AI Claims Handling Is Not High-Risk Under the EU AI Act. Here Is What Binds It Instead.
Claims handling is absent from Annex III. GDPR Article 22 binds it anyway. Only 24% of insurers say they could pass a governance review in 90 days.
The short answer
- •Claims handling is not in Annex III. The Commission's own draft classification guidelines name claims management as an example of a system falling outside point 5(c), and they use health insurance, the one line where underwriting is high-risk, to make the point.
- •The Digital Omnibus deferral changes nothing for a claims operation. The chapter that moved to December 2027 was never the chapter that governed you.
- •GDPR Article 22 is what binds. It has applied since 25 May 2018. A declined or reduced claim sits squarely inside it. Swiss and UK operations answer to their own equivalents.
- •EIOPA has already told supervisors what it expects: explainable outcomes and reproducible records under existing sectoral law, scaled to the impact of the system.
- •The test is reconstruction. If you cannot rebuild a closed decision on demand, the deadline you missed was 2018, not 2027.
On 24 July 2026 the Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744. It entered into force three days later. High-risk obligations for standalone Annex III systems move from 2 August 2026 to 2 December 2027. For AI embedded in regulated products, from 2 August 2027 to 2 August 2028.
Sixteen extra months, then.
A claims operation did not get them. Not because the deferral is narrow, but because claims handling was never in the chapter that moved.
Is AI claims handling high-risk under the EU AI Act?
No. Annex III does not list it.
Point 5 of Annex III covers access to essential private and public services. It names four things: evaluating eligibility for essential public assistance benefits, where used by or on behalf of public authorities; evaluating creditworthiness or establishing a credit score, excluding systems used to detect financial fraud; risk assessment and pricing in relation to natural persons in the case of life and health insurance; and the evaluation, classification and dispatch of emergency calls.
Life and health risk assessment and pricing is in scope. Motor, property, warranty and commercial-lines claims handling is not.
The Commission now says so itself. Its draft guidelines on the classification of high-risk AI systems, published on 19 May 2026 and open for consultation until 23 June, set out worked examples on both sides of the line.
Annex III point 5(c): the Commission's worked examples
| Inside point 5(c): high-risk | Outside point 5(c) |
|---|---|
| Reviewing life insurance applications, where the system processes age, health status, family history, lifestyle and occupation against mortality tables to guide acceptance and terms | Claims management in health insurance once the insured event has happened: verifying whether a claim is valid under the policy terms or determining the amount payable |
| Predicting the expected annual medical cost for a risk group, where the resulting figure becomes the premium charged to that group | Claims management used to improve the accuracy of claims processing and decision-making, such as validating claimant information against external databases |
| Product design for life insurance, where it is not used for risk assessment or pricing in individual cases |
The Commission's reasoning for the exclusion is worth reading in its own words:
These use cases are distinct from carrying out a risk assessment or pricing, even though their outcome might affect the enjoyment of the health insurance.
Note which line of business that example uses. Health insurance is the one place where underwriting is high-risk. Claims management falls outside the use case even there. The guidelines are draft and non-binding. The Commission is explicit that authoritative interpretation of the AI Act rests with the Court of Justice. But they are the clearest official statement available and they point the same way.
That is the answer to the question. It is also where most readings stop and where the two things that actually decide your exposure begin. They are different questions for different systems. Conflating them is how compliance plans go wrong.
Four terms that decide the answer
Annex III. The list of high-risk use cases in Regulation (EU) 2024/1689. A system is high-risk under this route only if it matches a use case on the list. Adjacency to a listed use case is not membership of it.
Profiling. Automated evaluation of personal aspects of a natural person: economic situation, health, reliability, behaviour. The AI Act borrows the term from the GDPR. It carries decisive weight in Article 6(3).
A solely automated decision. Under GDPR Article 22, a decision reached without meaningful human involvement that produces legal effects or similarly significant ones. A human who cannot in practice overturn the output does not make the decision jointly.
Audit-readiness. The property of being able to reconstruct a past decision from records the system produced at the time. It is distinct from audit-preparation, which is an exercise you run before an examination.
If you do have an Annex III system, profiling closes the exit
This applies to life and health risk assessment and pricing, not to claims handling. If you run those systems, read on. If you do not, skip to the next section, because Article 6(3) has nothing to say about you.
