What U.S. Insurers Should Learn From the EU AI Act

Stay ahead in support AI
Get our newest articles and field notes on autonomous support.
On August 2, the EU AI Act took effect. For the first time, new rules for both providers and deployers of AI systems are operating under a single risk-based framework. It imposes stricter requirements on high-risk systems, and for customer-facing tools like chatbots, it sets a simple transparency rule: People generally must be told when they are interacting with AI.
For U.S. insurers, it would be easy to file this under “Save for later” and move on. But that would be a mistake. Europe's last major regulation, GDPR, followed a familiar path. Few U.S. companies were directly bound by it but its influence reached far past borders anyways, shaping vendor contracts, procurement standards, and product design worldwide.
The AI Act is likely to follow a similar path. Not every U.S. insurer will be directly subject to it. But its transparency rules offer an immediate lesson for one of the industry’s most common AI use cases: customer service.
Here’s what all insurers need to know.
Disclosure is Not Escalation
Article 50 does not say that every conversation must begin with: “Would you rather speak to a human?” What it says is that an AI system that interacts directly with a person must identify itself as AI, unless that fact is already obvious.
That may sound like a small distinction, but the implications can be significant.
It’s true customers should know when they are dealing with AI. They should also be able to reach a person when they need one. But those two things have very different requirements.
An insurer that puts a large “talk to a representative” prompt at the start of every interaction may think it is taking the safest route or reducing friction. In practice, it is often building unnecessary friction that the law doesn’t require. Customers transfer before the AI even has a chance to solve anything. The deployment then looks less effective because it was designed to be bypassed.
The opposite approach is no better. A bot that traps a customer in a loop, misses signs of distress, or continues after losing confidence creates a new service failure at scale.
The right model is neither human-first nor AI-only. It is intelligent escalation.
Escalation Has to Be Built Around the Work, Not the Interface
Good escalation starts from one principle: The level of human involvement should rise with the consequence of the work.
Changing a mailing address is not the same as interpreting coverage. Answering a billing question is not the same as denying a claim. Insurers should design around those differences, not a single button that treats everything the same.
Here’s what to consider when building.
- The AI should identify itself once, in short, plain-language, not buried in a disclosure that nobody reads.
- Humans should stay accessible, not advertised. A persistent option beats a prompt that interrupts before the AI has tried to help.
- Escalation should trigger on context, not on request. Repeated failure, signs of financial hardship, a formal complaint, a request outside the system's authority — these are signals that should move a customer to a person automatically, without the customer having to find the right words to ask.
- The handoff should carry the work, not just the call. Conversation history, verified information, relevant documents, actions already taken, the reason for escalation. All of it should move with the customer. Otherwise, the person starting over is doing the AI's job twice.
- None of it works without authority defined in advance. This includes what the AI is allowed to say, which systems it can touch, which actions it can take on its own, and what needs a human's approval. It all needed to be decided before launch, and logged every time.
AI Can Work Beside the Representative, Not Just in Front of Them
Not every customer-service AI deployment falls under Article 50's disclosure rule. When the AI operates solely in the background, never communicating with the customer directly, the direct-interaction requirement doesn't apply.
That is exactly the model health plans are already proving out. The conversation around customer-service AI tends to assume the technology either replaces a representative or isn't there at all. There is a middle ground: the customer still speaks with a person at the company, and the AI is helping that person move faster and more consistently.
A recent Becker's Hospital Review article discusses how SCAN Health Plan uses AI for real-time transcription, automated notes, and guided workflows. Independence Blue Cross piloted a tool that cut the steps representatives need to retrieve information and improved first-inquiry resolution. Humana's Agent Assist builds real-time summaries, predicts member needs, and surfaces relevant information for human advocates.
Falling outside the disclosure requirement doesn't mean falling outside governance. A recommendation surfaced to an employee shapes the answer a customer receives and the action that follows, whether or not the customer ever sees the AI that produced it.
The Control Layer Matters More Than the Disclaimer
The EU AI Act has been discussed as a compliance burden. For insurers, it is actually more useful as a design signal.
Transparency belongs at the start of the interaction. Authority belongs inside the workflow. Human judgment belongs wherever consequence, discretion, or accountability require it. Auditability belongs across the entire process.
Insurers do not need to choose between automation and human service. They need an operating model that uses each where it is strongest. AI for speed, consistency, and routine execution. People for judgment, exceptions, and authority.
That takes more than a model or a chatbot. It takes an operational control layer around AI, one that governs what an agent may say, access, and execute; records what happened, monitors performance, and routes work to people when human judgment is required.
The AI Act does not tell insurers to slow down. It tells them what must be in place to move forward, and Notch is here to build the control layer AI that is required.
Read more about the risks & challenges of customer support within insurance.
Key Takeaways
Got Questions? We’ve Got Answers
Autonomous AI for operations leaders ready to turn complexity into advantage.
Deployed in weeks. Autonomous in months. Compounding for years.





