Artificial intelligence in the insurance sector: navigating an evolving supervisory landscape

AI is reshaping the insurance sector, prompting regulators and supervisors to focus on fair and explainable outcomes. Insurers must strengthen governance, manage bias, and demonstrate clear accountability to meet rising global expectations.

Artificial Intelligence (AI) is becoming embedded across the insurance value chain, from underwriting and pricing to claims handling, fraud detection and customer service. As a result, the regulatory question for insurers is no longer whether AI should be used, but how firms can demonstrate that it delivers fair and appropriate outcomes for customers.

In the UK, the FCA is not introducing a standalone AI rulebook. Instead, it is using its existing conduct and consumer protection framework to supervise how firms use AI in practice. This matters for insurers because AI-driven decisions can affect whether a customer is offered cover, the price they pay, how a claim is assessed, and how they are treated through the product lifecycle.

For UK insurers, this creates a clear shift in supervisory focus. AI is not just a technology or innovation topic. It is becoming a conduct, governance and accountability issue. Firms will need to show that AI use is explainable, appropriately controlled, and supported by evidence rather than high-level assurances.

This article looks at the FCA’s developing approach to AI supervision, how it compares with the more prescriptive EU regime and the more fragmented US approach, and what this means for international insurers operating across different regulatory frameworks.

Why AI raises challenges for insurers

Insurance is inherently data-driven, and AI offers clear benefits: it enables more refined risk selection, improved pricing accuracy, faster claims processing and more efficient operations. However, these same capabilities can amplify regulatory concerns, particularly where AI influences customer outcomes. As AI becomes more advanced, some risks will reduce but others will increase.

Past examples of bias in predictive healthcare algorithms in the US illustrate how AI systems can produce discriminatory outcomes when underlying data, assumptions or proxies are not properly understood and controlled[1]. While it is difficult to compare this directly with insurance, AI remains capable of amplifying biases that have not been surfaced, resulting in unintended discrimination.

AI-driven decisions in insurance often have direct consequences for customers. They can affect whether a consumer is offered cover, the premium they pay, how claims are assessed and how they are serviced. This makes the technology highly relevant to core regulatory priorities such as fair value, consumer understanding and the treatment of vulnerable customers.

It also raises questions around cyber security, operational resilience and outsourcing, particularly where insurers rely on third-party AI tools or providers to support regulated activities. UK regulators have also warned that current frontier AI models may increase the sophistication and scale of cyber threats[2]. This reinforces the need for insurers to retain effective oversight and clear accountability. 

A key challenge for insurance firms is understanding and meeting the regulators’ developing expectations, especially when there are differing cross-border requirements that may apply.

AI has the potential to enhance decision-making, but it can also scale bias and opacity if not properly governed. Strong AI governance is not about limiting innovation – it is what enables firms to innovate with confidence and regulatory credibility.

Jessie Jones Director - Risk and Regulatory Consulting

Responsibility for the regulation of AI

One reason AI regulation has developed unevenly is that responsibility for oversight does not sit neatly with a single regulator.

Traditionally insurance supervisors have not been responsible for the wider oversight of technology, including AI or model providers. For example, the UK Financial Conduct Authority (FCA) applies its existing frameworks to supervise insurers’ reliance on third parties and chains of accountability between firms, senior managers, technology providers and model developers. However, these frameworks were not originally designed with AI in mind. This creates challenges in ensuring clear accountability for outcomes, especially where harm to customers arises.

This issue is particularly important from a conduct and consumer protection perspective. AI systems can directly influence customers outcomes, for example, through pricing or fraud detection. Without effective oversight, there is a risk that these systems could lead to unfair discrimination, reduced transparency, or poor customer treatment, particularly for vulnerable customers.

AI oversight is therefore dispersed across multiple regulators, with no single authority responsible end‑to‑end for insurance AI. As a result of this gap, the UK Parliament warned regulators of exposing the public and the financial system to potentially serious harm due to their positions on AI in January 2026[3].

The UK supervisory approach: a principles-based framework

As mentioned, the UK FCA relies on its existing regulatory frameworks, such as those for consumer protection, accountability and governance, as part of its principles-based approach.

For insurers, the supervisory approach creates both opportunity and challenge. While avoiding prescriptive regulation supports innovation, it also places greater responsibility on firms to interpret regulatory expectations and evidence compliance.

