Skip to content
AI & Governance · July 20, 2026 · 9 min read

The Blind Spot of the Small Insurer

60% of mid-sized insurers don't see AI as important to their revenue model. That's not caution. And the six EIOPA principles show how it can be done differently.

Illustration for article: The Blind Spot of the Small Insurer

TL;DR

  • 60% don't see AI as important, nearly 80% already use it. Perception and practice diverge — and that gap is the real risk, not the AI use itself.
  • At small insurers, 61% lack the capacity to even start. Not in a few years, but right now — and that lag grows faster than a three-month pilot can close.
  • Six EIOPA principles have been ready since 2021. Data governance, fairness, human oversight, proportionality, robustness and explainability — not a technical wish list, but good governance.
  • Governance isn't a brake, it's a safety net. DNB mostly sees shortfalls in documentation and monitoring — not too little AI, but uncontrolled AI.
  • From August 2, 2026, it gets sharper. Risk assessment and pricing for life and health insurance will fall under the strictest EU AI Act requirements.

De Nederlandsche Bank released new figures last month on AI at insurers. Only 40% of mid-sized players see AI as important to their revenue model. At small insurers, 61% even lack the capacity to get started.

Not in a few years. This is happening now. And it's exactly the blind spot the regulator has been warning about.

What DNB actually found

The figures come from research DNB shared with the sector this month: insurers and AI (opens in new window). The regulator split insurers by impact class: large, medium, small. And there's a clear line in the data. The smaller the insurer, the smaller the role AI plays in its plans.

Among large insurers, everyone considers investing in AI important for their future revenue model. Among mid-sized players, that drops to 40%. Among small ones, to 55%. And the capacity to actually do something with it is even lower: only 39% of small insurers have structurally freed up people and resources. The rest haven't.

This figure, by the way, is often retold incorrectly. "Half of insurers do nothing with AI," you hear. It's not that simple. The figure isn't about who uses AI. It's about who considers it important, and who has the capacity to act on it. That distinction is exactly what exposes the blind spot.

At the same time, something notable happens in the same figures. Nearly 80% of large and mid-sized insurers already had one or more AI applications running at the start of 2025. So AI is being used. It just isn't seen as strategic, and at the smallest players, the basic capacity to keep up is missing altogether.

That's the first crack. A sector that already deploys AI in practice, but hasn't yet taken it seriously in the boardroom. Perception and use diverge. And that gap isn't a detail. It's a risk.

Waiting feels safe. It isn't.

In 35 years in insurance, I've seen this pattern before. A new technology emerges, the large players move first, and the smaller ones wait until it's "proven." Dutch insurer Klaverblad even built its slogan around it: "If you just stay yourself long enough, you'll automatically become special." It happened that way with online distribution. It happened that way with data-driven underwriting. And every time, waiting turned out more expensive than joining in.

The tricky part about AI is the pace. A small insurer that decides today "we'll wait and see" is making a decision whose bill only lands on the table two years from now. By then, the competitor has partially automated its claims process, sharpened its underwriting, and made customer contact faster. Catching up no longer works with a three-month pilot.

I wrote earlier that 95% of AI pilots deliver nothing. That sounds like an argument to wait until things settle down. It's the opposite. The 5% that do make money come from organisations that started early, made mistakes, and learned from them. You can't buy that learning curve afterwards. You build it, or you don't have it.

And there's a second reason waiting isn't a strategy. The rules are already there.

The six principles the regulator already laid out

Here's the part many executives miss. You don't have to reinvent the wheel. EIOPA, the European insurance regulator, already set out six principles for responsible AI use in the sector back in 2021. DNB uses them as a benchmark, part of the broader AI governance it expects from insurers. Just over 70% of insurers already account for them in their own governance. Nearly a third don't.

These principles sound heavy, but they translate into plain language. A quick walk through the six:

Data governance and documentation. You need to know where the data comes from that trains your model, whether it's accurate and representative, and you must document the choices you made along the way. No black box without a logbook. An underwriting model trained on old claims data from a single region isn't a neutral model. It has a memory you need to be able to account for.

Fairness and non-discrimination. A model must not systematically disadvantage customer groups. If your underwriting or pricing model unintentionally excludes certain postcodes or age groups, that's your responsibility, not the algorithm's. And "the computer did it" is not an answer for a customer who gets rejected.

Human oversight. There must always be a person who can assess the outcome and intervene. AI advises. On what really matters — a rejection, a high premium, a fraud signal — a human decides.

Proportionality. The weight of your controls should match the risk of the application. A chatbot answering FAQs needs fewer safeguards than a model that decides whether someone gets a life insurance policy. This principle is also your protection: you don't have to build heavy governance around every application equally.

