Back to blogStrategia

    AI Rating in insurance: the gate is the perimeter, not the process

    Insurers have solid validation processes applied to a narrower set of models than the regulation counts as AI systems. The three categories left outside, and what each class means.

    ZeroFive.AI July 6, 2026Updated on September 23, 2026 5 min

    In short. In insurance, AI Rating measures the same four dimensions as always, and the profile that emerges differs from banking: Delivery tends to be high thanks to existing model governance, while Risk stays exposed on one specific point, the systems that arrived from outside the actuarial function and never passed through validation. The gate blocking the class isn't a lack of processes, it's the perimeter those processes apply to.

    Insurers come to AI maturity measurement with a control framework more mature than almost any other sector. The result often surprises them, because the score doesn't reflect that maturity.

    The four dimensions through an insurance lens

    Readiness measures preparation, data, skills, infrastructure. In an insurer it is generally good on portfolio data and weaker on unstructured claims data, which is exactly where the most immediate use cases concentrate.

    Delivery measures the ability to reach production and maintain. It is the dimension where insurers sit above average, because the model lifecycle exists and works. The limit is that it applies to models recognised as such.

    Risk measures governance, compliance and ethics. The gap concentrates here. Annex III touches the core of the business, IVASS supervision is already present, and the data processed is often health data under Article 9 of the GDPR.

    Confidence measures management commitment, user trust and perceived robustness. In insurers it is often high within the technical function and low across the network, which uses tools without knowing what they do.

    The gate that closes: the perimeter, not the process

    The recurring profile is this: solid validation processes, applied to a narrower set of models than the regulation counts as AI systems.

    Three categories fall outside. Models bought from suppliers, where the company is a deployer and often has neither technical documentation nor visibility on updates. AI features switched on inside management software already in use, which nobody ever classified. Tools adopted by individual functions without passing through an adoption process.

    Until the inventory covers those three categories, the Risk dimension stays below threshold however good the validation of internal models is. And since the gates are non-compensable, the final class drops to the level of the constraint.

    Which actuarial models fall within the definition

    The most debated point in insurance assessments concerns which actuarial models fall within the regulation's definition of an AI system.

    The definition is broader than the one insurers use internally, and the practical consequence is that some models long treated as actuarial tools may fall inside the perimeter. Deferring that classification doesn't reduce the risk, it moves it: if the assessment gets made by an authority rather than by the company, it arrives with no room to prepare.

    The reasonable answer is to classify in writing, with the reasoning, including the cases where the conclusion is that a model stays outside. That documented reasoning is worth more than the conclusion.

    Which framework does your company actually need?

    AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.

    Start your AI Rating

    What a class means in practice

    ClassTypical situation in an insurerWhat's reasonable to do
    DSystems outside the actuarial function unmapped, no extended controlsBuild the complete inventory before new adoptions
    CSolid validation of internal models, incomplete perimeterExtend model governance to third-party systems
    BComplete perimeter, evidence in place, some areas exposedPrepare for audit and control Annex III systems
    AMature system verified across all dimensionsReserved for verified assessments, not self-assessments

    On that last row it's worth being explicit: a self-assessment does not produce a class A, because that class presupposes a structured verification with checked evidence.

    Why measure before allocating

    An insurer in class C allocating budget to bring AI onto pricing pays twice: once for the project that won't clear the controls, and again to redo it once the gates are closed.

    The same money, spent first on extending the perimeter, produces an organisation able to absorb subsequent projects. This is why rating belongs at the start of the planning cycle rather than as a final check on decisions already taken.

    Where to start

    The prerequisite is the AI system inventory, built around the three categories usually left outside. From there you verify the role for each system and extend the risk assessment.

    The full model, with the four dimensions and the gate logic, is described on the AI Rating page. The sector's regulatory picture is on the AI governance for insurance companies page.

    For an assessment of your company's position you can book a meeting or start the self-assessment.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI Rating#insurance#AI maturity#model governance#Annex III
    Share

    Keep reading