AI for brokers

The EU AI Act and your brokerage: what actually applies to AI-drafted WhatsApp replies

The high-risk deadline moved to December 2027. What the AI Act genuinely requires of a brokerage using AI drafts on WhatsApp, and what it does not.

Published on 8 min readFCB.ai
Contents
  1. What applied on 2 August 2026, and what moved to 2027
  2. Is a brokerage AI high-risk? Read Annex III point 5 before you answer
  3. The transparency rule that did apply — and who it binds
  4. Where a broker's real AI obligations come from
  5. A checklist that survives a supervisor's question
  6. Frequently asked questions

The weeks around 2 August 2026 produced a familiar wave of vendor emails telling insurance intermediaries that their AI was now "high-risk" and that a conformity file was overdue. For the overwhelming majority of brokerages using AI to draft or triage WhatsApp messages, that is wrong on two counts. The high-risk category almost certainly does not describe what you are doing, and even where it might, the deadline moved six days before it arrived.

There is real work to do — it is just not where the marketing says it is. Here is the shape of the obligations as they stand for an intermediary.

What applied on 2 August 2026, and what moved to 2027

The AI Act is Regulation (EU) 2024/1689. It entered into force in August 2024 and was built to phase in over three years, with the obligations on high-risk systems landing on 2 August 2026. That did not happen. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, pushing the high-risk deadlines back and trimming documentation duties for smaller firms.

ObligationApplies from
Prohibited practices (Article 5) and AI literacy (Article 4)2 February 2025
General-purpose AI models, governance, penalties2 August 2025
Transparency duties (Article 50)2 August 2026, with machine-readable marking of systems already on the market deferred to 2 December 2026
High-risk systems listed in Annex III2 December 2027 (originally 2 August 2026)
High-risk AI embedded in regulated products (Annex I)2 August 2028

Two things follow. The deferral is a deferral, not a repeal — if you are genuinely in Annex III, you have gained roughly sixteen months, not an exemption. And the piece that did land on schedule is transparency, which is the part most firms had not read.

Is a brokerage AI high-risk? Read Annex III point 5 before you answer

Annex III mentions insurance exactly once. It captures AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Both halves of that sentence are limits.

It is life and health. Motor, household, commercial combined, professional indemnity and marine are not named. It is risk assessment and pricing — underwriting decisions about an individual — not communication, not administration, not marketing.

Now hold your own stack against that. A model that drafts a reply for an adviser to check does not price anything. A classifier that reads an inbound message and tags it as a renewal query or a complaint does not price anything. A churn score that ranks who your team should phone this week does not price anything. None of these is the AI system Annex III point 5 describes, and saying so in writing takes one paragraph.

Three situations genuinely change the answer, and they are worth checking rather than assuming:

  • Delegated underwriting. If you hold a binder or act as an MGA for life or health business and a tool sets acceptance terms or premium for individuals, you are on the other side of the line. Take advice rather than a view.
  • Scores used to gate cover. A risk score that decides who gets a call is an operational tool. The same score used to decide who gets offered a policy is doing something else entirely.
  • Putting your name on it. Article 25 can turn a deployer into a provider — with the provider's obligations — if you place a high-risk system on the market under your own brand or substantially modify it.

The transparency rule that did apply — and who it binds

Article 50 is where most brokers guess wrong, because the obligations are split between providers and deployers and the split is counter-intuitive.

Article 50(1) requires providers to design AI systems intended to interact directly with people so that those people are informed they are dealing with an AI. The duty sits with whoever built the system, not with you as its deployer, and it falls away where the interaction is obvious to a reasonably well-informed, observant and circumspect person. What this means in practice is that you should ask your vendor, in writing, how they satisfy Article 50(1) — and keep the answer.

Article 50(4) is the deployer-facing one, and it is narrower than the headlines suggest. It covers deepfakes and AI-generated text published to inform the public on matters of public interest, with a carve-out where the text underwent human review and a person or organisation holds editorial responsibility. A one-to-one WhatsApp message to your own client about their own policy is not publication on a matter of public interest.

So no, the AI Act does not oblige you to stamp a disclosure on every AI-drafted reply an adviser reviews and sends. That is the floor the Act sets, not the standard a supervisor will judge you against. An automated reply that answers a coverage question without any indication that no human has seen it is a fairness problem long before it is an AI Act problem — which is the real distinction between a chatbot and supervised AI in a broking context.

Where a broker's real AI obligations come from

If the AI Act asks little of you directly, three other bodies of law ask a great deal.

