Download

Why Insurance Tech No Longer Guarantees Competitive Edge

As technology becomes commoditized across insurance, trust and human capabilities may emerge as the industry's next competitive differentiators.

Compet Advantage

What happens if, five years from now, almost every insurer has access to similar artificial intelligence capabilities, comparable digital services, similar data and increasingly standardized products?

For many companies, that future has already arrived.

And if technology can no longer guarantee differentiation, the insurance industry must ask itself an uncomfortable question:

What will we compete on?

The Era of Great Convergence

For decades, insurers competed through products, distribution networks, scale and technological capabilities. Today, many of those advantages are rapidly losing their uniqueness.

Technologies that were once available only to the largest players are now accessible to almost everyone. Cloud solutions, artificial intelligence, digital claims handling, advanced analytics and automation are increasingly becoming industry standards.

The same is happening with products. In many segments of insurance, it is becoming harder and harder for customers to understand how one company is fundamentally different from another.

Barriers to entry are falling.

The speed of imitation is increasing.

Traditional sources of competitive advantage are weakening.

This does not mean that technology has become less important. Quite the opposite. Technology has become essential.

But essential does not mean unique.

From Innovation to Hygiene Factor

Ten years ago, a mobile app was a sign of innovation.

Today, not having one is often seen as a sign of technological backwardness.

The same pattern is emerging across the industry. What created competitive advantage yesterday is quickly becoming a basic market expectation today.

Artificial intelligence, process automation, digital claims handling and advanced analytics are all moving from the category of "competitive advantage" to the category of "minimum requirement."

The Commoditization Trap

When customers no longer perceive meaningful differences between insurers, competition almost inevitably shifts toward price.

This is one of the most dangerous positions any industry can find itself in.

Price competition erodes profitability, weakens underwriting discipline and limits the industry's ability to invest in future capabilities.

More importantly, insurance risks becoming a commodity.

If customers can compare dozens of offers in minutes, switch providers with minimal friction and receive a similar digital experience almost everywhere, a fundamental question emerges:

Why should they choose you?

What Does a Real Competitive Advantage Look Like?

A competitive advantage has one important characteristic: it is difficult to copy.

If it can be purchased from a software vendor, it is probably no longer a competitive advantage.

Technology can be bought.

Software can be replicated.

Algorithms can be copied.

Trust, reputation and culture cannot.

The Return of Human Differentiation

We may be entering an era in which insurers once again compete not primarily through technology, but through distinctly human capabilities:

  • trust;
  • reputation;
  • speed of decision-making;
  • organizational culture;
  • quality of claims experience;
  • the ability to operate effectively during crises.

At its core, insurance has always been a business built on a promise.

A promise to be there when people and businesses need support the most.

Customers rarely remember the interface of a mobile app or the number of features it offered.

They remember something else.

Whether they received help after an accident.

Whether the claims process was fair.

Whether the company fulfilled its promise.

The Paradox of Insurance's Future

The paradox of insurance's future may be this: the more accessible technology becomes, the more valuable the things that cannot be bought become.

Trust.

Reputation.

Leadership.

Organizational resilience.

And the ability to deliver on a promise when customers need it most.

Perhaps the greatest competitive advantage of an insurer in 2030 will not be the technologies it uses.

It will be who the company is.


Mykhailo Hrabovskyi

Profile picture for user MykhailoHrabovskyi

Mykhailo Hrabovskyi

Mykhailo Hrabovskyi is a regional director with 17 years of experience in insurance, specializing in business development, innovation, and organizational leadership across Ukraine.

Lessors Underestimate Their Vendor Risk

Multifamily operators have mastered resident risk management, but rising liability costs reveal a dangerous gap in dealing with vendors.

Vendor Risk

The multifamily industry has spent years building sophisticated infrastructure around resident risk. Property managers verify renter income, screen credit histories, track lease compliance, and embed insurance at the point of lease signing.

The logic is sound: a resident who can't pay rent or damages a unit is a known, quantifiable risk.

But walk through any large apartment complex on a given day, and you'll find a different cast of risk actors entirely. Landscapers, HVAC technicians, plumbers, pest control crews, cleaning services – vendors who move across units, common areas, and mechanical systems, often simultaneously across dozens of properties in a portfolio.

These are people whose work directly affects building safety, tenant wellbeing, and operator liability. And yet, the insurance infrastructure built to protect against resident risk has almost nothing to say about them.

That is the blind spot. And in 2026, it's getting more expensive to ignore.

A Liability Environment That Has Fundamentally Reset

The pressure on multifamily operators is no longer theoretical. Insurance has become, in fact, one of the most volatile line items in multifamily operating expenses, with per-unit pass-through cost rising 55% since 2020 and 228% since 2000, according to Federal Reserve data.

What's more: in certain markets, insurance now surpasses $1,200 per unit – making it a defining component of operating strategy, not a background line item.

The liability side is hardening even faster. Since 2020, jury awards exceeding $10 million have increased by more than 300%, according to Marsh McLennan's 2026 Commercial Real Estate Industry Outlook, and the real estate sector has been directly in the crosshairs.

Meanwhile, Sedgwick's 2025 Liability Litigation Commentary found that nuclear verdicts rose 52% in the most recent measured period, with awards over $100 million surging 82% and the average verdict now exceeding $51 million – figures the report attributes to deepening corporate mistrust, third-party litigation funding, and plaintiff-friendly venues. Real estate consistently ranks among the most exposed sectors.

These figures are not driven solely by resident behavior. Many of the conditions that trigger massive claims – unsafe worksite practices, improperly completed repairs, workers without active coverage – trace directly back to the vendor layer.

What makes vendor-related claims particularly dangerous is their legal complexity. When a third-party vendor causes an injury, tenants frequently name the property management company, the property owner, and the vendor in the same lawsuit; managers who assume the vendor is entirely at fault often discover that premises liability law doesn't work that way.

In sum, without verified insurance and airtight contract language in place, operators absorb losses they didn't cause.

The Document Collection Problem

The industry's default response to vendor risk has been the certificate of insurance: collect a COI before work begins, file it, move on. It's a reasonable first step that has calcified into a false finish line.

A certificate of insurance is proof of coverage – not a guarantee. COIs are point-in-time snapshots; they don't update automatically when policies lapse, get canceled, or have coverage limits reduced mid-term.

According to the Certificial 2026 Insurance Requirements Benchmarking Report, which analyzed 291 supplier insurance requirement sets, critical endorsements like Completed Operations – required by 84% of property management programs – are among the most frequently misconfigured or missing elements in vendor COIs.

In most cases, these gaps go undetected because there is no systemic process for verifying what a certificate actually contains against what a contract requires.

At scale, this compounds quickly. Most management teams treat vendor compliance as a documentation problem but in reality, it is a lifecycle control problem. Compliance failures rarely occur because a document is missing; they happen because vendor management lacks continuous enforcement across onboarding, renewal, and active work.

A portfolio operator managing 50 properties, for example, might have 500 or more active vendor relationships at any given time; a single uninsured contractor working across 30 of those properties is a systemic risk.

An Underwriting Blind Spot

What makes this particularly striking from an insurance perspective is how unevenly attention has been distributed. The industry has built robust frameworks for underwriting resident risk – income ratios, credit tiers, claims history, even behavioral data. Embedded insurance at lease signing has matured into a genuine distribution channel.

