The EU AI Act Isn't Coming for Your AI Draft — It's Coming for Autopilot
Headlines and deadlines make it sound like every use of AI is now a legal risk. For most brokers and advisors, one simple habit — a human signs off before anything goes out — already satisfies most of what the law and the GDPR actually ask for.
This article provides general information based on the current state of EU and German regulation. It is not legal advice for your specific situation.
If you've followed insurance or financial-advisory trade press this year, you could be forgiven for thinking that opening ChatGPT is now a regulatory event. "EU AI Act." "GDPR fines." Deadlines stacked on deadlines. For a Makler or an independent Finanzberater quietly using AI to draft a client email, summarise a call, or organise a file, that unease is understandable — nobody wants to be the test case for a new law.
It's also, for the vast majority of everyday advisory work, misplaced. The Act was built to catch a specific kind of AI use. Ordinary advisory work, done with a person checking the result before it goes anywhere, mostly isn't it.
What the Act actually worries about
The EU AI Act sorts AI systems by risk, and only one tier — "high-risk" — brings serious obligations: conformity assessments, technical documentation, built-in human-oversight requirements, the works. For financial and insurance services specifically, high-risk means AI that scores or assesses someone's creditworthiness, or that does the risk assessment and pricing for life and health insurance — specifically life and health, not motor or property — or that profiles people. Those are the high-risk categories the Act names in its Annex III. The Act is worried about a machine deciding, on its own, something that materially shapes a person's financial life.
Drafting a policy summary, tidying up client correspondence, preparing meeting notes — all reviewed by a person before any of it reaches the client — sits nowhere near that category. It's minimal or limited risk: the same shelf as a spell-checker or a spam filter.
And even for firms working closer to that line, there's more room than the headlines suggest. The EU's "Digital Omnibus" package — adopted 29 June 2026, taking effect 2 August 2026 — pushed those specific high-risk obligations back to 2 December 2027. Nobody using AI to organise their own desk needs to lose sleep over Annex III this year.
The one habit doing most of the work
If there's a single design choice that quietly does most of your compliance work for you, it's this: a human approves before anything goes out.
That habit keeps you out of "high-risk" territory to begin with — the Act's high-risk categories describe AI that decides or scores on its own, and human sign-off means it doesn't. It also happens to satisfy one of the GDPR's oldest and clearest rules (Article 22): the ban on letting a decision be made solely by an automated system when that decision has a legal or similarly significant effect on someone. If a person reviews and approves what the AI produced, the decision was never solely automated in the first place.
It's good practice regardless of the law, too. You catch the AI's mistakes before a client does, and you build a natural audit trail — who approved what, and when — that regulators, and increasingly clients, are likely to ask about anyway. One habit, three problems handled. That's rare in compliance.
What actually does apply to you
None of this means there's nothing to do. Three things are real and worth a moment's attention.
AI literacy (Article 4 of the Act) has been a legal duty since 2 February 2025 for any firm using AI — in practice, making sure the people using the system, and the people it affects, understand roughly what it can and can't do. That's a paragraph in your compliance file, not a project.
From 2 August 2026, a lighter transparency rule applies (Article 50): if a client is interacting directly with an AI system — a chatbot, say, not a person using AI to help write something — they need to be told. Marking AI-generated content as such is mostly your AI vendor's job, not yours; a private, human-reviewed email to a client generally falls outside this rule entirely.
The bigger, already-in-force constraint is simply the GDPR, and it applies the moment client data touches any AI system: you need a lawful basis for the processing, a proper data-processing agreement with your AI vendor — the same AVV your compliance checklist already asks for with every other supplier — and, for German clients especially, clarity on where that data actually sits.
Where this leaves you
None of this requires becoming an AI-law expert. It requires setting AI up properly once — the right agreement with the right vendor, a person on the approval step — and then getting on with your work.
We built a free two-minute self-check on exactly this, for insurance and finance advisors — no sign-up, nothing stored. See where you stand:
helloaurora.ai/ki-check— The Aurora Team