Published on: 
September 10, 2026

EU AI Act: What the New Timeline Means

5 min read
Sixfold breaks down the EU AI Act and how the company looks at AI underwriting

The EU AI Act sets rules for companies that develop and use AI in the European Union. It entered into force in 2024, with different requirements scheduled to apply over time.

In June 2026, the European Parliament and Council adopted the Digital Omnibus on AI, a package of targeted amendments to the EU AI Act. It moves the compliance date for stand-alone high-risk AI systems from August 2, 2026, to December 2, 2027. The update is relevant to Sixfold because the Act identifies certain uses of AI in life and health insurance as high-risk.

The updated timeline gives Sixfold more time to incorporate the standards and guidance that the European standards bodies and the Commission are still developing. Sixfold’s AI Governance Program and the work already underway continue. Give our customers concrete answers on AI governance.

What Changed

The EU AI Act uses a risk-based approach. Systems that could have a greater effect on people’s safety or fundamental rights are subject to stricter requirements.

Annex III specifically lists AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance. It does not classify every use of AI in insurance or underwriting as high-risk.

The Act also distinguishes between providers, which develop AI systems, and deployers, which use them. Sixfold is a provider under the Act. Its focus includes documentation, testing, governance, and giving customers clear information about how its solution is developed and managed.

How Sixfold Stays Consistent

Sixfold designed its AI Governance Program to remain useful as requirements develop. The program uses several reference points:

  1. The NIST AI Risk Management Framework, which provides guidance for identifying and managing AI risk.
  2. The EU AI Act’s high-risk provider requirements, which set detailed expectations for documentation, testing, and accountability.
  3. International AI management frameworks that provide additional guidance for governing AI responsibly.

Together, these reference points give Sixfold a consistent structure for managing AI risk. Sixfold treats the EU AI Act’s high-risk provider requirements as a demanding benchmark.

What Sixfold is Doing Today

Sixfold’s AI Governance Program is an ongoing internal process for identifying, assessing, and addressing the risks involved in developing and deploying AI.

The program covers five areas: general governance, risk and compliance, data and model governance, ethics and Responsible AI, and security and privacy. Each area has named owners, defined deliverables, and a regular review schedule.

Risk and compliance reviews take place quarterly. The ethics function reviews new functionality and human oversight design each quarter. The full group of program owners meets every two weeks.

Sixfold is also preparing technical documentation aligned with Annex IV of the EU AI Act. This work brings together information about the solution, its intended use, governance, testing, validation, and deployment procedures. It gives customers and regulators a clearer view of how the solution is developed and managed.

Bias and fairness testing is another part of the program, with the methodology adapted for each line of business. The approved amendments permit special category personal data to be processed when strictly necessary to detect and correct bias, with appropriate safeguards, in both high-risk and non-high-risk AI systems. This provides greater clarity for providers conducting bias testing, and Sixfold will continue incorporating additional guidance as it is published.

Structure for New Requirements

Europe is not the only jurisdiction updating its AI rules. Colorado repealed and replaced its original 2024 AI Act with SB26-189, which was signed in May 2026 and takes effect January 1, 2027. The new law drops the algorithmic discrimination duty of care in favor of a transparency and disclosure based framework. It encompasses Automated Decision-Making Technology, or ADMT, rather than AI only, and focuses on areas including developer documentation, consumer notices, recordkeeping, and consumer rights.

The details differ across jurisdictions, but Sixfold can assess new and changing requirements through the structure it already has in place: defined roles, documentation, testing, and regular reviews.That is the practical benefit of a program grounded in established, stable frameworks. Sixfold can incorporate new requirements without rebuilding its governance approach every time a law changes.

Customers & Responsible AI

Sixfold works with insurance customers to give them a clear understanding of how its solution is developed, tested, and governed. This includes documentation on intended use, testing methods, safeguards, human oversight, and the processes Sixfold uses to manage AI risk.