Carriers inside Annex III generally plan to escape via Article 6(3), which lifts high-risk status where a system “does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making” and meets one of four conditions: a narrow procedural task, improving a previously completed human activity, detecting patterns without replacing human assessment or performing a preparatory task.
One sentence cancels all four:
Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.
A life or health pricing model that segments individuals on economic situation, health, reliability or behaviour is profiling. The derogation does not reach it.
Article 6(4) then closes the loop. A provider who considers an Annex III system not high-risk must document that assessment before the system is placed on the market or put into service, register it under Article 49(2) regardless and produce the documentation to national competent authorities on request. Not-high-risk is a filing, not an absence of paperwork.
Which regime actually binds a European claims operation?
What reaches a claims operation and from when
| Instrument | What it reaches | Applies from |
|---|---|---|
| EU AI Act, high-risk chapter (Annex III) | Life and health risk assessment and pricing. Not claims handling. | Deferred to 2 December 2027 for standalone systems; 2 August 2028 for AI embedded in regulated products |
| GDPR Article 22 | Decisions based solely on automated processing producing legal or similarly significant effects, such as a declined or reduced claim | 25 May 2018 |
| Switzerland's revised Federal Act on Data Protection | Its own restriction on automated individual decision-making, for Swiss-established operations | In force |
| UK GDPR | The United Kingdom's retained equivalent of these rules | In force |
| EIOPA Opinion EIOPA-BoS-25-360 | Supervisory expectations for insurance AI that is neither prohibited nor high-risk: governance, explainability, record-keeping | 6 August 2025 |
The pattern is the one that catches people out. The instrument everyone is preparing for is the one that does not reach them. The instrument that does reach them has been in force for eight years.
Does GDPR Article 22 apply to an automated claims decision?
Yes. Unlike the AI Act it has applied since 25 May 2018.
One qualifier before the detail. The GDPR is not the only data protection regime a European claims operation can answer to. Which instrument binds you depends on where you are established and whose data you process. What follows is the GDPR's analysis. Read it as the pattern rather than the whole map and confirm the instrument that governs your own book.
Article 22 restricts decisions based solely on automated processing that produce legal effects or similarly significant ones. A declined or reduced claim meets that bar.
Three sources define what that now requires. None of them moved in July.
Automated scores can themselves be decisions.
In OQ v Land Hessen, the SCHUFA case (C-634/21, 7 December 2023), the CJEU held that the automated generation of a probability value about a person's ability to meet payment commitments is itself automated individual decision-making under Article 22(1), where a third party receiving that value draws strongly on it to establish, implement or terminate a contract. The duty attaches to the party producing the score, not only the party acting on it.
A sign-off is not oversight.
Under the Article 29 Working Party guidelines on automated decision-making (WP251rev.01), endorsed by the EDPB, human involvement escapes Article 22 only where it is meaningful, carried out by someone with the authority and competence to change the decision. The guidelines state directly that employees rubber-stamping automatically generated profiles will not take a controller outside Article 22.
An explanation has a defined standard.
In Dun & Bradstreet Austria (C-203/22, 27 February 2025) the CJEU set out what “meaningful information about the logic involved” requires under Article 15(1)(h): the procedure and principles actually applied to reach the decision, communicated concisely and intelligibly. The Court did not require a causal account of how one individual's data drove their result. It indicated instead that explaining how the outcome would differ had the data been different can satisfy the duty. It also held that handing over the algorithm does not discharge it, because a complex mathematical formula is neither concise nor intelligible. It held too that a trade secret does not permit a blanket refusal: the controller must put the disputed information to the supervisory authority or a court to balance.
That is a comparative standard, not a narrative one. Answering it requires knowing what the system actually did with which inputs.
Where the sector supervisor sits
EIOPA's Opinion on AI governance and risk management (EIOPA-BoS-25-360, 6 August 2025) is addressed to national supervisors and deals specifically with insurance AI systems that are neither prohibited nor high-risk under the AI Act. It is built on the Insurance Distribution Directive, Solvency II, the Digital Operational Resilience Act and the Solvency II and IDD delegated regulations, not on the AI Act.
