AI in the brokerage: study by the DKM's KI Navigator, with AssCompact Take part now!

EU AI Act from August 2026: what insurance brokers need to prepare now

What insurance brokers need to have prepared by 2 August 2026: an AI inventory, an AI policy, training under Art. 4, transparency under Art. 50. A sorted breakdown for 3- to 20-person brokerages, without the compliance panic.

DD

By Daniel D.

Modus

Last updated: May 27, 2026

News & Insights

Thursday morning, 9:14. A caseworker in your brokerage has ChatGPT summarise an initial claim report. On your website, a chatbot answers the first questions from new prospects. Outlook automatically suggests replies. No one has written a policy for this, no one has documented any training, no one has checked which risk class it falls into.

That's the normal state in most 3- to 20-person brokerages in Germany. And it's exactly the configuration that, from 2 August 2026, falls under the tightened part of the EU AI Act.

Most pieces on the EU AI Act target insurers, Big Four compliance departments or the next hyperscaler study. What's been missing so far: a calm, sorted breakdown for the brokerage that neither develops its own AI nor employs a three-digit compliance team. That's exactly what this article provides.

2 August 2026 and what really applies on that day

The AI Act doesn't come into force on a single day. It arrives in four stages, and each stage adds to what already applies. Anyone looking in 2026 only at the August deadline overlooks that some of the obligations have already been applicable since 2025.

Three points matter in this staggering:

First: Art. 4 on AI literacy already applies. Anyone using AI in day-to-day business as of today must give their staff an appropriate understanding of the systems in use, document it and keep it up to date. The Federal Network Agency has published a guidance paper that makes the benchmark concrete.

Second: 2 August 2026 is the day the transparency obligations under Article 50 take effect. From then, chatbots on broker websites must be identifiable as AI systems, AI-generated content must be labelled accordingly, and the high-risk list in Annex III becomes enforceable. From that day the fine ranges also apply.

Third: the regulation concerns not only those who develop AI. It also concerns those who deploy AI. This distinction is at the heart of the second question.

DateWhat appliesRelevance for brokerages
Feb 2, 2025Prohibitions, Art. 4 AI literacyTraining obligation and proof of competence for all staff who use AI
Aug 2, 2025Obligations for providers of general-purpose AI models (GPAI)Does not affect brokers directly, but shapes the market for the tools they use
Aug 2, 2026High-risk Annex III, transparency under Art. 50, penalty frameworkThe main deadline for brokers
Aug 2, 2027High-risk Annex I (embedded AI in regulated products)Rarely relevant in the broker context

Is your brokerage affected at all? The risk classes untangled

The AI Act distinguishes two central roles: provider and deployer. A provider is anyone who develops an AI system or places it on the market under their own name. A deployer is anyone who uses such a system under their own responsibility.

For the vast majority of brokerages the rule is: you are deployers, not providers. You use ChatGPT, Microsoft Copilot, Outlook AI functions, website chatbots, AI features of your broker management system. You don't develop these systems, you use them. That means only the deployer obligations apply to you, not the considerably more extensive provider obligations.

Within the deployer perspective, the regulation sorts AI systems into four risk classes:

  • Prohibited practices (e.g. social scoring by authorities, manipulative influence). Practically irrelevant in normal broker business.
  • High-risk systems under Annex III. In the insurance environment this includes in particular AI systems for risk and price assessment in life and health insurance, as well as AI-supported creditworthiness checks and biometric analyses.
  • Limited risk with transparency obligations under Art. 50. This covers chatbots, AI-generated texts and images, emotion recognition.
  • Minimal risk. This is where most practical AI use in a brokerage lands: AI-supported text generation, email classification, summaries, standard research.

For the typical 3- to 20-person brokerage, the honest answer is: you generally do not operate high-risk AI systems. Risk and price assessment engines sit with the insurer, not the intermediary. Biometric analyses are not a topic outside very specialised large brokers. What remains are tools with limited or minimal risk.

A typical broker stack in May 2026 looks like this:

In this list the chains of responsibility are clear. High-risk systems appear in broker operations only where an insurer provides them. In that case the provider obligation sits with the insurer, not with the intermediating brokerage.

This breakdown puts into perspective the compliance panic that runs through many publications. But it doesn't replace your own stocktaking. That's precisely the first of the four obligations.

