Automated decisions in a broker inbox: what changed for UK brokerages in February 2026
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
For most of 2026, the compliance conversation about AI in insurance distribution has revolved around a single question: is my tool high-risk under the AI Act? For a brokerage the answer is almost always no, and once the Annex III deadline moved, the whole subject seemed to lose its deadline. That reading skips the document that actually describes what an EU supervisor now expects of an intermediary using AI.
EIOPA published its Opinion on Artificial Intelligence governance and risk management (EIOPA-BoS-25-360) on 6 August 2025. It is aimed squarely at the AI systems that are neither prohibited nor high-risk — which is to say, at almost everything a broker actually runs: a classifier that reads inbound messages, a model that drafts a reply for an adviser to check, a score that ranks who to call this week.
Three features decide how seriously to take it.
First, its scope. Paragraph 1.3 says the opinion "covers the activities of both insurance undertakings and intermediaries (hereafter jointly referred as 'undertakings'), insofar as they may use AI systems within their respective areas of competence in the insurance value chain." Intermediaries are named. Every time the text says "undertakings" after that point, it means you too.
Second, its addressee. The opinion is addressed to the competent authorities — the AFM, BaFin, the Central Bank of Ireland, the ACPR, the CSSF and their peers — not directly to firms. It reaches a brokerage through the supervisory approach of its own national regulator rather than as a rulebook you can be fined against tomorrow. That makes it a description of the questions you will eventually be asked, which is more useful than a rule and easier to prepare for.
Third, its legal footing. Paragraph 2.8 is explicit that the opinion "does not set out new requirements". What it does is read existing law in the light of technology that did not exist when the law was drafted: Articles 17, 20 and 25 of the IDD, Articles 41, 46 and 82 of Solvency II, Articles 4 to 12 of DORA, Articles 258 and 260 of Delegated Regulation 2015/35 and Articles 6 to 9 of the product oversight and governance regulation.
Half of that list does not reach a pure intermediary. Solvency II governance and the technical-provisions articles are undertaking law. What genuinely binds a brokerage is the IDD: Article 17, to act honestly, fairly and professionally in the customer's best interests; Article 20, to give objective information in a comprehensible form and a contract consistent with demands and needs; Article 25, on product approval processes, where you manufacture or co-manufacture. Read the opinion with those three articles in hand and it becomes much shorter.
One boundary worth stating plainly: EIOPA supervises the EU and EEA. A UK brokerage is outside its remit and reaches the same destination through the FCA — the Consumer Duty, SYSC and the senior manager who owns the outcome. If that is your market, the Consumer Duty governance checklist is the equivalent document.
The opinion does not ask every firm to do the same work. Paragraph 3.2 asks undertakings to assess the risk of each AI system first, because "there are varying levels of risks amongst those AI systems that are not prohibited or considered as high-risk", and then to build measures proportionate to what that assessment found. Systems with minimal anticipated impact "may be subject to a relatively simple and streamlined assessment".
Paragraph 3.3 lists the criteria. Here they are with the reading that matters in a broking office.
| EIOPA criterion (3.3–3.4) | What raises or lowers it in a brokerage |
|---|---|
| Scale of data processing and sensitivity of the data | Health answers in a protection or PMI enquiry, and claim narratives, sit higher than a motor renewal thread |
| Number of customers affected, including vulnerable customers | A model that touches every inbound message affects the whole book, not a pilot cohort |
| Extent to which the system can act autonomously | An auto-reply that sends without review is a different system from a draft a named adviser approves |
| Consumer-facing or purely internal | Tagging inbound messages for triage is internal; text that reaches the client is not |
| Potential adverse impact on the individual, including non-discrimination | A score that changes who gets contacted needs a fairness answer; a spellchecker does not |
| Lines of business important to financial inclusion or compulsory by law | Motor and health carry more weight than travel or gadget cover |
| Business continuity, financial position, legal obligations, reputation | If the tool going down stops your renewal run, say so in the assessment |
For most brokerages this is a two-page document per tool, reviewed when the tool changes. Writing it is also the cheapest way to answer the vendor emails that insist you are high-risk: the assessment shows your reasoning, dated.
