CATEGORY
EU AI Act from August 2026: What insurance brokers must prepare now
Daniel D.
12 Min Lesezeit

Thursday morning, 9:14 a.m. A clerk in your brokerage office has ChatGPT summarize an initial claim report. On your website, a chatbot answers the first questions from new prospects. Outlook automatically suggests replies. Nobody has written a guideline for this, nobody has documented a training session, nobody has checked which risk class this falls into.
This is the normal state of affairs in most 3- to 20-person brokerage offices in Germany. And this is exactly the constellation that falls under the stricter part of the EU AI Act starting August 2, 2026.
Most articles on the EU AI Act target insurers, Big 4 compliance departments, or the next hyperscaler study. What was missing until now: a calm, structured classification for the brokerage business that neither develops its own AI nor employs a three-digit compliance team. This is exactly what this article provides.
August 2, 2026, and what really applies on that day
The AI Act does not enter into force on a single day. It comes in four stages, and each stage complements the existing scope. Anyone in 2026 who only looks at the August deadline overlooks the fact that some of the obligations are already applicable from 2025.
DateWhat appliesRelevance for brokerage offices02.02.2025Prohibitions, Art. 4 AI literacyObligation to train and provide proof of competence for all employees using AI02.08.2025Obligations for providers of general-purpose AI models (GPAI)Does not affect brokers directly, but shapes the market of the tools used02.08.2026High-risk Annex III, transparency according to Art. 50, penaltiesThe main deadline for brokers02.08.2027High-risk Annex I (embedded AI in regulated products)Rarely relevant in the brokerage context
Source: EU Commission, AI Act Overview
Three points are important in this staging:
First: Art. 4 on AI literacy already applies. Anyone currently using AI in day-to-day business must convey, document, and maintain an appropriate understanding of the systems used for their employees. The Federal Network Agency has published a guidance paper clarifying this standard.
Second: August 2, 2026, is the day on which the transparency obligations according to Article 50 become active. Chatbots on brokerage websites must then be recognizably identified as AI systems, AI-generated content must be marked accordingly, and the high-risk list in Annex III becomes enforceable. Fines will also apply start on this day.
Third: The regulation does not only affect those who develop AI. It also affects those who use AI. This distinction is at the heart of the second question.
Is your brokerage office affected at all? The risk classes demystified
The AI Act distinguishes between two key roles: providers and deployers. A provider is anyone who develops an AI system or places it on the market under their own name. A deployer is anyone who uses such a system under their own responsibility.
For the vast majority of brokerage offices, they are deployers, not providers. You use ChatGPT, Microsoft Copilot, Outlook AI functions, website chatbots, AI functions of your broker management program. You do not develop these systems, you use them. This means that only the deployer obligations apply to you, not the much more extensive provider obligations.
Within the deployer perspective, the regulation categorizes AI systems into four risk classes:
Prohibited practices (e.g., social scoring by authorities, manipulative cognitive behavioral manipulation). Practically irrelevant in normal brokerage business.
High-risk systems according to Annex III. In the insurance environment, this includes in particular AI systems for risk and pricing assessment in life and health insurance, as well as AI-powered creditworthiness assessments and biometric analyses.
Limited risk with transparency obligations according to Art. 50. This includes chatbots, AI-generated texts and images, and emotion recognition.
Minimal risk. This is where most of the practical AI use in a brokerage office ends up: AI-assisted text creation, classification of emails, summaries, standard research.
For the typical 3- to 20-person brokerage office, the honest answer is: As a rule, you do not operate any high-risk AI systems. Risk and pricing assessment engines lie with the insurer, not the broker. Biometric analyses are not an issue outside of very specialized major brokers. What remains are tools with limited or minimal risk.
A typical broker stack in May 2026 looks like this:
ToolUse in brokerage officeRisk classChatGPT, Microsoft CopilotEmail drafts, research, text creationMinimalOutlook CopilotSuggested replies, meeting preparationMinimalWebsite chatbotInitial answers to prospectsLimited (Art. 50)AI function in broker management programTransaction classification, document recognitionMinimal to limitedClaims form assistantInitial report structuringMinimalRisk pricing engine of an insurerResponsibility of the insurerHigh risk, but not at the broker
In this setup, the chains of responsibility are clear. High-risk systems only appear in the brokerage business where they are provided by an insurer. In this case, the provider obligation lies with the insurer, not the broker office.