Vendor risk, by contrast, barely registers as an underwriting input. Industry guidance for multifamily owners consistently notes that owners should have controls put in place with their vendors to maintain liability coverage, with strong contract language to facilitate the transfer, but this remains largely an operational recommendation, not something that meaningfully informs how liability coverage is priced or structured at the portfolio level.

The result is a coverage architecture that is sophisticated on one side and nearly invisible on the other.

Insurers pricing multifamily liability are doing so with limited visibility into the vendor ecosystems operating across those properties. This is thus a pricing problem as much as it is an operational one; liability claims in the U.S. have surged by 57% over the past decade, yet the risk inputs driving those claims at the property level remain largely unmeasured.

What Enforcement Actually Requires

Leading property management firms are moving from reactive compliance to proactive automation: integrating COI tracking into vendor workflows, moving away from spreadsheets to centralized systems, and adopting audit-ready dashboards to stay compliant year-round.

This is progress, but it still addresses the collection problem rather than the enforcement problem. Real vendor risk management, meanwhile, requires something more active: knowing when a vendor's scope of work exceeds their policy limits, holding payment when coverage lapses, flagging when contract terms trigger downstream insurance requirements.

These are not document management functions; they are risk intelligence functions, and they require infrastructure that treats vendor data as an operational input, not a filing task. The recent combination of insurance compliance infrastructure with vendor contract management and spending intelligence points to where the market is heading: a platform where rules are defined once and enforced continuously – across residents and vendors alike.

It is an acknowledgment that the compliance perimeter for a multifamily operator does not stop at the lease.

The broader industry, therefore, will need to reach the same conclusion. As liability costs continue to climb and jury awards grow, operators who treat vendor risk as an afterthought will face a reckoning that the COI in their files won't protect them from.

The blind spot has a price tag – and it's rising.

A Hidden Issue in New AI Laws

New transparency laws mandate AI content marking by Aug. 2 -- but don't ensure end users see those marks.

New Laws

On Aug. 2, the rules change for anyone who makes or moves digital media.

The European Union's AI Act brings its transparency obligations into force that day. If you build a system that generates images, audio, or video, you have to mark the output in a machine-readable way. A downstream system can then tell synthetic media from a camera original. That marking piece is phasing in across the back half of 2026, but the direction is set. The EU's Code of Practice points to C2PA Content Credentials as an example of the kind of marking it has in mind.

On the same day, California's AI Transparency Act hits its core date. Senate Bill 942, as amended by Assembly Bill 853, requires covered content to carry a disclosure. And the statute went further than most people noticed. It says the mark has to be permanent, or extraordinarily difficult to remove, to the extent technically feasible. The platform and hosting anti-stripping obligations follow on Jan. 1, 2027.

Once you put those two laws side by side, the signal is clear: marking is no longer optional, and it is no longer a branding exercise. It is a legal requirement with a date on it.

That is real progress, and the people who built the marking layer earned the credit for it. C2PA, the Content Authenticity Initiative, the standards work that turned provenance from a conference word into a working specification: that is the reason a law can now point at something concrete and say do this. A decade ago there was nothing to mandate, and as a result of these changes, now there is. Cameras now ship that can sign an image at the shutter. Editing tools record what they changed. Major platforms have begun to read and display those credentials. That is a real foundation and it didn't exist a few years ago.

While everyone races to hit the deadline, there's still something left hanging in the balance. A mark is only worth what survives.

The law can require that a piece of content be marked at the moment it is made. So far, there's no mention of whether it requires that the mark still be there when the content arrives somewhere. Those are not the same event. The ordinary path a file takes from where it was created to the screen where someone finally makes a decision about it is where the media trip can split.

Today, that trip is brutal on metadata. A photo gets uploaded, and the platform re-encodes it and strips what it does not recognize. It gets screenshotted, and the screenshot carries none of the original's history. It moves through a content management system, gets resized for the web, passes through a messaging app that flattens it, ends up in a claims portal that saves its own copy. Every one of those steps is routine. Every one of them can quietly remove the mark the law now requires.

An organization can truthfully say it supports content credentials and still ship media that arrives unverifiable. Supporting the standard at the point of creation is not the same as guaranteeing the credential is intact at the point of use. The first is a checkbox. The second is a promise about everything that happens in between, and almost nobody is making that promise yet.

California clearly saw this coming. That is why the statute does not just say mark it. It says the mark has to be permanent, or extraordinarily difficult to remove, to the extent technically feasible. That is not a marking requirement. That is a durability requirement, written into law. It is the legislature telling the market that applying the label is not enough. The label has to hold.

Here is the catch. A statute can require durability. It cannot manufacture it. Requiring that a mark survive distribution does not make the mark survive distribution. That is an engineering result, and at the moment it is an unfinished one.

Marking, the part the law can point at, is largely solved — but again, there is still a big gap. Survival, the part the law now demands, is not. And survival is the harder half, because it is not a standards problem you can close by agreeing on a format. It is an architecture problem. It asks a different question. Not how do we label origin, but what still holds after the content has been through the tools real people use every day.

None of this is a knock on the marking standards. It is the opposite. The manifest at origin and the continuity of that manifest downstream are different layers solving different parts of one problem. The first tells you where something started and the second tells you what happened to it on the way here.

You need both. The industry built the first. The second is where the work is now.

There is a second failure the law does not touch at all. Both statutes aim at content that an AI system generated. But a large share of the media that decides real outcomes was never born inside any provenance system. The claim photo shot by a policyholder on an unmanaged phone. The eyewitness image from the scene of a news event. These arrive with no credential, not because someone stripped it, but because there was never a device in the loop to apply one.

The law marks the synthetic and says nothing about the authentic. Yet the authentic photo, arriving with nothing to vouch for it, is exactly the one a carrier or a newsroom has to trust. The same architecture that makes a mark survive the trip is the architecture that could give that first mile a credential it never had.

You see the cost clearest where money and trust are on the line.

If we take a look at a typical insurance claim, almost every claim now starts with a photo, taken by a policyholder, on a phone nobody controls, sent in through an app. By the time an adjuster sees it, that image has passed through several systems, any of which may have re-saved it. If the only proof of authenticity lived in metadata, and one system stripped it, the carrier is now making a payout decision on an image it cannot verify. The law was satisfied but the carrier is still guessing.

It's a similar situation for a newsroom. A verification desk can establish where a photograph came from. That is what it is staffed to do — but what it usually cannot establish is whether the proof of origin survived the crops, the resizes, and the re-encodes between the source and the published page. The reader sees a credential, or sees nothing, and has no way to know which steps ate the history.

Courtrooms are struggling with the same problem, because the chain of custody was built for evidence you could hold in your hand and log at every transfer. A digital photograph has nothing binding it to the moment of capture and no unbroken record of what touched it afterward. Courts admit it anyway. The question is shifting from is this real to can you show it held from capture to submission. That is a continuity question, and a mark applied at the source cannot answer it alone.

In all three, the same thing is true. Origin was the easier half. What survives the trip is the half that decides the outcome.

This is not an argument for more law. The regulators did their part. They named the requirement and put a date on it, and California even named the hard version of it. Asking a statute to also spell out how a mark survives a re-encode would be asking the wrong institution to solve an engineering problem. The law can set the bar. Someone still has to clear it.

So what closes the gap? Not another marking format. We have those, and they are good. The fix is architecture: anchoring authenticity at the moment of capture, and verifying its continuity as the content moves, built into the systems that already handle that content instead of bolted on afterward. Not a wall that defeats every possible attack, which no honest engineer would promise. A layer designed to hold through the ordinary trip that breaks things today, and to say so plainly when it has not held.

