Grant Thornton's 2026 AI Impact Survey, fielded between February 23 and March 18 across 100 insurance respondents, found that 44% of insurance executives say governance or compliance problems contributed to an AI project failing or underperforming. Only 24% are very confident they could pass an independent AI governance review within 90 days.
Carriers can show that their models work. The survey's finding is that most cannot show how they governed the models while they worked, and that is the gap that stops deployments.
Key Takeaways
- 44% cite governance as a contributor to AI project failure, against 24% who are very confident of passing an independent review inside 90 days, from a survey of 100 insurance respondents among 950 total business leaders.
- 68% report that AI controls exist but are fragmented across teams and tools, and while boards have widely adopted AI governance policies, only 20% have tested a response plan for an AI failure.
- 73% are piloting, scaling, or running autonomous AI systems, so wide deployment sits on top of the 76% who acknowledge they could not evidence their controls on demand.
- Formal inventory exercises surface 20% to 40% more in-scope systems than carriers estimate, which is the single most reliable budget surprise in a governance build.
- A retrofit runs $4 million to $8 million for a mid-sized carrier, against roughly 15% to 20% of model development cost when governance is instrumented from the start.
What the Survey Found Underneath the Headline
The Grant Thornton figures separate three things that usually get reported as one.
Controls exist. Sixty-eight percent of insurance respondents say AI controls are in place but fragmented across teams and tools: a model risk team holds validation records, compliance holds bias testing results, IT holds data lineage logs, and nothing aggregates them into a record an examiner could read.
Policy exists. Sixty-one percent of boards have established AI governance policies. Set against the 24% audit-confidence figure, the distance between adopting a policy and being able to operate it is most of the survey, usually because the policy was written at a level of abstraction that does not translate into a testable control for a specific underwriting or claims use case.
Testing does not exist. Only 20% have tested their response plan for an AI failure. Tom Puthiyamadam, the Grant Thornton partner overseeing the survey, framed the aggregate pattern as investment that is not correlating with an increase in AI accountability. Meanwhile 73% of respondents are piloting, scaling, or running autonomous systems.
Why the Bill Arrives After the Model Works
The reason governance kills projects rather than delaying them is that the cost is incurred in the wrong order.
A model is built, validated on performance, and moved toward production. Compliance then asks for training data provenance, protected-class impact testing, and model change management records. Those artefacts have to be reconstructed rather than retrieved, because nothing recorded them at ingestion time.
Reconstruction is where the money goes. Building an audit-ready program for a mid-sized carrier with 2,000 to 4,000 in-scope systems runs $4 million to $8 million across personnel, infrastructure, and outside counsel.
| Workstream | Timeline | Key Outputs |
|---|---|---|
| Model Inventory | 6-8 weeks | Complete registry of all AI/ML systems, risk classification, owner assignment |
| Bias Testing (First Pass) | 10-14 weeks | Statistical parity, four-fifths rule, proxy screening for all high-risk models |
| Drift Monitoring Dashboards | 6-10 weeks | Automated alerts for accuracy degradation, distribution shift, emerging bias |
| Audit Trail Specification | 2-4 weeks | Logging requirements, retention policy, reproducibility standards |
| Vendor Contract Amendments | 2 weeks | Disclosure requirements, bias testing access, incident notification SLAs |
| Organizational Standup | 8-12 weeks | Executive hire, team build, RACI assignment, reporting cadence |
Two numbers govern that estimate. The first is scope: formal inventory exercises turn up 20% to 40% more systems than the carrier expected, once shadow models built inside actuarial teams, vendor-embedded scoring engines, and legacy rule systems that qualify as algorithmic decision-making are counted. A carrier budgeting for 2,000 should provision for 2,400 to 2,800, and the overshoot alone adds $500K to $1M.
The second is the retrofit premium. Instrumenting governance into a new deployment costs roughly 15% to 20% of model development cost. Retrofitting it onto a production pipeline costs multiples of that, because training data provenance has to be rebuilt from version control history and team memory, and change history from deployment logs.
That asymmetry is what makes the decision look like a resource prioritization rather than a governance failure when the project is shelved. It also explains the pattern in the monitoring data: most carriers watch a model for accuracy degradation, because accuracy affects the loss ratio, and few watch the same model for an emerging four-fifths rule violation on a protected class or for input distribution shift, because those affect only the examination that has not happened yet. In a first comprehensive bias pass, 15% to 30% of consumer-facing models get flagged, which is not a finding of discrimination but a finding that the carrier cannot affirmatively evidence its absence.
