Download

World Cup Shows Insurers How to Avoid a Red Card

Amid a hugely successful World Cup tournament, Argentina demonstrated how actions by a few bad actors can chase away millions of fans (or customers).

Image
WC

A World Cup soccer tournament wouldn't be a World Cup without controversies, and the just-concluded event had its share. 

Then Argentina said, Hold my Fernet con Cola. 

Following the team's 1-0 loss in the finals to a clearly superior Spanish team, an Argentine player picked a fight on the field that included grabbing a Spanish player by the throat and throwing him to the ground, and Argentine teammates backed him up. Just about the whole Argentine team then acted churlish during the awards ceremony, even turning their backs as the Spanish players were awarded their gold medals and the team trophy. 

Within minutes, reporters and fans were revisiting every untoward thing Argentina had done during the tournament, then during prior tournaments, then on the team bus, then.... 

Argentina provides a great example of how actions taken even by a few in the heat of the moment can sour masses of people on a group or a brand. It's a lesson that I think insurers, in particular, should take to heart, given that our most consequential actions tend to come when dealing with people in situations where their emotions are running hot. 

Let's have a look. 

Argentina had been a possible feel-good story coming into the tournament this year. It had finally won the World Cup in 2022 for its captain, all-time great Lionel Messi. If Argentina had repeated as champion, it would have been the first to do so since Brazil in 1962. Messi, who had won the Golden Ball award in 2022, given to the best player in the tournament, was in the running for the award again. Going into the final, he also had a shot at the Golden Boot, given to the top scorer in the World Cup. At 39 years old, a beloved player was putting in a remarkable performance.

Now, Argentina is known for being chippy, even dirty, and it played to form throughout the tournament, including by having a player sent off in the final after a violent tackle. Spain, while hardly free of fouls, played a classic style that contrasted sharply with Argentina and led any number of people to post at the conclusion of the game some variant of, "Football won today." 

The history of writeups about the Argentine team suggests that would have been about the extent of the complaints about Argentina's tactics. 

Then the Argentine players started knocking around some of the Spaniards after the final whistle, and all bets were off. 

Someone quickly shared a clip of the Argentine player instigating the post-game brawl. Then people started going back through the whole game, pointing out everything even borderline that Argentine players did here is one-such 13-minute clip. But why stop there? Here is a 5 1/2-minute clip of transgressions by Argentina that weren't penalized in the semifinal against England. Of course, there was group play, too here is nine minutes of uncalled fouls against Switzerland. 

Earlier incidents became fair game, as well. A video surfaced in 2024 of Enzo Gonzalez, the Argentine player who drew a red card in the final, and teammates chanting racist slurs on the team bus, as posts such as this one quickly noted over the weekend. Gonzalez had apologized profusely, including personally to Black players on his club team, and surely thought the incident was behind him. No longer. Many on social media also noted that the Spanish goalkeeper had been classy in accepting the Golden Glove award, for the best at his position in this year's tournament, while the Argentine keeper had used the award to make an obscene gesture when he won in 2022.

Analysts were universally brutal about Argentina after the final. The New York Times ran a story under the headline, "Argentina disgraced themselves, and the World Cup final, with their charmless petulance." In case that wasn't enough, the NYT ran another story, full of images, under the headline, "How Argentina turned the World Cup final dirty with shoves, skulduggery and squealing."

My point being: Once sentiment turns against you, even based on an incident by one person or a small group, things can go downhill fast and keep going.  

This surely isn't news to insurance companies, which understand that claims are the moment of truth. Everyone and everything has to line up just right when you're dealing with longstanding, loyal customers in their moment of need. They've earned compassionate, professional excellence and they'll react in horror if they don't get it. 

But I still think object lessons like those provided by Argentina are worth noting and spreading, because it only takes a few people, or even a single person, to undercut what so many other people are doing to earn loyalty. Social media can broadcast bad actions incredibly fast these days and seems to relish doing so, especially if there is compelling video. 

And narratives are hard to shake once they take hold. The Argentine team is being cooked especially hard because it was already known as a dirty team. In insurance, if you're not known for great customer service, complaints will find an especially alert audience — I'm sure State Farm, for instance, is being incredibly careful these days, given the controversy over its handling of claims from last year's wildfires in California.

I won't suggest buying the jersey of Leandro Paredes, the Argentine player who ran up on a Spanish player from behind after the game and knocked him over, because some of the money would find its way back to him. But maybe he can be an anti-hero for anyone dealing with insurance customers. Whatever you do, people, don't earn us a reputation like that guy....

Cheers,

Paul

P.S. When I think back on the World Cup, I'll prefer to think about the positive surprises. Who knew that Costco and ranch dressing would be such delights for those visiting the U.S.? Erling Haaland? I've spent years hating on him in a Man City kit but found him impossibly charming both in a Norway jersey and in his experience with U.S. culture. Then there was Spanish star Lamine Yamal's three-year-old brother, Keyne, who stole every scene he was in throughout the tournament. 

And I'll especially cherish a moment that Jude Bellingham and Bukayo Saka and their English team had in their third-place game against the French. 

When England earned a penalty kick, Bellingham prepared to take it. He had emerged as a full-on star for England and had already scored six goals; seven would be unworldly. But he knew that Saka had scored twice against France, knew that concerns about injury had (unwisely, in my view) kept Saka out of the semifinal that England lost against Argentina, and may have been thinking about how Saka and two Black teammates had missed penalty kicks in a tournament in 2021 and had endured wildly racist criticism. 

Bellingham told Saka, "Go on and get your hat trick," and handed him the ball. Saka converted with a kick that the keeper wouldn't have touched even if he had guessed right, rather than diving in the opposite direction. Saka's goal turned out to be the winner. 

Bellingham, by the way, got his seventh goal a few minutes later with an extraordinary display of technical virtuosity. So nice guys finish.... first?

Becoming a Frontier Insurer

Explore how Frontier Insurers use AI, GenAI, and Agentic AI to lead on competitiveness, cost structure, and growth in the intelligent era.

Frontier Insurer

AI has moved past the hype stage—it's reshaping cost structures, competitiveness, and growth across insurance. Carriers who hesitate are locking in cost and risk profiles that only get harder to unwind. Drawing on original research with insurance executives, this report shows how AI, GenAI, and Agentic AI are separating Leaders from Followers and Laggards—and why 2026 is the point of no return.

AI is now a boardroom priority, tied to insurers' top 2026 goals: cutting costs, streamlining operations, and improving customer experience. Across underwriting, claims, servicing, billing, distribution, and loss control, carriers are moving from talk to active pilots, targeting friction in paperwork-heavy areas like claims and service. But appetite is outpacing the data foundation needed to support it, raising scalability and reliability risks without stronger governance.

The center of gravity is shifting from "AI as a data tool" to "AI as a workforce multiplier," powered by the Frontier Firm—companies built on on-demand intelligence and human-agent teams, where staff act as "agent bosses." Leaders are already scaling GenAI and Agentic AI with mature data capabilities behind them; laggards risk losing ground on performance and cost.