That layer is infrastructure and it sits underneath the products that newsrooms, carriers, and platforms already run. It completes the provenance work instead of competing with it. And it is the piece the Aug. 2 deadline is about to expose, because a lot of organizations are going to mark their content, check the box, and learn the first time it matters that the mark did not reach the other end.

The deadline is doing something useful. It is forcing a floor. After Aug. 2, marking is table stakes, and that is good.

So if this is the new floor, we're still not at the finish line. The law set the requirement that content be marked and, in California, that the mark endure. The market still has to build the thing that makes endurance real. Whoever builds it first is not just compliant. They are the ones who can still trust what they are looking at after the deadline stops being news. Everyone else will have marked their content, called it done, and gone on guessing with money on the line.

Insurance Doesn’t Have an AI Problem...

...It has a design problem. Insurers risk wasting AI investments by prioritizing technology over understanding the workflows and needs of the people using it.

AI Problem

Every AI conversation in insurance right now seems to start in the same place. Models, platforms, copilots, automation. So it might sound strange to say the industry's AI problem isn't a technology problem. It's a design problem.

I'm the founder and CEO of a design agency that has worked with insurance companies for more than 15 years, and I keep seeing the same pattern. We invest in technology before we understand the people who are supposed to use it. Then, when adoption is low, we blame it on people.

AI is just the latest, highest-stakes version of that same old mistake.

Whether investments in AI pay off won't come down to what model you pick. It'll come down to whether the people you built it for actually use it.

I am a designer by trade: art school, design school, maker through and through. Cake & Arrow did not start in insurance. We began in retail and e-commerce, designing digital experiences for consumer-centric brands. Then, about 15 years ago, a CIO at an insurance company asked us to help reimagine a sales platform for agents.

We came in as outsiders, and that outside view helped us see something people deep inside the business often can't: insurance experiences are too often built around the business, the policy, and the transactional moments—not around the customers, employees, agents, and brokers trying to navigate them.

Investing in Technology Is Not the Same as Progress

The instinct in insurance is often to start with the technology. A new tool shows up, a new capability emerges, and every executive team wants to show progress. I get the pressure. Boards are asking about AI. Everyone wants to move fast.

But buying technology is not the same as making progress.

A powerful AI tool is still worthless if it isn't solving an actual problem for an actual person. The most advanced chatbot, copilot, or automation platform will fail if it gets bolted onto a broken process. That's the actual risk with AI right now. Making the same old mistake, only faster and at greater expense.

When talking to insurers, I often make a distinction between "design" and "Design with a capital D." When I talk about "Design," I'm not talking about colors, fonts, or pretty screens. Design is the research, the strategy, and the deliberate decision-making underneath every product and experience. It's understanding who a tool is for, what its purpose is, where the work breaks down, and how a solution earns its place in someone's day.

And here's the thing: Design is already happening, whether companies acknowledge it or not. Every agent portal, claims experience, policyholder app, and AI workflow is the result of a decision someone made. The real question is: where and with whom did the decision originate? With the person doing the work, or with an executive mandate, business requirement, vendor pitch, or short-term goal? Too often, the decisions made in insurance have little to do with the human beings they impact.

Agents Are Not the Barrier

In our recent report, The Connective Thread: From Agent and Broker Research to a New Design Vision for AI-Enabled Insurance Work, we spoke directly with agents and brokers about how they are using AI today, where they are finding value, and what is still getting in the way. What stood out was not the agents' resistance, but their resourcefulness.

Agents are already experimenting. They're drafting emails, summarizing policies, comparing quotes, prepping for meetings, and translating complex insurance language into something clients can actually understand. Some are quietly building workarounds because the official systems around them do not support how they actually work.

So the problem is not that agents do not want to use AI. It's that the tools too often do not map to the real friction in their work. The industry keeps talking about AI as an automation story. But when you talk to agents, what they want is integration.

They are not asking for another tab, login, or disconnected assistant. They're already moving between agency management systems, CRMs, email, spreadsheets, carrier portals, and rating tools. They're entering the same information over and over, hunting across systems for context and trying to track what changed, what a client needs, and what follow-up might fall through the cracks. That is not a single-task productivity problem. It is a workflow problem.

AI that helps write an email is useful. AI that understands the context behind the email, pulls from the right systems, shows where the information came from, flags what needs review, and keeps the human in control… that's something else entirely. That is where AI becomes connective tissue, instead of one more tool to add to the pile.

Design Around People, Not Around Replacing Them

For decades, the insurance industry has strived for ways to disintermediate agents. AI has only added fuel to that fire. There's a real temptation to see AI as a way to replace human labor, cut costs, and eliminate the messiness of human relationships.

But that framing misses where the value actually lives.

Sure, AI can create efficiencies. It can reduce administrative burden, help agents manage bigger books, and spend less time on repetitive work. But if your starting point is replacement, you'll miss the bigger opportunity to design tools that unlock capacity, judgment, and relationship-building.

The best agents are valuable because they know what matters. They understand their clients, and they understand risk. They can feel when something is off, and they know what to ask next. That's how they turn complexity into confidence. AI should be making more room for that work, not pushing it to the side.

This is where human-centered design stops being a nice-to-have and becomes a business necessity.

If you want agents to adopt AI, you have to understand how they actually work, not how leadership assumes they work. And that requires more than a survey. It means observing real workflows, listening for friction, and noticing the invisible work that quietly holds the system together. Research embedded in the design process points toward solutions.

Adoption Is the Whole Game

One of the biggest misconceptions about AI is that adoption is what happens after the rollout. It's not. Adoption is the whole game.

A tool is only successful if the people it is built for actually want to use it. People want tools that fit into their world, solve problems they recognize, and make their work meaningfully better in a way they can feel.

Insurance has a long history of underestimating this. The industry spends significant money on technology that never lands because it has never fully accounted for the human experience surrounding it. Then, when usage is low, the conclusion is often that people are "resistant to change."

Most of the time, that's the wrong diagnosis.

People are not resistant to change that helps them. They're resistant to tools that make their day harder, add complexity, create risk, ask them to trust outputs they cannot verify, or worse, are designed to replace them.

AI cannot simply generate confident answers. It has to earn trust. Agents need to see where information came from, verify recommendations, correct outputs, and approve what goes to a client. "Trust but verify" is not just a user preference here. It's a design requirement.

What Leaders Should Do Differently

If a carrier, brokerage, or insurtech CEO asked me where to start right now, I'd say this: Catch yourself before you jump to the solution.

The pressure to move fast is real, and speed does matter. But moving fast doesn't mean skipping the work that makes speed useful. Before you decide what AI feature to build or what vendor to buy, sit with these three questions:

  • Who is this for?
  • What problem are we solving?
  • And what outcome are we actually after?

Then go talk to the people who'll use it. Watch how they work, find where the friction really lives, and let that learning shape the AI strategy before the roadmap hardens. A few focused weeks of research and design up front can save you months, or years, of expensive misalignment down the line.

The Opportunity Is Still Enormous

Despite the industry's habit of chasing tech before thinking about people, I remain optimistic. The opportunity to differentiate in insurance is astounding. The bar for better experiences is still too low.

AI can help agents spend less time searching and re-entering the same information. It can help newer employees get up to speed faster. It can preserve institutional knowledge, make complex decisions more transparent, and free up time for the things that actually build loyalty. Advice, empathy, and relationship-building.

