Primary topic: AI in Insurance: Industry Transformation, Risk Assessment, Privacy, and Governance
Research focus: AI in underwriting, pricing, and claims; algorithmic claim-denial litigation; deepfake claims fraud; policyholder data breaches; the NAIC and EU AI rulebooks; and the new fight over who insures AI risk itself
What “AI in Insurance” Covers
AI now sits in every stage of the insurance chain. Risk grows with how much a system can affect a policyholder’s money or coverage.
| Area | What AI does | Impact on the customer |
|---|---|---|
| Underwriting and pricing | Scores risk and sets premiums | What you pay, and whether you get cover |
| Claims handling | Sorts, estimates, and sometimes decides claims | Whether and when you get paid |
| Fraud detection | Flags suspicious claims and fake evidence | Lower premiums for honest customers, or wrongful flags |
| Distribution and service | Chatbots, quotes, and personalized offers | Speed and convenience, with data exposure risk |
| Actuarial and reserving | Models loss trends and capital needs | Insurer stability and long-term pricing |
Visual: AI Across One Policy Lifecycle
AI scores the applicant
AI checks documents and identity
AI chatbot answers questions
AI reviews photos and records
AI reprices the risk
Five stages. Five points where a policyholder can be helped or harmed by an automated decision.
Why Governance Became Urgent in 2026
Four pressures hit insurers at once. Each is real. Together they change the job.
Visual: Four pressures on insurers
Lawsuits over automated claim decisions and alleged bias
AI-made fake photos and documents flood claims desks
Massive breaches of policyholder health and financial data
NAIC exams, EU deadlines, and new AI policy exclusions
Visual: Key dates insurers should know
Already happened
NAIC adopts its AI Model Bulletin for insurers
ISO introduces generative AI exclusions for liability policies
NAIC pilots its AI evaluation tool in 12 states
Aflac Japan discloses a breach of 4.38 million customers
NAIC is expected to consider formal adoption of its AI evaluation tool
EU deadline for most high-risk AI rules, after the Digital Omnibus delay
Pressure 1: Automated claim decisions are now in court
Several lawsuits challenge how health insurers use algorithms in claims. Patients sued Cigna over a system called PxDx. They allege it let doctors reject claims in bulk, without reading files. Cigna says PxDx does not use AI. The company says it covers around 50 low-cost tests and procedures. A federal judge in California let a proposed class action proceed in March 2025. Plaintiffs were asked to amend parts of their complaint.
Families also sued UnitedHealth over a tool called nH Predict. They allege it cut off post-acute care based on predictions, not individual needs. A Minnesota federal judge allowed part of that case forward. Humana faces a similar suit in Kentucky. Humana says a human stays in the loop whenever AI is used.
Read this carefully. These are allegations, not final findings. Courts have not ruled the insurers did wrong. But the legal theory matters for every insurer. Plaintiffs argue a company cannot hide behind “the algorithm decided.” Few patients ever appeal a denial, which is part of the point being made. New suits keep arriving. In early 2026, plaintiffs sued State Farm. They allege its claim algorithms flag, delay, or deny claims from some groups at higher rates. That case is also only allegations.
Sources: AI, Algorithm-Based Health Insurer Denials Pose New Legal Threat, Bloomberg Law, April 2025, Health Insurers Sued Over Use of AI to Deny Medical Claims, ArentFox Schiff, and State Farm Hit With Lawsuit Over AI Bias, Beinsure, February 2026
Pressure 2: AI-made fake claims are flooding desks
Generative AI can now make photorealistic crash scenes, water damage, and receipts. Verisk’s 2026 State of Insurance Fraud study surveyed 1,000 US consumers and 300 claims professionals. The results are stark.
Visual: AI and insurance fraud (Verisk, 2026)
A separate ACFE and SAS survey found only 7 percent of anti-fraud professionals feel more than moderately prepared for AI-driven fraud. Among insurance respondents, none felt more than moderately confident.
Visual: A claim photo used to be proof. Now it needs proof of its own
A photo of the damage settles the claim. If it looks real, it is real.
Free tools can generate a convincing fake in seconds. The photo now needs its own check, through metadata, source device, or live capture.
Sources: 2026 State of Insurance Fraud Report, Verisk, March 2026 and Insurers Grapple With New Fraud Threat: AI-Generated Images, SAS, May 2026
Pressure 3: Insurers hold data attackers want
Insurers store Social Security numbers, health details, claims histories, and bank accounts. That makes them prime targets. The breaches below were not caused by AI. They show why more AI data flows raise the stakes.
