The AI Act and the Insurance Sector: Which Obligations Really Apply to the Intermediary Using Artificial Intelligence
Regulation (EU) 2024/1689 classifies risk assessment and the pricing of life and health policies as “high-risk”. But the intermediary is almost always a deployer, not a provider: here’s what really changes for you.
Don’t ask whether insurance is “high-risk”. Ask what your role is
For months we’ve been told that, with the AI Act, insurance falls among the “high-risk” activities. The message reaches the intermediary in two opposite versions, both wrong: either alarm (“if I use AI I’m breaching a very tough regulation”), or denial (“it’s the insurers’ problem, not mine”).
The truth is simpler. Regulation (EU) 2024/1689 doesn’t classify “the sector” as a block: it assigns different obligations depending on the role you play with respect to each individual artificial intelligence system. The right question isn’t “is insurance high-risk?”, but “what is my role, and what does it really require of me?”. In most cases, the answer shortens the list of requirements rather than lengthening it.
Where we stand
The AI Act came into force on 1 August 2024 and applies in stages. The bans on prohibited practices and the obligation to train staff on AI have applied since 2 February 2025. The heaviest obligations, those on high-risk systems, were set for 2 August 2026.
The Digital Omnibus package intervened on this last deadline: in May 2026 the European Parliament and Council reached an understanding to move the application of the high-risk rules to 2 December 2027 (and to 2 August 2028 for systems built into other products). Two caveats, however: until the text is definitively adopted the original deadline remains valid, and in any case the postponement moves the timing, not the obligations. It’s breathing room, not a pardon. On the sector, IVASS has already made clear that insurers and intermediaries will have to comply with the high-risk rules within the deadlines set.
Provider or deployer: the distinction that changes everything
The AI Act builds obligations around role. For insurance, two figures matter.
The provider develops an AI system and places it on the market under its own name. It bears the heaviest load: technical documentation, risk management, conformity assessment. It’s the insurer that builds its own pricing model, or the software house that sells a scoring engine.
The deployer uses an AI system under its own responsibility. Its obligations are real but lighter: use it according to the instructions, ensure human oversight, inform the customer when the system contributes to decisions that concern them.
And here comes the point almost no one explains. What is “high-risk” for insurance? The systems that assess risk and set the premium for life and health policies for natural persons. But who does this work? Almost always the insurer. The intermediary distributes products already priced upstream: in the vast majority of cases it is not the deployer of a high-risk system. Most of the tools an agency really uses — assistants to read documents, classify cases, support claims handling, or first-line chatbots — fall outside high-risk.
The exception exists: if, under your own responsibility, you use tools that assess risk or price life and health policies — underwriting delegations, MGA-type arrangements, a proprietary scoring model — then you fall among the deployers of high-risk systems, with more stringent obligations.
What you really have to do
Even outside high-risk, three things concern you already today.
The first is training: whoever uses AI tools must ensure that staff know what they do and what limits they have. It has been in force since 2025 and is the simplest obligation to fulfil and the easiest to forget.
The second is transparency towards the customer: if an automated assistant interacts with the insured, they must be told; if AI contributes to an analysis or a proposal, the customer has the right to know. It’s not just compliance. It’s consistent with the regulation’s human-centric principle, whereby the algorithm supports but does not replace professional judgement — precisely the value that sets a good intermediary apart.
The third is due diligence on the technology partner: your deployer obligations assume the provider has done its part (documentation, instructions, conformity). The question to ask isn’t “does it work?”, but “is it documented and compliant?”. A tool developed to measure, whose logic and documentation you control, places you in a clean and traceable position — the opposite of the “black box” bought sight unseen.
What you risk
Penalties reach up to 35 million euros or 7% of turnover for prohibited practices, and up to 15 million or 3% for high-risk infringements (for SMEs the lower amount applies). But for an intermediary the most concrete risk is another: using an AI tool that influences the customer’s choices without transparency, or without being able to demonstrate staff training, exposes you to complaints, to IVASS scrutiny and to challenges on the privacy front.
In summary
The AI Act doesn’t treat insurance as a single block: it distributes obligations according to role. The intermediary is almost always a deployer, rarely the party responsible for a high-risk system. Training, transparency and choosing the right partner: that’s where compliance starts, and the postponement of the deadlines is time to prepare, not permission to procrastinate.
A126 develops bespoke applications for insurance intermediaries. When they include artificial intelligence features, we take care of the most complex part — documentation and provider-side compliance — delivering you traceable, transparent tools built around the way you work.
Want to understand which of the AI tools you use fall under the AI Act’s obligations? Get in touch for a free consultation.
A126 Corporate Advisors — Bespoke digital solutions for those who work in insurance intermediation.