But only if it is designed around people.

The companies that get this right understand that technology alone does not create transformation. People do. It comes down to whether they trust the tool enough—and find it valuable enough—to actually use it.

Insurance doesn't need more AI for the sake of AI. It needs AI that solves actual problems for the people doing the work, in the real flow of their day. That's the design challenge. And if the industry takes it seriously, it's also the clearest path to transformation.


Josh Levine

Profile picture for user JoshLevine

Josh Levine

Josh Levine is the founder and CEO of Cake & Arrow, an experience design and product innovation company that works exclusively with insurance companies. 

With a career spanning over 25 years, he has led innovation and design initiatives for more than 40 of the most prominent carriers, distributors, and insurtechs—including MetLife, Travelers, Aflac, Chubb, Aon, Amwins, and Unqork. 

Biggest Threat Yet to Captive Insurance Agents

State Farm's announcement of a tough new compensation structure suggests that the captive model for insurance agents has finally passed a tipping point.

Image
Captive

Back in 2013, when Chunka Mui and I were doing some consulting work on innovation for the CEO of a top-five personal lines insurer, he was trying to rewire the compensation structure for his captive agents. He wanted to encourage them to focus more on growth and less on building a book of business and then servicing it ("coasting," in his words). 

He noted that he wasn't trying to cut the total dollars paid to agents. He just wanted to take two percentage points out of the base commission and pay the money out as incentives. 

"But every time I float the idea," he said, "the agents turn around and kick me in the crotch." (He used a more colorful word.)

Having kept an eye on the issue for more than a dozen years now, I believe that State Farm's announcement of a take-it-or-leave-it, incentive-driven compensation model for its 19,000 captive agents marks a turning point. Change always takes time, but I believe the captive agent business will be very different a few years from now.

Let's have a look. 

A smart piece by David Gritz of InsurTech NY provides the backdrop, showing how the industry has been deemphasizing the traditional captive model for years. Noting that the trend predates the generative AI explosion by many years, he writes:

  • "June 2020: Nationwide ends its captive agent program.
  • "November 2021: Liberty Mutual transitions captive agents to independent agencies.
  • "January 2023: Allstate signals a reduction in captive distribution.
  • "June 2026: State Farm reduces benefits and commissions for captive agents.

"Viewed individually, each decision can be explained by company-specific circumstances. Viewed together, they reveal something larger: carriers are increasingly questioning whether exclusive distribution remains the optimal model for growth."

Gritz also neatly summarizes what, for me, is the core change that is working against captive agents:

"Consumers can purchase insurance through direct channels, comparison platforms, embedded insurance experiences, independent agencies, affinity groups, digital marketplaces, MGAs, and increasingly AI-powered interfaces.

"Carriers want the flexibility to pursue all of these opportunities simultaneously. Exclusive distribution creates natural channel conflict when a carrier wants to experiment with new distribution strategies."

He gets into other reasons, too, but for me the key is that three decades of development of the internet, led by customer service pioneers such as Amazon, have conditioned us to expect to be able to see all our options, and instantly. We don't just look at what clothes Macy's or Nordstrom might offer us; we look at every seller. Even if we've settled on a brand or a specific item, we still look everywhere for the best prices — in seconds. 

In that sort of world, it just doesn't make sense for someone looking for insurance to walk into the office of the local State Farm agent, even if the agent is a smart and lovely person who sponsors the customer's daughter's soccer team. 

It's not clear how quickly the change away from captive agents will happen. A Silicon Valley truism is that you have to make sure you don't confuse a clear view with a short distance. And the reason for that adage is that so many people make that exact mistake all the time — including, well, me.

I predicted the end of car dealerships 25 years ago, because all you really need is a way to test drive a car. You can then order your choice straight from the manufacturer, get it in a couple of weeks, and not have billions of dollars of car inventory sitting on lots around the country, pushing up costs for everybody. But change has been so slow that we're only now starting to see the sorts of effects on dealers that I expected by 2005 or 2010.

Still, the transition away from captive agents is inevitable. Independent agents will keep growing — witness the interest in the HUB International IPO — while captive agents will have to fight a rear guard action. They will be under pressure from both ends. Their carrier employers will demand more growth and more flexibility to explore other distribution channels. Customers will press for lower prices while also insisting on more options.

And I think State Farm, as one of the last big holdouts relying on captive agents, has pushed the transition past the tipping point, so it should only accelerate from here.

Cheers,

Paul

Insurers Must Prepare Now for El Niño Season

With El Niño forecast at 80% and AI-driven fraud rising, carriers must act now before disaster season arrives.

El Nino

Every spring, the forecasts roll in, and every year the insurance industry does the same thing. We brace ourselves.

2026 is no exception. The Climate Prediction Center, part of NOAA, recently raised the odds of an El Niño pattern forming to 80%. Some experts are warning of a "super" El Niño that could hold on for a full year. El Niño brings extreme heat, floods, and the kind of volatile conditions that turn straight into claims — wildfires, floods, severe storms, even hurricanes. Over the next 12 months, carriers could see a real surge.

Here is the part that should give every carrier pause. El Niño usually calms the Atlantic hurricane season. Warmer Pacific waters drive up wind shear, and that wind shear holds down the number and intensity of Atlantic storms. Usually. A couple of years ago, El Niño delivered far less wind shear than expected, and paired with record-high Atlantic surface temperatures, we ended up with more than 20 named storms. The U.S. got lucky on landfalls that year. Luck is not a strategy.

And the weather is only half the story. Reduced federal programs, thinner funding, and fewer emergency response teams all push more weight onto insurers to get aid and boots on the ground after a fire or a storm — to help families and businesses actually start to recover. On top of that, fraudsters have discovered AI. Fake photos. Fabricated video of damage that never happened. The claims floor just got more complicated.

So what do we actually do about it? Glad you asked. Here are four moves carriers can make right now.

Start with education.

Most policyholders read their policy exactly once — the day they buy it. Maybe they skim the claims steps when the welcome packet shows up. But unless someone has recently watched a tree come through their roof, they have no idea what they need or how to file. So tell them. Before storm and wildfire season kicks off, run an education campaign for policyholders in high-risk areas. Remind them to keep insurance documents somewhere they can actually grab them in a hurry — go-bags, emergency kits, the glovebox, their phone. Walk them through how to reach you after a disaster, especially when the cell towers are down and the internet is gone. The worst possible time to learn the claims process is in the middle of losing everything.

Invest in claims management.

When disaster hits several regions at once, you need a claims partner who can staff up fast. That is the whole ballgame. Beyond handling the legitimate claims, carriers now have to catch the fraudulent ones — the AI-generated images and video built to slip past a busy adjuster. AI cuts both ways here. It is genuinely useful for scaling claims processing, but it needs guardrails, so that a real human confirms a real person experienced real damage. AI is not going to replace decades of adjuster expertise. What it can do is make good adjusters faster and good operations sharper. The job is finding a partner who holds that balance.

Build your housing network before you need it.

Wildfires, floods, hailstorms — these used to be local problems. A town, a county, a bad week. Not anymore. They have become recurring, national events, and the displacement they cause stretches longer and wider every year. When a family's home is unlivable or a company's building is unsafe to enter, they need somewhere to go, and they need it fast. But when one region gets hit two or three times in a season, or hundreds of households are displaced at once, hotels and short-term rentals and office space dry up in a hurry. If your book has real exposure to El Niño this summer, line up those relocation partners now. Not after.

