AI governance and digital regulation

The EU AI Act for Crypto Firms: Classification Before Compliance

The function, intended purpose and role of the firm determine the obligation. Industry labels do not.

Abstract illustration of an AI system connected to a wallet, a person, a screen and a compliance shield

A CASP can deploy a customer chatbot, fraud model, biometric identity check, recruitment tool and credit model under five different legal starting points. One corporate AI policy will not classify them.

Five systems, five starting points

A useful inventory begins with function. Consider five tools inside one crypto group: a support chatbot, a transaction-fraud model, a facial identity check, a recruitment screener and a retail credit model. Their technology may be similar. Their legal classification is not.

The AI Act reaches high-risk systems through Article 6(1), for certain regulated products and safety components, and Article 6(2), for the use cases listed in Annex III. Most CASP questions arise under Annex III.1

Article 6(3) can remove an Annex III system from the high-risk category where the provider documents that the system performs a narrow procedural, preparatory or similarly limited task without significant risk of harm. Profiling of natural persons remains high-risk. The assessment belongs to the provider and carries documentation and registration consequences.15

Use CaseStarting PointMain Control
Customer chatbotArticle 50 transparency; usually outside high-riskDisclose AI interaction and maintain escalation
AML or fraud detectionOutside Annex III unless another listed purpose appliesDocument function, decision effect and human review
Identity verificationSole-purpose identity confirmation excluded from remote-biometric categoryGDPR biometric-data, accuracy and security controls
Recruitment or worker monitoringAnnex III high-risk; some emotion inference prohibitedWorker notice, oversight and later high-risk duties
Retail creditworthinessAnnex III high-riskImpact assessment where applicable, provider and deployer controls
Row of panels representing different AI use cases in a crypto firm, from chatbots and monitoring to identity checks, employment tools and credit decisions
One firm can operate ordinary, high-risk and prohibited use cases at the same time.

What applies before the high-risk deadline

The AI Act entered into force on 1 August 2024 and applies in stages. AI literacy and prohibited practices have applied since 2 February 2025. Most Article 50 transparency duties start on 2 August 2026.12

The 2026 Digital Omnibus completed legislative approval in June. The adopted text moves Annex III stand-alone high-risk duties to 2 December 2027 and product-safety high-risk duties to 2 August 2028.34

Those dates do not suspend existing law. GDPR governs personal data, DORA governs ICT risk and third-party arrangements for in-scope CASPs, and MiCAR continues to govern the regulated process in which the AI is used.678

In AI inventories I review, firms often list models and vendors but omit the decision. That omission is costly. “Screening tool” says little; “can block a withdrawal without a second reviewer” says what the governance process needs to know.

Identity checks, fraud and credit

A system that checks document quality, compares a live image with an identity document, detects tampering and sends uncertain cases to a trained reviewer starts outside Annex III high-risk status on those facts.

The biometric category excludes verification whose sole purpose is confirming that a person is who they claim to be. The creditworthiness category expressly excludes systems used to detect financial fraud.1

GDPR still applies to biometric personal data. The firm needs a lawful basis, clear information, retention limits, security, accuracy testing and, where required, a data-protection impact assessment.6

Repurpose the same model to decide whether a natural person receives credit and the classification can change. Creditworthiness and credit scoring are listed high-risk uses. Fraud detection is a different purpose, even when the underlying features overlap.

My reading is that repurposing will create more provider risk than original development in many CASPs. Teams reuse a model because it performs well, then discover that the new decision carries a different legal status.

The employment risk inside the firm

Annex III covers AI used to target job advertisements, filter applications, evaluate candidates, decide promotion or termination, allocate tasks based on individual behaviour and monitor employee performance.1

Crypto firms may therefore have a clearer high-risk system in HR than in financial-crime monitoring. Before deployment, the firm also needs to inform affected workers and their representatives under Article 26, alongside wider employment-law duties.

Emotion inference in the workplace is prohibited except for medical or safety purposes. Product descriptions such as engagement analysis or stress insight should be tested against the actual inference, not accepted at face value.

When a deployer becomes a provider

Article 25 reallocates responsibility where a deployer puts its own name or trademark on a high-risk system, makes a substantial modification while it remains high-risk, or changes the intended purpose of a non-high-risk system so that it becomes high-risk.1

Substantial modification has a defined threshold. The change must fall outside what the original conformity assessment foresaw and affect compliance with the high-risk requirements or alter the assessed intended purpose. Fine-tuning, threshold changes and prompt engineering need review, though they do not all cross that threshold.

The release process should compare the vendor's intended purpose with the firm's implemented purpose, data, users and decision effect. A material difference pauses deployment until legal, risk and technology owners record the new role allocation.

Pipeline diagram showing an AI system moving from vendor documentation through the firm's use and modification to a changed compliance status
Role allocation can change when the firm rebrands, repurposes or substantially modifies the system.
“The classification follows the system the firm actually deploys, not the product it originally bought.

One inventory, four rulebooks

DORA applies to the ICT risk of an AI tool and its supplier even when the system is outside the AI Act high-risk categories. Outage, concentration, data integrity and exit remain financial-services concerns.7

GDPR applies whenever personal data is processed. Profiling, biometric data, automated decisions, fairness and transparency can all be relevant without an Annex III trigger.6

MiCAR governs the regulated activity. An AI system that drafts a marketing communication, screens a withdrawal or supports custody operations sits inside the firm's conduct, outsourcing, record-keeping and control duties.8

The practical answer is one system inventory with several legal views. Separate registers tend to diverge: one calls the tool a chatbot, another a processor, another an ICT service, while nobody records that it can refuse a customer request.

A release gate for 2026

The operating model can be concise. Six records should exist before a material AI use reaches production.

1Inventory System, owner, vendor, model, data, users, affected persons and decision consequence.
2Role map Provider, deployer, importer, distributor and any group allocation.
3Classification Article 5, Article 6, Annex III and Article 50 rationale with a review trigger.
4Current duties AI literacy, prohibited-use screening, transparency, GDPR and DORA controls.
5High-risk readiness Instructions, human oversight, input data, logs, monitoring, incident handling and notices.
6Change approval New purpose, rebranding, integration, fine-tuning or material model change before release.

The question that remains open

The Commission's high-risk guidance was still in draft consultation on 22 July 2026, and the Digital Omnibus required Official Journal publication before entry into force. Final guidance will settle some boundaries; product design will keep creating new ones.

A board does not need model architecture in every meeting. It needs to know which systems can block a customer, affect employment, process biometric data or alter a regulated decision, who owns the limitations and whether a human can intervene in time.

A CASP is exposed when the system has changed faster than the record describing it.

“INSIGHTS”