Insurance

    AI Is Moving Deeper Into Insurance Operations

    By Trussed AIAugust 2026

    Anthropic's recent activity in insurance is worth paying attention to, not because insurers are adopting another enterprise AI tool, but because of where Claude is starting to show up. AIG is using it in underwriting, where CEO Peter Zaffino has said the company has compressed the timeline to review business by more than 5x in early rollouts while simultaneously improving data accuracy from 75% to over 90% (Anthropic). Travelers is rolling it out across nearly 10,000 engineers, data scientists, analysts and product owners, who are using it to enhance and accelerate software, analytics and machine learning model development (Business Wire). Allianz is integrating Claude into its internal AI platform and developing custom AI agents capable of orchestrating multi-step workflows and automating labor-intensive processes at scale, from intake documentation to claims processing in areas such as motor and health insurance (Allianz). Verisk, meanwhile, has connected its data directly into Claude through MCP connectors, providing property, casualty, and specialty insurance data for underwriting, claims, and risk analysis (Anthropic).

    These are four different use cases at four different companies, but they point in the same direction. The first wave of enterprise generative AI was largely about individual productivity: helping an employee summarize a document, write code, research a question, or draft an email. What we are seeing now is AI being connected to the workflows, data, and systems through which insurance companies actually operate. That is a meaningfully different kind of adoption, and it changes what insurers need in order to manage it responsibly.

    Once AI participates in underwriting, claims, risk analysis, and other core processes, insurers need to know what models are operating in their environment, what those models are allowed to do, what information they can access, which policies apply to them, and what happened when a particular AI-driven action or decision occurred. As AI becomes part of insurance operating infrastructure, governance has to become infrastructure as well.

    From Governance Programs to Governance Infrastructure

    Most large insurers already have some form of AI governance program in place, including policies, approval processes, oversight structures, and documentation requirements. Those programs are necessary, but a governance program and governance infrastructure solve different problems. A governance program defines what should happen. It might specify which models can be used, what data they can access, what testing is required, and when human review is necessary. Governance infrastructure makes those requirements operational by enforcing policy when an AI system is actually used and by creating a record of what occurred.

    That distinction becomes more important as adoption moves beyond controlled pilots. Committees, spreadsheets, and manual reviews can work reasonably well for a limited number of applications. They become difficult to sustain once AI is embedded across hundreds of workflows and generating large volumes of interactions across multiple models and providers. The architecture has to change along with the scale of adoption, and the four examples above suggest that scale is arriving faster than most governance programs were built to handle. Notably, Allianz and Anthropic have already signaled awareness of this: part of their partnership involves co-developing AI systems to log every decision, rationale and data source to ensure full traceability and compliance with regulations (Mobile World Live).

    What That Infrastructure Requires

    The first requirement is a live inventory of the AI environment. Insurers cannot govern systems they do not know exist, particularly as different business units adopt different models, copilots, vendor applications, developer tools, and agents on their own timelines. An operational inventory needs to show what is running, who owns it, which models and providers it uses, what data it touches, and what governance requirements apply to it. That information needs to reflect the environment continuously, rather than being reconciled every quarter or after the fact.

    The second requirement is runtime policy enforcement. Design-time reviews remain important, but they do not govern what happens after a system is deployed. If a model accesses information it should not access, an application begins using an unapproved model, or an agent attempts an action outside its authorized scope, policy needs to be evaluated at the moment the interaction occurs. This becomes more important as insurers introduce agentic systems, since the number of actions that can realistically be reviewed by a person before execution declines as those systems take on more autonomy.

    The third requirement is automated audit evidence. For consequential AI interactions, an insurer should be able to determine which model was used, what data was accessed, what policies were evaluated, and what action occurred. Producing that evidence cannot depend on manually reconstructing logs across disconnected systems after the fact. At scale, it needs to be generated as a normal byproduct of how the AI systems operate, not as a separate exercise layered on top.

    Finally, these controls have to work across models and vendors. An insurer's AI environment will not be built entirely on Claude, GPT, Gemini, or any other single model family, and the examples above already show why: different business units are choosing different tools for different jobs. If governance is implemented independently inside every application or vendor platform, insurers end up with inconsistent controls and incomplete visibility. A common control layer is what makes it possible to apply organizational policy consistently across that heterogeneous environment.

    Regulation Is Accelerating the Need

    The regulatory environment makes these requirements more immediate. The NAIC Model Bulletin calls for insurers to maintain an AI governance program covering areas including oversight, risk management, documentation, and controls, while other regulatory frameworks introduce their own requirements related to logging, human oversight, impact assessment, and monitoring.

    For insurers operating across multiple jurisdictions, the challenge is demonstrating that governance is functioning across an increasingly complex AI environment, not just that a policy exists on paper. Building separate manual processes for every model, application, regulatory requirement, and examination creates an operational burden that eventually slows AI deployment rather than enabling it.

    Regulation makes the need for this kind of infrastructure explicit, but it is not the only reason to build it. If AI is going to participate in consequential business processes, insurers need a reliable way to control those systems and understand their behavior regardless of what any single regulator requires. Regulatory evidence should be a natural output of that infrastructure, rather than the sole reason for building it in the first place.

    The Infrastructure Around the Model

    The developments at AIG, Travelers, Allianz, and Verisk illustrate different dimensions of the same shift. Travelers shows the scale enterprise AI adoption can reach within a single organization. AIG shows what happens when AI enters a core underwriting workflow. Allianz is moving toward agentic claims processes. Verisk is connecting AI directly to the specialized data that insurance decisions depend on. Taken individually, each is a data point about one company's AI strategy. Taken together, they describe an industry where AI is becoming a layer that sits between employees, applications, proprietary data, and the business processes insurers run every day.

    The models themselves are only one part of that architecture. Insurers also need infrastructure that can see what is operating across the environment, apply organizational policy consistently, control what those systems are permitted to do, and preserve evidence of what happened. That is the role of a runtime AI control plane. Trussed is building that control layer for enterprises operating AI in regulated environments, sitting between applications and models so governance policies can be enforced at the point of interaction, across different models, providers, and use cases. The same layer provides the live inventory and audit evidence insurers need to understand how AI is actually operating across their organization.

    The significance of AI becoming insurance operating infrastructure is not that insurers will run their businesses on a single foundation model. It is that models from multiple providers will increasingly participate in the systems through which underwriting, claims, risk, technology, and other insurance functions operate. As that happens, it becomes less viable to govern AI through processes that sit outside the technology itself. Insurance AI will need a control layer that operates continuously across the environment. That is the infrastructure insurers need to build alongside the models and applications they are already deploying today.

    Sources:

  1. AIG / Anthropic: Claude for Financial Services
  2. Travelers / Anthropic: Business Wire via Yahoo Finance
  3. Allianz / Anthropic: Allianz Newsroom, Mobile World Live
  4. Verisk / Anthropic: Anthropic, Agents for Financial Services, Verisk Newsroom