Annex III, point 5 covers AI affecting access to essential private services, and names life and health insurance specifically.
AI that evaluates individual risk profiles for life or health insurance, named directly in Annex III, point 5(c). This isn't an interpretation; it's in the text.
Systems that calculate or influence individual premiums for life and health policies, including telematics-style health scoring and wearable data models.
AI that decides or materially influences whether an applicant is offered life or health coverage, including automated decline rules.
If you assess creditworthiness for payment plans or premium financing, that's a separate Annex III trigger under point 5(b).
The high-risk listing is narrower than most insurers assume: it covers life and health lines, not the whole industry.
Even if your system isn't high-risk, Article 50 transparency may still apply, especially for customer-facing chatbots and AI-generated communications.
Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.
Insurers are used to heavy regulation, and existing model governance under Solvency II plus GDPR DPIAs will partially cover the AI Act's risk management (Article 9) and data governance (Article 10). But the AI Act adds what your actuarial governance doesn't touch: bias documentation across protected groups, conformity assessment, EU database registration, automatic logging, and instructions for deployers. EIOPA has signalled AI Act supervision will run alongside, not replace, existing insurance supervision.
See the full GDPR overlap mappingInsurance AI is named in the regulation itself, so supervisors won't debate whether you're in scope. The classifier is free; classify your system and start generating the documentation you need.
Classify your AI system