Governance
Artificial Intelligence In Claims.
The industry conversation, set out honestly: what AI is genuinely used for in claims, where it fails, what regulators now require, and the constraints any responsible deployment has to accept.
Kempron's position is about principles and constraints. It does not describe what Kempron builds, how it is built, or what it is built on.
The State Of Play
Where It Is Genuinely Used In Claims Today
The applications that work share a family resemblance.
Machine learning has been in production in insurance far longer than the current wave of interest suggests. The applications that work are narrow, measured against a clear ground truth, with a human being responsible for the consequential decision. The applications that fail tend to fail for the opposite reasons.
- Triage and routing. Directing a claim to the right handler, the right channel or the right level of scrutiny. Low regulatory exposure when it affects who looks at a file rather than what is decided.
- Document and image classification. Identifying what a document is, reading structured fields, sorting photographs. Mature, well understood, and measurable against a straightforward ground truth.
- Anomaly and network detection in fraud. Used to score files for investigation rather than to decline them. Équité Association, for instance, publicly describes its own platform as generating fraud risk scores to provide actionable intelligence to its members. (Équité Association, 11 February 2026.) The scoring supports an investigator; it does not replace one.
- Estimate review. Comparing an estimate against a body of comparable estimates to flag outliers for a human appraiser.
- Summarisation and drafting support. Compressing long files for a handler. Useful, and also the application where a plausible-sounding error is hardest to notice, because the output reads exactly like a correct one.
What is conspicuously not on that list is autonomous settlement of contested claims, autonomous liability determination, and anything that decides a bodily injury question without a human being accountable for it.
Failure Modes
Where It Fails, And Why
These are properties of the technology, not of any particular implementation.
- Confident wrongness. The characteristic failure of modern generative systems is not silence but fluency. An incorrect summary of a claim file is not obviously incorrect. It arrives in the same register as a correct one, which defeats the informal error-checking a reviewer would otherwise apply.
- Distribution shift. A model trained on one period, one book of business or one repair network degrades when any of those change. Vehicle technology, repair methods, fraud patterns and legal environments all move. A system that is not re-evaluated against current data is silently becoming less accurate while reporting the same confidence.
- Proxy discrimination. A model does not need a protected characteristic as an input to produce a disparate outcome. Postcode, vehicle type, occupation and repair network can all function as proxies. This is the failure mode regulators have concentrated on hardest, and correctly.
- Feedback loops. A system trained on historical decisions learns historical behaviour, including behaviour the organisation has since decided was wrong. Scrutiny directed by yesterday's pattern generates tomorrow's training data, and the pattern becomes self-confirming.
- Automation bias. Human oversight is the control every framework relies on, and it is the control most likely to be hollow in practice. A reviewer approving a high volume of recommendations under time pressure is not providing meaningful oversight, whatever the process diagram says.
- Unexaminable reasoning. A claims decision that cannot be explained after the fact is a decision that cannot be defended to an ombud, a regulator or a court. Accuracy does not cure this. The obligation is to account for the decision, not merely to have got it right.
- The evidence problem underneath all of it. A model applied to poor, late or contested inputs produces confident output from bad evidence. This is not a modelling failure; it is the structural problem described in The Claims Problem, and no amount of modelling sophistication substitutes for evidence captured properly in the first place.
Regulation
Why Regulators Care, And What They Now Require
Several jurisdictions moved within roughly four years of each other. The convergence is more informative than any single instrument. Each is set out on the regulator pages.
United States
The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It sets expectations for a written AI systems programme, board and senior management accountability, testing for unfair discrimination, documentation, and — directly relevant to a company like ours — oversight of third-party AI vendors and the data they supply. Alaska was the first state to adopt, on 1 February 2024. By August 2025, 24 states had adopted. (Adoption tracking as reported by Quarles & Brady and by Locke Lord's InsureReinsure, 2025.) Several large states, including California, Colorado, New York and Texas, run their own insurance-specific frameworks alongside or instead of it; New York's Department of Financial Services issued Circular Letter No. 7 in 2024 on AI and external consumer data in underwriting and pricing.
An insurer's obligations extend to its suppliers. A supplier that cannot support a customer's AI governance programme becomes a regulatory problem for that customer. The US framework in full.
European Union
The EU Artificial Intelligence Act entered into force on 1 August 2024 and applies in stages. Most prohibitions have applied since 2 February 2025. General-purpose AI model obligations began on 2 August 2025. Transparency obligations under Article 50 apply from 2 August 2026. Obligations for Annex III high-risk systems apply from 2 December 2027, and for Annex I high-risk systems from 2 August 2028. (Per the Future of Life Institute's AI Act resource, updated 31 August 2026 following the Digital Omnibus amendments.)