- Aflac, 2025: Personal information of about 22.65 million people was involved. That included Social Security numbers, health information, and claims data.
- Allianz Life, July 2025: A hacker used social engineering to breach a third-party cloud tool. Most of the insurer’s 1.4 million US customers had data taken.
- Aflac Japan, June 2026: Attackers stole data on about 4.38 million customers. Reports say attackers were inside for about ten days. The company noticed through a spike in system load, not a security alert.
Two lessons stand out. Third-party tools are a weak link. Social engineering beats technology. AI makes both problems bigger, since every new AI vendor is another door into policyholder data.
Sources: Aflac Reveals Personal Data of 22.6 Million People Stolen, TechRadar, Allianz Life Discloses Massive Data Breach, Cybersecurity Dive, July 2025, and Insurance Giant Aflac Discloses Data Breach, Infosecurity Magazine, July 2026
Pressure 4: New rulebooks, and shrinking coverage
Regulators moved from advice to examination. The NAIC adopted its Model Bulletin in December 2023. By the NAIC’s Spring 2026 meeting, 24 states and DC had adopted it. Other trackers count 25 by mid-2026. California, Colorado, New York, and Texas run their own frameworks. The bulletin expects a written AI program, built on the NIST AI Risk Management Framework.
The real change is how examiners will check. The NAIC is piloting an AI Systems Evaluation Tool in 12 states through September 2026. A formal version is expected at its Fall 2026 meeting. No formal enforcement actions under the bulletin had been reported through early 2026. The pressure right now is exam readiness, not fines.
In the EU, the AI Act treats risk assessment and pricing in life and health insurance as high-risk. The Digital Omnibus pushed most high-risk deadlines to December 2, 2027. Transparency duties still apply from August 2, 2026. That includes telling users they are talking to a chatbot, and labeling deepfakes.
At the same time, insurers are stepping back from AI risk in their own policies. In January 2026, ISO introduced generative AI exclusions for commercial liability policies. Lawyers advise that AI losses may now fall between coverage lines. Buyers should read renewals closely.
Sources: NAIC Spring 2026 National Meeting Highlights, Mayer Brown, EU AI Act Digital Omnibus: The New High-Risk AI Deadlines, Secure Privacy, 2026, and The End of Silent AI, Fenwick, June 2026
Research Study: The NAIC Model Bulletin and How Examiners Will Test It
The NAIC bulletin is principle-based. It bans no AI use. It asks insurers to run an AI program covering governance, testing, and third-party oversight. Its evaluation tool gives examiners a way to check that during a market conduct exam. The message from compliance guidance is simple. The burden is shifting from policy language to auditable proof that AI was tested before launch, and watched after.
What insurers can learn:
- Keep one central inventory of every AI system, including vendor models
- Tier each system by how much it can harm a policyholder, and record the tier
- Store testing and monitoring records where examiners can find them in days
- Map your program to NIST once, and reuse it across other frameworks
Source: AI Regulation in Insurance 2026, actuary.info, March 2026
Research Study: Verisk on AI, Deepfakes, and Claims Fraud
Verisk’s study pairs a consumer survey with a claims-professional survey. It shows fraud is partly about behavior, not only technology. Easy editing tools lower the barrier. Some consumers see small edits as harmless. Most insurers, meanwhile, admit low confidence in detecting deepfakes.
What insurers can learn:
- Do not trust a photo or receipt as proof by itself anymore
- Add image forensics that check metadata, pixel patterns, and source device
- Tell customers plainly that manipulated claims raise everyone’s premiums
- Track false positives, so honest customers are not wrongly flagged
Source: 2026 State of Insurance Fraud Report, Verisk
Research Study: Generative AI and the Vehicle Insurance Fraud Arms Race
A 2025 white paper on vehicle insurance fraud describes how generative AI lets criminals fake crash photos and damage at scale. Detection tools can misfire in both directions, missing real fraud or flagging honest claims. The authors work for a vehicle-inspection company, so read this as a practitioner view, not neutral research.
What insurers can learn:
- Expect an ongoing contest, not a one-time fix
- Combine image analysis with independent inspections and telematics data
- Budget for regular updates to detection tools
- Route high-value or suspicious claims to trained investigators
Source: A New Wave of Vehicle Insurance Fraud Fueled by Generative AI, arXiv, 2025
Research Study: The Coverage Gap for AI Risk
Law-firm analyses in 2026 describe a shift. AI risk used to sit silently inside cyber, tech errors and omissions, and general liability policies. Now carriers either exclude it or price it apart. The result is fragmentation. A loss can fall between two policies, each pointing at the other. Some insurers are starting to offer affirmative AI coverage instead.
