Prompted LinesAI guidance for insurance

Strategy ยท Leaders & policy owners ยท ~13 min

Governance and regulation

Set accountability, approve data use, and define the evidence required before a pilot expands. Includes an insurance regulatory overview, a 90-day action plan, and a policy template to adapt with Legal and Compliance.

Leadership decision

Name an accountable executive, approve the tools and data each pilot may use, and agree who can stop it. Require an owner, an evaluation record, and an escalation path before expanding access or authority.

The regulatory and risk landscape

Requirements depend on the entity, jurisdiction, line of business, and use of the output. Have Legal/Compliance map those requirements to each use case. The policy below is a starting point for that work.

  • NAIC Model Bulletin: describes state supervisory expectations for a written AI Systems Program, proportionate controls, and documentation available for examination. The August 6, 2026 adoption map lists 24 states plus D.C.; state bulletins and other state guidance must be checked individually.
  • NAIC AI Systems Evaluation Tool: the pilot plan covers twelve states from March through September 2026. It is an examination initiative, not a new nationwide AI law.
  • Existing insurance law still applies. The bulletin ties AI oversight to applicable insurance laws, including unfair trade and claims practices. Using a vendor does not transfer the insurer's accountability.
  • Colorado: amended Regulation 10-1-1, effective October 15, 2025, covers specified external-data governance for life, private passenger auto, and health benefit plan insurers. Its scope is not a universal standard for every line or state.
  • New York DFS Circular Letter 7 (2024): sets expectations for AI and external consumer data in underwriting and pricing, including actuarial validity, discrimination testing, governance, and disclosure. Confirm applicability before using those systems.
  • NIST AI Risk Management Framework: a voluntary framework for organizing risk management. Its Generative AI Profile adds risks specific to generative systems. Following a framework does not itself establish legal compliance.
  • EU AI Act: assess territorial scope, including where system outputs are used. The Commission timeline places Annex III high-risk rules at December 2, 2027 and Annex I regulated-product rules at August 2, 2028; other obligations already apply. These are different categories, not two deadlines applying to all insurance underwriting. See the regulation timeline.

Five risks to assess

Illustrative control design

Five controls with one clear escalation route

Assess these layers together around each workflow. They address different risks; passing one check does not replace the others.

  • ConfidentialityLimit the dataApproved tool and data pairing, need-to-know access, and appropriate retention.
  • AccuracyCheck the evidenceTrace material facts to sources, reconcile figures, and surface unresolved gaps.
  • Unfair discriminationEvaluate the outcomeTest the intended decision use and keep an accountable human review route.
  • Vendor riskReview the supplierKnow the AI features, data access, change process, and support commitments.
  • Over-relianceMaintain effective oversightGive reviewers evidence, time, authority to challenge, and a way to report missed errors.
Human authority remains explicit: who can accept the output, approve the consequential action, or stop the workflow?

Worked example: an outbound draft contains claimant information that the recipient is not approved to receive. If the check detects it, hold the draft, notify the owner, correct the disclosure, and recheck before sending.

Illustrative operating controls for the risks discussed above. Apply the company policy and the requirements identified for the specific use case.

Questions leaders should be asking

Use these in management meetings to check whether the program is operating as intended:

  1. Do we have a written AI governance policy and an inventory of where AI (including vendor-embedded AI) is used today?
  2. Do employees have a sanctioned, enterprise-grade AI tool, and a clear rule about consumer tools?
  3. For each use case: what is the human review step, and who is accountable for the output?
  4. How would we answer a market conduct exam question about AI in underwriting or claims, today?
  5. Which vendors have added AI features to products we already license, and what data do they see?
  6. What is our measurement plan: are we tracking time saved, error rates, and adoption, or just launching pilots?
  7. Who owns AI governance? (Common answer: a small cross-functional group of data science, legal/compliance, IT security, and a business sponsor.)

A pragmatic 90-day posture

  1. Weeks 1โ€“4: name the accountable executive; adopt an interim acceptable-use policy (template below); approve tools, permitted data, training terms, and retention settings; brief staff before access.
  2. Weeks 4โ€“8: complete the governance group and AI inventory, including vendor tools; select 2โ€“3 pilots with named owners, baselines, quality thresholds, and spending limits.
  3. Weeks 8โ€“13: run pilots with human-in-the-loop review; measure; report results and a scale/kill decision to the executive team.

Suggested sequence ยท weeks from start

A proposed 13-week plan (about 90 days)

Proposed work windows in elapsed weeks from programme start. Bar lengths follow the week scale. The final gate is a decision to scale or stop after the pilots.

Start to week 4Set the ground rules

Accountable executive, interim policy, approved access, and a staff briefing.

Weeks 4โ€“8Organize and select pilots

Governance group, AI inventory, and pilot selection.

Weeks 8โ€“13Run pilots and measure

Pilots with human review. Week 13: report results and a scale-or-stop decision to the executive team.

