AI Regulation Tracker · EIOPA · Guidance

What does EIOPA Opinion on AI governance and risk management (EIOPA-BoS-25-360) say about AI in banking?

Published Aug 6, 2025 · Last reviewed Oct 5, 2026

EIOPA published its Opinion on AI governance and risk management (EIOPA-BoS-25-360) on 6 August 2025. It is addressed to national supervisors of insurers and insurance intermediaries and explains how existing insurance legislation, namely the Solvency II Directive, the Insurance Distribution Directive and DORA, should be read for AI systems that are neither prohibited nor high-risk under the AI Act. It sets no new requirements; it sets out supervisory expectations on risk-based proportionality, risk management, fairness and ethics, data governance, documentation and record keeping, transparency and explainability, human oversight, and accuracy, robustness and cybersecurity. It does not apply to banks directly, but banks that distribute insurance, own insurers or want a worked EU example of principle-based AI governance can use it as a reference. EIOPA will review supervisory practices two years after publication, around August 2027.

OFFICIAL TEXT: eiopa.europa.eu ↗ · IN FORCE · EIOPA

DocumentEIOPA Opinion on AI governance and risk management (EIOPA-BoS-25-360) — EIOPA-BoS-25-360 Opinion on AI governance and risk management
Issued byEuropean Insurance and Occupational Pensions Authority
TypeGuidance
StatusIn force
PublishedAug 6, 2025
Applies toNational competent authorities supervising insurance undertakings and insurance intermediaries under Solvency II and the Insurance Distribution Directive; not addressed to banks as such, but relevant to banks that sell insurance as intermediaries and to bancassurance groups. It excludes AI systems that are high-risk or prohibited under the AI Act
Official sourceeiopa.europa.eu ↗
Use casesAI governance (general) · Fair lending & discrimination · Model risk management · Customer-facing chatbots · Third-party & vendor AI

What are the key points of EIOPA Opinion on AI governance and risk management (EIOPA-BoS-25-360)?

  • Status and addressees: Opinion adopted under Article 29(1)(a) of Regulation (EU) No 1094/2010, addressed to competent authorities, covering insurance undertakings and intermediaries (paragraphs 1.1-1.3); it sets no new requirements and does not change the scope of the AI Act or of insurance law (paragraph 2.8).
  • Scope: AI systems that are not prohibited or high-risk under the AI Act; the AI Act's high-risk systems for life and health insurance risk assessment and pricing are excluded to avoid overlap (paragraph 2.6). It uses the AI Act definition and the Commission's AI system definition guidelines (paragraph 2.10).
  • Legal basis: Articles 17, 20 and 25 of the Insurance Distribution Directive, Articles 41, 46 and 82 of Solvency II, Articles 4, 5, 6, 11 and 12 of DORA and related delegated regulations (paragraph 1.2).
  • Proportionality (section 3, paragraphs 3.1-3.6): undertakings first assess the impact of each AI system, then calibrate governance measures to it; AI governance sits within the existing system of governance under Article 41 of Solvency II and the IDD.
  • Risk management (paragraphs 3.7-3.11): the responsible use of AI needs a combination of measures; undertakings define and document their approach and remain responsible for AI systems, whether developed in-house or with third-party providers, and should obtain adequate information and assurances from them (paragraph 3.11).
  • Fairness and ethics (paragraphs 3.12-3.17): act honestly, fairly and professionally under IDD Article 17, make reasonable efforts to remove bias including proxy discrimination, monitor outcomes and give customers redress mechanisms.
  • Data governance, documentation and explainability (paragraphs 3.18-3.28): complete and accurate training and test data, records of AI system lifecycle decisions, and explanations tailored to the use and to the recipient.
  • Human oversight (paragraphs 3.29-3.33) and accuracy, robustness and cybersecurity (paragraphs 3.34-3.38): trained staff and guardrails; defined accuracy levels with metrics including fairness metrics; resilience against data poisoning and adversarial attacks; and ICT continuity fall-back plans, linked to DORA Articles 6-12.
  • Monitoring (section 4): EIOPA will look at supervisory practices two years after publication and may issue further analysis on specific AI systems.

What did EIOPA Opinion on AI governance and risk management (EIOPA-BoS-25-360) change for banks?

The Opinion is the first EU supervisory-authority text to spell out an AI governance framework for a financial sub-sector under existing sectoral law rather than the AI Act. For banks the direct effect is limited, since insurance law is its legal basis, but it shows how EU supervisors expect AI governance to be built from existing risk management, conduct and ICT rules, and it applies to the insurance side of bancassurance groups and to banks that act as insurance distributors.

What does the EIOPA Opinion on AI governance and risk management require, and does it apply to banks?

EIOPA's Opinion on AI governance and risk management (EIOPA-BoS-25-360, 6 August 2025) tells national supervisors to expect insurers and insurance intermediaries to apply proportionate AI governance built on Solvency II, the Insurance Distribution Directive and DORA: assess each AI system's impact, document the approach, remain responsible for third-party AI, test for bias, keep records, explain outcomes, ensure meaningful human oversight and secure systems against attack. It is not binding and creates no new requirements. It does not apply to banks as such, only to the insurance business of groups and to banks selling insurance as intermediaries, and it excludes AI systems classed as high-risk or prohibited under the AI Act.