The digital brokerage starts with the question of how work arises in the first place. Anyone who has grasped that finds the compliance setup easier, because they're already documenting their own AI use anyway.

ToolUse in the brokerageRisk class
ChatGPT, Microsoft CopilotEmail drafts, research, content creationMinimal
Outlook CopilotReply suggestions, meeting preparationMinimal
Website chatbotFirst responses to prospectsLimited (Art. 50)
AI feature in the broker management system (BMS)Case classification, document recognitionMinimal to limited
Claim form assistantFirst-report structuringMinimal
An insurer's risk-pricing engineThe insurer's responsibilityHigh-risk, but not at the broker

The four obligations that really matter for small offices

Without a high-risk classification, the list of obligations shrinks to four operational building blocks. In total, for a small office that's about four to six hours of one-off setup, followed by ongoing upkeep.

Obligation 1: AI inventory

You need a written overview of all AI systems actually in use in the office. Not every tool in the stack, but every one in productive use.

A sufficient table has five columns:

  • Tool and provider
  • Purpose of use in the office
  • Risk class (limited, minimal)
  • Responsible person
  • Date of last review

This overview serves as the basis for training, policy and audit. It's also what you present to a supervisory authority in the event of an inquiry.

Obligation 2: AI policy

A one-page internal policy governs what AI may be used for in the office, what not, and who signs off. Pragmatic content:

  • Which data classes may be entered into AI tools (e.g. general client communication yes, sensitive health data no)
  • Which tasks may run fully automatically, and which only as preparation with human sign-off
  • Which tools are approved, and which must be checked before use
  • Who is the point of contact in cases of uncertainty

The policy doesn't replace GDPR documentation, it supplements it. It's the anchor that training and inventory refer to.

Obligation 3: AI literacy under Article 4

Art. 4 requires every deployer to ensure that the staff who work with AI have an appropriate understanding of the systems. That doesn't mean every employee needs a computer science degree. It means: they can understand what the AI is intended for, where its limits lie, which errors are typical and how to check a result.

In practice, for a small office it's enough to have:

  • A 60- to 90-minute internal training session per year
  • A simple training register with name, date, content, signature
  • A brief refresher whenever there's a major tool change

The Federal Network Agency's guidance paper gives pragmatic orientation on this. Training intensity is guided by the scope and risk of the AI use.

Obligation 4: Transparency under Article 50

From 2 August 2026, three points must be transparently governed:

  • Chatbot labelling. Anyone using an AI-supported chat on their website must make it identifiable. A discreet note, "This conversation is supported by an AI system", at the entry to the chat is sufficient.
  • AI-generated content. Texts, images and voices that are AI-generated and could deceive people must be labelled. In practice this rarely concerns normal marketing copy, but does concern, for example, avatars in training videos.
  • Emotion recognition and biometric categorisation. Here the person concerned must be informed. In classic broker business this is rarely relevant.

These points aren't laborious. Above all they require being conscious of where AI becomes visible in client contact.

Anyone who wants to generate operational leverage, rather than hiring more staff, will have to document AI tools systematically anyway. At heart, the regulation requires what a well-run business should be doing regardless.

What BaFin and AfW say, and what it means in broker practice

Two voices shape the framing in the insurance environment: BaFin as the supervisory authority for the insurance sector, and the AfW federal association as the most important broker representation.

On 6 March 2025, BaFin made its position concrete in a speech: responsibility for the responsible use of AI lies with the companies, not with the tools. Translated into the broker context, that means: anyone using AI must be able to demonstrate that they use it appropriately. That's exactly the purpose of the inventory, policy and training register.

The AfW federal association for financial services, in its guidance paper on the AI Act for insurance brokers, has a clear message: the typical intermediary business does not fall under the high-risk obligations, but must take the deployer obligations seriously. This matches the framing in this article and reduces the effort to what is actually necessary.

On the question of fines, the striking figures circulate: up to 35 million euros or 7 percent of worldwide annual turnover. These top figures target hyperscalers and systematic breaches. For a 5-person brokerage that conscientiously fulfils its obligations, that's not a realistic risk. Anyone working without any documentation, on the other hand, and unable to produce any compliance trail in the event of an inquiry, is on thinner ice. Even if the fine in practice probably stays manageable, the reputational risk with clients and insurers is larger.

The national supervisory structure is expected to be split: the Federal Network Agency as the central AI supervisory authority, BaFin as the sectoral supervisor for insurance. For the insurance broker, in case of doubt, BaFin is the more relevant point of contact.

