Skip to main content
insurance-policy-as-code-v1-16x9
AI

Policy as code is becoming the insurance industry’s trust layer

By Ralitsa Nenkova
Global Insurance Leader, Consult Partner, Vice President
By Shaun Barney
Global Head of AI
Ideas lab | 24-Sept-2026 | Read time: 1 min

Two years ago, AI in insurance was primarily a productivity story. The conversation centered on whether AI could do a given task. That question has largely been answered. Copilots now help underwriters, claims professionals and customer service teams work faster and more efficiently.

Today, as insurers move from AI-assisted tasks to AI-driven workflows, the conversation has changed. Leaders no longer ask whether AI can perform a task. They ask who makes the decision, who remains accountable for the outcome, what happens when AI is wrong, and how a decision can be defended to a regulator months or even years later.

The challenge is no longer capability. It is control.

In an industry where every decision is potentially examinable, competitive advantage and regulatory compliance will depend on the ability to govern AI-driven decisions. This is why policy as code has the potential to serve as the insurance industry’s trust layer.

Agentic AI is a workflow problem, not a copilot problem

Much of the first wave of enterprise AI in insurance focused on helping individuals complete tasks faster. Claims handlers gained copilots. Underwriters gained research assistants. Customer service teams gained chatbots.

Those tools improve productivity, but they do not fundamentally change how an insurer operates. Agentic AI, however, has shifted the focus from individual tasks to entire workflows.

In a traditional operating model, information moves slowly among underwriting, claims, fraud and customer service functions. In an agentic operating model, insights move with the work itself, allowing decisions in one area to continuously inform decisions in another.

The breakthrough is that intelligence begins to flow across the enterprise, allowing insurers to uncover risks, opportunities and operating insights that were previously invisible.

A severe weather claim can trigger fraud analysis, influence underwriting and pricing decisions and generate new actuarial signals. The value comes from connecting these activities to a single workflow rather than treating them as isolated events.

The challenge is that once AI begins operating across workflows, governance can no longer live in operating manuals and policy documents. The rules must travel with the workflow itself. Every action must remain auditable, explainable and compliant regardless of which system performs it.

Trust must exist independently of the model

Insurance already has a well-established approach to governing decisions: delegated authority. Underwriters, claims professionals and managing agents all operate within defined limits that specify what decisions they can make, when additional approval is required and when a case must be escalated. These guardrails have enabled the industry to distribute decision-making safely and consistently for decades.

The same principle can be applied to AI. The difference is that instead of governing people alone, insurers must also govern systems that can analyze information, make recommendations and take actions across multiple business processes.

The greatest opportunities and risks often occur as work moves from one team to another. These transitions are where delays, inefficiencies and inconsistent decisions often arise. Improving a single task can create value, but improving the entire workflow delivers a greater impact.

As AI becomes embedded in those workflows, insurers need a control layer that governs what data can be used, enforces business and compliance rules, records the evidence behind the decision and delivers a clear audit trail. And as AI models continue to evolve, the rules that govern them must remain consistent.

This raises an important question: how is that trust enforced? Governance frameworks, operating manuals and compliance policies already exist inside most insurers. The challenge is that agentic AI systems move faster than humans can manually apply them. That is where policy-as-code capabilities become critical. By translating policies into rules that systems can automatically execute and enforce, insurers can scale AI-driven workflows while maintaining accountability, consistency and regulatory compliance.

Policy as code becomes the insurance industry’s trust layer

Policy as code turns governance from something people are expected to remember into something systems automatically enforce. The rules become part of the workflow itself.

The critical design choice involves separating governance from the model. Models will continue to evolve, improve and be replaced. Governance protocols should not. Policy as code creates a stable control layer that remains consistent regardless of which model sits underneath it. That means insurers can adopt new AI providers, add new agents or change architectures without rebuilding their compliance framework from scratch.

In a claims workflow, policy as code can help ensure that only approved data is used, verify that required evidence is present, determine whether human review is needed and create an audit trail of the outcome.

The model reasons. The policy layer governs.

The value of this approach is an organization’s ability to demonstrate how decisions were made, whether they complied with established rules and who remained accountable for the outcome. The real test becomes: if an examiner asked tomorrow how a decision was made, could you show them the rule that governed it, the evidence considered, and the authority under which it acted?

Most insurers already have the policies, controls and governance frameworks required to answer those questions. The challenge is transforming those rules from documents people reference into controls that systems can read, execute, document and enforce.

With policy as code as the insurance industry’s trust layer, insurers can make every important decision explainable, auditable and defensible, regardless of which AI model is involved.

Reduce operational risk, cost and decision time across compliance workflows without compromising trust.
 

Ralitsa Nenkova

Global Insurance Leader, Consult Partner, Vice President

Shaun Barney

Global Head of AI

Speak to our experts.

Have questions or want to learn more?