The European contrast: a more prescriptive regime
Building on the UK’s supervisor-led, principles-based approach to AI in insurance, the EU has taken a more formal and prescriptive approach with the introduction of the AI Act, which applies from 2024. The Act adopts a risk-based classification of AI systems, and strongly supports consumer protection by safeguarding rights, fairness, and transparency.
Under this framework, certain AI applications in life and health insurance, particularly those used in pricing and underwriting, are classified as “high-risk”.
High-risk systems are subject to detailed requirements, including:
- Data quality and bias controls
- Comprehensive documentation and record-keeping
- Human oversight mechanisms
- Ongoing monitoring and risk management
Since the introduction of the EU AI Act, the EU’s Digital Omnibus has refined the Act by easing compliance burdens and delayed key requirements, giving firms more time to prepare whilst maintaining the overall regulatory direction. High-risk AI obligations have been pushed to December 2027 for standalone high-risk systems and August 2028 for high-risk AI systems embedded in regulated products, subject to the Omnibus taking legal effect through formal adoption and publication.
The AI Act places requirements on providers of AI systems, as well as the users, which may prove beneficial for EU based insurers in ensuring compliance when using third party tools. However, users continue to have specific obligations under the Act. Where AI solutions are sourced from third-party providers, insurers remain fully accountable for regulatory compliance. This creates challenges where proprietary models limit transparency, requiring firms to establish appropriate due diligence, contractual safeguards and ongoing monitoring.
While AI offers significant benefits for financial institutions, such as improved efficiency, risk management, and customer outcomes, it also introduces material risks, particularly around model risk data quality, cyber threats, and third-party dependencies. The FSB published in June 2026 a consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). While the report does not create binding requirements, it sets out 12 sound practices covering both organisation-wide governance (including board accountability, clear roles, and integration into risk frameworks) and AI lifecycle management (from design and data governance to testing, monitoring, and human oversight). A key principle is that AI risks should be managed proportionately to their materiality, with stronger controls for critical use cases and continuous monitoring as models evolve.
This fragmented approach means that insurers operating in both the UK and EU must navigate two different but overlapping frameworks. While the UK emphasises principles and outcomes, the EU introduces more formal compliance obligations tied to risk classification.
EIOPA has published an opinion last year (Opinion on AI governance and risk management) clarifying how existing insurance regulation, including Solvency II and the Insurance Distribution Directive, should be applied to the use of AI systems. Rather than creating a separate AI regime, this guidance reinforces the expectations for management of AI-related risks. For example; bias, model opacity, and reliance on third-party providers.
These should be managed within established governance, risk management and conduct frameworks. In particular, insurers are expected to ensure that AI supports fair customer outcomes, robust controls and clear accountability across the AI lifecycle, consistent with existing prudential and conduct requirements. EIOPA’s Opinion clarifies how these existing frameworks apply to AI in insurance, following a risk‑based and proportionate approach, without introducing a separate AI regime.
Overall, while EU supervisors retain an important role in interpretation and enforcement, their approach is more tightly anchored in codified requirements than in the UK, highlighting a shift from supervisory discretion toward rule-driven oversight.
To better understand the impacts of the act for the financial sector, including an update on the changes introduced by the Digital Omnibus, read our article: AI in the EU financial sector, balancing regulation and innovation.
The US direction of travel: governance and fairness
In contrast to the principles‑based approach relying on existing regulatory frameworks, and the EU’s harmonised rulebook, the US approach to AI in insurance reflects a fragmented, state-led supervisory landscape, where regulatory expectations are shaped through a combination of model laws, guidance, and enforcement activity.
The National Association of Insurance Commissioners’ (NAIC) model bulletin on AI use by insurers, published in 2023[4], has been adopted by multiple states and sets out expectations for governance, transparency and fairness. It is principles-based and must be implemented by individual states, resulting in varying levels of adoption and consistency.
The bulletin emphasises that insurers remain responsible for compliance with existing laws, including those prohibiting unfair trade practices and discrimination. It also recommends the implementation of a formal AI governance programme, including testing, validation, documentation and oversight by senior management.
Although less centralised than the EU regime, US expectations reinforce similar themes to FCA supervision, particularly around accountability, governance and fair outcomes, but through a more fragmented and enforcement-driven model.
This results in a supervisory approach that, compared with the UK, is defined by evolving supervisory practice across states rather than a single, articulated regulatory framework, reinforcing the importance of regulator-specific engagement and interpretation.
At the same time, the direction of travel remains uncertain, with growing tension between state-led regulation and emerging federal initiatives aimed at shaping a lighter, nationally consistent AI framework. This creates a dynamic regulatory environment, where insurers must manage fragmentation and the risk of future regulatory realignment.