AI regulation for UK insurance brokers: what actually applies

A practical guide to the AI rules already affecting UK insurance brokers, when EU requirements apply, and what firms should check now.

Allan Cândido

Marketing Executive, Cluda

Since 2 August, anyone in the EU talking to a chatbot has had to be told it's a chatbot. Meanwhile, the EU has pushed back its rules for high-risk AI, including pricing in life and health insurance, to December 2027. And in July, the FCA's Mills Review confirmed that the UK regulator won't be writing a separate AI rulebook.

For a broking firm, those three developments can seem to point in different directions: some rules are in force, some are delayed, and the UK regulator says nothing new is coming. In practice, most UK brokers already have AI obligations. They come from rules you know well, and they apply to AI tools already inside the business, including the ones nobody signed off.

This guide sets out which rules apply, when the EU regimes reach a UK firm, and what to check this week.

Does the FCA have specific AI rules for insurance brokers?

No, and it has said it doesn't intend to write any. The Mills Review, published on 6 July 2026, looked at how AI is changing retail financial services. It confirmed that the FCA sees its existing frameworks, Consumer Duty and the Senior Managers and Certification Regime, as the foundation for AI governance. FCA chair Ashley Alder described the approach as principles-based and focused on outcomes.

So the question the FCA will ask about your AI use is the one it asks about everything else: is the customer getting a good outcome, and can you show it?

Under Consumer Duty, that runs through the four outcomes: products and services, price and value, consumer understanding, and consumer support. A tool might summarise a policy for a client, flag a gap in cover or shape a recommendation. Its output then feeds straight into at least two of those outcomes. If the summary misses a pre-authorisation requirement and a claim is later declined, the Duty doesn't care whether the error came from a person or a model.

SM&CR adds the accountability layer. The regime doesn't create a senior manager function for AI. Instead, someone in your firm already holds responsibility for the processes AI now touches. That person should be able to say which tools are in use, what they're used for, how their outputs are tested and who monitors them.

Two points are easy to miss:

  • Buying the tool doesn't transfer the risk. A third-party AI product is still your process when it's used to advise your client. The vendor's terms of service don't move accountability away from your firm.

  • Vulnerable customers still need to be identified and supported. An AI-assisted process that works well for a typical client can fail quietly for someone who needs more time, a different format or a human conversation. The FCA expects firms to have thought about that before it happens.

Does the EU AI Act apply to UK insurance brokers?

It can, even without an EU office. Article 2 of the AI Act catches firms outside the EU in three situations:

  • they place an AI system on the EU market;

  • they put one into service in the EU;

  • the output of an AI system they provide or use is used in the EU.

The third is the one that catches brokers by surprise. Suppose your firm uses an AI tool to produce comparisons, recommendations or client communications for clients in the EU, or for EU-based employees on a group scheme. The Act can then apply, even though the work happens in the UK.

The Act also distinguishes between providers, who develop an AI system or put their name on it, and deployers, who use one in their business. Most brokers are deployers. If you build your own tool, or put a white-labelled chatbot on your website under your brand, you may be the provider. Providers carry more of the obligations.

What the EU AI Act requires now, and what's been delayed

The Act comes into force in phases, and the timetable has just changed. Here is where things stand.

In force since 2 February 2025: prohibited practices. Article 5 bans a short list of uses outright. The one most relevant to insurance is social scoring: assessing people on their behaviour or personal characteristics, then treating them unfavourably in a way that is unjustified, disproportionate or unrelated to the context in which the data was collected. Fines for prohibited practices reach €35 million or 7% of worldwide annual turnover, whichever is higher.

In force since 2 August 2026: transparency. Under Article 50, AI systems that interact directly with people must make it clear they are AI, unless that is already obvious. Formally, the duty sits with the provider. So if you run a chat assistant on your website or client portal, either the vendor has built the disclosure in or you need to add it. Breaches carry fines of up to €15 million or 3% of turnover. As Jones Walker's analysis points out, the delay agreed this year left these transparency obligations untouched.

Delayed to 2 December 2027: high-risk systems. Annex III lists AI used for risk assessment and pricing of individuals in life and health insurance as high-risk. High-risk systems will need risk management, data governance, human oversight, logging and documentation. Those obligations were due in August 2026. The EU's Digital Omnibus has pushed them back to December 2027 for systems like these, and to August 2028 for AI built into regulated products (Gibson Dunn has a clear summary).

This is where brokers most often mix up the categories. High-risk doesn't mean banned. Pricing and underwriting AI in life and health can be used lawfully with the right controls, and the deadline for those controls is still more than a year away. Social scoring is already banned, and it carries the largest fine in the Act.

For brokers placing PMI, group risk or protection business, the practical question is where your insurers use AI in pricing and underwriting for EU lives. That is where the high-risk rules will bite first, and where you'll want answers before December 2027.

How data protection law applies to automated decisions in insurance

UK and EU law have now split on this, so brokers with clients in both places need to know each version.