Structural performance doesn't come from more cases being handled manually, but from work running in a clearly documented and traceable way. At its core, the AI Act demands exactly this diligence.

Your 6-step roadmap to 1 August 2026

Anyone who, as of May 2026, still has no compliance structure for AI use can comfortably manage the preparation by 1 August. This roadmap is tailored to a 5- to 15-person office.

Total: around six hours spread over three months. That's manageable alongside day-to-day business.

After 1 August, the upkeep of obligations continues. The inventory is reviewed quarterly, the training register updated annually, the policy adjusted whenever there are major changes to tool use. Anyone who sets this up cleanly once maintains it with manageable effort.

Revenue per employee stands and falls on the question of how many hours seep away into non-value-adding work. A well-set-up AI compliance costs six hours once and protects against considerably more expensive improvisation if a supervisory authority actually does inquire.

MonthActionOwnerEffort
May 2026Create an AI inventory (tools, purpose of use, owners)Management1.5 hrs
June 2026Adopt an AI policy (one document, one page)Management1 hr
June 2026Prepare training material (internal slide decks, Q&A)Data protection/IT1.5 hrs
July 2026Run internal training (60-90 min, training register)Management1.5 hrs
July 2026Review and label the website chatbotMarketing/IT0.5 hrs
August 2026Schedule the first quarterly review of the AI inventoryManagement0.5 hrs

Frequently asked questions

When does the EU AI Act apply to insurance brokers?

Substantial parts already apply. Art. 4 on AI literacy has been applicable since 2 February 2025. The main obligations for deployers, in particular transparency obligations under Art. 50 and the high-risk rules from Annex III, come into force on 2 August 2026. Anyone using AI in day-to-day business as of today is therefore already obliged to build up and document AI literacy in the team.

Is my brokerage affected if I only use ChatGPT for standard texts?

Yes, though within the scope of the deployer obligations and not as a high-risk use. ChatGPT for preparing emails or claim reports falls under minimal to limited risk. You have to document the use, train your staff in handling it, and ensure that no sensitive data flows into the system uncontrolled. A high-risk classification generally doesn't apply here.

What obligations arise from Article 4 of the AI Act?

Art. 4 requires providers and deployers to ensure their staff have a sufficient level of AI literacy. In practice that means: anyone using AI knows how the system works, where its limits lie and how to check results. For small offices, an annual internal training session with a training register is enough. A formal certification is not required.

Is AI training mandatory for insurance brokers?

Yes, as soon as AI systems are used productively in the office. The training obligation follows from Art. 4 and is not tied to the high-risk classification. It applies to all deployers and is guided by the scope and risk of the AI use. A refresher once a year is a practical benchmark; in individual cases less is enough, in individual cases more is needed.

What happens in the event of breaches of the AI Act?

The theoretical fine range goes up to 35 million euros or 7 percent of worldwide annual turnover. These top figures target systematic breaches by large providers. For a typical brokerage with rock-solid documentation, that's not a realistic scenario. The greater practical risk comes from supervisory inquiries without a presentable compliance trail, and the reputational damage this causes with clients and insurers.

What is the difference between provider and deployer under the AI Act?

A provider is anyone who develops an AI system or distributes it under their own name. A deployer is anyone who uses such a system under their own responsibility. Insurance brokers are generally deployers, because they use AI tools from other providers. It follows that the considerably more extensive provider obligations (conformity assessment, technical documentation, risk management system) do not apply to brokerages. What remains are the deployer obligations on documentation, training and transparency.

Conclusion: diligence beats panic

The EU AI Act doesn't demand a compliance revolution from insurance brokers. It demands an orderly stocktaking, a concise policy, an annual training session and three visible transparency notices. In total that's six hours of setup effort by 1 August 2026, followed by ongoing upkeep.

What the AI Act changes beyond that: it makes the responsible handling of AI a documented routine. Anyone who takes it seriously gains more than just legal certainty. They gain a clear view of where AI actually creates value in their own business, and where it's just running along as fashionable trimming.

That's exactly where the structural question begins that we observe daily at Modus. Which work does the system take over, which stays with the human, and how do we measure the leverage?

Scale revenue. Not headcount.

Don't miss any developments in AI for insurance brokers. Sign up for updates now.

Ready to decouple growth from complexity and headcount?