The European regulation governing AI through a risk-tiered approach, imposing enhanced obligations on high-risk systems.
The EU AI Act is the first comprehensive regulatory framework dedicated to artificial intelligence, adopted by the European Union and phased in from 2025 and 2026. It rests on a risk-tiered approach that classifies AI systems into several categories with increasing obligations. Uses deemed unacceptable, such as certain forms of social scoring, are prohibited. High-risk systems, for example in recruitment, credit, insurance or critical infrastructure, are subject to strict requirements of risk management, data quality, transparency, documentation and human oversight. Limited-risk systems are bound only by transparency obligations, and minimal-risk uses remain unrestricted. Specific provisions also govern general-purpose AI models. For insurance and risk management, the AI Act is structuring on two counts, it imposes compliance obligations whose breach creates legal exposure, and it enshrines the requirement of human oversight for critical uses, which curbs full automation. The AlgoPolis paper sees in it an institutional buffer that slows hyper-flattening by forcing a human safeguard to be kept in the decision loop.
An insurer deploying an AI model for pricing, a use classified as high-risk, must document its datasets, demonstrate the absence of prohibited discrimination and ensure effective human oversight of decisions.
AI Act, règlement sur l'intelligence artificielle, EU AI Act