What insurers and buyers can learn:
- Insurers should decide whether to exclude, sublimit, or affirmatively cover AI, and say so clearly
- Buyers should map their AI use against every policy before renewal
- Brokers should ask which AI exclusion forms apply, and which are filed with regulators
- Clear wording now prevents disputes later
Sources: The End of Silent AI, Fenwick, June 2026 and The New AI Coverage Fight, Shumaker, Loop and Kendrick, July 2026
What the Experts Are Saying
Scott Bessent, US Treasury Secretary, September 21, 2026
Alana McMullin, Lathrop GPM, July 2026
Peter Norwood, Finance Watch, November 2025
Notice the split. Regulators and consumer groups want firm guardrails. Industry wants clear dates and workable rules. Both sides agree on one thing. AI decisions need a responsible human owner. Our reporting on Bessent’s rejection of an AI liability shield and AI industry liability exposure follows the same debate.
Sources: Treasury Secretary Bessent Says AI Firms Shouldn’t Get Liability Shield, Quartz, September 2026, Insurer Interest in AI Exclusions Growing, Claims Journal, July 2026, and Digital Omnibus: Supporting Innovation and Consumer Protection, Insurance Europe
Privacy: Policyholder Data Is Sensitive by Nature
Insurance data is not just personal. It is intimate. Health records. Driving habits. Home details. Bank accounts. Family information. AI can widen the flow of that data through new tools, so the rules must tighten as fast as the tools spread.
Visual: Where policyholder data can leak through AI
Third-party CRMs and AI tools hold copies of records
Staff paste claim files into public AI tools
Photos, voice, and video hold hidden personal detail
Social engineers trick staff into giving access
Practical privacy rules for every insurer:
- Collect only the data each AI use case truly needs
- Strip names, IDs, and health details before data reaches any model
- Get written vendor terms on storage, reuse, and no training on policyholder data
- Set short retention limits for chat logs, images, and call recordings
- Harden help desks with call-back checks, since social engineering drove recent breaches
- Tell customers when AI plays a role in a decision that affects them
Governance Stack: Who Owns What
Sets AI risk appetite. Reviews the AI inventory. Owns the fairness policy.
Underwriting and claims own how AI is used and who can override it.
Own logging, access control, vendor integration, and kill switches.
Test for bias, review vendors, and prepare for regulator exams.
Actionables: What Each Team Should Do, Why, and What It Changes
Use these tables as working checklists. Each row names the action, why it matters, and the result you should expect.
For Boards and Senior Leaders
| Action | Why it matters | Expected impact |
|---|---|---|
| Require a full AI inventory with a risk tier for each system | Examiners under the NAIC framework expect to see it | Faster, calmer market conduct exams |
| Name one accountable executive for AI in claims and pricing | “The algorithm decided” is not a defense in court | Clear ownership and lower legal exposure |
| Decide your position on AI exclusions and AI coverage | Coverage is fragmenting, and buyers will ask hard questions | Fewer coverage disputes and a clearer market offer |
| Fund fraud defense and vendor security as separate budget lines | Deepfake claims and vendor breaches are both rising | Lower fraud losses and fewer breach surprises |
For Underwriters, Actuaries, and Claims Leaders
| Action | Why it matters | Expected impact |
|---|---|---|
| Never let AI alone deny a claim | Claim-denial suits center on missing individual review | Lower bad-faith risk and fairer outcomes |
| Test pricing models for outcome differences across groups | Regulators increasingly expect outcome testing | Bias caught early, before a regulator finds it |
| Record a plain-language reason for every adverse decision | Policyholders and courts will ask why | Faster appeals and stronger defenses |
| Track appeal and overturn rates for AI-assisted decisions | A high overturn rate signals a model that is wrong too often | An early warning light for model quality |
For Fraud (SIU) and Security Teams
| Action | Why it matters | Expected impact |
|---|---|---|
| Add image forensics for claim photos and documents | 98 percent of insurers say AI editing fuels digital fraud | More fake claims caught before payment |
| Require live, in-app photo capture for high-value claims | Uploaded files are easy to fake; live capture is harder | Fewer inflated or invented losses |
| Add call-back verification to help desks and agent portals | Social engineering drove the Allianz and related breaches | Much harder for an attacker to talk their way in |
| Alert on abnormal data downloads, not only failed logins | Aflac Japan reportedly noticed its breach through a load spike | Detection in hours instead of days |
For Developers and Data Engineers
| Action | Why it matters | Expected impact |