The time to prepare is now.

El Niño is not projected to fully arrive until summer, but the extreme weather did not wait for the calendar. Tornado outbreaks have already torn across the Midwest and the South. Nebraska battled the largest wildfire in its history. The West broke heat records in March. If last year taught us anything, even a mild hurricane season leaves plenty of room for a record number of other disasters and billions in damage.

We will never know exactly when or where the next one lands. But predictive AI models have made the forecasts sharper than they have ever been, which means insurers are better positioned to respond than ever before. So let us act like it. Educate policyholders with guidance built for their real risk. Invest in the right mix of technology. Choose a claims partner who can scale when the sky falls. The storms are coming either way. The only thing still undecided is how ready we are when they get here.

Split P&C Market Demands Split Renewal Strategy

Property rates are easing while casualty lines tighten, requiring insureds to tailor renewal strategies by coverage line, not market averages.

Financial Graphs

No, you cannot have a single word answer to the question, "Is the insurance market soft?" The more useful question is: which part of the market, and for which account? Data unlocks the nuance of this market and allows insureds to benefit from places their risk profile coincides with pockets of softness in the market.

Alera Group's 2026 Property and Casualty Market Outlook reports that we're in a mixed market. Preliminary data from our market update (due out in July) validates this result. Property is easing (unless you're in specific CAT zones), while umbrella and excess remain stubbornly constrained for many accounts. That unevenness is where renewal outcomes for the rest of the year will be won or lost.

When the market is hard everywhere, renewal work often collapses into damage control. When conditions start to shift, the work changes. It becomes less about whether you can get a quote and more about whether the account is positioned—through its submission, risk story, and program design—to earn the best terms available.

Treating "P&C" like one market is the biggest risk

The market outlook is based on Alera Group's third-quarter 2025 market survey of insurers, wholesalers, and industry vertical experts. The data is then matched against in-depth interviews with market drivers and experts. The report points to selective moderation in rates across many lines, alongside improving coverage availability and meaningful capacity expansion. At the same time, several casualty-driven segments remain pressured, and the broader environment—including social inflation, regulatory constraints, and catastrophe loss trends—continues to complicate underwriting and buyer expectations.

That mix is exactly why a single renewal playbook can backfire. A team can assume the market is easing, only to run straight into tighter casualty scrutiny or a suddenly almost impossible-to-insure property location. On the other hand, they can assume nothing has changed and miss opportunities created by improving capacity and broader availability.

What the outlook implies for renewal conversations

The outlook projects average decreases in several major lines, but with wide ranges. Commercial Property (including Business Interruption) is projected at -4.6% average (range -20% to +5%). D&O shows projected decreases, as well, -3.8% for private (range -10% to +5%) and -11.7% for public (range -20% to 0%). Workers' Compensation is projected at -5.6% (range -20% to +10%).

At the same time, several lines remain projected to increase, often moderately, but not always. Commercial Auto is projected at +10.6% (range +5% to +15%), General Liability +6.7% (range 0% to +15%), Umbrella and Excess Liability +7.0% (range 0% to +15%), and Medical Malpractice +10% (range +5% to +20%). Cyber is projected at +1.4% average (range -15% to +10%), while Professional Liability is essentially flat (+0.1%).

These are useful directional markers, but they do not remove uncertainty. Account pricing still varies with fundamentals like industry sector, risk quality, and proximity to catastrophe-prone areas. Underwriting decisions are also increasingly shaped by nuanced variables such as highly specialized risk factors applicable to niche business types, local legal and legislative trends, and leverage with vendors with regard to risk transfer. Underwriters have more data than ever, and some are determined to use it—even when its applicability may be unproven or not yet well-calibrated for a specific class of risk.

Capacity is the opening signal that creates real leverage

Capacity is the name of the game this year. In the survey, respondents forecast increased capacity most dramatically in Commercial Property (53% increasing; 47% same; 0% decreasing) and Personal Lines and Private Risk (64% increasing; 18% same; 18% decreasing).

That does not mean every account will suddenly get better outcomes. But it does change what is possible. When capacity expands, you can revisit decisions that were previously "forced" by scarcity. For example, you can rework how a tower is built, how layers are placed, whether limits are efficiently purchased, and whether the structure still reflects the insured's balance sheet and risk appetite, or just last year's constraints.

Underwriting flexibility is not universal, and casualty remains the pressure point

The outlook also suggests underwriting is becoming more flexible in some areas. Commercial Property shows 40% more flexible (60% same; 0% stricter). D&O (public) shows 67% more flexible (33% same; 0% stricter). Workers' Compensation is also trending more flexible (38% more flexible; 62% same; 0% stricter). Personal Lines and Private Risk and Surety show flexibility as well.

But casualty-driven segments remain a different conversation. Umbrella and Excess underwriting is projected as 46% stricter (46% same; 7% more flexible). General Liability is 36% stricter (55% same; 9% more flexible). Commercial Auto is 29% stricter (57% same; 14% more flexible). Medical Malpractice is 33% stricter (67% same; 0% more flexible).

To put it in plain language (and to set expectations internally), some parts of the market are opening, but underwriting is not "relaxing" across the board.

What to do next: separate opportunity work from defensibility work

In a split market, renewal strategy has to split too.

Where property and other areas show improving capacity and more workable options, the work is about earning better outcomes. That means building a submission that matches the sophistication of underwriting today and using improved conditions to revisit program design.

Where umbrella and excess and other casualty-driven segments remain pressured, the work is about defensibility. It means being ready for harder questions, narrower comfort with severity, and heightened scrutiny.

In both cases, the differentiator is execution. The market outlook shows the value of starting early enough to produce a clear and defensible picture of the risk. That includes accurate valuations and exposure schedules, a straightforward explanation of operational changes, and evidence of how the insured's controls reduce the frequency and severity of loss. It also means closing the gap between what the insured believes about their risk and what the data suggests—particularly as underwriting relies more heavily on imagery, analytics, and localized catastrophe modeling.

And finally, 2026 remains a structural year. The market outlook highlights captives, structured programs, and quota-share arrangements as approaches where traditional capacity is restricted or expensive, and points to tools like parametrics to address gaps where traditional policies may not respond as expected. When conditions are changing, structure can be as important as rate.

The takeaway

This is not an "easy" market, but it can be more workable if teams resist the urge to generalize. For leaders, that means planning renewals with line-by-line realism, investing in data discipline and underwriting-ready submissions, and being willing to revisit program structure as capacity returns. As conditions continue to shift, better outcomes will go to the most prepared insureds and the most disciplined teams.


Justin Foa

Profile picture for user JustinFoa

Justin Foa

Justin Foa is leader of Alera Group’s property and casualty (P&C) practice. 

Foa has more than 30 years of insurance industry experience, including more than 10 years with multinational brokerage firms before he joined his family’s firm, Foa & Son, becoming its president in 2006. 

He is a graduate of the Wharton School of Business at the University of Pennsylvania, where he earned his bachelor’s degree in insurance and risk management. 

Cybersecurity Training in Insurance Must Keep Pace

Annual cybersecurity training no longer suffices as AI-powered threats grow more sophisticated, demanding insurers adopt continuous, personalized employee education.

CyberSecurity

Few industries have a greater need for effective cybersecurity training than insurance. Insurers store vast amounts of sensitive information like personal identifiers, financial data, medical records, and Social Security numbers, which makes insurance organizations a prime target for cybercriminals.