Keep controls proportionate to the use case. Give staff a practical approved route, make exceptions visible, and expand only when the pilot meets its quality and value thresholds. Pause a pilot when an incident or unresolved control gap makes continued use unacceptable.

For the multi-year strategic view (where the industry stands, what competitors have deployed, and a phased 36-month progression with governance gates and economics) see the companion AI integration phases.


Responsible-use policy template

Template

Bracketed items require company decisions and Legal/Compliance review before adoption. The tiers and prohibitions below are proposed company rules. This template does not replace the full AI Systems Program, system documentation, or jurisdiction-specific requirements.

1. Scope

These guidelines apply to all employees and contractors using: general-purpose AI assistants; AI features embedded in vendor software (including underwriting, claims, and productivity platforms); and internally built AI/LLM applications. Coordinate these guidelines with existing predictive-model governance; do not exclude a system from applicable AI requirements simply because it uses a traditional predictive model.

2. Sanctioned tools: the bright line

  1. Use only company-approved AI tools [list; e.g., enterprise instances under company agreements with no-training and retention terms].
  2. Never enter company, policyholder, claimant, broker, or employee information into personal or consumer AI accounts. This includes "just this once," and it includes screenshots.
  3. Requests for new tools or AI-enabled vendor features go to [AI governance group] before use.

3. Data rules

Data classSanctioned enterprise toolsConsumer / personal AI tools
Public informationโœ“ Allowed for approved workโœ— Not approved for company work
Internal, non-confidentialโœ“ Allowedโœ— Prohibited
Confidential businessApproved data/tool pairing only; need-to-know accessโœ— Prohibited
Policyholder / claimant PII, PHIโš  Approved use cases only; minimize and de-identify where feasibleโœ— Prohibited
Restricted (M&A, litigation)โœ— Requires specific approvalโœ— Prohibited

Tool approval is not blanket permission to use every data class. Confirm the approved use, configuration, and retention settings. Outputs derived from confidential inputs inherit the input's classification.

4. Human accountability

  1. You own what you ship. AI output that you send, file, or act on is your work product. Review it as you would a junior colleague's draft.
  2. Consequential decisions require human review. No AI output may, without documented human review, determine or effectively determine: risk selection or declination, pricing or rating, claim acceptance/denial or reserve values, coverage interpretations communicated externally, or personnel decisions.
  3. Verify facts, numbers, and citations. Any figure, quotation, legal or regulatory citation, or policy-language reference must be checked against the source before use.
  4. Disclosure: [company position; recommended minimum: disclose AI assistance within work products supporting actuarial opinions and regulatory filings; customer-facing disclosure per applicable state law].

5. Use-case risk tiers

TierExamplesRequirements
Low Drafting or summarizing low-sensitivity material; code assistance in an approved environment Pre-approved use and data; trained user; human review
Medium Submission triage, document extraction feeding a human decision, internal RAG knowledge tools Registered in AI inventory; named owner; accuracy and security evaluation before release; ongoing monitoring
High Anything materially influencing underwriting, pricing, or claims outcomes; anything customer-facing Full model-governance treatment: validation, bias testing, monitoring, documented human oversight, Legal/Compliance sign-off, exam-ready documentation
Prohibited Fully automated adverse decisions (declination, denial, non-renewal) without human review; AI-generated legal or regulatory positions without counsel review; data use violating ยง3 n/a

6. Governance structure

  • AI Governance Group: [named members; recommended: data science lead (chair), Legal/Compliance, IT Security, business-unit sponsor]. Owns this policy, the AI inventory, tool approvals, and tier classification.
  • AI inventory: a living register of every AI system in use (internal, vendor-embedded, and experimental) with owner, tier, data touched, and evaluation status. Keep the register available for management review and regulatory inquiries.
  • Vendor AI diligence: procurement and renewals must ask: Does this product use AI? On what data? Can it be disabled? What are the provider's training and retention terms?
  • Incident handling: suspected disclosure, unauthorized action, or material error is reported to [channel] within [company reporting window]. The owner pauses affected use when needed, preserves evidence, and coordinates correction and required notifications.
  • Records: retain the evidence needed to reconstruct material decisions, including configurations, model versions, evaluations, and approvals, per [retention schedule]. Minimize sensitive prompt/output logging and restrict access.

7. Security notes

  • AI systems that read external documents (submissions, emails, claims correspondence) are exposed to prompt injection: adversarial instructions embedded in those documents. Such systems must be designed with least-privilege tool access and no unreviewed external actions; Medium tier minimum.
  • Report suspected AI-related phishing or deepfake contact (including voice or video impersonation of executives, brokers, or claimants) to IT Security immediately.

8. Training requirement

All staff complete [AI awareness briefing] before tool access; Medium/High-tier system owners complete [role-specific training]. Re-certification [annually]. Review cycle for this document: [quarterly] by the AI Governance Group.

Where this goes next

This is the last of the Strategy chapters. Everything above constrains the work; the Practice chapters describe how to do it. Hands-on use starts with a fictional exercise you can check before using company data. Its data rules are sections 2 and 3 of this template applied at the desk.