Civil Law And Ai Health Insurance Underwriting Discrimination Claims In Europe .
Civil Law and AI Health Insurance Underwriting Discrimination Claims in Europe
1. Introduction
AI health-insurance underwriting discrimination arises when an insurer uses an artificial-intelligence system to assess an applicant's health risk, determine eligibility, calculate premiums, impose exclusions, or otherwise decide insurance terms, and the system produces discriminatory results.
Examples include an AI system that:
charges higher premiums because of a person's disability;
rejects applicants with particular medical conditions;
uses genetic information or genetic proxies;
penalises particular ethnic or demographic groups through proxy variables;
uses health, lifestyle, family-history, or behavioural data in discriminatory ways;
gives systematically worse results to people with particular protected characteristics;
relies on inaccurate medical data;
reproduces discriminatory patterns contained in historical insurance data;
makes an automated decision without meaningful human review.
The important point is that European law does not generally treat an AI decision as legally neutral merely because a computer made it. Existing equality, insurance, data-protection, consumer-protection and civil-liability rules can apply to the insurer and, depending on the circumstances, other participants in the AI system.
The subject is particularly important because the EU AI Act expressly identifies AI used for risk assessment and pricing concerning natural persons in life and health insurance as a high-risk category. The legislation recognises the possibility of financial exclusion and discrimination. (EUR-Lex)
Important case-law qualification: There is still relatively little reported European litigation specifically involving an AI health-insurance underwriting algorithm. Therefore, the cases below combine (1) directly relevant insurance-discrimination authorities, (2) health-insurance cases, and (3) leading EU cases on automated profiling and health-data processing. They are best understood as analogous authorities for future AI underwriting disputes, rather than cases in which courts actually decided an AI underwriting claim.
2. Meaning of AI Health-Insurance Underwriting
Traditional underwriting involves evaluating factors such as:
age;
medical history;
existing illnesses;
family history;
occupation;
lifestyle;
expected medical expenditure;
previous claims;
mortality/morbidity statistics.
An AI underwriting system can process substantially more information, potentially including:
electronic health records;
prescription history;
wearable-device information;
genetic information;
claims history;
socioeconomic information;
geographical information;
purchasing behaviour;
online activity;
lifestyle indicators;
indirectly inferred health characteristics.
For example:
An insurer's AI model predicts that an applicant has unusually high future healthcare costs and therefore rejects the application.
The legal question is not simply whether the prediction was statistically accurate.
The court may ask:
Was the data lawfully obtained?
Was health data processed lawfully?
Was a protected characteristic used directly or indirectly?
Did the algorithm create discriminatory effects?
Was the decision based exclusively on automated processing?
Could the applicant challenge the decision?
Was the underlying data accurate?
Was there meaningful human intervention?
Was the insurer transparent about the decision-making process?
Did the insurer cause compensable loss?
3. European Legal Framework
A. EU AI Act
The EU AI Act is particularly important.
Article/Annex III identifies AI systems intended for risk assessment and pricing concerning natural persons in life and health insurance as high-risk AI systems. (AI Act Service Desk)
This is significant because the EU legislature specifically recognised that such systems can affect:
access to insurance;
insurance affordability;
financial inclusion;
fundamental rights;
discrimination;
people's health and livelihood.
The AI Act therefore provides an important regulatory framework concerning:
risk management;
data and data governance;
technical documentation;
record keeping;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity;
post-market monitoring.
However, AI Act compliance does not automatically answer every civil-law question. A system could satisfy technical AI requirements and still potentially create liability under discrimination, GDPR, contract, tort/delict, consumer or insurance law.
4. GDPR and Health Data
Health data constitutes a special category of personal data under Article 9 GDPR.
AI underwriting therefore raises serious questions concerning:
lawful processing;
purpose limitation;
data minimisation;
accuracy;
transparency;
profiling;
automated decision-making;
security;
accountability.
Article 22 GDPR is especially relevant where an applicant is subjected to a decision based solely on automated processing that produces legal or similarly significant effects.