To complicate the situation further, artificial intelligence (AI) is helping bad actors create more convincing scams and deploy them at a greater scale. According to Verizon's 2026 Data Breach Investigations Report, 62% of breaches worldwide involve the human element. One thing that has become clear is annual cybersecurity training alone is no longer enough to keep pace with such an ambitious moving target like cyber hygiene. Insurance organizations must rethink how they train employees and adopt more engaging (and frequent) approaches than what regulations mandate.

The Unique Challenges of Cybersecurity Training in Insurance

One of the biggest challenges in cybersecurity training is getting people to care. While insurance regulations mandate cybersecurity training, checking a regulatory box does not create lasting behavioral change. In fact, the word "compliance" often puts employees in a frame of mind that is counter to what the trainer wants, which is an engaged employee.

Cybersecurity professionals spend their days immersed in technical concepts, but most employees do not. A significant portion of the trainer's role involves translating highly technical security measures into practical guidance that employees can understand and apply in their daily work.

That challenge is amplified in insurance because every role interacts with risk differently. Executives, claims adjusters, underwriters, agents, brokers, customer service representatives, actuaries, and policy administrators all face different cybersecurity threats and responsibilities. An annual one-size-fits-all approach rarely works.

The stakes are high because insurers possess information that cybercriminals actively seek. These employees are targeted more frequently because attackers understand the value of the data insurers protect. That means trainers must continuously reinforce strong cyber hygiene habits and help employees recognize evolving threats before they become incidents.

Cybersecurity Trainers Must Think Like Marketers

Many trainers understand their job is to improve cybersecurity awareness. Fewer recognize that they are also competing for attention. Meaningful behavior change requires continuing engagement and repeated touchpoints. That is why cybersecurity trainers should borrow proven principles from marketing. I use my own framework called SURE to reinforce this throughout all my work.

Simple. Communication should be easy to understand. Use shorter words, shorter sentences, and straightforward explanations. Respect employees' time. The faster people can grasp a message, the more likely they are to act on it.

Useful. Content should provide immediate value. Marketers rarely rely on a single content format. They create webinars, blog posts, white papers, videos, newsletters, and social content, often repurposing the same message across multiple channels. Trainers should adopt the same mindset.

Emotionally Resonant. People respond to messages that connect emotionally and feel relevant. Consider the difference between a training titled "Annual Cybersecurity Training Overview" and one called "How to Spot Scams and Protect Sensitive Information." The second emphasizes action and outcomes. It immediately answers the question every employee asks: Why should I care?

Easy to Skim. Content should be easy to skim, with clear hierarchy, thoughtful formatting, and strategic use of bullets, visuals, and spacing. The easier the information is to consume, the more likely employees are to remember it.

These principles may come from marketing, but they are equally valuable in training. Additionally, rather than relying on traditional classroom training alone, organizations should use approaches that help employees stay engaged, retain information, and put their learning into practice.

Using AI to Make Training More Engaging

Leveraging gamification is another way to make learning more interactive. An example of this is conducting monthly phishing simulations. Employees who correctly identify and report suspicious emails can earn points that accumulate toward recognition or rewards. Over time, this creates positive reinforcement and turns cybersecurity awareness into a continuing activity.

Artificial intelligence makes these exercises even more valuable. Instead of sending the same generic phishing email to every employee, AI can help trainers generate realistic scenarios tailored to specific roles. A procurement employee might receive a fake vendor invoice. An executive could receive a spoofed message that appears to come from a board member. New hires and experienced employees can receive different scenarios based on their responsibilities and risk profiles.

This level of personalization matters because attackers are already doing it. Cybercriminals are using AI to create increasingly convincing messages that mirror real business communications. An estimated 3.4 billion phishing emails reach inboxes every day, and approximately 82.6% are now AI-generated. If threat actors are becoming more sophisticated, cybersecurity training must evolve at the same pace.

Leveraging AI and Video for Microlearning

The problem is that this evolution is near impossible to accomplish in an annual seminar. New phishing emails happen every hour. Instead, organizations should embrace microlearning, the practice of delivering information in short, focused, and easily digestible formats. Rather than asking employees to sit through a singular lengthy training session where unique phishing tips might be lost on them by the end, organizations can provide quick learning moments for new individual scams or threat tactics as they happen and reinforce critical concepts. Historically, this would take too much time and bandwidth of a training team (which typically is not large even in a large company). But AI tools are making it easier now.

For example, to make short, quick videos, one approach is to use Camtasia Snagit's step-capture functionality to document a singular process by automatically capturing images of each step. Those images can then be imported into Camtasia.ai and transformed into a short instructional video complete with AI-generated narration and transcription. There are other technologies and means of doing this that help trainers create professional learning content that is easy to update and distribute.

It becomes a lighter lift and the training is more timely, more relevant, and more likely to be consumed by busy employees.

Cyber threats are becoming more sophisticated, personalized, and difficult to detect. As AI continues to reshape the threat landscape, cybersecurity training must evolve as well. Insurance organizations need to evolve training programs from what's mandatory to a continuous, engaging, and tailored approach to the realities employees face every day. That means leveraging AI, embracing microlearning, incorporating gamification, and adopting the communication techniques that marketers have used successfully for years.

The goal is still to make training clear, but it is also to make it memorable. In an industry where one click can lead to a significant breach, creating training that employees actually remember may be one of the most important security investments an insurer can make.

July 2026 ITL FOCUS: Cyber

ITL FOCUS is a monthly initiative featuring topics related to innovation in risk management and insurance.

ITL July 2026 FOCUS: Cyber

 

FROM THE EDITOR

The first known cyber insurance policy was issued in 1997 through AIG — a $15 million coverage limit for internet-related risks at a time when many executives still weren't sure the internet would last. Nearly three decades later, cyber is one of the fastest-moving, most competitive lines in all of insurance.

The threat landscape has never been more complex. AI hasn't just raised the volume of attacks — it's sharpened them. Phishing emails that once announced themselves with broken English and implausible promises have given way to hyper-personalized, eerily convincing communications. Deepfakes are blurring the line between real and fabricated in ways that insurance policies haven't fully caught up with. And invoice fraud — one of the oldest scams in the book — is quietly surging, powered by social engineering that exploits LinkedIn connections, email thread histories, and the reluctance of junior employees to question a message that appears to come from the CEO.

For the latest on where cyber stands and insight on where it’s going, we turned this month to Liz Kim, president of US operations at BOXX Insurance, whose nearly 30 years in the industry span law, claims leadership, underwriting, product development, reinsurance brokering, and now carrier strategy.

Her core message: The battle between attackers and defenders never really ends, it just shifts terrain. Ransomware gives way to extortion, which gives way to business email compromise, which gives way to whatever comes next. The only durable advantage is staying ahead of the bad guys — through education, technology, and underwriting discipline.

Read the full interview to find out why invoice manipulation deserves more attention than it's getting, what AI is actually changing in cyber insurance, and how third-party vendor relationships have quietly become the industry's biggest claims problem.

 
 

The Emerging Threat to Cybersecurity

Paul Carroll

To start us off, what is your overall outlook for the cyber insurance industry?

Liz Kim

If only we could predict where it's going to go, right? I've been in the cyber insurance industry for many years and I've worked across a lot of different roles. I've been in it as a lawyer, as head of claims for a major insurer, in underwriting, in product development, and as a broker. We’re in a soft market now, but, as with all insurance, the cyber market is cyclical.

