Most industries have to interpret whether Annex III covers them. Insurance doesn't. The EU AI Act explicitly lists AI used for "risk assessment and pricing in relation to natural persons in the case of life and health insurance." If that's your product, you have until December 2, 2027 — 484 days — to comply.
Annex III, point 5 covers AI affecting access to essential private services — and names life and health insurance specifically.
AI that evaluates individual risk profiles for life or health insurance — explicitly named in Annex III, point 5(c). This is not an interpretation; it's in the text.
Systems that calculate or influence individual premiums for life and health policies, including telematics-style health scoring and wearable data models
AI that decides or materially influences whether an applicant is offered life or health coverage at all, including automated decline rules
If you assess creditworthiness for payment plans or premium financing, that's a separate Annex III trigger under point 5(b)
The high-risk listing is narrower than most insurers assume — it covers life and health lines, not the whole industry.
Even if your system is not high-risk, transparency obligations under Article 50 may still apply — especially for customer-facing chatbots and AI-generated communications. Run the free classifier to find out.
Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.
Some work carries over — most doesn't
Insurers are used to heavy regulation, and existing model governance under Solvency II plus GDPR DPIAs will partially cover the AI Act's risk management (Article 9) and data governance (Article 10) requirements. But the AI Act adds obligations your actuarial governance doesn't touch: bias documentation across protected groups, conformity assessment, EU database registration, automatic logging, and instructions for use written for deployers. EIOPA has also signalled that AI Act supervision will run alongside — not replace — existing insurance supervision.
See the full GDPR overlap mapping →