Executive summary
Insurance leads every other financial services sector in AI adoption - and trails in governance confidence. The Bank of England and FCA's most recent joint survey found 95% of insurance firms already using AI, the highest of any sector surveyed, yet only around a third of financial services firms report a complete understanding of the AI technologies they deploy. EIOPA's February 2026 survey of European insurers found nearly two-thirds actively using generative AI, with most deployments stuck at proof-of-concept and governance frameworks trailing adoption.
That gap - between what firms are deploying and what they can defend to a supervisor - is now the binding constraint on customer-facing AI in insurance. It is not a technology problem. The models are capable. The constraint is that most AI vendors cannot answer the questions a compliance function is obliged to ask: where does this system sit relative to the regulated activities perimeter, how are its answers grounded and evidenced, what happens when it should not answer, and who is accountable when it gets something wrong.
2026 is the year the gap closes, one way or the other. The EU AI Act's chatbot-disclosure obligations apply from 2 August 2026 - the one AI Act deadline the Digital Omnibus did not move, and the date from which regulators can fine for breaching it. The FCA will publish its good and poor practice report later this year, shaped by the firms already testing customer-facing AI under its observation. And the FCA's Mills Review, published in July 2026, has put the regulatory perimeter for AI-driven financial guidance on the regulator's desk with a three-to-six-month clock.
This paper sets out how the UK and EU regulatory frameworks actually apply to AI assistants in insurance servicing; where the perimeter between information, guidance and regulated advice sits; what supervisors have said they expect; and a due-diligence checklist that compliance teams can apply to any vendor.
Our position is straightforward: the regulation is not the obstacle. Unaccountable deployment is. Firms that treat governance as a design input rather than a procurement afterthought are already moving AI assistants into production, in some cases under direct FCA observation.
1. The adoption–governance gap
The data describes a sector that has adopted faster than it has governed.
The Bank of England and FCA's third survey of AI in UK financial services (November 2024) found that 75% of firms are already using AI, up from 58% in 2022 - and that insurance leads all sectors at 95%. A third of all AI use cases are third-party implementations, roughly double the 2022 figure, meaning the governance question increasingly runs through vendors rather than in-house teams. Yet only 34% of firms reported a "complete understanding" of the AI they use; 46% reported partial understanding. Firms named the Consumer Duty among their largest perceived regulatory constraints on AI use, behind only data protection and resilience rules. The same pattern holds in the EU: in EIOPA's 2026 survey, only 49% of insurers had a dedicated AI policy in place - up from a quarter in 2023, but still trailing the two-thirds already using the technology.
The result is a pattern the FCA has repeatedly described: pilots that never reach production because the firm cannot demonstrate the governance, assurance and resilience needed to deploy safely. The regulator has been explicit that its Live Testing programme exists partly to help firms move beyond such "perpetual pilots."
In January 2026, the House of Commons Treasury Committee sharpened the pressure from the other direction, warning that the current wait-and-see posture risks "serious harm to consumers and the wider system" and recommending that the FCA publish practical AI guidance by the end of 2026 - including a clearer account of who inside firms is accountable for AI-caused harm. In July 2026 the FCA's Mills Review answered in part, mapping how AI could reshape retail financial services by 2030 and recommending that the regulator examine, within three to six months, the AI models providing financial guidance outside its perimeter.
The commercial consequence is a widening split. A small group of firms - including NatWest, Monzo, Santander and Scottish Widows in the FCA's first Live Testing cohort from December 2025, and Barclays, UBS and Experian in the second, which began testing in April 2026 - are testing customer-facing AI in production, under supervisory observation, and will shape the FCA's forthcoming good and poor practice publication, with a full programme evaluation due in early 2027. Everyone else will be measured against what that group establishes.
2. The UK framework: no new rules is not no rules
The FCA's position, restated consistently through 2025 and 2026, is that it will avoid additional regulation for AI by relying on existing frameworks. There is no AI rulebook. There are, instead, three existing regimes that together answer almost every question a firm will face when deploying an AI assistant:
The Consumer Duty. The Duty requires firms to act to deliver good outcomes for retail customers across four outcomes: products and services, price and value, consumer understanding, and consumer support. An AI assistant sits squarely inside the last two. If an assistant gives a member a wrong answer about their cover, that is a consumer understanding failure. If it strands a claimant in a loop with no route to a human, that is a consumer support failure - and the FCA's guidance on the fair treatment of vulnerable customers (FG21/1) applies with particular force to a channel that vulnerable members may reach at moments of bereavement, illness or financial distress. The Duty is outcomes-based and technology-neutral: the firm cannot outsource accountability for the answer to the model, or to the vendor.
