The conversation around artificial intelligence in insurance has moved beyond whether and when to adopt it. The harder question now is whether firms can prove to regulators that their AI actually produces good customer outcomes.
Tim Hardcastle, chief executive and co-founder of INSTANDA, said the FCA's positioning has changed the narrative. "That's a much harder question to answer because firms have to show evidence the AI they're using produces good outcomes." He sees the FCA's direction as complementary to the EU AI Act, with both focused on transparency, auditability and delivering good customer outcomes.
Governance shapes adoption speed and risk
Hardcastle said smaller brokers and MGAs are adopting AI faster than tier-one insurers because they have less governance to navigate. That speed creates an advantage, but also a different risk profile. A cyber incident at a smaller MGA may attract less attention than the same event at a household-name insurer, but lighter governance and limited security resources can leave smaller firms more exposed.
Governance cannot simply mean slowing everything down, Hardcastle said. When businesses are encouraged to explore AI but not given clear guidance on approved tools, unauthorised "shadow" AI tools emerge. Many firms are responding by introducing approved AI tools, localising data so confidential information does not feed external training models, and strengthening security around AI deployments rather than trying to secure the models themselves. "Not impossible, but very, very difficult," he said.
He pointed to the Bank of England deputy governor's proposal for an AI "kill switch" that would disconnect systems automatically if suspicious behaviour was detected. Anthropic's disclosure that state-sponsored actors manipulated Claude Code as part of a cyber-espionage campaign illustrates why such safeguards matter.
Where AI fits across the insurance value chain
Data ingestion - turning unstructured broker information such as emails, drawings and photographs into usable data - is where Hardcastle sees the highest adoption. Insurers regard it as comparatively low risk provided governance catches hallucinations or misinformation.
Pricing is a different proposition, particularly in personal lines. Traditional rating models can be audited and justified to regulators because their logic is transparent. Current AI models do not offer the same explainability. "I don't believe that we will see AI being used for pricing anytime soon," Hardcastle said, though AI could help refine pricing models by identifying additional rating factors through pattern analysis.
In commercial lines, AI acts as an assistant to underwriters, automating information requests and support, "but it doesn't make your decision." Claims is following a similar path - AI agents handle first notification of loss and routine tasks, but should not decide independently whether to pay a claim. Hardcastle said there must be human involvement in any step of the decision making process.
For professionals who want to understand how these governance and strategy questions apply to their own AI for Insurance implementation, the distinction between operational use and decision-making authority is central to regulatory compliance.
Good data before good AI
Poor-quality or inconsistent information produces the same flawed conclusions in generative AI as it did in traditional machine learning. Hardcastle compares the effect to the Leaning Tower of Pisa. "If your foundations are slightly off and then you rapidly build something, it ends up skewing." Clients across INSTANDA's global customer base consistently report that data, workflows and processes need to work well before AI is layered on top.
MIT's 2025 State of AI in Business report found that 95% of enterprise AI pilots fail to reach production. Hardcastle believes that reflects firms still testing how predictable the technology really is before trusting it with business-critical decisions.
The industry's most important distinction, he said, is being AI-enabled rather than AI-led. "Being AI led puts you in a position where you will ultimately not be able to stand in front of a regulator and say this is how the decisions were made, because the AI effectively would be making the decisions." He does not believe that approach is compatible with insurance's obligations around fairness, transparency and consumer protection. The same principle applies to technology vendors. "The community of technology vendors supporting [insurers] all have to be AI-enabled for the industry to work within the regulatory framework."
Those strategic decisions about AI governance and vendor selection are where AI for Executives & Strategy training can help insurance leaders build frameworks that satisfy both competitive pressure and regulatory scrutiny.
Why this matters for insurance professionals
The regulatory window for "experiment first, explain later" is closing. Every underwriter, claims handler and pricing actuary who uses AI tools - or whose vendor uses them - now carries a share of the burden to document how decisions are made. The practical takeaway is simple: audit your data pipelines before adding AI, keep humans in any decision that affects a customer's coverage or payout, and have a clear answer ready for what you would tell a regulator if they asked why your AI did what it did.
Your membership also unlocks: