← Blog

The EU AI Act Isn't Coming for Your AI Draft — It's Coming for Autopilot

Headlines and deadlines make it sound like every use of AI is now a legal risk. For most brokers and advisors, one simple habit — a human signs off before anything goes out — already satisfies most of what the law and the GDPR actually ask for.

This article provides general information based on the current state of EU and German regulation. It is not legal advice for your specific situation.

If you've followed insurance or financial-advisory trade press this year, you could be forgiven for thinking that opening ChatGPT is now a regulatory event. "EU AI Act." "GDPR fines." Deadlines stacked on deadlines. For a Makler or an independent Finanzberater quietly using AI to draft a client email, summarise a call, or organise a file, that unease is understandable — nobody wants to be the test case for a new law.

It's also, for the vast majority of everyday advisory work, misplaced. The Act was built to catch a specific kind of AI use. Ordinary advisory work, done with a person checking the result before it goes anywhere, mostly isn't it.

What the Act actually worries about

The EU AI Act sorts AI systems by risk, and only one tier — "high-risk" — brings serious obligations: conformity assessments, technical documentation, built-in human-oversight requirements, the works. For financial and insurance services specifically, high-risk means AI that scores or assesses someone's creditworthiness, or that does the risk assessment and pricing for life and health insurance — specifically life and health, not motor or property — or that profiles people. Those are the high-risk categories the Act names in its Annex III. The Act is worried about a machine deciding, on its own, something that materially shapes a person's financial life.

Drafting a policy summary, tidying up client correspondence, preparing meeting notes — all reviewed by a person before any of it reaches the client — sits nowhere near that category. It's minimal or limited risk: the same shelf as a spell-checker or a spam filter.

And even for firms working closer to that line, there's more room than the headlines suggest. The EU's "Digital Omnibus" package — adopted 29 June 2026, taking effect 2 August 2026 — pushed those specific high-risk obligations back to 2 December 2027. Nobody using AI to organise their own desk needs to lose sleep over Annex III this year.

The one habit doing most of the work

If there's a single design choice that quietly does most of your compliance work for you, it's this: a human approves before anything goes out.

That habit keeps you out of "high-risk" territory to begin with — the Act's high-risk categories describe AI that decides or scores on its own, and human sign-off means it doesn't. It also happens to satisfy one of the GDPR's oldest and clearest rules (Article 22): the ban on letting a decision be made solely by an automated system when that decision has a legal or similarly significant effect on someone. If a person reviews and approves what the AI produced, the decision was never solely automated in the first place.

It's good practice regardless of the law, too. You catch the AI's mistakes before a client does, and you build a natural audit trail — who approved what, and when — that regulators, and increasingly clients, are likely to ask about anyway. One habit, three problems handled. That's rare in compliance.

What actually does apply to you

None of this means there's nothing to do. Three things are real and worth a moment's attention.

AI literacy (Article 4 of the Act) has been a legal duty since 2 February 2025 for any firm using AI — in practice, making sure the people using the system, and the people it affects, understand roughly what it can and can't do. That's a paragraph in your compliance file, not a project.

From 2 August 2026, a lighter transparency rule applies (Article 50): if a client is interacting directly with an AI system — a chatbot, say, not a person using AI to help write something — they need to be told. Marking AI-generated content as such is mostly your AI vendor's job, not yours; a private, human-reviewed email to a client generally falls outside this rule entirely.

The bigger, already-in-force constraint is simply the GDPR, and it applies the moment client data touches any AI system: you need a lawful basis for the processing, a proper data-processing agreement with your AI vendor — the same AVV your compliance checklist already asks for with every other supplier — and, for German clients especially, clarity on where that data actually sits.

Where this leaves you

None of this requires becoming an AI-law expert. It requires setting AI up properly once — the right agreement with the right vendor, a person on the approval step — and then getting on with your work.