|---|---|---|
| Log inputs, model version, output, and human override for each decision | Regulators want auditable evidence, not policy text | Exam responses in days, not weeks |
| Mask personal and health data before it reaches any model | Prompts and logs are common leak paths | Smaller damage if a vendor or log is exposed |
| Give every customer-facing AI a kill switch and a human handoff | Wrong coverage advice can create real liability | You can stop a faulty tool within minutes |
| Restrict third-party tool access with least privilege | A compromised CRM exposed most Allianz Life customers | A vendor breach reaches far less data |
For Insurtech Startups and Founders
| Action | Why it matters | Expected impact |
|---|---|---|
| Build audit logs and reason codes as core features | Your insurer clients must prove oversight to regulators | Shorter sales cycles and stronger trust |
| Publish plain data terms: storage, reuse, and no training on client data | Carriers screen vendors on privacy first | Fewer legal delays during procurement |
| Ship bias testing reports with your models | Outcome testing is becoming an exam expectation | A real edge over black-box competitors |
| Prepare for vendor-oversight rules, which may include licensing | A model law on third-party data and models is anticipated | Less scrambling if vendor rules arrive |
For Compliance, Legal, and Vendor Risk Teams
| Action | Why it matters | Expected impact |
|---|---|---|
| Map every state and EU rule that touches your AI use | Rules differ by state and region and keep changing | No surprise gaps in a multi-state footprint |
| Write audit rights and data terms into every AI vendor contract | You answer to regulators for vendor models | You can inspect a vendor when a regulator asks |
| Run a mock AI examination twice a year | The NAIC evaluation tool is moving toward formal use | Gaps found by you, not by an examiner |
| Prepare a customer notice for AI-assisted decisions and chatbots | EU transparency duties already apply, and states are moving too | Trust preserved and disclosure duties met |
For Brokers and Corporate Risk Managers Buying Insurance
| Action | Why it matters | Expected impact |
|---|---|---|
| List every AI tool your business uses before renewal | Insurers now ask about AI and may exclude it | Accurate answers and fewer disputes later |
| Ask carriers which AI exclusion forms apply to your policy | Broad “arising out of” wording can remove real coverage | No nasty surprise at claim time |
| Compare cyber, tech E&O, and liability wording side by side | AI losses can fall between lines | Gaps found and closed before a loss |
| Price affirmative AI cover where it is offered | Some insurers now sell AI-specific protection | Clearer protection for your riskiest AI use |
Risk Tiers: Matching Oversight to Impact
| Tier | Example | Required control |
|---|---|---|
| Assist | Summarize a claim file for an adjuster | Adjuster reviews source documents |
| Recommend | Suggest a risk class or triage category | Human sign-off with a recorded reason |
| Execute bounded tasks | Auto-pay small, clear-cut claims | Payment ceiling, sampling audits, and bias tests |
| High-impact decision | Deny a claim, cancel cover, or set a major price change | Mandatory human review before the decision takes effect |
Implementation Roadmap
List every AI system, vendor, and data flow. Assign a risk tier.
Run bias and outcome tests. Set human review rules for adverse decisions.
Add image forensics, vendor limits, and help-desk protections.
Keep audit evidence ready. Run a mock exam twice a year.
KPIs to Track
| KPI | What it tells you |
|---|---|
| AI inventory coverage | Share of AI systems, including vendor tools, formally listed and tiered |
| Appeal and overturn rate | How often AI-assisted decisions are reversed |
| Outcome gap across groups | Differences in approval, price, or payout that need explaining |
| Synthetic media detection rate | How many fake photos and documents you catch |
| Vendor assessment coverage | Share of AI and data vendors reviewed for security and data terms |
| Breach detection time | Hours from intrusion to detection |
Future Predictions: 2027 to 2030
2027: AI Exams Become Routine
Trackers point to 2027 as the year state AI examination capacity matures. Expect insurers to be asked for evidence, not just policies. The EU’s December 2027 deadline arrives in the same window.
2028: Vendor Rules Tighten
A NAIC model law on third-party data and models is anticipated. It could bring licensing or registration for AI vendors serving insurers.
2029: Verified Evidence Becomes Standard
As fake images spread, insurers will likely require verified capture, such as in-app photos with signed metadata, for many claim types.
2030: AI Coverage Becomes a Mature Product Line
Today’s exclusions and patchwork will likely settle into clear AI liability products, with defined limits, testing requirements, and pricing tied to governance quality.
