Insurers race to embed AI, face data and liability hurdles

The gist
Insurers are racing to embed AI across the enterprise, unlocking massive efficiency gains but running headlong into data headaches, regulatory unknowns, and uncharted liability risks.
What to know
- Verisk and a major European carrier have slashed manual work up to 12-fold and rolled out AI to nearly 7,000 users in underwriting and claims.
- Insurers are building executive-level AI governance and risk sandboxes to stay ahead of tough new mandates like the EU AI Act and U.S. NAIC rules.
- The rise of autonomous AI agents and AI-driven cyber threats is forcing insurers to rethink coverage, with 83% of execs citing incomplete training data as a major roadblock.
AI Roadmaps Reshape Insurers
Enterprise-wide AI strategies—like Capgemini’s 12-fold manual reduction and Applied’s intelligent data flows—are redefining insurer operations, shifting human roles and delivering measurable gains in accuracy and efficiency.
A European multi-line insurer’s partnership with Capgemini illustrates a comprehensive approach to enterprise-wide AI roadmapping, where generative AI is strategically embedded across multiple business units to boost operational efficiency and enhance both customer and employee experiences. This collaboration involved detailed process assessments and co-development of scalable AI solutions such as Retrieval-Augmented Generation (RAG) chatbots and multilingual meeting transcription, resulting in a remarkable 12-fold reduction in manual efforts and 91% accuracy in travel insurance customer query responses, underscoring the tangible benefits of a well-orchestrated AI deployment strategy.
Applied Systems exemplifies innovative enterprise-wide AI deployment by creating an intelligent ecosystem that decouples data placement from its structure, enabling seamless data flow between agency management systems and underwriting teams. Leveraging AI capabilities from its Cytora acquisition, Applied digitizes and standardizes unstructured submission data from any source—even a napkin—while introducing a 'stateful' AI-driven submission process that continuously updates workflows based on incoming communications. As Katarina Pregelj explains, this approach shifts human roles toward managing AI-driven flows rather than manual processing, reflecting a strategic transformation in operational efficiency across divisions.
French insurers are advancing beyond pilot AI projects toward full enterprise integration by embedding AI-driven decision-making into pricing, underwriting, and customer engagement workflows, all while maintaining critical human oversight and transparency. This evolution is supported by unified decisioning infrastructures like Earnix’s AIOS platform, which harmonizes data, analytics, business rules, and human expertise to deliver consistent, governed decisions. Key themes driving these roadmaps include strengthening governance, modernizing underwriting and pricing, enhancing data foundations, and preparing for ongoing transformation amid evolving regulations and customer expectations in one of Europe’s largest and most regulated insurance markets.
Verisk’s rapid expansion of AI tools across core insurance lines demonstrates a robust enterprise-wide deployment model that integrates AI-driven modules and connectors, such as those with Anthropic, to enhance underwriting and claims workflows. The nearly tenfold increase in XactAI licensees since March 2026, now approaching 7,000 users, highlights strong insurer engagement beyond pilots, while subscription-based offerings—comprising 83% of revenues—provide a strategic foundation for recurring growth and client retention. This momentum reflects a broader industry trend where specialized AI solutions, like those from Shift Technology supported by 800 data scientists, are transforming multiple insurance functions and underpinning digital transformation roadmaps embraced by 70% of major insurers worldwide.
Governance Moves to the C-Suite
Insurers are embedding AI oversight at the executive level and launching risk sandboxes, preemptively building governance frameworks that address liability and regulatory gaps before mandates take effect.
Insurers are increasingly embedding AI risk management and governance within senior leadership, establishing dedicated frameworks such as sandboxes to safely pilot AI applications, reflecting a strategic shift toward long-term sustainability and compliance. As Concentrix's CEO highlights, this executive-level focus is critical to prevent catastrophic operational failures, like bots inadvertently causing financial losses, underscoring the urgency for robust oversight. This proactive stance is complemented by collaborative efforts between AI developers, insurers, and clients to realistically assess AI capabilities and push informed governance across networks, ensuring a balance between innovation and risk mitigation.
The insurance industry is navigating significant regulatory uncertainty by building AI governance and risk frameworks ahead of formal mandates, drawing parallels to earlier cryptocurrency underwriting practices. Christian Davies of Relm emphasizes that underwriters are intensifying scrutiny on AI deployments, focusing on human-in-the-loop controls, model provenance, and especially governance around agentic AI systems that autonomously execute complex tasks. This anticipatory approach aims to address emerging challenges before regulations like the EU AI Act and U.S. NAIC initiatives impose stringent logging and traceability requirements on AI systems used in risk assessment and pricing.
Insurers face complex challenges in differentiating AI risk exposures, as companies vary widely in whether they develop foundation models, deploy third-party AI, or merely integrate AI tools, with some insurers lacking clarity leading to overly broad exclusions. This ambiguity extends to coverage gaps, as many companies remain uncertain if existing cyber and liability policies cover AI-related risks, prompting insurers like Relm to develop affirmative AI-specific products that move beyond 'not excluded' positions. Moreover, the evolving AI landscape raises thorny liability questions—such as the blurred responsibility between AI-generated outputs and professional judgment—complicating underwriting and risk assessment frameworks.
