Money and essential services
Life and health insurance
Core judgement
The AI Act regulates rather than prohibits AI underwriting. Its high-risk list covers risk assessment and pricing concerning individuals in life and health insurance. This includes an AI-produced premium as well as acceptance, refusal or risk classification.1 The main high-risk duties for this category begin on 2 December 2027 following an enacted amendment.2
The category is not a general rule for every kind of insurance. Motor, homeowners’, professional-liability and disability insurance are not expressly listed. A 2026 Commission review described that omission as a possible regulatory gap but did not extend the list.3 From December 2027, Article 6(3) will also allow a provider to classify a narrow or preparatory tool as non-high-risk if it does not materially influence the result. Profiling systems remain high-risk, and the market-surveillance authority can review the provider’s classification.1
From 2 August 2026, Article 86 applies on paper: the insurer or other deployer must explain AI’s role and the main elements of a legally or similarly significantly adverse individual decision based on an Annex III high-risk system.1 Whether deferred Article 6 classification limits operation before 2 December 2027 remains unsettled; no guidance or ruling resolves this.1 Since 2 August 2026, Article 85 has permitted a complaint concerning Article 86 to the relevant market-surveillance authority, normally the national financial supervisor for regulated insurers.1 Article 86 does not apply when EU law provides an equivalent explanation right.
The GDPR may offer the more practical current safeguard. Since 25 May 2018, Article 22 has restricted legally or similarly significant insurance decisions based solely on automated processing of personal data. The insurer or other controller bears that duty, while data-protection authorities and courts enforce it.4 Contract-based or consent-based decisions require the controller to provide human intervention, an opportunity to express a view and a way to contest. If health data are used, Articles 9 and 22 impose narrower conditions and suitable safeguards, enforced by the same authorities since that date.5
From 2 December 2027, Article 26 requires the life or health insurer deploying a high-risk system to tell the person that AI is making or assisting the decision and to assign competent, authorised human oversight. Article 27 requires that deployer to assess fundamental-rights effects before first use and notify the authority. Articles 10 and 16 require the provider to examine bias and use relevant, sufficiently representative data. The market-surveillance authority, normally the financial supervisor, enforces these duties.1
Boundary. These operator duties do not create an entitlement to a particular policy or premium. Article 86 sets no request format, response deadline or appeal route, and national insurance-supervisor complaint procedures were not mapped. No final guidance supplied here settles how wellness scores, usage-based policies or support tools fit the high-risk boundary.
References
Quizzes
Which insurance use is expressly listed in this AI Act high-risk category?
- Life and health risk assessment or pricing
- Every personal insurance product and premium
- Only claims handling after insured losses
The high-risk list specifically names risk assessment and pricing for life and health insurance, not every insurance line.
A significant insurance decision based solely on automated processing may already engage ____.
- GDPR safeguards for automated personal-data decisions
- future AI Act impact-assessment duties
- the exclusion for non-life insurance
For personal-data based significant automation, the GDPR supplies current safeguards; the main AI Act operator duties start later.
Comments
No comments yet. Start the conversation.