Decisão em minutos · auditável · explicável Straight-through processing como padrão Plataforma de IA para seguros Em conformidade com LGPD Decisão em minutos · auditável · explicável Straight-through processing como padrão
Voltar para Insights & News
· Artigo

Is AI Underwriting High-Risk? EU, US, Brazil 2026

Yes, AI underwriting is high-risk under the EU AI Act when used for risk assessment or pricing in life and health insurance (Annex III). As of 2026, that classification brings obligations around data governance, transparency, human oversight, and record-keeping for those lines. The United States and Brazil regulate the same underwriting activity through different instruments, but the shared thread across all three regions is auditability, explainability, and human oversight.

Is AI Underwriting High-Risk? EU, US, Brazil 2026

Yes, AI underwriting is high-risk under the EU AI Act when used for risk assessment or pricing in life and health insurance (Annex III). As of 2026, that classification brings obligations around data governance, transparency, human oversight, and record-keeping for those lines. The United States and Brazil regulate the same underwriting activity through different instruments, but the shared thread across all three regions is auditability, explainability, and human oversight.

Is AI underwriting high-risk under the EU AI Act?

AI underwriting is high-risk under the EU AI Act when an AI system assesses risk or sets prices for natural persons in life and health insurance.

The EU AI Act (Regulation 2024/1689) sorts AI systems into risk tiers, and Annex III is the list of high-risk uses. It names AI intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. That language is deliberately narrow. It targets the models that decide who gets covered and at what price in two specific personal lines, because those decisions carry the clearest potential for consumer harm and unfair discrimination. Classification turns on what the system does, not on the label a vendor puts on the product.

High-risk does not mean prohibited. It means the AI system, and the insurer or MGA that deploys it, must satisfy a defined set of obligations before and during use. In practice these include a risk management system, data governance and quality controls, technical documentation, automatic event logging, transparency to the deployer, meaningful human oversight, and appropriate accuracy, robustness, and cybersecurity. Duties fall on both the provider that builds the system and the deployer that uses it, so a carrier cannot outsource its obligations by buying a model off the shelf.

According to the EU AI Act (Regulation 2024/1689), non-compliance with high-risk obligations carries penalties up to 15 million euros or 3% of total worldwide annual turnover.
According to the European Commission (2024), the EU AI Act entered into force on August 1, 2024, and its Annex III high-risk obligations apply from August 2026.

Does the EU AI Act apply to my line of business?

Because the Annex III insurance entry is limited to life and health, your line of business decides most of your exposure. A useful first cut across common portfolios:

  • Life insurance risk assessment and pricing by an AI system is expressly high-risk under Annex III.
  • Health insurance risk assessment and pricing by an AI system is high-risk under Annex III on the same basis.
  • Commercial property, marine, transport, and casualty are not named in the insurance entry, so they generally fall outside the high-risk insurance category.
  • Personal motor and home are not named either, though national supervisors may still apply conduct and anti-discrimination rules.
  • Prohibited AI, such as social scoring or manipulative profiling, is banned outright regardless of the line it touches.

Scope also depends on reach, not only geography. The AI Act can apply to insurers and vendors established outside the EU when the output of the AI system is used inside the EU, so a Brazilian or US carrier writing EU life or health risk can be captured. Where the model's output lands, and which line it serves, matter more than where the head office sits.

What does the NAIC Model Bulletin require in the United States?

The United States has no single federal AI insurance law, so the center of gravity is the states and the NAIC. The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023, and a majority of states have since issued it. The bulletin does not create a hard classification like Annex III. Instead it sets a supervisory expectation that any insurer using AI in decisions affecting consumers maintains a written AI systems program covering:

  • Governance and accountability with board and senior-management ownership of AI risk.
  • Risk management controls that test for accuracy, bias, and unfair discrimination across the AI lifecycle.
  • Third-party oversight with due diligence on vendors and externally sourced models and data.
  • Documentation detailed enough for a regulator to reconstruct how a decision was reached.

