Annex III Category Analysis: Essential Private Services
The EU AI Act classifies AI systems by risk level, with high-risk systems subject to the most stringent requirements. Insurance AI falls under Annex III, Category 5: Access to and enjoyment of essential private services and essential public services and benefits.
Specifically, Annex III point 5(c) covers:
AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Creditworthiness and its financial-fraud exception are a separate point 5(b).
The rationale is clear: insurance decisions can materially affect individuals’ access to essential services. Life and health insurance denial or unaffordable pricing can leave individuals without crucial financial protection during illness, disability, or death.
Why Life and Health Insurance Specifically?
The European Commission’s impact assessment identified life and health insurance as “essential private services” because:
- Fundamental rights impact: Denial of health insurance affects access to healthcare, a fundamental right under the EU Charter
- Asymmetric information: Insurers have sophisticated analytical capabilities; individuals cannot meaningfully contest AI-driven decisions
- Discrimination risk: AI systems trained on historical data may perpetuate or amplify discriminatory patterns
- Limited alternatives: Unlike property insurance, individuals cannot easily forgo life or health coverage
Scope: What Counts as High-Risk Insurance AI
Understanding the precise scope of “risk assessment and pricing” is critical for classification. The regulation targets AI systems that make or materially influence decisions about individual insurance applicants.
Covered Activities
| Activity | High-Risk? | Reasoning |
|---|---|---|
| Individual underwriting | Yes | Directly affects access to life/health insurance |
| Premium pricing for individuals | Yes | Unaffordable premiums effectively deny access |
| Risk scoring/classification | Yes | Foundational to underwriting and pricing decisions |
| Claims assessment (denial/approval) | Not listed by itself | Claims handling is not the same text as risk assessment and pricing; classify the actual function |
| Policy renewal decisions | Depends on function | Covered if the system performs life/health risk assessment or pricing; renewal alone is not the trigger |
| Fraud detection | Not listed by 5(c) | The express fraud exception belongs to creditworthiness point 5(b), not a general insurance carve-out |
Key Determining Factors
Four factors determine whether insurance AI is high-risk:
1. Insurance Type
- ! Life insurance: High-risk
- ! Health insurance: High-risk
- - Property/casualty: Not explicitly listed
- - Commercial lines: Not explicitly listed
2. Subject of Decision
- ! Natural persons (individuals): Covered
- - Legal persons (companies): Not covered
- - Group policies: Depends on individual impact
3. Decision Impact
- ! Risk assessment or pricing: listed for natural persons in life/health
- ! Pricing (material): High-risk
- - Minor administrative: Likely not high-risk
4. AI System Role
- ! Listed intended purpose: apply Article 6 analysis
- ! Decision support (material): High-risk
- ? Pure analytics/reporting: Gray area
When Insurance AI IS High-Risk
An insurance system is within the listed Annex III use when its intended purpose matches the criteria below. Providers must still apply Article 6, including any documented Article 6(3) assessment where relevant:
High-Risk Classification Applies When:
- Life or health insurance risk assessment or pricing in relation to individual natural persons
- AI system makes or materially influences the decision (not purely informational)
- System is placed on EU market or used in EU (regardless of provider location)
- A third-country provider or deployer is covered where the system’s output is used in the Union, subject to the Act’s scope and exclusions
Examples of high-risk insurance AI:
- ML model predicting mortality risk for life insurance applications
- Health insurance premium optimization algorithm using individual health data
- Underwriting model used to assess individual risk and set health-insurance pricing
- Risk-scoring system used to price a natural person’s life-insurance renewal
When Insurance AI May NOT Be High-Risk
Certain insurance AI applications may fall outside the high-risk classification:
Potential Exclusions from High-Risk:
- Property and casualty insurance (auto, home, commercial) - not explicitly listed
- Commercial/corporate insurance (legal persons, not natural persons)
- Fraud detection systems — not listed by insurance point 5(c); the express fraud exception in 5(b) applies to creditworthiness systems
- Internal analytics not affecting individual decisions (portfolio analysis, reserving)
- Customer service chatbots providing general information (limited risk, transparency only)
Important caveat: Property and casualty systems can still fall within another Annex III use or an Annex I product pathway on their own facts. But Annex III is not a general “essential services” catchall, and point 5(c) should not be extended beyond its life-and-health wording without a legal basis.