Download this report to explore:

  • Why modernized data and an Intelligent Core are essential for scalable, responsible AI
  • How to bring the Frontier Firm and Agent Boss models into your organization
  • How AI is reshaping cost, competitiveness, and growth across the insurance value chain

 

 

Get Started>>


ITL Partner: Majesco

Profile picture for user majescopartner

ITL Partner: Majesco

Majesco isn’t just riding the AI wave — we’re leading it across the P&C, L&AH, and Pension & Retirement markets. Born in the cloud and built with an AI-native vision, we’ve reimagined the insurance and pension core as an intelligent platform that enables insurers and retirement providers to move faster, see farther, and operate smarter. As leaders in intelligent SaaS, we embed AI and Agentic AI across our portfolio of core, underwriting, loss control, distribution, digital, and pension & retirement administration solutions — empowering customers with real-time insights, optimized operations, and measurable business outcomes.


Everything we build is designed to strip away complexity so our clients can focus on what matters most: delivering exceptional products, experiences, and long-term financial security for policyholders and plan participants. In a world of constant change, our native-cloud SaaS platform gives insurers, MGAs, and pension & retirement providers the agility to adapt to evolving risk, regulation, and market expectations, modernize operating models, and accelerate innovation at scale. With 1,400+ implementations and more than 375 customers worldwide, Majesco is the AI-native solution trusted to power the future of insurance and pension & retirement. Break free from the past and build what’s next at www.majesco.com


Additional Resources

Modernize or Fall Behind: 2025 Retirement & Pension Top Industry Trends

Read More

Closing the Insurance Customer Protection Gap: How Generational Differences in Risk, Readiness, and Coverage Are Redefining Insurance Value

Read More

Bridging the Customer Protection Gap

Read More

Transforming Specialty Insurance with AI

Read More

Leaders Reinventing Insurance: Strategic Focus on Business Operating Model and Technology Foundation

Read More

How to Accelerate Recovery From Floods

Bipartisan legislation would use federal mitigation funds to support parametric flood insurance, accelerating disaster recovery in underinsured communities.

flood

Forecasts suggest this year's hurricane season could bring lower than average storm activity. But disaster risk is not measured solely by the number of named storms.

It only takes one major flood to expose the vulnerabilities that persist across the US flood protection system. And increasingly, flood losses are not confined to coastal communities or storm surge alone. Flooding driven by heavy rainfall, overflowing rivers, and flash floods are increasingly affecting communities far beyond traditional flood zones, often in places where insurance take-up is low and financial resilience is limited.

This reality highlights an urgent policy challenge; America's flood protection gap continues to widen at a time when economic exposure is growing.

Flooding can happen almost anywhere, yet millions of American households and businesses remain uninsured or underinsured against flood risk. When disasters strike, the consequences extend well beyond individual property losses, which alone are already devastating. Delayed recovery affects local employers, municipal budgets, infrastructure systems, housing markets, and broader regional economic activity.

Insurance plays a critical role in helping individuals, businesses, and communities recover more quickly and reducing long-term economic disruption. Strong insurance participation supports financial stability after disasters, accelerates rebuilding, and reduces reliance on post-event federal assistance. It's an essential component of economic resilience for all Americans.

That's why Congress should advance the bipartisan Community Flood Resilience Act, introduced by Congressman Andrew Garbarino and Congressman Gregory Meeks.

The legislation reflects a pragmatic recognition that resilience requires both physical mitigation and financial preparedness. By allowing a portion of federal flood mitigation assistance funding to support community-based parametric flood insurance solutions, Congress is advancing a thoughtful public-private sector approach to disaster resilience.

This legislation does not replace the National Flood Insurance Program (NFIP). Instead, it acknowledges that public and private solutions can work together to expand protection, improve awareness, and strengthen recovery capabilities. In today's evolving risk environment, collaboration is essential.

Community-based parametric insurance provides funding when predefined conditions are met, such as measured rainfall levels, river heights, or other objective flood triggers. Because payments are tied to those triggers rather than lengthy loss-adjustment processes, communities can access funds much more quickly after a disaster. Faster access to funding can help local governments stabilize essential services, support small businesses, and assist vulnerable populations during the critical days immediately after flooding occurs.

Speed matters after disasters. Delays in recovery funding often translate into prolonged economic hardship for communities already under strain. Parametric insurance policies can deliver payments within 30 days, or less, when the funds are needed the most.

The legislation also emphasizes education, outreach, and transparency. Participating communities must describe how they promote flood insurance awareness, encourage mitigation efforts, and communicate clearly about how these products function alongside traditional coverage. These provisions recognize that resilience begins with understanding what's at risk.

The insurance industry has long played a foundational role in supporting economic growth and recovery following catastrophic events. As risks evolve, innovation in risk transfer and resilience financing will increasingly become important complements to infrastructure investment, stronger building standards, and disaster mitigation programs.

Public-private collaboration will be critical to narrowing the protection gap. Legislation like the Community Flood Resilience Act demonstrates how policymakers can encourage innovation while strengthening community preparedness and preserving the role of insurance in supporting economic resilience.

Resilience is built before disasters through smarter planning, stronger mitigation, and broader financial protection. Public policy that improves flood insurance participation and accelerates recovery better protects homes and businesses, and promotes the long-term economic stability of communities across the country.

As flood risk expands beyond traditional geographic boundaries, policymakers need tools that strengthen both physical resilience and financial preparedness. The Community Flood Resilience Act is a practical way to do both.


Adrian Hall

Profile picture for user AdrianHall

Adrian Hall

Adrian Hall is CEO US for Swiss Re Corporate Solutions.

He is also a member of the Swiss Re Corporate Solutions global executive committee and a board director for Swiss Re Corporate Solutions America Insurance.

Previously, he was the managing director & head, UK, Ireland, South Africa and EMEA Wholesale, and CEO & Chief, Agent Canada, for Swiss Re Corporate Solutions. An insurance industry veteran with over 30 years of experience, he has lived and worked across five continents.

Hall holds a bachelor of science degree in business from University of Wales, Swansea and a master’s certification in marketing leadership from York University, Schulich Business School, Canada.

The Ghost in State Farm's Machine

State Farm's sweeping cuts to agent compensation signal how private equity thinking now shapes even mutual insurers' operating models.

Ghost in the Machine

State Farm just told 19,000 captive agents the deal has changed. Deferred compensation? Gone. Health benefits? Reduced. Renewal commissions? Squeezed in favor of new-business production.

State Farm is a policyholder-owned mutual—the largest in the country—not a private equity play. Yet the announcement reads like it came straight out of a KKR, Apollo, or Blackstone operating playbook.

For decades, State Farm's model rested on a simple premise: a book of business is not self-sustaining. It requires labor. Agents weren't just selling policies; they were maintaining them—fielding calls, resolving issues, retaining customers, spotting risks before they became claims. Renewal commissions weren't a bonus. They were the operating system.

But operating systems get deprecated.

Every generation redraws the line between labor and leverage, between what requires a human and what can be systematized. The real question isn't whether people add value. It's whether they add the same value they once did—and whether that value supports the same cost structure.

Seen through that lens, State Farm's move wasn't surprising. It was inevitable.

Three forces have been quietly closing in.