States also legislate directly. Colorado SB21-169, enacted in 2021, is an early state-level example. It restricts insurers' use of external consumer data and predictive models and requires them to test for unfair discrimination, with the Colorado Division of Insurance issuing implementing regulations starting in life insurance. The direction of travel is consistent: document the model, test it for bias, and keep a human accountable.

How does Brazil regulate AI underwriting through SUSEP and LGPD?

Brazil has no dedicated AI statute in force as of 2026, so AI underwriting sits under two existing regimes rather than a purpose-built one. SUSEP, the Superintendência de Seguros Privados, supervises insurer solvency and market conduct, and its governance and open-insurance rules increasingly shape how carriers use data and automated models. Layered on top is the LGPD, Brazil's general data protection law, which governs any processing of personal data.

The LGPD is the sharper edge for underwriting. Article 20 gives a data subject the right to request review of decisions taken solely on the basis of automated processing that affect their interests, including profiling. For an insurer that means a practical duty to be able to explain an automated underwriting or pricing decision and to offer a review of it on request. WIR's Brazil-specific view of SUSEP and AI in insurance covers the local detail. The takeaway is that Brazil, like the EU, converges on explainability and a right to review of automated decisions.

The common thread: auditability, explainability, and human oversight

Read side by side, the EU AI Act, the NAIC bulletin, and Brazil's SUSEP-plus-LGPD stack ask for the same three things: a decision you can audit, an explanation you can produce, and a human who can intervene. The vocabulary and legal force differ, but a carrier that can show how each AI-assisted underwriting decision was reached, on what data, and at which human checkpoint, is broadly aligned with all three.

That is a documentation and logging problem as much as a modeling one, and it is where architecture matters. WIR Innovation is an external AI layer for insurers and MGAs that automates underwriting, submission intake, quoting, and decisioning without replacing the core system. Because it sits on top of Guidewire, Duck Creek, Sapiens, or a legacy platform rather than inside it, every submission it structures, every appetite check it runs, and every referral it drafts can be captured with its inputs and rationale, then written back to the system of record. That log is the evidence trail regulators increasingly expect. For the mechanics, see how to audit AI underwriting decisions for compliance and how to keep underwriting decisions auditable by design.

One caveat on positioning. An external AI layer is infrastructure that produces auditable records, not a compliance product, and it does not certify any insurer as compliant. This article is market intelligence, not legal advice. Whether a given system is high-risk under the EU AI Act, in scope of the NAIC bulletin, or subject to SUSEP and the LGPD depends on your specific systems, lines, and jurisdictions, and you should confirm your obligations with qualified counsel.

Perguntas frequentes

Is AI underwriting high-risk under the EU AI Act?

Yes, the EU AI Act treats AI underwriting as high-risk when a system assesses risk or sets prices for people in life or health cover (Annex III). High-risk does not mean banned. It means the insurer and the AI provider must meet obligations on data governance, transparency, human oversight, and record-keeping before and during use.

Does the EU AI Act apply to insurers outside the EU?

The EU AI Act can apply to insurers and vendors based outside the EU when the output of the AI system is used inside the EU. A carrier in Brazil or the United States that writes EU life or health risk can be captured. Where the output lands and which line it serves matter more than the head office location.

What does the NAIC Model Bulletin require in the United States?

The NAIC Model Bulletin sets a supervisory expectation, not a hard classification, that insurers using AI in consumer decisions keep a written AI systems program. It covers governance, controls that test for bias and unfair discrimination, third-party vendor oversight, and documentation a regulator can reconstruct. The NAIC adopted it in December 2023 and a majority of states have issued it.

How does Brazil regulate AI underwriting?

Brazil has no dedicated AI statute in force as of 2026, so AI underwriting sits under SUSEP supervision and the LGPD data protection law. LGPD Article 20 gives a person the right to request review of a decision taken solely by automated processing. In practice, an insurer should explain an automated underwriting decision and offer a review on request.