Insurance has been using actuarial models — mathematical systems that use statistical patterns in historical data to predict future outcomes and price risk accordingly — since the early 19th century. Lloyd’s of London was pricing maritime risk through underwriter judgment and accumulated data tables in the 1680s. The fundamental activity of insurance: take inputs about a person or asset, run them through a model, produce a risk score, set a premium. This has not changed in 340 years.
The EU AI Act’s high-risk classification of AI systems used in “access to or use of… essential private services and benefits” — which includes insurance — is, in a narrow technical sense, treating a digitized version of something insurance has always done as a novel and dangerous practice requiring regulatory scrutiny. The classification isn’t wrong. The digital AI versions of actuarial models are more powerful, faster, more granular, and less transparent than their historical antecedents, and they can produce discriminatory outcomes at a scale and speed that human underwriters never could.
But the regulation’s application in practice has produced consequences that are stranger and more specific than the general principle suggests.
What “Credit Scoring” Actually Covers
The high-risk provisions for essential private services include AI systems used in credit scoring, but the term “credit scoring” has been interpreted by national competent authorities with varying breadth. Germany’s interpretation is relatively narrow: a credit scoring system is a system that produces a score specifically used for credit decisioning. France’s interpretation, articulated in CNIL guidance from April 2026, is considerably broader: any AI system whose output “materially influences” a credit decision is a credit scoring system, regardless of whether the output is labeled a “score.”
This interpretive divergence creates a compliance problem for fintech companies operating across multiple EU member states. A product that the company has structured to avoid high-risk classification in Germany may nonetheless be high-risk under France’s interpretation. Achieving compliance simultaneously across 27 member states — each with its own national competent authority and interpretive culture — requires either the broadest possible compliance approach (treating every plausibly relevant system as high-risk) or a sophisticated country-by-country legal analysis.
The broadest-possible approach is what most large financial institutions have adopted, effectively. Major banks — BNP Paribas, Deutsche Bank, ING — have inventoried their AI systems, classified everything that touches credit, insurance, or investment decisioning as high-risk regardless of its specific function, and are pursuing conformity assessments accordingly. This is conservative and expensive. It’s also the approach that legal teams recommend when the cost of misclassification is potential enforcement and fine.
Fintech startups — where the compliance overhead is proportionally much more significant — have been less able to afford this approach. Many have opted for the country-by-country analysis, which creates ongoing legal cost and the ever-present risk that they guessed wrong on a specific market.
The Insurance Pricing Paradox
The insurance AI story has an additional wrinkle that makes it particularly instructive. Insurance pricing models that use AI to process large numbers of variables — including behavioral data, location data, and increasingly biometric data — can produce more accurate risk predictions than traditional actuarial methods. More accurate pricing, in theory, benefits consumers through more efficient risk pooling: people who represent lower risk pay less; people who represent higher risk pay more.
The EU AI Act’s transparency requirements for high-risk AI create an interesting tension with insurance pricing’s commercial logic. Insurers are not required to reveal their pricing models — trade secret protection covers proprietary actuarial methodologies — but they are required to provide meaningful explanation to customers of how AI-based decisions affecting them were reached. An insurer must be able to explain, in a way a customer can understand, why their premium was set at a specific level.
This “explainability” requirement creates pressure against complex AI pricing models whose outputs cannot be easily explained in human-intelligible terms. A gradient boosting model that considers 3,000 variables to produce a premium quote cannot be explained to a customer in a meaningful way without compromising the model’s proprietary value. The Act’s explainability requirement and commercial pricing logic are in direct tension.
Some insurers are responding by simplifying their AI pricing models — moving back toward fewer, more interpretable variables. This satisfies the Act’s transparency requirements but may produce less accurate pricing. Whether “less accurate pricing” is a harm or a feature depends heavily on your view of whether extremely granular AI-based risk differentiation is beneficial or discriminatory. If the AI model is pricing people accurately, it may be pricing low-income neighborhoods, certain ethnic groups, and people with certain health conditions out of affordable insurance. If it’s pricing inaccurately, it’s creating adverse selection problems. This is not a question the EU AI Act resolves; it’s a question the Act forces into the open.
The insurtech startup Tractable — based in London with EU operations — has navigated this by building explainability into their AI damage assessment products from the beginning. Their vehicle damage and property damage assessment AI is designed to produce not just a cost estimate but a documented reasoning chain that can be shown to customers and regulators. This design choice is expensive but has become a competitive differentiator in the EU market.
