EIOPA's AI governance opinion covers intermediaries too: what it asks of a brokerage
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
An assistant that drafts a reply for an adviser to read is one thing. An automation that decides something about a client on its own — declines the request, excludes them from renewal terms, closes their notification — is another, and UK data protection law changed its mind about the second category this year. On 5 February 2026, section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with four new Articles, 22A to 22D. If your brokerage has been treating "no solely automated decisions" as a settled rule in its AI policy, that policy is out of date.
The old Article 22 started from prohibition: a decision based solely on automated processing with legal or similarly significant effects was banned unless you could fit into one of three exceptions — contract necessity, authorisation by law, or explicit consent. The new framework, commenced by the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026, starts from permission with conditions. For ordinary personal data, a controller may take a significant automated decision on any lawful basis, including legitimate interests, provided the safeguards in Article 22C are in place. The ICO's own summary is that the Act opens up the full range of lawful bases you can rely on when using people's personal information to make significant automated decisions about them, so long as the safeguards continue to apply.
Three definitions in Article 22A do the heavy lifting. A decision is based solely on automated processing if there is no meaningful human involvement in taking it. A decision is significant if it produces a legal effect for the data subject or has a similarly significant effect. And when you assess meaningful human involvement, Article 22A(2) requires you to consider, among other things, the extent to which the decision is reached by means of profiling — which is the statutory way of saying that an adviser clicking "approve" on a score they do not understand is not a human in the loop.
Most of what a brokerage runs on WhatsApp never gets near Article 22C. The value of the exercise is being able to say why, in writing, before someone asks. Work through each automation with three questions: is a decision being taken, is it significant for the client, and is there meaningful human involvement before it takes effect?
| Automation | Significant decision? | Solely automated? | Where it lands |
|---|---|---|---|
| AI drafts a reply, adviser reads it, edits and sends | Usually not | No — the adviser decides | Outside 22A–22C, but the review must be real, not a rubber stamp |
| Rule-based auto-reply confirming a renewal date or office hours | No legal or similar effect | Yes | Outside the regime; transparency and accuracy still apply |
| Attrition risk score used to build an adviser call list | No decision yet | — | Profiling under Article 4; accuracy and information duties |
| Client excluded from a campaign segment by score | Normally not | Yes | Document the logic; revisit if the exclusion denies a benefit |
| Automated refusal to quote, or automated referral that ends the enquiry | Likely yes | Depends on the human step | Article 22C safeguards; Article 22B if health data is involved |
| AI classification that closes a claim notification with no adviser review | Yes | Yes | Article 22C safeguards and, realistically, a DPIA |
Two traps sit in this table. The first is the attrition risk score: computing it is profiling, which is governed by the accuracy and transparency rules but is not a decision. It becomes a decision the moment nobody looks at the output before something happens to the client. The second is Article 22B(4), which is easy to skip: a significant decision may not be taken solely by automated means where the processing relies on Article 6(1)(ea), the recognised legitimate interests basis. Choosing the convenient lawful basis can therefore close the automation door you were trying to open.
Article 22B preserves the stricter regime where special category data is in play — and for a brokerage writing private medical, group risk, income protection or travel with medical declarations, that is a live question, not a theoretical one. A significant decision based entirely or partly on Article 9(1) processing cannot be taken solely by automated means unless either the data subject gave explicit consent to the processing the decision is based on, or the decision is necessary for entering into or performing a contract with the controller, or is required or authorised by law, and an Article 9(2)(g) substantial public interest condition applies.
In plain brokerage terms: an automation that sorts a client into a "refer to underwriter" track on the strength of a disclosed condition, with no adviser in the loop, needs a condition you can name. Most firms will find it faster to keep a human decision point than to build the consent architecture around it.
Where a significant, solely automated decision is taken, Article 22C requires safeguards for the data subject's rights, freedoms and legitimate interests, consisting of or including measures that provide the data subject with information about the decisions taken in relation to them, enable them to make representations about those decisions, enable them to obtain human intervention on the part of the controller, and enable them to contest the decision. Article 22D lets the Secretary of State add to those safeguards by regulations, and define — positively or negatively — what counts as meaningful human involvement; those regulations cannot amend Article 22C itself.
For a small brokerage, evidencing this is mostly paperwork you should already have. Four practical steps:
Guidance is still settling. The ICO consulted on draft guidance on automated decision-making, including profiling in spring 2026, and a separate 2026 statutory instrument requires the regulator to produce a code of practice on artificial intelligence and automated decision-making. Expect the detail on meaningful human involvement to firm up; expect the four safeguards not to move. If your firm has not yet mapped whether this processing needs a data protection impact assessment, start with our guide on when an AI-assisted broker inbox needs a DPIA.
The UK moved; the EU did not. A broker in Dublin, Amsterdam or Frankfurt is still under Article 22 of the EU GDPR, where the default remains prohibition and you need contract necessity, member state law or explicit consent before a significant solely automated decision, with the Article 22(3) safeguards on top. Layer on the obligations covered in our guide to the EU AI Act for brokers using AI-drafted replies, and a firm serving clients on both sides ends up running two regimes through one inbox. The pragmatic answer for most brokerages is to build to the stricter standard — keep a human decision point, document it, and let the UK flexibility be headroom you do not need to use. The rest of our AI topic covers the governance side.
No, provided the adviser genuinely takes the decision. The test in Article 22A(1)(a) is whether there is meaningful human involvement in taking the decision, and Article 22A(2) makes you weigh how far the outcome was reached by profiling. An adviser who reads the draft, has the client history in front of them and can rewrite or discard it is deciding. An adviser told to approve a queue of a hundred drafts a day is not.
Computing a score is profiling, not a decision. It becomes a significant automated decision only when the score alone triggers an outcome with legal or similarly significant effects for the client and no human reviews it. A score that produces a call list for an adviser stays on the right side of that line — but the accuracy, transparency and lawful basis obligations still apply to the score itself.
Article 22B keeps the stricter position wherever special category data is part of the picture. A solely automated significant decision based on health data needs explicit consent to the underlying processing, or contract necessity or legal authorisation coupled with an Article 9(2)(g) condition. In most brokerages the realistic answer is to keep an adviser in the decision.
The DPIA obligation did not change. Systematic and extensive evaluation of individuals through automated processing on which significant decisions are based remains a high-risk trigger, and large-scale processing of health data is another. The commencement of Articles 22A to 22D makes the assessment more useful, not less, because it is where you record which automations you decided were significant and why.
It should describe the significant automated decisions the firm takes that are subject to Article 22C safeguards, the logic involved in general terms, the consequences for the client, and how to ask for human intervention or contest a decision. Say it in the notice, and make sure the route you describe actually works when a client uses it on WhatsApp.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.
Article 35 does not care that your AI only drafts replies. The screening test a brokerage should run before switching it on, and what to write down after.