Whilst the FCA has not proposed specific rules for AI, it has provided guidance on how its existing frameworks can be mapped to the Government’s key principles for the regulation of AI:

1.       Safety, security, robustness

2.       Appropriate transparency and explainability

3.       Fairness

4.       Accountability and governance

5.       Contestability and redress.

The FCA’s stance reflects the UK Government’s broader “pro-innovation” approach, which emphasises flexibility and relies on sector regulators to interpret and apply overarching principles.

The FCA has supported firms with the testing of AI. It has brought together experts and sought input through information gathering exercises. For example, the ‘Mills Review’ was launched in January 2026 to consider how AI will reshape retail financial services for consumers, firms, markets and regulators. This included how risks and opportunities are emerging in practice and how existing frameworks should apply as deployment scales. Findings and recommendations were presented to the FCA Board and published externally in July 2026. The FCA reviewed how AI is shaping financial services, including how risks and opportunities are emerging in practice and how existing frameworks should apply as deployment scales. As AI evolves, regulation, supervision and industry practices are maturing in parallel, and firms that embed adaptive AI governance into how decisions are designed, tested and owned will be best positioned to differentiate.

Alongside financial regulation, data protection requirements continue to play a central role. The Information Commissioners Office (ICO) has emphasised fairness, transparency and accountability in the use of AI, particularly where personal data is processed to support decision-making.

While the FCA’s approach is principles-based, other jurisdictions are taking more prescriptive routes. For international insurers, these regimes should be understood as complementary pressures reinforcing the same core outcomes, but also not as identical legal frameworks.

Sarah Ouarbya

The FCA’s approach makes clear that firms cannot rely on the complexity of AI as a shield; they must be able to explain and stand behind the decisions it produces. In a principles-based regime, the burden shifts to firms to interpret expectations and demonstrate outcomes, not just intent.

Sarah Ouarbya Partner - Risk and Regulatory Consulting

The European contrast: a more prescriptive regime

Building on the UK’s supervisor-led, principles-based approach to AI in insurance, the EU has taken a more formal and prescriptive approach with the introduction of the AI Act, which applies from 2024. The Act adopts a risk-based classification of AI systems, and strongly supports consumer protection by safeguarding rights, fairness, and transparency.

Under this framework, certain AI applications in life and health insurance, particularly those used in pricing and underwriting, are classified as “high-risk”.

High-risk systems are subject to detailed requirements, including:

  • Data quality and bias controls
  • Comprehensive documentation and record-keeping
  • Human oversight mechanisms
  • Ongoing monitoring and risk management

Since the introduction of the EU AI Act, the EU’s Digital Omnibus has refined the Act by easing compliance burdens and delayed key requirements, giving firms more time to prepare whilst maintaining the overall regulatory direction. High-risk AI obligations have been pushed to December 2027 for standalone high-risk systems and August 2028 for high-risk AI systems embedded in regulated products, subject to the Omnibus taking legal effect through formal adoption and publication.

The AI Act places requirements on providers of AI systems, as well as the users, which may prove beneficial for EU based insurers in ensuring compliance when using third party tools. However, users continue to have specific obligations under the Act. Where AI solutions are sourced from third-party providers, insurers remain fully accountable for regulatory compliance. This creates challenges where proprietary models limit transparency, requiring firms to establish appropriate due diligence, contractual safeguards and ongoing monitoring.

While AI offers significant benefits for financial institutions, such as improved efficiency, risk management, and customer outcomes, it also introduces material risks, particularly around model risk data quality, cyber threats, and third-party dependencies. The FSB published in June 2026 a consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). While the report does not create binding requirements, it sets out 12 sound practices covering both organisation-wide governance (including board accountability, clear roles, and integration into risk frameworks) and AI lifecycle management (from design and data governance to testing, monitoring, and human oversight). A key principle is that AI risks should be managed proportionately to their materiality, with stronger controls for critical use cases and continuous monitoring as models evolve. 

This fragmented approach means that insurers operating in both the UK and EU must navigate two different but overlapping frameworks. While the UK emphasises principles and outcomes, the EU introduces more formal compliance obligations tied to risk classification.

EIOPA has published an opinion last year (Opinion on AI governance and risk management) clarifying how existing insurance regulation, including Solvency II and the Insurance Distribution Directive, should be applied to the use of AI systems. Rather than creating a separate AI regime, this guidance reinforces the expectations for management of AI-related risks. For example; bias, model opacity, and reliance on third-party providers.

These should be managed within established governance, risk management and conduct frameworks. In particular, insurers are expected to ensure that AI supports fair customer outcomes, robust controls and clear accountability across the AI lifecycle, consistent with existing prudential and conduct requirements. EIOPA’s Opinion clarifies how these existing frameworks apply to AI in insurance, following a risk‑based and proportionate approach, without introducing a separate AI regime.

