EU AI Act

Is Insurance Underwriting AI High-Risk Under EU AI Act?

The Act specifically lists life-and-health risk assessment and pricing. Underwriting, claims, renewals, and other lines need classification by intended purpose rather than assumption.

12 min read
Joe Braidwood
Joe Braidwood
CEO, GLACIS
12 min read

Quick Answer: Yes, for Life and Health Insurance

AI intended for risk assessment and pricing in relation to natural persons in life and health insurance is listed as high-risk in EU AI Act Annex III point 5(c), subject to Article 6. This can include underwriting models when their intended purpose is that listed risk-assessment or pricing function.

Property, casualty, and commercial insurance AI are not explicitly listed; classification depends on the intended use and the Act’s scope. Relevant Annex III high-risk obligations apply from December 2, 2027 under the AI Omnibus.

Different recordkeeping regimes need separate mappings

SEC Rule 17a-4 governs specified broker-dealer records and, after 2022 amendments, permits either WORM storage or an audit-trail alternative meeting the rule. It does not define the EU AI Act Article 12 standard or automatically apply to an insurer’s underwriting logs.

Map the actual insurance, prudential, privacy and AI Act record requirements for each workflow. Tamper evidence may support integrity, but no single storage method establishes compliance across them.

Dec 2027
Relevant Annex III date
EUR 15M
Max Penalty (3% Revenue)
7
Articles to Comply With
50+
US State Regulators

In This Guide

Annex III Category Analysis: Essential Private Services

The EU AI Act classifies AI systems by risk level, with high-risk systems subject to the most stringent requirements. Insurance AI falls under Annex III, Category 5: Access to and enjoyment of essential private services and essential public services and benefits.

Specifically, Annex III point 5(c) covers:

AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Creditworthiness and its financial-fraud exception are a separate point 5(b).

The rationale is clear: insurance decisions can materially affect individuals’ access to essential services. Life and health insurance denial or unaffordable pricing can leave individuals without crucial financial protection during illness, disability, or death.

Why Life and Health Insurance Specifically?

The European Commission’s impact assessment identified life and health insurance as “essential private services” because:

Scope: What Counts as High-Risk Insurance AI

Understanding the precise scope of “risk assessment and pricing” is critical for classification. The regulation targets AI systems that make or materially influence decisions about individual insurance applicants.

Covered Activities

Activity High-Risk? Reasoning
Individual underwriting Yes Directly affects access to life/health insurance
Premium pricing for individuals Yes Unaffordable premiums effectively deny access
Risk scoring/classification Yes Foundational to underwriting and pricing decisions
Claims assessment (denial/approval) Not listed by itself Claims handling is not the same text as risk assessment and pricing; classify the actual function
Policy renewal decisions Depends on function Covered if the system performs life/health risk assessment or pricing; renewal alone is not the trigger
Fraud detection Not listed by 5(c) The express fraud exception belongs to creditworthiness point 5(b), not a general insurance carve-out

Key Determining Factors

Four factors determine whether insurance AI is high-risk:

1. Insurance Type

  • ! Life insurance: High-risk
  • ! Health insurance: High-risk
  • - Property/casualty: Not explicitly listed
  • - Commercial lines: Not explicitly listed

2. Subject of Decision

  • ! Natural persons (individuals): Covered
  • - Legal persons (companies): Not covered
  • - Group policies: Depends on individual impact

3. Decision Impact

  • ! Risk assessment or pricing: listed for natural persons in life/health
  • ! Pricing (material): High-risk
  • - Minor administrative: Likely not high-risk

4. AI System Role

  • ! Listed intended purpose: apply Article 6 analysis
  • ! Decision support (material): High-risk
  • ? Pure analytics/reporting: Gray area

When Insurance AI IS High-Risk

An insurance system is within the listed Annex III use when its intended purpose matches the criteria below. Providers must still apply Article 6, including any documented Article 6(3) assessment where relevant:

High-Risk Classification Applies When:

  • Life or health insurance risk assessment or pricing in relation to individual natural persons
  • AI system makes or materially influences the decision (not purely informational)
  • System is placed on EU market or used in EU (regardless of provider location)
  • A third-country provider or deployer is covered where the system’s output is used in the Union, subject to the Act’s scope and exclusions

