On August 2, the EU AI Act took effect. For the first time, new rules for both providers and deployers of AI systems are operating under a single risk-based framework. It imposes stricter requirements on high-risk systems and for customer-facing tools like chatbots, and it sets a simple transparency rule: People generally must be told when they are interacting with AI.
For U.S. insurers, it would be easy to file this under “save for later” and move on. But that would be a mistake. Europe’s last major regulation, GDPR, followed a familiar path. Few U.S. companies were directly bound by it, but its influence reached far past borders anyway, shaping vendor contracts, procurement standards, and product design worldwide.








