industries · Insurance

Solvency II and the AI Act without handing the case file to a third party

Insurance AI that survives an audit: an auditable EU provider, on-premise, a traceable stack. The flagship case is claims extraction and analysis, with decision traceability at the center of compliance.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

DORA

Regulation (EU) 2022/2554 · applicable since 17 Jan 2025, insurers included

RequiresDORA covers insurance and reinsurance undertakings: ICT third-party risk management, audit capability and exit strategies for critical providers.

HelmcodeAn auditable EU provider with a dedicated or on-premise option and a standard OpenAI-compatible API: the exit strategy is changing a URL.

Solvency II

Directive 2009/138/EC · operational risk governance

RequiresA sound system of governance over operational risk: documented processes, control and the ability to explain the decisions supporting AI systems.

HelmcodeA single auditable stack with documented data flows and human oversight, so the AI process fits inside your governance instead of fighting it.

AI Act

Regulation (EU) 2024/1689, Annex III 5(c) · high-risk for life & health insurance pricing

RequiresRisk assessment and pricing for natural persons in life and health insurance is high-risk (Annex III 5(c)), with traceability and oversight obligations whose start date moved: agreed in May 2026 to December 2027, pending formal adoption. Other insurance uses are classified case by case.

HelmcodeOpen models with published model cards and licenses document exactly what runs, where and with which weights; the classification of each use is for your legal team.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

what the supervisor asks for

What EIOPA expects of an AI system.

EIOPA, the European insurance supervisor, issued an Opinion in August 2025 on how existing insurance law applies to AI. It creates no new rules: it reads Solvency II, the IDD, DORA and GDPR in light of the AI Act, and tells national supervisors what to look for. Four of its expectations decide an architecture, so they are worth reading before you pick one.

01

The provider’s IP is your problem

The Opinion is explicit that a third party’s intellectual property rights get in the way of the governance you owe, and that you have to make up for it: contract clauses, service level agreements, external audits, due diligence. Every one of those is compensating control for something you cannot inspect. Weights you run yourself remove the cause rather than the symptom.

02

Explainable twice over

A result has to be explainable to the supervisor in technical terms and to the customer in plain language, with documentation that keeps the trail. Two audiences, one system, and neither explanation can be written about a model whose behaviour you can only observe from the outside.

03

Data governance includes data you did not collect

Data has to be complete, accurate, adequate and documented across the whole lifecycle of the system, third-party data included. That last clause is the hard one: it reaches into what a vendor trained on, which is exactly the part a closed API will not tell you.

04

Oversight is a person, not a policy

Human oversight has to hold across the lifecycle, with training adapted to each role. That is an organisational requirement rather than a technical one, and it is the one nobody can sell you: what infrastructure can do is make sure the person overseeing has something to look at.

EIOPA · European Insurance and Occupational Pensions Authority "Opinion on Artificial Intelligence governance and risk management", EIOPA-BoS-25-360, 6 August 2025, issued to national competent authorities under Article 29(1)(a) of Regulation (EU) No 1094/2010. Risk-based and proportionate: it interprets existing law rather than adding to it. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

GLM-5.2MIT · 1M ctx
Reasoning for claims analysis and complex case files, the most capable open model today.
DeepSeek V4 FlashMIT · 1M ctx in Helmcode
Extraction and summaries of claims and policies at volume, on a flat rate.
Qwen 3.6Apache 2.0 · 256K ctx in Helmcode
Customer and policyholder communications with the best open writing in Spanish.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

Does DORA apply to insurers?

Yes. DORA (Regulation (EU) 2022/2554, applicable since 17 January 2025) covers insurance and reinsurance undertakings, treating ICT providers as part of operational risk: third-party risk management, audit capability and exit strategies. An open-model stack on EU infrastructure with an on-premise option and a standard API simplifies all three.

Is AI pricing in insurance high-risk under the AI Act?

Risk assessment and pricing for natural persons in life and health insurance is listed as high-risk (AI Act, Annex III 5(c)). When those obligations start is the part in motion: a May 2026 agreement moves the Annex III tranche to December 2027 and is pending formal adoption as of July 2026. Other insurance lines and uses are classified case by case, which your legal team decides. Either way, an open, auditable stack makes documenting the system straightforward.

How does this help with Solvency II?

Solvency II (Directive 2009/138/EC) requires a sound system of governance over operational risk. A single auditable stack with documented data flows and human oversight lets the AI process fit inside that governance, with traceability of what ran and where.

Does claims data leave our network?

Not unless you allow it. The default is EU-only inference with zero logs; on-premise runs the same models and API inside your datacenter, the usual choice for claims files and specially protected data.

Can a European insurer use a Chinese model like GLM or DeepSeek?

Yes, if the weights run on controlled infrastructure. The regulatory risk is in sending data to a foreign API, not in the origin of the model: open weights run in the EU or on-premise keep data inside your perimeter and stay auditable end to end.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.