The GDPR framework also recognises that automated profiling can produce discriminatory effects based on matters including:
racial or ethnic origin;
genetic characteristics;
health status;
disability;
sexual orientation;
religion and other protected characteristics.
The CJEU has expressly connected Article 22 safeguards with the prevention of discriminatory effects. (EUR-Lex)
5. Equality and Anti-Discrimination Law
Depending on the particular insurance product and Member State, relevant rules can arise from:
EU Charter of Fundamental Rights;
Directive 2004/113/EC;
national equality legislation;
disability-discrimination legislation;
constitutional principles;
European Convention on Human Rights;
national insurance legislation.
A major issue is the difference between:
Direct discrimination
The algorithm explicitly uses a protected characteristic.
Example:
"Female applicants receive a higher premium."
Indirect discrimination
The algorithm does not expressly use the protected characteristic but uses another variable that systematically disadvantages the protected group.
Example:
The model uses a particular behavioural or geographical variable that acts as a proxy for ethnicity.
Algorithmic discrimination
The discriminatory result may arise without anyone intentionally programming discrimination.
For example:
Historical insurance data contains discriminatory patterns → AI learns the pattern → AI reproduces it → insurer relies upon the result.
The absence of discriminatory intent does not necessarily eliminate legal consequences.
6. Case Law
Case 1 — Association belge des Consommateurs Test-Achats ASBL v Conseil des ministres
CJEU, Case C-236/09, 1 March 2011
This is one of the most important European insurance-discrimination authorities.
The case concerned the use of sex as an actuarial factor in insurance.
The CJEU examined Article 5(2) of Directive 2004/113 and held that an unlimited exemption allowing differences in insurance premiums and benefits based on sex was incompatible with the principle of equal treatment. (EUR-Lex)
Importance for AI underwriting
The case establishes a crucial principle:
Actuarial justification does not automatically make discriminatory insurance treatment lawful.
This is highly relevant to AI.
An insurer might argue:
"Our algorithm is not discriminatory; statistical data shows that this group presents a different insurance risk."
Test-Achats demonstrates why that argument must be examined against applicable equality law.
AI example
Suppose an AI model discovers that a particular protected group historically generated higher healthcare costs.
The insurer cannot simply say:
"The algorithm found a statistical correlation."
The legal question remains whether the use of that characteristic or proxy is legally permissible.
7. Case 2 — Van Kück v Germany
ECtHR, Application No. 35968/97, 12 June 2003
This case concerned a German private health-insurance dispute involving reimbursement for hormone treatment and gender-reassignment surgery.
The applicant challenged the refusal of reimbursement.
The ECtHR examined the relationship between private health insurance, medical necessity, personal autonomy and Article 8 of the Convention. It concluded that the German authorities had failed to strike a fair balance between the interests of the private health insurer and the individual's interests. (HUDOC)
Importance for AI underwriting
Van Kück is relevant because it shows that private health insurance decisions can intersect with fundamental rights.
For AI systems this raises questions such as:
Can an AI model classify gender-related healthcare as unusually risky?
Can historical data cause certain treatments to be treated as automatically unnecessary?
Can an algorithm indirectly discriminate against transgender applicants?
Can an insurer blindly rely on an automated medical classification?
Principle
Insurance decision-making cannot necessarily be separated from fundamental rights merely because the relationship is contractual.
8. Case 3 — P.B. and J.S. v Austria
ECtHR, Application No. 18984/02, 22 July 2010
This case concerned the extension of health and accident insurance coverage to a same-sex partner under an Austrian civil-service insurance scheme.
The ECtHR considered Article 14 together with Article 8 and found discriminatory treatment concerning access to insurance coverage. (HUDOC)
Importance for AI
The case demonstrates that insurance arrangements may fall within the protection against discrimination when connected with Convention rights.
An AI system could create similar problems indirectly.
