Skip to content

Curated Insight: Fraud detection in the EU AI Act (based on recent draft guidance)

TL;DR
• The European Commission has published draft guidance on which AI systems count as high-risk under the EU AI Act.
• Fraud detection is carved out for credit systems, but not for life and health insurance (risk assessment / pricing), unless fraud detection is its own system.

 

In support of its AI Act, the European Commission published draft guidelines in May 2026 on how to classify high-risk AI systems. Consultation closed in July.

A high-risk classification matters because it creates additional obligations. The guidelines are draft, so could change after the consultation feedback is considered. But there’s a lot of detail, including specifics about fraud detection in FS.

Useful to know even outside the EU. In scope anyway if systems or their outputs get used there. Other jurisdictions are watching, or could be in future. Putting compliance aside, it also tells us which systems deserve additional focus and controls.

 

Credit. Creditworthiness and credit scoring systems are high-risk. Fraud detection is carved out, if that’s the main purpose of the system, even if the output is used for creditworthiness or the credit score.
Note: AML/CTF is handled separately.

 

General insurance isn't mentioned. The provision covers life and health only; property, motor, and the rest aren’t named. There's some debate about whether they're really out of scope. If we're not taking a purely compliance-focused view, we may be able to use the life and health guidance for general insurance systems too.

 

Life and health insurance. Risk assessment and pricing systems are high-risk, but without a fraud carve-out. So if the pricing system also does fraud detection, the whole thing is high-risk. The fraud part is only outside if it's a separate system.

It becomes an architecture question (how the systems were built). Where fraud scoring is inside the underwriting platform, it might because that's how the vendor does it. Adding AI to that platform, without an architectural redesign, can inadvertently bring fraud detection into scope.

 


Disclaimer: The info in this article is not legal advice. It may not be relevant to your circumstances. It was written for specific contexts within banks and insurers, may not apply to other contexts, and may not be relevant to other types of organisations.