Short answer. Life and health insurance risk assessment and pricing is classified high-risk under Annex III, point 5(c) of the EU AI Act, and the Digital Omnibus regulation that entered into force on July 27, 2026 pushed the compliance deadline for standalone high-risk systems from August 2, 2026 to December 2, 2027. An insurer still needs a documented risk management system, human oversight at the underwriting decision point, and post-market monitoring built well before that date, because the technical work, not the legal deadline, is what takes 12 to 18 months.
An underwriting or pricing system falls inside Annex III point 5(c) the moment it scores, prices, or informs a decision about an identifiable person’s life or health insurance terms. That covers a traditional actuarial engine with a machine-learning risk factor bolted on, a full ML pricing model, and a hybrid pipeline that blends both. Claims-triage tools that flag a case for human review sit closer to the edge of scope and need a documented rationale for why they are, or are not, treated as high-risk.
Operationalizing the obligation means three workstreams run in parallel, not one document written after the model ships. A risk management system under Article 9 has to name the specific harms the model could cause (unfair pricing by protected characteristic, model drift after a claims shock, data quality gaps in a legacy policy administration system) and how each is mitigated. Human oversight under Article 14 has to be a real intervention point, not a “review” button an underwriter clicks without the authority or the time to override the model. Post-market monitoring under Article 72 has to run against production traffic, not a validation set from the last model retrain.
Ableneo has shipped 34 production AI projects across 4 countries and 7 industries in 2025, with roughly 4 of 5 reaching production rather than stalling as a pilot. That delivery discipline, not the compliance paperwork alone, is what determines whether an insurer’s Article 9 risk file describes a system that actually behaves the way the documentation claims.
Insurers in Slovakia, the Czech Republic, and Austria answer to two overlapping regimes at once. The EU AI Act governs the model itself: its risk classification, its documentation, its human oversight. The Digital Operational Resilience Act (DORA) governs the operational resilience of the ICT system that runs the model, including incident reporting and third-party ICT risk, and it applies directly to insurance and reinsurance undertakings under Article 2, not just to banks. A national insurance supervisor auditing an underwriting model in 2027 will expect both files, not one.
The December 2027 deadline is a legal deferral, not an engineering one. Annex IV technical documentation, a conformity assessment under Article 43, and an EU database registration all take real build time against a live policy administration system that was never designed to expose model logic or log a decision trail. Insurers that start scoping now, while the deadline still feels distant, are the ones that will have a defensible file in December 2027 instead of a rushed one filed in November.
Life and health insurance risk assessment and pricing is high-risk under EU AI Act Annex III, point 5(c).
Article 14 requires a natural person with the competence, authority, and time to understand the system’s output, notice when it is behaving abnormally, and decide not to use it or to override it. For underwriting, that means the underwriter assigned to the referral queue needs visibility into the top factors driving a score, not just a pass or fail label, and needs the organizational mandate to overturn the model without an approval chain that discourages it in practice. A referral rate tuned so high that no underwriter can meaningfully review each case defeats the requirement even if a human technically clicks a button.
It removes the panic but not the work. Insurers that treat the deferral as permission to wait will compress 12 to 18 months of risk-management, data-governance, and logging work into the final quarter of 2027, competing for the same external auditors and conformity assessment capacity as every other insurer in the market at the same time. A more useful reading of the deferral is a scoping year: map every model against Annex III point 5(c), decide provider versus deployer status for each, and build the Article 9 risk file for the highest-exposure model first, typically the one with the largest book of affected policyholders.
The AI Act asks whether the model’s decision is documented, overseen, and monitored. DORA asks whether the ICT system running that model is resilient, whether a major incident gets reported to the national supervisor, and whether the third-party vendor supplying the model or the infrastructure is properly assessed under DORA’s ICT third-party risk requirements. In practice, one incident, a pricing model that starts producing distorted quotes after a data pipeline failure, can trigger obligations under both regimes at once: an Article 73 AI Act serious-incident consideration and a DORA major ICT-incident report, on different clocks, to different desks inside the same regulator.
Article 10 requires the training, validation, and testing data behind a high-risk model to be examined for bias against protected characteristics before deployment, and Article 9’s risk management system has to keep testing for it afterward, not just at launch. If a supervisor or a complainant identifies a pattern, an insurer without a documented bias-testing trail is defending intent with no evidence, while an insurer with logged testing results and a remediation history is defending a governed process. The difference is not the outcome of any single price quote, it is whether the file exists before the question is asked.
Both creditworthiness assessment and life or health insurance pricing sit inside Annex III point 5, and both carry Article 9 risk management, Article 14 human oversight, and Article 72 post-market monitoring duties. The practical difference is the underlying decision and the adjacent regulation stacked on top of it. Credit scoring sits next to GDPR Article 22’s automated-decision rules and a bank’s existing model-risk-management function built for Basel-style capital models. Insurance underwriting sits next to actuarial fairness standards and Solvency II’s own risk-governance expectations, and the affected outcome is a health or life insurance term rather than a credit line. An insurer cannot simply copy a bank’s AI Act playbook; the risk taxonomy and the oversight point are different even though the article numbers are the same.
Ableneo works with insurers including UNIQA across Slovakia and Austria on production AI, and treats an EU AI Act risk file the same way it treats the model itself: something that has to survive contact with a live production system, not a document written to satisfy a checklist. Ableneo’s 2025 delivery record across 34 production implementations is the reason an insurer’s compliance file and its underwriting model tend to agree with each other: the team that writes the Article 9 documentation is the same team that built and monitors the system it describes.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.