← Back to blog

IRDAI’s Approach to AI: Building Safe Insurance Systems

How IRDAI, India’s insurance regulator, is responding to the growing use of artificial intelligence in insurance by focusing on governance rather than bans. It shows how AI is improving underwriting, claims and fraud detection, but also creating risks around bias, privacy and opaque decisions. It then highlights IRDAI’s steps setting up an AI working group, urging insurers to “AI‑proof” systems before integrating with the Bima Sugam digital marketplace, and insisting that AI tools be fair, transparent, explainable and accountable, so that innovation can continue while policyholders’ data, rights and trust stay protected.

Sakthi Thangavelu·Co-founder, AramGRC·June 29, 2026·7 min read

The Insurance Regulatory and Development Authority of India (IRDAI) is the apex regulator for the insurance sector. It licenses and supervises insurers, protects policyholders’ interests, ensures companies remain financially sound and frames regulations for new products and technologies. When new tools such as artificial intelligence (AI) or blockchain enter the market, IRDAI’s task is not simply to say yes or no; it is to ensure that innovation happens without compromising customer protection, financial stability or fair conduct.

As AI moves from buzzword to everyday infrastructure inside insurance companies, questions of governance become central. How do we allow insurers to benefit from AI while preventing opaque, biased or privacy‑invasive systems from harming policyholders? IRDAI’s recent initiatives on AI governance are aimed at answering exactly this question.

How AI Is Changing Insurance

Over the past few years, AI and machine‑learning models have begun to support almost every stage of the insurance lifecycle. Life and general insurers are using AI to:

  • Streamline proposal and onboarding through automated KYC, document verification and eligibility checks.
  • Enhance underwriting and pricing by analysing large volumes of data, including health records, behavioural indicators and telematics, to refine risk assessments.
  • Automate claims processing by reading documents, analysing images or medical records, and triaging claims for faster decisions.
  • Improve customer service with chatbots and voice assistants that handle routine queries, renewal reminders and simple transactions.
  • Strengthen fraud detection via anomaly‑detection and pattern‑recognition models that flag suspicious claims, providers or intermediaries.

These tools make insurance more efficient and scalable. They reduce manual workload, shorten turnaround times and can help insurers expand coverage to new segments. For a country seeking higher insurance penetration, that is a significant advantage.

Yet the same characteristics that make AI attractive are speed, scale, data‑intensity also creates new kinds of problems, so existing laws and regulations have to be updated or strengthened to deal with those problems.

Why AI Needs Strong Governance in Insurance

Insurance is built on trust. Policyholders share extensive personally identifiable information (PII), and often sensitive health and financial data, in exchange for the promise of fair claims handling and secure data management. Integrating AI into this relationship introduces specific governance challenges.

Bias and unfair outcomes

AI systems learn from data. If the underlying data is skewed or historically biased, models can reproduce or amplify those biases. In insurance, this may translate into:

  • Certain groups consistently receive higher premiums.
  • Greater frequency of claim rejections or delays for particular categories of customers.
  • Risk profiles shaped by proxies that correlate with protected or sensitive traits.

From a legal and regulatory perspective, such outcomes are problematic even if they are not intentional. Insurers cannot simply say “the algorithm decided”, they remain responsible for ensuring non‑discriminatory treatment under IRDAI’s conduct and product rules. IRDAI has explicitly flagged algorithmic bias as a key risk that must be addressed through governance.

Opacity and explainability

Traditional underwriting and claims decisions, however imperfect, can be explained by human staff: which factors were considered, how they were weighed, and why a particular outcome was reached. Complex AI models, especially deep learning systems, often function as “black boxes”.

For customers, this creates frustration: “Why was my premium increased?”, “Why was my claim treated as suspicious?”, “Why was my proposal declined?”. For regulators and courts, opacity makes it harder to assess whether decisions are lawful and fair. AI governance therefore requires explainability, models whose outputs can be translated into reasons that humans can review and challenge where necessary.

Privacy and data protection

AI thrives on large data sets. Insurers may be tempted to collect, retain and share more data than before, including alternative data sources and behavioural indicators. Without guardrails:

  • Purpose limitation may be breached data collected for one purpose used for another.
  • Retention periods may become indefinite, increasing exposure to breaches.
  • Consent may be bundled or not truly informed.

India’s Digital Personal Data Protection (DPDP) framework expects clarity on why data is collected, how long it is retained, how it is processed and what rights data principals have. In the AI context, that means insurers must be able to demonstrate lawful basis, purpose limitation, storage limitation, consent mechanisms and mechanisms for data principals to query or object to certain uses of their data. IRDAI’s expectations around privacy in AI systems are closely aligned with these DPDP principles.

Accountability and human oversight

When AI systems influence decisions, especially high‑impact ones such as claim denial or policy cancellation, accountability cannot disappear into the model. From IRDAI’s perspective, someone must be responsible: boards and senior management, business owners, risk and compliance teams, not just vendors or data scientists.

Governance frameworks must therefore define responsibility clearly, retain meaningful human oversight over critical decisions and create mechanisms for review and redress. Put simply, responsible AI in insurance means that if an algorithm influences a high‑impact decision, someone can explain that decision, someone is accountable for it, and the outcome can be challenged and corrected where it is unfair.

IRDAI’s Perspective: Responsible, Not Rejected AI

Despite these concerns, IRDAI has not taken an anti‑AI stance. The regulator recognises that AI can:

  • Reduce operating costs and make insurance more affordable.
  • Improve risk selection and protect the financial stability of insurers.
  • Strengthen fraud detection and reduce leakage, thereby benefiting honest policyholders.

IRDAI’s emphasis is on responsible AI. In regulatory language, this means AI that is fair, accountable, auditable, transparent, explainable and privacy‑preserving. AI is welcome to enhance efficiency and fraud control, but it must operate inside a governance framework that protects policyholders and upholds IRDAI’s prudential and conduct standards.

From a regulatory perspective, this approach is sensible. Banning AI outright would deprive the sector of useful tools, while unrestricted adoption would expose policyholders to opaque and potentially discriminatory systems. A carefully designed governance framework allows IRDAI to encourage innovation while treating AI as a high‑risk technology subject to strict oversight.

IRDAI’s AI Working Group: Towards a Formal Framework

To structure this balance between innovation and protection, IRDAI has constituted a seven‑member working group on AI governance on 17 June 2026, through an office order. The group’s mandate includes:

  • Mapping current AI usage across insurers and intermediaries- underwriting, pricing, claims, fraud analytics, chatbots and internal operations.
  • Assessing risks and maturity, including how existing governance, information security and conduct frameworks apply to AI tools and where gaps exist.
  • Studying global approaches, such as AI regulation in other financial jurisdictions, and identifying practices that can be adapted for Indian insurance.
  • Recommending an AI governance framework, proposing principles and structures for ethical, fair, transparent and explainable AI, including governance bodies, model‑risk management processes, audit requirements and security controls.impactmojo+1

The working group’s output is expected to inform future IRDAI guidelines or regulations on AI. In effect, AI‑specific rules will sit on top of existing instruments, corporate governance norms, product and conduct regulations, fraud‑management circulars, information‑security guidelines and data‑protection obligations, creating a layered regulatory environment for AI in insurance.

Bima Sugam: Digital Infrastructure as an AI Catalyst

An important backdrop to IRDAI’s AI push is Bima Sugam, the Insurance Electronic Marketplace. Under IRDAI’s 2024 regulations, Bima Sugam is envisaged as a unified digital platform where customers can compare products, buy and renew policies, access records, file and track claims and lodge grievances, connecting insurers, intermediaries and policyholders through interoperable digital rails.

This digital public infrastructure naturally encourages greater use of automation and AI. As insurers prepare to integrate with Bima Sugam and the proposed Public Insurance Registry, AI‑driven tools will increasingly be embedded in customer journeys, underwriting flows, fraud checks and service channels.

Recognising this, IRDAI has urged insurers to “AI‑proof” their systems as a priority. The regulator has raised concerns over algorithmic bias, data‑privacy risks and accountability gaps and has signalled that AI‑driven processes plugged into Bima Sugam must be governed, tested and controlled. Insurers are responding by strengthening AI governance frameworks introducing independent model validation, regular audits, documentation requirements and more robust human review of AI‑supported decisions.

Bima Sugam thus acts as a catalyst for AI governance. Before AI tools are connected to a national marketplace that millions of policyholders will rely on, insurers are being pushed to ensure their models are fair, explainable, secure and aligned with data‑protection and conduct norms. Participation in this new digital infrastructure effectively requires responsible AI.

Immediate Expectations from Insurers

Even before the working group finalises a formal framework, IRDAI already expects insurers using AI to take concrete steps. At a minimum, these include:

  • Data‑protection alignment: AI‑related data processing must follow DPDP principles like purpose and storage limitation, lawful basis for processing, consent where required, defined retention periods and mechanisms for data principals to exercise their rights, including through consent managers and grievance channels.
  • Bias and impact assessments: Material AI models, especially those used in underwriting, pricing and claims, should be tested for discriminatory impact and unfair outcomes, with corrective measures where needed.
  • Documentation and audit trails: Insurers should maintain documentation of model design, training data, validation results and changes over time, along with logs of key decisions influenced by AI, so that regulators and courts can reconstruct how a decision was reached.
  • Human‑in‑the‑loop for critical decisions: High‑impact decisions should involve human review or override capability, rather than being fully automated, ensuring that policyholders are not at the mercy of unreviewed algorithms.
  • Clear governance structures: Boards and senior management should be aware of AI use, approve policies that reference AI explicitly, and establish committees or functions responsible for AI governance and model risk management.

Importantly, these expectations apply not only to insurers but also to intermediaries. Brokers, corporate agents and technology vendors deploying AI‑driven lead‑generation, claims‑assistance tools must align with IRDAI’s governance expectations and data‑protection norms. Contracts and outsourcing arrangements will increasingly need to address model risk, data use, audit rights and liability for AI‑related errors.

AI in insurance, therefore, operates under a layered regulatory environment: general data‑protection law at the base, sector‑specific rules on governance, products, conduct, fraud and security above that, and an emerging AI‑specific framework designed to make these obligations workable for AI and machine‑learning systems.

Conclusion: AI Governance as a Shared Responsibility

AI is reshaping insurance in India, from risk assessment to customer service. IRDAI’s evolving approach recognises both the promise and the peril. By promoting responsible AI—fair, accountable, auditable, transparent and privacy‑preserving, constituting an AI working group and pushing digital infrastructure such as Bima Sugam, the regulator is signaling that AI must be treated with the same discipline as any other core function in insurance.

For insurers, intermediaries and insurance techs, this means that AI governance is not optional; it is a component of good business and regulatory compliance. For policyholders, it means that as algorithms enter the heart of insurance, their rights, data and interests should remain at the centre of the system.

IRDAIAIINSURANCE SYSTEM
WhatsApp