// Line of business
The hard part is different in every line.
Insurance AI does not fail generically. It fails in ways specific to the line: the schedule that reads as authoritative when it was never right, the severity set in a courtroom, the form that is bespoke by design, the loss with no historical analog. Start where your documents are.
Each page below is written in the artifacts and the formats, not in use cases. If the detail is wrong, you will know inside a paragraph.
// The situation
The line decides the build. The state, what ships.
Roughly half the states have adopted the NAIC AI Model Bulletin, and New York’s Department of Financial Services states the position plainly: an insurer cannot rely solely on a third party’s claim of non-discrimination. Colorado’s expanded Regulation 10-1-1 compliance deadline passed on 1 July 2026, and the NAIC’s AI Systems Evaluation Tool is in pilot with adoption expected at the 2026 Fall National Meeting.
NAIC and state bulletins · current at September 2026.
Regulatory responsibility is non-delegable. Buying a product does not move the obligation, which means the governance file is part of the build rather than a document somebody writes afterward. Every page below names the surface it has to satisfy.
// What is actually hard, by line
Five lines. Five different failure modes.
Page live
Commercial property →
A cleaned schedule looks authoritative whether or not the values in it were ever right, and the modifiers that most change modeled loss are the fields most often blank.
Page live
Commercial auto and fleet →
Severity is being set in courtrooms by noneconomic-damage anchoring, jurisdiction and jury composition, none of which is in your submission data.
Page live
Excess and surplus →
Freedom of rate and form means the wording is bespoke per risk, which is exactly what defeats models trained on standardized documents.
Page live
Cyber →
The loss distribution is dominated by rare correlated events with no historical analog, so there is nothing underneath a severity model to train it on.
Outside our operating record
Life, health and group benefits
Fully automated adverse decisions are already unlawful in a growing list of states, in health insurance first — AI may inform, a licensed human must decide, and the insurer has to be able to show its work.
// We ran one of these
We spent a decade building and operating an AI-native carrier — underwriting, claims, servicing, distribution, the regulators and a P&L we had to answer for — which is why these pages are written in schedules, loss runs and filings rather than in capabilities.
The operating record →// What's hard about this
Two things are true in all five.
The fact that decides the file is usually not in the document you were given.
Roof geometry is missing from the schedule. The reason the admitted market declined the risk was communicated by phone. The MFA answer is technically true and operationally meaningless. In each case the extraction is easy and the decision still is not, because the governing input was never written down. So the build reports its own confidence: every value arrives labeled extracted, inferred or defaulted, and the labels are data rather than a footnote. A system that normalizes a document without reporting how much of it was inferred has made the file harder to reason about, not easier.
Every model in these lines is trained on a series that has moved.
Auto severity, cyber aggregation and secondary-peril frequency are all structurally non-stationary, and a model fitted to the old series prices to a trend that keeps moving. The answer is not a better fit. It is to build where the historical series still holds — extraction, reconciliation, frequency, compliance assembly — and to instrument the moving part separately, so the thing that changed is visible as a measurement rather than absorbed silently into a score.
// What ships with it
The governance file is scoped to the line, not the vendor.
Every build leaves with a model inventory entry, data lineage, pre-deployment testing results, drift thresholds with remediation triggers, and a named human decision-maker specification. What varies is the surface it has to satisfy: outcomes testing in Colorado, an annual compliance certification attested by a named officer in Connecticut, wording that says eliminate rather than mitigate the risk in Virginia.
State AI bulletins and regulations · current at September 2026.
Bring us one workflow.
We will tell you where the work actually goes on that line, and which part is worth building first.