EIOPA. Its Opinion on AI governance and risk management, published on 6 August 2025 and addressed to national supervisors, is deliberately aimed at AI systems that are neither prohibited nor high-risk under the AI Act — which is to say, precisely the tools brokers use. It works through existing sectoral law, including the IDD that governs you as an intermediary, and sets expectations across fairness and ethics, data governance, documentation and record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity. It is explicitly risk-based and proportionate: a five-person brokerage is not expected to build an insurer's model risk framework.

The IDD. You must act honestly, fairly and professionally in the customer's best interests, and the product proposed must be consistent with their demands and needs. An AI draft that overstates cover breaches that duty whether or not a machine wrote it — which is why the demands and needs discipline for WhatsApp conversations matters more once drafting is assisted, not less.

Data protection. Feeding client conversations to a model needs a lawful basis and honest transparency, and GDPR Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. An auto-reply confirming a renewal date is not that. A score used to refuse to quote could be.

UK readers: the AI Act binds deployers established in the EU, and third-country deployers where the system's output is used in the EU. A UK brokerage serving UK clients is outside it. The FCA has no AI rulebook and works through existing requirements instead, which is the ground covered by our Consumer Duty governance checklist for AI replies.

A checklist that survives a supervisor's question

  1. Inventory what you actually run. One page listing every AI that touches a client: drafting, classification, scoring, transcription, translation. Most firms find two they had forgotten.
  2. Classify each one against Annex III point 5, in writing. A paragraph of reasoning per system is enough, and it is what you will be asked for. Revisit it if you take on delegated authority.
  3. Get the Article 50 answer from your vendor. In writing, filed with the contract, not recalled from a sales call.
  4. Keep the human where the money is. Anything touching cover, price, liability or a claim decision should produce a draft for a person rather than send itself. In ORIS, negative sentiment always routes to a pending draft with a notification instead of an automatic reply — the point is less the setting than the fact that the rule is written down and somebody owns it.
  5. Support AI literacy. Article 4 has applied since 2 February 2025; the omnibus softened it to supporting the development of literacy among staff rather than guaranteeing a level of it. For a brokerage that means a short session on what the tool can and cannot do, repeated when it changes, and minuted.
  6. Log what went out. Audit logs and CSV export exist so you can reconstruct what a client was told and by what. That record answers the IDD question and the AI question at the same time.
  7. Diarise December 2027. If your classification came out close to the line, the extra months are for building the file, not for forgetting about it.

Read alongside the rest of our writing on AI in broking, the pattern is consistent: the technology question is usually settled quickly, and the governance question is what takes the time.

Frequently asked questions

Does the AI Act apply to us if we only use a vendor's tool?

Yes, as a deployer, but deployer obligations are far lighter than provider obligations and most of them only bite for high-risk systems. If your tools fall outside Annex III, what remains is largely the AI literacy duty in Article 4 and sensible governance. The heavy design, documentation and conformity duties sit with whoever built and placed the system on the market.

We score clients on how likely they are to lapse. Is that high-risk?

On the ordinary reading, no. Annex III point 5 covers AI used for risk assessment and pricing in life and health insurance for natural persons. A retention score that decides which clients your team contacts is an operational prioritisation tool, not an underwriting decision. The analysis changes if the same score starts influencing whether cover is offered or on what terms, so keep the two uses genuinely separate and record which one you are doing.

Do we have to tell clients that a reply was drafted by AI?

The AI Act does not require it for one-to-one client messages. Article 50(1) puts the design duty on the provider of a system that interacts directly with people, and the deployer duty in Article 50(4) is about deepfakes and public-interest text, not private correspondence. Fair-treatment expectations are a separate matter: if a message is sent automatically with no human check, saying so plainly is the safer practice and costs you nothing.

We are a UK broker. Does any of this apply to us?

Not directly, unless the output of your AI system is used in the EU or you have EU-established entities. The UK has no equivalent statute; the FCA expects firms to reach the same destination through the Consumer Duty, SYSC governance requirements and existing record-keeping rules. Firms with Irish, Dutch or German operations should assume both frameworks apply to those entities.

So what actually changed on 2 August 2026?

The transparency duties in Article 50 began to apply, with a further deferral to 2 December 2026 for machine-readable marking of systems already on the market. The high-risk obligations that were supposed to start that day were moved to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. For a typical brokerage the practical answer is that nothing new became due, and the useful work is documenting why.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo