On May 7, 2026 the European Parliament and Council reached a provisional political agreement under the Digital Omnibus package deferring the EU AI Act Annex III high-risk deadline from August 2, 2026 to December 2, 2027. For life and health underwriting that is 16 more months before conformity assessments, bias testing, and human oversight must be running. None of the technical requirements changed, and one of them now carries a measured capital price.

Key Takeaways

  • 16 additional months for standalone Annex III high-risk AI, moving August 2, 2026 to December 2, 2027, with the substance of Articles 9 through 15 of Regulation (EU) 2024/1689 untouched.
  • 7% above actuarial value is what protected groups pay in a peer-reviewed MDPI Risks study of 12.4 million quote-bind-claim observations from four pan-European insurers.
  • Only life and health risk assessment and pricing falls under Annex III Category 5(c). P&C rating models sit outside the high-risk tier and face Article 50 transparency duties at most.
  • 8.9% supervisory detection probability is the breakeven above which proactive debiasing costs less than the expected fine plus the incremental Solvency Capital Requirement.
  • Up to 35 million EUR or 7% of global turnover is the EU penalty ceiling, against market conduct examination authority on the US side.

What the Deferral Moved, and What It Left in Place

The Digital Omnibus agreement restructures the timeline without reopening the obligations.

Obligation Original Date New Date Deferral
Annex III high-risk AI (standalone), including insurance underwriting August 2, 2026 December 2, 2027 16 months
Annex I high-risk AI (product safety) August 2, 2027 August 2, 2028 12 months
Article 50(2) watermarking and synthetic content August 2, 2026 December 2, 2026 4 months

Several provisions run on their original dates. Article 5 prohibited practices have applied since February 2, 2025, as have the Article 4 AI literacy obligations requiring insurers to employ staff with a sufficient level of AI literacy. The GPAI requirements under Articles 50 through 55 are already active.

Two things limit how much relief this is. The agreement is provisional and still needs formal endorsement from Parliament and Council. And the self-assessment registration requirement under Article 6(3) survived, despite the Commission proposing to remove it, so an insurer that classifies a system as non-high-risk under Annex III must still register it in the EU database and document why.

The scope is also narrower than most summaries imply. Annex III Category 5 reaches insurers twice: 5(a) covers creditworthiness assessment, catching credit-based insurance scores, and 5(c) covers risk assessment and pricing in life and health insurance. Auto rating and homeowners risk scoring are not high-risk, though a model that interacts directly with consumers can still fall under Article 50. The compliance burden lands on life and health teams, not P&C pricing units.

One boundary is unsettled. The Harvard Data Science Review analysis by Hacker and Eber reads the Act as capturing a wide spectrum of technologies including more traditional machine learning frameworks. On that reading a GLM feeding an underwriting decision is in scope, and a documentation obligation attaches to models actuaries have long treated as transparent by construction.

Where the Bias Figure Becomes a Capital Figure

The MDPI Risks study by Mahajan, Agarwal, and Gupta covers 12.4 million quote-bind-claim observations from four pan-European insurers spanning 2019 Q1 through 2024 Q4. Protected groups paid up to 7% above actuarial value. The distortion persists after gender, ethnicity proxy, disability status, and postcode deprivation index are excluded from training; SHAP analysis attributes most of the uplift to socio-economic proxies, chiefly occupation and urban density.

The paper's actuarial contribution is what it does with that 7%. A pricing distortion of that size inflates loss-ratio volatility in the protected segments, and that volatility feeds the quantiles calibrating the Solvency II Standard Formula SCR. The authors derive a closed-form mapping from three legal fairness metrics to the SCR, with feed-through from Quantitative Reporting Template S.25 filings.

The implication is that a biased book holds more capital than a debiased one, all else equal. Bias stops being a conduct-risk footnote and becomes a line item an appointed actuary can size in an ORSA.

Which remedy works is narrower than expected. Only adversarial debiasing closed the gap below the materiality threshold without degrading predictive power. Reweighting and threshold adjustment either failed the fairness bands, a disparate impact ratio of 0.80 to 1.25 and 0.10 tolerances on statistical parity difference and equalized odds gap, or cut discrimination far enough to hurt pricing accuracy. The economic test is a detection probability of 8.9%, above which debiasing is cheaper than the expected fine plus incremental SCR.

For a carrier writing in both markets, the EU number sets the constraint. Penalties reach 35 million EUR or 7% of global turnover, against Colorado DOI examination authority and a NAIC evaluation tool that is voluntary through its 12-state pilot.

The Fairness Definition the Act Does Not Settle

EIOPA's Opinion on AI Governance and Risk Management names the actuarial function as responsible for controls on AI systems within its remit, and sets five fairness metrics in its Annex I: demographic parity, calibration, equalized odds, equalized opportunities, and individual fairness.

It also states plainly that some of the group fairness metrics could contradict actuarial fairness, where customers bearing the same risk are charged the same price. The Act does not resolve that conflict, and neither does the Opinion.

This is the load-bearing problem for whoever owns compliance. Clearing a demographic parity test can require charging two policyholders with the same expected loss different prices, which is the outcome risk classification exists to prevent. Forvis Mazars argues actuaries are the natural owners of the role because they already run model validation. But that validation is built to test predictive accuracy and reserve adequacy, and it offers no tiebreak when two defensible fairness definitions point opposite ways.

The second unresolved item is vendor exposure. EIOPA holds insurers ultimately responsible for the AI systems they use, whether developed in-house or with a third party. A carrier licensing an underwriting model inherits the documentation, bias testing, and oversight duties for a system whose training data demographics it may never see, and the deferral does nothing about that. Colorado made the same allocation in its own rewrite of the general AI law, which leaves the insurance-specific testing regime standing on its own timeline.

Further Reading

Sources