AI Governance

The EU AI Act for insurers: what it means for pricing, underwriting and model governance

Life and health pricing AI is named high-risk under Annex III. What the deferred timeline changes, and how to fold AI Act duties into model risk management.

By Jonas Osman AbdelghafourPublished 3 August 2026

The EU AI Act is the world's first comprehensive law regulating artificial intelligence, and the EU AI Act for insurers is not a distant abstraction: AI systems used for risk assessment and pricing in life and health insurance are explicitly named as high-risk under Annex III. For actuaries and risk teams, that puts the machinery of modern insurance — pricing engines, underwriting triage, claims models — inside a regulatory perimeter that looks a lot like prudential model governance, but with its own conformity assessments, documentation duties, and penalties. Here is what matters, what has changed recently, and how to prepare without over-engineering.

The risk-based architecture, in plain terms

The AI Act does not regulate "AI" as a monolith. It sorts systems into tiers. Prohibited practices — social scoring, manipulative techniques, certain biometric uses — are banned outright and have been since February 2025. General-purpose AI models (the foundation models behind chatbots and copilots) carry transparency obligations that took effect in August 2025. Then comes the tier that matters most for insurance: high-risk systems, which face the full compliance regime — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements, and registration.

Annex III lists the use cases deemed high-risk. Alongside employment, credit scoring, and education, it includes AI systems used for risk assessment and pricing in relation to life and health insurance. Note the scope carefully: the designation targets life and health business specifically. A motor pricing GLM is not automatically high-risk under Annex III — though credit-based scores, employment screening, and other listed uses can still pull adjacent systems into scope, and national regulators and EIOPA expect sound AI governance across all lines regardless.

The timeline just moved — but don't relax

The original schedule made high-risk obligations for Annex III systems applicable from 2 August 2026. That deadline has shifted: under the EU's "Digital Omnibus" simplification package, provisionally agreed in spring 2026, the compliance date for Annex III high-risk systems is deferred to late 2027, partly to give the Commission time to finish standards and guidance. Insurers should treat this as breathing room, not a reprieve, for three reasons.

First, deadlines that move once can move again — in either direction — and conformity work for a complex pricing system realistically takes eighteen months or more. Second, the prohibitions and GPAI transparency rules are already live, so any insurer deploying generative AI in customer-facing processes has current obligations today. Third, supervisors are not waiting for the AI Act to bite: EIOPA's 2025 opinion on AI governance and risk management made clear that existing directives — Solvency II's system-of-governance requirements and the IDD's product oversight rules — already require proportionate AI governance.

What compliance actually requires of a high-risk system

Strip away the legal drafting and the high-risk obligations map onto disciplines actuaries already know, with extensions. A risk management system must run across the AI lifecycle — identification, evaluation, mitigation — which is familiar territory for anyone operating a model risk management framework. Data governance requirements demand that training, validation and test data be relevant, representative, and examined for biases; for insurers this connects directly to ongoing debates about proxy discrimination in rating variables. Technical documentation and logging must be sufficient for a regulator to reconstruct how the system works and what it did — think model documentation standards, but enforceable. Human oversight means a person with authority and competence can intervene, override, or shut down the system. And accuracy and robustness obligations require declared performance metrics and resilience to errors and adversarial manipulation.

The penalties give these teeth: fines for non-compliance with high-risk obligations can reach €15 million or 3% of global turnover, and up to €35 million or 7% for prohibited practices.

The strategic questions for actuarial and risk functions

The compliance checklist is the easy part to describe. The harder questions are organizational. Who owns AI inventory? Most insurers cannot yet produce a complete register of models and AI systems with a use-case classification — yet scoping is the first step of any AI Act program, because obligations attach to specific systems, not to the company. Where does AI governance sit relative to model risk management? Building a parallel AI governance function alongside an existing MRM framework duplicates effort; the pragmatic route is to extend MRM with the AI Act's specific artefacts (conformity documentation, registration, fundamental-rights considerations). And what about vendors? Many insurers deploy AI bought, not built. The Act distinguishes providers from deployers, but deployers of high-risk systems still carry oversight, monitoring, and data-quality duties they cannot contract away.

There is also an underappreciated actuarial angle: the AI Act's fairness and data-governance expectations will interact with pricing sophistication. Techniques that improve predictive power — GBMs, external data enrichment — increase documentation and bias-testing burdens. The cost-benefit calculus of model complexity now includes a regulatory term, and actuaries are well placed to quantify it.

The takeaway

The EU AI Act turns AI governance from good practice into hard law, and it names life and health insurance pricing among its high-risk use cases. The recent deferral of Annex III deadlines to late 2027 buys time, but the prohibitions are already in force, supervisors already expect AI governance under existing rules, and the build-out — inventory, classification, extended model risk management, vendor due diligence — is measured in years, not months. Insurers that treat the AI Act as an extension of actuarial model governance, rather than a bolt-on legal project, will comply at lower cost and end up with better models.

Related reading

See also Model Risk and Insurance Risk.

About the author

Jonas Osman Abdelghafour is an actuary and risk expert who advises insurers, reinsurers and pension funds on reserving, capital, underwriting governance, financial-crime exposure and enterprise risk management. His work sits at the intersection of quantitative actuarial practice and the governance, risk and compliance (GRC) frameworks that regulators now expect boards to evidence. See qualifications and expertise for background, or get in touch to discuss a consulting engagement.

Frequently asked questions

What should risk leaders know about the risk-based architecture, in plain terms?

The AI Act does not regulate "AI" as a monolith. It sorts systems into tiers. Prohibited practices — social scoring, manipulative techniques, certain biometric uses — are banned outright and have been since February 2025. General-purpose AI models (the foundation models behind chatbots and copilots) carry transparency obligations that took effect in August 2025. Then comes the tier that matters most for insurance: **high-risk systems**, which face the full compliance regime — risk management,...

What should risk leaders know about the timeline just moved — but don't relax?

The original schedule made high-risk obligations for Annex III systems applicable from 2 August 2026. That deadline has shifted: under the EU's "Digital Omnibus" simplification package, provisionally agreed in spring 2026, the compliance date for Annex III high-risk systems is deferred to late 2027, partly to give the Commission time to finish standards and guidance. Insurers should treat this as breathing room, not a reprieve, for three reasons.

What compliance actually requires of a high-risk system?

Strip away the legal drafting and the high-risk obligations map onto disciplines actuaries already know, with extensions. A **risk management system** must run across the AI lifecycle — identification, evaluation, mitigation — which is familiar territory for anyone operating a model risk management framework. **Data governance** requirements demand that training, validation and test data be relevant, representative, and examined for biases; for insurers this connects directly to ongoing debat...

What should risk leaders know about the strategic questions for actuarial and risk functions?

The compliance checklist is the easy part to describe. The harder questions are organizational. Who owns AI inventory? Most insurers cannot yet produce a complete register of models and AI systems with a use-case classification — yet scoping is the first step of any AI Act program, because obligations attach to specific systems, not to the company. Where does AI governance sit relative to model risk management? Building a parallel AI governance function alongside an existing MRM framework dup...

What should risk leaders know about the takeaway?

The EU AI Act turns AI governance from good practice into hard law, and it names life and health insurance pricing among its high-risk use cases. The recent deferral of Annex III deadlines to late 2027 buys time, but the prohibitions are already in force, supervisors already expect AI governance under existing rules, and the build-out — inventory, classification, extended model risk management, vendor due diligence — is measured in years, not months. Insurers that treat the AI Act as an exten...