Artificial intelligence and insurance in 2026: pricing, algorithmic discrimination and new regulatory obligations
The general application of the European Artificial Intelligence Regulation —the AI Act— on 2 August 2026 marks a turning point in the use of algorithmic systems in the underwriting and pricing of insurance, particularly life and health insurance. Those systems are classified as high-risk and are subject to strict requirements as to governance, data quality, transparency, human oversight and cybersecurity, although part of the obligations for the Annex III systems has been deferred until 2 December 2027. The framework also operates alongside the GDPR and the “Ley Orgánica de protección de datos” —Spain's data protection act—, and alongside EIOPA's criteria on the ethics and trustworthiness of AI, which raises very topical questions concerning segmentation of the insured, the explainability of automated decisions, algorithmic discrimination, refusal of cover and liability where the insurer's decision stems from an algorithm.
1.The European AI Regulation and its general application from August 2026
The European Artificial Intelligence Regulation —the AI Act— lays down a harmonised framework for the development, placing on the market, putting into service and use of AI systems in the Union, with the aim of ensuring human-centric and trustworthy AI, protecting health, safety and fundamental rights, and preventing the fragmentation of the internal market. The Regulation entered into force twenty days after its publication and applies, as a general rule, from 2 August 2026, although it provides for a staggered timetable for certain obligations. Chapters I and II, on scope and definitions, have applied since February 2025, and the chapters on governance, supervision and confidentiality since August 2025, while the specific obligations for the high-risk systems in Annex III will not be enforceable until 2 December 2027.
The Regulation takes a risk-based approach, prohibiting certain AI practices regarded as unacceptable, imposing strict requirements on high-risk systems and laying down transparency obligations for other systems. AI systems used for risk assessment and pricing in life and health insurance are classified as high-risk, because of their potential impact on fundamental rights such as equality, non-discrimination, data protection and personal autonomy. Those systems are subject to requirements as to risk management, data governance, technical documentation, traceability, transparency, human oversight and technical robustness.
2.High-risk systems in life and health insurance and the partial deferral of obligations
The Regulation classifies as high-risk those AI systems which are used in sensitive fields, including financial services where they affect natural persons' access to essential services or the assessment of their creditworthiness and risk. Risk assessment and pricing in life and health insurance, where they are based on AI systems, fall within that category, in so far as they may determine access to cover, the amount of the premiums and the contractual terms, with direct effects on social protection and equal treatment.
High-risk systems must meet specific requirements. The provider must put in place a risk management system that identifies, analyses and mitigates the risks the system may create for health, safety and fundamental rights. It must ensure the quality of the data used to train and validate the system, avoiding biases capable of leading to unjustified discrimination. It must draw up and keep detailed technical documentation making it possible to understand the design, the operation and the limitations of the system, and it must ensure the traceability of operations, keeping records of the decisions taken and of the data used. It must ensure transparency and provide professional users with sufficient information for them to understand the capabilities and limitations of the system, and it must ensure human oversight, so that important decisions are not taken without meaningful human intervention or control.
The European reform of July 2026 has introduced a partial deferral, until 2 December 2027, of the obligations applying to the Annex III systems, among them those used in life and health insurance. That deferral responds to the need to give operators time to adapt their systems and processes to the requirements of the Regulation without interrupting the provision of services. The general framework for the protection of fundamental rights and for liability nevertheless remains applicable, and AI systems in insurance must already comply with the rules on data protection, non-discrimination and transparency.
3.AI governance in insurance: data quality, fairness and explainability
AI governance in insurance is built around several axes. Data quality is essential. The data sets used to train and validate pricing and risk assessment models must be representative and free from systematic errors, and must not incorporate biases that reproduce historical discrimination. Academic commentary and European decisions have warned that AI can create and reinforce biases, including indirect ones, where the underlying data reflect discriminatory social structures. Segmentation of the insured by reference to variables such as postcode, occupation, medical history or digital behaviour may lead to indirect discrimination on grounds of racial or ethnic origin, sex, age or socio-economic situation if it is not properly controlled.
Fairness and non-discrimination are central principles. The AI Act operates alongside anti-discrimination legislation and Article 14 of the Spanish Constitution, which prohibits any discrimination on grounds of birth, race, sex, religion, opinion or any other personal or social condition or circumstance. The use of sensitive data, or of proxies for sensitive data, in pricing models may infringe those principles. The “Ley Orgánica de igualdad de trato y no discriminación” —Spain's equal treatment and non-discrimination act—, in Article 23, requires algorithms involved in decision-making within the public administration to take account of criteria of bias minimisation, transparency and accountability, and encourages impact assessments to determine possible discriminatory bias. Although that provision concerns the public administration, its principles can be transposed to the insurance sector.
The explainability of automated decisions is a further axis. AI systems used for pricing and risk assessment must be explainable, at least so far as is necessary for professional users and, where appropriate, the insured to understand the factors that influenced the decision. The AI Act stresses the importance of transparency and of explainability, while acknowledging that it is not always possible to give a complete explanation of how complex models work, such as black-box algorithms. In such cases, what is required is at least an explanation of the relevant variables and of the general logic applied, as well as the possibility of human review.
