Skip to main content
Outreach
Jul. 2026

European AI Act: Hero or Villain for the Insurance Sector?

Author: Carlos R. Larrea Cruces, Business Development Manager at Innova-tsn

 

AI is currently undergoing a period of rapid expansion. Companies are exploring new use cases, technologies are evolving at great speed and, at the same time, public institutions are working to build a framework that enables organisations to harness its potential without losing sight of the risks it may also pose. Against this backdrop, the European Union’s Artificial Intelligence Act, commonly known as the EU AI Act and referred to in Spain as the RIA, has emerged. However, its arrival coincides with a unique reality: there is still no substantial track record in the implementation of this technology that would allow us to speak of established experts in its application.

There are several reasons for this. Firstly, the regulatory framework is very recent and is still taking shape. Although the RIA has not yet become fully applicable, a draft regulatory package that would amend it, known as the Digital Omnibus, is already under discussion. In addition, the European Commission and national authorities continue to publish guidelines and best practices to facilitate its implementation, requiring organisations to make a constant effort to stay up to date.

This situation is compounded by the fact that many artificial intelligence initiatives are still experimental in nature. The number of use cases continues to grow, but when examined in detail, many still correspond to proofs of concept or pilot projects that have not yet been fully scaled. This is particularly evident in the field of generative artificial intelligence.

Finally, the pace of technological evolution itself introduces an additional degree of complexity. Solutions that required advanced development capabilities just a year and a half ago can now be built much more quickly and efficiently using low-code or no-code tools. In a sense, businesses and regulators are moving forward at the same time.

Against this backdrop, an inevitable question arises: why introduce specific regulation for artificial intelligence now? And, in particular, in a sector such as insurance, which is already characterised by a high degree of regulation, why add another regulatory layer? The purpose of the RIA is not to hinder the development of artificial intelligence or limit its potential, but rather to establish a framework that ensures these technologies are used responsibly. The regulation requires the different stakeholders involved to undertake a conscious and structured assessment of the risks that may arise from the implementation of AI systems, both in relation to citizens’ fundamental rights and their broader impact on society.

In fact, this approach is by no means unfamiliar to the insurance sector.

Risk assessment and management are at the very heart of its business. The adoption of AI governance within insurance companies should therefore be understood as a natural evolution of practices that the sector has been applying in other areas for decades. AI governance is generally structured around two main dimensions: corporate and operational. The former covers the strategy, policies and procedures governing the use of AI within an organisation. In this area, the insurance sector already has extensive experience through the implementation of regulatory frameworks such as Solvency II, DORA and the General Data Protection Regulation.

The second dimension encompasses technological aspects, data lifecycle management and the management of the lifecycle of artificial intelligence models. These areas are not unfamiliar to the insurance industry either. The high degree of technological development experienced by the sector in recent years has already integrated these capabilities into its day-to-day operations.

It is often suggested that increased regulation could become a barrier to innovation. However, the design of the European framework itself seeks to prevent this risk. The regulation includes measures aimed at facilitating technological development, such as exemptions from certain obligations for AI systems in the research phase that are not placed on the market, as well as the creation of testing environments using real-world data — known as regulatory sandboxes — which enable organisations to experiment under controlled conditions.

Furthermore, the regulation introduces mechanisms to facilitate compliance for SMEs and mid-cap companies. These organisations are regarded by the European institutions as some of the main drivers of innovation within the business landscape, making it essential to reduce the burden associated with regulatory compliance in order to preserve their capacity for development and innovation.

One of the most significant benefits relates to transparency. The regulation places explainability and traceability at the heart of sound AI governance. These principles make the results generated by AI models easier to understand for the different areas of an organisation that need to use them, while helping to strengthen trust among both customers and regulators, without requiring companies to disclose trade secrets.

Another benefit is linked to the creation of a corporate culture of governed innovation. The RIA emphasises the importance of the human factor in the use of artificial intelligence, establishing requirements for AI literacy among employees and defining clear roles for human oversight of automated systems.

Ultimately, rather than representing an additional regulatory burden, the European Union’s Artificial Intelligence Act can become a lever for strengthening trust, competitiveness and the insurance sector’s capacity for innovation in this new technological era.