First, competition. Progressive and GEICO operate without an agent-heavy cost base. They built direct models—leaner, faster, less sentimental. As they gained share—Progressive recently passed State Farm as the top writer of auto policies in the US—State Farm was forced to respond.

Second, management migration. Over the past two decades, executives have moved through private equity portfolio companies, internalizing a shared language—almost a mantra—of efficiency, productivity, and return on capital. What was once distinctive to private equity is becoming simply how management thinks.

Third, AI. Service calls, billing questions, renewals, first notice of loss—tasks that once justified large workforces and long-tail commissions—are increasingly handled by software that doesn't sleep, doesn't churn, and declines in marginal cost over time.

This doesn't make human agents obsolete. It makes legacy compensation models obsolete.

Human value doesn't disappear, it concentrates in complex cases, edge scenarios, trust, judgment—the hard stuff. But the routine? The repeatable? The predictable? That's already slipping out of human hands.

The private equity approach asks a relentless question of every line item: if we were building this today, would we pay for it this way? That question is destabilizing inside legacy models, because once you ask it honestly, a lot of "strategic investments" start to look like habits. And habits, over time, get expensive.

So this isn't a story about private equity taking over State Farm. It's something more consequential: the normalization of a worldview private equity helped industrialize. Nothing is sacred—except the spreadsheet. Every cost is conditional. Yesterday's logic expires faster than anyone wants to admit.

Cost cutting is the easy part. Plenty of companies are doing that—and calling it strategy.

The harder move is what comes next: reinvesting those savings to build something better. Better experiences. Stronger capabilities. New forms of growth that justify the disruption.

In the end, the winners won't be those who simply get leaner. They'll be the ones who get smarter about where humans still matter—and ruthlessly disciplined about where they don't.

That's the real ghost in the machine.


Riv Arthur

Profile picture for user RivArthur

Riv Arthur

Riv Arthur is a business leader and technologist working in insurance, healthcare, and private equity.

It's a Wired, Wired, Wired, Wired World

As sensors have demonstrated during the World Cup, the globe is becoming so wired that it's possible to spot earthquakes, wildfires, and floods in time to mitigate harm.

Image
Early Warning

When Norway won games during the World Cup, so many people jumped up and down that earthquake sensors picked up tremors in Oslo. The same was true when Mexico won games; tremors were detected in Guadalajara and other parts of the country. 

That's some impressive fan support. Vamonos, Mexico! Dra til, Norge!

But detecting the tremors also required some very impressive sensors — of the sort that can help insurers increasingly head off injuries and property damage from earthquakes, wildfires, and floods by giving people advance notice of the impending trouble.

Let's have a look. 

Earthquake sensors are top of mind for me because of the devastating quakes in Venezuela and because of the 5.6-magnitude quake in late June that shook parts of Northern California where I lived until recently. 

Sensors in Google phones managed to alert more than 11.4 million people in Venezuela that a major earthquake was coming, at least several seconds before they felt the impact, according to the New York Times, and as much as two minutes ahead of time. It's not clear how many lives were saved and injuries prevented — and the losses were devastating, with nearly 4,500 deaths confirmed from the 7.2- and 7.5-magnitude earthquakes — but many people surely managed to protect themselves by quickly taking cover. 

What Google is doing is intriguing, and potentially a model for other alert systems. Google has turned all its phones into sensors that take advantage of the fact that earthquakes create two types of waves, as part of a system that is available in nearly 100 countries. One type (P-waves) travels very fast but does little damage. The other (S-waves) does the vast majority of the damage but travels significantly more slowly. Google's phones detect the fast-arriving P-waves as they travel through the ground, and, when Google sees all phones in an area lighting up at once, it knows S-waves and rumbling are coming. 

It's rather like thunder and lightning. Google's phones see the lightning and can tell people that thunder is coming. (The obvious difference being that, in the case of earthquakes, the damage comes after the alert, while lightning is both the alert and the cause of damage.)

The systems don't necessarily provide a lot of warning. P-waves travel at 5-6km/sec, while S-waves spread at 3-4km/sec. So you'd need to be perhaps 20 miles away from the epicenter to get five seconds of warning. People will need to be educated about what to do with those five seconds (drop, cover and hold on) and become accustomed to the idea of alerts, so they don't freeze when the warnings arrive. 

But the sensor network could still get a lot of people away from whatever might fall on them, even with little advance notice, and prevent other damage, too. A woman I know was on an on-ramp for I80 in Berkeley when the Loma Prieta earthquake hit Northern California in 1989. The on-ramp collapsed, dropping her 30 feet onto a pile of rubble. The collapse not only totaled her car, of course, but had her in and out of surgery for years, and left her traumatized from knowing how many people were crushed beneath her. With just five seconds notice, she would have been able to pull off the road and stop short of the elevated roadway. 

In the recent California quake, the governor's office bragged that the state's new early warning system had alerted more than 1 million residents before the shaking started in their area, drawing on feeds from some 600 sensors installed around the state. The system is also available in Oregon and Washington, and Apple offers a similar sort of alert system, drawing on sensors that others have installed.

Insurers don't have a role to play in the development of networks like Google's and don't have to help with the sort of deployment of hard-wired sensors like those in California, but they can certainly assist with the education. Those that do will not only reduce injury claims but will earn good citizen points. At a time when insurers are looking for ways to engage with policyholders more often — not just when collecting premiums or paying claims — offering education about how to protect yourself seems like a promising avenue.

Sensors that can detect wildfires before they get out of control are likewise becoming far more sophisticated and are being deployed on the ground, in the air, and in satellites. Personally, I'm most intrigued by what's happening with satellites, both because they can cover nearly unlimited territory, almost minute by minute, and because I believe in having others do as much work for me as possible. 

Google doesn't sell its phones on the basis that they'll detect earthquakes. People buy the phones for the obvious reasons, then Google adds a bit of software, et voila! A detection network is suddenly deployed. I think the same potential is there to add wildfire detection capabilities to the thousands of low-earth satellites that Elon Musk and others are deploying to facilitate communications. Let them pay for the expensive hardware and the launch, then add a camera and other forms of sensors that can look down and spot even small fires.

Floods, thus far, require dedicated networks of sensors, but there's progress there, too, as Houston is showing. Cities are installing small, inexpensive sensors that monitor water levels constantly, which usually providing hours of warning about developing floods. Cities can also warn motorists in real time to avoid underpasses where water has collected. 

Because these networks of sensors can't just be piggybacked onto other hardware, progress can be slow — adoption remains spotty, for instance, in Central Texas even in the wake of the disastrous flood a year ago that killed 130 people, including 25 young girls and two counselors at a summer camp. But the technology is there and will continue to make inroads.

A rule of thumb I developed some years ago now, as part of what I call the Laws of Zero, is that you can assume that any bit of information you want will be available to you at what looks like zero cost (compared with today) if you look down the road a ways. 

The concept is me looking for areas outside computer chips where the magic of Moore's law can apply. Moore's law — essentially, that the power of a computer processor doubles every year and a half to two years at no increase in cost — means that a unit of computing power that cost a dollar in 2000 costs roughly 1/600th of a penny today. So, free (almost) for anyone making long-range plans in 2000.

