By use case · Written by Yobel Tzegai · Last checked 9 October 2026

Is AI insurance pricing high-risk under the EU AI Act?

AI insurance pricing under the EU AI Act: life and health insurance are point 5(c) of Annex III; motor and property pricing are not on the list.

Check your AI systems, freeBook a 30-minute walkthrough

The answer, in detail

Where an insurance use usually sits
UseUsual outcomeProvisionWhat would change it
Risk assessment and pricing for life or health coverHigh-riskPoint 5(c) of Annex IIIAn Article 6(3) assessment; never where it profiles natural persons
Pricing motor, home or travel insuranceNot high-risk under Annex IIIArticle 6(2), and point 5(c), which names life and health onlyA credit check on the customer, point 5(b) of Annex III
Detecting claims fraudNot listed in Annex IIIAnnex III, which does not list itPredicting a person will commit an offence based solely on profiling, Article 5(1), first subparagraph, point (d)
A claims chatbotA transparency duty for its providerArticle 50(1)Obvious to a reasonably well-informed, observant and circumspect person

What is in point 5(c)?

What does the insurer owe as deployer?

What can the policyholder ask for?

An explanation of the role the system played in a decision that produces legal effects or similarly significantly affects them.

Your customer asks. You answer with proof.

  1. 1List every AI system

    Add the AI you use. Each system gets a role, a risk class and the article it rests on.

    Live
  2. 2Attach the proof

    Link each duty to a file and the page it stands on: a policy, a log setting, a training record.

    Live
  3. 3Answer their questionnaire

    Answering a customer's questionnaire inside the app, from the proof you already linked.

    Coming soon

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • AI inventory Every AI system you build or use, with its owner and risk class
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
  • Deadlines Each obligation carries the date it applies from, derived from where the provision sits rather than written onto the row

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Fundamental rights impact assessment (Article 27) Not supported The step-by-step plan lists Article 27 as a step only for systems classified under points 5(b) and 5(c) of Annex III. Article 27(1) also binds deployers that are bodies governed by public law or private entities providing public services, and the product does not ask whether you are one. Nothing carries the assessment itself.
  • Conformity assessment (Article 43) Not supported We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb.
  • EU database registration (Article 49) Not supported Listed as a duty with its date. The registration itself is yours.

What is live today

Checked against the app on 8 October 2026
Starter

€499 a month

Prices exclude VAT.

  • Up to 20 AI systems
  • Every duty, deadline and article
  • Evidence and the audit log
  • Your first system is free, with no end date
Check your AI systems, free

All plans

Questions

Is claims fraud detection high-risk?

Annex III does not list it. Point 5(b) excepts systems used to detect financial fraud from the credit point, and point 5(c) covers risk assessment and pricing. A system that predicts a person will commit a criminal offence based solely on profiling or personality traits is prohibited by Article 5(1), first subparagraph, point (d), with its exception.

Can we reuse our GDPR impact assessment?

In part. Under Article 27(4), as replaced by Regulation (EU) 2026/1744, where an obligation is already met through a data protection impact assessment under Article 35 of the GDPR, the deployer may cross-reference its relevant sections or include relevant parts in the fundamental rights impact assessment. The rest is still to be done.

Read next
See what your customers will ask about your AI.No account needed. Every answer cites the article it rests on.