Customers can bring questions about Sixfold’s governance practices directly to the team. Sixfold can provide the supporting information needed for conversations with procurement, risk, compliance, and other internal stakeholders. That gives customers concrete answers about their AI provider instead of broad statements about Responsible AI.

Questions about Sixfold’s AI governance approach? Reach out to your customer success representative or get in touch with the Sixfold team.

Learn more about Sixfold’s AI Governance Program and its broader Responsible AI approach.

━━━

Frequently Asked Questions

When do the EU AI Act’s high-risk requirements apply?

Under the amendments approved in June 2026, requirements for stand-alone high-risk AI systems will apply from December 2, 2027. Requirements for high-risk AI systems embedded in regulated products will apply from August 2, 2028.

Is all AI used in insurance considered high-risk under the EU AI Act?

No. Annex III specifically lists AI intended for risk assessment and pricing in relation to natural persons in life and health insurance. It does not classify every use of AI in insurance or underwriting as high-risk.

Does the updated EU AI Act timeline change Sixfold’s approach?

Sixfold’s AI governance program continues regardless of the EU AI Act timeline changes. The updated timeline gives the company more time to incorporate forthcoming standards and guidance into the program and documentation already underway.

How is Sixfold preparing for the EU AI Act?

Sixfold is preparing technical documentation aligned with Annex IV, conducting bias and fairness testing, and running regular governance reviews. Its program uses the NIST AI Risk Management Framework, the EU AI Act’s high-risk provider requirements, and international AI management frameworks as reference points.

What does the EU AI Act update mean for Sixfold customers?

Customers can continue to expect documented information about how Sixfold’s solution is developed, governed, and tested. The updated timeline gives Sixfold additional time to incorporate detailed guidance and strengthen the materials it provides as an AI provider.

Share this post
Natalie Senft Senior Natalie Senft Senior Demand Generation Manager at Sixfold
Natalie Senft
Senior Demand Generation Manager
Use Case
Current Process
With Narratives
Quoting
Currently, risk factors are pulled together manually to decide if a case should be quoted.
Automatically summarizes key risk drivers upfront, providing a clear snapshot to prioritize cases faster.
Peer Reviews
Peer reviews are slowed by unstructured summaries; reviewers often have to go back to source documents.
Risk factors and case notes are presented clearly and consistently.
Referrals
Referral memos vary between underwriters; approvers often have to sort through inconsistent write-ups to understand the case.
Consistent case summaries make it easier for approvers to see the full risk story and sign off faster.
Decision Documentation
Underwriting rationale is often recorded unevenly; teams spend time cleaning up notes when preparing for audits.
A standardized record of underwriting rationale is created automatically, ready for audit without extra effort.
Business Impact
Faster decisions on which risks to quote.
More consistent risk appetite application and faster reviews.
Faster referral decisions.
Lower compliance risk and faster audit prep.
Quoting
use case
Current Process
Currently, risk factors are pulled together manually to decide if a case should be quoted.
With Narratives
Automatically summarizes key risk drivers upfront, providing a clear snapshot to prioritize cases faster.
Business Impact
Faster decisions on which risks to quote.
Peer Review
use case
Current Process
Peer reviews are slowed by unstructured summaries; reviewers often have to go back to source documents.
With Narratives
Risk factors and case notes are presented clearly and consistently.
Business Impact
More consistent risk appetite application and faster reviews.
Referrals
use case
Current Process
Referral memos vary between underwriters; approvers often have to sort through inconsistent write-ups to understand the case.
With Narratives
Consistent case summaries make it easier for approvers to see the full risk story and sign off faster.
Business Impact
Faster referral decisions.
Decisions Documentation & Audits
use case
Current Process
Underwriting rationale is often recorded unevenly; teams spend time cleaning up notes when preparing for audits.
With Narratives
A standardized record of underwriting rationale is created automatically, ready for audit without extra effort.
Business Impact
Lower compliance risk and faster audit prep.