For example:
An algorithm does not expressly ask whether someone is homosexual but uses variables that produce systematically different insurance outcomes for same-sex couples.
The legal analysis would therefore have to consider the actual discriminatory effect, not merely whether the software contains an explicit "sexual orientation" field.
9. Case 4 — SCHUFA Holding (Scoring)
CJEU, Case C-634/21, OQ v Land Hessen, judgment of 7 December 2023
This is one of the most important modern cases for AI-style underwriting.
The case concerned automated credit scoring under Article 22 GDPR.
The CJEU held that the automated establishment of a probability value concerning a person's ability to meet future payment obligations can constitute automated individual decision-making where a third party strongly relies on that score in deciding whether to establish, implement or terminate a contractual relationship. (EUR-Lex)
Why this matters for insurance
Imagine:
AI produces a "health-risk score" → insurer automatically relies on the score → applicant is rejected or charged substantially more.
The insurer may argue:
"The AI did not make the decision. It merely supplied a score."
SCHUFA demonstrates why that distinction may not be sufficient where the score effectively determines the contractual outcome.
Principle
An algorithmic score can itself become legally significant when another decision-maker strongly relies upon it.
This is extremely important for AI underwriting.
10. Case 5 — CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria
CJEU, Case C-203/22, judgment of 27 February 2025
This case concerned automated scoring and the GDPR right to receive meaningful information about the logic involved in automated decision-making. (Curia)
The Court considered how a data subject can understand an automated result without necessarily receiving the complete algorithm.
The Court emphasised meaningful information about the procedure and principles actually applied.
Importance for health insurance
Suppose an applicant receives:
"Your AI health-risk score does not meet our underwriting threshold."
That may raise questions such as:
Which information was used?
Was medical history used?
Was genetic information used?
Was lifestyle information used?
Were proxy variables used?
Which factors significantly affected the result?
Was inaccurate information used?
A simple statement saying "the computer calculated your risk" may not provide meaningful transparency.
Principle
The right to explanation is particularly important when an automated score materially affects the individual's rights or contractual position.
11. Case 6 — ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein
CJEU, Case C-667/21, 21 December 2023
This case concerned the processing of health data under Articles 6 and 9 GDPR and also Article 82 concerning compensation and liability. (EUR-Lex)
The case is particularly relevant because it concerns:
health data;
a medical/health-insurance institution;
GDPR;
lawful processing;
liability;
compensation.
Importance for AI underwriting
AI underwriting frequently requires large quantities of medical information.
Therefore, an insurer must consider:
Is the health information lawfully processed?
Is the processing covered by an appropriate Article 9 condition?
Is the information necessary?
Is it being used for the stated purpose?
Is access properly controlled?
Is the information accurate?
Has inappropriate disclosure occurred?
Has unlawful processing caused compensable harm?
Civil-liability significance
A discrimination claim may therefore exist alongside a data-protection compensation claim.
12. Case 7 — A v Veselības ministrija
CJEU, Case C-243/19, 29 October 2020
This case concerned healthcare coverage and a difference in treatment based on religion.
The CJEU considered the interaction between healthcare insurance/social-security arrangements and Article 21 of the EU Charter concerning non-discrimination. (EUR-Lex)
Importance for AI underwriting
It illustrates that healthcare and insurance decisions can engage EU equality principles.
For AI:
If an automated healthcare-risk model systematically produces worse results for persons associated with a protected characteristic, the legal analysis cannot stop with actuarial accuracy.
The insurer may need to examine:
the protected characteristic;
the actual disadvantage;
justification;
proportionality;
necessity;
the legal basis for the differentiation.
13. Case 8 — Schuler-Zgraggen v Switzerland
ECtHR, Application No. 14518/89, 24 June 1993
The case concerned disability and social-insurance benefits.
The applicant had developed tuberculosis and subsequently received an invalidity pension. The dispute concerned the treatment of her entitlement within the Swiss social-insurance system. (Global Health Rights)
Importance for AI health underwriting
The case is relevant to the broader principle that disability and health-related characteristics can engage non-discrimination protections in European social-insurance systems.
