01The state of AI in insurance
Insurance should be the natural home of enterprise AI. The industry employed actuaries before anyone said data scientist, and its entire operating model is the conversion of information into probability and price.
That is not what has happened. Most insurers now run promising pilots: a claims summarisation tool here, an underwriting copilot there, a fraud model in a sandbox. Far fewer have those systems in production, assisting real decisions on real policies. That gap between demonstration and deployment is where most insurance AI initiatives live, and where many quietly end.
The pressure to close that gap is not abstract. Claims inflation has pushed loss ratios the wrong way across motor, home and health lines, catastrophe volatility keeps reinsurance costs elevated, and expense ratios remain stubborn because core processes still depend on people reading documents and rekeying data between systems. Each of those pressures is an argument for AI, and each is being made in board papers right now.
If you run underwriting, claims, risk or data for an insurer, you do not need convincing on the opportunity. The harder questions are why AI stalls in insurance specifically, and what the organisations reaching production do differently.
02The insurance data problem
A typical general insurer runs several policy administration systems, usually one per era of the company’s history. Each merger and acquisition added another, and the promised consolidation programmes rarely finished the job. Life insurers are often worse off, with closed books still running on platforms decades old.
Claims lives somewhere else, on platforms bought and built separately from underwriting, so the record of what was insured and the record of what went wrong sit in different systems with different identifiers and conventions. Billing may be a third system, the reinsurance ledger a fourth.
Then there is the channel. Brokers, aggregators, partners and direct digital channels each generate their own view of the customer and the risk, in their own formats, at their own quality. A broker-placed commercial risk arrives as submissions and schedules that look nothing like a direct channel’s structured records.
Beneath it all sits the unstructured layer, which in insurance carries most of the meaning: claims files, assessor and investigator reports, medical reports, repair quotes, photographs, call notes and years of correspondence hold the substance of what actually happened. The structured fields are often just the index.
The consequence: the same customer and the same risk are described differently in every system that touches them. The same building appears under three addresses and two construction codes. The same claimant exists under four identifiers. Point an AI system at that estate directly and it will answer instantly and confidently, and it will be inconsistently wrong in ways nobody can trace.
03What governed AI could deliver
Set the data problem aside for a moment and the potential is easy to state; the same use cases appear in every insurer’s strategy paper:
- Underwriting acceleration. Submission documents ingested, extracted and summarised into the workbench, so underwriters spend their time on judgement rather than rekeying.
- Claims triage and severity prediction. Incoming claims assessed for complexity, likely severity and required expertise at lodgement, so the right claims reach the right handlers early.
- Leakage and fraud signals. Patterns across claims, providers and repairers surfaced for investigation rather than discovered in hindsight.
- Pricing and portfolio insight. Portfolio drift, accumulation and emerging-risk questions answered in minutes from governed data instead of quarterly from extracts.
- Complaints and conduct monitoring. Expressions of dissatisfaction and conduct signals tracked across channels while there is still time to act on them.
- Reinsurance and regulatory reporting. Treaty data, bordereaux and regulatory returns assembled from consistent, traceable data rather than hand-stitched spreadsheets.
Nothing on that list is speculative; every capability has been demonstrated inside insurers. The interesting question is why so little of it is in production, and the answer is rarely the models.
04Why initiatives stall
Four forces hold insurance AI between pilot and production, and they compound.
Prudential obligations. Insurers are prudentially supervised, so the bar for any system touching policyholder data or influencing decisions is set by regulation, not enthusiasm. A pilot that cannot demonstrate compliance with information security, operational resilience and accountability requirements does not get promoted.
Fairness and discrimination risk. Pricing and decisions in insurance are legally constrained in ways most industries never face. A model that produces unfairly discriminatory pricing or claims outcomes is not a tuning problem, it is a legal and conduct problem. Risk functions rightly refuse to approve systems whose inputs and behaviour they cannot inspect.
Explainability expectations. When a claim is declined or a risk is loaded, regulators, code governance bodies, dispute schemes and ultimately courts can ask why. “The model said so” is not an answer any general counsel will defend. Every AI-assisted decision needs a traceable line from source data to output.
