Skip to main content

Governed PowerPoint AI for insurance teams.

Insurance AI governance is not one checklist. DORA governs digital operational resilience and ICT third-party risk. Solvency II keeps insurers responsible for outsourced functions. EIOPA expects risk-based AI governance, clear responsibility, data controls, documentation and meaningful human oversight. offgen gives presentation teams a controlled way to apply those principles.

Which rules matter for PowerPoint AI in insurance?

For a presentation workflow, the core review usually covers DORA, data protection, the insurer’s governance system and its third-party or outsourcing rules. The AI Act classification depends on the actual use. Generating or editing an internal presentation is not automatically a high-risk insurance system. If an implementation influences life or health insurance risk assessment or pricing, it requires a separate high-risk assessment and must not be treated as a simple presentation use case.

The regulatory framework for insurance presentation AI

EIOPA’s current guidance combines existing insurance rules with DORA and the AI Act. The right control level follows the use case, its effect on customers and the operational function it supports.

FrameworkSupervisory expectationMeaning for an offgen deployment
DORAInsurers manage ICT risk, incidents, resilience testing and third-party risk. Contracts, the Register of Information, audit rights and exit planning depend on service scope and criticality.Classify the presentation workflow and document the service, EU hosting, suppliers, incident cooperation, assurance and exit responsibilities.
Solvency II outsourcingThe insurer remains fully responsible. Outsourcing must not impair governance, increase operational risk unduly, hinder supervision or undermine continuity for policyholders.Determine whether the arrangement is outsourcing and whether it concerns a critical or important function. Keep clear responsibilities, monitoring, confidentiality, continuity and termination terms.
EIOPA AI governanceEIOPA expects a proportionate lifecycle approach with clear roles, fairness, meaningful explanations, sound data governance, documentation, records and human oversight.Define approved inputs, accountable users, permitted workflows, review steps and records before presentation content is distributed or used in a decision process.
EU AI ActThe AI Act classifies systems by their intended purpose. Risk assessment and pricing for natural persons in life and health insurance are specifically listed as high-risk use cases.Keep presentation assistance separate from automated pricing or risk decisions. Reassess the classification if data flows, integrations or intended purpose expand into those activities.
GDPR and confidentialityPersonal data needs a lawful purpose, data minimization, access controls, appropriate security, retention rules and transparent processing roles.Configure data sources, permissions, retention and deployment for the intended insurance workflow. Use only data that is necessary and approved for the presentation task.

Controls that fit insurance work

The goal is not to block AI. It is to make the permitted workflow obvious, reviewable and proportionate to the material handled by underwriting, claims, actuarial, broker and board teams.

01

Approved knowledge and templates

Teams create from governed slide libraries, brand rules, approved wording and selected business context instead of an unrestricted public chatbot.

02

Human review before use

Outputs remain native and editable in PowerPoint. Accountable employees review facts, assumptions, customer impact, disclosures and approvals.

03

Clear separation from decisions

Presentation generation can support communication without becoming an automated underwriting, pricing or claims decision. Integrations should preserve that boundary.

04

EU hosting and model residency

The managed service, customer data and standard language models are hosted and processed within the European Union.

05

No customer-data training by default

Insurance files, prompts, templates and generated presentations are not used to train the standard managed models by default.

06

Evidence and traceability

Role-based access, audit logging, tenant isolation, ISO 27001 controls and procurement documentation support accountable operation.

A proportionate insurance AI review

Start with intended purpose and customer impact. The same tool can require different controls depending on whether it formats an internal board pack or feeds a regulated decision.

  1. 01

    Define intended purpose

    Describe the presentation task, users, source systems, data types, recipients and whether the output informs a decision affecting a person.

  2. 02

    Classify the frameworks

    Assess DORA service criticality, outsourcing status, GDPR roles and whether the intended purpose changes the AI Act classification.

  3. 03

    Set workflow controls

    Limit approved sources, roles and integrations. Define review, correction, approval, logging and incident processes.

  4. 04

    Validate evidence and exit

    Review the contract, service locations, suppliers, assurance, continuity and exit plan, then test the workflow with representative data.

Where the presentation boundary ends

A governed presentation assistant can help prepare underwriting committee packs, claims summaries, broker materials, board decks and supervisory presentations. It should not silently become the system that decides eligibility, pricing, reserves, claims outcomes or customer treatment. If the intended purpose or integrations cross that line, the risk classification and control framework must be reassessed.

AI governance and offgen: insurance questions

Yes. DORA has applied since 17 January 2025 and covers insurance and reinsurance undertakings within its scope, alongside other financial entities. The insurer remains responsible for its ICT risk management and third-party arrangements.
Not simply because it uses AI or creates insurance presentations. Classification depends on intended purpose. The AI Act specifically lists systems used for risk assessment and pricing of natural persons in life and health insurance as high-risk. A deployment connected to those purposes needs a separate assessment.
The insurer determines whether the arrangement is outsourcing and whether it covers a critical or important operational function. If it does, Solvency II outsourcing requirements remain relevant in addition to DORA.
The standard presentation workflow is designed to assist content preparation, not to replace underwriting, pricing, reserving or claims decisions. If a customer creates such an integration, intended purpose and controls must be reassessed before use.
Content is delivered as a native, editable PowerPoint file. Teams can inspect sources and assumptions, correct the material and apply their established review and approval process before distribution.
The managed service, customer data and its standard language models are hosted and processed within the European Union. Customer data is not used to train those models by default.
Yes. The public security, hosting, sovereignty and data protection pages provide the starting point. Current assurance and procurement material can be requested through the Trust Center.

Official insurance governance sources

The page uses current EU and supervisory sources. The exact legal assessment depends on the insurer, intended purpose, supported function, data and deployment.

Define a governed insurance workflow

Bring the intended use, data categories, recipients, review owners and deployment preference. We will map the offgen boundary and evidence to your governance process.

Discuss the insurance setup

Book a demo

Choose a time and share how your company creates PowerPoint presentations today.

We will map your PowerPoint knowledge base, MCP use cases, governance rules, and first agentic presentation workflow.

In 30 minutes, you will see

How existing masters, templates, slide libraries, and approved content become a Company Brain

How people and AI agents can create native PowerPoint presentations through MCPs

How brand governance, editability, human review, and enterprise security work together