Deep Dive Why underwriting AI is treated as high-risk Systems used to assess and price risk for insurance are named directly in the Act's high-risk categories, because they materially affect a person's access to coverage. That classification isn't something a vendor's marketing can talk its way out of; it follows from what the system does. What Article 26 asks of the insurer, not just the vendor A deployer can't simply rely on a vendor's conformity paperwork. The insurer has to assign a named person with real oversight authority, monitor the system against live decisions rather than a one-time test, and be able to show that oversight is actually happening in production, not just documented on paper. What this looks like built in, rather than bolted on An audit logging layer that captures every risk-relevant event tied to an individual decision, a human oversight checkpoint with real visibility and override authority before a decision is finalised, and consistent rule enforcement across every case, not just the ones flagged for review.