Legacy integration cost. Each initiative that connects directly to policy administration, claims and billing systems pays the full integration tax alone: bespoke connections, bespoke mappings, bespoke security review. The second project pays it all again. Integration spend crowds out the value the project was meant to deliver.
Underneath all four sits the data problem. Models acting on inconsistent data produce inconsistent decisions, and at insurance scale that means thousands of pricing, claims and service decisions a day drifting apart until a regulator, an auditor or a class action asks the question.
05The regulatory landscape
None of that caution is optional; the regulatory perimeter is already in place, and it is strikingly consistent from one market to the next. The International Association of Insurance Supervisors, the global standard-setter whose members supervise almost all of the world’s insurance premiums, used its 2025 application paper on the supervision of artificial intelligence to make the point plainly: the existing expectations on governance and conduct carry straight over to AI. Five kinds of obligation matter most for insurers, and while the named regulator changes with the map, every developed market enforces an equivalent of each.
Prudential standards. Prudential regulators make information security and operational resilience board-level obligations. In the European Union, Solvency II (Directive 2009/138/EC) sets the risk-based prudential framework that insurers and their national supervisors, coordinated by EIOPA, operate within. In Australia, APRA’s CPS 234 requires security capability commensurate with the threats to an insurer’s information assets, including those managed by third parties, and its CPS 230, in force since July 2025, extends the same discipline to operational risk and material service providers. In the United Kingdom, the Prudential Regulation Authority supervises insurers’ financial soundness and resilience along comparable lines. An AI system that reads policyholder data and feeds business processes sits squarely inside all of them.
Conduct regulation. Conduct regulators judge outcomes however they are produced. In the United Kingdom, the Financial Conduct Authority’s Consumer Duty, in force since July 2023, requires firms to deliver good outcomes for retail customers and to prove they monitor for them. In Australia, ASIC holds licensees to providing their financial services efficiently, honestly and fairly under the Corporations Act. Across the European Union, the Insurance Distribution Directive (Directive (EU) 2016/97) sets conduct and product-oversight duties for how insurance is sold. If AI assists a decision that harms a customer, the fact that software was involved is no defence in any of them.
Industry codes of practice. Self-regulatory codes add a further layer on claims handling, complaints and support for customers experiencing vulnerability. Australia’s General Insurance Code of Practice is one example, with comparable codes and conduct expectations operating across the United Kingdom and European markets. AI that touches claims or service must operate within those commitments, and code governance reporting requires insurers to know when it has not.
Data-protection law. Privacy law governs the collection, use and disclosure of the personal information insurance runs on, including the health information in life and health lines that attracts stricter handling almost everywhere. The EU’s General Data Protection Regulation (Regulation (EU) 2016/679) is the benchmark much of the world is measured against, and Australia’s Privacy Act and Australian Privacy Principles impose parallel obligations. Sending that data to external AI services raises questions many privacy teams cannot answer comfortably.
The direction of travel. Regulation written specifically for insurance AI is now arriving, and it points one way. In the European Union, the AI Act (Regulation (EU) 2024/1689) treats AI used for risk assessment and pricing of individuals in life and health insurance as high-risk, with obligations covering data governance, logging, transparency and human oversight. In the United States, the NAIC’s model bulletin on the use of AI systems by insurers, now adopted across more than twenty states, expects a documented AI programme with board accountability and testing for unfair discrimination, and New York’s NYDFS has issued its own guidance on AI and external consumer data in underwriting and pricing. Wherever your book sits, that is a preview of where insurance AI regulation is heading.
Read together, these frameworks converge on a single requirement: an insurer must be able to demonstrate control over what its AI systems saw, did and decided, with evidence. That requirement is architectural, and it is exactly what a control plane exists to satisfy.
06The control plane approach in insurance
An enterprise AI control plane is the infrastructure layer that sits between an organisation’s systems and its AI tools, resolving the estate's data into one governed, stored semantic layer and governing every interaction between the two. The full architecture is set out in the reference guide; what follows is how the pattern lands in insurance specifically.
