even when the outcome is not high-risk. The record is what shows why: point 5(b) of Annex III excepts it, and the Article 5 checks were made. Article 4 applies to it either way.

Read next
See what your customers will ask about your AI.No account needed. Every answer cites the article it rests on.