The EU AI Act's high-risk obligations for life and health underwriting AI no longer take effect on August 2, 2026. The Council of the EU gave final approval to the Digital Omnibus on June 29, 2026, after the European Parliament's endorsement on June 16, deferring the Annex III standalone deadline to December 2, 2027 and embedded high-risk systems to August 2, 2028.

That is a correction worth stating plainly. Our own April analysis treated August 2 as the operative date for conformity assessments and bias testing, and it was, at the time, the legally binding date. It is not now. We covered the provisional deal in May; the deadline has moved twice this year.

Key Takeaways

  • December 2, 2027 is the new Annex III standalone high-risk deadline, with embedded systems at August 2, 2028. Article 5, Article 4 and the GPAI obligations under Articles 51 through 55 did not move at all.
  • December 2, 2026 is now the nearer date. Article 50(2) transparency for AI-generated content slipped four months, against the sixteen-month reprieve Annex III systems received.
  • €15 million or 3% of worldwide turnover is the statutory maximum for the Article 16 and Article 26 obligations governing underwriting AI, not the €35 million or 7% ceiling attached to Article 5 prohibited practices.
  • Paragraph 3.30 of EIOPA's August 2025 Opinion names the actuarial function as responsible for controls on AI systems in its remit, but stops short of saying it discharges Article 14 human oversight.
  • Annex III category 5(c) still captures life and health risk assessment and pricing. EIOPA's requested carve-out for generalized linear models did not survive into the final text.

What August 2, 2026 Still Requires

Three obligations remain on their original timeline regardless of the deferral, and none of them are new. Article 5's prohibited practices, covering manipulative techniques, exploitation of vulnerable groups and unlawful biometric categorization, have applied since February 2, 2025. Article 4's AI literacy requirement took effect the same date, obligating insurers to ensure staff operating or overseeing AI systems hold a "sufficient level of AI literacy". General-purpose AI obligations under Articles 51 through 55 have applied since August 2, 2025.

One deadline moved closer rather than further away. Article 50(2) transparency for AI-generated or synthetic content shifted from August 2, 2026 to December 2, 2026, a four-month delay against the sixteen-month reprieve applied to Annex III (Gibson Dunn, June 2026). For carriers using generative AI in claims correspondence or chatbot-mediated interaction, that labeling requirement is now the nearer item on the calendar.

The penalty figure most compliance memos cite belongs to a different tier. The €35 million or 7% of global turnover ceiling attaches to Article 5 prohibited-practice violations. Provider obligations under Article 16 and deployer obligations under Article 26, which govern conformity assessments, technical documentation and human oversight for underwriting AI, cap at €15 million or 3% (Article 99(4)). A third tier, misleading information to regulators, caps at €7.5 million or 1%, and SMEs face whichever amount is lower.

Annex III's scope itself did not change. Category 5(c) still captures "AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance", with P&C underwriting outside the classification. EIOPA had argued that including traditional generalized linear models "would not materially reduce the risks associated with these models". That carve-out did not survive into the final text.

Obligation Original Date Confirmed New Date Status as of July 2026
Article 5 prohibited practices February 2, 2025 Unchanged In force since Feb. 2025
Article 4 AI literacy February 2, 2025 Unchanged In force since Feb. 2025
GPAI model obligations (Arts. 51-55) August 2, 2025 Unchanged In force since Aug. 2025
Annex III standalone high-risk (life/health underwriting) August 2, 2026 December 2, 2027 Formally adopted, entering into force July 2026
Article 50(2) synthetic content labeling August 2, 2026 December 2, 2026 Formally adopted
Annex I embedded high-risk (product safety) August 2, 2027 August 2, 2028 Formally adopted

The Article 14 Overseer Nobody Has Named

The obligation that survived both rounds of negotiation intact is the one with no owner on most carrier org charts.

Article 14 requires high-risk systems to be designed so a natural person can "properly understand the relevant capacities and limitations" of the system, correctly interpret its output, and remain capable of detecting anomalies, dysfunctions and unexpected performance, including resisting automation bias. For a life or health pricing model that maps closely onto what a credentialed actuary already does when validating a rating plan: interrogate model behavior, flag anomalous output, exercise professional judgment before a rate structure reaches production.