Startup and Product Opportunities
- Claims fairness monitor: Tracks outcomes across groups and flags gaps before regulators do
- Trusted-capture app: Signs claim photos at the moment of capture so fakes are easy to reject
- Synthetic media detector for claims: Screens photos, receipts, and documents at scale
- NAIC exam-readiness platform: Maps a carrier’s AI systems and evidence to examiner questions
- AI vendor risk scorer for insurers: Rates model vendors on security, data terms, and transparency
- AI coverage mapper for buyers: Compares exclusions and endorsements across a company’s policies
Frequently Asked Questions
Is it legal for insurers to use AI to decide claims?
Insurers can use AI, and regulators have not banned it. But the NAIC bulletin expects governance, testing, and accountability. Courts are testing cases where automated tools allegedly replaced individual review.
Did the Cigna and UnitedHealth cases end in findings against the insurers?
Not based on the sources reviewed here. The cases were still moving through court. Cigna says PxDx does not use AI. Treat the claims as allegations.
How many states follow the NAIC AI bulletin?
Sources differ slightly. Mayer Brown reported 24 states and DC as of the NAIC Spring 2026 meeting. Other trackers count 25 by mid-2026.
How is AI changing insurance fraud?
It makes fake photos and documents easy to produce. Verisk found 98 percent of insurers say AI editing tools fuel digital fraud, yet only 32 percent feel very confident detecting deepfakes.
Were the big insurer breaches caused by AI?
No. The Aflac and Allianz Life incidents involved social engineering and third-party access. They matter because AI adds more data flows and more vendors to protect.
What is the EU AI Act deadline for insurers?
Most high-risk duties now apply from December 2, 2027, after the Digital Omnibus delay. Transparency duties, like chatbot disclosure, still apply from August 2, 2026.
Why are insurers excluding AI from policies?
They are deciding how much AI risk to keep, price, or exclude. ISO introduced generative AI exclusions for liability policies in January 2026.
What should an insurer do first?
Build a complete AI inventory with risk tiers. Then make sure no AI system alone can deny a claim or cancel cover.
Final Perspective
Insurance runs on trust. A policyholder pays today for a promise tomorrow. AI can keep that promise faster and cheaper. It can also break it quietly, at scale, without anyone noticing.
The 2026 picture is clear. Courts are testing automated denials. Fraudsters use AI to fake proof. Breaches keep exposing sensitive records. Regulators want evidence, not slogans. And insurers are now deciding how much AI risk to carry for everyone else.
The answer is not to slow down. It is to govern. Keep a human on every decision that can hurt a customer. Test for bias. Verify evidence. Limit vendors. Keep records. Firms that do this will earn regulator trust, customer trust, and better terms for their own risk.
For sector-specific playbooks that apply the same discipline elsewhere, see our related guides on AI Security and Governance in Banking, AI Security and Governance in Healthcare, AI Security and Governance in FinTech, AI Security and Governance in Investment and Asset Management, and our earlier guides on AI in Capital Markets, AI in Trading, and AI in Crypto.
For deeper coverage of the insurance topics above, see our reporting on AI in life and health insurance underwriting, AI in property and casualty underwriting, AI in telematics-based insurance pricing, AI in health insurance payers and claims, and the AI kill switch debate.
Sources
- AI, Algorithm-Based Health Insurer Denials Pose New Legal Threat, Bloomberg Law, April 2025
- Health Insurers Sued Over Use of Artificial Intelligence to Deny Medical Claims, ArentFox Schiff
- State Farm Hit With Lawsuit Over AI Bias, Discrimination and Unpaid Insurance Claims, Beinsure, February 2026
- 2026 State of Insurance Fraud Report, Verisk, March 2026
- Insurers Grapple With New Fraud Threat: AI-Generated Images, SAS, May 2026
- A New Wave of Vehicle Insurance Fraud Fueled by Generative AI, arXiv, 2025
- Aflac Reveals Personal Data of 22.6 Million People Stolen, TechRadar
- Allianz Life Discloses Massive Data Breach Linked to Supply-Chain Attack, Cybersecurity Dive, July 2025
- Insurance Giant Aflac Discloses Data Breach, Infosecurity Magazine, July 2026
- NAIC Spring 2026 National Meeting Highlights, Mayer Brown
- AI Regulation in Insurance 2026, actuary.info, March 2026
- EU AI Act Digital Omnibus: The New High-Risk AI Deadlines, Secure Privacy, 2026
- Digital Omnibus: Supporting Innovation and Consumer Protection, Insurance Europe
- The End of Silent AI, Fenwick, June 2026
- Insurer Interest in AI Exclusions Growing, Claims Journal, July 2026
- The New AI Coverage Fight, Shumaker, Loop and Kendrick, July 2026
- Treasury Secretary Bessent Says AI Firms Shouldn’t Get Liability Shield, Quartz, September 2026


Leave a Reply