Using AI in underwriting decisions is legal under the EU AI Act, but life and health insurance underwriting and pricing are explicitly classified as high risk AI systems under Annex III, which means using AI there is permitted only if the insurer meets a specific set of obligations rather than deploying freely. Those obligations include a documented risk management system, data governance covering the quality and representativeness of training data, technical documentation and logging sufficient to reconstruct how a decision was made, mechanisms for meaningful human oversight, and a conformity assessment before the system goes into production. The Act entered into force on 1 August 2024, obligations for general purpose AI models started on 2 August 2025, and most high risk system obligations, including those covering insurance underwriting, apply from 2 August 2026, so insurers currently building or deploying these systems should treat that date as a hard compliance deadline rather than a distant one. Non-life underwriting is not automatically high risk in the same way, though pricing practices are still subject to general non-discrimination and consumer protection law. Nanobase AI designs underwriting AI systems with EU AI Act documentation and human oversight requirements built in from the start rather than retrofitted before the deadline.
The deadline is closer than the compliance work usually is
Insurers building or already running AI underwriting systems tend to treat 2 August 2026 as a distant regulatory date rather than an active project deadline, which is a risky assumption given how much documentation and process work the obligations actually require. The EU AI Act's high-risk obligations for insurance underwriting apply from 2 August 2026, and the gap between "we have a working model" and "we have a conformity-assessed, documented, human-overseen system" is usually larger than teams expect until they run the assessment.
What's actually classified as high-risk
Life and health insurance underwriting and pricing are explicitly classified as high-risk AI systems under Annex III of the Act. Non-life underwriting is not automatically high-risk in the same way, though pricing practices there remain subject to general non-discrimination and consumer protection law regardless of the AI Act's specific classification, so a P&C insurer isn't exempt from scrutiny, just from this particular high-risk category.
Obligations mapped to deliverables
| Obligation | What it requires in practice | Typical owner |
|---|---|---|
| Risk management system | Documented process identifying and mitigating risks across the model's lifecycle | Model risk or compliance team |
| Data governance | Evidence of training data quality and representativeness | Data science team with compliance sign-off |
| Technical documentation and logging | Sufficient detail to reconstruct how a specific decision was made | Engineering team |
| Human oversight | A defined mechanism for a human to review or override automated decisions | Underwriting operations |
| Conformity assessment | Formal assessment confirming the system meets Act requirements before production use | Compliance, often with external assessment support |
Logging is the obligation most teams underestimate: it's not enough to log the final decision, the system needs to log enough detail to reconstruct the reasoning behind a specific automated decision months later if a regulator or an applicant challenges it.
A gap-assessment sequence
- Inventory every AI system touching underwriting or pricing decisions, including ones built years ago that predate any formal AI governance process.
- Classify each system against Annex III to confirm which ones fall under the high-risk category for your specific lines of business.
- Assess current state against each of the five obligations above, documenting what exists and what's missing for each system.
- Prioritize remediation by system risk and by how close the gap is to the 2 August 2026 deadline, not by which fix is easiest.
- Build the conformity assessment into the remediation plan as a distinct final step, not an afterthought once everything else is "done."
Timeline context
The Act entered into force on 1 August 2024, obligations for general-purpose AI models started on 2 August 2025, and most high-risk system obligations, including those covering insurance underwriting, apply from 2 August 2026. Treat that date as a hard compliance deadline for any system already classified as high-risk, since retrofitting documentation and oversight mechanisms after the deadline is materially harder than building them into a system already in development.
Frequently asked questions
Does this apply to AI vendors we buy from, or only systems we build ourselves?
Both; if a purchased or licensed system performs high-risk underwriting functions, the deploying insurer generally still carries obligations around use, oversight, and monitoring, and should confirm the vendor's own conformity documentation covers the relevant requirements.
Is a rules-based scoring system also in scope, or only machine learning models?
The Act's definitions focus on AI systems broadly, so this depends on the specific technical characteristics of the system rather than whether it's labeled "AI" internally; a legal or compliance review of borderline systems is worth doing rather than assuming a rules engine is automatically excluded.
What happens if we're not ready by the deadline?
Non-compliance exposure varies, but the more immediate operational risk is having to pause or roll back a production underwriting system that isn't conformity-assessed, which is more disruptive than starting the gap assessment now.
Does non-life pricing need any of this documentation?
Not under the high-risk classification specifically, but general non-discrimination and consumer protection obligations still apply, so bias testing and documentation remain good practice even without the Annex III trigger.
How Nanobase AI helps
Nanobase AI designs underwriting AI systems with EU AI Act documentation, logging, and human oversight requirements built in from the start rather than retrofitted before the deadline. This pairs closely with how insurers avoid bias and discrimination in underwriting models, and see our EU AI Act, GDPR, and KVKK compliance checklist for the broader compliance picture.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.