The latest wave of technology is in generative AI. Nearly every organization is racing to adopt it. Aggregated responses from surveys from 2022 and on by the NAIC show how far the race has run in the insurance sector. Considering the participating carriers, roughly 88% of personal auto insurers, 70% of homeowners, 58% of life, and 92% of health report that they use, plan to use, or are exploring AI.
However, a recent MIT study (Project Nanda), its 2025 report, "The GenAI Divide: STATE OF AI IN BUSINESS 2025," based on a review of over 300 publicly disclosed AI initiatives, pointed out that about 95% of corporate generative-AI pilots produced no measurable financial return so far. Also, there is an open concern about return on investment related to AI infrastructure and implementations. This tempers the enthusiasm.
MIT's explanation highlights that the failures were organizational, not technical. The models or underlying technology largely worked. However, the organizations around them did not.
The Barrier Is Data, and Regulators Expect Better
Among various organizational factors, data plays a key role in the success of AI implementations. Data is the foundation for AI.
Recent surveys from major audit firms indicate the same. KPMG's 2026 Q2 AI Pulse survey indicates that 58% of executives across industries and 63% of banking leaders named data readiness and access as the single largest barrier for deploying AI agents, which rely on generative AI models as their foundation. As per Deloitte’s Chief Data and Analytics Officer Survey, 61% of CDAOs consider improving data quality and access key to the success of agentic AI initiatives.
In addition, the data estate is only getting larger, which widens the governance gap the longer it is left unaddressed. Rubrik's report from 2023 "The Journey to Secure an Uncertain Future" states that enterprise data grew about 42% in 18 months and is projected to experience roughly sevenfold growth over five years.
In insurance, operations depend heavily on data such as market analysis, underwriting guides, actuarial reports, risk models and analysis, claims information, etc. As a result, the quality of data is far more important for AI implementations to be successful in the sector.
Start with what regulators now expect. The NAIC's model bulletin on AI and AI Systems Evaluation Tool (currently in pilot) directs insurers to document the data feeding an AI system for currency, quality, integrity, and suitability. New York's Department of Financial Services advises that insurers must not use external consumer data or AI in underwriting or pricing unless they can demonstrate that the data is accurate, reliable, and actuarially valid. Colorado now requires a documented governance and risk-management framework for the data and models insurers use. The common clause is that an AI system is only as reliable as the data beneath it, and regulators expect that data to be current, clean, and suitable.
This is not unfamiliar ground for the industry. Under the NAIC's Model Audit Rule, larger carriers already attest each year that internal controls over their financial data are effective. Hence, data governance is not a new discipline to practice. However, AI is mandating it.
The Insurance Estate Makes It Worse
Now set that standard against reality. If we relate this to the property and casualty insurance sector, the challenge with data could be much deeper. The guidelines, rules, and regulations vary by state. Carriers must stay on top of the continuing changes and comply with them. As a result, a carrier may hold information for longer than intended, considering unforeseen litigation and claimant risks. It leads to sprawl over time. This data could live across systems silently, unattended. Much of it has never been actively governed. It is the kind of data estate the regulatory standards are scoped to rule out.
Point AI at such an estate, and the problem becomes concrete. The model may not be able to differentiate between a draft and the authoritative version. Data may be overshared, which can lead to PII exposure and compliance issues. A claim may need to be assessed against the underwriting or state regulatory guidelines in effect when the policy was issued, not today, and the model has no way of knowing which version applies. It results in serving up obsolete information with the same confidence as reliable material. In a regulated business, the wrong answer isn't about helpfulness; it's about the implications later an organization may have to defend. Recently, shared AI conversations from multiple platforms have turned up in public search results, a clear example.
A key fact to remember: Organizations are increasingly held responsible for their AI's outputs, much as they are for their employees' actions. This brings an additional responsibility for organizations to feed in quality data.
Records Readiness Is AI Readiness
So, the key foundation for AI implementation is not the model. It is the data the model relies on. In records and information management terms, AI readiness is records readiness, and it relies on a few well-defined guidelines established long before today's excitement.
Know your estate. None of this is new; regulators have expected disciplined recordkeeping for years. It starts with knowing your data landscape. An organization cannot govern, secure, or safely expose to AI what it has never inventoried. That means locating where records live, including every source relevant to the organization.
Reduce the ROT. Auditable disposition- cleaning the redundant, obsolete, and trivial through a documented, rule-based process- reduces the estate the AI reads. Unaddressed ROT can lead to incorrect risk assessments and expose PII.
Classify and set retention. Define the guidelines and publish the retention schedule. Associate required or relevant metadata with the content. Enforcing retention is a must. Structuring the data and governing it with information management guidelines ensures the AI draws on the authoritative version rather than an accidental copy, and it keeps the estate aligned with the retention obligations insurers already carry.
Assign ownership. People move on, but not data. Unowned data results in ungoverned data, and ungoverned data is what sabotages the pilot. Someone must be accountable for each significant data domain, the same way someone is accountable for the financial controls the Model Audit Rule already requires.
Limit the data the AI is enabled on. Assess the objectives of the AI agent being built. Feed in only the required content adhering to established regulatory and compliance guidelines. Periodically certify the usage.
In general, projects start by defining the end objective, considering the technology or model capabilities, and focusing on adoption. Consideration of the current state of data is often skipped. Yet it is the difference between the organizations that fall to MIT's 95% and the few that reach real value. The carriers succeeding with AI adoption will not be the ones with the most advanced model or first to adopt. They will be the ones with a clean data estate. Organizations must document the data estate, dispose of the ROT, govern the records, and only then turn the AI on targeted data it can trust.
Buy the model second. Fix the data first.
References
- MIT, "The GenAI Divide: State of AI in Business 2025" (Project NANDA): https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/
- NAIC AI/ML adoption surveys: https://content.naic.org/insurance-topics/artificial-intelligence
- NAIC Model Bulletin on the Use of Artificial Intelligence by Insurance Companies: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf
- NY DFS Insurance Circular Letter No. 7 (2024): https://www.dfs.ny.gov/industry-guidance/circular-letters/cl2024-07
- Colorado Division of Insurance Regulation 10-1-1: https://doi.colorado.gov/announcements/notice-of-adoption-amended-regulation-10-1-1-governance-and-risk-management-framework
- KPMG AI Quarterly Pulse Survey Banking Q2 2026: https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2026/banking-aipulsesurvey-q2.pdf
- KPMG AI Quarterly Pulse Survey Q2 2026: https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2026/aipulsesurvey-q2.pdf
- 2026 Chief Data and Analytics Officer (CDAO) survey: https://www.deloitte.com/us/en/about/press-room/chief-data-and-analytics-officer-survey-finds-cdaos-acting-as-ai-trailblazers.html
- RUBRIK The state of data security (2023): https://www.rubrik.com/content/dam/rubrik/en/resources/report-review/rpt-rzl-journey-to-secure-an-uncertain-future.pdf
