If you are looking for the broader picture —why insurers' AI pilots don't scale and which three processes are the natural candidates—, start with AI for insurers: claims, underwriting and production. This piece drills into one of them: automating insurance claims with AI, with the operational and regulatory detail the overview doesn't cover.
A claim isn't one process: it's six
The most expensive framing error is treating "claims" as one thing you automate in a single move. It isn't. A claim goes through phases of very different natures, and AI fits each one unevenly:
- Intake and classification. The notice arrives by phone, app, email or broker. You must identify the policy, the cover and the claim type.
- Document gathering. Reports, photos, invoices, loss adjuster reports, police statements.
- Cover check. Is what happened covered by this policy, with these limits and these exclusions?
- Assessment. How much it costs, against which scale, with or without a loss adjuster.
- Decision and communication. Accept, reject or request more information. And explain it to the policyholder.
- Payment and closure.
Where AI contributes most and risks least is in 2 and 3: reading heterogeneous documentation, extracting data and checking it against the policy wording. That is reading and comparison work — high in volume, low in judgement. Where it risks most is in 5, because that's where there is a decision affecting a person and a communication that now carries obligations of its own.
That distinction isn't theoretical: it determines what you can deploy today and what requires additional governance. And it determines what affects you out of everything landing this week.
What changed on 24 July: the postponement is now law in force
Through June and July the sector read "the EU delays the AI law" headlines about a political agreement that had not been published yet. That ambiguity is over: Regulation (EU) 2026/1744, which amends Regulation (EU) 2024/1689 (the AI Act), was published in the Official Journal on 24 July 2026 and has been in force since 27 July.
The dates it sets, now binding as a calendar:
| What | When it applies |
|---|---|
| Transparency obligations (art. 50) and the associated penalty regime | 2 August 2026 — not postponed |
| Marking of synthetic content (art. 50(2)) for generative systems already on the market before 2 Aug 2026 | 2 December 2026 — four-month transitional period |
| High-risk systems under art. 6(2) and Annex III (where the insurance case sits) | 2 December 2027 |
| High-risk systems under art. 6(1) and Annex I (AI embedded in already-regulated products) | 2 August 2028 |
For an insurer, the practical reading has two halves worth keeping apart. First: there are sixteen months of runway before the hard high-risk obligations bite, and that runway is an opportunity to build properly — not an excuse not to start. Second: what applies on 2 August applies anyway, whether or not your system is high-risk.
What applies on 2 August if you have AI touching claims
As far as claims handling goes, the transparency obligations of Article 50 come down to two concrete things:
- Disclosing that there is an AI. If the policyholder interacts with an AI system —an assistant that opens the claim, a channel requesting extra documentation— and it isn't obvious, you must tell them.
- Marking generated content. Synthetic content —text, image, audio— must be identifiable as such in a machine-readable format.
Translated into your operation: if you use a conversational assistant at intake, or automatically generate the communication to the policyholder about the resolution of their claim, that affects you now. And it affects the channel — not the model — so the work isn't data science: it's interaction design, disclosure and logging.
One useful nuance the reform introduces: for providers of generative systems already on the market before 2 August 2026, the marking duty of Article 50(2) isn't enforceable until 2 December 2026. Four months of air, not an exemption.
Not all your processes are high-risk (and it pays to know which)
Here is the nuance that gets flattened most often in the sector, and where reading precisely saves a lot of unnecessary work.
Annex III, point 5(c) classifies as high-risk AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance. Two delimitations follow, and they matter:
- It is pricing and risk assessment, not claims handling as such. Automating the reading of a loss report and checking it against the policy wording is not, in itself, what that point describes.
- It is life and health. Pricing in non-life lines —motor, home, commercial— is not covered by 5(c).
The practical reading for a composite insurer: the same governance model does not apply equally across your whole operation. Treating everything as high-risk is expensive and stalls projects that could be in production; treating nothing as high-risk is the other extreme, and that one does get paid for.
Caveat: these delimitations have legal consequences and must be validated with your own counsel against the official consolidated text before you make deployment decisions. They are set out here as a working framework, not as legal advice. Regulatory situation verified on 1 August 2026 on EUR-Lex.
What actually makes claims automation fail (and it isn't the model)
Worth saying, because the regulatory calendar is being used these days to explain everything: claims pilots that never reach production rarely fail because of regulation, and almost never because of model capability. They fail for three recurring reasons.
