TL;DR: Insurance AI is treated as high-risk under the EU AI Act and subject to NAIC expectations for inventories, named accountability, fairness testing, and post-deployment monitoring, according to Openlayer. The real governance gap is no longer policy design but runtime enforcement that produces evidence continuously, not after an audit request.
NHIMG editorial — based on content published by Openlayer: AI Governance for Insurance: Risk Management July 2026
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems.
Questions worth separating out
Q: What breaks when insurance AI governance is only documented on paper?
A: Paper governance breaks when teams cannot prove what model version was active, who reviewed the output, or whether fairness thresholds were breached at runtime.
Q: When should insurers prioritise runtime monitoring over static model validation?
A: They should prioritise runtime monitoring whenever the model affects underwriting, pricing, or claims outcomes in a regulated market.
Q: What do security and AI governance teams get wrong about model explainability?
A: They often treat explanation tools as a substitute for better model design.
Practitioner guidance
- Bind governance artifacts to model versions Link technical documentation, validation results, and approval records to the exact deployed model hash so auditors can reconstruct the decision context without manual reconciliation.
- Set escalation thresholds for fairness drift Define protected-class gap thresholds, proxy-weight change alerts, and cohort-level performance triggers that force review before outputs reach underwriting or claims workflows.
- Preserve prediction-level evidence chains Store input features, preprocessing steps, attribution output, and final decision outcome together so adverse action notices and incident reviews can be defended consistently.
What's in the full article
Openlayer's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance for building an audit-ready insurance AI governance workflow that maps documentation to EU AI Act and NAIC requirements.
- Specific examples of fairness thresholds, proxy monitoring logic, and incident record structures used in regulated model oversight.
- A practical breakdown of how runtime enforcement links model versioning, human oversight, and post-market monitoring into a single evidence chain.
- The article's framework crosswalk for aligning AI governance, compliance documentation, and escalation records across multiple regulatory regimes.
👉 Read Openlayer's guide to AI governance for insurance and risk management →
AI governance for insurance: are your controls producing evidence?
Explore further
Runtime evidence is now the real control plane for regulated AI. Insurance governance fails when organisations treat documentation as a static deliverable instead of a live evidence stream. In regulated workflows, the important question is not whether a policy exists, but whether the system can prove oversight at the exact point of decision. For IAM and governance teams, that shifts the focus from policy intent to auditability, traceability, and accountable operation.
A question worth separating out:
Q: Who is accountable when a vendor-supplied insurance model produces a biased decision?
A: The deploying insurer is still accountable for the regulated decision, even if the model came from a vendor. Contract terms can allocate tasks, but they do not remove liability. The organisation needs visibility into monitoring, incident handling, and documentation because regulators examine the deployer, not just the supplier.
👉 Read our full editorial: AI governance for insurance now depends on runtime evidence