AI Governance

The EIOPA opinion: a supervisory bridge between Solvency II and the EU AI Act

EIOPA's opinion clarifies how existing insurance law applies to AI systems and directs national supervisors toward a risk-based, proportionate approach rather than blanket restrictions.

By Jonas Osman AbdelghafourPublished August 6, 2025

Summary The European insurance supervisor's opinion on artificial intelligence governance and risk management clarifies how existing sectoral legislation applies to AI systems, directing national supervisors toward a risk-based and proportionate approach that weighs benefits against risks rather than imposing blanket restrictions.

Source: EIOPA · 6 August 2025 · read the original article

Why an opinion rather than new rules The opinion's premise is that Solvency II-era governance requirements already cover most of what AI oversight demands: a system of governance, fit and proper requirements, the own risk and solvency assessment, outsourcing rules and the actuarial function. AI does not create a governance vacuum; it stresses existing controls.

That framing has a practical consequence for insurers. The compliance response is to extend documented functions to AI use cases rather than to construct a parallel AI governance structure that sits outside the system of governance and is therefore harder to supervise.

Proportionality in practice A risk-based approach means the depth of control scales with the impact of the decision. In insurance, that maps cleanly onto a hierarchy: underwriting acceptance and pricing, claims decisioning, fraud detection and anti-money-laundering screening, distribution and marketing, and internal productivity tools.

The first three warrant full documentation, testing and human review evidence. The last two warrant use boundaries and monitoring. Applying identical control to all five is the most common design error and consumes the budget that the high-impact tier needs.

The bridge to the AI Act For European insurers the opinion is the supervisory document national regulators will reach for when reviewing AI use, and it sits between existing sectoral obligations and the EU AI Act's high-risk regime. The two are complementary: the AI Act sets product-style requirements for high-risk systems, while the sectoral framework governs how the undertaking is run.

A single control inventory should therefore be mapped to both, so that a system classified as high-risk under the AI Act also carries its ORSA, outsourcing and actuarial function linkages.

Methodology and limitations This summarises a published supervisory opinion as at the date shown and links to the original. Opinions guide national supervisory practice rather than creating directly binding obligations, and national implementation varies.

Related reading See [Insurance Risk](/expertise/insurance-risk), [Regulatory Compliance](/expertise/regulatory-compliance), [Corporate Governance](/expertise/corporate-governance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).

Frequently asked questions

Why an opinion rather than new rules?

The opinion's premise is that Solvency II-era governance requirements already cover most of what AI oversight demands: a system of governance, fit and proper requirements, the own risk and solvency assessment, outsourcing rules and the actuarial function. AI does not create a governance vacuum; it stresses existing controls.

What should risk leaders know about proportionality in practice?

A risk-based approach means the depth of control scales with the impact of the decision. In insurance, that maps cleanly onto a hierarchy: underwriting acceptance and pricing, claims decisioning, fraud detection and anti-money-laundering screening, distribution and marketing, and internal productivity tools.

What should risk leaders know about the bridge to the AI Act?

For European insurers the opinion is the supervisory document national regulators will reach for when reviewing AI use, and it sits between existing sectoral obligations and the EU AI Act's high-risk regime. The two are complementary: the AI Act sets product-style requirements for high-risk systems, while the sectoral framework governs how the undertaking is run.

What should risk leaders know about methodology and limitations?

This summarises a published supervisory opinion as at the date shown and links to the original. Opinions guide national supervisory practice rather than creating directly binding obligations, and national implementation varies.

What should risk leaders know about related reading?

See [Insurance Risk](/expertise/insurance-risk), [Regulatory Compliance](/expertise/regulatory-compliance), [Corporate Governance](/expertise/corporate-governance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).