This classification puts the compliance panic that resonates in many publications into perspective. However, it does not replace an individual assessment. This assessment is the first of the four obligations.
Digital brokerage starts with the question of how work actually arises. Once you understand this, building compliance becomes easier because you are already documenting your own use of AI anyway.
The four obligations that are really relevant for small offices
Without a high-risk classification, the catalog of obligations shrinks to four operational building blocks. In total, this is about four to six hours of one-time effort to set up for a small office, followed by continuous maintenance.
Obligation 1: AI Inventory
You need a written overview of all AI systems that are actually used in the office. Not every tool in the stack, but every one with productive use.
A sufficient table has five columns:
Tool and provider
Purpose of use in the office
Risk class (limited, minimal)
Responsible person
Date of last check
This overview serves as the basis for training, guidelines, and audits. It is also what you present to a supervisory authority in the event of an inquiry.
Obligation 2: AI Guidelines
A one-page internal policy regulates what AI may be used for in the office, what it may not be used for, and who approves it. Pragmatic content:
Which data classes may be entered into AI tools (e.g., general customer communication yes, sensitive health data no)
Which tasks can run fully automatically, which only as preparation with human approval
Which tools are approved, which must be checked before use
Who is the contact person in case of uncertainties
The guideline does not replace GDPR documentation, but complements it. It is the anchor to which training and inventory refer.
Obligation 3: AI Literacy according to Article 4
Art. 4 requires every deployer to ensure that employees working with AI have a sufficient understanding of the systems. This does not mean that every employee needs a computer science degree. It means: they can understand what the AI is intended for, what its limits are, what errors are typical, and how to verify a result.
In practice, for a small office, the following is sufficient:
A 60- to 90-minute internal training session per year
A simple training register with name, date, content, signature
A quick refresher for any major tool update
The Federal Network Agency's guidance paper provides pragmatic guidance on this. The frequency of training is based on the scope and risk of the AI use.
Obligation 4: Transparency according to Article 50
From August 2, 2026, three points must be transparently regulated:
Chatbot labeling. Anyone who uses an AI-powered chat on their website must make this recognizable. A discreet note "This conversation is supported by an AI system" at the beginning of the chat is sufficient.
AI-generated content. Texts, images, and voices that are AI-generated and could mislead people must be labeled. In practice, this rarely affects standard marketing copy, but rather avatars in training videos, for example.
Emotion recognition and biometric categorization. Here, the data subject must be informed. Rarely relevant in classic brokerage operations.
These points are not complex. They primarily require that you are aware of where AI becomes visible in customer contact.
Anyone who wants to generate operational leverage instead of hiring more staff will have to document AI tools systematically anyway. The regulation basically demands what a well-run business should be doing anyway.
What BaFin and AfW say and what this means in broker practice
Two voices shape classification in the insurance sector: BaFin as the supervisory authority for the insurance sector, and the AfW Federal Association as the most important broker representation.
The BaFin specified its position in a speech on March 6, 2025: The responsibility for the responsible use of AI lies with the companies, not with the tools. Translated into the brokerage context, this means: anyone who uses AI must be able to prove that they use it professionally. That is precisely the purpose of the inventory, guideline, and training register.
The AfW Federal Association of Financial Services has a clear message in its guidance paper on the AI Act for insurance brokers: the typical broker business does not fall under the high-risk obligations, but must take the deployer obligations seriously. This is aligned with the classification in this article and reduces the effort to what is actually necessary.
Regarding potential fines, eye-catching numbers are circulating: up to 35 million euros or 7 percent of global annual turnover. These peak values are aimed at hyperscalers and systematic violations. For a 5-person brokerage office that conscientiously fulfills its obligations, this is not a realistic risk. On the other hand, anyone who works without any documentation and cannot present any compliance trace in the event of an inquiry is walking on thin ice. Even if the fine remains manageable in practice, the reputational risk toward customers and insurers is greater.
The national supervisory structure is expected to be split: the Federal Network Agency as the central AI supervisory authority, BaFin as the sectoral supervisor for insurance. For insurance brokers, BaFin is likely the more relevant contact in case of doubt.
Structural performance is not created by processing more tasks manually, but by ensuring that work is clearly documented and traceable. At its core, the AI Act demands exactly this level of care.
