The conversation around artificial intelligence in insurance has moved beyond whether and when to adopt it, according to Tim Hardcastle (pictured), chief executive and co-founder of INSTANDA. Increasingly, the challenge is demonstrating that AI produces good customer outcomes when regulators ask questions.
"The FCA's positioning has changed the narrative into, 'How do you show us?'" Hardcastle said. "That's a much harder question to answer because firms have to show evidence the AI they're using produces good outcomes."
He sees the FCA's direction as complementary to the EU AI Act, with both increasingly focused on transparency, auditability and delivering good customer outcomes. Ultimately, the question for insurers is whether they can, as Hardcastle puts it, "stand behind it in front of a regulator."
The divide between early adopters and more cautious insurers is also familiar. Hardcastle believes the first wave of Insurtech adoption is repeating itself, with smaller brokers and MGAs generally moving faster than large, tier-one insurers.
"There is this spectrum of smaller brokers, smaller MGAs who have less committed [governance] to go through to approve things – they will be faster adopters," he said, noting that speed can create an advantage, but it also creates a different risk profile. A cyber incident at a smaller MGA may attract less immediate attention than the same event at a household-name insurer, but lighter governance and more limited security resources can make smaller firms more exposed. If an incident did become public, the consequences could be far more severe.
Governance, however, cannot simply mean slowing everything down, Hardcastle shares. When businesses are encouraged to explore AI but are not given clear guidance on which tools are approved, the use of unauthorised “shadow” AI tools surfaces.
Many firms are responding by introducing approved AI tools, localising data so confidential information does not feed external training models, and strengthening security around AI deployments rather than attempting to secure the models themselves directly. Securing the underlying models, he said, is "not impossible, but very, very difficult."
He also pointed to the Bank of England deputy governor's proposal for an AI "kill switch" that would disconnect systems automatically if suspicious behaviour was detected. Anthropic’s disclosure that state-sponsored actors had manipulated Claude Code as part of a cyber-espionage campaign, illustrates why such safeguards matter. While the incident was not a data breach in the narrowest sense, the wider industry discussed it with similar seriousness since manipulated AI systems can still enable data exposure, operational disruption and reputational harm.
AI adoption differs markedly across the insurance value chain. Data ingestion – turning unstructured broker information such as emails, drawings and photographs into usable data – is where Hardcastle sees the highest adoption, since insurers regard it as comparatively low risk provided there is governance to catch hallucinations or misinformation.
Pricing, however, is a different proposition, particularly in personal lines. Traditional rating models can be audited and justified to regulators because their logic is transparent. Current AI models do not offer the same level of explainability, making widespread adoption in personal lines unlikely in the near term.
"I don't believe that we will see AI being used for pricing anytime soon," he said, although AI could still help refine pricing models by identifying additional rating factors through pattern analysis that a human might not spot.
Commercial lines are different again. There, AI acts as an assistant to underwriters, automating information requests and support, "but it doesn't make your decision."
Claims is following a similar path, with AI agents increasingly handling first notification of loss and other routine tasks. They should not, however, be allowed to decide independently whether to pay a legitimate claim, or not. There must be human involvement in any step of the decision making process.
The bigger challenge is often the quality of the underlying data rather than AI itself. Poor-quality or inconsistent information produces the same flawed conclusions in generative AI as it did in traditional machine learning. Hardcastle compares the effect to the Leaning Tower of Pisa.
"If your foundations are slightly off and then you rapidly build something, it ends up skewing."
Clients across INSTANDA's global customer base consistently report that data, workflows and processes need to work well before AI is layered on top, not the other way round.
The wider market is reaching a similar conclusion. MIT's 2025 State of AI in Business report found that 95% of enterprise AI pilots fail to reach production, something Hardcastle believes reflects firms still testing how predictable the technology really is before trusting it with business-critical decisions.
That need for solid foundations also underpins what he sees as one of the industry's most important distinctions: being AI-enabled rather than AI-led.
"Being AI led puts you in a position where you will ultimately not be able to stand in front of a regulator and say this is how the decisions were made, because the AI effectively would be making the decisions," he said.
He does not believe that approach is compatible with insurance's obligations around fairness, transparency and consumer protection. The same principle, he argues, applies equally to technology vendors supporting the industry.
"The community of technology vendors supporting [insurers] all have to be AI-enabled for the industry to work within the regulatory framework."