The policy wording isn't anywhere the AI can use it. Covers, limits, deductibles and exclusions live in PDFs by product and by year of issue, with versions only long-tenured staff know about. Without that context structured and current, the system answers generically — and in insurance, generic means wrong.
There is no traceability of why what was decided got decided. If a policyholder complains, or the regulator asks, "the model said so" is not an answer. Every conclusion has to point to the specific clause and the document in the file that supports it.
The human is in the wrong place. Either everything gets reviewed —and then there are no savings— or nothing does —and then there is risk. What works is putting human control where the impact justifies it: phase 5, the decision and the communication. Not in reading invoices.
The last two, moreover, are exactly what the high-risk technical documentation will require of you in 2027. Building them now isn't front-loading regulatory work: it's what makes the project work at all. That it also serves you in December 2027 is a consequence, not the reason. On how that is designed from the start, compliance-first: audit-ready AI agents from day one.
How to start without a big programme
A path that respects the above and delivers measurable results in weeks:
- Pick one narrow claim type —one line of business, one high-frequency, low-complexity claim— instead of "claims" in general.
- Classify before you build. Which processes touch pricing or risk assessment in life and health, and which don't. Half a day with your counsel saves months of wrongly sized governance.
- Order the context before the model: current policy wordings by product, scales, internal criteria, past files. It is the least glamorous work and the one that decides the outcome.
- Automate phases 2 and 3 (document reading and cover checking), leaving decision and communication in the handler's hands.
- Cover transparency from day one: AI interaction disclosure and marking of generated content. It's cheap to do while designing the channel and expensive to retrofit.
- Require traceability by default: every extraction and every conclusion, with its source.
- Measure three things: average handling time, reopening rate and cost per claim. If the second goes up, the first is worthless; if the third doesn't fall as you scale, the business case dissolves. On that last one, the real cost of AI in production.
Frequently asked questions
Is automating insurance claims with AI a high-risk system under the AI Act?
Not necessarily. Annex III, point 5(c) of Regulation (EU) 2024/1689 points to risk assessment and pricing in relation to natural persons in life and health insurance. Handling a claim is not, in itself, that case. Every specific case must be validated with legal counsel against the official text.
Has the AI Act been delayed?
Partially, and it is now law in force. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July, postpones to 2 December 2027 the obligations for high-risk systems under Article 6(2) and Annex III, and to 2 August 2028 those for systems under Article 6(1) and Annex I. The transparency obligations of Article 50 were not postponed: they apply from 2 August 2026.
What applies from 2 August 2026 if I use AI in claims handling?
The transparency obligations of Article 50: informing a person that they are interacting with an AI system when it is not obvious, and marking artificially generated or manipulated content. If you use a conversational assistant to open the claim, or automatically generate communications to the policyholder, that affects you regardless of whether the system is high-risk. For generative systems already on the market before that date, the marking duty of Article 50(2) is enforceable from 2 December 2026.
Does it affect non-life insurance?
Annex III point 5(c) refers to life and health insurance. Risk assessment and pricing in motor, home or commercial lines are not covered by that case, which does not exempt you from the other applicable obligations, starting with transparency.
What do I measure to know whether claims automation is working?
Average handling time and reopening rate, together and on the same dashboard. Going faster while reopening more claims is making the process worse with extra steps. And cost per processed claim, so the business case still stands when volume scales.
Conclusion
Claims automation is one of the best effort-to-return processes in an insurer, and the postponement of the high-risk obligations opens a reasonable window to build it properly rather than fast. But don't mistake the postponement for a general moratorium: what applies on 2 August applies anyway, and it affects the channel you talk to your policyholder through.
And the part that decides the outcome is neither regulatory nor about the model: it's whether your own knowledge —current policy wordings, handling criteria, past files— is available and structured. That's where it's won or lost. It's the same idea behind your company's AI intelligence: process by process, with the AI that understands how you work.
Honesty note: onext does not yet have a publishable case in the insurance sector. What we bring is the method for taking document-heavy processes into governed production, proven in other sectors, and the reading that in insurance the bottleneck is no different: it's the corporate context. If you're looking for a provider with twenty claims case studies, that isn't us. If you're looking for someone to put your context in order and leave you operating it, let's talk.
If you want to see how this would look in your operation, and we'll go through it with a real claim type of yours.

Jordi García is Tech Lead at onext. He works on bringing AI into governed production across development and product teams —with Spec-Driven Development, context engineering and human verification at every step— and authors onext's technical insights on the method, quality and cost of applied AI.
LinkedIn →