Its own framing is the point worth taking. Those systems, it says, “continue to operate subject to existing sectoral legislation without new requirements”, the exceptions being certain transparency duties, the promotion of staff AI literacy and voluntary codes of conduct. EIOPA is not adding a regime. It is telling supervisors that the one already in force applies.
Within it, undertakings should ensure the outcomes of AI systems can be meaningfully explained and should keep appropriate records of training and testing data and of modelling methodologies to enable reproducibility and traceability. Expectations scale with impact: limited for systems that barely touch customers, more stringent for those that do.
Claims handling therefore leaves the AI Act's heaviest chapter and arrives at a proportionate but real set of expectations by a different route. The obligation does not disappear. It changes address.
What does it cost to be unable to explain a decision?
The Hamburg data protection authority fined a financial services provider EUR 492,000, reported on 30 September 2025. The firm rejected credit card applications automatically, including from applicants with demonstrably good creditworthiness, without human oversight. The regulator's finding was not that the model was wrong. It was that the company did not adequately explain the logic behind its algorithmic decisions, nor provide sufficient access to the underlying rationale when asked.
The authority expressly treated the firm's cooperation as a significant mitigating factor. That was the discounted price.
The gap that will actually catch carriers
Grant Thornton's 2026 AI Impact Survey, fielded 23 February to 18 March 2026 across 950 executives including 100 in insurance, found:
of insurance leaders say their boards have established AI governance policies.
say their AI controls exist, but the evidence is fragmented across teams and tools.
are very confident they could pass an independent AI governance review within 90 days.
say governance or compliance challenges have contributed to AI project failure or underperformance.
Grant Thornton's own reading: “Most insurers already have AI governance policies in place, but they haven't built the operational infrastructure to prove and test them.”
The distance between 61 and 24 is the whole problem. That same fragmentation is what strands pilots short of production, for the same reason: it is structural rather than a modelling defect and it is found late. We covered that pattern in why claims AI pilots stall before production readiness.
A policy is a claim about how you behave. Evidence is proof that you did. Supervisors examine the second.
Why the 2027 date does not help
Field-level provenance, tamper-evident decision logs and versioned, reproducible decision records are architectural properties. They are determined when the pipeline is designed and they cannot be added afterwards, because a log written without provenance cannot be enriched with provenance later. The decision it recorded is gone.
This is why audit-readiness and audit-preparation are different things. Preparation is an exercise you run before an examination. Readiness is a property the system either has while it runs or does not have at all. Only one of them answers a question about a claim closed last year.
An explanation is an opinion about a decision. Provenance is evidence of one. Dun & Bradstreet asks what the system would have produced from different inputs. Only the second can answer. The architecture we use to produce it is set out in auditability in claims AI: building evidence chains that auditors actually accept.
There is a design consequence worth stating plainly. The more of a decision that runs on deterministic rules rather than a model, the less of it needs explaining under a comparative standard, because the rule is the explanation. On a European vehicle warranty programme we route 80 to 90% of line items through deterministic logic, with the model confined to document understanding. That is an architectural choice with a compliance dividend, not a compliance measure bolted on afterwards.
The test worth running this week
Take one closed claim from last year. Ask your team to reconstruct the decision: every field and where it came from, which model version ran, what a human changed and on what basis.
If that takes one click, you can answer a supervisor under any of the regimes above. The 2027 date is a formality.
If it takes a quarter, you have found the real deadline. It was not 2 December 2027. It was 25 May 2018. The deferral did not move it.
Reconstructing a decision on demand is what MIRA is built to do: agentic document understanding on the input side, deterministic logic on the decision side and a record of both.
Key takeaways
- Claims handling is not listed in Annex III. Only life and health risk assessment and pricing appear, under point 5(c). The Commission's draft classification guidelines of 19 May 2026 give claims management as an example of a system falling outside that point, even in health insurance.
- The Digital Omnibus deferral does not help a claims operation, because the chapter that moved was never the one that governed it.
- GDPR Article 22 is the binding constraint in the EU. It has applied since 25 May 2018. A declined or reduced claim is squarely within it. Swiss and UK operations answer to their own equivalents.
- The Article 6(3) profiling override is a trap for life and health systems only. It cannot rescue or condemn a system that was never in Annex III.
