Automated decisions in a broker inbox: what changed for UK brokerages in February 2026
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
The high-risk deadline moved to December 2027. What the AI Act genuinely requires of a brokerage using AI drafts on WhatsApp, and what it does not.
The weeks around 2 August 2026 produced a familiar wave of vendor emails telling insurance intermediaries that their AI was now "high-risk" and that a conformity file was overdue. For the overwhelming majority of brokerages using AI to draft or triage WhatsApp messages, that is wrong on two counts. The high-risk category almost certainly does not describe what you are doing, and even where it might, the deadline moved six days before it arrived.
There is real work to do — it is just not where the marketing says it is. Here is the shape of the obligations as they stand for an intermediary.
The AI Act is Regulation (EU) 2024/1689. It entered into force in August 2024 and was built to phase in over three years, with the obligations on high-risk systems landing on 2 August 2026. That did not happen. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, pushing the high-risk deadlines back and trimming documentation duties for smaller firms.
| Obligation | Applies from |
|---|---|
| Prohibited practices (Article 5) and AI literacy (Article 4) | 2 February 2025 |
| General-purpose AI models, governance, penalties | 2 August 2025 |
| Transparency duties (Article 50) | 2 August 2026, with machine-readable marking of systems already on the market deferred to 2 December 2026 |
| High-risk systems listed in Annex III | 2 December 2027 (originally 2 August 2026) |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2028 |
Two things follow. The deferral is a deferral, not a repeal — if you are genuinely in Annex III, you have gained roughly sixteen months, not an exemption. And the piece that did land on schedule is transparency, which is the part most firms had not read.
Annex III mentions insurance exactly once. It captures AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Both halves of that sentence are limits.
It is life and health. Motor, household, commercial combined, professional indemnity and marine are not named. It is risk assessment and pricing — underwriting decisions about an individual — not communication, not administration, not marketing.
Now hold your own stack against that. A model that drafts a reply for an adviser to check does not price anything. A classifier that reads an inbound message and tags it as a renewal query or a complaint does not price anything. A churn score that ranks who your team should phone this week does not price anything. None of these is the AI system Annex III point 5 describes, and saying so in writing takes one paragraph.
Three situations genuinely change the answer, and they are worth checking rather than assuming:
Article 50 is where most brokers guess wrong, because the obligations are split between providers and deployers and the split is counter-intuitive.
Article 50(1) requires providers to design AI systems intended to interact directly with people so that those people are informed they are dealing with an AI. The duty sits with whoever built the system, not with you as its deployer, and it falls away where the interaction is obvious to a reasonably well-informed, observant and circumspect person. What this means in practice is that you should ask your vendor, in writing, how they satisfy Article 50(1) — and keep the answer.
Article 50(4) is the deployer-facing one, and it is narrower than the headlines suggest. It covers deepfakes and AI-generated text published to inform the public on matters of public interest, with a carve-out where the text underwent human review and a person or organisation holds editorial responsibility. A one-to-one WhatsApp message to your own client about their own policy is not publication on a matter of public interest.
So no, the AI Act does not oblige you to stamp a disclosure on every AI-drafted reply an adviser reviews and sends. That is the floor the Act sets, not the standard a supervisor will judge you against. An automated reply that answers a coverage question without any indication that no human has seen it is a fairness problem long before it is an AI Act problem — which is the real distinction between a chatbot and supervised AI in a broking context.
If the AI Act asks little of you directly, three other bodies of law ask a great deal.
EIOPA. Its Opinion on AI governance and risk management, published on 6 August 2025 and addressed to national supervisors, is deliberately aimed at AI systems that are neither prohibited nor high-risk under the AI Act — which is to say, precisely the tools brokers use. It works through existing sectoral law, including the IDD that governs you as an intermediary, and sets expectations across fairness and ethics, data governance, documentation and record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity. It is explicitly risk-based and proportionate: a five-person brokerage is not expected to build an insurer's model risk framework.
The IDD. You must act honestly, fairly and professionally in the customer's best interests, and the product proposed must be consistent with their demands and needs. An AI draft that overstates cover breaches that duty whether or not a machine wrote it — which is why the demands and needs discipline for WhatsApp conversations matters more once drafting is assisted, not less.
Data protection. Feeding client conversations to a model needs a lawful basis and honest transparency, and GDPR Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. An auto-reply confirming a renewal date is not that. A score used to refuse to quote could be.
UK readers: the AI Act binds deployers established in the EU, and third-country deployers where the system's output is used in the EU. A UK brokerage serving UK clients is outside it. The FCA has no AI rulebook and works through existing requirements instead, which is the ground covered by our Consumer Duty governance checklist for AI replies.
Read alongside the rest of our writing on AI in broking, the pattern is consistent: the technology question is usually settled quickly, and the governance question is what takes the time.
Yes, as a deployer, but deployer obligations are far lighter than provider obligations and most of them only bite for high-risk systems. If your tools fall outside Annex III, what remains is largely the AI literacy duty in Article 4 and sensible governance. The heavy design, documentation and conformity duties sit with whoever built and placed the system on the market.
On the ordinary reading, no. Annex III point 5 covers AI used for risk assessment and pricing in life and health insurance for natural persons. A retention score that decides which clients your team contacts is an operational prioritisation tool, not an underwriting decision. The analysis changes if the same score starts influencing whether cover is offered or on what terms, so keep the two uses genuinely separate and record which one you are doing.
The AI Act does not require it for one-to-one client messages. Article 50(1) puts the design duty on the provider of a system that interacts directly with people, and the deployer duty in Article 50(4) is about deepfakes and public-interest text, not private correspondence. Fair-treatment expectations are a separate matter: if a message is sent automatically with no human check, saying so plainly is the safer practice and costs you nothing.
Not directly, unless the output of your AI system is used in the EU or you have EU-established entities. The UK has no equivalent statute; the FCA expects firms to reach the same destination through the Consumer Duty, SYSC governance requirements and existing record-keeping rules. Firms with Irish, Dutch or German operations should assume both frameworks apply to those entities.
The transparency duties in Article 50 began to apply, with a further deferral to 2 December 2026 for machine-readable marking of systems already on the market. The high-risk obligations that were supposed to start that day were moved to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. For a typical brokerage the practical answer is that nothing new became due, and the useful work is documenting why.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.