Insurance presentation workflows are not one thing. A regulatory reporting pack, an actuarial analysis, a distribution brochure and an internal update share a file format and almost nothing else. Applying one AI policy across all four is the most common governance mistake I see in this sector.
Split them first. Then the controls become obvious.
The four categories, and why they differ
| Category | Examples | Primary obligation | Control weight |
|---|---|---|---|
| Regulatory and supervisory | Reporting packs, supervisory dialogue, board risk material | Accuracy, traceability, reconciliation | Highest |
| Actuarial and technical | Reserving analysis, pricing reviews, capital modelling | Professional standards, methodology integrity | Highest, different in kind |
| Distribution and customer facing | Product presentations, adviser material, customer documents | Product governance, permitted claims, mandatory disclosures | High |
| Internal | Management updates, project reporting, training | Ordinary confidentiality | Moderate |
The second row is the one that gets underestimated by people coming from other sectors. Actuarial work carries professional standards obligations that sit on named individuals. An actuary signing an opinion is accountable in a way that is not satisfied by a workflow approval, and a tool that blurs the line between assembled exhibits and actuarial conclusions creates a problem for that individual personally.
Where AI genuinely helps
Recurring management and portfolio reporting. Loss ratios, combined ratios, portfolio development, claims frequency and severity trends, assembled from approved sources into the approved template. High volume, repetitive, reconcilable against a source. This is the strongest case in insurance.
Native chart construction from controlled tables. Verifiable because the chart can be checked against its data, and correctable when a figure moves after a late adjustment.
Retrieval of approved product wording and mandatory disclosures. Not copied from last quarter's deck, which is exactly how a superseded disclosure survives for two years across three markets. Retrieved from records with owner, approval date, market and language.
Brand and format enforcement. Deterministic, and in a group with multiple entities it also handles the local variations that people get wrong under time pressure.
Translation and localisation of approved material. With regulatory text locked and market specific wording retrieved rather than translated. In a multi entity European insurer this is a serious saving. It is also a serious risk if the regulatory text is treated as translatable prose.
Pre delivery quality checks. Number reconciliation, unit and currency consistency, missing disclosures, stale data warnings, accessibility. Read only, immediate value.
Document review at scale. Reading policy wordings, regulatory texts or contract sets against specific questions, with citations to source and page.
Where it must not go
Actuarial conclusions. Reserve adequacy, pricing adequacy, capital sufficiency. These are professional judgements with named accountability.
Underwriting and pricing decisions. Beyond the professional standards point, these are decisions about individuals with direct consequences, and in life and health lines they sit close to the Annex III categories of the AI Act.
Claims determinations. Same reasoning, with the added factor that claims material is dense with personal and often health data.
Suitability and advice. Product governance and conduct obligations apply to what is said to customers and advisers, and they attach to people.
Unreconciled figures in a supervisory pack. Every figure that leaves the insurer in a regulatory context traces to an authoritative source and is reconciled.
Uncleared product claims. What a product does, what it excludes and how it compares are compliance statements, not marketing copy to be improved for readability.
The AI Act question is live for insurers
Most sectors can reasonably conclude that a slide drafting tool is not a high risk system and move on. Insurers should look more carefully, because the Annex III categories touch this sector directly.
The current position, stated precisely:
- The AI literacy obligation under Article 4 has applied to deployers of any AI system since 2 February 2025.
- Transparency obligations under Article 50 have applied since 2 August 2026.
- Obligations for Annex III high risk systems were deferred to 2 December 2027 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026.
- Systems embedded in products under Annex I follow on 2 August 2028.
Annex III includes AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. A presentation tool is not that. But if the same platform is later extended toward analysis that feeds pricing or risk assessment, the classification changes, and the deferral to December 2027 means you have preparation time rather than an exemption.
The practical advice: document the classification assessment now, define the boundary of what the tool may be used for, and set a trigger to reassess if that boundary moves. The deferral moved a date, not a direction.
Data protection specifics
Three things are more acute in insurance than in most sectors.
Health data is special category data. In life and health lines it appears constantly, and Article 9 requires an additional condition beyond an ordinary lawful basis. A portfolio analysis deck containing claims detail may carry health data even when no individual is named.
Claims material identifies people readily. A claim narrative with a date, a location and a circumstance often identifies someone to anyone who knows the case, which includes the people in the room.
Small cohorts re identify. Portfolio analysis by segment, region and product can produce cells small enough that individuals are identifiable by inference. Treat small group suppression as a genuine control rather than a statistical nicety, because in a claims context the inference is easy for an informed reader.
The practical control is minimisation before anything reaches the model. Select the rows and columns needed, aggregate, suppress small cells, and strip free text narrative unless it is genuinely required.
Approved wording and local variation
For a multi entity insurer this is often more important than the visual brand rules, and it is where I would put the early effort.
