How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment

    EU AI Act Compliance

    EU AI Act High-Risk Classification and Compliance Requirements for Life and Health Insurance Pricing Systems

    Under the EU AI Act, AI systems used to assess risk and set prices for natural persons in life and health insurance are classified as high-risk under Annex III. This triggers obligations under Articles 9 through 15 covering risk management, data governance, technical documentation, logging, transparency, and human oversight, with deployer duties under Article 26 and Annex III obligations applying from 2 August 2026.

    Key Compliance Parameters

    A quick-reference summary of how this classification maps onto the AI Act's core provisions.

    ParameterDetails
    Classification basisAnnex III: risk assessment and pricing of natural persons in life and health insurance
    Core obligationsArticles 9-15: risk management, data governance, documentation, logging, transparency, oversight
    Deployer dutiesArticle 26 applies to insurers using vendor-built or in-house pricing systems
    Application date2 August 2026 for Annex III high-risk obligations under Article 113
    Conformity routeInternal control under Annex VI, with EU database registration under Article 71

    Why Life and Health Pricing AI Meets the High-Risk Threshold

    Regulation (EU) 2024/1689 classifies AI systems intended for risk assessment and pricing of natural persons in relation to life and health insurance as high-risk under Annex III. This classification is use-case based rather than technology based: any system that scores, prices, or informs underwriting decisions affecting an identifiable individual's life or health insurance terms falls within scope, regardless of whether the underlying model is a traditional actuarial engine, a machine learning model, or a hybrid pipeline. The brief for this classification cites Annex III point 5(a); readers should confirm the exact sub-point against the current consolidated Annex III text before relying on it for legal purposes, since insurance risk assessment and pricing use cases are addressed within point 5 of Annex III but the precise lettering warrants verification. What is not in question is that once a system falls under this Annex III category, it is subject to the full set of high-risk obligations in Articles 9 through 15, plus deployer obligations under Article 26 for the insurer putting the system into use.

    Deployer Obligations Under Article 26

    Insurers that deploy a high-risk pricing or underwriting system, whether built internally or licensed from a vendor, carry obligations independent of the provider's own compliance work. Article 26 requires deployers to assign competent human oversight, monitor the system's operation in production, and use the system in accordance with the provider's instructions for use. This means an insurer cannot rely solely on a vendor's conformity declaration; the compliance function must confirm that oversight personnel are designated, that monitoring is actually occurring against live pricing decisions, and that any deviations from intended use are identified and addressed. For actuarial teams, this shifts part of the compliance burden from a pre-deployment checklist into an ongoing operational responsibility tied to how the pricing system behaves after it goes live.

    Runtime Controls Needed to Demonstrate Ongoing Compliance

    Articles 12 and 14 define required outcomes, specifically traceability of functioning and the ability for a human to understand, monitor, and intervene in system outputs, without mandating a specific implementation. This gives governance teams flexibility to layer compliance controls around existing actuarial pricing engines rather than rebuilding core models. In practice, this typically requires three architectural components positioned between the scoring pipeline and any binding pricing or underwriting decision: an audit logging layer that captures risk-relevant events tied to individual pricing outputs, a human oversight checkpoint that gives a designated reviewer visibility and override authority before a decision is finalized, and a policy enforcement point that can apply documented rules consistently across the pipeline. Runtime governance platforms, including Trussed AI, provide audit logging, policy enforcement, and oversight checkpoint capabilities designed to sit alongside production AI systems for exactly this kind of layered instrumentation, without requiring changes to the underlying pricing models.

    Conformity Assessment and Implementation Timeline

    MilestoneDetails
    1 August 2024The AI Act enters into force, starting the phased schedule of obligations under Article 113.
    Transition periodInsurers use this window to instrument existing pipelines for logging, documentation, and oversight rather than treating compliance as an immediate deadline.
    Conformity assessmentMost Annex III high-risk pricing systems use the internal control route under Annex VI, requiring insurers to self-assess and issue a declaration of conformity.
    Database registrationRegistration in the EU high-risk AI systems database under Article 71 is a required administrative step before market placement.
    2 August 2026Annex III high-risk obligations generally become applicable under Article 113.

    Evaluation Criteria for Governance Teams

    • Scope mapping: Identify which pricing, scoring, or underwriting components in the production stack meet Annex III criteria, including third-party and vendor-supplied models.
    • Logging gap analysis: Assess whether existing infrastructure produces event-level traceability sufficient for Article 12, or whether a logging layer needs to be added.
    • Oversight designation: Confirm who holds human oversight authority under Article 14 and Article 26, and what tooling gives them visibility and override capability.
    • Documentation inventory: Catalog existing Annex IV-relevant documentation, including dataset lineage and model versioning, and identify gaps.
    • Timeline planning: Build a working plan toward database registration and declaration of conformity ahead of the 2 August 2026 application date.

    Core Obligations Under Articles 9-15

    A concise recap of the requirement categories discussed above, for teams building a compliance checklist.

    • Risk management processes appropriate to the system's lifecycle
    • Data governance and quality controls for training, validation, and input data
    • Technical documentation sufficient to support conformity assessment
    • Logging and traceability of pricing-relevant outputs (Article 12)
    • Transparency and clear instructions for use provided to deployers
    • Human oversight with the authority to review and intervene in outputs (Article 14)

    Deployer note

    Insurers deploying a system built by a third party still carry independent obligations under Article 26, separate from the provider's own conformity work.

    Operationalize EU AI Act Compliance for Pricing Systems

    Runtime governance can help insurers layer audit logging, human oversight checkpoints, and policy enforcement onto existing pricing pipelines without rebuilding actuarial models.

    Request a Demo