Robustness and performance. The model must keep doing what it's supposed to do, even as circumstances change. A model that works well today can drift off course in six months, for instance if customer behaviour shifts. You need to keep measuring that, not tick it off once at delivery.

Transparency and explainability. You must be able to explain why the model reached a decision. To the customer who gets rejected. And to the regulator who asks.

Read them again. This isn't a technical wish list. It's good governance, applied to software that makes decisions about your customers. And the regulator is sharpening the line. In August 2025, EIOPA published a formal opinion on AI governance and risk management, with one key message: no entirely new rules are coming. Existing insurance legislation simply also applies to AI. You can read it in the EIOPA Opinion on AI governance and risk management (opens in new window).

Governance isn't a brake. It's your fastest route.

The reflex at many management teams is that governance is the brake and innovation is the accelerator, fighting for right of way. I think it's exactly the other way round.

The reason AI projects stall is rarely that the technology doesn't work. It's that nobody thought in advance about who's responsible when it goes wrong, how you'd notice it going wrong, and how you'd explain what happened. Those are exactly the questions these six principles ask. Governance isn't the opponent of a good AI project. It's the checklist that keeps it standing.

And this is precisely where DNB sees things go wrong. The regulator found that insurers insufficiently document their development steps and, once in use, monitor too little whether the model still does what it's supposed to. They build faster than they check.

That's the real danger. Not too little AI, but uncontrolled AI.

Whoever embraces the principles early doesn't build slower. They build with a safety net, and dare to do more precisely because of it. I build AI tools myself, without a classical developer background, and the lesson is always the same: the projects that go wrong aren't the ambitious ones. They're the projects where nobody checks exactly what the model is doing. An insurer already has that safety net within reach. It's laid out in six principles.

Being small is no excuse

The counterargument I hear most often from smaller insurers: this is for the big players. We don't have data scientists, no dedicated AI team, no budget to set up a governance department. So let's leave it to the market.

I understand the reflex. But it's wrong, for two reasons.

The first is that proportionality actually works in your favour. You don't need to build a heavy governance machine for a simple application. A small insurer with a handful of AI applications can already comply with a straightforward approach: know what's running, appoint someone responsible, document the key choices. That's not a department. That's discipline.

The second reason is more uncomfortable. Many smaller insurers don't build their own AI, but buy applications from external vendors. That feels like a way to shift the risk to someone else. It isn't. The customer is your customer. The policy is your policy. And the responsibility for a fair, explainable decision stays with you, even if the model comes from a vendor. "Our software provider handles that" is not governance. It's an assumption you never checked.

Whoever buys instead of builds needs those six principles even more, not less. Because you have to ask your vendor exactly the questions you'd otherwise ask your own team. Can you explain how this model reaches a decision? What happens if it drifts? Who intervenes if it goes wrong?

What this means for your boardroom

Concretely, what can you do on Monday?

Don't start with the technology. Start with the question of which AI applications are already running in your organisation, who's responsible for them, and whether anyone checks that they still work properly. At nearly 80% of mid-sized insurers, something is already running. Chances are the answer to "who's keeping an eye on this" takes an uncomfortably long time to arrive.

Then hold the six principles up against your existing applications. Not as a checklist, but as discussion material for the management team. Where does human oversight sit? Where can you explain how a decision came about, and where can't you? Which application directly affects a customer's wallet, and therefore deserves the heaviest safeguards? You don't have to solve everything at once. You do need to know where you stand.

And watch the calendar. From August 2, 2026, stricter requirements apply under the EU AI Act for high-risk applications. For insurers, that includes risk assessment and pricing for life and health insurance. That's not a corner of the business. That's the heart of the insurance trade. The sector still uses this kind of high-stakes application sparingly in the Netherlands, and that's exactly the moment to get the basics in order: now, before you have to.

Insurers that start today with documentation, oversight and explainability won't have to scramble in panic next year. They'll have already done the homework.

The 60% who don't see AI as important to their revenue model, and the nearly 30% who ignore the principles, are making the same mistake. They see AI as a technical choice that can still wait a while. It's a boardroom decision that's already running. The question isn't whether AI affects your insurance business. The question is whether you're the one at the wheel when it does.

Sources

* The figures on AI use, capacity and governance at Dutch insurers, plus the criticism on documentation and monitoring: DNB, insurers and AI (opens in new window) * The six principles for responsible AI use in insurance: EIOPA, Artificial Intelligence Governance Principles, June 2021 (opens in new window) * The formal opinion that existing legislation already applies to AI, without entirely new rules: EIOPA Opinion on AI governance and risk management, August 2025 (opens in new window) * Why most AI pilots fail and what the winning minority does differently: Making AI Pilots Succeed * The slogan Klaverblad built its brand on: Klaverblad campaign (opens in new window)