# EU AI Act (for compliance tools)

**The EU AI Act is Regulation (EU) 2024/1689, the EU's horizontal law on artificial intelligence. For a compliance tool it matters in three ways: general duties that already apply (AI literacy, and transparency when people interact with an AI system); a classification that decides whether the stricter high-risk rules apply; and, for high-risk systems, requirements on logging, transparency and human oversight that apply to Annex III systems from 2 December 2027.**

*Also called:* the AI Act, the Artificial Intelligence Act.

## Why it matters for PSPs and EMIs

Payment and e-money institutions increasingly use AI to summarise evidence, match names, classify documents or suggest risk ratings. Under the AI Act they are usually "deployers" of those systems, and their vendors are "providers". Whether the system is high-risk depends on its intended purpose. Separately, the AMLR sets its own rules on decisions produced by automated processes and AI systems, so a firm using an AML tool has to satisfy both.

## What the law says

- **Roles.** AI Act Art. 3(1) (AI system), Art. 3(3) (provider) and Art. 3(4) (deployer).
- **Already applicable.** Chapters I and II (including the Art. 4 AI-literacy duty and the Art. 5 prohibited practices) since 2 February 2025, except two prohibitions added in 2026, which apply from 2 December 2026; the transparency duties of Art. 50 (for example, telling people they are interacting with an AI system) from 2 August 2026, the Act's general date of application (Art. 113).
- **The 2026 amendment.** The Digital Omnibus on AI, Regulation (EU) 2026/1744 (published 24 July 2026, in force 27 July 2026), moved the application of the high-risk requirements (Chapter III, Sections 1 to 3) to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. It also reworded Art. 4: providers and deployers must take measures to support the development of AI literacy; the duty does not require any particular level to be reached by each individual.
- **Is an AML tool high-risk?** Annex III lists the high-risk use cases. It does not list anti-money-laundering customer due diligence as such. Point 5(b) covers creditworthiness assessment and credit scoring of natural persons, "with the exception of AI systems used for the purpose of detecting financial fraud"; recital 58 adds that systems provided for by Union law to detect fraud in financial services should not be considered high-risk under the AI Act. Point 1(a) covers remote biometric identification but excludes biometric verification that only confirms a person is who they claim to be. The classification of a specific system depends on its intended purpose; a provider that considers an Annex III system not high-risk must document that assessment (Art. 6(3) and (4)).
- **If high-risk.** Art. 12 (automatic logging), Art. 13 (transparency and information to deployers), Art. 14 (human oversight, including awareness of automation bias and the ability to override), Art. 26 (deployer duties, with specific provisions for financial institutions) and Art. 86 (right to an explanation).
- **AML rules on automated decisions.** AMLR Art. 76(5): firms may take decisions resulting from automated processes or AI systems only if the data are limited to customer-due-diligence data, any decision to accept, refuse or end a relationship, or to increase or decrease due diligence, is subject to meaningful human intervention, and the customer can obtain an explanation and challenge the decision (except in relation to a suspicious transaction report).
- **Data protection.** GDPR (Regulation (EU) 2016/679) Art. 22 on decisions based solely on automated processing.

## How ProofVolt handles it

In ProofVolt, every AI-assisted output is traceable to its inputs, every conclusion shows its sources, and an officer decides. Website checks follow fixed rules, not a model's judgement. No AI output can quietly clear a risk. These are product capabilities that support the Act's themes of record-keeping, transparency and human oversight; they are not a statement about how ProofVolt is classified under the Act.

## Related

- [Four-eyes principle](/glossary/four-eyes-principle/)
- [AMLR](/glossary/amlr/)
- [What an auditor asks about AI in compliance](/guides/auditor-questions-ai-in-compliance/)

Canonical: https://proofvolt.eu/glossary/eu-ai-act/
