Skip to content
Named directly in Annex III, point 5(c)

Insurance pricing AI is high-risk
by name, not by interpretation

Most industries have to interpret whether Annex III covers them. Insurance doesn't. The EU AI Act explicitly lists AI used for "risk assessment and pricing in relation to natural persons in the case of life and health insurance." If that's your product, you have until December 2, 2027 — 484 days — to comply.

Which insurance AI is high-risk?

Annex III, point 5 covers AI affecting access to essential private services — and names life and health insurance specifically.

Life & health risk assessment

AI that evaluates individual risk profiles for life or health insurance — explicitly named in Annex III, point 5(c). This is not an interpretation; it's in the text.

Premium pricing for life & health

Systems that calculate or influence individual premiums for life and health policies, including telematics-style health scoring and wearable data models

Underwriting eligibility decisions

AI that decides or materially influences whether an applicant is offered life or health coverage at all, including automated decline rules

Creditworthiness in premium financing

If you assess creditworthiness for payment plans or premium financing, that's a separate Annex III trigger under point 5(b)

What's not high-risk in insurance?

The high-risk listing is narrower than most insurers assume — it covers life and health lines, not the whole industry.

Property & casualty pricing (Annex III 5(c) names only life and health insurance)
Motor insurance telematics for vehicle pricing (unless tied to health assessment)
Internal actuarial modeling and reserving with no individual-level decisions
Fraud analytics that flag claims for human review without restricting access
Customer service chatbots (limited risk — Article 50 transparency applies instead)

Even if your system is not high-risk, transparency obligations under Article 50 may still apply — especially for customer-facing chatbots and AI-generated communications. Run the free classifier to find out.

10 mandatory obligations for high-risk insurance AI

Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.

1
Risk management system (Article 9)
2
Data governance & bias documentation (Article 10)
3
Full Annex IV technical documentation
4
Automatic event logging (Article 12)
5
Transparency & instructions for deployers (Article 13)
6
Human oversight measures (Article 14)
7
Accuracy, robustness & cybersecurity (Article 15)
8
Conformity assessment (Article 43)
9
EU database registration (Article 49)
10
Post-market monitoring (Article 72)

Already regulated under Solvency II and GDPR?

Some work carries over — most doesn't

Insurers are used to heavy regulation, and existing model governance under Solvency II plus GDPR DPIAs will partially cover the AI Act's risk management (Article 9) and data governance (Article 10) requirements. But the AI Act adds obligations your actuarial governance doesn't touch: bias documentation across protected groups, conformity assessment, EU database registration, automatic logging, and instructions for use written for deployers. EIOPA has also signalled that AI Act supervision will run alongside — not replace — existing insurance supervision.

See the full GDPR overlap mapping →

484 days until enforcement

Insurance AI is named in the regulation itself — supervisors won't need to debate whether you're in scope. Classify your system now and start generating the compliance documentation you need.