I won't go into all seven of the areas I identified, but it's pretty easy to see how sensors fit the Laws of Zero pattern. Moore's law will drive the cost of the computing and any memory toward zero. WiFi and satellite connectivity are becoming ubiquitous, so there's no marginal communication cost. Batteries are also plunging in cost, and many sensors won't even need them, either because they can use solar power (whose cost is heading toward zero) or because they're built into bigger systems such as Google phones or Starlink satellites. 

The Law of Zero about sensors means we will keep seeing progress. Insurers won't even have to pay for that progress. They can just piggyback on what others are doing, then help policyholders understand how to take advantage of the progress — reducing claims while earning good will.

In the meantime, if you aren't watching the France-Spain World Cup semifinal this afternoon, or at least sneaking the occasional peak while at work, I'll bet you'll be able to tell the result if you have access to seismograph readings from Paris and Madrid at 5pm or so Eastern time. 

Cheers,

Paul

 

 

A Founder's Guide to Surviving Investor Rejection

At 66, a cybersecurity veteran trades retirement planning for startup building and learns that success doesn't depend on yeses; it requires "not no"'s. 

Walking a high wire

One of my favorite movie scenes comes from "Volunteers."

Tom Hanks is trying to negotiate with a local warlord. Standing nearby is the warlord's beautiful bodyguard—whose command of English is somewhere between nonexistent and interpretive dance. Tom flashes a grin that suggests he'd be perfectly happy if she happened to be part of the bargain.

The warlord responds with something to the effect of, "If I say yes… and not no…"

I honestly don't remember exactly how the scene ended. What I remember is what popped into my own head.

I'd settle for not no.

At the time, it was just a funny line. Thirty years later, after more investor meetings than I care to count, I finally understand why it stuck with me.

Founders spend years chasing "yes." Investors rarely give you one. Instead they say…

"Interesting."

"Come back after revenue."

"Let's reconnect in six months."

"We'd like to see your next release."

"Keep us posted."

None of those are yes.

But they aren't no.

If you're building a company, you eventually realize that companies aren't built on yes.

They're built on not no.

The High Wire

Being a founder is the proverbial high-wire act. There's no safety net. No guarantee. No instruction manual.

People love talking about entrepreneurial risk. Let me save you some time. It's all risky.

The right decisions.

The wrong decisions.

The crazy decisions.

Sometimes you don't know which one you made until two years later.

Then there are the mornings.

3 a.m.

Every.

Single.

Morning.

Not because the alarm went off. Because your brain did.

There's always one more investor to research.

One more slide to improve.

One more grant proposal to edit.

One more feature to design.

One more email to send before the day job begins.

People think founders work 80-hour weeks. The truth is… founders never really stop working. The company follows you to bed. It wakes up before you do.

And then there's that feeling. If you've ever built a company, you know exactly what I'm talking about. That knot in the pit of your stomach. It never completely goes away. It's there when you wake up. It's there during investor meetings. It's there while you're brushing your teeth. It whispers the same questions over and over.

What did I forget?

Are we going to make it?

Am I asking my family to believe in something impossible?

Is this the dumbest thing I've ever done… or the smartest?

I've come to think of it as the founder's tax. Nobody talks about it. Everybody pays it. Some people call it stress.

Founders call it Tuesday.

Venture Capitalists and Sea Turtles

One of my favorite startup metaphors comes from Silicon Valley.

Ron LaFlamme, the eccentric attorney, explains venture capital using sea turtles. Sea turtles lay hundreds of eggs because only one or two eventually make it to the ocean.

"That's what Peter Gregory is doing," Ron explains. "Making sure one or two of his compression plays make it to the sea."

The first time I heard that I remember thinking,

"Why not just pick stronger turtles?"

Of course, that's not how venture capital works. They're playing portfolio math. Fund enough companies and one eventually becomes the next Google.

They're not looking for certainty. They're looking for outliers.

Founders don't have that luxury.

Most of us get one turtle.

One company.

One dream.

One shot.

It's amazing how differently you look at risk when you're carrying your only turtle.

Government Grants: The Ultramarathon

If raising venture capital is a marathon… government grants are an ultramarathon.

Uphill.

Into the wind.

Dragging a filing cabinet behind you.

You spend six weeks writing.

Three weeks editing.

Two weeks wondering whether Requirement 3.2.17(b) means exactly what you think it means.

You finally hit "Submit."

Then… absolutely nothing.

Weeks become months.

Months become more months.

Eventually an email arrives.

Your pulse quickens.

Your palms get sweaty.

You open it.

"Thank you for your interest…"

That's government-speak for, "Better luck next time."

The amazing part?

You immediately start writing the next proposal.

Founders are funny that way.

The government didn't invent persistence.

Entrepreneurs did.

Accelerators

I actually like accelerators.

Some of them.

Many provide genuine value.

They introduce founders to investors.

They surround you with experienced entrepreneurs.

They shorten the learning curve.

Some absolutely earn the equity they receive.

Others…

Well…

Let's just say the first image that came to my mind was a skinny kid explaining proper deadlifting technique to a professional bodybuilder.

It made me laugh.

Mostly because I've been there.

Now before anyone gets offended…

No, I don't know everything.

Far from it.

But this ain't Marine Corps boot camp.

I don't need somebody teaching me how to polish my boots. I've spent decades leading soldiers, briefing executives, running cybersecurity organizations, and solving difficult problems. Teach me something I don't know. Introduce me to someone I couldn't otherwise meet. Open a door that's been closed. Challenge my assumptions.

That's acceleration.

Teaching me how to center a title on a PowerPoint slide? Not so much.

Now, to be fair, accelerators usually introduce you to investors. Of course, they don't do it out of the goodness of their hearts. They generally take a slice of your company.

Sometimes it's a reasonable slice.

Sometimes…

It's a fat butcher's slice.

Every founder has to answer the same question.

Was it worth it?

If the answer is yes… great.

If not… that was one expensive PowerPoint lesson.

The Founder's Retirement Plan

Somewhere along this journey I stopped looking at my investment portfolio as retirement.

I see software development.

Advertising.

Patent attorneys.

Trade shows.

Cloud hosting.

Developers.

My financial advisor sees diversification.

I see operating capital.

Retirement?

I'll think about retirement after Version 5.0 ships.

Every now and then I tell Suzanne we're flying first class to the Maldives for a week of scuba diving.

Just as soon as…

well…

just as soon as we can afford a margarita machine.

Fans of "Silicon Valley" will appreciate that reference.

Everyone else probably thinks I've developed an unhealthy obsession with frozen drinks.

They're not entirely wrong.

The funny thing about founders is that we stop measuring wealth the way everyone else does.

A new car?

That's six months of development.

Kitchen remodel?

Marketing budget.

Vacation?

Another developer.

People ask how founders keep funding their companies.

Simple.

We stop thinking about assets.

We start thinking about runway.

Yin and Yang

People ask what it's like to build a company with my wife. The answer usually surprises them. We work remarkably well together.

Mostly because we work remarkably well apart.

Ron LaFlamme would probably describe us as yin and yang.

That's us.

I'm the dreamer.

Suzanne is the realist.

I see possibilities.

She sees details.

I chase ideas.

She quietly points out the 17 reasons one of them probably won't work.

