The forthcoming implementation of the European Union’s Artificial Intelligence Act (AI Act), set to take effect in February 2025, is poised to have profound impacts across a variety of sectors, with a particularly notable influence on the insurance industry. The Act outlines stringent measures governing the use of AI technologies, categorised by varying levels of risk, and offers a framework aimed at regulating AI usage to enhance security, transparency, and reliability.
Specifically, the insurance sector will see its AI applications classified under four risk tiers: minimal, limited, high, and unacceptable. Minimal risk use cases, which involve AI in roles such as document classification or search engines, will not be subjected to new regulatory obligations. Limited risk applications, such as customer service chatbots and fraud detection systems, will require documentation of AI decision-making processes and user awareness of AI deployment.
Significantly, core insurance functions like underwriting, life and health pricing, claims processing, and training are identified as high-risk. For these, extensive measures will be necessary, including updates to risk management processes and ensuring human oversight to mitigate AI malfunctions. Additionally, insurance providers must document AI development and operations diligently to maintain compliance and demonstrate this to relevant authorities. The robustness and security of AI systems must also be assured through specific scientific and technological steps.
Certain applications deemed to pose an unacceptable risk, such as those involving social scoring or sensitive biometric data, will face outright prohibition under the new regulation. The complexities of these regulations are further underscored by the nuances involved in cross-category use cases, where the highest applicable risk rating must be adhered to. For example, the use of voice recognition in fraud detection could be considered high risk due to its involvement of biometric data.
Large language models also fall under specific regulatory scrutiny, though the onus of compliance primarily rests on the developers of these third-party systems rather than the insurers who integrate such technologies. Insurers, nevertheless, will need to adjust their procurement and partner evaluation processes accordingly.
The introduction of the AI Act comes amidst a landscape already populated by various regulatory frameworks, such as Solvency II and GDPR. Often, these frameworks overlap, meaning the transition to compliance with the AI Act may be less cumbersome for insurers already adhering to pre-existing regulations. The Act’s extraterritorial reach means non-European insurers deploying AI in Europe, or impacting EU citizens, will also be required to comply.
Successful adaptation to these new regulations may entail the formation of multidisciplinary AI governance teams within insurance companies. These teams, comprising experts from business, compliance, data science, IT, and legal sectors, will be key in navigating the legislative nuances of the Act. Upskilling data science and engineering teams will also be crucial to build AI systems that comply with the new standards, leveraging emerging tools and techniques to enhance transparency and security.
Additionally, the European Commission plans to publish a list of standards to guide compliance efforts, with ISO 42001 anticipated to cover AI governance requirements extensively. Companies adhering to these standards will be deemed compliant with the Act.
The AI Act is more than a regulatory hurdle; it provides an opportunity for the insurance industry to enhance its technological capabilities, increase transparency, and foster trust in AI systems. By adhering to these guidelines, the insurance industry may experience improved reliability and effectiveness of their AI technologies, potentially leading to better market adoption and return on investment.
Vlad Flamind, a Lead Data Consultant at global technology consultancy firm Zühlke, highlights that while compliance is a necessary step, the AI Act's broader implications can serve to guide the responsible and profitable integration of AI in insurance operations.
Source: Noah Wire Services