For AI underwriting, disability-related variables require particular caution.
An AI model could inadvertently learn:
disability → increased medical expenditure → increased insurance risk → exclusion.
Such a chain cannot automatically be treated as legally sufficient merely because it is statistically observable.
14. Case 9 — CJEU automated profiling principles under Article 22
The modern Article 22 jurisprudence surrounding SCHUFA is particularly important even though it concerns financial scoring rather than insurance.
The CJEU recognised that Article 22 protects individuals against risks created by automated processing and profiling. The Court noted that such profiling can involve predictions about aspects such as:
economic situation;
health;
preferences;
behaviour;
reliability.
It also recognised the risk of discriminatory effects, including discrimination based on genetic or health status. (EUR-Lex)
This makes the reasoning highly transferable to AI insurance underwriting.
15. Main Legal Issues in AI Health-Insurance Discrimination
A. Direct discrimination
The easiest case is where the AI expressly uses a protected characteristic.
Example:
"Female applicants receive a 15% higher premium."
Test-Achats demonstrates that actuarial/statistical reasoning cannot automatically override equality rules. (EUR-Lex)
B. Indirect discrimination
This is more difficult.
The algorithm may not contain a protected characteristic but use a substitute.
For example:
Ethnicity → neighbourhood → healthcare utilisation → AI score
The algorithm technically uses "neighbourhood", not ethnicity.
But if neighbourhood functions as a proxy producing systematically discriminatory outcomes, the court may examine the substantive effect.
16. Genetic Discrimination
Genetic information is particularly sensitive.
AI could potentially process:
genetic test results;
family medical history;
genetic predisposition;
inferred genetic characteristics.
European law contains strong safeguards around genetic information, although the exact insurance rules vary between jurisdictions.
The broader European legal framework recognises concerns about discrimination based on genetic characteristics, while national insurance and genetic-testing legislation can impose additional restrictions.
Therefore:
An insurer cannot assume that because genetic information improves predictive accuracy, its use is automatically lawful.
17. Health Data as Special-Category Data
AI underwriting can involve highly sensitive information:
| Data | Legal concern |
|---|---|
| Medical diagnosis | Health data |
| Prescription history | Health data |
| Hospital records | Health data |
| Genetic information | Special protection |
| Disability status | Equality + health-data issues |
| Mental-health information | Health data |
| Biometric information | Potentially special-category data |
| Wearable data | May reveal health information |
| Family medical history | Potentially sensitive |
| Lifestyle information | Profiling risk |
The GDPR therefore becomes central to an AI underwriting dispute.
18. Accuracy and Algorithmic Errors
An AI model may be discriminatory because it relies on incorrect information.
Example:
A database incorrectly records that an applicant has a chronic disease.
The AI system interprets this as high medical risk.
The insurer increases the premium.
The applicant suffers financial harm.
This can produce several legal issues:
inaccurate personal data;
unlawful profiling;
defective automated decision-making;
discrimination;
breach of contract;
negligence/delict;
compensation.
The GDPR places particular importance on accuracy and accountability.
19. Historical Bias
AI learns from historical data.
Suppose historical underwriting practices systematically charged a particular group more.
The AI is trained on those historical decisions.
It learns:
"This group = higher risk."
The insurer then claims that the AI is merely reflecting historical actuarial data.
The civil-law issue becomes:
Can an insurer lawfully reproduce historical discriminatory practices through an automated system?
The answer depends on the applicable equality and insurance rules, but statistical reproduction does not itself provide a complete legal defence.
Test-Achats is especially instructive because it demonstrates the tension between actuarial factors and equality principles. (EUR-Lex)
20. Proxy Discrimination
Proxy discrimination is particularly important for AI.
A model might use:
postcode;
occupation;
purchasing behaviour;
language;
education;
lifestyle;
internet activity;
healthcare-provider patterns.
These variables can correlate with protected characteristics.
