What does the AI Act mean for the insurance industry’s marketing and comms?
The EU’s AI Act now regulates the use of AI in insurance (among many other industries!). While this will no doubt be keeping compliance and legal teams busy, there are also some important ramifications for communications and marketing teams when it comes to explaining the use of AI to customers and regulators.
This is particularly important as insurers begin experimenting with agentic AI, which allows systems to work more autonomously. The more independently AI operates, the more difficult it can become to explain how it reached a particular decision and who is ultimately responsible.
For example, when should customers be told that AI has influenced a decision? How can insurers explain the use of new technology like agentic AI without creating unnecessary concern or an accidental PR crisis?
While comms teams won’t be in charge of interpreting or implementing the legislation, they will need to understand how their business uses AI and what safeguards are in place to make sure they’re compliant.
In this article, we explore how emerging AI regulation could affect the way insurance businesses communicate about using agentic AI. While focusing on the EU’s AI act, we also touch upon the rules for the UK and USA as well to help give a global perspective.
What is agentic AI?
Let’s start with a handy definition of agentic AI:
“Artificial intelligence (AI) agents are small, specialised pieces of software that can make decisions and operate cooperatively or independently to achieve system objectives. Agentic AI refers to AI systems composed of agents that can behave and interact autonomously in order to achieve their objectives.”
The key here is the word ‘autonomously’, because agentic AI independently make their own decisions on how to meet a goal. Previously, a software developer would have created steps and processes for a computer program to follow.
Agentic AI earns its name, because it’s more intelligent. Thanks to LLMs, it can find new information and learn how to do new things. It can reason and create its own processes, which means it can solve unexpected problems on its own. This means that it’s staggeringly useful for virtually every industry, including insurance.
What does agentic AI mean for the insurance industry?
Insurers love technology. The industry is well-known for being early adopters of the latest advancements, whether that’s developing an app to make getting insurance quotes quicker and easier for customers or using advanced computer models to automate underwriting or fraud detection.
The opportunities that come from using AI are huge, so insurers are understandably keen to adopt even smarter and potentially more accurate agentic AI systems.
But, unfortunately, there are some big hurdles to overcome.
Why agentic AI creates a communications challenge
At the moment, new agentic systems seem to be making processes even more complex. For a process to be truly end-to-end, agentic AI and LLMs still have to work with legacy policy systems and existing tech stacks. The more touch points there are, the higher the risk of things going wrong. If things go wrong, you have to be able to manage any potential damage to your brand.
Even if all the rules and requirements are met, there must be crystal clear communications so that customers and regulators can understand exactly how your AI systems work. Due to how complex this technology can be, that might create an interesting challenge for communications teams. It can be tempting to boast simple claims about AI making insurance faster or more accurate, but the reality behind those claims can be much harder to explain.
Marketing and comms teams therefore need to understand what the technology actually does before talking about it publicly. Otherwise, there’s a risk that messaging could oversimplify how it works or make promises that the business just can’t support.
What regulations should insurers consider when using agentic AI?
Depending on where you operate and have customers, there are different regulations that you’ll have to meet. Legal and compliance teams will lead on this, but, wherever you’re based, the rules also affect how insurers talk about their use of AI to customers and other audiences.
Europe
The EU AI Act treats AI used in insurance risk assessment and quote pricing as ‘high-risk’, so full compliance with their regulatory framework was due by August 2026, but the EU’s recent Omnibus VII legislative package has moved the dates to 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products.
As it’s so comprehensive, we’ll cover this framework in more detail below. Essentially brokers and insurers using AI systems will need to be transparent about their use of AI, document their AI governance, keep detailed logs, run impact assessments and make sure there is real human oversight over AI outputs.
For marketing and comms teams, the important point is that what they say needs to match what is actually happening inside the business. Any claims about responsible AI need to be backed up by real processes and safeguards.
UK
There aren’t actually any AI-specific regulations in the UK, partly because the Financial Conduct Authority (FCA) doesn’t want to stifle innovation and competitiveness for an emerging technology that many see as a tool to improve things for both consumers and for insurers themselves. But the FCA is also very clear that their existing rules still apply, many of which do have a bearing on AI adoption.
They’ve written a page on how their rules apply to AI, but essentially, under the FCA’s Consumer Duty rules: ‘A firm must act to deliver good outcomes for retail customers.’ Like the EU’s AI act, the Consumer Duty rules also cover governance and transparency.
