The EU AI act: a familiar regulatory challenge for specialty insurers

For many in the specialty insurance market, the arrival of the EU Artificial Intelligence Act will feel very similar to the experience of implementing the General Data Protection Regulation.

Having previously managed the technical delivery of GDPR within a specialty insurance company, the scale of effort required to become compliant with the EU AI Act is likely to be comparable. While the regulation focuses on AI rather than personal data, the organisational challenge is much the same: identifying impacted systems, engaging technical teams and embedding new governance requirements across the business. 

One of the biggest challenges is securing early buy-in from the teams who support the systems involved. Most technology and operational teams already have defined delivery plans and committed workloads. Introducing a regulatory change with fixed delivery expectations inevitably creates disruption to those plans. As seen during GDPR implementation, some pushback is natural when teams are asked to accommodate non-negotiable regulatory requirements alongside existing commitments.

Resource constraints also become a practical issue. Teams are already supporting day-to-day business operations and working through existing backlog items. Finding time to implement a regulatory change especially one that requires system assessments and documentation can stretch already limited capacity.

This is why awareness is critical. Teams need to understand the financial, regulatory and reputational risks to the business if the regulation is not implemented effectively. Positioning the EU AI Act as a business risk rather than just a technology task helps build the engagement needed to move the work forward. 

From there, organisations need to work closely with system owners and technical teams to determine where AI is being used and how those systems may fall within the scope of the regulation. Providing practical guidance such as questionnaires or classification frameworks can help teams identify affected systems and determine what steps are required to achieve compliance.

For specialty insurers that successfully navigated GDPR, the EU AI Act should feel like a familiar journey. The key will be early engagement, clear guidance and ensuring teams understand how the regulation applies to the systems they support.

If your organisation is beginning its EU AI Act journey and would like practical guidance on assessing AI systems, classifying risk and building a compliant governance framework contact us.

Find out more about how we support insurers in navigating regulatory change while keeping delivery programmes on track here