EU AI Act for insurance
Point 5(c) is unusually precise about which lines it covers: risk assessment and pricing in relation to natural persons in life and health insurance. Motor, property, travel and commercial lines are not named. That precision is worth understanding before an insurer classifies its whole book as high-risk.
What is in scope, and what is not
| Detail | |
|---|---|
| Named in point 5(c) | Risk assessment and pricing for natural persons in life and health insurance, underwriting models, risk scoring, individual premium setting |
| Not named in point 5(c) | Motor, property, travel, pet, liability and commercial lines. Claims handling, fraud detection, reserving and reinsurance analytics are also not within 5(c) |
| Caught elsewhere | Claims chatbots and generative correspondence — Article 50, live now. Health-data-driven products may engage biometric or emotion-recognition points. Distribution AI evaluating creditworthiness for premium finance engages point 5(b) |
Expert analysis. Classification turns on the intended purpose of each system. This is our reading of common deployments, not an authoritative classification.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Not named does not mean unregulated
Motor pricing is outside point 5(c) as drafted. It is not outside the law. Insurance conduct rules, national rules on the use of data in pricing, and equality law apply whether or not the AI Act classifies the system as high-risk. A motor pricing model producing discriminatory outcomes is a problem under Union equality law with no AI Act classification needed.
Two further cautions. Article 7 empowers the Commission to amend Annex III by delegated act, so today’s line is not permanent. And a system does not need to be high-risk to be caught by Article 50, which is live now and applies to any customer-facing conversational or generative feature.
Practical recommendation. Classify per system and document the reasoning, including for the lines you conclude are outside 5(c). An undocumented “motor is not covered” is a conclusion; a documented one is a position.
What runs alongside
- Article 27 FRIA is mandatory for deployers of point 5(c) systems, regardless of whether the deployer is a public body. Performed before first use, with results notified to the market surveillance authority.
- Insurance Distribution Directive conduct obligations, including product oversight and governance, apply to the products these systems price.
- Solvency II governance and model validation practice give you a substantial part of the Article 9 and Article 15 evidence base, though oriented to risk to the undertaking rather than to people.
- National health data rules. Several member states impose specific conditions on the use of health and genetic data in underwriting that operate independently of both the AI Act and the GDPR.
What applies before December 2027
Article 50 applies now to claims chatbots, quote assistants and AI-generated customer correspondence. Article 4 literacy applies to underwriters and claims handlers as deployers.
The deferral in Regulation (EU) 2026/1744 covers Chapter III Sections 1 to 3. It does not cover Article 5, Article 4, Chapter V general-purpose AI, Article 49 registration or Article 50 transparency. Full timeline →
Status labels on this page
Verified fact: The Annex III points, article references and dates cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The in-scope/out-of-scope allocation, the sector edge case, and the parallel-regulation reading.
Unsettled: Harmonised standards remain in development and the Commission's Annex III guidelines are in draft. Sector supervisory practice has not yet formed.
Document the lines you conclude are outside
The valuable artefact is not the classification of the systems that obviously qualify. It is the reasoned, dated record for the ones you decided were not covered.
Classify before you build
Twelve questions mapping your system against Articles 5, 6, 50 and Annex III. No email required.
Frequently asked
Is insurance AI high-risk under the EU AI Act?
Annex III point 5(c) names AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Those are high-risk. Motor, property, travel and commercial lines are not named in point 5(c), though AI in those lines may be caught by other provisions such as Article 50 transparency, and remains subject to insurance conduct rules and equality law.
Do insurers have to do a fundamental rights impact assessment?
Deployers of high-risk AI systems listed in Annex III point 5(c), covering risk assessment and pricing in life and health insurance, owe an Article 27 fundamental rights impact assessment before first use, regardless of whether the deployer is a public body, and must notify the market surveillance authority of the results.
Is claims fraud detection high-risk?
Fraud detection is not named in point 5(c), which covers risk assessment and pricing. The separate exclusion in point 5(b) for AI used for the purpose of detecting financial fraud relates to creditworthiness assessment. A fraud detection system should be classified on its own intended purpose against the whole of Annex III rather than assumed to be outside.