Overall, while EU supervisors retain an important role in interpretation and enforcement, their approach is more tightly anchored in codified requirements than in the UK, highlighting a shift from supervisory discretion toward rule-driven oversight.

To better understand the impacts of the act for the financial sector, including an update on the changes introduced by the Digital Omnibus, read our article: AI in the EU financial sector, balancing regulation and innovation.

The US direction of travel: governance and fairness

In contrast to the principles‑based approach relying on existing regulatory frameworks, and the EU’s harmonised rulebook, the US approach to AI in insurance reflects a fragmented, state-led supervisory landscape, where regulatory expectations are shaped through a combination of model laws, guidance, and enforcement activity.

The National Association of Insurance Commissioners’ (NAIC) model bulletin on AI use by insurers, published in 2023[4], has been adopted by multiple states and sets out expectations for governance, transparency and fairness. It is principles-based and must be implemented by individual states, resulting in varying levels of adoption and consistency. 

The bulletin emphasises that insurers remain responsible for compliance with existing laws, including those prohibiting unfair trade practices and discrimination. It also recommends the implementation of a formal AI governance programme, including testing, validation, documentation and oversight by senior management.

Although less centralised than the EU regime, US expectations reinforce similar themes to FCA supervision, particularly around accountability, governance and fair outcomes, but through a more fragmented and enforcement-driven model.

This results in a supervisory approach that, compared with the UK, is defined by evolving supervisory practice across states rather than a single, articulated regulatory framework, reinforcing the importance of regulator-specific engagement and interpretation.

At the same time, the direction of travel remains uncertain, with growing tension between state-led regulation and emerging federal initiatives aimed at shaping a lighter, nationally consistent AI framework. This creates a dynamic regulatory environment, where insurers must manage fragmentation and the risk of future regulatory realignment.

Miglena Gavrilova

While regulatory approaches differ across the UK, EU and US, expectations are converging around fairness, transparency and accountability. For international insurers, the challenge is not just compliance but navigating overlapping regimes that take fundamentally different approaches to AI oversight.

Miglena Gavrilova Senior Manager

What this means for insurers in practice


For insurers, the practical challenge is to move from high-level AI principles to evidence-based governance. This means maintaining a clear inventory of AI use cases, assessing materiality and customer impact, assigning ownership across the model lifecycle, and documenting how risks such as bias, explainability, data quality, cyber resilience and third-party dependency are identified and controlled. Boards and senior management should expect AI governance to become part of mainstream risk management, rather than a separate innovation workstream. This is particularly important for cross-border groups, where UK, EU and US expectations differ in form but increasingly converge around fairness, accountability, transparency and demonstrable customer outcomes.

Common expectations

While these approaches differ in how supervision is exercised, from judgement-led in the UK to more compliance-driven in the EU and decentralised enforcement in the US, they reflect a growing alignment on core expectations, despite structural differences in regulation and enforcement.

Developments across the UK, EU and US highlight a global trend towards stronger governance, greater transparency and a growing focus on conduct, with regulators emphasising fairness, accountability and demonstrable consumer outcomes where AI influences customer decisions.

Across jurisdictions, a broadly consistent set of expectations is emerging:

  • AI must deliver fair and appropriate customer outcomes (including privacy and the protection of personal data)
  • Firms must be able to explain and justify decisions
  • Governance and accountability must be clearly defined
  • Bias and discrimination risks must be actively managed
  • Third-party dependencies must be understood and controlled
  • Data, model performance, monitoring and human oversight must be proportionate to the materiality and risk of the use case.

AI is increasingly treated by supervisors as a conduct and accountability issue, requiring firms to demonstrate that AI-driven decisions deliver fair and appropriate customer outcomes in practice, rather than relying on high-level governance alone.

For insurers, the challenge is not only to comply with evolving expectations, but to evidence outcomes and accountability while building governance frameworks that support innovation in a controlled and sustainable way. 

Read more on AI supervision with our other article: Scaling AI in Banking: Diverging Regulatory Capacity and Control Models in the US and Europe.

Follow also our AI Impact Hub - Forvis Mazars for thought leadership, expert perspectives and real-world insights.

Sources

[1] Healthcare algorithm used across America has dramatic racial biases | Health | The Guardian

[2] FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience | FCA

[3] Current approach to AI in financial services risks serious harm to consumers and wider system - Committees - UK Parliament

[4] Model - Innovation, Cybersecurity, and Technology (H) Working Group

 

Key contacts