Which Fact Preceded the Alert? Article 5(1)(d) AI Act Splits Your Two Scoring Models
The Commission's guidelines of 29 July 2025 expressly place an anti-money-laundering-obligated bank within the scope of the prohibition under Article 5(1)(d) AI Act (para. 209). The fraud model escapes via para. 210; the AML model escapes only through the exception in the final clause — and that exception rests on the model documentation, not the model.
Dr. iur. Servatius von Tatzenberg
Article 5(1)(d) of the AI Act prohibits AI systems that predict the risk of a natural person committing a criminal offence based solely on profiling them or assessing their personality traits and characteristics. The text does not name any particular sector as its addressee. In its Guidelines on Prohibited AI Practices of 29 July 2025, the Commission draws a conclusion that tends to get lost in advisory practice: a bank subject to anti-money-laundering obligations falls within the scope of the prohibition (para. 209). Its AML scoring escapes only through the exception in the guidelines’ final clause — and that exception rests on the model documentation, not on the model itself.
This is not a 2027 problem. The prohibition has applied since 2 February 2025 (Article 113(a)) and has carried fines since 2 August 2025, of up to EUR 35 million or 7 percent of worldwide annual turnover (Article 99(3)). The Digital Omnibus left point (d) untouched, as we noted on 26 July. Nor does the deferral of high-risk obligations to 2 December 2027 offer any relief: Annex III point 5(b) covers creditworthiness assessment but expressly excludes systems for detecting financial fraud, and point 6(d) applies only to law enforcement authorities. A pure transaction-monitoring model therefore never makes the high-risk list and is measured against Article 5 alone.
The guidelines draw the line twice, and it does not run along technical lines. Paragraphs 210 and 211 carve out private profiling in the ordinary course of business where it protects the firm’s own financial interests and any link to a criminal offence arises only incidentally and downstream. That describes the fraud model: card misuse, account takeover, chargebacks. Paragraph 209 is different, because there the law itself obliges the bank to predict a criminal offence. Two models that read the same transaction data, and often share the same feature library, end up on opposite sides of a prohibition — and which side depends on the documented purpose.
The common reassurance rests on Recital 42. It exempts risk analytics that are not based on the profiling of individuals, citing as an example the assessment of the likelihood of financial fraud by companies based on suspicious transactions. The operative word is “companies.” Paragraph 215 confirms the exception for legal persons; paragraph 216 pulls sole traders and self-employed professionals back in. A score on a retail counterparty is a prediction about a natural person, and the recital does not cover it.
What the exception requires is set out in paragraphs 202 and 206. The AI system must support the human assessment rather than replace it, and that assessment must already rest on objective, verifiable facts directly linked to a criminal activity. The guidelines require pre-established facts — the English text says “pre-established” — meaning they must exist before the score is generated. A model whose own alert is the only fact in the chain cannot pull itself out of the prohibition by its own bootstraps. In the tax example given in the same paragraph, the Commission rejects “opaque variables, especially inferred information that is predictive and therefore non-objective and hard to verify.”
The Future of Privacy Forum reads the word “solely” as a loophole. Paragraph 202 half-closes it again, because any further elements must be “real, substantial and meaningful.” That lands squarely on the features from which transaction-monitoring models derive their discriminatory power: deviation from a peer group, behavioural segment, network value drawn from counterparty relationships. Objective and verifiable are a sanctions-list hit, PEP status from a register, the counterparty’s country of domicile, the amount, a prior suspicious-activity report. Only a firm that can show the second category carries the alert — with the first merely sharpening it — can claim the exception.
Paragraph 209 sets two conditions: the data must be solely that which Union anti-money-laundering law designates, and there must be human review of the prediction. The guidelines point for this to Article 20 of Regulation (EU) 2024/1624, which does not become applicable until 10 July 2027. Until then, that data is designated by the national law transposing the Anti-Money Laundering Directive; your EU subsidiary is measured against that standard today, not against the future single one. Article 20(4) of the regulation will in any case later require demonstrating to the supervisor the adequacy of the measures taken. The same documentation carries both obligations.
Who is caught is set out in Article 2(1). A Swiss bank with no EU establishment, whose outputs are not used within the Union, is outside scope. Inside scope is the group model built in Zurich and made available to a Frankfurt or Luxembourg subsidiary: the subsidiary is the deployer within the Union, the parent company the provider. That parent’s model documentation is, as a rule, written against Article 6 GwG and Articles 13, 14 and 20 of the GwV-FINMA (the FINMA Anti-Money-Laundering Ordinance). The Swiss framework is not Union anti-money-laundering law within the meaning of paragraph 209, and the mapping of features to the governing EU instrument is missing.
The second condition is the more delicate one. Paragraph 205 draws on the Ligue des droits humains judgment (C-817/19): human review of a hit must be based on objective criteria and must ensure the non-discriminatory nature of the automated matching. A four-eyes click through two thousand alerts a day does not meet that standard. Article 20(3) GwV-FINMA already requires, today, that transactions identified by the monitoring system be evaluated within a reasonable period. A firm that logs that evaluation generates exactly the record the AI Act exception demands.
The step for Monday is a three-column table, one row per model. First column: the stated purpose, in the wording used in the model approval. Second column: the features, split between pre-existing verifiable facts and derived variables. Third column: the evidence that a human evaluated the alert, and what that evidence consists of. Rows where the first column points to a criminal offence and the second column stays thin belong on the agenda of the next risk committee meeting.
How narrowly “solely” will be construed remains open; that question will ultimately be settled by the CJEU, not the Commission. The nearer deadline is a different one. AMLA opened consultation on 9 February 2026 on the draft regulatory technical standards under Article 28(1) AMLR, with a deadline of 8 May 2026, after which it will submit them to the Commission for adoption. Those standards designate the information to be collected for due-diligence purposes. Once adopted, they will fix the data list that paragraph 209 refers to — and with it, the outer limit of what features an AML model may run on without losing the exception.