By: Richard Wulff

The digital transformation of the insurance industry has accelerated rapidly, driven by the integration of Artificial Intelligence (AI) across the insurance value chain. Within trade credit insurance, AI and mathematical modelling present major opportunities to develop granular risk assessments, streamline claims processing, and efficiently detect fraudulent activity. This can all happen at a much greater speed than was previously possible. However, deploying these technologies introduces regulatory challenges surrounding data governance, transparency, model explainability, and potential biases.

In a recent survey, all ICISA members writing trade credit insurance and CPRI use artificial intelligence of some sort. This is usually a combination of the three types surveyed: “off-the-shelf” AI (such as Copilot, ChatGPT, Gemini and the like), proprietary/internally built models, and third-party models with internal customisation. By far, the business processes where AI models are most widely used today are (in this order) workflow management, risk underwriting, and marketing and strategy. The expectation is that this will spread to risk modelling and claims in the near future. All respondents to the survey expect to increase their use of AI models in the next 12 months.

Insurance regulators globally are establishing frameworks to govern AI adoption for the insurance industry at large. Their collective stance balances technological innovation with oversight to safeguard financial stability, operational resilience, and consumer protection.

Clarifying model scope and the EU AI Act

In July 2024, the European Union published Regulation (EU) 2024/1689 (the AI Act), which adopts a risk-based approach establishing compliance burdens for high-risk AI systems.

For statistical models widely used across general and trade credit insurance, such as Generalised Linear Models (GLMs) and Generalised Additive Models (GAMs), regulators have clarified supervisory boundaries. EIOPA advocates that traditional GLMs and GAMs be excluded from high-risk classifications under the AI Act, arguing that these models:

  • Are longstanding, transparent, and stable statistical techniques rather than complex “black-box” AI systems,
  • Operate under meaningful human oversight, and
  • Are already governed by robust sectoral requirements under insurance, prudential, data protection, and operational resilience legislation.

Subjecting traditional statistical models to high-risk AI compliance layers would create redundant regulatory burdens, divert supervisory attention from genuinely complex emerging AI technologies, and yield limited supervisory benefits.

Insurers remain subject to the Solvency II directive, which provides rules for basic processes such as risk management and data accuracy for underwriting and reserving whether or not AI is in play. Other EU directives such as the rules on product oversight and governance, ruling on product testing, continuous monitoring, record keeping, and appropriate distribution channels remain applicable, as would the Digital Operational Resilience Act (DORA), governing ICT governance, business continuity and system security. This has led the European regulator to decide that for systems deemed non-critical[1] additional regulation is not strictly necessary.

Core supervisory expectations for AI governance

Regulators expect all undertakings, including insurers and intermediaries, to institute risk-based, proportionate governance frameworks embedded into their Enterprise Risk Management (ERM) and model risk management systems.

Where artificial intelligence is used, as in non-AI-supported processes, the following must be safeguarded within the enterprise risk management and governance framework. The key pillars of such are

  1. Fairness, Ethics, and Data Governance: Insurers must maintain data governance policies ensuring training and testing data are complete, accurate, and appropriate. Insurers must actively detect and remove unlawful proxy discrimination to prevent biased outcomes. Accessible complaints procedures must also be maintained for affected clients.
  2. Transparency and Explainability: Undertakings must ensure AI outcomes can be meaningfully explained using local/global explanatory tools or by using complex AI solely to fine-tune traditional models. Insurers must inform customers when AI is used and provide non-technical explanations of material decisions upon request.
  3. Human Oversight and Governance Structure: Insurers remain fully accountable for their AI systems, including third-party solutions. Roles across internal lines of defense must be explicitly defined:
    • Administrative, management, or supervisory bodies hold ultimate responsibility for overall AI adoption, setting strategy and risk appetite.
    • Control functions such as compliance, risk, data protection, and actuarial functions must verify regulatory adherence, monitor model drift, and oversee underwriting models. Regulators like BaFin emphasise that insurers must strengthen second- and third-line controls to match rising model complexity.
  4. Accuracy, cyber resilience, and DORA: AI models must maintain consistency and accuracy throughout their lifecycle. Under DORA, systems must be secured against cyber vulnerabilities, adversarial attacks, and data poisoning, backed by robust business continuity plans.

In AI-supported operations, as in “traditional” processes, these pillars are expected to lead to robustness, security, and DORA compliance. That can only be in the interest of all involved: insurers, clients, and supervisors. It is with some relief that the regulator has not found it necessary to gold-plate the existing, functioning rules.

Global regulatory perspectives

Supervisory authorities share consistent priorities of transitioning from rigid rules toward flexible, outcomes-focused supervision centred on accountability and resilience.

  • EIOPA & European Supervisors (BaFin): Supervisors recognise that while AI adoption currently centres on cost reduction and process automation, formal governance frameworks are evolving. The primary goal is integrating rules applicable to AI in the existing frameworks without suffocating beneficial innovation.
  • IAIS Agenda: The IAIS views AI oversight as a core element of operational resilience alongside cyber risk and private credit management. The IAIS advocates an outcomes-focused, flexible framework that balances cross-border consistency with national supervisory context.
  • US Regulators (NAIC): US insurance commissioners emphasise overarching principles over prescriptive mandates. Supervisors stress that emerging technologies (including agentic AI) do not alter an insurer’s core legal obligations. Insurers must understand their systems, maintain accountability for third-party tools, and protect consumers from unfair outcomes.

Conclusion

In the trade credit insurance/CPRI market, artificial intelligence is used for the good of policyholders and the economy at large by making processes quicker and more affordable. This leads to better outcomes for all parties.

We are happy to see that regulators support the measured adoption of artificial intelligence in our field, recognising its capacity to enhance risk analysis and efficiency. However, regulatory consensus dictates that innovation must not compromise policyholder protection, financial stability, or resilience. By grounding AI governance in established sectoral frameworks (such as Solvency II and DORA) and enforcing human accountability, trade credit insurers can successfully leverage AI while satisfying global regulatory standards.

[1] AI as part of critical infrastructure, AI embedded as safety components in regulated products like medical devices, surgical robots, and vehicles, AI used in law enforcement, biometric recognition, and migration and border control are seen as critical.

Published Sep 17, 2026Intermediate

Related Articles

Stay Ahead of the Curve

Get exclusive insights, expert analysis, and breaking news on liquidity and risk management, delivered to your inbox

Stay Updated

Get the latest insights straight from TTP - on trade finance, treasury management, and global payments delivered to your inbox.

Join 25,000+ professionals.
Unsubscribe anytime.

Advertisement