Examples of high-risk insurance AI:

When Insurance AI May NOT Be High-Risk

Certain insurance AI applications may fall outside the high-risk classification:

Potential Exclusions from High-Risk:

  • Property and casualty insurance (auto, home, commercial) - not explicitly listed
  • Commercial/corporate insurance (legal persons, not natural persons)
  • Fraud detection systems — not listed by insurance point 5(c); the express fraud exception in 5(b) applies to creditworthiness systems
  • Internal analytics not affecting individual decisions (portfolio analysis, reserving)
  • Customer service chatbots providing general information (limited risk, transparency only)

Important caveat: Property and casualty systems can still fall within another Annex III use or an Annex I product pathway on their own facts. But Annex III is not a general “essential services” catchall, and point 5(c) should not be extended beyond its life-and-health wording without a legal basis.

Requirements If Classified as High-Risk (Articles 9-15)

High-risk insurance AI systems must comply with seven core requirements under Articles 9-15 before placement on the EU market:

9

Risk Management System

Continuous, iterative process throughout the AI system lifecycle. Identify and analyze known and foreseeable risks. Estimate and evaluate risks. Adopt risk mitigation measures. Test to ensure appropriate performance.

10

Data and Data Governance

Training, validation, and testing data must be relevant, representative, and free of errors. Examine data for biases. Ensure appropriate statistical properties for the intended purpose.

11

Technical Documentation

Comprehensive documentation per Annex IV covering system design, development, capabilities, limitations, and monitoring procedures. Must demonstrate conformity assessment compliance.

12

Record-Keeping (Logging)

Automatic event-logging capabilities over the system lifetime at a level appropriate to intended purpose. The system-specific design should support traceability and post-market monitoring; Article 12 does not itself prescribe a record for every insurance decision.

13

Transparency and Information

Instructions for use enabling deployers to understand system capabilities, limitations, and appropriate use. Clear information about AI involvement in decisions affecting individuals.

14

Human Oversight

Design systems for effective human oversight. Enable human intervention, including ability to override or reverse AI decisions. Prevent automation bias. Insurance: human review of adverse underwriting decisions.

15

Accuracy, Robustness, Cybersecurity

Achieve appropriate levels of accuracy, robustness, and cybersecurity. Resilient against errors, faults, and attempts at manipulation. Performance consistent across relevant conditions.

Article 12 Logging Requirements: GLACIS Core Relevance

Where an insurance system is classified as high-risk, Article 12 requires automatic event-logging capabilities appropriate to the system’s intended purpose. The required design is system-specific:

Article 12 Logging Requirements

  • Automatic recording of events relevant to identifying situations that may result in risks
  • Traceability of AI system functioning throughout its lifecycle
  • System-specific scope rather than a universal requirement to retain every input and output
  • Special minimum fields in Article 12(3) for covered biometric-identification systems, not all insurance AI
  • Retention for periods appropriate to intended purpose and applicable law

Insurance implications: Map the events and retention needed for each system, operator role, and applicable law. Do not assume Article 12 imposes the same input, output, model-version, and reviewer fields on every underwriting or claims workflow.

Traditional policy-administration systems may not preserve the operational context needed for later review. For a configured, in-scope path, GLACIS can preserve signed records of selected control events. Those records may support Article 12 traceability, but the Regulation does not prescribe cryptography and a GLACIS record does not by itself satisfy Article 12 or establish compliance.

Fairness and Discrimination Requirements

Insurance AI faces heightened scrutiny for discriminatory outcomes. The EU AI Act addresses this through multiple provisions:

Article 10: Data Governance

Training data must be “examined in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination.” For insurance, this means:

Intersection with Existing Law

The AI Act supplements, doesn’t replace, existing anti-discrimination frameworks:

US Regulatory Comparison

Unlike the EU’s comprehensive approach, US insurance AI regulation is fragmented across state insurance commissioners and lacks federal AI-specific legislation.