Paragraph 3.7 sets out six areas that a proportionate governance framework should cover. Paragraph 3.8 insists they work as a combination rather than a checklist, which is why weakness in one is expected to be compensated elsewhere.
| Area | What a small brokerage can actually put in place |
|---|---|
| Fairness and ethics | A short written policy, ethics and fairness covered in staff training, monitoring of outcomes, and complaints handled through the mechanism you already have (3.16 confirms it need not be AI-specific) |
| Data governance | Which client data enters the tool, whether it is complete, accurate and appropriate, and the same standard applied to any data bought from a third party (3.21) |
| Documentation and record keeping | Records that make the behaviour traceable and reproducible: which model version, what it was asked, what it produced, who approved it |
| Transparency and explainability | Explanations adapted to the audience — a global account for your regulator, plain non-technical language for a client who asks |
| Human oversight | Named roles, escalation paths, guardrails, training suited to each role (3.32), and a person accountable for what leaves the inbox |
| Accuracy, robustness and cybersecurity | Performance metrics that surface drift, testing of API connections to other systems (3.37), and fall-back plans when the tool is unavailable |
The single most useful sentence for a firm using a language model is in paragraph 3.6. Where accuracy and explainability trade off — "for certain AI systems such as those used to process images, videos, or text, for which it is not possible to comprehensively explain how a certain output was obtained and for which there are no suitable alternatives" — EIOPA accepts that "complementary risk management measures such as data governance or human oversight may be developed to compensate for a lack of explainability."
That is the regulatory logic behind the way an assistive inbox should be configured. In ORIS, the classification of an inbound message and the draft reply are both suggestions; the adviser sends. Auto-reply exists but runs under explicit rules with cooldowns and per-client limits, and negative sentiment always produces a draft for a human instead of an automatic send. That design is not a feature list, it is the compensating control paragraph 3.6 describes, and it is what makes the explainability answer survivable.
Paragraph 3.11 is the one to raise in a procurement meeting. Undertakings "are ultimately responsible for the AI systems that they use, regardless of whether the AI systems are developed in-house or in collaboration with third party service providers", and should "obtain adequate information and assurances from third-party service providers about the characteristics, capabilities, data used to train and test the AI systems, and the limitations of the AI systems used."
It then anticipates the answer you will get. Where intellectual property makes full disclosure impossible, EIOPA expects mitigation rather than surrender: appropriate clauses in contracts and service level agreements, external audits, due diligence testing and monitoring. Four questions get you most of the way — which model and version is behind this, what happens to our client text, what are the documented failure modes, and what do we see when the output is wrong. A vendor that cannot answer them is telling you something about the assurances you will be able to give your own supervisor. The comparison between a scripted chatbot and supervised AI is a useful frame for the first of those questions.
Paragraph 3.28 sets out three transparency duties, and the third is the one nobody acts on. Customers should be informed that they are interacting with an AI system. On request, the influence of the AI system on a decision with a material impact on them should be explained "using simple, clear and non-technical language". And — the part aimed at your agency relationships — "where relevant, insurance intermediaries should also be informed by insurance undertakings when a decision is made on the basis of an AI system so that they can comply with their legal obligations towards customers."
You cannot meet an Article 20 duty to explain an outcome you were never told the basis of. That makes AI disclosure a fair item on the agenda at your next agency review, alongside the questions you already ask about referral criteria and claims philosophy. Note too that transparency and staff AI literacy were never deferred: paragraph 2.5 confirms that non-high-risk systems continue under sectoral law "with the exception of certain transparency requirements (e.g. need to inform the customer that she/he is interacting with an AI system), the need to promote staff AI literacy, and the development of voluntary codes of conduct." The detail of how those sit alongside the AI Act timetable is in our note on what the AI Act genuinely requires of AI-drafted replies.
EIOPA says it will look into supervisory practice two years after publication, which puts the first convergence exercise in the second half of 2027. A brokerage that writes its impact assessments this year will be ready without having to invent anything.
Yes, as far as the IDD reaches you. The opinion covers intermediaries using AI systems within their area of competence in the insurance value chain, and its intermediary hooks are Articles 17, 20 and 25 of the IDD, which apply to insurance distribution generally rather than to life and health only. The Solvency II and technical-provisions material in the opinion is aimed at undertakings and will not concern you.
Not directly. It is addressed to national competent authorities and states that it creates no new requirements. Its practical force comes from the fact that your own supervisor is expected to apply it when assessing whether existing IDD obligations are being met, and that EIOPA intends to review supervisory convergence two years after publication.
No. Paragraph 3.11 places ultimate responsibility on the firm using the system, whether it was built in-house or bought. The vendor's role is to supply information and assurances; yours is to obtain them, document what you were told, and put complementary measures in place where the answers are incomplete.
Proportionality runs through the whole opinion, and paragraph 3.6 says expectations for AI systems with low or very limited impact "would be very limited". In practice that means a written approach to AI use across the firm, an impact assessment per tool, a record of who approved what, and evidence that staff were trained for the role they play in oversight. It does not mean the conformity file the AI Act asks of high-risk systems.
Alongside, not underneath. Footnote 9 of the opinion notes that other legislation including the GDPR may contain provisions relevant to the use of AI systems, and paragraph 3.30 expects the data protection officer, where one exists, to verify that personal data processed by AI systems is handled lawfully. If your inbox tool triggers a data protection impact assessment, that assessment and the EIOPA impact assessment answer different questions and both need writing.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.
Article 35 does not care that your AI only drafts replies. The screening test a brokerage should run before switching it on, and what to write down after.