The Duty also cuts the other way, in the deploying firm's favour. Its monitoring obligations require firms to evidence customer outcomes - and an AI assistant, properly instrumented, generates exactly that evidence: what customers asked, what they misunderstood, where journeys failed, which cohorts struggled. Interaction data that a call centre loses in disposition codes becomes, in an AI channel, a continuous Consumer Duty outcomes dataset.
The Senior Managers and Certification Regime. The SM&CR answers the accountability question the Treasury Committee raised: a named senior manager is responsible for the activities within their remit, and deploying an AI system does not dilute that responsibility. The Bank/FCA survey found 84% of firms using AI already assign an accountable person for their AI framework, and 72% place accountability with executive leadership. The practical implication for procurement is that the accountable SMF-holder must be able to understand and defend the system - which sets a floor on the explainability and auditability a vendor must provide.
Existing conduct and systems-and-controls rules. Outsourcing rules, operational resilience requirements, and SYSC governance obligations all apply to third-party AI exactly as they apply to any other material outsourced service. With a third of AI use cases now third-party built, the FCA's supervisory interest in vendor governance is structural, not incidental.
On top of this, the FCA is generating supervisory expectations through engagement rather than rulemaking: the AI Lab, the Supercharged Sandbox, Live Testing cohorts through 2026, the Mills Review (launched January 2026, with input closing that February and findings published in July 2026), and a good and poor practice publication due later in 2026. That publication will be the nearest thing UK financial services has to AI guidance. Firms deploying now should design against the direction of travel it will codify: the FCA has said it evaluates the AI system - model, deployment context, governance, human-in-the-loop arrangements, and input and output controls - not the model in isolation.
3. The perimeter question: when does an answer become advice?
This is the question most vendors avoid and every compliance officer asks first.
An employee types: "Am I covered for physio?" Depending on how the system answers, that interaction is factual information, non-advised guidance, or a regulated activity. The boundary matters because insurance distribution - advising on, proposing, or carrying out other work preparatory to the conclusion of contracts of insurance - is a regulated activity in the UK under FSMA and the Regulated Activities Order, and across the EU under the Insurance Distribution Directive. An answer that steers a specific person towards a specific product, framed around their circumstances, starts to look like advice or arranging, and the firm whose permissions cover that activity needs to be identifiable.
The FCA has flagged this exact issue, twice this year. Its March 2026 perimeter report highlighted the rapid growth of general-purpose AI tools offering financial guidance and recommendations - AI chatbots prominent among them - and noted that such tools may not fit neatly within existing frameworks, raising the question of whether current perimeter boundaries adequately protect consumers. The Mills Review, published in July 2026, went further: it observed that personalised, adaptive chatbot responses can start to resemble regulated advice, and recommended the FCA examine the scale, nature and market effect of AI models sitting outside its perimeter within three to six months. The question this section addresses is now on the regulator's desk, not merely on ours. The industry, meanwhile, is already navigating the line in practice: Scottish Widows' AI investment tool, tested within the FCA's Live Testing programme, is explicitly designed to provide guidance rather than regulated advice - "a satnav for investments" that informs without deciding - precisely because the distinction determines which rules apply.
For an insurer or benefits provider deploying an AI assistant, the perimeter question decomposes into three practical design requirements:
Scope control. The system must know what kinds of answers it is permitted to give - factual policy information, signposting, guided processes - and decline or hand off when a query crosses into personal recommendation territory. This cannot be a prompt-level aspiration; it must be an enforced, testable control.
Attributable permissions. When an interaction does constitute or approach regulated activity - a mid-term adjustment, a claims notification, surfacing a voluntary product - someone's regulatory permissions must cover it. General-purpose AI vendors sit outside the perimeter and leave the deploying firm to absorb the whole analysis. A vendor that is itself an authorised insurance intermediary can architect the answer differently, because it has had to do this analysis for its own regulatory status. To be clear about what this does and does not change: nothing transfers the deploying firm's accountability under the Duty and SM&CR - no vendor arrangement can. What an authorised vendor changes is the architecture of the answer and the evidence behind it.