The Mortgage Market Test Case
The most concrete example of how financial services AI compliance is playing out in practice is the European mortgage market, where AI credit assessment has become a live enforcement issue.
Dutch ING Bank began deploying an AI-based mortgage assessment system in November 2024. The system uses machine learning to evaluate mortgage applications, incorporating a broader range of data than traditional credit scoring models. By early 2025, approximately 40 percent of Dutch mortgage applications were being assessed by the system as the primary evaluation. ING notified the Dutch financial regulator (AFM) and began the process of EU AI Act high-risk conformity assessment.
The conformity assessment process, conducted by Lloyd’s Register (serving as a Notified Body for AI systems), took seven months. It identified 12 areas requiring modification in ING’s system — primarily relating to transparency documentation, human oversight protocols, and the system’s handling of edge cases. ING made the modifications and received certification in August 2026.
The modifications required by the conformity assessment were substantive. ING had to redesign the human oversight workflow — previously, a loan officer could simply approve or override the AI’s decision; the certification required a more documented process for override decisions, with reasons recorded and subject to audit. ING also had to redesign how they explained AI mortgage decisions to rejected applicants — the previous explanation (“your application did not meet our criteria”) didn’t meet the Act’s requirement for meaningful explanation.
These are genuine improvements to consumer protection. But they came at a cost that ING can absorb — the conformity assessment process cost approximately €180,000, the product modifications required 14 person-months of engineering, and ongoing compliance will require dedicated audit resources. A fintech lender attempting to enter the Dutch mortgage market with an AI underwriting product would face the same requirements without the infrastructure to meet them cheaply.
The Net Effect
The financial services sector’s experience with EU AI Act compliance in its first year illustrates the regulation’s fundamental tension: its compliance overhead is regressive in competitive terms, falling more heavily on smaller players, while its protections for consumers are genuinely valuable.
European consumers who were being evaluated by financial AI now have better transparency rights, clearer explanation obligations, and more documented human oversight processes. These are real gains. The consumer who was previously denied a loan by an AI system with no explanation now has a legal right to a meaningful one.
What hasn’t changed is the fundamental competitive dynamic: the large banks with the resources to achieve compliance gracefully are strengthening their market position relative to fintech challengers. The regulation designed to make financial AI more trustworthy is also making financial AI markets more concentrated. Both things are true simultaneously, and the regulation’s architects — focused on consumer protection, not competition policy — didn’t fully price in the second-order competitive effects.
This is the financial services AI Act story in miniature. Better in the ways it intended. Worse in the ways it didn’t consider.
The Open Banking Intersection
There’s a specific dynamic in European fintech that intersects with the AI Act in ways that haven’t received adequate attention: Open Banking and PSD3.
The EU’s revised Payment Services Directive (PSD3), implementing in 2025-2026, expanded open banking requirements — creating standardized APIs through which customers can share their financial data with third-party providers. Open banking was designed to increase competition by lowering barriers for fintech challengers to access customer financial data with customer consent.
The AI Act’s high-risk provisions for financial services AI interact with open banking in a structurally awkward way. A fintech using open banking data to build a personalized financial management AI is working with a data type explicitly designed to be accessible for competitive services. But if that AI crosses into credit assessment or insurance risk profiling, it’s in the high-risk tier — with conformity assessment requirements that the regulation’s open banking policy was trying to make it easier for challengers to avoid.
A Lisbon-based fintech — Bluestone, currently in Series A — built a cash flow-based lending product specifically to serve EU SMEs that traditional bank credit scoring systematically undervalues. Their lending model uses 18 months of cash flow data (available through open banking) to predict repayment capacity. It’s a meaningfully different approach from traditional credit scoring and produces better outcomes for the underserved segment it targets.
Is it high-risk under the AI Act? Almost certainly yes — it determines credit access. Bluestone is currently navigating the conformity assessment process at an estimated cost of €120,000, while their US-backed competitors offering similar products to American SMEs spent nothing equivalent. The open banking data access that was supposed to make them competitive comes with an AI regulation overhead that partially negates the competitive benefit.
The regulation pulled in two directions simultaneously — increasing data access through open banking while increasing compliance burden on the AI built on that data — and nobody appears to have sat in the same room to notice.
One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.
