Governance
Artificial Intelligence In Claims.
The industry conversation, set out honestly: what AI is genuinely used for in claims, where it fails, what regulators now require, and the constraints any responsible deployment has to accept.
Kempron's position here is about principles and constraints. This page does not describe what Kempron builds, how it is built, or what it is built on.
The State Of Play
Where AI Is Genuinely Used In Claims Today
The honest version, separated from the marketing.
Machine learning has been in production in insurance for far longer than the current wave of interest suggests, and the applications that work share a family resemblance: they are narrow, they are measured against a clear ground truth, and a human being remains responsible for the consequential decision. The applications that fail tend to fail for the opposite reasons.
- Triage and routing. Directing a claim to the right handler, the right channel or the right level of scrutiny. Low regulatory exposure when it affects who looks at a file rather than what is decided.
- Document and image classification. Identifying what a document is, reading structured fields, sorting photographs. Mature, well-understood, and measurable against a straightforward ground truth.
- Anomaly and network detection in fraud. Used to score files for investigation rather than to decline them. Équité Association, for instance, publicly describes its own platform as generating fraud risk scores to provide actionable intelligence to its members. (Équité Association, 11 February 2026.) The scoring supports an investigator; it does not replace one.
- Estimate review. Comparing an estimate against a body of comparable estimates to flag outliers for a human appraiser.
- Summarisation and drafting support. Compressing long files for a handler. Useful, and also the application where a plausible-sounding error is hardest to notice, because the output reads exactly like a correct one.
What is conspicuously not on that list is autonomous settlement of contested claims, autonomous liability determination, and anything that decides a bodily injury question without a human being accountable for it.
Failure Modes
Where It Fails, And Why
Worth stating in detail, because a vendor who cannot describe the failure modes of their own category should not be trusted with the category.
- Confident wrongness. The characteristic failure of modern generative systems is not silence but fluency. An incorrect summary of a claim file is not obviously incorrect. It arrives in the same register as a correct one, which defeats the informal error-checking a reviewer would otherwise apply.
- Distribution shift. A model trained on one period, one book of business or one repair network degrades when any of those change. Vehicle technology, repair methods, fraud patterns and legal environments all move. A system that is not re-evaluated against current data is silently becoming less accurate while reporting the same confidence.
- Proxy discrimination. A model does not need a protected characteristic as an input to produce a disparate outcome. Postcode, vehicle type, occupation and repair network can all function as proxies. This is the failure mode regulators have concentrated on hardest, and correctly.
- Feedback loops. A system trained on historical decisions learns historical behaviour, including behaviour the organisation has since decided was wrong. Scrutiny directed by yesterday's pattern generates tomorrow's training data, and the pattern becomes self-confirming.
- Automation bias. Human oversight is the control every framework relies on, and it is the control most likely to be hollow in practice. A reviewer approving a high volume of recommendations under time pressure is not providing meaningful oversight, whatever the process diagram says.
- Unexaminable reasoning. A claims decision that cannot be explained after the fact is a decision that cannot be defended to an ombudsman, a regulator or a court. Accuracy does not cure this. The obligation is to account for the decision, not merely to have got it right.
- The evidence problem underneath all of it. A model applied to poor, late or contested inputs produces confident output from bad evidence. This is not a modelling failure; it is the structural problem described in The Claims Problem, and no amount of modelling sophistication substitutes for evidence captured properly in the first place.
Regulation
Why Regulators Care, And What They Now Require
Four jurisdictions moved within roughly three years of each other. The convergence is more informative than any single instrument.
United States
The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It sets expectations for a written AI systems programme, board and senior management accountability, testing for unfair discrimination, documentation, and — directly relevant to a company like ours — oversight of third-party AI vendors and the data they supply. Alaska was the first state to adopt, on 1 February 2024. By August 2025, 24 states had adopted the bulletin, with Wisconsin the most recent at that point. (NAIC adoption tracking as reported by Quarles & Brady and by Locke Lord's InsureReinsure, 2025.) Several large states, including California, Colorado, New York and Texas, operate their own insurance-specific AI frameworks alongside or instead of the model bulletin.
The practical consequence for a vendor is that an insurer's obligations extend to its suppliers. A supplier who cannot support a customer's AI governance programme is a supplier who creates a regulatory problem.