The FCA’s Senior Managers & Certification Regime makes individuals more accountable for their conduct and competence, so even with AI automation there still needs to be personal accountability and oversight.
UK GDPR also has provisions on automated decision-making, which means that customers can challenge decisions such as a denied insurance claim made only by automated systems.
Insurers therefore need to be careful about presenting their use of AI, because if people think it’s completely autonomous you could find yourself open to challenges and investigations, even if real people are behind the final decisions.
USA
Like the UK, there isn’t a single AI law for insurance. Instead, the National Association of Insurance Commissioners (NAIC) created a model bulletin on the use of AI systems by users, which acts as a guide for state insurance regulators. As of early 2026, 23 states and Washington, D.C. have adopted it.
The model bulletin tells insurers what is expected from them when using AI systems, and what regulators may ask to see during an investigation (including governance, data quality, transparency, evidence of bias controls, etc).
12 states are also taking part in NAIC’s AI systems evaluation tool pilot, to help ‘regulators understand how insurers use artificial intelligence and assess whether their governance practices may be effective in managing potential risks’.
Some states, such as New York, have added their own rules, so the exact requirements for compliance depend on where you do business.
For insurers working across different markets, this can make broad claims about being “AI compliant” tricky. Any communications need to be clear about which rules they are referring to.
How an AI accountability framework can help
The EU’s AI act has a specific regulatory framework for the insurance sector, so any company that’s looking to build their own accountability framework for AI use in the insurance industry would do well to study it (pretty urgently if you work in the EU).
For insurers, the AI Act offers a useful guide to what accountability looks like in practice. For example:
- Providers must ensure training, validation, and testing data sets follow data governance practices to detect and prevent biases that could lead to discrimination.
- Providers must ensure AI systems are designed to be transparent enough for users to interpret a system’s output and use it appropriately.
- Providers should ensure that the AI system undergoes a conformity assessment based on internal control to ensure compliance with the AI Act.
- Deployers should conduct a fundamental rights impact assessment prior to the first use of the AI system.
- Providers should register themselves and the AI system in the EU database.
- Providers/deployers should inform the relevant authority/providers and take corrective action/suspend the use of the system in case they identify a serious incident.
Your marketing and comms teams won’t be responsible for putting these measures in place. But an accountability framework will give them something pretty solid to work from. It can help them understand where AI is being used, what safeguards are in place, where people remain responsible and what the business can confidently say about the technology. This is particularly useful when launching a new AI-powered product or answering questions from journalists.
What happens when an insurer can’t explain its use of AI?
So far, the clearest example of misuse of AI in insurance comes from the ongoing Lokken vs. UnitedHealth Group in the USA.
UnitedHealth Group has a lawsuit filed against them for using algorithms to prematurely cut off care for elderly patients. The allegation is that the AI systems are being used to ignore human medical advice to save costs, which effectively breaches contracts that guarantee a human physician-led review. While the case is still ongoing, UnitedHealth Group has been ordered to produce documents and information related to the development of their AI system and they could be tied up in litigation for years, or have to pay quite a hefty settlement to resolve the case before it reaches trial.
Whatever the eventual outcome, the case shows how quickly the use of AI can become a reputational issue. Insurers need to be able to explain how decisions are made and what happens if a customer challenges an outcome.
We’ll keep updating this article to add more examples as we find them (so if you spot any, please let us know).
Why communicating how you’re using AI matters
The regulatory requirements vary by location, but the underlying accountability principles don’t really change. Wherever you operate, insurers need to be clear about how AI is being used and who is responsible for its outputs.
Insurers are now in a position where they need to be completely transparent about their AI use, but that isn’t a bad thing by any means. A clear PR strategy can help you to meet the necessary regulatory requirements while positioning your brand as a responsible innovator that customers, regulators, partners and investors can trust.
Before talking publicly about agentic AI, insurers should be able to answer a few simple questions:
- What does the technology actually do and what does it not do?
- Where does human judgement remain part of the process?
- What evidence supports claims about accuracy or efficiency?
- Does the business have a crisis communications plan for responding to mistakes or publicly disputed decisions?
That doesn’t mean turning regulatory compliance into a marketing campaign. It simply means making sure that anything you say about AI is accurate and can be backed up.
Looking for an InsurTech PR specialist or AI PR expert to tell your story? Drop us a line, we’d love to help!

By David Biggins
David is an award-winning marketer with a long history of helping large institutions and small businesses to develop their digital marketing.

