The AI decision that gets examined in insurance is rarely the model. It is the declined claim, the premium that priced a customer out, or the application referred to manual review and never picked up. By the time anyone asks how the outcome was reached, the question is not whether the model was accurate on average. It is whether this particular person was treated fairly, and whether the firm can show its reasoning.
That is a governance question long before it is a data science question, and insurance is one of the few sectors where the regulatory position is already specific rather than general.
Not all insurance AI carries the same obligations
Under the European Commission: AI Act, AI systems used for risk assessment and pricing in relation to natural persons in life and health insurance fall within the Annex III high-risk category. Much general insurance activity does not fall there on the same basis. This asymmetry is frequently missed by firms writing a single organisational AI policy: two models built by the same team, on the same platform, can sit in materially different regulatory positions depending on the line of business and the purpose.
Classification is driven by intended purpose rather than technique. A gradient-boosted model estimating claims frequency in motor is not high-risk merely because a similar architecture is used for health underwriting. Determine the position system by system, record the reasoning, and revisit it when the Commission publishes its classification guidelines.
Falling outside Annex III is not the same as falling outside scope. Prohibited practices apply regardless of sector, transparency duties may still attach, and data protection law applies to every one of these systems.
What the supervisor has already said
The European Insurance and Occupational Pensions Authority: Opinion on Artificial Intelligence governance and risk management, published in August 2025, sets out supervisory expectations for insurance undertakings using AI. It is addressed to national supervisors, which means it describes what your regulator has been told to look for.
Its structure is worth reading directly, but the substance is a risk-based and proportionate framework covering data governance, record-keeping, fairness, cyber security, explainability and human oversight, applied across the AI system lifecycle. Two features deserve emphasis. First, proportionality cuts both ways — a low-materiality model does not need the governance of a pricing engine, but a pricing engine does not get the governance of a low-materiality model. Second, the expectation that firms can meaningfully explain outcomes is stated in terms of the consumer’s interest, not the modeller’s convenience.
EIOPA’s earlier European Insurance and Occupational Pensions Authority: report on artificial intelligence governance principles remains a useful companion, particularly on how fairness and explainability interact in practice.
Fairness is where this gets hard
Insurance is legitimately in the business of differentiating risk. That is the product. The difficulty is that risk-based differentiation and unlawful discrimination can be produced by the same statistical process, and the model cannot tell you which one it has done.
Removing protected characteristics from the feature set does not resolve this. A model with sufficient data will reconstruct them from correlates — postcode, occupation, purchase channel, device type, payment history. Proxy effects are not a modelling error to be debugged; they are an expected consequence of predictive power that has to be actively tested for.
Practical testing means measuring outcomes across groups you are not permitted to price on, precisely so you can demonstrate you did not. This creates its own tension with data minimisation, and the resolution is a documented, purpose-limited approach agreed in advance rather than an ad hoc data pull. The Information Commissioner’s Office: guidance on AI and data protection addresses this directly for UK firms, including the accountability position of senior management.
Record what you tested, what you found and what you decided. A firm that has never measured disparate outcomes cannot claim there are none.
Claims: the automation gradient
Claims handling invites automation because volumes are high and much of the work is routine. The gradient matters more than the decision to automate.
- Assembly: gathering the policy, the claim, prior history and relevant documents into one view. Low risk, high value, and where most of the time actually goes.
- Triage: routing by complexity or suspected fraud. Moderate risk — a wrongly routed claim is recoverable, but systematic misrouting of a customer segment is not a routing problem.
- Settlement and decline: the consequential decision. This is where human accountability belongs unless a category has been separately assessed, documented and monitored.
Fraud models deserve particular care. A fraud score is an accusation with a probability attached, and the cost of a false positive falls on a customer who has just suffered a loss. Referral thresholds, the evidence shown to the investigator, and the route by which a customer challenges an outcome are all design decisions with consumer-outcome consequences.
Governance that a supervisor can follow
Build an inventory of models by line of business, with intended purpose, classification and accountable owner. Attach to each a record of the data used, the fairness testing performed, the explanation available to a customer, the human oversight design and the monitoring in place. Where the model is supplied by a third party, record what happens when the provider retrains it and whether you can reproduce a prior decision.
The NIST: AI Risk Management Framework is not an EU instrument, but its Govern, Map, Measure and Manage structure is a serviceable scaffold for organising this work while EU harmonised standards are still being developed.
Use the model governance you already have
Insurers are unusual among AI adopters in that they already operate mature model governance. Capital and reserving models sit under validation regimes with independent review, documented assumptions, back-testing and defined escalation when performance drifts. Many firms nonetheless build a parallel and much weaker governance track for AI, on the reasoning that machine learning is a different discipline.
That is usually a mistake of organisation rather than substance. The questions an independent validator asks of a reserving model — what are the assumptions, how were they tested, what happens at the edges of the data, who challenged this, what would make us stop using it — are the right questions for a pricing model built with gradient boosting. The techniques for answering differ; the governance spine does not.
Practically, this means routing material AI models through the existing validation function with an extended toolkit, rather than creating an AI committee that reports separately and carries less authority. It also means the actuarial function should be involved in AI pricing work from the start. Where a model influences pricing or reserving, the professional obligations of the people signing off do not change because the method did.
What this cannot do
No governance framework resolves the underlying policy question of how much differentiation a firm considers acceptable. That is a commercial and ethical judgement for the board, and a model will implement whatever answer it is given without ever surfacing the question. Nor can explainability techniques manufacture a defensible narrative for a model that is genuinely opaque — a post-hoc explanation is an approximation, and presenting it to a customer as the reason for a decision is a misrepresentation.
Stop when you cannot state the intended purpose precisely enough to classify the system, when fairness testing has not been performed on a pricing or underwriting model touching natural persons, when nobody can explain an individual outcome to the person it affected, or when a third-party model cannot be reproduced after a provider update. Each of those is recoverable before deployment and considerably harder afterwards.
Further reading: EIOPA: Opinion on AI governance and risk management; EIOPA: report on AI governance principles; European Commission: AI Act; Information Commissioner’s Office: guidance on AI and data protection; NIST: AI Risk Management Framework.
See how an AI Readiness & Governance Assessment classifies your insurance models and their controls.




