August 19, 2026

Insurance Is the Exception in Enterprise AI Adoption | CoreLine

Financial services is the one sector where risk and compliance is a high-adoption AI function. Stanford's AI Index 2026 explains why - and what insurers should build next.
date
August 19, 2026
categories
categories
Development
Insurance Is the Exception in Enterprise AI Adoption
table of contents

Buried in the adoption data of Stanford’s AI Index 2026 is a single sentence that describes the insurance industry’s position better than most industry reports manage.

Across sectors, the functions with the lowest AI adoption are strategy and corporate finance, and risk and compliance. Then: “Financial services were an exception; they reported high use in risk and compliance functions, which are more central to their core operations” (Ch4).

Everywhere else, AI went to the functions where being wrong is cheap: marketing copy, internal knowledge search, developer tooling. In financial services and insurance it went into the function where being wrong is the entire business. That is not recklessness. It is what happens when a sector has been running quantitative risk models under regulatory scrutiny for forty years and already owns the muscle: model documentation, validation, challenge, monitoring, and an actuarial function whose job is to say no.

Insurers therefore start from an unusual position. The governance capability is mature and the AI capability is new, the exact inverse of most industries, and a genuine advantage if the two are connected properly.

Where insurance sits on the adoption ladder

The context: 88% of organizations use AI in at least one business function, and only 3% to 10% have a fully scaled AI program depending on company size (Ch4, Figs 4.3.1 and 4.3.6). Agent adoption is further back: in the risk function specifically, 85% report no agent use at all (Ch4, Fig 4.3.8).

That last figure cuts both ways. It says the sector is behind on agentic automation, and it says almost nobody has yet made the expensive mistake of putting an under-governed agent inside a claims or underwriting decision. There is still time to do this in the right order.

Where the reported returns land is also instructive: respondents associated cost savings most with software engineering and manufacturing functions, and revenue gains with marketing and sales (67%), strategy and corporate finance (65%), and product development (62%) (Ch4, Fig 4.3.4). For an insurer, that maps to a realistic sequencing: distribution and servicing first, core underwriting decisions later and more carefully.

The regulatory fact that changes the sequencing

Under the EU AI Act, insurance risk assessment and pricing for life and health cover sits in the high-risk tier, alongside creditworthiness assessment and employment screening. High-risk classification brings a substantial obligation set: risk management, data governance and representative training data, technical documentation, automatic logging and traceability, transparency, effective human oversight, accuracy and robustness, post-market monitoring, and serious incident reporting.

The Act’s phasing has already moved once and may move again, so verify current dates against the primary text rather than a blog post, including this one. What is not in question is the direction, or that 43% of organizations now name the EU AI Act as an influence on their responsible-AI decisions, with ISO/IEC 42001 arriving at 36% and the NIST AI RMF at 33% in their first year in the survey (Ch3, Fig 3.3.11).

The strategic implication for an insurer is straightforward: the claims and servicing side is where AI can move quickly; the underwriting and pricing side is where it moves under a documented obligation set. Treating those as the same programme with the same governance is how a distribution chatbot ends up delayed by an underwriting-grade review, and how an underwriting model ends up shipped on a chatbot’s evidence base.

What insurers should build first

Claims triage and document extraction. High volume, repeatable, quality is checkable against the adjuster’s decision, and a human retains the call. This is the ambient-documentation pattern from healthcare applied to insurance: the model drafts and extracts, a licensed human decides. It passes all three of the AI Index’s conditions for where gains actually appear: well-defined, repeatable, monitorable.

Fraud signal enrichment, not fraud decisions. Surfacing features and prior-claim context to an investigator is a different regulatory object from scoring a claimant. The same model can support both; only one of them requires you to explain an adverse decision to a regulator.

Policy and endorsement document generation. Draft-and-review, with the underwriter as author.

Broker and customer servicing. Where the revenue-side gains actually show up in the data, and where errors are recoverable.

Underwriting and pricing: last, with the full apparatus. Not because it is less valuable, but because it is the high-risk tier, and because your actuarial validation function should be the one setting the acceptance criteria before an engineer picks a model.

The engineering that makes any of it defensible

An insurer’s AI systems need to satisfy the model risk function, the data protection officer, and eventually a regulator asking about a specific decision on a specific policy. In practice that resolves to a short list of artifacts.

Decision reconstruction. Model version, prompt version, retrieval corpus version, input features, output, and any human override, logged together, immutably, per decision. If you build one thing from this article, build this. Every other requirement in every framework depends on it existing.

Overrides recorded as overrides. Human oversight that leaves no trace is indistinguishable from no oversight. The adjuster or underwriter disagreeing with the model is your most valuable training and monitoring signal, and it is usually thrown away.

Data contracts and lineage. Which fields fed the decision, where they came from, how fresh they were, and what happens when an upstream schema changes. Our data contracts for enterprise applications post covers the mechanics; in insurance the same work doubles as your training-data provenance record.

Evals owned by the risk function, not the delivery team. Acceptance thresholds set by the people accountable for the model, run continuously, gating every model upgrade. The AI Index notes the provider transparency problem that makes this non-negotiable: the Foundation Model Transparency Index fell from 58 to 40 in 2025 (Ch3). You cannot inspect the model, so you must measure it.

Fairness testing as a scheduled control. Disparate outcome rates across protected characteristics, tested on a schedule and documented, not as a launch gate that happens once. Note the report’s uncomfortable empirical finding: responsible-AI dimensions trade off against each other, and training techniques improving one consistently degraded others (Ch3). There is no configuration that maximises accuracy and fairness simultaneously; there is only a tradeoff chosen deliberately and evidenced.

Provider portability. A concentrated dependency on one model vendor is a concentration risk, and insurers have a whole discipline for those.

The sector’s advantage here is real and worth naming: insurers already know how to govern a model. The work is not inventing an AI governance capability from nothing; it is extending an existing model risk framework to cover systems whose failure modes are stranger, whose vendors disclose less, and whose behaviour changes when someone else ships an upgrade.

That extension is buildable, and the sector has a narrow window to do it before agent adoption arrives with its own momentum. Our insurtech work and our custom software for insurance practice are built around it, and the AI execution gap covers the wider pattern this sits inside.

All figures cited from the Stanford HAI Artificial Intelligence Index Report 2026 (9th edition); adoption data originates in McKinsey’s 2025 survey and is self-reported. Regulatory descriptions are a technical reference, not legal advice; verify current EU AI Act obligations and phasing against the primary text.

need a second opinion?
Talk to our engineers about your architecture, stack, or delivery challenge.