Skip to content
What the EU's AI Regulations Mean for Insurance Underwriting and Claims
September 1, 20265 min read

What the EU's AI Regulations Mean for Insurance Underwriting and Claims

The EU's AI regulations changed for insurance carriers, MGAs, and TPAs last month, and almost none of them are dealing with just one law. These rules apply to any organization that places an AI system on the EU market or whose AI output touches EU customers, regardless of where the company is headquartered.  

Right now, insurers must meet new EU AI Act transparency rules, plus obligations under GDPR and DORA that were already in force before this month. The AI Act's toughest rules for underwriting, the high-risk system requirements, don't apply until next year.

That overlap is what most compliance checklists miss. Leaders who treat the latest regulatory change as a single deadline to clear are missing the rules that were already in place, and missing who else the rules reach beyond their own EU entity. 

 

What Actually Took Effect in August

 

What Actually Took Effect in August    

Three things changed for insurers on August 2, 2026, and they cover any provider or deployer of an in-scope AI system serving EU customers, whether that company sits inside or outside the EU. First, any AI system that talks directly to a customer, like a claims chatbot or a quoting assistant, now has to disclose that the customer is talking to AI, unless that's already obvious. Second, providers of general-purpose AI models now face new documentation and risk-management rules. Third, AI-generated or altered content has to carry a visible label so people can tell it was made or changed by AI.

One major change did not happen yet. Regulators pushed back the high-risk system rules under Annex III, which cover life and health underwriting, risk scoring, and automated pricing, by 16 months. That deadline now lands on December 2, 2027, not this August. This one is aimed at insurers and MGAs writing life and health business tied to the EU market. The rules are coming. They just aren't here yet.

Why GDPR DORA and the AI Act All Apply to Claims and Underwriting

 

Why GDPR DORA and the AI Act All Apply to Claims and Underwriting  

Three different rules can apply to a single AI decision in underwriting or claims, and each one reaches a different scope of organization. Here's how each one fits: 

  • GDPR covers any organization, anywhere, that processes the personal data of people in the EU. It has covered automated decisions since 2018 and gives customers the right to a clear explanation of any decision made by an algorithm. That means a person has to be able to step in before AI denies a claim or sets a price, and explain why the AI decided what it did. If AI prices a policy or affects a claim outcome for an EU customer, GDPR is already in play, no matter where the insurer is based.

  • DORA extends to EU-regulated financial entities directly, which includes roughly 22,000 banks, insurers, reinsurers, and their ICT third-party providers. It has applied to insurers since January 2025 and requires risk management and resilience testing for the systems that run your AI, not just the AI itself.  

  • The AI Act governs providers and deployers placing AI on the EU market, and it names insurance directly in only one place. Annex III lists life and health insurance pricing and risk assessment as high-risk uses, which pulls in any carrier or MGA writing that business for EU policyholders. Insurers have to test the AI before it goes live, documenting how it works, and keeping a human able to override it. 

One AI-assisted decision, like a submission review or a claims triage, can touch all three rules at the same time, and a US-based TPA serving EU customers is just as in scope as a carrier headquartered in the EU. A single governance program has to satisfy all three sets of requirements at once, rather than three separate teams running three separate audits. 

 

The Insurance Market Is Moving Faster Than the Law

 

The Insurance Market Is Moving Faster Than the Law 

The insurers who write errors and omissions and directors and officers coverage didn't wait for the AI Act's 2027 deadline. They're tightening AI coverage right now, for any policyholder that uses AI in its operations, not just those with EU exposure.

E&O and D&O policies used to cover AI-related claims by default. Insurers are rewriting those policies with explicit AI exclusions well ahead of the regulatory timeline. That shift already shows up at renewal. An underwriter reviewing your E&O or D&O coverage now asks for proof of bias testing, output monitoring, and human review before pricing the policy the way they used to.

So while regulators gave insurance carriers until 2027 to meet the AI Act's high-risk rules, the market writing liability coverage for those same carriers didn't extend the same grace period. A team that treats the Annex III delay as a reason to wait may show up to its own coverage renewal without the documentation an underwriter now expects. 

 

What the EU's AI Regulations Mean for How You Implement AI

 

What the EU's AI Regulations Mean for How You Implement AI

One AI implementation, built the right way, can satisfy GDPR, DORA, and the AI Act at the same time, for any carrier, MGA, or TPA that any of these rules apply to. Each rule asks for a version of the same proof: what the AI decided, why, who reviewed it, and how to reconstruct that decision later.

That means building review and audit steps into how AI actually runs in production, not adding them after the fact. Every AI decision needs a clear record. Every uncertain result needs a human check before it reaches a customer or a claim file. Every model change needs a version history you can pull up on demand. 

 

Example: Bevaya's Governed Automation layer builds this once instead of three times. Bevaya captures every flow change, model run, and reviewer decision in an immutable audit log, and enforces role-based access control at the organization, workspace, and project level. InsurGPT™, Bevaya's insurance-specific AI engine, draws on 300M+ insurance documents and runs at 98%+ extraction accuracy. Every uncertain value routes to a human reviewer instead of a guess. Carriers, MGAs, and TPAs typically go live in 8 to 12 weeks, across 120+ production deployments to date. You build one audit trail for a regulator, and an underwriter asks for the same one at renewal.

 

What the EU's AI Regulations Mean for Insurance Underwriting and Claims

 

The organizations that come out ahead here won't be the ones that raced to beat the August deadline. They'll be the ones that stopped treating the EU's AI regulations as three separate line items. One AI implementation, built with the right checks from day one, holds up no matter when the next deadline lands, wherever that organization is based. 

 

 

 

 

Share this article

Related Articles