Four Examinations, One Set of Artefacts
The complication is that the audit layer is not being built for one examiner, and the deadlines land together.
The NAIC's AI Systems Evaluation Tool pilot runs from March 2, 2026 through September 2026 across 12 states, and it is a market conduct examination instrument rather than a survey. Its Exhibit C asks for design, training data and performance on high-risk systems; Exhibit D screens for proxy variables tied to protected characteristics. A carrier in a pilot state that cannot populate them is choosing between rapid remediation and a non-response to its regulator.
The Third-Party Data and Models Working Group advanced its vendor registration framework on March 23, 2026, heading for public exposure in Q3 2026 and adoption consideration in November. Registration creates no safe harbour: the carrier stays accountable for vendor model behaviour, so the registry mainly gives regulators a baseline to compare a carrier's own due diligence file against.
The EU AI Act classifies insurance risk assessment as high-risk under Annex III with enforcement from August 2, 2026, and penalties up to 35 million euros or 7% of worldwide revenue. Colorado's insurance compliance deadline is June 30, 2026, and nearly 25 states have adopted the NAIC Model Bulletin in some form.
Each of those tests the same underlying artefacts: the inventory, the bias testing record, the lineage documentation, the change log. That is the one piece of good news in the arithmetic, because the build is shared. It is also why the 76% figure is not four separate problems that can be sequenced. A carrier that cannot evidence its controls in September cannot evidence them in November either.
Further Reading
- Hartford's Algorithmic Impact Assessment Sets the Carrier Transparency Bar - How one carrier operationalized AI governance documentation ahead of regulatory requirements.
- The AI Governance Gap in Actuarial Practice - ASOP 56 compliance and model risk management for AI systems in actuarial workflows.
- NAIC Flags Agentic AI as Insurance's Next Governance Gap - The Spring 2026 panel on autonomous AI risks and what actuaries validating agentic workflows must consider.
- Machine Learning for Loss Reserves: The ASOP Compliance Gap - Documentation friction for ML reserve models and a hybrid approach preserving audit defensibility.
- Insurer AI Adoption Hits 82% But Only 7% Reach Full Scale - The adoption-to-scale gap that governance failures largely explain.
- AI Liability Insurance Reaches Unicorn Scale at Corgi - How the governance-readiness gap quantified here translates into insurable exposure, with Corgi's modular coverage architecture and scenario-based pricing for AI-specific perils.
- The Insurance AI Proof Gap in Cross-Survey Context - Five 2026 surveys benchmarked side by side show insurance carries the widest gap between AI revenue claims and governance audit readiness of any sector.
- 68% Outsource AI, 18% Track Vendor Risk - How the audit layer gap compounds when two-thirds of carrier AI is vendor-built and most carriers lack contractual audit rights or model change controls.
- Allianz Co-Develops Audit-Ready AI With Anthropic - A carrier that solved the audit layer problem by co-developing decision logging directly into the AI architecture with its LLM vendor.
- How 42% of Insurers Operate Without AI Measurement - Capgemini's global survey confirms the audit layer gap extends to basic outcome tracking, with 55% ownership ambiguity and a 72/28 technology-to-change-management spending imbalance.
Sources
- Grant Thornton: 2026 AI Impact Survey Report (Insurance Edition)
- BusinessWire: Grant Thornton Survey on the Widening AI Proof Gap (April 2026)
- Alston & Bird: Key AI, Cybersecurity, and Privacy Takeaways from the NAIC 2026 Spring Meeting
- Mondaq: NAIC Spring 2026 Meeting Third-Party Data and Models (H) Working Group
- Sidley Austin: Regulatory Update NAIC Spring 2026 National Meeting
- Swept AI: The Insurance CIO's AI Governance Playbook for Q3 2026
- Swept AI: NAIC Third-Party Model Vendor Registry 2026
- Swept AI: NAIC AI Evaluation Tool 12-State Pilot 2026
- NAIC: Third-Party Data and Models Working Group Spring 2026 Meeting Materials
- Actuarial Standards Board: ASOP No. 56 (Modeling)
- Actuarial Standards Board: ASOP No. 56 Fourth Exposure Draft
- Cherry Bekaert: AI in Insurance - How to Build a Compliant Governance Framework
- Fenwick: Tracking the Evolution of AI Insurance Regulation
- Insurance Business: Widening AI Proof Gap Exposes Weak Governance (April 2026)