The overlap is not automatic. Nothing in Article 14 names the actuary. EIOPA's August 2025 Opinion on AI governance and risk management gets closer without closing it: paragraph 3.30 names the actuarial function as "responsible for the controls on AI systems that fall under its responsibilities", which reads as an endorsement of the actuary-as-overseer model but does not state that the actuarial function satisfies Article 14 as a matter of law.

The distance between an actuary who validates the model and an actuary who is the designated Article 14 overseer of record is a documentation problem rather than a competency one, and the deferral did not touch it. Article 14 obligates providers and deployers to build the human-oversight function into the system's design and operating procedure. Having a qualified person somewhere in the org chart who could plausibly do the job does not discharge that.

A defensible position assigns the role explicitly to a named actuarial function with documented authority to halt or override model output, records the training that qualifies that person under Article 14(4)'s competence requirement, and separates that role in writing from the IT model owner who maintains infrastructure without exercising the judgment the article contemplates. At the €15 million or 3% tier, what is missing at most carriers is not the analysis. It is a governance document naming who performs it.

Two Supervisory Files for One Book

A global carrier writing both EU and US life and health business now documents the same controls twice, in two formats, for two audiences.

EIOPA folds AI governance into existing Solvency II sectoral law rather than building a parallel AI-specific regime. Its six pillars, fairness and ethics, data governance, documentation and record-keeping, transparency and explainability, human oversight, and accuracy, robustness and cybersecurity, are principles the actuarial and risk functions operationalize using judgment calibrated to a system's materiality. There is no template to fill in; supervisors assess whether an existing governance framework has been credibly extended to AI-specific risk.

The NAIC's approach is standardized and examination-ready. The twelve-state AI Systems Evaluation Tool pilot, running through September 2026, gives examiners a common rubric: Exhibit A quantifies AI usage, Exhibit B assesses governance risk, Exhibit C catalogs high-risk systems, Exhibit D captures data provenance. A proposed third-party vendor registry would extend the same standardization to models a carrier did not build but remains responsible for, and the Model Bulletin reporting structure supplies the filing form.

The two regimes agree on substance. Both hold insurers accountable for vendor-built AI, and both expect bias testing and human oversight. What differs is the file itself: a principles-based narrative calibrated to EIOPA's six pillars against standardized exhibits mapped to a specific rubric. Building one artifact that satisfies both is what the extended runway actually buys, and EIOPA's supervisory convergence review lands in 2027, alongside the deferred deadline.

The deferral is not blanket cover. AI-related conduct risk remains examinable under Solvency II's system-of-governance requirements regardless of AI Act timing, so a governance failure that would independently breach sectoral law is exposed now rather than in December 2027. Separating what the AI Act requires by that date from what insurance sectoral law already requires of any automated decision system is the distinction the moved deadline has made easiest to lose.

Further Reading


Sources

  1. Council of the European Union, “Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules,” consilium.europa.eu, June 29, 2026
  2. Freshfields, “EU AI Act Unpacked #34: The Final Digital Omnibus on AI,” freshfields.com, June 2026
  3. Gibson Dunn, “EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines and Other Key Changes,” gibsondunn.com, June 2026
  4. Center for Democracy and Technology, “Final AI Omnibus Text Dilutes Fundamental Rights Protections,” cdt.org, June 2026
  5. EU Artificial Intelligence Act, Article 14: Human Oversight, artificialintelligenceact.eu (EUR-Lex, Regulation (EU) 2024/1689)
  6. EU Artificial Intelligence Act, Article 99: Penalties, artificialintelligenceact.eu (EUR-Lex)
  7. EU Artificial Intelligence Act, Annex III: High-Risk AI Systems Referred to in Article 6(2), artificialintelligenceact.eu
  8. EIOPA, “Opinion on AI Governance and Risk Management” (EIOPA-BoS-25-360), eiopa.europa.eu, August 2025
  9. EIOPA, Letter to EU Institutions on AI Act and EU Insurance Legislation Proposal, eiopa.europa.eu, 2026
  10. Greenberg Traurig, “AI Patent and Compliance Outlook for 2026,” gtlaw.com, 2026
  11. Fenwick, “Tracking the Evolution of AI Insurance Regulation,” fenwick.com, 2026
  12. NAIC, Insurance Topics: Artificial Intelligence, content.naic.org, 2026