Skip to main content

AI in life and health insurance pricing: what the Act requires

The system being classified

You are an insurer using AI for risk assessment and pricing in life or health insurance for natural persons in the EU.

Verdict

High-risk system

Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.

9 applicable obligations
Maximum fine tier: €15,000,000 or 3% of global annual turnover
Key date: 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus)

This is the classification of the configuration described above, not of your system. One different answer can move it — which is exactly what the comparison further down shows, and what the free assessment settles in about ten minutes.

What produced this verdict

These are the entire inputs. The engine is deterministic, so these answers always produce the verdict above.

Annex III categories

  • · Access to essential services

Scope and role

  • · Deployer — you use it under your own authority
  • · Placed on the EU market, or output used in the EU
  • · Article 27 FRIA duty-holder

What applies, and from when (9)

Every entry cites the article it comes from and the date it binds. That second column is the part most summaries of the Omnibus get wrong.

ArticleObligationBinding from
Art. 4
AI literacy
Ensure staff dealing with AI systems have a sufficient level of AI literacy (training records recommended).
2 February 2025
Best practice
AI system inventory
Maintain a central register of all AI systems in use, their purpose, risk tier and owner.
Good practice
Art. 26(1)
Operate per provider instructions
Assign technical and organisational measures to use the system strictly according to its instructions for use.
2 December 2027
Art. 26(2)
Assign trained human oversight
Name specific, competent, trained people with authority to oversee the system and overrule or halt it.
2 December 2027
Art. 26(4)
Input data control
Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
2 December 2027
Art. 26(5)
Monitor and suspend on risk
Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk.
2 December 2027
Art. 26(6)
Retain logs (minimum 6 months)
Keep automatically generated logs under your control for at least six months.
2 December 2027
Art. 26(11) + 86
Inform affected persons; explain on request
Tell natural persons subject to decisions made or materially informed by an Annex III system that it is in use, and be ready to give the Article 86 explanation of the role the system played in a decision.
2 December 2027
Art. 27
Fundamental rights impact assessment
Deployers that are public bodies or private entities providing public services, and deployers of credit-scoring or life/health-insurance risk-pricing systems (Annex III 5(b)/(c)), must complete a FRIA before first use.
2 December 2027

What would change this verdict

Each row below is the same scenario with one answer changed, re-run through the same engine. These are not predictions about your system; they are what our classifier returns when that single fact differs. Where one change to the scenario necessarily moves a second answer with it, the row says which, and why.

You also build the model in-house

Same risk tier

Building and using the same system makes you both provider and deployer, and you owe both stacks.

  • Obligations: 921 (+12)
  • +1 flagged for counsel review

You claim the Article 6(3) derogation

Becomes minimal risk

Available where the system performs a narrow procedural task, improves the result of prior human work, or does no more than preparatory profiling — and never where it profiles natural persons. Claiming it is a documented decision, not a checkbox.

  • Obligations: 92 (-7)
  • +1 flagged for counsel review
  • Key date changes to No dated obligations pending — AI literacy (Art. 4) applies since 2 February 2025; keep the inventory current

Your system is not this system

The assessment asks the same questions this page answered for a generic configuration, and produces the verdict, the gap list and the 30-day plan for yours. Ten minutes, free, no sign-up, and it runs entirely in your browser — your answers never reach us.

Classify your own system →

Other configurations

Produced by rule set 1.6.1, legal state 2026-08-05. The engine is deterministic and contains no language model in the verdict path, and every rule is published at /methodology for you to audit.

AnnexWise is preparation software, not legal advice. This page classifies a described configuration; it is not an opinion on any particular organisation or system.