The IFoA and the London-based Financial Services Forum published "It's Still Not Magic: Framing the Risks Facing Financial Services in the Gen AI Era" on June 2, 2026, updating a 2019 predecessor. Its argument breaks from the regulatory consensus: generative AI's most consequential risks are not incidental flaws to be patched through governance but structural features of the same architecture that makes the technology useful.
Key Takeaways
- 70% of the 78 senior practitioners surveyed rate AI risks among the greatest facing financial services over the next five years, and 75% say those risks rose substantially once generative AI became widely available.
- 95% of UK insurance firms were already using AI in the Bank of England and FCA 2024 survey, the highest rate of any financial services subsector.
- From 9 to 21 use cases is the expected median per firm over three years, with foundation models already 17% of all AI use cases.
- Cyber threats, misleading outputs and staff knowledge gaps are the top three concerns, each a different failure mode rather than three versions of one.
What the Survey Establishes
The acceleration number is the one that carries. Seventy percent naming AI among the sector's greatest risks is a level; 75% saying those risks rose substantially since generative AI arrived is a direction, and it dates the change to the enterprise deployment wave rather than to AI adoption generally.
The three named concerns map to distinct failures. Cyber reflects the technology's capacity to scale attacks against financial infrastructure, which the IMF's May 2026 analysis treats as a systemic stability question rather than an operational one. Misleading outputs is the hallucination problem stated properly: fluent, confident and wrong. Knowledge gaps describes a workforce deploying and overseeing systems it frequently cannot evaluate.
The deployment context makes those findings descriptive rather than anticipatory. 95% of UK insurance firms were already using AI in 2024, median use cases per firm are expected to more than double from 9 to 21 within three years, and foundation models already account for 17% of them.
The Tensions Are Not Governance Failures
The report's analytical contribution is a set of what it calls uncomfortable tensions: cases where the capability creating the value and the capability creating the risk are the same capability.
Fluency against reliability is the clearest. A model that hedged every statement would be more honest and less useful, and the same linguistic competence that lets an assistant draft a clean policy summary lets it fabricate plausible loss development factors. Inclusion against exclusion is structural in the same way: analysis that finds an unserved segment is analysis that sharpens exclusionary pricing, and which one happens depends on implementation choices governance cannot monitor at scale, which is the gap ASOP No. 12's proposed unintended bias section is written into.
Human-in-the-loop against human control is the tension with the sharpest actuarial edge. Putting a reviewer in the chain is not the same as giving that reviewer control, and when a system produces output faster than a person can evaluate it, the loop becomes a formality. Only a minority of UK financial services leaders report confidence that their governance is keeping pace with deployment.
| IFoA “Uncomfortable Tension” | Relevant U.S. ASOP | Compliance Gap |
|---|---|---|
| Fluency vs. reliability | ASOP No. 56 (Modeling) | No validation framework for text-based actuarial outputs; backtesting assumes quantitative predictions |
| Misleading outputs | ASOP No. 23 (Data Quality) | Data quality checks not designed for AI-generated intermediate products that look authoritative but may contain fabrications |
| Inclusion vs. exclusion | ASOP No. 12 (Risk Classification) | One-time bias testing insufficient; same model can widen and sharpen exclusion depending on data distribution shifts |
| Human-in-the-loop vs. human control | ASOP No. 56 (Modeling) | Review requirements assume human cognitive capacity to evaluate outputs; GenAI volume can exceed that capacity |
| Concentration risk | NAIC Model Bulletin / State DOIs | Vendor diversification does not equal risk diversification when underlying foundation models share architecture and training data |
That middle column is where the thesis bites. ASOP No. 56 requires the actuary to evaluate a model's appropriateness, assess data and structure, and perform validation testing. Validation testing as written assumes a quantitative output measurable against emerged experience. An actuary can compare a GLM's predicted loss ratios to what developed; evaluating whether a drafted reserve analysis contains a subtle reasoning error is a different exercise with no backtest available.
The Academy's October 2024 professionalism guidance closes the gap by assertion, stating that an actuary cannot use a GenAI result without validation and then claim "That's what the model told me." That is the right standard. The report's point is that it is aspirational rather than operationally achievable once GenAI sits across pricing, reserving and regulatory compliance simultaneously, because the same workflows that make it worth deploying produce more output than the reviewer signing for it can assess.
Keyur Patel, the report's author, states the position without softening it: "The same characteristics that make AI useful in financial services also create many of the risks that make it so difficult to govern." The question the report puts to firms is not whether the risk can be mitigated but how much of it they are prepared to accept.
Buying a Second Vendor Does Not Buy Diversification
Concentration is the tension that resists the standard remedy, because the remedy assumes the thing being concentrated is a supplier.
Foundation models require concentration to work: the datasets, the compute and the small number of organisations able to assemble both. That is not a market inefficiency competition will resolve over time; it is how the capability is produced. So an insurer running two vendors to avoid single-provider dependency may be running two products over models that share architecture and substantially overlapping training data, and the failure mode it was diversifying against is unchanged.
The IMF's warning describes what that looks like at sector scale: an AI attacker discovering a common vulnerability across interconnected institutions turns a local breach into a systemic one, because the institutions were never as independent as their vendor lists suggested.
Three things separate this from the 2019 report, and all three run the same direction. Output modality moved from numerical predictions that can be backtested to unstructured text, code and analysis that resists validation. Scope moved from underwriting segmentation and claims triage to customer communications, regulatory filings, compliance monitoring, internal audit and strategic analysis. And procurement moved from proprietary models a firm built or commissioned to a handful of shared APIs.
The first two changes make each deployment harder to check. The third makes every firm's unchecked deployment correlated with everyone else's.
Further Reading on actuary.info
- ASOP No. 12 Gets Its AI-Era Rewrite: What Actuaries Need to Know About Unintended Bias - Analysis of the proposed revision’s new Section 3.4 and how bias-testing requirements intersect with GenAI-driven risk classification.
- Why Carrier AI Projects Fail at the Audit Layer, Not the Technology - Documentation of governance failures across carrier AI deployments, illustrating the IFoA report’s argument that controls cannot keep pace with deployment speed.
- SR 26-2 Rewrites Model Risk Rules but Leaves Insurer AI in a Regulatory Vacuum - How the Federal Reserve’s explicit exclusion of generative AI from the new model risk framework creates the compliance gap the IFoA report identifies.
- NAIC Flags Agentic AI as Insurance’s Next Governance Gap - The four NAIC mitigation strategies and their limitations in light of the structural-tensions thesis.
- Hartford’s Algorithmic Impact Assessment Sets a New Carrier AI Transparency Standard - One carrier’s approach to the governance challenge the IFoA report frames as structurally unresolvable through process alone.
- EIOPA Surveys 347 European Insurers on GenAI Adoption and Governance - The largest regulator-run AI survey in global insurance quantifies how far European carriers have come on governance, with 49% now holding dedicated policies ahead of the EU AI Act deadline.