NAIC Model Bulletin (2023)

The National Association of Insurance Commissioners issued a Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It provides guidance but isn’t binding law:

Colorado SB21-169

Colorado’s law is the most comprehensive US state regulation, requiring insurers to:

Key Differences: EU vs. US

Aspect EU AI Act US (State-Level)
Approach Process-based requirements Outcome-based (no unfair discrimination)
Scope Life and health explicitly high-risk All lines, varying by state
Enforcement Centralized (EUR 15M penalties) State commissioners, varying penalties
Documentation Prescriptive (Annex IV) General governance requirements
Conformity Pre-market assessment required Post-deployment oversight

Implementation Checklist

For insurers with covered high-risk systems, use this checklist to track progress toward the applicable 2 December 2027 Annex III date or 2 August 2028 Annex I product-embedded date:

High-Risk Insurance AI Compliance Checklist

Phase 1: Assessment (Months 1-2)

  • Inventory all AI systems used in underwriting, pricing, and claims
  • Classify each system against Annex III criteria
  • Document intended purpose and deployment context
  • Identify affected natural persons (EU residents)

Phase 2: Gap Analysis (Months 2-3)

  • Assess current risk management processes against Article 9
  • Evaluate data governance and bias testing (Article 10)
  • Audit existing logging capabilities against Article 12
  • Review human oversight mechanisms (Article 14)

Phase 3: Implementation (Months 3-9)

  • Implement continuous risk management system
  • Deploy automated logging with tamper-evident records
  • Prepare technical documentation per Annex IV
  • Establish human oversight workflows for adverse decisions
  • Conduct bias testing and document results

Phase 4: Conformity (Months 9-12)

  • Complete internal conformity assessment
  • Prepare EU declaration of conformity
  • Establish post-market monitoring procedures
  • Train staff on compliance requirements

Frequently Asked Questions

Is insurance underwriting AI high-risk under the EU AI Act?

Annex III point 5(c) lists AI intended for risk assessment and pricing in relation to natural persons in life and health insurance. Underwriting systems performing that function can be high-risk, subject to Article 6. Other insurance lines and activities are not swept in merely because they are consequential.

What makes insurance AI high-risk under Annex III?

Point 5(c) specifically lists risk assessment and pricing for natural persons in life and health insurance. The exact intended purpose matters, and Article 6(3) can require a documented significance assessment; the Act does not create a general category for every insurance decision.

Is property and casualty insurance AI high-risk?

Property, casualty, auto, and commercial lines are not listed in point 5(c). Another Annex III use or Annex I product pathway could apply on its own facts, but importance alone does not extend the life-and-health wording.

What logging requirements apply to high-risk insurance AI?

Article 12 requires automatic event-logging capabilities over the high-risk system’s lifetime at a level appropriate to intended purpose. It does not prescribe one universal insurance field list; Article 12(3)’s specific minimum fields concern certain biometric-identification systems.

How does the EU AI Act compare to US insurance AI regulation?

The United States does not have one federal insurance-AI statute equivalent to the EU AI Act. Federal civil-rights, consumer-protection, privacy, and sector rules can still apply, while states regulate insurance through existing law, enacted AI or data rules, and regulator guidance. The NAIC Model Bulletin is a model adopted or adapted by participating jurisdictions, not a nationwide law. Colorado SB 21-169 and its implementing rules are one state-specific example. Map the actual jurisdictions and use cases rather than treating US requirements as purely outcomes-based.

When must insurance companies comply with EU AI Act high-risk requirements?

Covered high-risk AI systems must implement applicable requirements for risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity. Under the AI Omnibus, relevant Annex III high-risk obligations apply from December 2, 2027. Classification depends on the insurance use case and the Act’s scope.

What are the penalties for non-compliant insurance AI?

The AI Act provides administrative-fine ceilings for specified infringements, including up to EUR 15 million or 3% of worldwide annual turnover for certain operator obligations, subject to the Act’s rules and the facts of the case. Market-surveillance measures can also restrict or require corrective action for non-conforming systems. Obtain role- and jurisdiction-specific advice rather than treating the ceiling as an automatic penalty.

Scoped operational evidence for insurance-AI review

Glacis can preserve signed, scoped records from configured insurance-AI control paths. Those records may support logging, testing, and oversight evidence; they do not prove that controls work or establish compliance. Relevant Annex III duties apply from December 2, 2027 where the system is covered.

Talk to us

Related Guides