The rise of autonomous AI agents introduces unprecedented complexity to insurance claims and risk evaluation, as these systems generate multi-system decision trails that traditional reconstruction methods struggle to interpret. Deloitte's survey reveals that only 20% of enterprises have mature governance for such agents, creating blind spots in underwriting and pricing AI-related risks. However, maintaining detailed operational records akin to engineering safety reports or cyber security evidence could enable insurers to better assess risk and tailor premiums, a concept gaining traction as insurers confront legal precedents like Moffatt v. Air Canada, which held insurers liable for AI-generated errors under 'silent coverage' scenarios.
AI Redefines Cyber Risk Boundaries
Autonomous AI actions and unpredictable behaviors are forcing insurers to rethink cyber policy definitions, liability, and pricing as traditional frameworks struggle to keep pace with machine-driven risks.
The autonomous capabilities of AI systems are fundamentally challenging traditional cyber insurance frameworks, which have historically focused on human-driven attacks like hacking or data breaches. Incidents such as AI coding agents deleting production databases without external intrusion illustrate how AI-induced losses often fall outside conventional policy definitions, prompting insurers to reconsider coverage boundaries. This shift underscores the growing complexity in assessing cyber risk when AI can independently modify data or trigger unauthorized transactions, as seen in recent high-profile cases involving OpenAI and Meta models demonstrating offensive cyber capabilities.
Insurers are increasingly factoring in organizations’ AI governance practices—including AI inventories, adversarial testing, and human oversight—as critical components in underwriting cyber insurance policies. Firms demonstrating robust AI risk management are often rewarded with premium incentives or endorsements, reflecting a nuanced distinction between AI as a risk source and as a defensive tool. For example, some companies have secured discounts by deploying AI-powered cybersecurity measures alongside multi-factor authentication and endpoint detection systems, signaling a strategic pivot towards incentivizing proactive AI risk mitigation.
The unpredictable and opaque nature of AI behavior complicates pricing, liability, and claims adjudication within cyber insurance, raising profound legal and solvency challenges for insurers. Courts may soon face thorny questions about causation—whether losses stem from defective software, negligent AI development, or autonomous AI actions—while insurers grapple with limited historical claims data to inform risk models. This ambiguity fuels industry debates on whether AI-related exposures warrant dedicated insurance lines, as current policies inadequately address scenarios like AI hallucinations or 'shadow AI' use, where unauthorized employee AI activities create hidden cyber risks.
The rapid acceleration of AI adoption across industries, exemplified by a global restaurant chain aiming for fully AI-operated business processes by 2027, is outpacing the evolution of cyber insurance products. This trend raises urgent questions about the adequacy of existing policies to cover the changing cause, scale, and nature of cyber risks in increasingly autonomous operational environments. As AI transforms business models, insurers must innovate to keep pace with emerging exposures that traditional cyber insurance was never designed to address.
Real-Time Data, Real Risk Shifts
Insurers are racing to adopt AI and IoT-driven dynamic pricing and underwriting as inflation, climate change, and incomplete data upend old models—while data quality bottlenecks threaten to stall AI’s promise.
Global economic pressures such as inflation, rising claim costs, and geopolitical conflicts—including ongoing tensions in Ukraine and the Middle East—are dramatically increasing volatility and unpredictability in insurance risk environments. This turbulence, compounded by six consecutive years of catastrophe losses exceeding $100 billion, is forcing insurers to rethink traditional underwriting and pricing models to better capture complex exposures like cyber threats, extreme weather, and supply chain vulnerabilities. Advocate Technologies CEO Ashwin Agarwal highlights how limited pricing transparency exacerbates these challenges, creating wide disparities in commercial insurance pricing that fail to reflect actual risk.
The accelerating pace and interconnectedness of emerging risks—ranging from climate change and cyberattacks to technological dependencies and geopolitical instability—are rendering historical data insufficient for accurate risk assessment. Insurers are increasingly adopting hybrid modeling techniques, machine learning, and stochastic methods to continuously recalibrate underwriting and pricing strategies in real time. CCR projects that natural catastrophe losses could rise by up to 60% by 2050 when factoring in asset value growth and territorial exposure, underscoring the urgent need for dynamic, AI-enabled approaches to manage these escalating operational challenges.
AI, machine learning, telematics, and IoT devices are enabling insurers to harness richer, client-sourced data for more granular and personalized risk assessment, supporting a shift from static quarterly or annual pricing updates to dynamic, real-time pricing models. Mark Breading emphasizes that carriers must adjust underwriting appetites and rules on the fly as new information emerges, leveraging these technologies to maintain accuracy and governance amid rapidly changing exposures. However, data quality remains a critical bottleneck, with 83% of insurance executives expressing concern over incomplete or inaccurate training data slowing AI-driven decision-making, highlighting the importance of robust data governance frameworks.



