Artificial intelligence is becoming a more common part of insurance claims, from document processing and fraud detection to damage assessment and claims triage. But as insurers move these systems into more important parts of the claims process, regulators are paying closer attention to how they are built, tested and used.
This is changing the role of AI regulation in insurance. It is no longer simply a question of whether an insurer is allowed to use artificial intelligence. The bigger issue is whether the insurer can show that an AI system is accurate, fair, secure, explainable and properly governed when it influences a claim.
That matters because claims decisions can directly affect policyholders. An AI system may help assess damage, identify unusual claims or recommend a settlement, but the consequences of an incorrect or biased decision can extend beyond an individual claim. They can create disputes, regulatory exposure, customer complaints and financial losses for insurers.
Regulators are responding in different ways across major markets. In the US, the insurance sector is building its AI oversight framework through state-level regulation and the National Association of Insurance Commissioners’ model guidance. By March 2026, 25 states had adopted the NAIC Model Bulletin, while regulators in 12 states were participating in a pilot AI Systems Evaluation Tool designed to examine insurers’ AI governance and risk-management practices.
Europe is taking a different route. The EU’s AI framework works alongside existing insurance regulation and places particular emphasis on governance, data quality, record-keeping, fairness, cybersecurity, transparency and human oversight. The European insurance regulator has also been working on how the AI Act applies to insurance-specific models and systems.
The result is not one global set of rules. Instead, insurers are facing a growing set of expectations that can vary by market while still focusing on many of the same risks.
AI Governance is Becoming Part of the Claims Process
The most important change is that AI regulation is moving closer to day-to-day claims operations.
An insurer using AI to summarise documents faces a different level of risk from one using an automated system to influence claim severity, fraud investigations or settlement decisions. The closer an AI model gets to a decision affecting a policyholder, the greater the need for human oversight, documentation and clear accountability.
The NAIC’s AI guidance makes clear that using an AI system does not remove an insurer’s existing legal obligations around unfair discrimination, unfair trade practices or consumer protection. Insurers also need governance and risk-management processes that allow regulators to understand how AI-supported decisions are being made.
That is creating a more practical model for claims teams. Automation can handle repetitive work, but insurers still need people who can review exceptions, challenge automated recommendations and take responsibility for final decisions.
At the global level, the International Association of Insurance Supervisors has identified five broad areas for AI supervision: risk-based oversight, governance and accountability, robustness and security, transparency and explainability, and fairness, ethics and redress.
For insurers, this means AI governance is becoming part of claims management itself, rather than something handled separately by technology or compliance teams.
Different Rules are Creating a Common Governance Challenge
The regulatory landscape is developing differently across markets, but the concerns behind AI regulation are becoming remarkably similar. Insurers are being asked to understand how AI systems work, what data they use, how decisions are monitored and who remains accountable when something goes wrong.
In the US, insurance regulation is developing largely through state-level frameworks. Regulators are increasingly asking insurers for more information about their AI systems, governance practices, risk controls and the data used by models. A regulatory AI evaluation tool was being piloted across 12 states as of March 2026, with the aim of helping supervisors assess insurers’ use of AI in areas including claims and other operations.
Europe is taking a more structured risk-based approach through the EU AI Act alongside existing insurance-sector rules. The European insurance supervisor has emphasised data governance, record-keeping, fairness, cybersecurity, explainability and human oversight. Importantly, not every AI system used by an insurer is automatically classified as high risk. The regulatory treatment depends on how the system is used and the risks it creates.
The distinction matters for claims teams. An AI system that summarises documents creates a different level of risk from one that influences a settlement recommendation or flags a policyholder for fraud investigation. As AI moves closer to decisions that affect coverage and payments, the need for clear controls becomes greater.
That is why global supervision is increasingly focused on risk-based and proportionate governance, rather than treating every AI application in the same way. International supervisory guidance now groups the main concerns around governance and accountability, system robustness and security, transparency and explainability, and fairness and redress.
Third-Party AI is Bringing New Responsibility into Claims
Another challenge is that insurers do not necessarily build the AI systems they use. Claims platforms, fraud tools, document models and image-assessment systems may come from external technology providers or rely on third-party models. That does not remove the insurer’s responsibility.
International supervisory guidance specifically highlights third-party risks and says insurers need to understand and manage the systems they use and the outcomes they produce.
This becomes particularly important when an AI system influences a claims decision. If a model produces an inaccurate recommendation, the insurer still has to deal with the customer, the regulator and potentially the financial consequences.
Recent European research shows how quickly this issue is developing. A 2026 survey found that insurers are adopting generative AI cautiously, with 49% of surveyed insurers having already developed dedicated AI policies, compared with roughly one quarter in 2023. The most frequently cited risks were inaccurate AI outputs, cybersecurity and data-protection concerns, while reliance on third-party providers was also widespread.
For claims operations, this means governance is becoming part of implementation rather than a final compliance check. Insurers need to know which decisions can be automated, which require human review, how model performance is monitored and how an outcome can be challenged or explained.
The broader direction of AI regulation is therefore becoming clear. Regulators are not simply deciding whether insurers can use AI. They are increasingly defining the conditions under which insurers can use it responsibly and demonstrate that the technology remains under control.


















