AI Won't Break Insurance. Lack of Governance Will.
I keep thinking about the gap between the conversations happening in insurance right now and the ones that probably should be.
The technology available to insurers today is genuinely remarkable: AI underwriting, real-time claims, predictive models that would have taken actuaries months to build now running in seconds. That's not the problem.
But there's something that tends to go unsaid when insurers, brokers, and regulators are all in the same room together: the thing standing between where this industry is now and where it wants to go isn't the technology. It's governance. And a lot of companies are about to learn that lesson the hard way.
The pilot era is over. Act like it.
For years, "AI in insurance" was a pilot program. Innovation-lab stuff. Demos that impressed the board but never made it into a live policy or a real claim decision. That's not 2026. AI is in production now, touching pricing, underwriting, fraud detection, claims adjudication, and marketing. The gap between "we're experimenting with this" and "this is how we operate" has closed faster than most organizations were ready for.
And that changes everything about what failure means. When AI breaks in a pilot, you write a lessons-learned document. When AI breaks in production, you increase your exposure to regulatory scrutiny.
Regulators are already preparing for this shift.
The NAIC's AI Systems Evaluation Tool is designed to supplement existing examination processes, and recent working group discussions signal growing focus on third-party models and data. The EU AI Act begins applying in August 2026, with additional obligations following in 2027. These aren't distant timelines. They're already on the calendar.
"We outsourced it" stopped working as an answer.
This is the part brokers and insurers alike need to sit with.
Regulators have been clear: you don't get to outsource accountability along with the work.
If your pricing model came from a vendor, you own what it does. If your claims AI introduces bias, you own the outcome. If your data pipeline came through an acquisition and no one fully understands it anymore, that's your problem, not a footnote.
The push toward greater transparency around third-party models isn't just paperwork. It reflects how regulators see responsibility: end-to-end, regardless of where the technology originated. Insurers that can't explain what they're using, where it came from, and how it's governed aren't just disorganized; they're exposed.
Brokers aren't off the hook either. If a decision affects a consumer and technology played a role, accountability doesn't disappear because a vendor was involved.
Here's what people keep getting wrong about governance.
The word gets used as if it means slowing down, like it's the compliance tax you pay for getting to use interesting technology. It's the opposite. Governance is what lets you scale.
Think about what "no governance" looks like in practice. You can't automate underwriting at speed if you don't have model validation, because you won't know when the model is drifting until something goes wrong. You can't process claims with AI if you don't have audit trails, because the first time a regulator asks you to explain a decision, you'll be rebuilding the logic from scratch. You can't expand into new risk segments if you don't have data lineage, because your assumptions are only as good as the data they were built on, and data goes stale.
Every bit of speed you gain without controls creates an equivalent amount of risk. The insurers that will actually win aren't the fastest movers. They'll be the ones that move fast and can prove it was intentional.
What regulators are actually asking for
I want to say something that doesn't always get said at industry conferences: regulators are not the enemy of innovation.
They understand the technology. They've been watching AI deployments closely. Increasingly, they understand concepts like drift, proxy variables, and model risk.
What they're trying to prevent is a pattern they've seen before: the industry adopts something powerful, deploys it widely, and only reacts after something predictable goes wrong.
Explainability isn't about auditing every model weight, it's about being able to explain outcomes to consumers. Third-party documentation isn't bureaucracy, it's resilience when vendors fail. Bias testing isn't optional, because discrimination at AI speed is still discrimination.
The NAIC's approach reflects this. For example, the AI Systems Evaluation Tool is designed to extend existing oversight, not replace it. None of that is unreasonable. And none of it is as hard as it sounds if governance is built in from the start rather than bolted on later.
The question worth sitting with
There's no shortage of conversations in insurance right now about opportunity: new risk pools, new distribution plays, new revenue. But the question I keep coming back to is simpler: Can you actually scale what you're building? Not technically. Governably.
The insurers that can say yes, the ones with model lineage, vendor accountability, explainable outputs, and bias controls, are going to earn something valuable: trust.
From regulators, from brokers, and from customers. And trust is what durable growth is built on. Everyone else is going to spend the next few years in remediation. The question isn't whether you're using AI. It's whether you can defend it.
If you're thinking through any of this, I'd love to connect.