Insurance was built on the concept of risk assessment — and AI has transformed how that assessment is done. Machine learning models now drive underwriting decisions, claims processing, fraud detection, and customer pricing across major insurers globally. The EU AI Act treats many of these applications as high-risk, placing significant compliance obligations on insurers operating in the EU market.
What the EU AI Act Means for Insurance
The EU AI Act's Annex III explicitly includes AI systems used to evaluate creditworthiness and credit scoring — which encompasses many insurance risk scoring applications. Beyond Annex III, AI systems used in employment decisions, access to essential services, and systems affecting fundamental rights may also fall within high-risk classifications depending on their specific use. Insurers should not assume that only explicitly listed use cases are captured — the Act's broad principles apply to any AI system whose failure could have significant adverse impact on individuals.
Additionally, the European Insurance and Occupational Pensions Authority (EIOPA) published its Guidelines on Artificial Intelligence Governance and Risk Management in 2023, providing sector-specific AI governance expectations that complement and reinforce the EU AI Act for EU-authorised insurers.
Underwriting AI: The Compliance Priority
Underwriting AI — systems that assess risk and determine premiums — sits at the intersection of actuarial science, data analytics, and regulatory exposure. For the EU AI Act, the critical questions are: Is the underwriting AI system making decisions, or informing decisions made by humans? What populations does it affect? What is the potential harm of an incorrect assessment?
Where underwriting AI makes or significantly influences coverage decisions or premium calculations for individuals, high-risk classification is highly likely. This triggers the full suite of EU AI Act technical requirements: risk management documentation, data governance for training data, automatic decision logging, explainability for affected individuals, and human oversight mechanisms. The explainability requirement is particularly challenging for complex machine learning models used in underwriting — insurers should audit their AI portfolio now to identify where explainability gaps exist.
Claims Processing AI
AI systems used in claims processing — fraud detection, damage assessment, settlement recommendation — carry varying risk profiles. Fraud detection AI that flags claims for investigation generally requires human review of flagged cases, making the human oversight question central. AI systems that directly approve or deny claims without human review face more stringent obligations and, in some member state implementations, may trigger GDPR Article 22 individual rights regarding solely automated decisions.
Audit Trail Requirements for Insurance AI
The EU AI Act's Article 12 automatic logging requirements are directly applicable to insurance AI used in risk assessment and claims. For a typical insurer, this means implementing logging that captures: the input variables used for each underwriting or claims assessment, the model output and any risk scores, the policy terms or claims outcome flowing from the assessment, any human review or override applied, and sufficient metadata to reconstruct the full decision chain years after the fact.
Insurance decisions have long liability tails. A policy issued on the basis of an AI risk assessment today may be subject to dispute or regulatory scrutiny years or even decades hence. Audit trail retention must reflect these timeframes — and the logs must be tamper-evident to constitute valid evidence in those future disputes.
EIOPA Guidelines and the AI Act
EIOPA's 2023 AI governance guidelines emphasise algorithmic accountability, data quality, and human oversight in terms that closely mirror the EU AI Act's requirements. Insurers who have already responded to EIOPA guidance are ahead of the curve for EU AI Act compliance, but should audit the specific technical requirements — particularly around automatic logging and audit trail tamper-evidence — where EIOPA's guidance is less prescriptive than the Act itself.