She's usually right.

Long before software, we bought a short-term rental.

The number one comment from our guests wasn't the location.

It wasn't the view.

It wasn't the amenities.

It was one word.

"Immaculate."

That's Suzanne.

If NASA hired her, astronauts would dust the launch pad before liftoff.

She has standards that make hotel inspectors nervous.

Thank goodness.

Somebody has to.

Every founder needs someone willing to ask,

"Are you sure?"

Not because they doubt the dream.

Because they want the dream to survive.

People celebrate founders.

They should spend more time celebrating the people who quietly make founders better.

The Turtle on the Fence Post

There's an old saying: "If you see a turtle on a fence post, you know it didn't get there by itself."

How he got up there is anybody's guess.

Yes…

I'm mixing metaphors.

It's my article.

Besides, if you've ever started a company, you know reality stopped making sense a long time ago.

You stop measuring life normally.

Your retirement account becomes software development.

Vacation becomes cloud hosting.

Credit cards become temporary venture capital.

Your dog starts recognizing the Amazon delivery driver by first name.

Normal people call this insanity.

Founders call it product-market fit.

The truth is, nobody builds a company alone.

Somebody always believed.

Somebody always introduced you to someone.

Somebody always opened a door.

And if you're lucky enough to succeed… maybe someday you'll become the person holding the door open for the next founder trying to get through.

That's a legacy, too.

Why 66?

People may someday ask me a simple question.

"Why did it take until you were 66?"

It's a fair question.

The funny thing is…

I don't think I waited until I was 66 to become a founder.

I think I spent 40 years accidentally preparing to become one.

The Army taught me leadership.

It also taught me that no plan survives first contact.

Corporate America taught me patience.

Cybersecurity taught me skepticism.

Attackers adapt.

Technology changes.

Certainty is usually an illusion.

Marriage taught me partnership.

Investors taught me persistence.

Government grants taught me humility.

And rejection…

Rejection taught me that success usually belongs to the person willing to hear "no" one more time than everyone else.

Looking back, every assignment, every promotion, every setback, every impossible deadline, every deployment, every conference room, every board presentation, every sleepless night somehow led here.

Maybe the company wasn't waiting for me.

Maybe I was waiting to become the person capable of building the company.

The Founder Nobody Sees

People see the pitch.

They see the product.

They see the trade show booth.

They see the LinkedIn announcement.

What they don't see… is the founder sitting at the kitchen table at 3 a.m. trying to get two hours of work done before heading to the day job.

They don't see weekends disappear.

They don't see vacations turn into strategy sessions.

They don't see the credit card bill arrive.

They don't see another investor politely explaining why your company isn't quite ready.

They don't see the quiet conversations between spouses.

"Can we keep doing this?"

"How much longer?"

"Are we crazy?"

The answer, by the way… is yes.

Founders are a little crazy.

Thankfully.

If they weren't, most companies would never exist.

Looking Forward Instead of Backward

At 66, something changes.

You stop asking,

"How much money can I make?"

You start asking,

"What am I going to leave behind?"

Money is nice.

Don't misunderstand me.

I'd love to stop looking at every block of stock in my retirement account as another software release or another attorney.

I'd love to finally buy that margarita machine.

I'd really love to take Suzanne to the Maldives and spend a week underwater instead of under deadlines.

But that's not why I'm doing this.

If our company succeeds, I hope my legacy isn't the software.

I hope it isn't the patent.

I hope it isn't the valuation.

I hope it's the organization that never became tomorrow's headline because somebody finally started looking through the windshield instead of the rearview mirror.

For decades, cybersecurity has become remarkably good at explaining yesterday.

Yesterday's ransomware.

Yesterday's phishing campaign.

Yesterday's breach.

Yesterday's lessons learned.

Those things matter.

But they're history.

I've always believed we could do more.

What if we could help organizations think about tomorrow?

Not with certainty.

Not with magic.

Not with a crystal ball.

Just disciplined analysis.

Patterns.

Trends.

Probabilities.

Enough information to make one better decision before the next attack arrives.

If we accomplish that… then every sleepless night was worth it.

Every rejection.

Every investor meeting.

Every government grant proposal.

Every conference.

Every dollar we invested instead of spending on ourselves.

Worth it.

The Last Word

The funny thing about entrepreneurship is that people think the story ends when an investor finally says yes.

It doesn't.

That's just the next chapter.

The real story is everything that happened before anyone believed.

The three o'clock mornings.

The knot in your stomach.

The day job that funded the dream.

The spouse who quietly kept believing.

The people who opened doors.

The investors who didn't say yes… but thankfully didn't say no, either.

Today we're still building.

Still pitching.

Still applying.

Still hearing,

"Come back later."

We're still looking at retirement accounts and seeing software development.

We're still laughing about margarita machines.

We're still dreaming about the Maldives.

We're still walking the high wire.

And after all these years…

I'd still settle for…

not no.

Because every once in a while…

"not no" becomes "yes."

Epilogue

Or maybe just the quiet refusal to quit.

Every founder needs something that carries them through the investor meetings, the rejection emails, the three o'clock mornings, and that knot in the pit of the stomach that never quite goes away.

Keep walking.

Keep building.

Keep believing.

Because every once in a while…

one little turtle actually makes it to the sea.

I'm fortunate.

When I need a reminder to keep going, I don't have to look very far.


Timothy O'Neil

Profile picture for user TimothyO'Neil

Timothy O'Neil

Timothy S. O’Neil, CISSP, CEH, is president and founder of AigisPoint Predictive Intelligence

A retired U.S. Army lieutenant colonel with more than 25 years of cybersecurity leadership experience, he has held senior security architecture and information security leadership roles across the healthcare, insurance, telecommunications, and consulting industries. He is the developer of the Strategic Predictive Threat Intelligence (SPTI) platform, designed to help organizations and cyber insurers anticipate emerging cyber threats before they become losses. 

Insurance AI Needs a Policy Preview Layer

Insurers can use AI to reduce manual review but only when human oversight is built into the workflow before documents reach customers.

AI Policy

As organizations adopt artificial intelligence (AI) in regulated industries, they face significant risks when validation mechanisms are not built into these systems, leading to compliance, legal, and reputational exposure. Having previously worked in technology for financial services, I can attest that there were many occasions when the technology organization was faced with the dilemma of whether to bring solutions to market quickly or in a manner safe for customers and shareholders. It is critical to establish the right balance to secure governance, while pushing the barriers to AI access in the enterprise. My current role requires me to analyze and deliver a process workflow to preview and validate policy documents.

Industry Context: Why Safe AI Matters

AI enhances productivity, speeds up decision making, and lowers costs. Yet, there are always auditors and governed policies in insurance and banking institutions for every policy document, or every autonomous decision — any deviation from expected outcomes can trigger regulatory scrutiny. Making a mistake is no longer seen solely as a technical problem, but rather as a legal or reputational case, security breaches, or people losing their money. I have observed this in cases where banks and insurers use AI to generate automated outputs, process complex tasks, detect anomalies, and reduce costs. Without proper governance, AI can amplify risks instead of reducing them.