Every mandatory disclosure, product description, exclusion summary and regulatory statement should be a record with:
- The exact approved text.
- The market and legal entity it applies to.
- The language, with each translation separately approved.
- The owner, usually legal or compliance.
- The approval date and review date.
- The products and contexts it may be used in.
Then locked in the template, so that neither a user nor an agent can alter it. An attempt to change it is reported rather than silently applied.
The reason this matters more here than elsewhere: a paraphrase of an exclusion is a different exclusion. Wording that reads more clearly can mean something materially different, and the person who improved it for readability is rarely the person who will have to defend it.
The governance model
- The four presentation categories are defined, with a control level assigned to each.
- Data classification maps to which tools may process which levels.
- Health data and claims material have an explicit handling rule, including minimisation.
- Small cohort suppression is applied in portfolio analysis before anything reaches a model.
- Every material figure has an authoritative source with period, entity and currency.
- Approved wording and disclosures are records, retrieved verbatim and locked.
- Local entity and language variants are enforced by the template, not by memory.
- Actuarial conclusions, underwriting, pricing and claims decisions are excluded from automation.
- The AI Act classification is documented, with a trigger to reassess if scope expands.
- AI literacy training is in place for everyone who reviews or releases generated material.
- Named human release for every supervisory, distribution and customer facing document.
- Audit trail covering source set, changes, validation results, reviewer and release.
Where to start
One recurring internal reporting workflow with an approved source and a known correct answer. Not the supervisory pack, and not distribution material, both of which carry the obligations you least want to learn on.
Run it on synthetic or sanitised data first. Test the failure cases deliberately: a figure that cannot be sourced, an attempt to alter a disclosure, a request that crosses an entity boundary, a small cohort that should have been suppressed. Record the failures as carefully as the successes.
Measure review effort alongside drafting speed. Then have compliance, actuarial, privacy, security and the business owner evaluate the evidence together, including what went wrong.
Where offgen fits
offgen keeps PowerPoint as the working artifact, which matters in insurance because committee review, actuarial annotation and late correction all happen in the file. Retrieval runs inside existing permissions and entity boundaries. Lockable elements protect mandatory disclosures and approved product wording so they cannot be paraphrased. Brand governance enforces market and entity specific rules during generation.
Our security overview, trust center and data processing agreement support the vendor assessment. More on the sector view is on our insurance page.
The line I would hold in this sector: automate the assembly, never the professional judgement. An actuary, an underwriter and a compliance officer each carry personal accountability that no workflow approval transfers, and a tool that obscures which sentences are assembled and which are judged makes their job harder rather than easier.
Frequently asked questions
Where can insurers safely use AI for presentations?
Recurring management and portfolio reporting from approved sources, native chart construction from controlled tables, retrieval of approved product wording and mandatory disclosures, brand and format enforcement, translation of approved material with locked regulatory text, and pre delivery quality checks.
What must not be automated in insurance presentations?
Actuarial conclusions, underwriting or pricing decisions, claims determinations, suitability assessments, any regulatory submission figure that has not been reconciled, and product claims that have not been cleared. Automate the assembly, keep the professional judgement.
Why do insurers need different rules for different presentation types?
Because a regulatory reporting pack, an actuarial analysis, a distribution brochure and an internal update carry entirely different obligations. A single blanket AI policy either strangles the internal update or, more dangerously, treats a distribution document with the care of an internal update.
How does the EU AI Act affect insurers using AI presentation tools?
The AI literacy duty under Article 4 has applied to deployers since 2 February 2025 and transparency duties under Article 50 since 2 August 2026. Annex III high risk obligations were deferred to 2 December 2027 by Regulation (EU) 2026/1744. Note that Annex III includes risk assessment and pricing in relation to life and health insurance, so the classification question is live for insurers in a way it is not for many sectors.
What are the main data protection issues in insurance presentations?
Health data in life and health lines is special category data under Article 9, claims material frequently identifies individuals, and portfolio analysis can re identify people in small cohorts. Minimise before anything reaches a model, and treat small group aggregation as a genuine re identification risk rather than a formality.
How should approved product wording be handled?
Retrieved verbatim from records with an owner, an approval date, a market and a language, then locked so neither a user nor an agent can alter it. Approved wording is not something to paraphrase for readability, because the wording is the compliance.
Sources
- 01Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex, 2016-04-27. Accessed 26 August 2026.
- 02Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex, 2024-07-12. Accessed 26 August 2026.
- 03Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex, 2026-07-24. Accessed 26 August 2026.
- 04Insurance industry solutions — offgen. Accessed 26 August 2026.
Related articles

About the author
Maximilian Betz
Co-Founder and CEO, MD
Max writes about management consulting, enterprise adoption, data protection, and the operating controls required for AI in regulated organisations.