Prompted LinesAI guidance for insurance

Strategy · Leaders & policy owners · ~9 min

Governance and regulation

The regulatory landscape, the questions leadership should be asking, a pragmatic 90-day posture, and an adaptable responsible-use policy template.

The regulatory and risk landscape

Top risks to manage, in order

  1. Confidentiality: employees pasting policyholder or company data into consumer AI tools. Solved with enterprise agreements plus policy; fix this first.
  2. Accuracy / hallucination in outputs that reach customers, regulators, or decisions.
  3. Unfair discrimination / bias if AI touches risk selection or pricing.
  4. Vendor risk: AI is arriving embedded in software insurers already buy; know where.
  5. Over-reliance: staff accepting AI output without review ("automation bias").

Questions leaders should be asking

Use these in management meetings; they map to what examiners will ask:

  1. Do we have a written AI governance policy and an inventory of where AI (including vendor-embedded AI) is used today?
  2. Do employees have a sanctioned, enterprise-grade AI tool, and a clear rule about consumer tools?
  3. For each use case: what is the human review step, and who is accountable for the output?
  4. How would we answer a market conduct exam question about AI in underwriting or claims, today?
  5. Which vendors have added AI features to products we already license, and what data do they see?
  6. What is our measurement plan: are we tracking time saved, error rates, and adoption, or just launching pilots?
  7. Who owns AI governance? (Common answer: a small cross-functional group of data science, legal/compliance, IT security, and a business sponsor.)

A pragmatic 90-day posture

  1. Weeks 1–4: adopt an interim acceptable-use policy (template below); procure enterprise AI access with zero-data-retention / no-training terms; brief all staff.
  2. Weeks 4–8: stand up the governance group; inventory current AI use including vendor tools; select 2–3 pilot use cases with named owners and success metrics.
  3. Weeks 8–13: run pilots with human-in-the-loop review; measure; report results and a scale/kill decision to the executive team.

The goal is governed momentum: moving fast enough to learn, with guardrails proportionate to risk. The two failure modes are symmetric: banning AI (staff will use personal accounts invisibly, so-called "shadow AI") and ungoverned enthusiasm (which regulators are now actively examining for).

For the multi-year strategic view (where the industry stands, what competitors have deployed, and a phased 36-month progression with governance gates and economics) see the companion AI integration phases.


Responsible-use policy template

Template

This is a policy TEMPLATE. Bracketed items require company-specific decisions; have Legal/Compliance review it before formal adoption. Aligned with the NAIC Model Bulletin's expectations for a written AI Systems Program and the NIST AI Risk Management Framework.

1. Scope

These guidelines apply to all employees and contractors using: general-purpose AI assistants; AI features embedded in vendor software (including underwriting, claims, and productivity platforms); and internally built AI/LLM applications. Traditional predictive models remain governed by existing model-governance policy; where an AI system feeds a regulated decision, both policies apply.

2. Sanctioned tools: the bright line

  1. Use only company-approved AI tools [list; e.g., enterprise instances under company agreements with no-training and retention terms].
  2. Never enter company, policyholder, claimant, broker, or employee information into personal or consumer AI accounts. This includes "just this once," and it includes screenshots.
  3. Requests for new tools or AI-enabled vendor features go to [AI governance group] before use.

3. Data rules

Data classSanctioned enterprise toolsConsumer / personal AI tools
Public information✓ Allowed✓ Allowed
Internal, non-confidential✓ Allowed✗ Prohibited
Confidential business✓ Allowed with need-to-know✗ Prohibited
Policyholder / claimant PII, PHI⚠ Approved use cases only; minimize and de-identify where feasible✗ Prohibited
Restricted (M&A, litigation)✗ Requires specific approval✗ Prohibited

Outputs derived from confidential inputs inherit the input's classification.

4. Human accountability

  1. You own what you ship. AI output that you send, file, or act on is your work product. Review it as you would a junior colleague's draft.
  2. Consequential decisions require human review. No AI output may, without documented human review, determine or effectively determine: risk selection or declination, pricing or rating, claim acceptance/denial or reserve values, coverage interpretations communicated externally, or personnel decisions.
  3. Verify facts, numbers, and citations. Any figure, quotation, legal or regulatory citation, or policy-language reference must be checked against the source before use.
  4. Disclosure: [company position; recommended minimum: disclose AI assistance within work products supporting actuarial opinions and regulatory filings; customer-facing disclosure per applicable state law].

5. Use-case risk tiers

TierExamplesRequirements
Low Drafting, summarizing internal docs, code assistance, meeting notes Sanctioned tool + human review; no approval needed
Medium Submission triage, document extraction feeding a human decision, internal RAG knowledge tools Registered in AI inventory; defined owner; documented accuracy evaluation before and after deployment
High Anything materially influencing underwriting, pricing, or claims outcomes; anything customer-facing Full model-governance treatment: validation, bias testing, monitoring, documented human oversight, Legal/Compliance sign-off, exam-ready documentation
Prohibited Fully automated adverse decisions (declination, denial, non-renewal) without human review; AI-generated legal or regulatory positions without counsel review; data use violating §3 n/a

6. Governance structure

7. Security notes

8. Training requirement

All staff complete [AI awareness briefing] before tool access; Medium/High-tier system owners complete [role-specific training]. Re-certification [annually]. Review cycle for this document: [quarterly] by the AI Governance Group.

← Costs & value Hands-on use →