My Approach: Designing Preview Architecture

Here is the approach I implemented. My intent was to develop an end-to-end policy documents ecosystem with the ability to AI-preview and AI-validate every incremental change before hitting the "go" button. In practice, I conceptualized the approach as a coherent journey:

  1. Document Generation: The policy documents are generated by our core systems in various formats (PDF, JSON, image).
  2. Staging and Preview: The documents are not delivered to the final destination but are first routed to a secure bucket. The documents are staged in a "preview" in which no changes happen to the customer record until validated.
  3. AI-Driven Validation: We run a comparison model using AI on the documents in the staging area. The model compares any inconsistency between the contents of the new policy and approved templates or data sources.
  4. Controlled Release: The system only allows final release if everything is checked out. Any discrepancies trigger alerts for manual review.

In this architecture, a separate preview layer is created where AI can operate independently and not interfere with the production servers, and gives the compliance teams the ability to look at every AI finding before changing the modus operandi of the business. This flexible approach supports complicated data environments where data can be captured across many different sources, from cloud software to outdated systems to manual data logging. This workflow ensures that all artifacts are consolidated and validated by AI before release (Figure 1).

Technical Insights and Implementation

The implementation uses cloud-based object storage (such as AWS S3), where each preview package is an immutable artifact. This allows downstream controlled processing exclusively to authenticated content. In practice, orchestration was accomplished using serverless functions (AWS Lambda), and AI-based document comparison runs as a separate service. The choice of a particular AI model architecture — not because of current AI market trends — lets us explain our decisions, as explainability was one of the requirements provided to us in advance by the regulator.

Auditability and logging were present throughout the whole implementation. Events and statistics of every process step are present on our monitoring platform, and metrics such as latency per document, exact detection rate, and percentage of documents sent to human validation are tracked and available for monitoring. One result we obtained from the model after integration was a validation detection rate of about 91% (precision on validation samples); false positives account for less than 10% of total detected discrepancies. This was not a guarantee, but a result of multiple validations in production cases with real samples. These statistical metrics allowed us to create visibility and confidence in the AI layer's reliability.

Most importantly, we also built a safety net: AI does not intervene directly. It detects mistakes but does not take any corrective actions itself. No policy can be modified unilaterally by AI. Our policy management system will always be updated in the traditional way, not via our AI layer. In other words, our AI can identify issues but cannot act on them. Approval and action must always occur in our official system or by an appropriate person permitted to undertake that action. We used this rule-based "exit gate" to convey our low-risk profile to the regulators.

Real-World Observations and Lessons

One of the key learnings from this project was reusability. The preview architecture I had designed for one line of business was abstract enough to fit another line of business. That team also used our architecture for their preview. They simply connected to our staging pipeline, dropped their documents in, and hooked into our AI validation pipeline. All hand-offs were defined (secure SFTP links, bucket triggers). The systems worked seamlessly together. Reusability has a multiplier effect — time and effort saved are multiplied across the enterprise.

One last thing to highlight: metrics are essential for adoption. Beyond the perceived savings in operational cost with the AI-preview system (nearly 60%, going from ~$10 to ~$4.80 per case), approximately $1.1M in annual savings from automating the repetitive task (~500 cases/day), and almost no effect on the manual workforce — since they no longer have to review every page, but just focus on identified failures — those strong results allowed us to get quick buy-in from compliance and management teams and to push the solution forward.

I also learned how to tune AI systems effectively. Initially, the system produced too many false positives. If there was a change in formatting of the document, or a small variation on a standard cover letter, we were triggering an alarm. We improved training data, tuned parameters, and reduced the noise. Another important aspect is that we ensured model behavior remained explainable. When an alarm is raised by the AI, it is possible to generate an explanation that is interpretable from the perspective of the regulator or auditor — in other words, a filtered log with all details and a digest automatically generated per alarm.

AI is ubiquitous today, and organizations are asking themselves, "Can we trust AI decision-making in our use cases?" The trust boundary is in the design. AI should be used as a recommendation engine, with clearly defined boundaries. AI should never play the role of sole decision maker. I had an AI-first architecture mindset when building this as a recommendation engine with guardrails. Architect the pipeline once as an extensible platform. The best lesson I learned is to always think platform first. Rather than trying to solve the AI access problem each time there is a new use case, build a standard reusable pipeline. When we deliver a new service such as AI document analytics, we can leverage the existing infrastructure instead of building the service from scratch. It was designed to hook into the existing document preview layer.

My second principle is to "fail fast but safely." We will never make massive changes, but instead pilot workflows, evaluate the results, and scale incrementally. Stakeholders will always be confident that we will catch any divergences early.

Key Takeaways for Practitioners
  • Design for Reuse: Create modular, consistent architecture. A generic preview pipeline can serve multiple teams and use cases, reducing duplication of effort.
  • Isolate AI Analysis: Keep AI processing separate from final system actions. Use staging areas or audit logs so that all AI-suggested changes can be reviewed before going live.
  • Instrument and Measure: Track accuracy, costs, and impacts. Solid metrics (like processing time or error rates) build confidence with stakeholders and guide improvements.
  • Prioritize Explainability: Select models and techniques that let you understand or explain decisions. In regulated settings, a "black box" is too risky.
  • Maintain Human Oversight: Automate the heavy lifting but ensure a human or rule-based review gate for any critical change. This balance preserves both efficiency and control.
  • Iterate and Improve: Begin with a strong baseline score and then enhance it by incorporating feedback. Use initial outcomes to justify an increase in the number of cases/projects and demonstrate progress.

AI does not have to be flawless to be used in regulated environments, but it must be measurable, verifiable, and governed. It should remain explainable, auditable, and never act without human oversight. A preview-based approach makes this possible by allowing AI to operate within a controlled workflow where outputs are visible and validated before they are committed. Start small, measure the impact, and expand gradually — this is how compliance shifts from a barrier into a competitive advantage.


Bhargavi Vepuri

Profile picture for user BhargaviVepuri

Bhargavi Vepuri

Bhargavi Vepuri is a director at Prudential Finance.  

She has led large-scale AI and cloud modernization initiatives focused on operational efficiency, document workflow validation, audit readiness, and regulated enterprise delivery quality.

Resting Heart Rate Reshapes Underwriting

Resting heart rate emerges as a powerful, underused mortality predictor that may outperform traditional underwriting metrics like cholesterol and BMI.

RHR Transformation

In an era defined by expanding data streams and increasingly sophisticated underwriting tools, it is often assumed that better decisions require more complex inputs. However, recent RGA research challenges that assumption by highlighting the value of a familiar, easily measured metric: resting heart rate.

Resting heart rate (RHR) – the number of heartbeats per minute when an individual is at rest – provides a real-time snapshot of cardiovascular efficiency and overall physiological health.

Despite its simplicity, RHR has historically been underused in underwriting frameworks. That gap is now narrowing.

A growing body of evidence points to RHR as a strong independent predictor of all-cause mortality. Recent research has gone so far as to describe it as a "forgotten risk factor," with findings indicating that elevated RHR can outperform traditional measures, such as hypertension, in predicting mortality risk.