Example
An AI system does not ask:
"Are you disabled?"
Instead, it uses:
prescription frequency;
employment history;
healthcare visits;
mobility-device purchases.
The resulting model may effectively identify people with disabilities.
That creates difficult questions concerning:
discrimination;
profiling;
health-data processing;
purpose limitation;
data minimisation.
21. Automated Rejection
Consider:
Applicant submits health-insurance application → AI evaluates medical history → risk score = 92/100 → automatic rejection.
The applicant may challenge:
First
Whether Article 22 GDPR applies.
Second
Whether an Article 22 exception exists.
Third
Whether appropriate safeguards were provided.
Fourth
Whether meaningful human intervention was available.
Fifth
Whether the underlying data were accurate.
Sixth
Whether the decision was discriminatory.
SCHUFA is particularly relevant where an algorithmic score substantially determines the contractual outcome. (EUR-Lex)
22. Human Review
A human being clicking "approve" after an AI recommendation does not necessarily eliminate the problem.
The important question is:
Was the human intervention genuinely capable of changing the result?
For example:
Weak human review
AI says:
"Reject."
Employee clicks:
"Confirm."
Meaningful review
Employee:
reviews the medical information;
examines the AI reasoning;
checks disputed information;
considers the applicant's explanation;
investigates possible discrimination;
can override the algorithm.
The second model provides substantially greater procedural protection.
23. Explainability
An applicant may ask:
"Why was my health-insurance application rejected?"
An insurer cannot necessarily answer only:
"Our proprietary algorithm determined that you were high risk."
The modern CJEU scoring jurisprudence emphasises meaningful information about the logic involved in automated decision-making. (Curia)
The applicant may need information sufficient to understand:
important factors;
relevant categories of information;
how those factors contributed to the result;
significance of the result;
consequences of the decision.
Trade-secret protection does not necessarily mean that all meaningful information can be withheld.
24. Civil Liability
A claimant may potentially formulate several legal causes of action.
1. Contractual liability
The insurer may have breached:
policy terms;
statutory insurance obligations;
contractual good-faith obligations;
disclosure obligations.
2. Tort/delict liability
Depending on national law:
negligence;
unlawful discrimination;
breach of protected rights;
misuse of personal data;
wrongful economic loss.
3. GDPR liability
Article 82 GDPR provides a compensation framework for damage resulting from infringements of the GDPR.
ZQ is particularly relevant to health-data processing and Article 82. (EUR-Lex)
4. Equality remedies
Depending on the applicable law:
compensation;
restoration of equal treatment;
declaration of unlawful discrimination;
administrative sanctions;
regulatory enforcement.
25. Causation
The claimant must generally connect the AI system's conduct with the alleged harm under the relevant legal regime.
Example:
Incorrect health data
↓
AI risk score
↓
Higher premium
↓
Applicant pays €4,000 more
Potential causation question:
Would the applicant have received the lower premium if the incorrect data had not been used?
This may require:
algorithmic records;
alternative calculations;
underwriting manuals;
model documentation;
audit logs;
historical data;
expert evidence.
26. Damages
Possible losses may include, depending on the applicable legal regime:
Economic loss
excessive premiums;
lost insurance coverage;
additional healthcare costs;
financial losses resulting from wrongful rejection.
Non-material damage
GDPR claims can potentially involve non-material damage where the statutory requirements are satisfied.
Discrimination-related harm
National equality law may provide additional remedies.
Corrective remedies
A claimant may also seek:
correction of data;
reconsideration of underwriting;
cessation of unlawful processing;
deletion where legally applicable;
regulatory intervention.
27. Liability of the AI Developer
A difficult question is:
Who is liable—the insurer or the AI developer?
The answer depends on the contractual and factual structure.
Insurer
Usually central where the insurer:
chooses the model;
supplies applicant data;
sets underwriting thresholds;
relies upon the output;
makes the final insurance decision.