One semantic layer across the estate. The control plane connects to policy administration, claims, billing and channel systems where they are, resolves the same customer, the same risk and the same claim once, and stores the result as one governed, unified semantic layer inside the insurer’s own tenancy, continuously hydrated from the sources. The systems of record keep doing their jobs and existing platform investments carry forward: weeks-scale deployment rather than a multi-year consolidation programme as the precondition for AI.
Least-privilege access on every interaction. Access rules are enforced at the moment AI consumes data, inherited from the insurer’s existing identity and access management. A claims copilot sees claims within its handler’s delegation. An underwriting assistant for one line of business cannot retrieve another’s records.
Complete lineage on every assisted decision. Every underwriting or claims decision assisted by AI carries a traceable record from source systems through transformation to output: which data, which model, which policy, whose authority. When a dispute scheme, auditor or regulator asks why, the evidence already exists.
Deployment inside your own tenancy. The control plane runs inside the insurer’s own cloud environment. Policyholder data, including health information, is not transmitted to or processed on external systems, which keeps sensitive personal information under prudential-grade control and keeps the privacy assessment tractable.
- Each pilot integrates directly with policy and claims systems
- The same customer means different things to different models
- Access rules rebuilt per project, enforced unevenly
- Explaining a decision means forensic reconstruction
- One semantic layer across policy, claims, billing and channels
- Every AI interaction passes one enforcement point
- Access inherited from existing IAM, applied every time
- Lineage and audit produced automatically for every output
Fig. 1 · Two operating models for insurance AI: per-project integration versus shared, enforced infrastructure.
DataReadyAI implements this pattern as three layers: a semantic normalisation engine that resolves policy, claims and channel data into one stored, governed layer, an AI orchestration engine that routes work across clouds and models, and a governance and activation layer that enforces policy and maintains immutable audit trails. The platform deploys inside your own AWS, Azure, GCP or Snowflake tenancy, and we are working with insurance and financial services organisations across multiple jurisdictions.
07Use cases in depth
With the control plane in place, that list stops being aspirational. Here is how each use case works, and where the human authority sits.
Claims triage and reserving support
Incoming claims are read in full, structured and unstructured content together, and scored for complexity, likely severity and required expertise. Handlers get a triaged queue and an early severity view that informs reserving conversations rather than replacing them. Reserve recommendations remain exactly that: recommendations, with the claims officer and the actuary holding the decision.
Underwriting submission ingestion and the workbench
Broker submissions, schedules and supporting documents are ingested and normalised into the underwriting workbench, with the risk pre-assembled against appetite, prior history and portfolio context. The underwriter starts from a complete picture instead of a document pile. Acceptance, terms and pricing authority stay with the underwriter.
Fraud and leakage signal detection
Once claims, policy and provider data share one semantic model, patterns invisible across system boundaries become visible: repairer billing anomalies, provider networks, claim narratives that repeat across identities. Signals route to investigators as leads with supporting evidence attached, not as verdicts.
Customer and policy 360 for service
Service teams and their copilots see a single governed view of the customer across every policy, claim and interaction, filtered by what each role is entitled to see. Fewer transfers, fewer repeated questions, and answers grounded in the whole record rather than one system’s fragment of it.
Complaints, conduct and remediation monitoring
Complaints and expressions of dissatisfaction are identified and tracked across calls, correspondence and claims files, giving conduct and code-compliance teams a live view rather than a quarterly reconstruction. When remediation is required, the affected cohort can be identified from governed data, with lineage to prove it is complete.
Reinsurance and regulatory reporting packs
Treaty statements, bordereaux and regulatory returns are assembled from the same governed semantic layer the rest of the business uses, with every figure traceable to source. The pack that took weeks of spreadsheet assembly becomes a governed output finance can sign off faster, with evidence attached.
08Implementation considerations for insurers
Insurers that reach production tend to follow the same sequence, and it is deliberately unheroic.
Start with one line of business and one workflow. Claims triage in motor, or submission ingestion in one commercial line. A bounded scope makes the risk assessment finite, gives the initiative a named owner, and produces a result the rest of the organisation can inspect.
Connect read-only first. The control plane’s first weeks are observation: scanning and mapping the estate, resolving entities, surfacing the real rather than documented state of the data. Nothing writes back to core systems, which keeps the initial security review proportionate and fast.