- Policy is not evidence. 61% of insurers have board-level AI governance policies; 24% believe they could pass a governance review in 90 days.
Frequently asked questions
Is AI claims handling high-risk under the EU AI Act?
No. Annex III does not list claims handling. Point 5(c) covers risk assessment and pricing for life and health insurance only. The Commission's draft classification guidelines of 19 May 2026 give claims management as an example of a system falling outside that point, even for health insurance products. A motor, property, warranty or commercial-lines claims operation falls outside the high-risk regime, though it remains subject to data protection law and to sectoral insurance law.
Is AI claims handling high-risk in health insurance?
No. Health insurance is the sharpest test of the rule, because underwriting in that line is high-risk. The Commission's draft guidelines still place claims management outside point 5(c) there, on the basis that verifying a claim against policy terms or determining the amount payable is distinct from risk assessment or pricing.
Does the December 2027 deferral apply to claims handling?
It has no effect on it. The Digital Omnibus deferred the date on which high-risk obligations begin to apply. It did not change which systems are high-risk. Claims handling was not among them before the deferral or after it.
What did Regulation (EU) 2026/1744 change?
It deferred the AI Act's high-risk obligations. Standalone Annex III systems move from 2 August 2026 to 2 December 2027. AI embedded in regulated products moves from 2 August 2027 to 2 August 2028. It was published on 24 July 2026 and entered into force on 27 July 2026.
Does GDPR Article 22 apply to an automated claims decision?
Yes, where the GDPR is the applicable regime. Article 22 restricts decisions based solely on automated processing that produce legal effects or similarly significant effects. A declined or reduced claim meets that threshold. It has applied since 25 May 2018 and was unaffected by the AI Act deferral. Operations outside the EU answer to the equivalent provision in their own regime, such as Switzerland's revised Federal Act on Data Protection.
What counts as meaningful human involvement?
Under Article 29 Working Party guidance (WP251rev.01), review must be carried out by someone with the authority and competence to change the decision. Employees rubber-stamping automatically generated outputs do not take a controller outside Article 22.
What must you disclose about the logic of an automated decision?
In Dun & Bradstreet Austria (C-203/22) the CJEU required the procedure and principles actually applied, communicated concisely and intelligibly, including how the outcome would differ had the data been different. Supplying the algorithm itself does not discharge the duty. A trade secret does not permit a blanket refusal.
Related reading
The structural reasons pilots do not reach production.
The architecture behind the reconstruction test above.
The programme the deterministic-routing figure comes from.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026; in force 27 July 2026. eur-lex.europa.eu
- Regulation (EU) 2024/1689 (AI Act), Annex III point 5; Article 6(3) and 6(4); Article 49(2). artificialintelligenceact.eu
- European Commission, Draft Guidelines on the classification of high-risk AI systems (Annex III volume), 19 May 2026; consultation closed 23 June 2026; non-binding. digital-strategy.ec.europa.eu
- CJEU, OQ v Land Hessen (SCHUFA), C-634/21, 7 December 2023.
- CJEU, CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria GmbH, C-203/22, 27 February 2025.
- Article 29 Working Party, Guidelines on Automated individual decision-making and Profiling, WP251rev.01, endorsed by the EDPB.
- EIOPA, Opinion on Artificial Intelligence governance and risk management, EIOPA-BoS-25-360, 6 August 2025. eiopa.europa.eu
- Hamburg Commissioner for Data Protection and Freedom of Information, EUR 492,000 fine, reported 30 September 2025.
- Grant Thornton, 2026 AI Impact Survey Report, insurance findings; fielded 23 February to 18 March 2026, 950 executives, 100 in insurance. grantthornton.com
Regulatory position stated as at 31 July 2026. This is not legal advice. Confirm classification and sequencing for your own systems with qualified counsel.
Key Takeaways
- Claims handling is absent from Annex III
- The Digital Omnibus deferral changes nothing for claims
- GDPR Article 22 has bound claims decisions since 2018
- Article 6(3) profiling override applies to life and health only
- EIOPA expects explainability under existing sectoral law
- Policy is not evidence: 61% have policies, 24% could prove them
Related Topics
Can You Reconstruct Last Year's Decision?
We build claims systems where every decision can be rebuilt from the record it produced at the time.