European insurers face two regulatory languages for the same technology. The EU AI Act speaks horizontally: risk categories, conformity, market surveillance, applied identically to a hiring tool and an underwriting engine. Insurance supervision speaks vertically: governance, proportionality, policyholder protection, embedded in decades of sectoral law. EIOPA's opinion on artificial intelligence governance and risk management, addressed to national supervisors, is the translation layer — it explains how existing insurance-sector legislation already applies to AI systems, and how supervisors should read the two regimes together.
The opinion's central choice is proportionality. Rather than blanket restrictions, EIOPA directs a risk-based approach that weighs an AI system's benefits against its risks — a deliberate echo of how insurance supervision has always treated models under Solvency II's governance requirements. For insurers, the message is subtle but liberating: you do not need a second, parallel compliance universe for AI. You need your existing governance system, extended honestly to a new class of model.
What "extended honestly" means in practice Three extensions carry most of the weight. First, scope: Solvency II-era model governance concentrated on capital and pricing models; EIOPA's framing pulls claims automation, customer interaction, and fraud systems — anything affecting policyholder outcomes — into governed territory. Second, proportionality with evidence: classifying a system as low-risk is a decision that must itself be documented and defensible, not a label applied to avoid work. Third, board literacy: risk-based supervision assumes someone at the top can actually weigh AI benefits against AI risks, which is a competence question before it is a compliance one.
The interplay with the AI Act is where preparation compounds. A life or health insurer whose pricing system is high-risk under the Act will answer to market-surveillance authorities and its insurance supervisor. Where the two regimes ask overlapping questions — data governance, human oversight, documentation — an insurer that built one coherent control set answers both from the same evidence. An insurer that built two parallel programs answers each badly.
The supervisory dialogue ahead National supervisors will implement the opinion unevenly at first; that is the nature of an EU of twenty-seven markets. Insurers operating cross-border should not wait for convergence — build to the most demanding plausible reading, and treat early supervisory conversations as an opportunity to shape expectations rather than absorb them. Bring your AI inventory, your risk classifications, and your testing evidence to the meeting before being asked.
The insurers that internalize EIOPA's framing — AI governance as ordinary governance, done properly, on new material — will find the AI Act era continuous with what they already do well. Those that treat it as an alien regime will build the parallel universe, pay for it twice, and defend it with difficulty.
Related reading - [The EU AI Act's August 2026 milestone](/insights/eu-ai-act-august-2026-banks-insurers-jonas-osman-abdelghafour) - [Data governance before AI governance](/insights/data-governance-before-ai-governance-insurance-jonas-osman-abdelghafour) - [From principle to proof: bias testing in AI underwriting and claims](/insights/ai-bias-testing-underwriting-claims-jonas-osman-abdelghafour)
See also Insurance Risk, Regulatory Compliance and Corporate Governance.
About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.
Frequently asked questions
What "extended honestly" means in practice?
Three extensions carry most of the weight. First, scope: Solvency II-era model governance concentrated on capital and pricing models; EIOPA's framing pulls claims automation, customer interaction, and fraud systems — anything affecting policyholder outcomes — into governed territory. Second, proportionality with evidence: classifying a system as low-risk is a decision that must itself be documented and defensible, not a label applied to avoid work. Third, board literacy: risk-based supervisio...
What should risk leaders know about the supervisory dialogue ahead?
National supervisors will implement the opinion unevenly at first; that is the nature of an EU of twenty-seven markets. Insurers operating cross-border should not wait for convergence — build to the most demanding plausible reading, and treat early supervisory conversations as an opportunity to shape expectations rather than absorb them. Bring your AI inventory, your risk classifications, and your testing evidence to the meeting before being asked.
What should risk leaders know about related reading?
See also [Insurance Risk](/expertise/insurance-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and [Corporate Governance](/expertise/corporate-governance).
What should risk leaders know about about the author?
Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.