HomeGadgetsReviewsInsurers building AI governance frameworks ahead of regulators, says Relm's Christian Davies

Insurers building AI governance frameworks ahead of regulators, says Relm’s Christian Davies

Relm's Christian Davies explains how insurers are building AI governance frameworks ahead of formal regulation, with underwriters scrutinising human-in-the-loop controls, model provenance and agentic AI deployments.

Preferred Source of Google

Key Points

  • Insurers building AI risk frameworks ahead of regulation, similar to earlier crypto underwriting
  • Agentic AI attracting particular scrutiny due to reduced human involvement in processes
  • Companies uncertain whether existing cyber and liability policies cover AI exposures

Insurance underwriters are increasingly examining how companies deploy artificial intelligence, asking questions about governance controls, output validation and liability chains that regulators have yet to formalise. This scrutiny intensifies as businesses adopt agentic AI systems that can complete processes with minimal human oversight.

Christian Davies, global head of distribution and innovation at Relm, a specialty insurer focused on emerging technology risks, tells .in’s that “insurers have a history of building risk frameworks ahead of regulation, pointing to cryptocurrency underwriting as a precedent, adding that this isn’t unique to AI”.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →

Edited excerpts:

The EU has delayed key high-risk AI obligations until December 2027. Are insurers effectively imposing their own compliance regime before regulators, and what evidence are underwriters demanding from AI companies?

This is not unique to AI. Insurers have a track record of building their own risk frameworks well ahead of regulation across many industries. Crypto is the clearest precedent, where industry was very much at the forefront of underwriting when there was effectively no regulatory framework in any jurisdiction.

Advertisement

Much of what underwriters ask of AI companies is proprietary information I can’t pass on, but Claire Davey, the mind behind Relm’s AI products, summarises it as such: “At renewal, the questions are going to be practical. How are you using AI? Who is responsible for it? How are outputs checked? What governance do you have around the model? Can you evidence any of that?”

Which governance controls have a measurable impact on premiums, limits or exclusions, and which are still treated by insurers as largely cosmetic?

The real governance controls come down to things like human-in-the-loop oversight, meaning having a person cross-checking and cross-verifying outputs, and how structured the underlying datasets are. It also depends heavily on how the AI is being used.

Advertisement

A company running a fully open frontier model won’t necessarily know its own tolerances for hallucination, where a model generates plausible but false information, or understand the guardrails in place. So we’d always want to know what type of model is being used and whether it’s been built in-house or is a third-party model.

Where we’re spending real time at the moment is agentic AI, systems that can autonomously execute multi-step tasks with progressively less human intervention. By design, there’s less and less human involvement in the loop. Agentic AI can, within certain bounds, take a process from start to finish entirely on its own. That’s where the exploration around risk management and governance controls is happening right now.

When it comes to governance, insurers shouldn’t treat anything as cosmetic.

ISO’s generative AI exclusions could narrow coverage across cyber, technology errors and omissions and professional liability policies. Where are companies most likely to discover that risks they assumed were covered are now excluded?

As a former broker, my view has always been that cover only exists if it’s written in. I’ve never liked the grey area where people assume something is covered simply because it isn’t explicitly excluded. That’s exactly why we built AI products to give absolute affirmative coverage rather than leaving clients to rely on a “not excluded” position.

Right now, a lot of companies genuinely don’t know whether they have cover for AI-related exposures or not because AI use has moved so quickly and so many businesses are only just starting to use it day to day. This is really the same issue as silent AI, in the same way we’ve talked about silent cyber.

Take professional liability: the moment AI starts contributing to advice, where’s the line between the AI making the legal judgement and the lawyer making it? We’ve already seen cases where have relied on AI-generated that turned out to be fabricated and put it in front of courts. Has that lawyer exercised their own professional judgement or relied on artificial intelligence to do it for them? That question is getting harder to answer.

Are insurers distinguishing between companies that develop foundation models, deploy third-party models and merely integrate AI into existing products, or are exclusions being applied too broadly?

I think there are three camps. Some insurers are distinguishing between those categories. Some think they’re distinguishing but don’t understand what they’re looking at. And a third group has decided they want no exposure to anything AI-related at all, so they’re applying broad, sweeping exclusions regardless of how a company uses AI.

That’s not so different from how the ISO exclusions themselves work: they’re deliberately broad to avoid unintended coverage, which is also why premiums tend to run high on the forms that carry them.

Could reduced insurance protection offset the commercial benefit of the EU’s regulatory extension by making AI deployments harder to finance, contract or scale?

Yes. Insurance is an enabler. It brings legitimacy to an industry, it’s the financial backstop when things go badly wrong, and it’s the resiliency layer that lets innovation actually happen. If cover and limits shrink too far, businesses become far more hesitant to engage with frontier industries like AI simply because that backstop isn’t there anymore.

What would an AI company need to demonstrate today to remain insurable after a model failure, data leak, discriminatory outcome or copyright claim?

The exact insurability position depends on the facts of the risk. I would point companies first to the importance of affirmative coverage rather than assuming something is covered because it is not excluded.

When several vendors are involved in an AI system, where does responsibility sit?

Responsibility comes down to causation. In any insurance claim, you’ve got to establish where the loss originated and how it occurred. There are also rights of subrogation in insurance. So if an insurer pays a claim for its client, but another party was responsible for the loss, the insurer may then pursue that responsible party, or that party’s insurer, to recover the loss.

That becomes especially important with AI because one incident can involve several parties: the company using the AI, the model provider, a software vendor, a data provider or another third party.

Your Questions, Answered

Are insurers creating AI compliance requirements before regulators?

According to Relm's Christian Davies, insurers have a history of building risk frameworks ahead of regulation. With the EU delaying high-risk AI obligations until December 2027, underwriters are already asking companies about AI governance, output validation and human oversight controls.

What AI governance controls affect insurance premiums?

Davies says controls with measurable impact include human-in-the-loop oversight, structured underlying datasets, the type of model deployed and whether it is built in-house or sourced from a third party. Agentic AI systems face particular scrutiny due to reduced human involvement.

Do existing cyber and liability policies cover AI-related risks?

Many companies do not know whether they have AI coverage because the technology has moved quickly. Davies notes this is similar to the earlier 'silent cyber' problem, where coverage was assumed but not explicitly written into policies.

How is liability determined when multiple AI vendors are involved?

Responsibility comes down to causation, establishing where the loss originated. Insurers may use subrogation rights to pursue responsible parties, which becomes complex when incidents involve multiple parties such as model providers, software vendors and data providers.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Mohd Ujaley
Mohd Ujaley
Mohd Ujaley is a journalist specialising in the intersection of technology with government, public sector, defence and large enterprises. As Editorial Director at Tech Observer Magazine, he leads editorial strategy, moderates industry discussions and engages with key stakeholders to shape conversations around technology, policy and digital transformation. With over 15 years of experience, Ujaley has held editorial roles at prestigious publications including The Economic Times, ETGovernment, Indian Express Group, Financial Express, Express Computer and CRN India. He holds a Bachelor’s degree in Business Economics, a Master’s in Mass Communication from Guru Gobind Singh Indraprastha University (GGSIPU), a Parliamentary Fellowship from The Institute of Constitutional and Parliamentary Studies and a Certificate in Public Policy from St. Stephen’s College, Delhi.
Advertisement
- Advertisement -
- Advertisement -

Orient Technologies posts 161% jump in EBITDA, returns to profit in Q1

Orient Technologies reported a 161 per cent quarter-on-quarter surge in operating profit for Q1 FY27, with earnings per share returning to positive territory at ₹1.13 after a loss in the previous quarter.

RELATED ARTICLES