Evidence. Whatever position the firm takes on where its assistant sits, it must be able to evidence it: what the system said, on what basis, within what configured limits. The perimeter is defended with records, not intentions.
One further point of precision, because benefits journeys involve several parties whose obligations differ. The insurer carries product responsibility and, under the Duty, accountability for outcomes in its distribution chain; an authorised intermediary carries the permissions for the distribution activities it performs; the employer arranging cover for its staff typically sits outside FSMA authorisation, subject to conditions; and a pure technology provider carries none of these - which is why the perimeter analysis cannot be left to it. Any deployment should be able to state which of these roles each party occupies, in writing.
Onsi's own position is a matter of public record: Onsi operates as both a technology provider and an authorised insurance intermediary, regulated by the FCA in the UK, the AFM in the Netherlands and the Danish FSA. We built the platform's scope controls, hand-off logic and audit architecture because our own permissions depend on them. We regard that as the correct starting point for anyone selling AI into this sector.
4. The EU overlay: the AI Act and EIOPA's expectations
Firms operating across the UK and EU - as most group benefits providers do - face a second framework that is rules-based where the UK's is outcomes-based.
The EU AI Act (Regulation 2024/1689), as amended by the Digital Omnibus on AI - on which the Council and Parliament reached political agreement on 7 May 2026, with the Parliament voting on 16 June 2026 and formal adoption pending. Four points matter for insurance servicing assistants:
- High-risk classification is narrower than commonly assumed - and now later than originally scheduled. In insurance, the Act's high-risk category (Annex III) captures AI systems used for risk assessment and pricing in life and health insurance. A servicing assistant that explains cover, guides claims and surfaces benefits is not, in itself, performing risk assessment or pricing - most such deployments fall into the limited-risk tier. Under the Omnibus agreement, the high-risk obligations that were due on 2 August 2026 are deferred to 2 December 2027 for Annex III systems (2 August 2028 for Annex I). Firms should verify classification per use case rather than assuming either way, particularly where an assistant's outputs feed underwriting or claims decisions - and should establish at the outset which party is the Act's "provider" and which its "deployer" for each system, since the obligations attach to the role, not the brand on the interface.
- The transparency deadline did not move. Article 50 requires that people interacting with an AI system such as a chatbot are made aware they are dealing with a machine, and that AI-generated content is identifiable. The Digital Omnibus deferred the high-risk regime; it left the Article 50 disclosure obligations on their original date of 2 August 2026 - and that is also the date from which regulators can impose fines of up to €15 million or 3% of worldwide turnover for breaching them. The only concession is a grandfathering of the Article 50(2) machine-readable content-marking duty, to 2 December 2026, for systems already on the market before 2 August 2026. For any assistant deployed in the EU, disclosure is a hard requirement within weeks of this paper's publication. The Commission's draft guidelines on Article 50 and its voluntary Code of Practice on the transparency of AI-generated content offer practical implementation detail.
- Deployer obligations are real even below high-risk. Limited and minimal-risk systems still carry transparency duties and AI-literacy expectations for staff - the latter softened by the Omnibus to a duty to support the development of literacy rather than to guarantee any level of it - alongside encouragement toward codes of conduct.
- The IDD sets a floor, not a ceiling. Insurance distribution rules are minimum-harmonising: national implementations differ materially in advice and documentation duties, demands-and-needs practice, language requirements and complaints arrangements. An assistant serving members in more than one member state needs scope controls and disclosures configurable per jurisdiction, not a single EU setting.
EIOPA's Opinion on AI governance and risk management (August 2025) is the sector-specific interpretive layer. It introduces no new rules; instead it maps existing insurance legislation - Solvency II, the IDD, DORA and the GDPR - onto AI systems that fall outside the Act's high-risk category. Its supervisory expectations are a compliance blueprint for exactly the systems this paper concerns: data governance (training and testing data that is complete, accurate and appropriate, with bias addressed); documentation and record-keeping across the system lifecycle; explainability, with guardrails and human oversight where full explainability is not feasible; fairness under IDD Article 17's duty to act in customers' best interests; cybersecurity and robustness, including monitoring for model drift; and complaint and redress mechanisms for customers affected by AI-driven outcomes.