RuleAuthorityWhat it requiresApplies
Paragraphs 3.1-3.6 — Risk-based approach and proportionalityEIOPAAssess the impact of each AI system and calibrate governance and risk management measures proportionately to it.Published 6 Aug 2025
Paragraphs 3.7-3.11 — Risk management system and third partiesEIOPADefine and document the approach to AI across the organisation, allocate roles and remain responsible for AI systems whether built in-house or with third parties, obtaining adequate assurances from providers.Published 6 Aug 2025
Paragraphs 3.12-3.17 — Fairness and ethicsEIOPAAct honestly, fairly and in customers' best interests, make reasonable efforts to remove bias, monitor outcomes and provide redress.Published 6 Aug 2025
Paragraphs 3.18-3.22 — Data governanceEIOPAUse complete, accurate and representative data across the AI lifecycle, applying the same quality standards to external data.Published 6 Aug 2025
Paragraphs 3.23-3.24 — Documentation and record keepingEIOPAKeep records and documentation on the AI system's design, data, testing and decisions proportionate to its risk.Published 6 Aug 2025
Paragraphs 3.25-3.28 — Transparency and explainabilityEIOPAProvide explanations of AI outcomes adapted to the use case and to the recipient, such as customers or supervisors.Published 6 Aug 2025
Paragraphs 3.29-3.33 — Human oversightEIOPAPut effective oversight arrangements, trained staff and guardrails in place so that human oversight supports the identification and mitigation of bias and keeps the AI system functioning as intended.Published 6 Aug 2025
Paragraphs 3.34-3.38 — Accuracy, robustness and cybersecurityEIOPADefine accuracy, robustness and cybersecurity levels, measure performance with metrics including fairness metrics, test API connections, protect against data poisoning and adversarial attacks, and keep fall-back plans for ICT continuity under DORA.Published 6 Aug 2025

The Opinion rests on insurance sectoral law, so its direct addressees are insurers, intermediaries and their supervisors. It uses DORA as one of its legal bases, which means its ICT risk and cybersecurity expectations match what banks must meet under the same Regulation, and it cross-refers to the Commission's AI system definition guidelines.

Its relevance to banking supervision is as a template. EIOPA, like the EBA and ECB, has chosen to derive AI expectations from existing governance, conduct and operational resilience rules rather than create a new AI rulebook; the EBA's AI Act factsheet reaches a similar conclusion for banking law.

For groups with both banking and insurance arms, the same AI system can be subject to the EIOPA Opinion for the insurance business and to ECB and EBA expectations for the bank, while the AI Act applies to both. EIOPA plans to review supervisory practices two years after publication.

WHAT THIS MEANS IN PRACTICE

  • Bancassurance groups should check which AI systems in the insurance entities fall within the Opinion and which are high-risk under the AI Act and so excluded from it.
  • Banks that sell insurance should confirm with their national supervisor how it will apply the Opinion to distribution activities, especially customer-facing chatbots and recommendation tools.
  • Reuse the Opinion's structure (impact assessment, proportionate governance, data, records, explainability, oversight, security) as a cross-check on the bank's own AI governance framework.
  • Align fairness and proxy-discrimination testing across banking and insurance entities in the group so that the evidence can be reused.
  • Treat the Opinion as non-binding but likely to inform supervisory questions, since EIOPA plans a convergence review about two years after publication.

Does the EIOPA Opinion on AI apply to banks?

Not directly. It is addressed to national competent authorities supervising insurance undertakings and intermediaries under Solvency II and the Insurance Distribution Directive. Banks are affected only where they act as insurance distributors or belong to groups with insurance undertakings; banks' own AI is governed by banking law, the AI Act and DORA.

Is the EIOPA Opinion on AI governance binding?

No. An EIOPA opinion is not legally binding. It sets out how EIOPA expects national supervisors to interpret existing insurance legislation for AI, and it states that it does not set new requirements.

When was the EIOPA Opinion on AI governance and risk management published?

EIOPA published it on 6 August 2025 as EIOPA-BoS-25-360, after a public consultation earlier in 2025.

How does the EIOPA Opinion relate to the EU AI Act?

It covers AI systems that are not prohibited or high-risk under the AI Act, such as claims handling, fraud detection or customer chatbots, and excludes high-risk systems like life and health insurance pricing to avoid overlap. It follows the Act's definition and is aligned with its principles on data governance, record keeping, transparency and human oversight.

Why does a bank need to know about an insurance supervisor's AI opinion?

It is a worked example of how an EU supervisor derives AI governance expectations from existing sectoral law and DORA, and it applies to the insurance side of bancassurance groups. Banks building their own AI governance can compare it with the ECB, EBA and AI Act material.

DateDocumentStatus
Sep 30, 2026SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act)Final
Sep 30, 2026Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew BaileyFinal
Sep 28, 2026AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act)Final
Sep 10, 2026Atkins remarks at Investor Advisory Committee (Sep 2026) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information EcosystemFinal
Sep 2, 2026FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber ResilienceIn force
Aug 31, 2026FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence modelsFinal

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning