EIOPA's Generative AI Market Survey, published February 2026 under reference EIOPA-BoS-25-679, collected responses from 347 insurance undertakings across 25 EU and EEA countries, covering roughly 80% of European gross written premium.
Two findings sit against each other. About two-thirds of respondents actively use generative AI. Dedicated AI policies exist at 49%, less than two months before the EU AI Act's high-risk provisions take effect on August 2, 2026.
Key Takeaways
- 347 undertakings across 25 countries, fielded through national competent authorities rather than voluntarily, covering approximately 80% of EU gross written premium. It is the largest regulator-administered AI adoption survey in global insurance.
- Roughly 65% actively use generative AI, but most deployments remain at proof-of-concept rather than production.
- Dedicated AI policies doubled from 25% in 2023 to 49%, which still leaves more than half of European insurers without a formal framework ahead of the August 2, 2026 deadline.
- 64% of use cases are backend productivity tools and 36% customer-facing, with the customer-facing pipeline active but largely pre-production.
- Hallucinations rank as the single most cited risk, ahead of cybersecurity, data protection and regulatory compliance.
What EIOPA Measured
The sample is what separates this from every other AI adoption number in circulation. EIOPA fielded the survey from May 2025 through national competent authorities, which gives it reach into undertakings that never answer a voluntary industry questionnaire. Consulting surveys typically run 100 to 200 self-selected respondents; this one covers 347 life, non-life and composite insurers representing about 80% of European premium.
Adoption is at roughly 65%, which EIOPA characterizes as swift but cautious. Both halves hold. Generative AI went from essentially no presence in European insurance operations in early 2023 to two-thirds penetration in about two years, in an industry whose technology cycles historically run five to seven years from pilot to broad deployment. And most of that penetration is proof-of-concept rather than production, the same gap visible in U.S. data where adoption far outruns scale.
Governance moved too, from 25% of undertakings holding dedicated AI policies in 2023 to 49% now. As a trend that is fast. As a level, against a hard regulatory date, it means the survey's bottom half arrives at August 2 without a framework.
For context on the baseline, EIOPA's 2024 Digitalisation Report had already found 50% of non-life and 24% of life insurers using AI in some form across the value chain. The GenAI wave landed on top of that, not instead of it.
Calling It a Pilot Does Not Control the Classification
The use case split shows where insurers placed their first bets. Backend productivity tools account for 64%: data extraction from invoices, audio and medical reports, content generation, coding assistance, and underwriting support. Customer-facing applications are the other 36%, mostly chatbots, voice assistants and automated response systems, and mostly still pre-production.
The sequencing is deliberate. Backend tools keep a human checkpoint between the model output and anything a policyholder sees, which is lower risk and easier to supervise while confidence and evidence accumulate.
What that sequencing does not do is control the regulatory classification, and this is where the proof-of-concept concentration becomes a problem rather than a caution. Annex III of the AI Act classifies systems used for life and health insurance underwriting and pricing as high-risk. A pilot that touches underwriting or claims data may already meet that definition, because the classification turns on the function and the data, not on whether the insurer has finished evaluating it.
The obligations then arrive in pairs. Providers carry Articles 9 through 17. Deployers carry Article 26 plus fundamental rights impact assessment under Article 27, conformity verification, human oversight protocols and documentation. An insurer running a vendor's model in a high-risk context holds the deployer set even though it built nothing, and cannot discharge it by pointing at the vendor's compliance.
That matters at this survey's dependency profile. EIOPA finds insurers depend heavily on external providers and pre-trained models, extending a 2024 split of 66% in-house against 34% outsourced further toward vendors, because only the largest European groups can justify training models internally. Most of the 347 therefore hold deployer obligations over systems whose architecture, training data provenance and validation procedures they can describe only as far as the vendor lets them.
The Top-Ranked Risk Is Not a Governance Gap
Respondents ranked hallucinations first among generative AI risks, ahead of cybersecurity, data protection and regulatory compliance.
| Risk Category | Ranking | Regulatory Nexus |
|---|---|---|
| Hallucinations / inaccurate outputs | 1 (most cited) | EU AI Act accuracy requirements; Solvency II ORSA |
| Cybersecurity threats | 2 | DORA (effective Jan 2025); AI Act robustness |
| Data protection risks | 3 | GDPR; AI Act data governance |
| Regulatory compliance challenges | 4 | EU AI Act; IDD; Solvency II |
In an insurance context the ranking is a statement about output reliability at the point of use. A hallucinated output in underwriting produces an incorrect risk assessment. In claims it produces a fabricated coverage interpretation. In service it communicates policy terms that do not exist. Each creates financial exposure and regulatory liability on the deployer's side of the Article 26 line.