We built a free two-minute self-check on exactly this, for insurance and finance advisors — no sign-up, nothing stored. See where you stand:

helloaurora.ai/ki-check

— The Aurora Team

← Blog

Der EU AI Act hat nicht Ihre KI im Visier – sondern den Autopiloten

Schlagzeilen und Fristen klingen aktuell oft so, als sei jede KI-Nutzung ein Rechtsrisiko. Für die meisten Makler und Finanzberater gilt jedoch: Eine Gewohnheit, die viele ohnehin schon pflegen – ein Mensch prüft und gibt frei, bevor ein Dokument das Haus verlässt – erfüllt bereits den Großteil dessen, was das Gesetz und die DSGVO verlangen.

Wer in diesem Jahr die Fachpresse verfolgt hat, könnte meinen, das Öffnen von ChatGPT sei mittlerweile ein hochgradig regulatorischer Vorgang. Für Berater, die KI nutzen, um E-Mails zu entwerfen oder Unterlagen zu ordnen, ist diese Unruhe verständlich. Für den überwiegenden Teil des Beratungsalltags ist sie jedoch unbegründet. Die EU-KI-Verordnung wurde für eine ganz bestimmte Art von KI-Einsatz gemacht, zu der die typische Sachbearbeitung unter menschlicher Aufsicht in der Regel nicht gehört.

Wovor der EU AI Act tatsächlich warnt

Nur die Stufe „hochriskant" bringt ernsthafte Pflichten mit sich. Im Finanzbereich betrifft dies vor allem KI, die autonom über Kreditwürdigkeit entscheidet oder Risikobewertungen in der Lebens- und Krankenversicherung vornimmt. Das Zusammenfassen von Versicherungsscheinen oder die Vorbereitung von Korrespondenz gilt hingegen als minimales Risiko und fällt damit in dieselbe Kategorie wie Rechtschreibprüfungen oder Spamfilter. Zudem wurden viele Hochrisiko-Pflichten durch das „Digital Omnibus"-Paket auf den 2. Dezember 2027 verschoben.

Die eine entscheidende Gewohnheit

Wenn ein Mensch die Ergebnisse freigibt, verhindert dies, dass das System als „hochriskant" eingestuft wird. Zudem erfüllen Sie damit Artikel 22 der DSGVO, der rein automatisierte Entscheidungen mit rechtlicher Wirkung untersagt. Es ist schlicht gute Praxis: Sie fangen Fehler ab und schaffen eine nachvollziehbare Spur für Aufsichtsbehörden und Kunden. Dass eine einzige Gewohnheit gleich drei Probleme löst, ist im Bereich der Compliance eine seltene Ausnahme.

Was tatsächlich auf Sie zukommt

  1. KI-Kompetenz (Art. 4): Seit Februar 2025 müssen Nutzer und Betroffene grob verstehen, was das System leistet. Ein Absatz in Ihrer Dokumentation genügt meist.
  2. Transparenz (Art. 50): Ab dem 2. August 2026 müssen Kunden informiert werden, wenn sie direkt mit einer KI (z. B. einem Chatbot) interagieren. Die Kennzeichnung KI-generierter Inhalte liegt überwiegend in der Verantwortung Ihres KI-Anbieters, nicht in Ihrer eigenen.
  3. DSGVO: Wie bei jedem Dienstleister benötigen Sie eine Rechtsgrundlage und einen Auftragsverarbeitungsvertrag (AVV) mit Ihrem KI-Anbieter.

Was das für Sie bedeutet

Sie müssen kein Rechtsexperte werden. Es geht darum, die KI einmal richtig aufzusetzen – mit dem passenden Anbieter und einer menschlichen Prüfinstanz.

Um zu sehen, wo Sie aktuell stehen, haben wir einen kostenlosen 2-Minuten-Selbstcheck für Versicherungs- und Finanzberater entwickelt (ohne Anmeldung):

helloaurora.ai/ki-check

— Das Aurora-Team

Hinweis: Dieser Beitrag bietet allgemeine Informationen auf Basis der aktuellen Rechtslage in der EU und in Deutschland und ersetzt keine Rechtsberatung im Einzelfall.