I think cyber is more cyclical than other lines, for a couple of reasons. First, although there are plenty of disaster scenarios that people talk about in the industry — things like a worldwide AWS outage — we haven't yet really had a true disaster, which would tighten capacity and increase prices. Second, we have new entrants coming into cyber all the time. Because of that constant influx, a lot of their value proposition comes down to nothing more than having the lowest prices. That dynamic drives pricing down more than you'd typically see in other lines of business.

That said, companies that maintain underwriting discipline and pair their insurance with meaningful services or technology solutions to reduce digital risks are better positioned to hold pricing than those that are purely insurance plays.

My overall outlook? It's always positive — because if it wasn't, I wouldn't still be in cyber after all these years. With the kinds of innovations we're seeing across the industry, it's always going to be an area that drives the market forward.

read the full interview >
 

MORE ON CYBER

The 4-Minute Mile of Cybersecurity

by Timothy O'Neil

Historical threat data and AI are finally enabling cybersecurity teams to forecast attacks once thought impossible to predict.

Read More

 

The Case for a Personal Digital Bodyguard

by Chris Hamilton

As cybercrime hits $21 billion, personal cyber insurance must pivot from reactive coverage to proactive protection.

Read More

 

AI Security Risks Challenge Cyber Insurers

by Eder Ribeiro

As AI adoption outpaces security practices, insurers face a new cyber risk category with concentrated exposures and long-tail claim potential.

Read More

 

It's Back to First Principles for Insurance

by Manjunath Krishna

Insurance is scaling into cyber, climate and AI risks faster than the first principles of insurability can adapt.

Read More

 

AI Penetration Testing Transforms Cyber Security

by Sumedh Barde

AI penetration testing transforms annual compliance snapshots into continuous security assurance without sacrificing the depth of manual expert testing.

Read More

 

AI Systems Reshape Cyber Insurance Risk

by Afroz Mohammed

AI-driven discovery of software vulnerabilities at machine speed challenges cyber underwriting models designed for environments where threats evolved gradually.

Read More

 

 

MORE FROM OUR SPONSOR

AI Exposes Gaps in E&O Coverage

Sponsored by BOXX Insurance

Autonomous AI systems are outpacing legacy tech E&O policies, exposing businesses to uninsured algorithmic accountability risks.
Read More

Insurance Thought Leadership

Profile picture for user Insurance Thought Leadership

Insurance Thought Leadership

Insurance Thought Leadership (ITL) delivers engaging, informative articles from our global network of thought leaders and decision makers. Their insights are transforming the insurance and risk management marketplace through knowledge sharing, big ideas on a wide variety of topics, and lessons learned through real-life applications of innovative technology.

We also connect our network of authors and readers in ways that help them uncover opportunities and that lead to innovation and strategic advantage.

Agentic AI Must Prioritize Decision Velocity

Agentic AI's true value in insurance lies not in speed alone, but in decision velocity with built-in governance and accountability.

Agentic AI

From rules-based automation in the 1990s and 2000s to machine learning algorithms in the 2010s to generative and agentic AI in this decade, the evolution of AI in insurance has been phenomenal, affecting the areas of underwriting, claims management, fraud detection, and customer engagement. Yet, in the last three years of the industry's AI rush, it's claims management that has become the default AI use case, with its evident ROI. This is possibly due to its visible cycle time, structured first-notice-of-loss data, and well-mapped workflows and exception paths. Very few carriers talk about their underwriting decision latency, their endorsement turnaround, or their fraud triage interval—all of which carry significant value.

And so, a question arises. Should speed be the only outcome of consequence in the new era of autonomous decision making? Be it in claims being processed in minutes, fraud being detected in real-time, or customer queries being answered instantly; speed of autonomy cannot be a destination by itself. We need to govern autonomy that combines speed, traceability, escalation, and accountability to create trust. Agentic AI's contribution to insurance is not throughput. It is compressed decision cycles with an intact audit trail.

Decision velocity is truly what agentic AI in insurance must aim for.

What decision velocity really means

For many industries, and more so for insurance, speed is considered a competitive advantage and differentiator. But in a life-intrinsic domain such as insurance, speed that cannot be explained, reversed or attributed to an accountable owner is an operational and regulatory risk. Without the discipline of correctness, auditability, and escalation, it becomes a liability in many ways.

Decision velocity brings this discipline to speed and scale. The discipline that embeds traceable reasoning and accountable ownership for every consequential decision from the time of the data event to its executed action. With intelligence, it moves the focus to decision ownership, not merely technology ownership. It transparently connects the facts of data, the patterns that analytics uncover, and the recommendations of AI in every business choice made.

Data freshness, reasoning compression and oversight latency — decision velocity thrives only when these three components move in complete unison and understanding. While agentic systems in insurance aim to accelerate decision making, they should not remove the controls that make the decision defensible.

An agentic architecture for insurance decisions

Traditional automation in insurance (and even RPA) is inflexible and deterministic. Rule and rating engines determine monetary thresholds and premium calculations based on predefined variables. And while there are referral workflows to alert and escalate potential risks that fall outside the delegated guidelines, the guardrails are narrow. What's more, they break when there is a shift in context.

Agentic AI can transform the operating model with its ability to ingest and validate multiple sources of data across policy administration systems, geographies, lines of business, and regulatory demands. However, all this pivots on the quality of data and its readiness for agentic AI systems, and this is what the agentic architecture must assure.

A production-grade insurance agent stack should comprise (a) a planning layer, (b) a retrieval layer with policy language, regulatory rules and prior decisions, (c) a tool layer of rating engines, fraud models, claims and policy admin systems, (d) guardrails, (e) a decision logger, (f) an escalation layer, and, above all, a human review console.

The premise of a singular and monolithic "do everything" agent will not work. Work must be bounded by multi-agent systems, where each agent owns one decision class with one accountable human. Remember, agentic does not mean autonomous at all costs. It means delegated work within governed boundaries. Such a model reduces scope risk. However, care must be taken to avoid fragmented decisions by reasoning in isolation. The production architecture must therefore have a unified orchestration layer, shared policy memory, common decision taxonomy, and clear accountability model across agents.

When it comes to data platforms for agentic insurance, the self-adaptive behavior in the user interface calls for real-time event and data streaming, plus real-time curation of enterprise data assets. The traditional enterprise data platform with staged data processing and disjointed data event streaming for specific use cases will not work (see table). Data quality must be uncompromisingly high, and multi-step refinement and generation of machine learning insights must be in real-time, with data features engineered from the ingested and streamed data into the enterprise data platform.

 

FeatureTraditional architectureAgentic architecture
User interfaceStatic forms for fixed journeys Adaptive journeys with outcome-based flexibility
Process logic and knowledge

Rules-based with pre-defined logic

 

 

Fragmented knowledge documents

Multi-agent systems —each agent owns a decision class with human-in-the-loop accountability

 

Vector databases hold knowledge artifacts such as policies, endorsements, transcripts of calls, notes, etc. with context, permissions and cognition

GovernanceManual and ad-hoc auditsAutomated audit controls for policy and process validation, and for data lineage

 

This, then, is how agentic AI brings decision velocity into insurance operations beyond claims management. Be it in underwriting submission triaging, policy endorsement processing, investigation of fraud signals, identification of subrogation opportunities or distribution support, the agentic architecture clearly delineates delegation from human intervention, and shows what the agent can do, where the human stays in the loop and what velocity gain looks like (see table).

