Beyond hiring: AI in credit and insurance scoring is high-risk too
Edition 06. A reading time of about 5 minutes.
The hook
These editions have stayed close to hiring, because that is where many readers first met the AI Act. But the high-risk list is wider than hiring, and two of its neighbors sit right next door: scoring people for credit, and pricing them for insurance. If your company touches either, the playbook you have been building applies almost unchanged, with one edge that is sharper than it is for hiring. This edition is for the teams who just realized they are in scope twice.
What this means
Annex III puts these uses in the high-risk tier by name, in point 5. Point 5(b) covers AI "intended to be used to evaluate the creditworthiness of natural persons or establish their credit score," with an explicit exception for systems used to detect financial fraud. Point 5(c) covers AI "intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance" (AI Act, Annex III). Hiring is point 4 of the same list. Different point, same tier, same weight.
So the deployer duties are identical to the ones earlier editions covered for hiring: use the system as instructed, assign real human oversight, monitor and suspend on risk, keep the logs (AI Act, Article 26). If you have built that program for hiring, you have built most of it for credit and insurance.
The sharper edge is the one that hiring usually escapes. The fundamental rights impact assessment, the FRIA, is required for these two categories. Article 27 names creditworthiness scoring and life and health insurance risk assessment as exactly the private-sector deployers who must perform it, before first use, and notify the market surveillance authority of the results (AI Act, Article 27). A private employer running a hiring tool generally does not owe a FRIA; a lender or insurer scoring people does. That is the one place the credit and insurance path is heavier than the hiring path.
What to do with this
Four steps, the first three identical to the hiring playbook.
- Run the same inventory, vendor, oversight, and evidence steps. Where AI scores creditworthiness or prices life and health risk, treat it as high-risk and apply everything from the earlier editions. The duties carry over one to one.
- Add the FRIA, and budget for it. Unlike hiring, these categories owe the Article 27 assessment before first use, with notification to the authority. It is real work; plan it rather than discover it.
- Mind the fraud carve-out. Credit-scoring AI used to detect financial fraud is carved out of point 5(b). Scoring for creditworthiness is not. Classify by the system's actual purpose, not its marketing.
- If you do both hiring and credit or insurance, run one program, not two. The deployer duties are shared; only the FRIA differs. One inventory, one oversight habit, one evidence trail, with a FRIA bolted on where the law asks for it.
The lesson underneath: the AI Act's high-risk list is a short, specific set of decisions about people, hiring, credit, insurance, benefits, and a handful more. If your company makes more than one of them with AI, the smart move is a single compliance spine, not a separate scramble per department.
This is educational material and a starting point, not legal advice. The EU AI Act is still being amended, and the high-risk timeline rests on an agreement that is not yet final law. For how the credit, insurance, and FRIA obligations apply to your specific systems, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.
AI that drafts at scale can also send the wrong thing at scale. See the Signato chamber block a forbidden send before it happens: run the free local trial, no card, nothing leaves your machine.
Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.
Know someone who hires in the EU? Forward this to them.