Insurance AI Under the EU AI Act
Insurance is heavily AI-dependent: underwriting, pricing, claims handling, fraud detection, and customer service all use machine learning. Under the EU AI Act, AI systems used for life and health insurance underwriting are classified as high-risk (Annex III, Category 5(a)). This means conformity assessment, technical documentation, human oversight, and bias testing — on top of existing Solvency II and IDD requirements.
High-Risk Insurance AI Systems
Explicitly High-Risk
- Life insurance underwriting: AI assessing mortality risk, health status, lifestyle factors to determine premiums and coverage
- Health insurance underwriting: AI evaluating health risks for pricing and acceptance decisions
- Risk classification: Models that segment customers into risk categories affecting premium levels
Likely High-Risk (Case-by-Case)
- Claims automation: AI that approves or denies claims with significant financial impact on policyholders
- Fraud detection: AI flagging claims as potentially fraudulent — false positives can delay legitimate claims
- Property/casualty pricing: If AI pricing decisions significantly affect access to insurance (e.g., excluding high-risk areas)
Key Compliance Requirements
Bias & Discrimination
Insurance pricing inherently discriminates by risk — that's the business model. The EU AI Act requires that discrimination is actuarially justified and not based on protected characteristics:
- Gender: Already prohibited in EU insurance pricing (ECJ Test-Achats ruling, 2012). AI models must not use gender as a feature or proxy.
- Race/ethnicity: Proxy variables (postcode, language, name) must be tested for indirect discrimination
- Disability/health status: For non-life insurance, health data usage is restricted. For health/life, it must be actuarially relevant.
- Testing approach: Fairness metrics across protected groups. Equalised odds, demographic parity, or calibration — choose metrics appropriate to the insurance context.
Human Oversight in Claims
- Claims above threshold: Define value thresholds above which human review is mandatory
- Denial decisions: All claim denials should involve human review — AI can recommend denial, human confirms
- Fraud investigation: AI flags suspicious claims; trained investigators make the determination
- Appeal process: Policyholders must have access to human review of AI-influenced decisions
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Solvency II Interaction
Insurance AI governance must satisfy both the EU AI Act and Solvency II:
- ORSA: Own Risk and Solvency Assessment must now include AI model risk
- Actuarial function: Must validate AI pricing models — actuarial sign-off on AI-driven premiums
- Outsourcing: AI models from third parties (InsurTech vendors) must comply with Solvency II outsourcing requirements AND EU AI Act provider obligations
- Data governance: Solvency II data quality requirements apply to AI training data
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton