Approved knowledge and templates
Teams create from governed slide libraries, brand rules, approved wording and selected business context instead of an unrestricted public chatbot.
Insurance AI governance is not one checklist. DORA governs digital operational resilience and ICT third-party risk. Solvency II keeps insurers responsible for outsourced functions. EIOPA expects risk-based AI governance, clear responsibility, data controls, documentation and meaningful human oversight. offgen gives presentation teams a controlled way to apply those principles.
For a presentation workflow, the core review usually covers DORA, data protection, the insurer’s governance system and its third-party or outsourcing rules. The AI Act classification depends on the actual use. Generating or editing an internal presentation is not automatically a high-risk insurance system. If an implementation influences life or health insurance risk assessment or pricing, it requires a separate high-risk assessment and must not be treated as a simple presentation use case.
EIOPA’s current guidance combines existing insurance rules with DORA and the AI Act. The right control level follows the use case, its effect on customers and the operational function it supports.
| Framework | Supervisory expectation | Meaning for an offgen deployment |
|---|---|---|
| DORA | Insurers manage ICT risk, incidents, resilience testing and third-party risk. Contracts, the Register of Information, audit rights and exit planning depend on service scope and criticality. | Classify the presentation workflow and document the service, EU hosting, suppliers, incident cooperation, assurance and exit responsibilities. |
| Solvency II outsourcing | The insurer remains fully responsible. Outsourcing must not impair governance, increase operational risk unduly, hinder supervision or undermine continuity for policyholders. | Determine whether the arrangement is outsourcing and whether it concerns a critical or important function. Keep clear responsibilities, monitoring, confidentiality, continuity and termination terms. |
| EIOPA AI governance | EIOPA expects a proportionate lifecycle approach with clear roles, fairness, meaningful explanations, sound data governance, documentation, records and human oversight. | Define approved inputs, accountable users, permitted workflows, review steps and records before presentation content is distributed or used in a decision process. |
| EU AI Act | The AI Act classifies systems by their intended purpose. Risk assessment and pricing for natural persons in life and health insurance are specifically listed as high-risk use cases. | Keep presentation assistance separate from automated pricing or risk decisions. Reassess the classification if data flows, integrations or intended purpose expand into those activities. |
| GDPR and confidentiality | Personal data needs a lawful purpose, data minimization, access controls, appropriate security, retention rules and transparent processing roles. | Configure data sources, permissions, retention and deployment for the intended insurance workflow. Use only data that is necessary and approved for the presentation task. |
The goal is not to block AI. It is to make the permitted workflow obvious, reviewable and proportionate to the material handled by underwriting, claims, actuarial, broker and board teams.
Teams create from governed slide libraries, brand rules, approved wording and selected business context instead of an unrestricted public chatbot.
Outputs remain native and editable in PowerPoint. Accountable employees review facts, assumptions, customer impact, disclosures and approvals.
Presentation generation can support communication without becoming an automated underwriting, pricing or claims decision. Integrations should preserve that boundary.
The managed service, customer data and standard language models are hosted and processed within the European Union.
Insurance files, prompts, templates and generated presentations are not used to train the standard managed models by default.
Role-based access, audit logging, tenant isolation, ISO 27001 controls and procurement documentation support accountable operation.
Start with intended purpose and customer impact. The same tool can require different controls depending on whether it formats an internal board pack or feeds a regulated decision.
Describe the presentation task, users, source systems, data types, recipients and whether the output informs a decision affecting a person.
Assess DORA service criticality, outsourcing status, GDPR roles and whether the intended purpose changes the AI Act classification.
Limit approved sources, roles and integrations. Define review, correction, approval, logging and incident processes.
Review the contract, service locations, suppliers, assurance, continuity and exit plan, then test the workflow with representative data.
A governed presentation assistant can help prepare underwriting committee packs, claims summaries, broker materials, board decks and supervisory presentations. It should not silently become the system that decides eligibility, pricing, reserves, claims outcomes or customer treatment. If the intended purpose or integrations cross that line, the risk classification and control framework must be reassessed.
Use these pages to validate operating locations, security controls, contractual roles and the service boundary.
Review ISO 27001, encryption, access controls, isolation and audit logs.
Review the European hosting boundary for the service, customer data and standard language models.
Review jurisdiction, model residency, data control, portability and exit.
Review processing roles, safeguards and contractual data protection terms.
The page uses current EU and supervisory sources. The exact legal assessment depends on the insurer, intended purpose, supported function, data and deployment.
Bring the intended use, data categories, recipients, review owners and deployment preference. We will map the offgen boundary and evidence to your governance process.
Choose a time and share how your company creates PowerPoint presentations today.
We will map your PowerPoint knowledge base, MCP use cases, governance rules, and first agentic presentation workflow.
In 30 minutes, you will see
How existing masters, templates, slide libraries, and approved content become a Company Brain
How people and AI agents can create native PowerPoint presentations through MCPs
How brand governance, editability, human review, and enterprise security work together