DORA adds the third-party dimension: its ICT risk management and vendor oversight requirements sit on the insurer and are discharged through contractual and oversight arrangements with AI suppliers - which means an insurer's diligence on an AI vendor is itself a regulatory obligation, not merely good practice.
The composite picture for a cross-border deployment: UK Consumer Duty and SM&CR as the outcomes-and-accountability layer; AI Act transparency from August 2026 as the disclosure floor; EIOPA's opinion as the governance specification; DORA as the vendor-oversight regime; and national IDD implementations as the local calibration. None of it prohibits AI assistants. All of it prohibits ungoverned ones.
5. What good governance actually requires
Translating the frameworks above into system design, six capabilities separate a deployable assistant from a liability:
1. Grounding in controlled knowledge. Answers must derive from the firm's own products, policies, provider networks and eligibility rules - a governed corpus with versioning and ownership - not from a foundation model's general training. This is what makes accuracy a managed property rather than a statistical hope, and it is the precondition for everything else on this list.
2. Enforced scope and refusal behaviour. The system needs hard boundaries on what it will answer, configured by the deploying firm, with graceful refusal and escalation rather than improvisation at the edges. Regulators evaluate input and output controls as part of the AI system; so should procurement.
3. Human hand-off by design. Consumer Duty's support outcome, FG21/1 and EIOPA's human oversight expectations converge on the same requirement: a customer must always have a route to a person, the transition must carry full context, and the triggers for escalation (vulnerability signals, complaints, distress, perimeter-adjacent queries) must be configurable and tested. Expressions of dissatisfaction must also be identified and routed as complaints under DISP, not lost in a conversation log.
4. Lawful, documented data handling. A benefits assistant that answers "I've been signed off with stress - what help is there?" is processing health data. That makes UK GDPR Article 9 conditions, a data protection impact assessment, and the automated decision-making provisions of Article 22 - as reformed by the Data (Use and Access) Act 2025 - part of the deployment design, not an afterthought for the privacy team. The same analysis applies under the EU GDPR for EU members.
5. Complete, queryable audit trails. Every interaction recorded: what was asked, what was answered, what knowledge grounded the answer, what version of which configuration was live. This is simultaneously the firm's perimeter defence, its complaints-handling evidence, and its Consumer Duty outcomes dataset.
6. Continuous monitoring and evaluation. Accuracy, containment, escalation rates, drift, and cohort-level outcome differences, monitored in production - the "output-driven validation" the FCA is exploring through Live Testing, applied as ordinary operational discipline.
Note what is absent from this list: any requirement for the deploying firm to build AI capability in-house. The frameworks are agnostic between build and buy. What they are not agnostic about is whether the accountable senior manager can explain and evidence the system. A vendor's job is to make that possible.
6. The due-diligence checklist
Ten questions for any AI assistant vendor. A credible vendor answers all ten in writing; the questions apply to Onsi as much as to anyone else.
- Regulatory status. Are you an authorised firm in any relevant jurisdiction? If not, whose permissions cover perimeter-adjacent interactions your system will handle, and what is your analysis of where those interactions sit?
- Grounding. What is the authoritative source of each answer, how is that corpus governed and versioned, and what happens when the corpus does not contain the answer?
- Scope controls. Show us the mechanism - not the prompt - that prevents the system from giving personal recommendations, and the test evidence for it.
- Hand-off. Demonstrate the escalation triggers, the context transfer to a human, the identification and routing of complaints, and the configurability of all three.
- Audit. Can we retrieve, for any historical interaction, the full record of what was said and what configuration produced it? For how long, and in what format?
- Accuracy evidence. What is your evaluation methodology, what are the results on our products (not benchmarks), and how is accuracy monitored post-deployment?
- AI Act position. What is your risk classification analysis for our use cases, which of us is provider and which deployer for each system, and how does your product satisfy Article 50 transparency from August 2026?
- Consumer Duty support. How does your reporting map to the four outcomes, and can it feed our board-level Consumer Duty reporting directly?
- Data and security. Where is data processed and stored, under what certifications (ISO 27001 or equivalent), what is your lawful basis and impact-assessment position for special-category health data, and how does your arrangement satisfy DORA's third-party requirements and the UK and EU GDPR?
- Failure disclosure. Describe a production failure of your system and what changed as a result. A vendor with no answer has either no deployments or no candour.