Requirements If Classified as High-Risk (Articles 9-15)
High-risk insurance AI systems must comply with seven core requirements under Articles 9-15 before placement on the EU market:
Risk Management System
Continuous, iterative process throughout the AI system lifecycle. Identify and analyze known and foreseeable risks. Estimate and evaluate risks. Adopt risk mitigation measures. Test to ensure appropriate performance.
Data and Data Governance
Training, validation, and testing data must be relevant, representative, and free of errors. Examine data for biases. Ensure appropriate statistical properties for the intended purpose.
Technical Documentation
Comprehensive documentation per Annex IV covering system design, development, capabilities, limitations, and monitoring procedures. Must demonstrate conformity assessment compliance.
Record-Keeping (Logging)
Automatic event-logging capabilities over the system lifetime at a level appropriate to intended purpose. The system-specific design should support traceability and post-market monitoring; Article 12 does not itself prescribe a record for every insurance decision.
Transparency and Information
Instructions for use enabling deployers to understand system capabilities, limitations, and appropriate use. Clear information about AI involvement in decisions affecting individuals.
Human Oversight
Design systems for effective human oversight. Enable human intervention, including ability to override or reverse AI decisions. Prevent automation bias. Insurance: human review of adverse underwriting decisions.
Accuracy, Robustness, Cybersecurity
Achieve appropriate levels of accuracy, robustness, and cybersecurity. Resilient against errors, faults, and attempts at manipulation. Performance consistent across relevant conditions.
Article 12 Logging Requirements: GLACIS Core Relevance
Where an insurance system is classified as high-risk, Article 12 requires automatic event-logging capabilities appropriate to the system’s intended purpose. The required design is system-specific:
Article 12 Logging Requirements
- Automatic recording of events relevant to identifying situations that may result in risks
- Traceability of AI system functioning throughout its lifecycle
- System-specific scope rather than a universal requirement to retain every input and output
- Special minimum fields in Article 12(3) for covered biometric-identification systems, not all insurance AI
- Retention for periods appropriate to intended purpose and applicable law
Insurance implications: Map the events and retention needed for each system, operator role, and applicable law. Do not assume Article 12 imposes the same input, output, model-version, and reviewer fields on every underwriting or claims workflow.
Traditional policy-administration systems may not preserve the operational context needed for later review. For a configured, in-scope path, GLACIS can preserve signed records of selected control events. Those records may support Article 12 traceability, but the Regulation does not prescribe cryptography and a GLACIS record does not by itself satisfy Article 12 or establish compliance.
Fairness and Discrimination Requirements
Insurance AI faces heightened scrutiny for discriminatory outcomes. The EU AI Act addresses this through multiple provisions:
Article 10: Data Governance
Training data must be “examined in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination.” For insurance, this means:
- Historical underwriting data may embed discriminatory patterns
- Proxy variables (ZIP code, occupation) may correlate with protected characteristics
- Insurers must document bias testing and mitigation measures
Intersection with Existing Law
The AI Act supplements, doesn’t replace, existing anti-discrimination frameworks:
- Gender Directive (2004/113/EC): Prohibits gender-based pricing in insurance (post-2012)
- Racial Equality Directive: Prohibits discrimination based on race or ethnic origin
- GDPR Article 22: Rights related to automated decision-making
US Regulatory Comparison
Unlike the EU’s comprehensive approach, US insurance AI regulation is fragmented across state insurance commissioners and lacks federal AI-specific legislation.
