Across the insurance industry, AI adoption is no longer theoretical. Most organisations are already investing, experimenting or deploying use cases across underwriting, claims and customer experience.
Yet beneath the surface, many initiatives are still stuck in pilot mode, struggling to scale in complex, regulated environments built on legacy technology.
In NashTech’s recent custom software development in insurance report, the data points to a clear gap between ambition and execution, and a growing role for custom software as the bridge between the two, with 98% stating AI is accelerating the shift from COTS to custom.
To explore what this looks like in practice, we spoke to NashTech’s Insurance Technology Director, Mark Hankin.
Mark draws upon more than 30 years of experience in technology within the FSI sector. Regularly engaging with leaders from carriers, MGAs, brokers and reinsurers, and consistently encounters the same key themes.
While appetite is strong, many insurers are still struggling to move beyond early experimentation. AI initiatives are often proving difficult to embed into day-to-day operations, particularly in environments shaped by legacy systems, complex data estates and strict regulatory requirements.
In practice, this creates a gap between intention and execution. AI is visible across the organisation, but not always delivering measurable, scalable impact.
This is not unusual. Insurance is a highly controlled, risk-sensitive industry. Change is deliberate by design. But it does mean that moving from pilot to production requires more than just adopting new tools; it demands the right foundations, from architecture to governance.
Question for Mark:
Has the insurance industry genuinely moved beyond AI experimentation, or do you still see most organisations operating in a pilot phase?
Mark Hankin:
"Honestly, it's a mixed picture. Some organisations have genuinely industrialised AI into live processes, while others are still politely calling a very expensive pilot their strategy. What I keep seeing is a real hesitation once a use case is proven technically. The sticking point is rarely the model itself; it's confidence in the controls wrapped around it. My honest view is that the industry as a whole has moved past the ‘let's try something’ stage, but plenty of individual firms are still there.
While many insurers are still working through how to scale AI, there are clear areas where it is already delivering tangible results.
Much of this progress is happening behind the scenes. Across the industry, AI is being used to improve operational efficiency, from extracting data from complex documents to supporting underwriting decisions and streamlining claims handling. In many cases, these use cases are accelerating processes that were previously manual, time-consuming and prone to error.
At the same time, adoption is far from uniform.
Across the European market, nearly two-thirds of insurers are already using generative AI, but most applications remain at the proof-of-concept stage. This reflects a cautious approach, ; organisations are prioritising controlled, internal use cases before expanding into more customer-facing applications.
In practice, this means a large proportion of AI activity remains focused on internal productivity rather than on transforming the end-to-end customer experience. External-facing use cases, such as AI-driven distribution or personalised policy journeys, are starting to emerge, but are yet to become widespread.
This uneven progress mirrors what we see in our latest report. While 98% of insurers recognise AI as a catalyst for transformation, many are still working through how to turn isolated use cases into consistent, measurable value at scale.
Question for Mark:
Where are you seeing AI deliver genuine, measurable value in insurance today, and where is the industry still overestimating its impact?
Mark Hankin:
The clearest value I've seen sits in the unglamorous back-office work, so document extraction, FNOL triage, that sort of thing. We built exactly this kind of thing for a large multi-brand insurance broking group, a shared AI platform now live with 500+ users and four agents supporting document processing, renewals and knowledge search across the group. Where the industry overestimates itself is in assuming those internal wins will translate just as easily into customer-facing journeys, by simply reusing the same approach, ethos and technology. They don't, because a customer expects an answer to be accurate, explainable and genuinely useful in the moment, whereas an internal tool can get away with being roughly right and improved later. So, the value is very real; it's just currently more operational than transformational, whatever the headlines might be suggesting.
As insurers push AI further into their operations, it puts pressure on the entire technology stack.
Most enterprise platforms in insurance were built around structured data, rule-based processing and tightly controlled workflows. AI, by contrast, relies on unstructured data, dynamic decision-making and continuous learning. Bringing those two worlds together is proving more complex than expected.
This is reflected clearly in our latest report:
Taken together, these findings point to a deeper issue. AI is not simply exposing isolated gaps; it is highlighting structural limitations across data, platforms and operating models.
As a result, many insurers are beginning to rethink their approach. Rather than layering AI on top of existing systems, they are looking at how their architecture needs to evolve to support it properly. This is where custom software is becoming a way to create the flexibility, integration and control needed for AI to work in practice.
In this context, off-the-shelf platforms can start to fall short. While they may support individual use cases, they often lack the adaptability to integrate AI deeply across underwriting, claims and customer journeys, especially in a regulated environment.
Question for Mark:
Why does AI expose the limits of traditional enterprise platforms, and at what point does off-the-shelf software stop being sufficient?
Mark Hankin:
Off-the-shelf platforms were designed for a world of structured data and predictable rules, and so can manage huge numbers of complex transactions accurately and at scale. AI is simply better suited to unstructured inputs and continuous learning, which most COTS platforms were never built to handle gracefully. We saw this on a large multi-brand insurance client where dozens of disparate data sources had to be consolidated into a single AI-ready platform; no off-the-shelf tool in their existing stack was really capable of economically handling that integration work. The tipping point, the moment a COTS platform's limits get exposed, tends to arrive when you need AI to sit genuinely inside a workflow rather than bolted on beside it; that's when buy likely starts to feel like a constraint rather than an efficiency.