Evidence that challenges underwriting conventions

RGA's research reinforces these findings with compelling consistency across populations and datasets. Analysis of UK Biobank data shows a clear and measurable relationship between RHR and mortality outcomes. For example, individuals with higher resting heart rates face significantly elevated mortality risk compared with peers with lower rates, even after adjusting for conventional underwriting factors.

What makes this relationship particularly relevant to insurers is its stability across different segments. The predictive power of RHR holds across:

  • Age groups
  • Sexes
  • Standard and substandard risk classes
  • Individuals with chronic conditions

This consistency positions RHR as more than a supplementary data point. It is a robust, independent factor that captures dimensions of risk not fully reflected in traditional metrics.

In fact, RGA findings suggest that RHR can outperform total cholesterol as a predictor of mortality and may substitute for BMI without meaningful loss of predictive accuracy. These findings challenge long-standing underwriting hierarchies and open the door to recalibrated risk models.

Why RHR captures what traditional metrics may miss

From a physiological perspective, RHR acts as a proxy for several underlying health dimensions, including cardiovascular fitness, autonomic nervous system function, and overall metabolic health. These attributes are not always fully captured by standard underwriting variables.

As a result, RHR provides incremental insight, helping underwriters identify hidden or emerging risks that might otherwise remain undetected.

Equally important is its practicality. RHR is:

  • Non-invasive and easy to measure
  • Routinely recorded in electronic health records
  • Available through medical exams and ECGs
  • Increasingly accessible through wearable devices and smartphones

Advances in photoplethysmography technology have further supported its reliability, demonstrating strong agreement with clinical-grade measurements.

Together, these characteristics make RHR predictive and operationally viable at scale.

From research to real-world application

The shift from academic insight to underwriting practice is already underway. As insurers integrate digital health data into workflows, attention is shifting toward maximizing the value of existing information rather than simply expanding data volume.

Within this context, RHR offers a compelling use case. RGA has begun incorporating RHR into underwriting decisions, including its integration into a facultative underwriting platform designed for complex cases.

This integration enables underwriters to apply evidence-based insights in real time, enhancing consistency and decision quality without introducing additional complexity.

Practical applications of RHR in underwriting include:

  • Refining preferred versus standard classifications
  • Identifying favorable risk within traditionally substandard cases
  • Supporting more proportionate evidence requirements

For example, an applicant flagged as higher risk based on conventional metrics may demonstrate a more favorable RHR profile, enabling a more nuanced – and potentially more competitive – offer.

Strategic implications for insurers

The emergence of RHR as a key underwriting variable has broader implications at the enterprise level.

  • It reinforces the importance of reexamining existing data. In many cases, valuable signals are already available but underused. Unlocking their potential can lead to meaningful improvements in risk selection without significant operational investment.
  • It highlights the growing convergence between underwriting and digital health ecosystems. As wearable devices and remote monitoring tools become more prevalent, the availability of continuous biometric data will only increase. RHR is well positioned to serve as a foundational metric in this evolving landscape.
  • It underscores the need for adaptive underwriting frameworks. Static guidelines may fail to capture emerging sources of insight. Incorporating dynamic, evidence-based metrics such as RHR can help ensure that underwriting remains aligned with real-world risk.
Conclusion: Keeping the industry's finger on the pulse

The case for integrating resting heart rate into underwriting is no longer theoretical. The evidence is robust, the data is accessible, and the operational pathways are clear.

As underwriting continues to evolve, the ability to extract deeper insight from simple metrics will become increasingly valuable. RHR exemplifies this shift, offering a blend of predictive strength, practical accessibility, and strategic relevance.

For insurers, the opportunity is twofold: improve mortality risk assessment while enhancing efficiency and customer experience.

By leveraging RHR more effectively, organizations can move toward more precise pricing, better risk differentiation, and ultimately stronger portfolio performance.

Co-Authors:

Dr. John J. Lefebre - Vice President and Senior Technical Global Medical Director at RGA

John Cardus - Vice President, Head of Global Underwriting Philosophy and Education at RGA

Dr. Guizhou Hu - Vice President, Head of Risk Analytics, Global Underwriting, Claims, and Medical at RGA

Richard Russell - Vice President, Biometric Research, Global Research and Development at RGA

Dr. Nico Vanzyl - Senior Vice President, Chief Medical Director at RGA

References

Kishan Bakrania

Profile picture for user KishanBakrania

Kishan Bakrania

Kishan Bakrania is a lead biometric data scientist with RGA's global research & development team. 

Prior to joining RGA in 2017, he earned a Ph.D. in epidemiology from the University of Leicester. He also holds an M.Sc. in medical statistics and a B.Sc. in mathematics from the University of Leicester.

'But the AI Told Me To Do It!'

As AI reshapes decision-making in insurance, the industry faces a critical question: Who holds liability when algorithms influence consequential outcomes?

AI Liability

I once wrote a presentation called: "It wasn't me. AI told me to do it!"

At the time, it was half joke, half warning.

Certainly feels less comical now.

Every organization adopting AI is moving toward the same uncomfortable question. When an AI-assisted decision causes harm, who carries the liability?

Clearly not the model. Models do not sign contracts, settle claims, bind risks, approve suppliers or accept regulatory responsibility. Maybe not the vendor, whose terms will usually say that you, the customer, remain responsible for how outputs are used. Not necessarily the employee, if they were using an approved tool in an approved process. Not necessarily the committee, if it says it relied on the employee's professional judgment.

Everybody, somebody and nobody.

This is not an anti-AI argument. I use AI. Most of us now do. In most cases it is harmless enough: drafting an email, summarizing a meeting, turning scrappy notes into something coherent. No sensible firm should build a heavy governance process around every prompt. That would be maddening and almost unenforceable.

But some uses are different.

If AI helps tidy up a launch invite, nobody cares. If it helps route a claim, draft an underwriting rationale, influence a supplier decision, interpret a compliance obligation or shape a board paper, then we are in different territory. We are talking about authority.

Insurance already understands authority. A junior underwriter cannot bind whatever they like. A claims handler has limits. A TPA works within a delegated claims authority. A coverholder operates within a binder. If something goes wrong, the questions are familiar: who had authority, what was the limit, was the decision escalated, and where is the evidence?

AI does not change those principles. It just makes them harder to see.

Take claims. An AI tool triages first notice of loss, summarizes the facts and recommends settlement within a low-value authority band. A handler reviews the screen and clicks through. Months later, a pattern emerges: the tool has been routing a class of claims too generously, too harshly, or inconsistently with the carrier's authority schedule.

At that point, the question is not simply whether the model was accurate. It is whether the settlement sat within authority, who accepted it, whether the handler actually reviewed it, and whether the firm can produce a record created at the time rather than a reconstruction after the complaint lands.

The same issue appears in delegated underwriting. An MGA uses AI to draft endorsements, referrals or risk summaries. The final document may still pass through a human. But did the output stay within binder authority? Did the right person approve it? Could a coverholder audit see the trail without piecing it together from emails and meeting notes?

These are not exotic technology questions. They are ordinary insurance questions, just wearing new clothes.

The problem for underwriters is that today's AI conversation is still too blunt. A proposal form might ask, "Do you use AI?" The insured says yes. Another insured says yes. Both attach an AI policy. On paper, they look broadly similar.

