AI governance in insurance – Building trust while accelerating adoption

Governance frameworks are rapidly becoming outdated as AI evolves. Read how senior data and AI leaders from the insurance industry are adapting governance to boost innovation at speed.
AI governance in insurance – Building trust while accelerating adoption

The discussion explored: 

  • Scaling governance alongside AI adoption  
  • Managing autonomous and embedded AI  
  • Balancing innovation with regulatory accountability  

 

Governance must evolve as quickly as AI 

Insurers acknowledged that the greatest governance challenge is the speed at which AI capabilities are changing. Policies developed around early GenAI use cases are already being tested by autonomous agents, AI embedded within enterprise software, and widespread employee access to foundation models. 

Rather than relying on annual policy reviews, organisations are moving towards continuous governance, with regular reviews to ensure controls remain aligned with emerging technology, regulation, and business priorities. 

Governance is becoming increasingly risk based. Rather than treating every AI initiative equally, organisations are introducing structured triage processes that assess factors such as: 

  • Customer-facing impact  
  • Personal or sensitive data  
  • Automated decision-making  
  • Third-party AI dependencies  
  • Regulatory exposure  

 

This enables lower-risk internal productivity tools to progress more quickly while ensuring greater scrutiny for AI supporting underwriting, pricing, claims, or customer decisions. 

Leaders stressed that governance should be embedded into existing enterprise risk processes and not as a separate function. AI risks are assessed alongside operational, cyber, and regulatory risks using governance structures that business leaders already understand. 

 

Governance should enable innovation 

Leaders agreed that governance teams deliver greater value when they engage throughout AI development. Instead of acting solely as reviewers, governance functions are supporting delivery through: 

  • Standardised risk assessments  
  • Testing and validation frameworks  
  • Bias assessment tools  
  • Model documentation guidance  
  • Implementation support  

 

One leader reflected that changing perceptions depended on demonstrating: 

“We were not the blocker, but the enabler.” 

Creating safe environments for experimentation is equally important. Insurers have established AI sandboxes that allow employees to develop capability without exposing sensitive customer data or production systems. 

Controls include: 

  • Restricted data access  
  • Limited permissions  
  • Token and cost controls  
  • No production deployment  

 

Insurance leaders argued that preventing experimentation altogether increases organisational risk by encouraging employees to adopt unapproved AI tools outside governance processes. 

Under-adoption now represents a business risk alongside misuse. Organisations that fail to build AI capability risk falling behind competitors as AI becomes embedded across core insurance operations. 

 

Federated governance helps scale AI responsibly 

As AI adoption expands across underwriting, claims, pricing, and corporate functions, centralised governance models are becoming increasingly difficult to sustain. 

Instead, organisations are adopting federated governance structures where central teams define standards while accountability sits within business functions through: 

  • AI leads  
  • Model stewards  
  • Data owners  
  • AI champions  

 

One organisation described supporting a central governance team with embedded AI leads across business units, maintaining visibility through a shared AI register while allowing decisions to be made closer to operational teams. 

Leaders highlighted the importance of maintaining visibility across AI deployed through third-party software providers. Solution providers are embedding AI into existing platforms, often introducing new capabilities outside traditional procurement cycles. 

This creates challenges around: 

  • Data residency  
  • Customer information  
  • Regulatory compliance  
  • Model transparency  
  • Contractual accountability  

 

Organisations are responding by strengthening procurement processes while maintaining enterprise-wide AI inventories to improve oversight of internally developed and third-party AI capabilities alike. 

 

Agentic AI is reshaping governance expectations 

While insurers feel confident governing traditional machine learning models, autonomous AI agents introduce new governance questions that existing frameworks were not designed to address. 

Concerns exist around: 

  • Runtime behaviour  
  • Autonomous decision-making  
  • Agent-to-agent interaction  
  • Escalation mechanisms  
  • Human accountability  

 

One participant described exploring an aviation-inspired “flight envelope” for AI agents, defining clear operational limits that autonomous systems cannot exceed regardless of how they evolve. 

Although still an emerging concept, these operational boundaries are likely to become increasingly important as insurers deploy AI into business-critical processes. 

Human oversight remains a fundamental control. Organisations require explicit review before AI-generated recommendations influence underwriting, claims, or production systems. However, leaders recognised that simply requiring approval is insufficient if reviewers become passive. 

Future governance is likely to require demonstration how those decisions were assessed and challenged, particularly in regulated environments where auditability and accountability remain paramount. 

 

Governance as a strategic capability 

AI governance in insurance is more than a compliance exercise. It is evolving into an operational capability that enables innovation with confidence while protecting customers, maintaining regulatory compliance, and strengthening resilience. 

The insurers making the greatest progress are: 

  • Embedding AI governance into existing risk frameworks  
  • Applying proportionate, risk-based oversight  
  • Federating accountability across functions  
  • Creating safe experimentation environments 
  • Preparing governance for autonomous AI  

 

As AI adoption accelerates, governance that is adaptive, transparent, and embedded across the organisation will become the key enabler of responsible innovation rather than a constraint on progress. 

 

These insights come directly from data and AI leaders working in insurance organisations tackling these challenges. To highlight your thinking, exchange lived experiences with peers, and shape the next wave of industry insights, join us at an exclusive DataIQ session: 

Governing Critical Data Elements: Best Practice for Mature Regulated Organisations in the US 

Evolving Data Governance for the AI Era in Regulated Industries