The discussion explored:
- Scaling governance alongside AI adoption
- Managing autonomous and embedded AI
- Balancing innovation with regulatory accountability
Governance must evolve as quickly as AI
Insurers acknowledged that the greatest governance challenge is the speed at which AI capabilities are changing. Policies developed around early GenAI use cases are already being tested by autonomous agents, AI embedded within enterprise software, and widespread employee access to foundation models.
Rather than relying on annual policy reviews, organisations are moving towards continuous governance, with regular reviews to ensure controls remain aligned with emerging technology, regulation, and business priorities.
Governance is becoming increasingly risk based. Rather than treating every AI initiative equally, organisations are introducing structured triage processes that assess factors such as:
- Customer-facing impact
- Personal or sensitive data
- Automated decision-making
- Third-party AI dependencies
- Regulatory exposure
This enables lower-risk internal productivity tools to progress more quickly while ensuring greater scrutiny for AI supporting underwriting, pricing, claims, or customer decisions.
Leaders stressed that governance should be embedded into existing enterprise risk processes and not as a separate function. AI risks are assessed alongside operational, cyber, and regulatory risks using governance structures that business leaders already understand.
Governance should enable innovation
Leaders agreed that governance teams deliver greater value when they engage throughout AI development. Instead of acting solely as reviewers, governance functions are supporting delivery through:
- Standardised risk assessments
- Testing and validation frameworks
- Bias assessment tools
- Model documentation guidance
- Implementation support
One leader reflected that changing perceptions depended on demonstrating:
“We were not the blocker, but the enabler.”
Creating safe environments for experimentation is equally important. Insurers have established AI sandboxes that allow employees to develop capability without exposing sensitive customer data or production systems.
Controls include:
- Restricted data access
- Limited permissions
- Token and cost controls
- No production deployment
Insurance leaders argued that preventing experimentation altogether increases organisational risk by encouraging employees to adopt unapproved AI tools outside governance processes.
Under-adoption now represents a business risk alongside misuse. Organisations that fail to build AI capability risk falling behind competitors as AI becomes embedded across core insurance operations.
Federated governance helps scale AI responsibly
As AI adoption expands across underwriting, claims, pricing, and corporate functions, centralised governance models are becoming increasingly difficult to sustain.
Instead, organisations are adopting federated governance structures where central teams define standards while accountability sits within business functions through:
- AI leads
- Model stewards
- Data owners
- AI champions
One organisation described supporting a central governance team with embedded AI leads across business units, maintaining visibility through a shared AI register while allowing decisions to be made closer to operational teams.
Leaders highlighted the importance of maintaining visibility across AI deployed through third-party software providers. Solution providers are embedding AI into existing platforms, often introducing new capabilities outside traditional procurement cycles.
This creates challenges around:
- Data residency
- Customer information
- Regulatory compliance
- Model transparency
- Contractual accountability
Organisations are responding by strengthening procurement processes while maintaining enterprise-wide AI inventories to improve oversight of internally developed and third-party AI capabilities alike.
Agentic AI is reshaping governance expectations
While insurers feel confident governing traditional machine learning models, autonomous AI agents introduce new governance questions that existing frameworks were not designed to address.
Concerns exist around:
- Runtime behaviour
- Autonomous decision-making
- Agent-to-agent interaction
- Escalation mechanisms
- Human accountability
One participant described exploring an aviation-inspired “flight envelope” for AI agents, defining clear operational limits that autonomous systems cannot exceed regardless of how they evolve.
Although still an emerging concept, these operational boundaries are likely to become increasingly important as insurers deploy AI into business-critical processes.
Human oversight remains a fundamental control. Organisations require explicit review before AI-generated recommendations influence underwriting, claims, or production systems. However, leaders recognised that simply requiring approval is insufficient if reviewers become passive.
Future governance is likely to require demonstration how those decisions were assessed and challenged, particularly in regulated environments where auditability and accountability remain paramount.
Governance as a strategic capability
AI governance in insurance is more than a compliance exercise. It is evolving into an operational capability that enables innovation with confidence while protecting customers, maintaining regulatory compliance, and strengthening resilience.
The insurers making the greatest progress are:
- Embedding AI governance into existing risk frameworks
- Applying proportionate, risk-based oversight
- Federating accountability across functions
- Creating safe experimentation environments
- Preparing governance for autonomous AI
As AI adoption accelerates, governance that is adaptive, transparent, and embedded across the organisation will become the key enabler of responsible innovation rather than a constraint on progress.
These insights come directly from data and AI leaders working in insurance organisations tackling these challenges. To highlight your thinking, exchange lived experiences with peers, and shape the next wave of industry insights, join us at an exclusive DataIQ session:
Governing Critical Data Elements: Best Practice for Mature Regulated Organisations in the US
Evolving Data Governance for the AI Era in Regulated Industries


