EU AI Act · use case
EU AI Act for Insurance Pricing and Underwriting AI: What Is High-Risk
AI for risk assessment and pricing in life and health insurance is high-risk under the EU AI Act. Where motor, home and claims AI stand, and what insurers must document.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
Depends on use
High-risk for life and health insurance (Annex III, point 5(c)); other lines usually minimal
When it applies
High-risk obligations apply from 2 December 2027.
Regulation (EU) 2024/1689, Annex III(5)(c); Art. 5 prohibitions; Art. 27
The EU AI Act is specific about insurance: AI used for risk assessment and pricing of natural persons in life and health insurance is high-risk. Motor, home, travel and other non-life lines are not listed, so pricing AI there is generally minimal-risk under the AI Act itself, although sectoral rules on fairness and the GDPR still apply.
This page is for insurers, insurtech underwriting platforms, and vendors of pricing or health-risk models. It also covers claims automation, where the classification depends on what the system decides.
Classification
Why this classification applies
Annex III, point 5(c) lists “AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance”. The recitals explain that these lines determine access to essential services and that errors can lead to financial exclusion and discrimination.
A model that sets premiums for a health plan, prices a term-life policy, or scores an applicant’s medical questionnaire is squarely in scope. A model that only detects duplicate claims in motor insurance is not on the list and would typically be minimal-risk, unless it profiles individuals in a way that triggers another Annex III point.
Two Article 5 prohibitions can bite in insurance: exploiting vulnerabilities (for example age or disability) to materially distort behaviour, and social-scoring practices that lead to detrimental treatment unrelated to the context in which the data was generated. Using lifestyle data from unrelated apps to penalise applicants is the kind of practice regulators have in mind.
Obligations
What you have to do
- For life and health pricing models: the full high-risk set (risk management, data governance, technical documentation, logging, human oversight, accuracy, conformity assessment, CE marking, EU database registration).
- Fundamental rights impact assessment before deployment by insurers, which can be integrated with the DPIA (Art. 27).
- Human oversight for underwriters with the ability to see risk factors and override the price or decision (Art. 14).
- Right to explanation for applicants subject to a high-risk decision (Art. 86).
- For all lines: no prohibited practices, AI literacy for staff (Art. 4), and Art. 50 transparency if customers interact with a chatbot or receive AI-generated communications.
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Assuming “insurance” as a whole is high-risk, or conversely that none of it is. The line is life and health.
- Health-risk scores used in group or travel policies. If the score assesses a natural person’s health risk for pricing, it is in scope regardless of the product label.
- Using wearables or app data as pricing inputs without checking the social-scoring prohibition and the GDPR special-category rules.
- No classification record for non-life models. Supervisors will ask why a model was treated as minimal-risk; the answer needs to be on paper.
FAQ
Frequently asked questions
Is motor insurance telematics pricing high-risk?
Not under Annex III(5)(c), which is limited to life and health insurance. Telematics pricing still has to comply with GDPR, sectoral conduct rules and the Art. 5 prohibitions, and the classification should be documented.
What about claims-handling AI?
Claims triage and fraud detection in insurance are not listed in Annex III. However, an AI system that decides whether a health-insurance claim is paid can, depending on design, be viewed as affecting access to essential services; obtain a documented legal view.
We use a vendor’s pricing engine. Who does the conformity assessment?
The vendor is the provider and must complete it before placing the system on the market. The insurer, as deployer, must use it as instructed, provide human oversight, keep logs and complete the fundamental rights impact assessment.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.