 

Insurance functionWhat the agent doesHuman interventionVelocity gain
Underwriting submission triage

Parse inbound submissions 

Extract risk attributes,

Identify missing information, request it from brokers, compare the submission against appetite and route it to the right underwriter

Underwriter still owns risk judgment, pricing exceptions and the bind decision, especially where appetite, coverage exclusions or regulatory sensitivity are involved

Less time spent chasing documents and classifying submissions

More underwriter time spent on judgment-heavy risks

Policy endorsement processing

Interpret customer or broker endorsement requests

Validate against policy language

Check downstream impact and surface exceptions

Service representative or underwriter approves, rejects or escalates changes that alter coverage, premium, risk profile or compliance obligations

Routine endorsements move faster

Exceptions are made visible before they become service or compliance issues

Fraud signal investigation

Chase leads across structured and unstructured data (claim notes, prior loss history, third-party signals and internal anomalies)  

Prepare evidence dossier

SIU investigator decides whether to pursue, close, escalate or involve legal and compliance functions. The agent should not independently accuse, deny or take adverse actionInvestigators get a packaged, traceable dossier instead of a raw flag, improving triage without weakening due process
Identification of subrogation opportunities

Scan open and closed claims for recovery indicators

Map liable parties,

Connect supporting evidence

Prioritize opportunities by recoverable value

Subrogation analyst validates liability, evidence quality, recovery economics and communication strategy before action is taken.

Early identification of more recoverable losses

Reduced leakage without creating automated recovery actions that lack context

Distribution supportRespond to agent and broker questions on coverage, quote status, appetite, missing documents and submission next steps using governed retrieval from approved sourceField underwriter or agency manager remains the escalation path for coverage ambiguity, commercial negotiation, relationship-sensitive issues and exceptions

Brokers get faster answers

Nuanced decisions remain with the people accountable for distribution quality and risk selection

 

Proactive governance for prevention of human oversight failure, agent failure and compliance

Here is a sobering reality. Unless proactively governed, agentic AI can fail while achieving what it was intended to. And this happens due to multiple reasons — stale, biased or narrow data, hallucinated policy interpretation, knowledge drift, conflicting recommendations from multiple bounded agents or complex feedback loops, missed context, overconfident routing and unclear escalation ownership. These are systemic risks that can cascade across the chain to compound uncertainty, opacity, and information asymmetry.

Defining what failure means is absolutely vital, both in business and operational terms. There must be clearly articulated failure controls: confidence thresholds, retrieval-source validation, exception queues, human override reasons, re-playable decision logs, adverse-action safeguards, etc., with temporary kill switches for agents that behave outside tolerance limits. And these controls must be translated into measurable metrics.

Continuous and evidence-based oversight is imperative, not periodical and static testing. Oversight intensity must be matched to consumer impact and reversal cost, and not to a uniform "human-must-approve" rule. It is this fallacy that causes the "rubber stamp failure," where reviewers end up approving almost all agent decisions — a classic instance of minimum oversight and maximum theatre.

Three levels of oversight are recommended, based on decision criticality. The first is the pre-decision review, especially for high-stakes and low-volume instances. The second is the post-decision sampled audit, for medium-stakes and high-volume instances. And the third, for everything else, exception escalation. To add greater effectiveness, we will need to tier systems by both impact and volatility — and ensure that each modification is accompanied by a "change-impact" review.

And oversight must sit above the agent layer, not only inside each workflow. Otherwise, multiple bounded agents can create distributed logic, inconsistent outcomes, and no single view of accountability across the underwriting or servicing process. True governance goes beyond compliance to creating resilient AI systems that assure total trust and safety as they continue to evolve.

The five key governance artifacts that hold up in a market conduct exam include model cards, decision logs with reasoning traces, consumer-impact assessments, bias testing cadence, and third-party model attestations (also see the box on "Five questions a state DOI examiner will ask about your AI").

Five questions a state DOI examiner will ask about your AI:
  1. What decision did the agent influence?
  2. What data did it use?
  3. Which human was accountable?
  4. How were exceptions handled?
  5. How do you test for bias, drift and inconsistent outcomes across agents?
The following may be referred to as guiding frameworks for governance:

The NAIC Model Bulletin on the use of AI Systems by Insurers (2023) and what it actually requires in terms of governance framework, third-party AI risk management, testing for bias and unfair discrimination, documentation, etc.

The Colorado AI Act and insurance rules that serve as a leading state-level enforcement signal, in terms of algorithmic discrimination testing, governance documentation and consumer disclosures.

The NYDFS Circular Letter No. 7 (2024) on AI in underwriting and pricing.

The EU AI Act for high-risk classification for life and health insurance, which clarifies implications for global carriers.

Seven key implementation lessons in production

The truth is, agentic pilots succeed because they run on narrow data, face relaxed oversight, avoid regulatory scrutiny, and are not integrated into real decision accountability workflows. Production is where the rubber hits the road. It requires governance to be embedded into decision accountability workflows from Day One, not added after a successful proof-of-concept. When governance is an afterthought, the pilot does not survive operational reality.

#1 — Bound the agent narrowly. Broad-scope agents hallucinate decisions. Make it one agent, one decision class, one owner.

#2 — Do not confuse narrow scope with narrow accountability. Narrowly bounded agents still need a shared governance layer so that their decisions do not fragment underwriting, servicing or fraud workflows.

#3 — Instrument before you scale. Observability — input, retrieval, reasoning, tool call, output, override — is the long pole. Carriers that skip this will hit a wall in production.

#4 — Design oversight as a product surface. If your reviewer experience is a spreadsheet, you will get rubber stamping. Treat oversight as a UX problem.

#5 — Data architecture is everything. Without a lakehouse, feature store, and semantic layer, agents work on stale or inconsistent data to produce indefensible decisions.

#6 — Change management is the real constraint. Underwriters and adjusters will not trust a system whose reasoning they cannot inspect. Explainability is an adoption requirement, not just a regulatory one.

#7 — Stress-test agent failure before launch. Simulate bad retrieval, missing documents, contradictory policy language, broker pressure, regulatory constraints, and handoff failures between agents.

Creating decision velocity with agentic AI in insurance is an unambiguous mandate for CIOs and CDOs. The good news is that the steps to do so are equally clear.

Create a 90-day diagnostic: a map of the top 20 consequential decisions, current latency, current oversight model, current regulatory exposure and current failure path.

For each decision, define what can be delegated to an agent, what must remain with a human, what needs pre-decision approval, and what can be handled through post-decision audit or exception escalation.

Pick a non-claims pilot. Underwriting submission triage or endorsement processing are the highest-yield, lowest-risk starting points.

Build the governance scaffolding — model registry, decision log, oversight workflow, escalation rules and accountable decision owner — before the agent, not after.

Define decision velocity as a tracked metric alongside loss ratio and combined ratio.

The message for the insurance industry is loud and clear. Enterprises will not be judged on how swiftly they adopted agentic AI. They will distinguish themselves on whether they made faster decisions without losing control, accountability, or trust. Those that treat agentic AI as a faster claims engine will hit a ceiling within a year. The ones that make it their decision-velocity capability, governed by design, will be the winners.


Prem Naveen

Profile picture for user PremNaveen

Prem Naveen

Prem Naveen is SVP, Data, AI & Analytics at Mastek, where he leads agentic AI, lakehouse and decision-engine programs for banks, asset managers and insurance carriers.