The IFoA's June 2026 work on GenAI risks reaches the conclusion that makes the survey's governance number harder to read as reassuring: the core risks are structural features of the technology, not governance gaps a better framework eliminates. Moving dedicated AI policies from 49% to 100% would improve documentation, oversight and escalation. It would not change the rate at which a model asserts something false.
The second and third ranked risks compound through the same vendor channel. Integrating third-party models opens new data pathways, and GenAI vendors sit squarely inside the scope of the Digital Operational Resilience Act, effective January 2025, which requires ICT risk management frameworks covering third-party providers. Data protection sits at rank three because pre-trained external models put policyholder data through processing the insurer did not specify, against GDPR purpose limitation and data minimisation.
DORA and the AI Act are the two tools EIOPA names for the dependency, and they stack rather than substitute: DORA wants contractual assurance from the provider, the AI Act wants the deployer to verify conformity assessment. Every vendor relationship carries both. That is the compliance layer arriving for a population where training and readiness investment is being cut rather than raised, and where most of the systems in question are still labelled pilots.
Further Reading on actuary.info
- IFoA Report Warns GenAI Risks in Insurance Are Structural, Not Fixable - The nine-risk framework from the IFoA's June 2026 report maps GenAI's inherent limitations, including hallucinations, against actuarial standards and regulatory expectations.
- Celent: 48% of Insurers Run GenAI in Production - The global adoption baseline that puts EIOPA's European findings in context, with three years of longitudinal survey data tracking the early-to-late majority transition.
- Insurer AI Adoption Hits 82% But Only 7% Reach Full Scale - Sedgwick's scalable-success metric explains why broad adoption rates coexist with low enterprise deployment, a pattern the EIOPA proof-of-concept data confirms for Europe.
- One in Five Insurers Deploys AI While Cutting Training Budgets - Covenir's U.S. survey documents the workforce readiness deficit that parallels EIOPA's finding of AI skills shortages constraining European adoption.
- ASOP 12 Exposure Draft Targets Unintended Bias in Pricing Models - The fairness requirements in EIOPA's AI governance opinion and the EU AI Act's non-discrimination provisions connect directly to the ASB's parallel work on bias in actuarial models.
Sources
- EIOPA, "Generative AI Market Survey: Outlook, Use Cases and Risk Management" (EIOPA-BoS-25-679), February 2, 2026. eiopa.europa.eu
- EIOPA, Generative AI Market Survey Full Report (PDF). eiopa.europa.eu
- WTW, "The Impact of Generative AI on Insurance Analytics: 8 Perspectives from EIOPA's Market-Wide Study," April 2026. wtwco.com
- EIOPA, "Opinion on AI Governance and Risk Management" (EIOPA-BoS-25-360), August 6, 2025. eiopa.europa.eu
- NAIC, "Artificial Intelligence and State Insurance Regulation" Issue Brief, March 2026. naic.org
- NAIC, AI Systems Evaluation Tool Pilot Program, 12 states, January-September 2026. fenwick.com
- Covenir, "2026 Insurance Operations Leaders Trends Report," 152 U.S. executives surveyed, February-March 2026. insurancejournal.com
- EU Regulation 2024/1689 (AI Act), Article 6, Annex III. artificialintelligenceact.eu
- Celent, "3rd Annual GenAI-oneers in Insurance," Q1 2026. celent.com
- Grant Thornton, "Insurance Insights: 2026 AI Impact Survey Report," 100 insurance executives. grantthornton.com
- EIOPA, "Report on the Digitalisation of the European Insurance Sector," 2024. eiopa.europa.eu
- IFoA and LFBF, "It's Still Not Magic: GenAI Risks in Insurance," June 2026. ifoa.org.uk
We are seeking feedback on how to improve the site and deliver high-quality content relevant to actuaries. Help us make it better.
Stay ahead with daily actuarial intelligence - news, analysis, and career insights delivered free.
Subscribe to Actuary Brew Browse All Insights