AI in insurance is furthest along in the parts of the workflow farthest from a payout decision — damage photos, fraud flags — and stalls hard exactly where a model output decides who gets paid or covered.
After a hailstorm rolls through Texas or a hurricane makes landfall on the Gulf Coast, insurers face a predictable bottleneck: thousands of damage claims arrive within days, and there aren't enough adjusters to physically inspect every roof and fender. This is the use case that put Tractable, a London-based insurtech, on the map. Its computer vision models are trained on large datasets of vehicle and property damage photos and are used by insurers to estimate repair costs directly from images a policyholder or contractor uploads — no in-person inspection required for a growing share of claims. After major catastrophe events, this kind of tooling has reportedly let insurers triage and settle straightforward claims in a fraction of the usual time, freeing human adjusters for the complex, disputed, or high-value cases that actually need judgment.
That's the pattern worth understanding about AI in insurance right now: it is genuinely mature in the parts of the workflow that are farthest from a decision about whether someone gets paid. Photo-based damage estimation, fraud pattern-matching, document extraction — these are running in production at scale, with measurable efficiency gains and relatively low regulatory friction. But the technology stalls hard, or at least draws intense scrutiny, exactly at the point where a model's output determines whether a claim gets approved, a policy gets priced out of reach, or a person gets covered at all. That's not a coincidence — it's where the regulators and the plaintiffs' bar have drawn the line, and it's the throughline for understanding where this industry actually stands.
Claims is the area where AI has the most direct, uncontroversial win: turning a photo, a form, or a phone call into a cost estimate or a routed workflow, without waiting on a human to do the first pass.
Computer vision damage assessment works by training convolutional neural networks (or, increasingly, vision transformers) on labeled datasets of damaged and undamaged vehicles or property, so the model learns to map pixel patterns — crumpled sheet metal, cracked windshields, missing shingles — to a damage severity and likely repair cost. Tractable is the most cited name here, and it's specifically positioned around catastrophe response, where speed matters most and the volume of near-identical claims (hail dents, wind damage) makes automation tractable in the literal sense. Lemonade, the direct-to-consumer insurtech, built its brand around a bot it calls "AI Jim" that can review a claim submission — video, photos, a short description — and in straightforward cases approve and pay out with minimal human involvement.
First-notice-of-loss (FNOL) chatbots handle the intake conversation: what happened, when, where, who was involved. These are largely a solved NLP problem — structured-data extraction and intent classification — and most major carriers now have some version of a conversational FNOL flow, whether built in-house or licensed.
The caveat that matters: the fully-automated path is reserved for the easy cases. Total losses, injury claims, disputed liability, and anything that looks anomalous still get routed to human adjusters, and most carriers using this technology are explicit that the AI narrows the funnel rather than replacing adjusters outright. The limitation is also technical — CV models trained on common damage patterns can struggle with unusual materials, poor photo quality, or fraud attempts specifically designed to fool image models (a known adversarial problem insurers are quietly aware of). Straight-through processing rates for the fully automated path are still a minority of total claims volume industry-wide, even at insurtechs built around the concept.
Underwriting is where AI has changed the inputs to risk pricing more than it has changed the basic actuarial logic. Three data sources have expanded what insurers can price on:
Telematics — usage-based insurance programs that track driving behavior (hard braking, speed, time of day, phone handling) via a mobile app or plug-in device — feed behavioral data into risk models that adjust premiums based on how someone actually drives rather than proxies like age and zip code. Progressive's Snapshot and similar programs from other major auto insurers have been running for years; the newer wrinkle is that machine learning models can now weight dozens of behavioral signals simultaneously rather than a handful of hand-coded rules.
Aerial and satellite imagery for property risk is arguably the underwriting area with the cleanest technical story. Companies like Cape Analytics and Betterview process high-resolution aerial and satellite imagery with computer vision to assess roof condition, vegetation overgrowth near a structure, pool presence, and other property attributes tied to wildfire, hail, and wind exposure — without sending an inspector to the property. This matters a lot in states like California and Florida, where insurers are pulling back from wildfire- and hurricane-exposed markets and need faster, cheaper ways to reassess risk on renewal rather than new-business underwriting alone.