About Onsi
Onsi provides AI assistants for insurers and benefit providers, combining trusted company knowledge, business rules and enterprise governance to deliver accurate, auditable employee experiences across benefits, claims and wellbeing. Onsi is a global technology provider and a UK and EU insurance intermediary: Onsi is a trading name of Collective Society Ltd, Collective Denmark ApS and Collective Netherlands B.V., authorised and regulated by the UK Financial Conduct Authority (No. 923788), the Danish Financial Services Authority (No. 42352985) and the Netherlands Authority for Financial Markets (No. 12049041) respectively. Onsi is ISO 27001 and Cyber Essentials Plus certified.
To receive Onsi's written answers to all ten due-diligence questions in section 6, contact ai@onsi.com.
Conclusion
The regulatory framework for AI assistants in insurance is more settled than the industry conversation suggests. The UK has decided its approach: existing rules, applied to AI, with expectations communicated through supervised practice rather than a new rulebook - and, through the Mills Review, a live examination of where the perimeter should sit. The EU has legislated, and in May 2026 agreed to defer its high-risk regime while holding the transparency deadline: risk-tiered obligations, a hard disclosure date of 2 August 2026, interpreted for insurance by EIOPA within Solvency II, the IDD and DORA. Neither regime blocks deployment. Both make ungoverned deployment indefensible.
The firms that move first will not be the ones with the best models. They will be the ones whose compliance functions were given real answers to real questions - perimeter, grounding, hand-off, audit, evidence - and could therefore say yes.
Sources
- Bank of England and Financial Conduct Authority, Artificial Intelligence in UK Financial Services - 2024 (third joint survey), 21 November 2024.
- Financial Conduct Authority, FS25/5: AI Live Testing - Feedback Statement, September 2025; FCA AI Lab and AI Live Testing programme materials, 2025–2026, including first-cohort announcement (December 2025) and second-cohort announcement (21 April 2026); good and poor practice report due later in 2026, programme evaluation due Q1 2027.
- Financial Conduct Authority, AI Live Testing: How it can support safe and responsible AI deployment (blog), February 2026.
- Financial Conduct Authority, Annual Perimeter Report, 26 March 2026 (AI-driven financial guidance tools and perimeter risk).
- Financial Conduct Authority, the Mills Review into the long-term implications of AI for retail financial services (launched 27 January 2026; published 6 July 2026), including the recommendation to examine AI models outside the regulatory perimeter within three to six months.
- House of Commons Treasury Committee, AI in Financial Services, published 22 January 2026 (recommending FCA practical guidance on AI, including SM&CR accountability, by the end of 2026).
- FCA, Innovation Insights and statements on relying on existing frameworks rather than new AI regulation, 2025–2026; FCA, FG21/1: Guidance for firms on the fair treatment of vulnerable customers, February 2021.
- Regulation (EU) 2024/1689 (the EU AI Act), in particular Article 50 (transparency obligations applying from 2 August 2026) and Annex III (high-risk classification); Digital Omnibus on AI (Commission proposal 19 November 2025; Council–Parliament political agreement 7 May 2026; European Parliament vote 16 June 2026; formal adoption pending), deferring Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028, and Article 50(2) content-marking to 2 December 2026 for systems on the market before 2 August 2026.
- European Commission, draft Guidelines on the implementation of the Article 50 transparency obligations and Code of Practice on Transparency of AI-Generated Content, 2026.
- EIOPA, Opinion on Artificial Intelligence Governance and Risk Management, 6 August 2025.
- EIOPA, Generative AI Market Survey: Outlook, Use Cases and Risk Management (responses from 347 undertakings across 25 countries), published 2 February 2026.
- Regulation (EU) 2022/2554 (DORA), ICT risk management and third-party provider oversight.
- Directive (EU) 2016/97 (Insurance Distribution Directive), in particular Article 17; Financial Services and Markets Act 2000 and the Regulated Activities Order (UK insurance distribution perimeter).
- UK GDPR Articles 9 and 22; Data (Use and Access) Act 2025 (reforms to automated decision-making).
This paper is provided for general information and does not constitute legal or regulatory advice. Regulatory positions are stated as at July 2026; the Digital Omnibus on AI remains subject to formal adoption. Firms should take their own advice on the application of these frameworks to their specific circumstances.