For many organisations, ‘AI-ready’ is still associated with adopting new tools or piloting use cases. But as insurers move beyond experimentation, it’s becoming clear that AI readiness is about the foundations those tools rely on.
At its core, being AI-ready means having the right conditions in place to support intelligent, data-driven decision-making at scale. That starts with data, its quality, structure and usability across the organisation. Without this, even the most advanced AI models struggle to deliver value consistently.
Beyond data, governance is becoming equally important. In a regulated environment like insurance, AI outputs need to be explainable, auditable and aligned to risk and compliance frameworks. This requires clear ownership, defined accountability and systems designed to support oversight from the outset, not retrofitted after deployment.
There is also a growing focus on platform engineering. As discussed earlier, AI places new demands on how systems interact, how workflows are orchestrated and how quickly organisations can adapt. This is driving investment in more modular, scalable architectures that can support AI across different business functions.
At the same time, capability gaps remain a challenge. Our report shows that 72% of insurers cite a lack of internal AI architecture expertise as a barrier to scaling adoption. This reinforces the idea that AI readiness is as much about skills and operating models as it is about technology.
Being AI-ready is about whether it can deploy, govern and scale it with confidence.
Question for Mark:
If an insurer wants to be AI-ready, what does that actually mean in practice, and what foundations need to be in place before AI can truly scale?
Mark Hankin:
In practice, it means the unglamorous groundwork has to be done: clean, well-governed data, clear ownership of models, and a platform that AI can plug into, rather than just sitting alongside it. On a recent engagement, we had to consolidate over 50 disparate data sources before any real-time AI pricing could work, and the client was keen to talk about the AI use case long before we'd even confirmed their data estate could support it, which is a bit like planning the interior design before the foundations are poured. It's right for Boards to get excited about the potential of AI, and that energy often drives programmes forwards. Just don't lose sight of the fact that you need the data, governance and architecture right first. Then the AI conversation becomes far more straightforward, and considerably less risky for us humans relying on its outputs.
As AI adoption accelerates, governance is emerging as one of the defining factors shaping how it is built and deployed in insurance.
In a regulated, risk-sensitive industry, governance is a core part of innovation. Requirements around explainability, auditability, security and third-party risk are not optional; they are fundamental to how insurers operate.
Our research clearly reflects this, with 84% of insurers citing security and governance as key challenges when scaling AI. These concerns are not theoretical. They influence how decisions are made, how models are integrated into workflows and how outcomes are validated over time.
In practice, this is driving a shift in how AI solutions are designed. Off-the-shelf tools may support individual use cases, but they often lack the transparency and control needed for regulated decision-making. As a result, insurers are increasingly looking for environments where AI can be more tightly governed, monitored and adapted, which is where custom software is playing a more strategic role.
Rather than treating governance as a constraint, insurers are embedding it into the design of their platforms from the outset. This enables AI to operate within clear boundaries, while still delivering efficiency and innovation.
Question for Mark:
What does responsible AI look like in a live insurance workflow, — and how does regulation influence how insurers approach build versus buy decisions?
Mark Hankin:
Responsible AI in a live workflow looks kind of boring, in the best possible sense. What's genuinely useful is when it catches something a human might miss, a pattern in claims data, an inconsistency in a submission, and flags it early enough to actually act on. But that only counts for anything if it comes with explainable outputs, an audit trail, and a human somewhere in the loop who can say why a decision was made. Regulation doesn't stifle build versus buy decisions so much as force the question earlier: can this vendor actually show me how their model reached a conclusion? I've watched insurers choose to build precisely because the answer was no, and that's simply not defensible to a regulator or a customer. Ultimately it comes down to trust, and trust has to be engineered in from the start; in no way can it be assumed.
Most organisations are already investing in, testing, and exploring AI adoption. The real divide will come down to execution, specifically, the ability to move from isolated use cases to scalable, embedded capabilities.
In practice, this will come down to three factors.
This shift is already influencing investment decisions. Our research shows that 97% of insurers are willing to invest more in partners that deliver long-term value, signalling a move away from short-term, project-based thinking towards more strategic transformation.
Question for Mark:
What will the most advanced insurers be doing differently a year from now, and what will hold others back from getting there?
Mark Hankin:
A year from now, the leading insurers will have stopped treating AI as a series of side projects and started treating it as core infrastructure, with the governance and architecture to match. What holds others back usually isn't ambition; it's the unglamorous debt of legacy systems (though that's a challenge I genuinely enjoy) and unclear ownership that never quite gets prioritised over the next quarterly or half-year deadline. I've seen this play out again and again: the insurers who move fastest are the ones where someone is clearly accountable for the platform an AI use case sits on, so decisions get made and problems get fixed without waiting for a committee. Compare that to the ones where a brilliant AI idea has no obvious owner once the initial excitement fades, and that's the gap that separates the leaders from the rest.
The insurance industry is working through how to embed AI into complex, regulated environments in a way that delivers real, scalable value.
As that shift continues, the role of custom software is changing, from a delivery choice to a strategic enabler of AI-driven transformation. It is becoming the foundation that connects data, platforms and governance, enabling insurers to move forward with confidence.
Looking to explore how to move beyond pilots and build an AI-ready foundation? Get in touch