The FCA has made its position clear: no new AI rules, but full accountability under existing frameworks. For UK insurers and brokers, that means the governance work starts now

AI adoption in UK insurance is a governance problem, not a technology problem

The FCA has chosen not to introduce an AI-specific rulebook. It has instead applied its existing principles-based framework – Consumer Duty, the Senior Managers and Certification Regime, SYSC governance requirements, and operational resilience obligations – to AI use cases. The message to regulated firms is clear: as the FCA’s chief data officer Jessica Rusu put it, SM&CR and Consumer Duty together provide “enough regulatory bite that we don’t need to write new rules for AI.”

That message is simultaneously reassuring and demanding. Firms do not need to build an entirely new compliance framework. But every AI deployment must be defensible within accountability structures that were not designed for algorithmic decision-making – and must remain defensible as the technology evolves faster than annual regulatory reviews can track.

For UK insurance firms and brokers, where AI adoption is running ahead of governance maturity, that gap is where the real exposure sits.

What the regulatory framework requires in practice

The FCA’s Consumer Duty, in force for all products and services since July 2024, requires firms to produce good outcomes for customers and demonstrate, on an ongoing basis, that they are doing so. Applied to AI, this means a model influencing pricing, claims handling, or customer communications must be monitored for outcomes, auditable for decisions, and explainable when challenged. The accountability for that model’s behaviour sits with an identified senior manager under SM&CR.

The FCA’s June 2024 multi-firm review of insurance outcomes monitoring found wide variation in quality across the sector. As AI is integrated into more of the processes driving those outcomes, firms with weak monitoring frameworks are increasingly exposed – not to a future AI-specific regime, but to the Consumer Duty obligations already in force.

The data picture reinforces the urgency. Gallagher‘s 2026 AI Adoption and Risk survey found that fewer than half of businesses have adopted formal risk management frameworks for AI, even as most are now implementing AI solutions. Among UK firms, 56% rated their AI knowledge as beginner or novice. Having a governance framework on paper is not the same as operating within one in practice – and the FCA review of outcomes monitoring has already demonstrated that it can tell the difference.

The integrity-first approach

Eugene Owusu, director of transformation and global compliance at Liberty Mutual Insurance, frames AI governance in terms that go beyond regulatory compliance. “Key for me is making sure that conversations include the right SMEs and the right regulatory knowhow, because at Liberty, one thing that we’re keen on is making sure that it’s integrity first.”

That distinction is vital. A compliance-first approach to AI governance asks: what do the regulations require? An integrity-first approach asks: what decisions is this system making, can we stand behind them, and can we demonstrate to our customers and our regulator that we can? The latter is more demanding and produces more durable governance – because it does not stop at the regulatory minimum.

Owusu is specific about what AI is actually delivering at Liberty: an acceleration of data work that previously took significant time. But the emphasis on data lineage, on people taking ownership of data quality, and on migrations landing with the right data in the right systems reflects a measured posture – AI as an accelerant for work that still requires human judgement and regulatory accountability, not a replacement for either.

Where governance depends on people, not systems

George Dagnall, NED at Hotspot Cover and director of insurance and partnerships at Concentrix, works in lines where the human judgement dimension is not theoretical. In medical crisis response, kidnap and ransom, and related specialist areas, the knowledge required to respond effectively cannot be reduced to an algorithm. “Those skills and that development cannot be easily replaced by just hiring tech-native individuals,” he said.

That observation reaches beyond specialist lines. The governance of AI in any insurance context depends on people who understand what the system is deciding and can evaluate whether those decisions are sound. A firm whose workforce lacks the domain knowledge to interrogate AI outputs cannot govern those outputs in any meaningful sense – and under SM&CR, the named senior manager responsible for a model’s behaviour needs to be able to demonstrate that the governance is real.

Paul Waring, director of IT and CISO at Blagrove Underwriting Agency, draws the same line from the technology side. At Blagrove, the in-house model means every change to the production system – made several times a week – is a change the firm’s own people understand, have tested, and can account for. That level of transparency is harder to maintain when the capability sits with a vendor. It is not impossible, but it requires deliberate governance investment rather than assumption.

The gap the FCA is watching

The FCA’s position is that the governance obligation exists from the moment AI is deployed, not from the moment a regulatory review arrives. The accountability framework is the existing one. The technology is the new variable.

For a broker or insurer deploying AI in customer-facing processes, claims handling, or pricing, the starting question is not “what does the FCA require of AI?” but “how does this deployment interact with our Consumer Duty obligations, our SM&CR accountability map, and our operational resilience framework?” Those questions have answers. Working through them before deployment, rather than after a supervisory visit, is the difference between governance and compliance theatre.

Source

contact us