Bring risk, compliance and the appointed actuary in early. The functions that can veto an initiative at sign-off become its sponsors once they see lineage and audit output working. Their requirements, including human-in-the-loop checkpoints wherever an output affects a customer, should shape the design rather than review it afterwards.
- One line of business, one workflow, one named owner. Expand from evidence, not ambition.
- Read-only connection first. Observe and unify before anything acts.
- Risk, compliance and the appointed actuary at the table from week one, not at sign-off.
- Human-in-the-loop checkpoints wherever decisions affect customers: claims outcomes, pricing, remediation.
- Expand only once the semantic layer exists. The second workflow inherits the first one’s foundations.
The economics follow. The first workflow carries the cost of standing up the semantic layer and governance machinery; every workflow after it inherits them. That is why second and third use cases land in a fraction of the time, and why insurers that reach production tend to accelerate rather than stall again.
DataReadyAI’s deployment pattern for insurers follows this sequence directly: read-only connection and semantic discovery first, with first value typically inside 2 to 3 weeks and production-grade activation of the first governed workflow in 6 to 8 weeks. Access control inherits your existing IAM from day one, and the platform is cloud- and model-agnostic across Databricks, Snowflake, AWS, Azure and GCP, so it fits the estate you have.
09Frequently asked questions
Can insurers use AI on claims data without it leaving their environment?
Yes, and for most risk and privacy teams it is the only acceptable pattern. A control plane deploys inside the insurer’s own cloud tenancy, so claims files, health information and customer records are not transmitted to or processed on external systems. AI works against a governed, unified layer of claims, policy and customer data stored inside that tenancy.
How does a control plane help meet regulators’ expectations on AI?
Across markets the expectation converges on one thing: demonstrable control over what an AI system saw, did and decided. Whether the reference is APRA’s CPS 234 and CPS 230 in Australia, the EU AI Act’s obligations for high-risk insurance AI, the NAIC model bulletin and NYDFS guidance in the United States, or the FCA’s Consumer Duty in the United Kingdom, a control plane enforces access policy on every AI interaction and produces immutable audit trails as a by-product of normal operation, which is the evidence those regimes require. It does not replace your compliance programme; it gives it infrastructure.
Does this replace our policy or claims systems?
No. The control plane connects to policy administration, claims, billing and channel systems as they are and resolves their data once into a governed, unified semantic layer stored inside the insurer's own tenancy, kept continuously current. The systems of record remain the systems of record, and configurable projections keep feeding existing reporting. That is what makes weeks-scale deployment credible.
How do we manage fairness risk in AI-assisted decisions?
Three controls work together: least-privilege access so models only see data appropriate to the decision, complete lineage so every output can be traced and challenged, and human-in-the-loop checkpoints so underwriters and claims officers hold decision authority where outcomes affect customers. Fairness testing remains an ongoing actuarial and conduct discipline; the control plane’s contribution is that the evidence needed to run it exists by default.
10Sources and further reading
- International Association of Insurance Supervisors, Application Paper on the Supervision of Artificial Intelligence (2025), the global standard-setter’s guidance on applying the Insurance Core Principles to AI.
- European Union, Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act), including its high-risk classification of AI used for risk assessment and pricing of individuals in life and health insurance.
- European Insurance and Occupational Pensions Authority, Solvency II (Directive 2009/138/EC) and the Insurance Distribution Directive (Directive (EU) 2016/97).
- European Union, Regulation (EU) 2016/679 (the General Data Protection Regulation).
- National Association of Insurance Commissioners, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (2023).
- New York Department of Financial Services, Insurance Circular Letter No. 7 (2024) on the use of AI systems and external consumer data in underwriting and pricing.
- UK Financial Conduct Authority, the Consumer Duty, alongside the Prudential Regulation Authority’s prudential supervision of insurers.
- Australian Prudential Regulation Authority, Prudential Standards CPS 234 (Information Security) and CPS 230 (Operational Risk Management).
- DataReadyAI, Enterprise AI Control Plane: Definition, Architecture and Buyer’s Guide.