Your 6-step roadmap until August 1, 2026
Anyone who does not have a compliance structure for AI use as of May 2026 can manage the preparation well until August 1. This roadmap is tailored to a 5- to 15-person office.
MonthActionResponsibleEffortMay 2026Create AI inventory (tools, purpose, responsible persons)Management1.5 hoursJune 2026Adopt AI guidelines (one document, one page)Management1 hourJune 2026Prepare training materials (internal slide decks, Q&A)Data Protection/IT1.5 hoursJuly 2026Conduct internal training (60-90 min, training register)Management1.5 hoursJuly 2026Check and label website chatbotMarketing/IT0.5 hoursAugust 2026Schedule first quarterly review in AI inventoryManagement0.5 hours
Total: about six hours spread over three months. This is doable alongside day-to-day business.
After August 1, the maintenance of obligations continues. The inventory is checked quarterly, the training register is updated annually, and the guidelines are adjusted in the event of major changes to tool usage. Once this has been set up properly, it can be maintained with manageable effort.
Revenue per employee stands and falls with the question of how many hours are lost in non-value-adding work. A well-configured AI compliance costs six hours once and protects against significantly more expensive improvisations if a supervisory authority actually asks.
Frequently Asked Questions
When does the EU AI Act apply to insurance brokers?
Significant parts are already in effect. Art. 4 on AI literacy has been applicable since February 2, 2025. The main obligations for deployers, in particular transparency obligations according to Art. 50 and the high-risk rules from Annex III, arise on August 2, 2026. Anyone currently using AI in day-to-day business is therefore already obliged to build up and document AI literacy in their team.
Is my brokerage office affected if I only use ChatGPT for standard texts?
Yes, but within the framework of deployer obligations and not as a high-risk application. Using ChatGPT for preparing emails or claims notifications falls under minimal to limited risk. You must document the use, train your employees on how to use it, and ensure that no sensitive data flows into the system unchecked. A high-risk classification does not apply here as a rule.
What are the obligations under Article 4 of the AI Act?
Art. 4 requires providers and deployers to ensure that their staff have a sufficient level of AI literacy. In practice, this means: anyone using AI knows how the system works, what its limits are, and how to verify results. For small offices, an annual internal training session with a training register is sufficient. Formal certification is not required.
Are AI training sessions mandatory for insurance brokers?
Yes, as soon as AI systems are used productively in the office. The training obligation follows from Art. 4 and is not linked to the high-risk classification. It applies to all deployers and is based on the scope and risk of the AI use. An annual refresher is a practical standard; in individual cases less is sufficient, on other occasions more is needed.
What happens in the event of violations of the AI Act?
The theoretical fine framework reaches up to 35 million euros or 7 percent of worldwide annual turnover. These peak values target systematic violations by major providers. For a typical brokerage office with solid documentation, this is not a realistic scenario. The practical risk of supervisory inquiries without a verifiable compliance trail and the resulting reputational damage to clients and insurers is greater.
What is the difference between provider and deployer under the AI Act?
A provider is anyone who develops an AI system or distributes it under their own name. A deployer is anyone who uses such a system under their own responsibility. Insurance brokers are usually deployers because they use AI tools from other providers. Consequently: the significantly more extensive provider obligations (conformity assessment, technical documentation, risk management system) do not affect brokerage offices. What remains are the deployer obligations on documentation, training, and transparency.
Conclusion: Care beats panic
The EU AI Act does not require a compliance revolution from insurance brokers. It requires an organized inventory, a brief guideline, an annual training session, and three visible transparency notices. In total, this amounts to six hours of setup effort until August 1, 2026, followed by ongoing maintenance.
What the AI Act changes beyond that: it turns the responsible handling of AI into a documented routine. Those who take this seriously gain more than just legal certainty. They gain a clear view of where AI actually creates value in their own operations and where it only runs as a fashionable accessory.
That is exactly where the structural question begins that we observe daily at Modus. What work does the system take over, what remains with humans, and how do we measure the leverage?
Scale revenue. Not headcount.
Do not miss any news in the field of AI for insurance brokers. Sign up for updates now.
See the mode in live operation.
30 minutes. Real-world tasks from your brokerage. We'll show you how incoming communication is transformed into structured work.