European Union
The EU Artificial Intelligence Act entered into force on 1 August 2024 and applies in stages. Most prohibitions have applied since 2 February 2025. General-purpose AI model obligations began on 2 August 2025. Transparency obligations under Article 50 apply from 2 August 2026. Obligations for Annex III high-risk systems apply from 2 December 2027, and obligations for Annex I high-risk systems from 2 August 2028. (EU AI Act, as summarised by the Future of Life Institute's AI Act resource, updated 31 August 2026 following the Digital Omnibus amendments.)
Annex III expressly lists AI systems used for risk assessment and pricing in health and life insurance as high-risk. The requirements placed on providers of high-risk systems are a reasonable proxy for where the whole field is heading: a risk management system across the lifecycle, data governance covering representativeness and error, technical documentation, automatic logging, instructions enabling deployer compliance, human oversight by design, accuracy and robustness, a quality management system, conformity assessment and registration. (EU AI Act, Articles 8 to 21, as summarised in the same source.)
Insurance Europe has said openly that the AI Act and the General Data Protection Regulation together constrain the industry's ability to collect and process the data it needs to detect fraud. (Insurance Europe, 5 December 2024.) That tension is real and is not resolved by choosing a side.
Canada
Canada has no insurance-specific AI statute in force. The operative constraints come from privacy law and from prudential guidance. Quebec's Law 25 confers rights in respect of decisions based exclusively on automated processing of personal information. OSFI Guideline B-13 governs technology and cyber risk for federally regulated insurers, and Guideline B-10 governs third-party arrangements including those involving a supplier's technology. The detail is on the Regulators page.
United Kingdom And Australia
The United Kingdom has taken a regulator-led rather than statute-led approach; the Association of British Insurers maintains a dedicated AI regulation policy position, and the FCA's Consumer Duty raises the standard for outcomes delivered to retail customers, which bears directly on claims handling. In Australia, conduct is supervised by ASIC, prudential matters by APRA, and the General Insurance Code of Practice administered by the Insurance Council of Australia sets service standards for claims.
The common thread. Every one of these frameworks asks the same four questions. Who is accountable? Can you show what the system did and why? Have you tested for unfair outcomes? Is a human being meaningfully in control of consequential decisions? A vendor who can answer those four questions can work in all of these jurisdictions. One who cannot will struggle in any of them.
Our Position
Kempron's Constraints
What follows are commitments about conduct. They are not a description of our technical approach, which we do not publish.
- Accountability stays with the insurer. The insurer carries the regulatory accountability for how a claim is handled. Nothing we build relocates a consequential decision away from the accountable party without that being explicit, agreed and documented.
- Explainability is a precondition, not a feature. If a step cannot be explained after the fact to the insurer, and if required to a regulator, an ombudsman or a court, it does not belong in a claims process. We would rather ship a less sophisticated process that can be defended than a more sophisticated one that cannot.
- Human oversight has to be real to count. Oversight that consists of approving a queue of recommendations under time pressure is not oversight. Where a human control is claimed, it should be designed so the human can actually exercise it, and the organisation should be able to tell whether they are.
- Testing for disparate outcomes is continuous. Proxy discrimination does not require a protected characteristic as an input, so its absence from the inputs proves nothing. Where an insurer is obliged to test, we support the testing rather than assert that our part is exempt.
- Evidence first, inference second. A model applied to poor inputs produces confident output from bad evidence. We regard the quality and timeliness of what is captured as the prior question, and we are sceptical of any claim that modelling sophistication compensates for it.
- Scope discipline. Narrow tasks with clear ground truth and measurable error are where this technology earns its place. Open-ended judgement about contested questions is not, and we will say so in a sales conversation.
- We support the customer's governance programme. Where an insurer operates an AI systems programme under the NAIC model bulletin or an equivalent, a supplier's job is to make that programme evidenceable. Documentation, logging and testing support are part of the engagement, not an extra.
- We do not publish our technical approach. Which techniques we use, how systems are built and what they are built on are not disclosed on this site. Under a mutual non-disclosure agreement, and as part of a third-party risk assessment, a counterparty receives what it needs to assess us properly.
What We Will Not Say
- We will not describe Kempron as AI-powered as a marketing position. The phrase has become a claim that carries almost no information, and it is not a substitute for a result measured against your baseline.
- We will not publish accuracy figures, detection rates or any other performance claim. The reasoning is in the FAQ.
- We will not assert that a system is unbiased. The honest statement is that an organisation tests for disparate outcomes, continuously, and can show the testing.
- We will not propose a deployment whose effect on the insurer's regulatory accountability we cannot explain in writing.