But they may be completely different risks.

One firm may let staff paste AI-generated analysis straight into consequential decisions with little more than a policy telling them to be careful. Another may classify the decision, check the user's authority, require escalation, capture sign-off and preserve the evidence. Those firms should not be priced as though they are the same.

At the moment, they might be.

This is because a policy is not proof. Training is not proof. A statement that "humans remain accountable" is useful, but only if you can identify the human, the decision, the authority and the record.

The missing artefact is a decision record.

For an AI-assisted decision that matters, an insurer should be able to ask: who requested the output, what was it used for, did the person have authority, was it escalated where needed, who accepted responsibility, and can the firm prove all this without reverse-engineering the story later?

That last part matters. After a loss, everyone becomes a process expert. People remember the governance policy. They remember the meeting. They remember the human in the loop. But insurance does not work on vibes. It works on evidence.

The answer, in my view, is not more slogans about responsible AI. It is the boring stuff insurance has always understood: authority, escalation, sign-off and evidence.

The 95% of routine AI use should stay fast. Let people summarize, draft and explore. But the consequential minority needs a different track. If an output is going to move money, affect a customer, change a risk position, influence a regulatory judgment or commit the firm, someone has to own it. Not in theory. Not in a policy. In the record.

"It wasn't me. AI told me to do it" may work as a joke in a presentation. It will not work in a claim file.

The firms that can show who made the decision, who had authority and what evidence exists will look different from the firms that cannot. At some point, insurers will price that difference.

The only question is whether they do it before the first major AI-accountability claim forces the issue.

Lessors Underestimate Their Vendor Risk

Multifamily operators have mastered resident risk management, but rising liability costs reveal a dangerous gap in dealing with vendors.

Vendor Risk

The multifamily industry has spent years building sophisticated infrastructure around resident risk. Property managers verify renter income, screen credit histories, track lease compliance, and embed insurance at the point of lease signing.

The logic is sound: a resident who can't pay rent or damages a unit is a known, quantifiable risk.

But walk through any large apartment complex on a given day, and you'll find a different cast of risk actors entirely. Landscapers, HVAC technicians, plumbers, pest control crews, cleaning services – vendors who move across units, common areas, and mechanical systems, often simultaneously across dozens of properties in a portfolio.

These are people whose work directly affects building safety, tenant wellbeing, and operator liability. And yet, the insurance infrastructure built to protect against resident risk has almost nothing to say about them.

That is the blind spot. And in 2026, it's getting more expensive to ignore.

A Liability Environment That Has Fundamentally Reset

The pressure on multifamily operators is no longer theoretical. Insurance has become, in fact, one of the most volatile line items in multifamily operating expenses, with per-unit pass-through cost rising 55% since 2020 and 228% since 2000, according to Federal Reserve data.

What's more: in certain markets, insurance now surpasses $1,200 per unit – making it a defining component of operating strategy, not a background line item.

The liability side is hardening even faster. Since 2020, jury awards exceeding $10 million have increased by more than 300%, according to Marsh McLennan's 2026 Commercial Real Estate Industry Outlook, and the real estate sector has been directly in the crosshairs.

Meanwhile, Sedgwick's 2025 Liability Litigation Commentary found that nuclear verdicts rose 52% in the most recent measured period, with awards over $100 million surging 82% and the average verdict now exceeding $51 million – figures the report attributes to deepening corporate mistrust, third-party litigation funding, and plaintiff-friendly venues. Real estate consistently ranks among the most exposed sectors.

These figures are not driven solely by resident behavior. Many of the conditions that trigger massive claims – unsafe worksite practices, improperly completed repairs, workers without active coverage – trace directly back to the vendor layer.

What makes vendor-related claims particularly dangerous is their legal complexity. When a third-party vendor causes an injury, tenants frequently name the property management company, the property owner, and the vendor in the same lawsuit; managers who assume the vendor is entirely at fault often discover that premises liability law doesn't work that way.

In sum, without verified insurance and airtight contract language in place, operators absorb losses they didn't cause.

The Document Collection Problem

The industry's default response to vendor risk has been the certificate of insurance: collect a COI before work begins, file it, move on. It's a reasonable first step that has calcified into a false finish line.

A certificate of insurance is proof of coverage – not a guarantee. COIs are point-in-time snapshots; they don't update automatically when policies lapse, get canceled, or have coverage limits reduced mid-term.

According to the Certificial 2026 Insurance Requirements Benchmarking Report, which analyzed 291 supplier insurance requirement sets, critical endorsements like Completed Operations – required by 84% of property management programs – are among the most frequently misconfigured or missing elements in vendor COIs.

In most cases, these gaps go undetected because there is no systemic process for verifying what a certificate actually contains against what a contract requires.

At scale, this compounds quickly. Most management teams treat vendor compliance as a documentation problem but in reality, it is a lifecycle control problem. Compliance failures rarely occur because a document is missing; they happen because vendor management lacks continuous enforcement across onboarding, renewal, and active work.

A portfolio operator managing 50 properties, for example, might have 500 or more active vendor relationships at any given time; a single uninsured contractor working across 30 of those properties is a systemic risk.

An Underwriting Blind Spot

What makes this particularly striking from an insurance perspective is how unevenly attention has been distributed. The industry has built robust frameworks for underwriting resident risk – income ratios, credit tiers, claims history, even behavioral data. Embedded insurance at lease signing has matured into a genuine distribution channel.

Vendor risk, by contrast, barely registers as an underwriting input. Industry guidance for multifamily owners consistently notes that owners should have controls put in place with their vendors to maintain liability coverage, with strong contract language to facilitate the transfer, but this remains largely an operational recommendation, not something that meaningfully informs how liability coverage is priced or structured at the portfolio level.

The result is a coverage architecture that is sophisticated on one side and nearly invisible on the other.

Insurers pricing multifamily liability are doing so with limited visibility into the vendor ecosystems operating across those properties. This is thus a pricing problem as much as it is an operational one; liability claims in the U.S. have surged by 57% over the past decade, yet the risk inputs driving those claims at the property level remain largely unmeasured.

What Enforcement Actually Requires

Leading property management firms are moving from reactive compliance to proactive automation: integrating COI tracking into vendor workflows, moving away from spreadsheets to centralized systems, and adopting audit-ready dashboards to stay compliant year-round.

This is progress, but it still addresses the collection problem rather than the enforcement problem. Real vendor risk management, meanwhile, requires something more active: knowing when a vendor's scope of work exceeds their policy limits, holding payment when coverage lapses, flagging when contract terms trigger downstream insurance requirements.

These are not document management functions; they are risk intelligence functions, and they require infrastructure that treats vendor data as an operational input, not a filing task. The recent combination of insurance compliance infrastructure with vendor contract management and spending intelligence points to where the market is heading: a platform where rules are defined once and enforced continuously – across residents and vendors alike.

It is an acknowledgment that the compliance perimeter for a multifamily operator does not stop at the lease.

The broader industry, therefore, will need to reach the same conclusion. As liability costs continue to climb and jury awards grow, operators who treat vendor risk as an afterthought will face a reckoning that the COI in their files won't protect them from.

The blind spot has a price tag – and it's rising.