UK GDPR, as amended from 5 February 2026. The Data (Use and Access) Act 2025 replaced the old Article 22 with new Articles 22A to 22D. Under Article 22A, a decision counts as solely automated when there is no meaningful human involvement in it. For ordinary personal data, the new regime is more permissive than the old one. Firms can make significant automated decisions on grounds such as legitimate interests, as long as the safeguards are in place:

  • telling the individual that automated decision-making is being used;

  • letting them make representations;

  • giving them access to human intervention;

  • letting them contest the decision.

Special category data is the exception, and health data is special category. Significant automated decisions based on it are still restricted to narrow conditions, such as explicit consent. For PMI, group income protection, critical illness and most employee-benefits work, the relaxation largely doesn't apply.

The "meaningful" test is where most firms will be judged. The ICO's guidance on AI and individual rights is clear that human involvement has to be active and real. A person routinely approving whatever the system produces doesn't count. In practice, the reviewer needs the information, the authority and the time to reach a different conclusion, and there should be evidence that they sometimes do.

EU GDPR. Article 22 still applies in its original form to EU data subjects. It gives people the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on them. In December 2023, the Court of Justice widened what that covers in the SCHUFA case (C-634/21). An automated score counted as a decision where it played a determining role in the outcome, even though a different company made the final call.

The two regimes are worded differently, but they end up in the same place. Having a person in the loop doesn't settle the question. What matters is whether that person actually makes the decision.

Does DORA apply to insurance brokers?

For most UK brokers, no. The Digital Operational Resilience Act is an EU regulation that applies to EU financial entities, so it only matters to you if your group has an EU-authorised entity.

Even then, Article 2(3)(e) of DORA excludes insurance and reinsurance intermediaries that are micro, small or medium-sized enterprises. Most independent brokers with EU operations will fall within that exclusion.

If your EU entity is in scope, AI services are ICT third-party services like any other:

  • they need to appear in your register of information;

  • where they support a critical or important function, you need an exit strategy that has been tested;

  • you need to know what happens to your data and your workflows if the provider fails or changes its terms.

An AI compliance checklist brokers can run this week

Most firms can work through this in an afternoon with their ops lead and compliance officer. Start with the first item, because everything else depends on it.

  1. List every AI tool in use, including the unofficial ones. Ask the team directly what they use to summarise policies, draft emails or compare quotes. Personal ChatGPT accounts count.


  2. Name the accountable person. For each tool, record which senior manager is responsible for its use, and make sure they know.


  3. Check you can evidence outcomes. Where Consumer Duty applies, pick one recent case where AI was used. Can you show what the tool produced, what a person checked, and why the advice was right for that client?


  4. Test your human review. Look at the last twenty AI outputs someone approved. If none were changed or rejected, find out whether the review is real.


  5. Map your EU exposure. Identify clients, scheme members or outputs that touch the EU. If there are none, you can deprioritise items 6 to 8.


  6. Check disclosure on anything chat-like. Any assistant on your website, portal or client channels should say clearly that it's AI.


  7. Ask your insurers where they use high-risk AI. Focus on life and health pricing and underwriting for EU lives, and ask for their compliance plan for December 2027.


  8. Confirm your DORA position. If you have an EU entity, check whether the SME exclusion applies. If it doesn't, make sure your AI suppliers are in the register of information and that critical ones have an exit plan.


  9. Flag health data. Any automated process that uses health information needs its own review under the stricter rules, in both the UK and the EU.



The practical point is that UK brokers do not need to wait for an AI-specific rulebook. The obligations are already there, through Consumer Duty, SM&CR and data protection law, with additional EU requirements where the firm or its outputs cross into the EU. The immediate task is to know which tools are being used, who is accountable for them, and whether their outputs can be properly reviewed and evidenced.

Frequently Asked Questions

Frequently Asked Questions

Is the FCA going to introduce AI-specific rules for brokers?

Not on current plans. The Mills Review confirmed the FCA will rely on Consumer Duty and SM&CR, while it keeps developing its AI Lab and monitoring the move towards more autonomous systems.

We only have UK clients. Does the EU AI Act matter to us?

Probably not directly. It can still reach you if a tool's output is used in the EU, for example for EU-based members of a UK group scheme. It's also worth checking whether the vendors you rely on are already building to the Act's standards.

Is using ChatGPT to compare policy wordings against the rules?

No rule bans it, but it raises the issues covered above. There's data protection, especially where client health data is pasted into a personal account. There's accountability for the output. And there's your ability to evidence what was checked. Most firms would struggle to defend it under Consumer Duty if an error reached a client.

Does a person approving every AI output count as human oversight?

Only if the involvement is meaningful. Under UK GDPR since February 2026, a decision with no meaningful human involvement is treated as solely automated. Under EU GDPR, following the SCHUFA ruling, a token sign-off on an outcome the system has effectively already decided can be treated the same way.