Resources
Home
/
Blog
/
Resources
/
What U.S. Insurers Should Learn From the EU AI Act

What U.S. Insurers Should Learn From the EU AI Act

A Calendar

Stay ahead in support AI

Get our newest articles and field notes on autonomous support.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
August 11, 2026

On August  2, the EU AI Act took effect. For the first time, new rules for both providers and deployers of AI systems are operating under a single risk-based framework. It imposes stricter requirements on high-risk systems, and for customer-facing tools like chatbots, it sets a simple transparency rule: People generally must be told when they are interacting with AI. 

For U.S. insurers, it would be easy to file this under “Save for later” and move on. But that would be a mistake. Europe's last major regulation, GDPR, followed a familiar path. Few U.S. companies were directly bound by it but its influence reached far past borders anyways, shaping vendor contracts, procurement standards, and product design worldwide.

The AI Act is likely to follow a similar path. Not every U.S. insurer will be directly subject to it. But its transparency rules offer an immediate lesson for one of the industry’s most common AI use cases: customer service.

Here’s what all insurers need to know.

Disclosure is Not Escalation

Article 50 does not say that every conversation must begin with: “Would you rather speak to a human?” What it says is that an AI system that interacts directly with a person must identify itself as AI, unless that fact is already obvious.

That may sound like a small distinction, but the implications can be significant.  

It’s true customers should know when they are dealing with AI. They should also be able to reach a person when they need one. But those two things have very different requirements.

An insurer that puts a large “talk to a representative” prompt at the start of every interaction may think it is taking the safest route or reducing friction. In practice, it is often building unnecessary friction that the law doesn’t require. Customers transfer before the AI even has a chance to solve anything. The deployment then looks less effective because it was designed to be bypassed.

The opposite approach is no better. A bot that traps a customer in a loop, misses signs of distress, or continues after losing confidence creates a new service failure at scale.

The right model is neither human-first nor AI-only. It is intelligent escalation.

Escalation Has to Be Built Around the Work, Not the Interface

Good escalation starts from one principle: The level of human involvement should rise with the consequence of the work.

Changing a mailing address is not the same as interpreting coverage. Answering a billing question is not the same as denying a claim. Insurers should design around those differences, not a single button that treats everything the same.

Here’s what to consider when building.

  1. The AI should identify itself once, in short, plain-language, not buried in a disclosure that nobody reads.
  2. Humans should stay accessible, not advertised. A persistent option beats a prompt that interrupts before the AI has tried to help.
  3. Escalation should trigger on context, not on request. Repeated failure, signs of financial hardship, a formal complaint, a request outside the system's authority — these are signals that should move a customer to a person automatically, without the customer having to find the right words to ask.
  4. The handoff should carry the work, not just the call. Conversation history, verified information, relevant documents, actions already taken, the reason for escalation. All of it should move with the customer. Otherwise, the person starting over is doing the AI's job twice.
  5. None of it works without authority defined in advance. This includes what the AI is allowed to say, which systems it can touch, which actions it can take on its own, and what needs a human's approval. It all needed to be decided before launch, and logged every time. 

AI Can Work Beside the Representative, Not Just in Front of Them

Not every customer-service AI deployment falls under Article 50's disclosure rule. When the AI operates solely in the background, never communicating with the customer directly, the direct-interaction requirement doesn't apply.

That is exactly the model health plans are already proving out. The conversation around customer-service AI tends to assume the technology either replaces a representative or isn't there at all. There is a middle ground: the customer still speaks with a person at the company, and the AI is helping that person move faster and more consistently.

A recent Becker's Hospital Review article discusses how SCAN Health Plan uses AI for real-time transcription, automated notes, and guided workflows. Independence Blue Cross piloted a tool that cut the steps representatives need to retrieve information and improved first-inquiry resolution. Humana's Agent Assist builds real-time summaries, predicts member needs, and surfaces relevant information for human advocates.

Falling outside the disclosure requirement doesn't mean falling outside governance. A recommendation surfaced to an employee shapes the answer a customer receives and the action that follows, whether or not the customer ever sees the AI that produced it.

The Control Layer Matters More Than the Disclaimer

The EU AI Act has been discussed as a compliance burden. For insurers, it is actually more useful as a design signal.

Transparency belongs at the start of the interaction. Authority belongs inside the workflow. Human judgment belongs wherever consequence, discretion, or accountability require it. Auditability belongs across the entire process.

Insurers do not need to choose between automation and human service. They need an operating model that uses each where it is strongest. AI for speed, consistency, and routine execution. People for judgment, exceptions, and authority.

That takes more than a model or a chatbot. It takes an operational control layer around AI, one that governs what an agent may say, access, and execute; records what happened, monitors performance, and routes work to people when human judgment is required.

The AI Act does not tell insurers to slow down. It tells them what must be in place to move forward, and Notch is here to build the control layer AI that is required.

Read more about the risks & challenges of customer support within insurance.

The AI Engine Behind
Regulated Operations

Book a Demo
Key Takeaways

Key Takeaways

  • Article 50 requires disclosure. It does not require escalation. An AI system that interacts with a person must identify itself as AI. Nothing in the rule asks for a "talk to a representative" prompt at the start of every conversation.
  • Front-loading a transfer button builds friction the law never asked for. Customers escalate before the agent has a chance to resolve anything. The deployment then gets measured on a design built to be bypassed.
  • Human involvement should rise with the consequence of the work. A mailing address change and a coverage interpretation do not belong behind the same button.
  • Escalation should trigger on context, not on request. Repeated failure, signs of financial hardship, a formal complaint, or a request outside the agent's authority should route to a person automatically.
  • The handoff has to carry the work. Conversation history, verified information, documents, actions already taken, and the reason for escalation move with the customer.
  • Background AI falls outside the disclosure rule and inside governance. Agent-assist tools never speak to the customer and still shape the answer the customer receives.
  • Authority gets defined before launch and logged every time. What the agent may say, which systems it can touch, which actions it can take alone, and what needs human approval.
  • FAQs

    Got Questions? We’ve Got Answers

    No items found.
    AUTONOMOUS ORGANIZATION

    Autonomous AI for operations leaders ready to turn complexity into advantage.

    Deployed in weeks. Autonomous in months. Compounding for years.

    Deliver better outcomes across every metric that matters
    Get more done across every channel, system, and workflow.
    Decouple revenue growth from operational cost.
    Every action governed, traceable, and audit-ready.