AI developer
Potential liability may arise where the developer:
supplied defective software;
concealed known defects;
provided misleading documentation;
breached contractual obligations;
violated applicable AI/product-safety obligations.
Both
In some circumstances multiple parties may potentially bear responsibility.
28. Insurer's Possible Defences
An insurer might argue:
Defence 1 — Statistical accuracy
"The model is statistically accurate."
But accuracy and non-discrimination are separate legal questions.
Defence 2 — No discriminatory intention
"Nobody intended to discriminate."
Intent may not be decisive where the applicable law prohibits discriminatory effects.
Defence 3 — AI merely assisted
"The final decision was made by a human."
The relevance of this argument depends on whether the human review was meaningful.
Defence 4 — Legitimate underwriting
"We must price risk accurately."
This is a legitimate commercial consideration, but it must be reconciled with applicable equality, privacy and insurance rules.
Defence 5 — Trade secret
"The algorithm is confidential."
Trade-secret protection may limit disclosure, but does not necessarily eliminate GDPR transparency obligations.
The CJEU's scoring jurisprudence is important here. (Curia)
29. Special Problem: Risk Classification vs Discrimination
Insurance fundamentally involves risk classification.
Therefore, an important legal distinction is:
Risk differentiation is not automatically discrimination, but a risk-based distinction may become unlawful if it conflicts with applicable equality rules.
For example:
Potentially legitimate
Different premiums based on legally permissible actuarial risk factors.
Potentially problematic
Higher premiums based on a protected characteristic where EU or national law prohibits that differentiation.
Particularly problematic
A supposedly neutral variable that functions as a discriminatory proxy.
30. Relationship Between AI Act and GDPR
These laws perform different functions.
| Issue | AI Act | GDPR |
|---|---|---|
| AI risk classification | Major role | Limited |
| Health data | Relevant | Central |
| Automated decision | Relevant | Article 22 central |
| Profiling | Relevant | Central |
| Data accuracy | Relevant | Article 5 central |
| Discrimination | Major concern | Major concern |
| Human oversight | Major requirement | Article 22 safeguards |
| Explanation | Transparency requirements | Articles 13–15 |
| Compensation | Not the main framework | Article 82 |
| Insurance AI | High-risk category | Processing rules apply |
Therefore:
Compliance with the AI Act does not replace GDPR compliance.
31. Why SCHUFA Is Particularly Important
The strongest analogy for AI health underwriting is the combination of:
SCHUFA + Test-Achats + Van Kück + ZQ
SCHUFA
Addresses automated scoring and contractual decision-making. (EUR-Lex)
Test-Achats
Addresses actuarial discrimination in insurance. (EUR-Lex)
Van Kück
Addresses private health insurance and fundamental rights. (HUDOC)
ZQ
Addresses health data and GDPR liability. (EUR-Lex)
Together, they provide a useful legal framework for analysing future AI-health-insurance litigation.
32. Hypothetical Example
Assume an insurer uses AI to evaluate 100,000 applicants.
The model considers:
medical history;
prescriptions;
postcode;
occupation;
lifestyle;
family history.
The model discovers that applicants from a particular demographic have historically produced higher medical expenses.
It therefore gives them higher risk scores.
Step 1 — Data protection
Was the underlying health information lawfully processed?
Step 2 — Accuracy
Was the data accurate?
Step 3 — Automated decision-making
Was the applicant subject to a decision based solely on automated processing?
Step 4 — Explanation
Can the insurer provide meaningful information about the logic?
Step 5 — Discrimination
Does the model directly or indirectly disadvantage a protected group?
Step 6 — Actuarial justification
Is the differentiation legally permissible?
Step 7 — Human intervention
Could a qualified person genuinely reconsider the result?
Step 8 — Causation
Did the AI result cause the applicant's financial loss?
Step 9 — Damages
What compensation or corrective remedy is available?