NAIC Model Bulletin (2023)
The National Association of Insurance Commissioners issued a Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It provides guidance but isn’t binding law:
- Insurers must establish AI governance frameworks
- AI outcomes must comply with existing unfair discrimination laws
- Transparency requirements for AI-driven decisions
- Human oversight of AI systems
Colorado SB21-169
Colorado’s law is the most comprehensive US state regulation, requiring insurers to:
- Test AI systems for unfair discrimination before deployment
- Document testing methodologies and results
- Submit governance reports to the Division of Insurance
Key Differences: EU vs. US
| Aspect | EU AI Act | US (State-Level) |
|---|---|---|
| Approach | Process-based requirements | Outcome-based (no unfair discrimination) |
| Scope | Life and health explicitly high-risk | All lines, varying by state |
| Enforcement | Centralized (EUR 15M penalties) | State commissioners, varying penalties |
| Documentation | Prescriptive (Annex IV) | General governance requirements |
| Conformity | Pre-market assessment required | Post-deployment oversight |
Implementation Checklist
For insurers with covered high-risk systems, use this checklist to track progress toward the applicable 2 December 2027 Annex III date or 2 August 2028 Annex I product-embedded date:
High-Risk Insurance AI Compliance Checklist
Phase 1: Assessment (Months 1-2)
- Inventory all AI systems used in underwriting, pricing, and claims
- Classify each system against Annex III criteria
- Document intended purpose and deployment context
- Identify affected natural persons (EU residents)
Phase 2: Gap Analysis (Months 2-3)
- Assess current risk management processes against Article 9
- Evaluate data governance and bias testing (Article 10)
- Audit existing logging capabilities against Article 12
- Review human oversight mechanisms (Article 14)
Phase 3: Implementation (Months 3-9)
- Implement continuous risk management system
- Deploy automated logging with tamper-evident records
- Prepare technical documentation per Annex IV
- Establish human oversight workflows for adverse decisions
- Conduct bias testing and document results
Phase 4: Conformity (Months 9-12)
- Complete internal conformity assessment
- Prepare EU declaration of conformity
- Establish post-market monitoring procedures
- Train staff on compliance requirements
Frequently Asked Questions
Is insurance underwriting AI high-risk under the EU AI Act?
Annex III point 5(c) lists AI intended for risk assessment and pricing in relation to natural persons in life and health insurance. Underwriting systems performing that function can be high-risk, subject to Article 6. Other insurance lines and activities are not swept in merely because they are consequential.
What makes insurance AI high-risk under Annex III?
Point 5(c) specifically lists risk assessment and pricing for natural persons in life and health insurance. The exact intended purpose matters, and Article 6(3) can require a documented significance assessment; the Act does not create a general category for every insurance decision.
Is property and casualty insurance AI high-risk?
Property, casualty, auto, and commercial lines are not listed in point 5(c). Another Annex III use or Annex I product pathway could apply on its own facts, but importance alone does not extend the life-and-health wording.
What logging requirements apply to high-risk insurance AI?
Article 12 requires automatic event-logging capabilities over the high-risk system’s lifetime at a level appropriate to intended purpose. It does not prescribe one universal insurance field list; Article 12(3)’s specific minimum fields concern certain biometric-identification systems.
How does the EU AI Act compare to US insurance AI regulation?
The United States does not have one federal insurance-AI statute equivalent to the EU AI Act. Federal civil-rights, consumer-protection, privacy, and sector rules can still apply, while states regulate insurance through existing law, enacted AI or data rules, and regulator guidance. The NAIC Model Bulletin is a model adopted or adapted by participating jurisdictions, not a nationwide law. Colorado SB 21-169 and its implementing rules are one state-specific example. Map the actual jurisdictions and use cases rather than treating US requirements as purely outcomes-based.
When must insurance companies comply with EU AI Act high-risk requirements?
Covered high-risk AI systems must implement applicable requirements for risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness, and cybersecurity. Under the AI Omnibus, relevant Annex III high-risk obligations apply from December 2, 2027. Classification depends on the insurance use case and the Act’s scope.
What are the penalties for non-compliant insurance AI?
The AI Act provides administrative-fine ceilings for specified infringements, including up to EUR 15 million or 3% of worldwide annual turnover for certain operator obligations, subject to the Act’s rules and the facts of the case. Market-surveillance measures can also restrict or require corrective action for non-conforming systems. Obtain role- and jurisdiction-specific advice rather than treating the ceiling as an automatic penalty.
