A European bank uses three separate AI systems: (1) a real-time credit scoring model that determines loan eligibility for retail customers, (2) a customer service chatbot that answers FAQ-type questions on the bank's mobile app, and (3) a social credit scoring system that rates customer trustworthiness based on social media behavior for access to financial products. Under the EU AI Act (Regulation 2024/1689), how should these three systems be classified?
Select an answer to reveal the explanation.
Short Explanation and Infographic
The EU AI Act has four risk tiers — think of it as a traffic light with an extra color for things so dangerous they're just banned. Social credit scoring based on social behavior to restrict access to financial services? That's explicitly listed in Article 5 as prohibited — full stop. Credit scoring for loan eligibility is explicitly in Annex III as High-Risk. A basic FAQ chatbot that doesn't pretend to be human falls into Minimal-Risk. Option B gets the trifecta right.
Full explanation below image
Full Explanation
The EU AI Act (Regulation 2024/1689, entering into force August 2024) establishes a four-tier risk classification system: Unacceptable Risk (prohibited), High Risk, Limited Risk, and Minimal Risk. Classification is determined by the AI system's use case and potential for harm, not by the regulated status of the deploying organization.
System 1 — Credit Scoring Model: Annex III of the EU AI Act explicitly lists 'AI systems used to evaluate the creditworthiness of natural persons or establish their credit score' as High-Risk AI. High-Risk AI systems must comply with mandatory requirements including data governance, technical documentation, transparency, human oversight, accuracy/robustness standards, and registration in the EU AI database. This classification applies regardless of the model's architecture (traditional ML, deep learning, etc.).
System 2 — FAQ Chatbot: A simple customer service chatbot that answers pre-defined questions about products and services, without making consequential decisions, falls into the Minimal Risk tier. The only additional obligation that might apply is Limited Risk transparency (disclosing to users that they are interacting with an AI) under Article 52—but a straightforward FAQ bot with no deceptive intent would not trigger even Limited Risk classification. Option B correctly classifies this as Minimal Risk.
System 3 — Social Credit Scoring: Article 5 of the EU AI Act explicitly prohibits AI systems that evaluate or classify individuals based on their social behavior or personal characteristics in ways that lead to detrimental or unfavorable treatment in contexts unrelated to those in which the data was generated. Using social media behavioral data to generate a 'trustworthiness' score that restricts access to financial products is a paradigmatic example of prohibited social scoring, regardless of whether the deploying entity calls it a 'credit risk model.' This system is Unacceptable Risk and must not be deployed.
Option A is incorrect because the EU AI Act classifies by use case, not by institutional status. A minimal-risk chatbot at a bank is still minimal risk.
Option C incorrectly classifies the credit scoring model as Unacceptable and the social credit system as High-Risk. These are inverted—credit scoring for loan eligibility is High-Risk (not banned), while social scoring for financial access is explicitly prohibited.
Option D misclassifies System 3 as High-Risk rather than Unacceptable. Social credit scoring is not merely regulated under High-Risk provisions; it is outright prohibited under Article 5.