You Bought More AI Than You Think

Dearborn Labs·August 13, 2026·6 min read

Some of the AI making decisions about your customers arrived bundled inside software bought for other jobs — and you can't answer for what you haven't found.

The short version (by humans, for busy humans)

This part was written by humans, for busy humans, in under 250 words. The full post below has the depth — read it yourself, or hand it to your AI.

Ask a carrier CEO where AI touches a decision about a policyholder, and you'll get the list of things the company bought as AI. That list is accurate. It's also incomplete, because some of the AI reaching your customers arrived as a feature inside software bought for a different job — a fraud score inside the claims platform, a propensity model inside the retention tool. Each one shapes a rate, a coverage decision, or a claim, and none of them are on the list.

That's the whole problem. You can't govern, explain, or answer for a decision path you haven't found. And someone is eventually going to ask you to produce the real list — a board member, a regulator, a plaintiff's attorney — at which point "the things we bought as AI" will be the wrong answer.

The fix isn't a governance program. It's a mapping exercise: pick one customer-facing workflow and name every system that shapes the outcome, not just the ones your team calls AI. We'd bet against most teams finishing on the first try — which is the point of running it now, on your own clock, instead of later on someone else's.

The depth is below, along with an offer to walk one workflow with you.


The full version (human on the loop — for depth, yours or your AI's)

The Tuesday before the board meeting

It's the Tuesday before your quarterly board meeting, and your general counsel forwards a two-line note from a board member: where does AI touch a decision about one of our policyholders?

You start a list. The rating model your actuaries signed off on last year. The claims-triage pilot from last spring. You're feeling good about it — and then you remember something your CIO mentioned once, in passing, about a fraud-scoring feature bundled into a platform you bought for an entirely different reason.

You open a new tab to check. You don't finish the list before the meeting.

That moment happens quietly enough that most executives never notice it happening to them. But the list you couldn't finish is the same list a regulator, a plaintiff's attorney, or a departing customer will eventually ask you to produce — without giving you even the forty-five minutes.

Why the list is wrong

(One scope note before we go on: this is an operating read on how this works in practice, and not legal advice.)

Procurement tracks what a system was bought to do — not everything it turns out to decide once it's live. So a carrier's AI inventory is a purchasing record: the initiatives on the roadmap, the tools that arrived labeled as AI. What's missing is the AI that came bundled inside something else. A fraud-scoring model inside a claims platform bought for throughput. A propensity model inside a retention tool bought to reduce churn. Both reach a customer, and neither shows up on anything a board would recognize as an AI list, because nobody bought them as AI.

This isn't one executive's bad afternoon. 68% of senior insurance leaders say their AI controls exist, but the evidence supporting them is fragmented across teams and tools [Source: Grant Thornton, "Insurance insights: 2026 AI Impact Survey," Apr 2026]. Fragmented evidence is what a blind spot looks like from the inside — every team can account for its own systems, and nobody holds the map.

And the map is the prerequisite for everything else. Whatever your position on owning models versus renting them, on governance committees, on correction rights — none of it can be applied to a system you haven't found. You cannot inspect, log, or fix a decision path nobody knows is there.

The exercise

Pick one customer-facing workflow — a quote, say, or a claim. Then name every system that shapes the outcome — not just the ones your team calls AI, every system. For each one, ask the question this whole series keeps coming back to: when it gets one wrong, what has to happen before the behavior changes, and who has to agree?

Run it once, on one workflow. We'd bet against most teams finishing the list on the first try, and the systems you forgot are the finding. They're the ones making decisions about your customers with nobody assigned to answer for them.

What you do with the map — which systems deserve ownership-grade scrutiny, which are fine rented — is a real question, and it has real answers. But it's the second question. You can't triage a list you haven't written.

So What

Someone is going to ask for this map before you're ready — a board member prepping for a governance discussion, a regulator following up on a complaint, an attorney building a case, or a customer walking away and telling the story of why. The map either exists before that conversation, or it gets built live, under worse terms, in front of someone with less patience than your own team.

Building it costs one workflow and an afternoon. That's the trade.

Want to run this on a real workflow?

Pick one workflow that touches a policyholder's rate, coverage, or claim, and run the inventory on it yourself. Or reach out and we'll walk one with you. The ask is to map one workflow — nobody's proposing an audit.

// Key Questions

Why can't most carriers list every place AI touches a policyholder decision?

Most carrier AI inventories track what was purchased and labeled as AI rather than everything currently shaping a customer decision. Models often arrive bundled inside other software — a fraud-scoring feature inside a claims platform, a propensity model inside a retention tool — bought for a different purpose entirely. Only 24% of senior insurance leaders say they're very confident they could pass an independent AI governance review within ninety days [Source: Grant Thornton, "Insurance insights: 2026 AI Impact Survey," Apr 2026], which points to a structural gap rather than a handful of outliers.

Does AI bundled inside other software count for AI governance purposes?

Yes. A fraud score, a propensity model, or a pricing signal embedded in a larger platform shapes customer outcomes the same way a standalone model does. In our view, what matters is the decision itself, not the packaging it arrived in. If a system influences a policyholder's rate, coverage, or claim, we'd argue it belongs on the carrier's AI inventory, regardless of what the purchase order said it was for.

What is an AI surface-area map, and how do you build one?

An AI surface-area map is an inventory of every system — labeled AI or not — that shapes a decision reaching a customer. The practical way to build one is a single-workflow exercise: pick one customer-facing workflow, list every system that influences the outcome, and record for each whether the decision path can be inspected and who has the authority to change it. One workflow takes an afternoon and usually surfaces at least one system nobody had assigned an owner.

Does a carrier need to own every AI system that touches a customer?

No. Much of a carrier's technology stack should stay rented. Deciding which systems deserve ownership-grade scrutiny — the ability to inspect, log, and correct a decision path — is a real question, but it comes after the map exists. You can't triage systems you haven't found.

Share
← Back to Insights