4.The GDPR, automated decisions and the rights of the insured
The use of AI in the underwriting and pricing of insurance necessarily operates alongside the General Data Protection Regulation —the GDPR— and the “Ley Orgánica de protección de datos y garantía de los derechos digitales” —Spain's data protection and digital rights act, the LOPDGDD—. The GDPR provides that every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her, unless the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law or is based on the data subject's explicit consent. In those cases, the controller must adopt suitable measures to safeguard the data subject's rights and freedoms, such as the right to obtain human intervention, to express his or her point of view and to contest the decision.
In the insurance sector, decisions on the acceptance of cover, the setting of premiums or the amendment of terms may be regarded as decisions producing significant legal effects. Where they are taken in an automated manner, on the basis of profiles generated by AI systems, they must comply with the requirements of Article 22 GDPR. The insured has the right to be informed of the existence of automated decisions, of the logic applied and of the significance and the envisaged consequences of such processing. The LOPDGDD reinforces those rights, requiring transparency in the information given to the person concerned and regulating the exercise of the rights of access, rectification, erasure, objection, restriction and portability.
Algorithmic discrimination is directly connected with data protection. The GDPR prohibits the processing of special categories of personal data, such as data relating to health, racial or ethnic origin, political opinions or sexual life, save in specific cases and subject to reinforced safeguards. The use of health data in life and health insurance must comply with the provisions of the LOPDGDD on the processing of health data, which refer to sector-specific legislation and require security and confidentiality measures. Profiling which infers sensitive information from apparently neutral data, such as consumption patterns or digital behaviour, may infringe those principles and give rise to risks of discrimination.
5.Liability where the insurer's decision stems from an algorithm
Liability where insurers' decisions stem from algorithms operates on several levels. First, the insurer's contractual liability towards the policyholder and the insured under the “Ley de Contrato de Seguro” —Spain's Insurance Contract Act—. The insurer must perform the obligations assumed in the policy and cannot rely on the internal workings of its AI systems to justify decisions contrary to the contract or to good faith. Clauses making a generic reference to automated pricing models must comply with the requirements of transparency and of content review, and cannot conceal surprising or prejudicial limitations.
Secondly, liability for infringement of data protection legislation. The GDPR and the LOPDGDD provide for significant administrative fines for unlawful processing, including discriminatory profiling or the taking of automated decisions without respecting data subjects' rights. The “Agencia Española de Protección de Datos” —Spain's data protection authority, the AEPD— has warned of the risks of AI for privacy and equality, and has insisted on the need for data protection impact assessments for high-risk processing, such as processing involving automated decisions on access to financial services.
Thirdly, liability for discrimination. Anti-discrimination legislation and the Equal Treatment Act allow actions for cessation and for compensation where direct or indirect discrimination occurs in access to goods and services, including insurance. Algorithmic discrimination, where an AI system produces systematically unfavourable outcomes for particular groups, may be the subject of such actions. The difficulty of identifying and proving algorithmic bias does not preclude liability from being asserted, and academic commentary has stressed that the apparent accuracy of the models cannot serve as an excuse for perpetuating inequalities.
Finally, regulatory liability. The AI Act provides for supervisory and enforcement mechanisms in the event of failure to comply with its requirements, including the possibility of prohibiting the placing on the market or the putting into service of high-risk systems which do not comply with the rules, and of imposing financial penalties. The national supervisory authorities, in coordination with the Commission's AI Office, will be responsible for ensuring, assessing and monitoring the conformity of AI systems with the regulatory framework, and insurance undertakings will have to submit their pricing and risk assessment systems to those controls.
6.Conclusion: a new framework for AI in insurance between pricing, fundamental rights and supervision
The general application of the European AI Regulation in August 2026, together with the GDPR, the LOPDGDD and anti-discrimination legislation, shapes a new framework for the use of artificial intelligence in the underwriting and pricing of insurance. The systems used in life and health insurance are classified as high-risk and are subject to strict requirements as to governance, data quality, transparency, human oversight and cybersecurity, although part of the obligations is deferred until December 2027 to allow for adaptation.
The use of data to set premiums, segmentation of the insured, the explainability of automated decisions, algorithmic discrimination, refusal of cover and liability where the insurer's decision stems from an algorithm become central questions of insurance practice. Insurance undertakings will have to review their pricing and risk assessment models, ensure the quality and fairness of the data, offer sufficient explanations to the insured, respect data protection rights and submit their systems to effective human oversight.
For legal practice, the challenge lies in articulating this new framework with the Insurance Contract Act and with the case law on clauses limiting the rights of the insured, transparency and good faith, and in offering answers to the disputes that will arise where insurers' decisions are based on algorithms. Artificial intelligence ceases to be a mere technical instrument and becomes a regulated and supervised element, whose use in insurance must reconcile efficiency and accuracy with the protection of fundamental rights and the confidence of the insured.