Carriers with AI in production grew from 37% to 61% in a single year, on a Datos Insights survey of 36 senior carrier technology leaders. Enterprise AI policy did not follow them into production. The Agent Charter, set out in a May 12, 2026 IA Magazine feature by Steve Forte of Patra Corp, is a document that specifies what one agent may decide without a human.

Key Takeaways

  • A 5% variance threshold is the operational core: policy field differences under it pass automatically, differences over it route to manual review, and limits, endorsements or exclusions escalate regardless of magnitude.
  • AI in production rose from 37% to 61% among the carrier technology leaders Datos surveyed, while only 24% of insurance executives told Grant Thornton they were confident of passing an independent AI governance review in 90 days.
  • 60% to 80% time reductions are reported in policy checking where decision boundaries are documented and enforced, which is also what creates pressure to widen them.
  • SR 26-2, issued April 17, 2026, superseded SR 11-7 and explicitly excluded generative and agentic AI from its scope, removing the framework many insurers had adopted voluntarily.
  • OpenAI sits in roughly 90% of carrier AI stacks, a correlation that firm-level model risk controls are not built to address.

What the Charter Actually Specifies

An enterprise AI policy states principles. An Agent Charter operates a layer below, defining for one agent in one workflow what it may decide alone, what triggers review, and what performance metrics keep it inside those bounds.

The framework sorts decisions into three tiers. Deterministic work such as document parsing, field extraction and carrier code lookup runs autonomously. Probabilistic work such as submission triage, renewal pricing recommendations and cross-policy comparison produces a recommendation a human acts on. Human-required work such as coverage interpretation, binding authority and policy language analysis stays with a licensed professional, and no amount of performance data moves it.

That last tier is where the insurance version differs from banking's lending authority matrices, which are the obvious analogue. Binding coverage, interpreting policy language and advising a client are licensed activities. State insurance law, not company policy, is what keeps them human.

The thresholds are what make the taxonomy operational. In policy checking, when an agent compares an issued policy against quoted terms:

  • Variances under 5% pass automatically. The agent logs the difference and moves the policy to the verified queue.
  • Variances above 5% route to manual review, with the specific fields flagged and the deviation quantified.
  • Critical field differences in limits, endorsements or exclusions escalate to a licensed professional regardless of size. A $1 difference in a general aggregate limit is not the same object as a $1 difference in a premium calculation.

The 5% is a calibration, not a constant. Each carrier sets its own and, more importantly, documents why, because that rationale is what a regulator under the NAIC's 12-state evaluation pilot will ask for.

Authority Creep Is the Failure Mode, and ASOP 56 Does Not Excuse It

The risk in agentic deployment is not a dramatic failure. It is the quiet expansion of what an agent effectively decides.

The arc is predictable. The agent launches under close review. Staff check every output and escalate edge cases. Weeks of acceptable results follow. Review becomes cursory, then spot-checking, then default acceptance, and the human-in-the-loop requirement becomes a signature. Stanford's Human-Centered AI Institute documented the underlying behavior in a 2023 study finding users significantly more likely to accept incorrect AI outputs from a system with an established accuracy record.

The reported 60% to 80% time reduction is the incentive that drives it. The better an agent performs, the stronger the organizational case for widening its autonomous authority, and the weaker the felt need to document the widening.

For an actuary this lands directly on professional liability. If an agent inside a pricing or reserving workflow has drifted past its documented 5% boundary, and the actuary signing the rate filing or reserve opinion did not know, the absence of documentation does not reduce the exposure. ASOP No. 56 requires understanding the models the work relies on, and an agent operating outside its charter is by definition a model whose behavior the actuary does not fully understand.

The charter's counterweight is structural rather than cultural: written boundaries create an auditable record, periodic threshold review blocks informal expansion, and monitoring tied to specific metrics rather than pass rates surfaces accuracy decline before anyone notices it behaviorally.

That gap is wide across the industry, not narrow. Alongside the 37% to 61% production jump, only 24% of executives told Grant Thornton they could pass an independent AI governance review in 90 days.

Survey Sample Key Finding
Datos Insights ILTF (April 2026) 36 carrier tech leaders AI in production: 37% to 61% in one year
Grant Thornton AI Impact (2026) 100 insurance executives Only 24% confident in passing AI governance audit
Capgemini World P&C (May 2026) 344 executives, 809 employees Only 10% successfully scaling AI; 42% track no metrics
AM Best (April 2026) 150+ rated insurers/MGAs 41% actively use AI; ~20% at advanced implementation
Conning AI & Insurance Tech (2025) Industry-wide survey 90% evaluating GenAI; 55% in early or full adoption
NAIC Survey (2025) Carrier reporting 88% of auto, 70% of home insurers adopting AI

The Federal Benchmark Wrote Itself Out of Scope

On April 17, 2026 the Federal Reserve issued SR 26-2, superseding the SR 11-7 model risk framework that had stood since April 2011 and that many insurers adopted voluntarily.

The update is a genuine modernization: requirements tailored by size and complexity, a narrower definition of model that excludes simple calculators, and validation timing driven by materiality rather than an annual default. It also explicitly carves generative and agentic AI out of its scope, indicating those systems will likely be treated elsewhere later.

That exclusion is the problem. Under the old guidance a carrier could argue its agentic systems fell inside the framework. The new guidance says in writing that they do not.

A GARP analysis by Krishan Sharma of Citigroup had already identified why SR 11-7 did not fit. It assumes models whose structure and behavior remain stable between review cycles, while agentic systems recalibrate on their own. It offers limited guidance on what constitutes sufficient explainability. And it is firm-specific, which cannot reach the correlation created by OpenAI sitting in roughly 90% of carrier AI stacks.

The insurance-side substitute is not equivalent. The NAIC Model Bulletin, adopted in 24 states and the District of Columbia, requires a written governance program covering risk management, documentation, third-party oversight and consumer protection. It is a compliance mandate at the enterprise level, and the evaluation pilot's Exhibit C is structured around individual model documentation rather than per-agent operational authority. A carrier can satisfy both and still have no record of what any single agent is permitted to decide.

Further Reading

Sources