Annex III expressly lists AI systems used for risk assessment and pricing in health and life insurance as high-risk. The requirements on providers of high-risk systems are a reasonable proxy for where the whole field is heading: a lifecycle risk management system, data governance covering representativeness and error, technical documentation, automatic logging, instructions enabling deployer compliance, human oversight by design, accuracy and robustness, a quality management system, conformity assessment and registration.
Insurance Europe has stated that the AI Act and the General Data Protection Regulation together constrain the industry's ability to collect and process the data it needs to detect fraud. (Insurance Europe, 5 December 2024.) The EU framework in full.
Canada
Canada has no insurance-specific AI statute in force. The operative constraints come from privacy law and prudential guidance. Quebec's Law 25 confers rights in respect of decisions based exclusively on automated processing of personal information. OSFI Guideline B-13 governs technology and cyber risk for federally regulated insurers, and Guideline B-10 governs third-party arrangements including those involving a supplier's technology. The Canadian framework in full.
United Kingdom
The United Kingdom has taken a regulator-led rather than statute-led approach. The FCA's Consumer Duty raises the standard for outcomes delivered to retail customers, which bears directly on claims handling, and the ABI maintains a dedicated AI regulation policy position. Data protection sits under the UK GDPR and the Data Protection Act 2018. The UK framework in full.
South Africa
South Africa has no insurance-specific AI instrument. The operative constraint is the Protection of Personal Information Act 4 of 2013, supervised by the Information Regulator, which restricts decisions based solely on automated processing of personal information, alongside the FSCA's conduct supervision and the Treating Customers Fairly framework. The South African framework in full.
Australia
Australia has no insurance-specific AI instrument either, but it has something more consequential for automation: claims handling and settling is itself a licensed financial service, requiring an Australian Financial Services licence since 1 January 2022. (ASIC Information Sheet 253.) Automation of a licensed activity inherits the licensee's general obligations, including to provide services efficiently, honestly and fairly. APRA's Prudential Standard CPS 230, in force from 1 July 2025, adds explicit service provider management obligations. The Australian framework in full.
The common thread. Every one of these frameworks asks the same four questions. Who is accountable? Can you show what the system did and why? Have you tested for unfair outcomes? Is a human being meaningfully in control of consequential decisions? A supplier able to answer those four questions can work in all of these jurisdictions.
Our Position
Kempron's Constraints
What follows are commitments about conduct. They are not a description of our technical approach, which we do not publish.
- Accountability stays with the insurer. The insurer carries the regulatory accountability for how a claim is handled. Nothing we build relocates a consequential decision away from the accountable party without that being explicit, agreed and documented.
- Explainability is a precondition, not a feature. If a step cannot be explained after the fact to the insurer, and if required to a regulator, an ombud or a court, it does not belong in a claims process.
- Human oversight has to be real to count. Oversight that consists of approving a queue of recommendations under time pressure is not oversight. Where a human control is claimed, it should be designed so the human can actually exercise it, and the organisation should be able to tell whether they are.
- Testing for disparate outcomes is continuous. Proxy discrimination does not require a protected characteristic as an input, so its absence from the inputs proves nothing. Where an insurer is obliged to test, we support the testing rather than assert that our part is exempt.
- Evidence first, inference second. A model applied to poor inputs produces confident output from bad evidence. The quality and timeliness of what is captured is the prior question.
- Scope discipline. Narrow tasks with clear ground truth and measurable error are where this technology earns its place. Open-ended judgement about contested questions is not.
- We support the customer's governance programme. Where an insurer operates an AI systems programme under the NAIC model bulletin or an equivalent, a supplier's job is to make that programme evidenceable. Documentation, logging and testing support are part of the engagement, not an extra.
- We do not publish our technical approach. Which techniques we use, how systems are built and what they are built on are not disclosed on this site. Under a mutual non-disclosure agreement, and as part of a third-party risk assessment, a counterparty receives what it needs to assess us properly.
What We Will Not Say
- Kempron is not described as AI-powered. The claim is not a substitute for a result measured against your own baseline.
- Kempron publishes no accuracy figures, detection rates or other performance claims.
- Kempron does not assert that a system is unbiased. Disparate outcomes are tested for continuously, and the testing can be shown.
- Kempron does not propose a deployment whose effect on the insurer's regulatory accountability it cannot explain in writing.