Life and health AI pricing is high-risk by default. Property, motor, and travel sit outside §5(c) — but watch behavioural pricing.
Summary
Annex III §5(c) is precise: it covers life and health insurance pricing and risk assessment. Property, motor, travel, and other non-life lines sit outside §5(c). The boundary moves with telematics and behavioural pricing — a motor product priced principally on inferred individual driver risk, with health-adjacent components (fatigue detection, biometric monitoring), is increasingly likely to be treated as in scope.
Like fintech, insurance is one of the few sectors where Article 27 fundamental rights impact assessments apply to private deployers, not just public bodies. An insurer deploying a new pricing model must complete the FRIA before first use and update it on material changes.
Solvency II is the parallel regime. AI used in technical-provisions calculation, capital modelling, ORSA inputs, or operational-risk modelling sits inside the Solvency II governance regime alongside the AI Act. The two are layered, not alternatives.
Annex III §5(c)
AI for risk assessment and pricing in life and health insurance — high-risk by default.
Article 27
Fundamental rights impact assessment — required for private deployers in §5(c) before first use.
Article 14
Human oversight — applicants must be able to obtain meaningful review of an adverse insurance decision.
Article 13
Transparency and instructions for use — model behaviour, performance, and known limitations across population segments.
Solvency II Article 41
System of governance — applies directly to AI used in solvency-relevant calculations.
Solvency II Articles 44–48
Risk management and own-risk and solvency assessment (ORSA) — must address AI model risk.
GDPR Article 22
Right not to be subject to solely automated insurance decisions with significant effect.
GDPR Article 9
Special-category data — health data processing requires an Article 9(2) basis.
What §5(c) covers, and what it does not
Annex III §5(c) covers AI used "for risk assessment and pricing in relation to natural persons in the case of life and health insurance." That phrase is narrow on its face but broad in operation:
- In scope: traditional life-underwriting AI; medical-underwriting AI; behavioural-pricing AI for life or health products; claims-triage AI on health claims that influences benefits; chronic-condition prediction models used to set premiums.
- Out of scope (under §5(c)): property and motor pricing; non-life claims processing not affecting individual premium; reinsurance pricing models that operate on portfolios rather than natural persons.
- Borderline: motor telematics combined with health-adjacent biometrics; cyber-insurance pricing for individuals; pet-insurance pricing where the policyholder data dominates.
Where §5(c) does not apply, Article 50 transparency obligations may still apply to AI customer-facing interactions, and the rest of the AI Act baseline (literacy, prohibited practices, GPAI) still applies.
Provider obligations
- Article 9 risk management with proxy-discrimination as a first-class risk: gender, age, disability, ethnic-origin proxies through postcode and family history.
- Article 10 data governance — actuarial data sets are deep but historically biased; document the bias-testing methodology and the corrections applied.
- Article 11 + Annex IV technical documentation including the model-validation framework.
- Article 13 instructions for use written for underwriters and product actuaries — including the residual risks the deployer must monitor.
- Article 14 design for oversight — every adverse decision must be reachable by a human reviewer.
- Internal Annex VI conformity assessment is the default route.
Insurer (deployer) obligations
- Article 26(1) intended-purpose use: a model trained on group life cannot be repointed at individual life without re-validation.
- Article 26(2) human oversight — usually the underwriting team — with the authority to overturn the AI on individual cases.
- Article 27 fundamental rights impact assessment — compulsory in §5(c). The FRIA covers the categories of natural persons affected, foreseeable impact on fundamental rights (including non-discrimination), bias risk, oversight design, and mitigations.
- Article 26(11) serious-incident reporting under Article 73.
- GDPR Article 22 individual review and Article 9 special-category processing for health data.
- Solvency II Articles 41 (governance), 44 (risk management), 45 (ORSA), and 48 (actuarial function) — AI in solvency-relevant calculations is part of the regulated risk-management system.
Solvency II and EIOPA expectations
EIOPA's 2021 report on AI governance principles in insurance is the practical baseline: proportionality, fairness and non-discrimination, transparency and explainability, human oversight, data governance and record-keeping, robustness, performance. EIOPA's 2024 supervisory statement on differential pricing practices specifically warns insurers about behavioural-pricing AI that disadvantages identifiable groups. Where AI Act Article 10 data-governance evidence and EIOPA differential-pricing supervisory expectations diverge in detail, the stricter applies — typically EIOPA on the actuarial fairness side, AI Act on the technical-documentation side.
Enforcement landscape
National insurance supervisors are the practical first responders: BaFin, ACPR, IVASS, DNB, the Spanish DGSFP. EIOPA coordinates. National DPAs (CNIL, AEPD, Garante) lead on the GDPR Article 22 / Article 9 side and have already produced relevant enforcement decisions on insurance-data practices.
01
Inventory pricing and underwriting models against §5(c); for borderline products, document the in-scope/out-of-scope analysis.
02
Run an Article 27 FRIA for every §5(c) deployer use; align with the Solvency II ORSA cycle so the same evidence base supports both.
03
Audit data-governance and bias-testing artifacts against Article 10 — including geographic, gender, age, and disability proxy testing.
04
Operationalise the GDPR Article 22 individual-review process; ensure the underwriting team has the authority to overturn the AI on appeal.
05
Coordinate insurance supervisor and DPA notifications under Article 73 / Solvency II / GDPR for serious incidents.
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Vejledning om sondringen mellem dataansvarlig og databehandler
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Vejledning om automatiserede afgørelser og profilering (GDPR art. 22)
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Vejledning om retten til sletning (retten til at blive glemt, GDPR art. 17)
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Vejledning om fortegnelse over behandlingsaktiviteter (GDPR art. 30)
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Region Hovedstaden — brud på sundhedsdata via MedHelp
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Konsekvensanalyse (DPIA) — hvornår og hvordan
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Behandlingssikkerhed — krav efter GDPR artikel 32
datatilsynet
DK
Fetched 2026-07
Datatilsynet: Databeskyttelsesrådgiveren (DPO) — krav, rolle og uafhængighed
AI Act Article 50 transparency
5 days
until 2026-08-02, when Article 50 transparency obligations apply (unchanged). Annex III high-risk obligations move provisionally to 2 December 2027 under the Digital Omnibus agreement of 7 May 2026, pending formal adoption.