33. Case-Law Comparison
| Case | Main issue | Relevance to AI underwriting |
|---|---|---|
| Test-Achats, C-236/09 | Sex-based insurance actuarial factors | Statistical actuarial reasoning cannot automatically defeat equality rules |
| Van Kück v Germany | Private health insurance and gender identity | Health-insurance decisions can engage fundamental rights |
| P.B. & J.S. v Austria | Same-sex insurance coverage | Insurance arrangements can engage non-discrimination principles |
| SCHUFA, C-634/21 | Automated scoring | Algorithmic scores can constitute significant automated decision-making |
| CK, C-203/22 | Explanation of automated scoring | Meaningful explanation and transparency are important |
| ZQ, C-667/21 | Health data and GDPR liability | Health-data processing can create GDPR liability |
| A v Veselības ministrija, C-243/19 | Healthcare insurance/social security and religion | Healthcare coverage can engage EU non-discrimination principles |
| Schuler-Zgraggen v Switzerland | Disability/social insurance | Disability-related insurance decisions engage equality considerations |
The first three are particularly useful for insurance discrimination, while SCHUFA and CK are particularly useful for automated decision-making, and ZQ is particularly useful for health-data liability. (EUR-Lex)
34. Key Legal Principles
Principle 1
AI does not eliminate insurer responsibility.
Principle 2
Statistical accuracy is not the same as legal permissibility.
Principle 3
Actuarial calculations remain subject to applicable equality rules.
Principle 4
Health data receives enhanced GDPR protection.
Principle 5
Automated scoring can itself have legal significance.
Principle 6
A human signature does not necessarily make an automated process genuinely human.
Principle 7
Applicants may have rights to meaningful information about automated decisions.
Principle 8
Proxy discrimination can be as important as explicit discrimination.
Principle 9
Incorrect training data can create both discrimination and data-protection problems.
Principle 10
AI Act, GDPR, equality law and insurance law operate cumulatively rather than as substitutes.
35. Future Litigation Questions
European courts are likely to confront questions such as:
Can an AI insurer use genetic-risk predictions?
Can wearable-device data be used to calculate premiums?
When does a health-risk score constitute automated decision-making?
What constitutes meaningful human intervention?
How much of an underwriting algorithm must be disclosed?
Can an insurer rely upon an AI model trained on historically discriminatory data?
Who bears responsibility for discriminatory AI—insurer or developer?
Can a protected characteristic be inferred indirectly?
What constitutes adequate evidence of algorithmic discrimination?
How should damages be calculated?
Can trade-secret protection restrict explanation?
What happens where an AI model is statistically accurate but produces prohibited discriminatory effects?
36. Exam-Oriented Conclusion
AI health-insurance underwriting discrimination in Europe is governed by an overlapping framework of insurance law, equality law, GDPR, fundamental rights, AI regulation and civil liability.
The EU AI Act is particularly significant because it expressly classifies AI used for risk assessment and pricing of natural persons in life and health insurance as high-risk AI. (AI Act Service Desk)
The leading cases provide complementary principles:
Test-Achats → actuarial insurance factors and equality;
Van Kück → private health insurance and fundamental rights;
P.B. and J.S. → discrimination and insurance coverage;
SCHUFA → automated scoring and contractual decision-making;
CK/Dun & Bradstreet → meaningful explanation of profiling;
ZQ → health-data processing and compensation;
A v Veselības ministrija → healthcare insurance and non-discrimination;
Schuler-Zgraggen → disability and social-insurance protection.
Thus, the central legal issue is not simply whether AI predicts insurance risk accurately, but whether the collection and use of data, algorithmic methodology, resulting differentiation, automated decision-making and resulting harm comply with European equality, privacy, insurance and civil-liability requirements. (EUR-Lex)
Ultra-Short Revision Formula
AI Health Insurance Discrimination =
Sensitive Health Data
AI Profiling
Risk Classification
Equality Law
GDPR Article 9
GDPR Article 22
AI Act High-Risk Rules
Human Oversight
Explainability
Causation & Damages
= Potential Civil/Regulatory Liability

comments