ML risk models more broadly — gradient-boosted trees, neural nets — are used to refine pricing on top of traditional actuarial tables, and companies like Lemonade market an AI underwriting assistant ("Maya") that collects applicant information conversationally and feeds it into automated pricing and policy issuance for straightforward personal lines.
The limitation here isn't technical maturity, it's regulatory exposure — because unlike a damage photo, a risk score determines who gets offered coverage and at what price, and that's precisely the decision regulators have targeted (more on that below). Life and health underwriting, where AI risk models increasingly touch actuarial and medical judgment simultaneously, is the sharpest edge of this problem.
Fraud detection is the AI application area insurers talk about least publicly and rely on most heavily, because it doesn't touch the claims-approval decision directly — it flags claims for human investigation rather than deciding outcomes.
Shift Technology, a French insurtech, is the most established name in this space: its models perform anomaly detection and network analysis across claims data, looking for patterns like the same repair shop, medical provider, or claimant cluster appearing across suspiciously linked claims, staged-accident rings, or billing patterns statistically inconsistent with a legitimate provider. Shift's tools are reportedly used by large European and global insurers including AXA. The technical approach blends supervised models (trained on historically confirmed fraud cases) with unsupervised graph and network analysis that can surface fraud rings without needing prior labeled examples of that exact scheme.
This is the application area with the least regulatory controversy, for a structural reason: a fraud flag doesn't deny a claim by itself, it routes a case to a special investigations unit for human review. The output is investigative prioritization, not adjudication — which keeps it mostly outside the "adverse decision" scrutiny that governs underwriting and claims-denial AI. The main practical limitation is false positives: aggressive fraud models can slow down or add friction to legitimate claims, which is a customer-experience cost insurers weigh against fraud losses avoided.
| Application area | Technical maturity | Adoption breadth | Regulatory exposure |
|---|---|---|---|
| Claims damage assessment (CV) | High — production use across major insurers and insurtechs | Wide for auto/property catastrophe claims; narrower for complex/injury claims | Low-moderate |
| FNOL chatbots / intake automation | High — mature NLP problem | Wide across large carriers and insurtechs | Low |
| Fraud detection (anomaly/network) | High — established vendor category | Wide among large P&C and health insurers | Low (flags route to human review) |
| Telematics-based pricing | High — years of production data | Wide in auto insurance specifically | Moderate |
| Aerial/satellite property risk imaging | Moderate-high, growing fast | Growing, concentrated in wildfire/hurricane-exposed markets | Moderate |
| ML underwriting/risk scoring (general) | Moderate — varies a lot by carrier and line | Uneven; more common in personal lines than complex commercial | High |
| Life/health underwriting algorithms | Moderate | Selective, cautious rollout | High — explicit regulatory targeting |
| Claims-denial / medical-necessity determination | Contested | Present but under direct legal and regulatory challenge | Highest |
The clearest way to see the pattern above isn't from the technology — it's from where regulators and plaintiffs have actually intervened.
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in 2023, doesn't ban any specific use case. Instead it requires insurers to stand up formal AI governance programs — documented risk management, oversight of third-party AI vendors, and the ability to explain and audit AI-influenced decisions — and it has since been adopted or adapted by a substantial number of state insurance regulators. It's a process requirement, not a use-case restriction, but it puts every insurer on notice that "the vendor's model did it" isn't an acceptable answer to a regulator.
Colorado's SB21-169, and the Colorado Division of Insurance regulation that followed from it, went further for a specific line of business: it requires insurers to actually test the external data sources and algorithms used in underwriting for unfair discrimination against protected classes, starting with life insurance. This is significant because it's an affirmative testing obligation, not just a disclosure rule — insurers have to be able to show their models aren't proxying for race, disability, or other protected characteristics even when those attributes are never explicitly used as inputs.
The EU AI Act takes the most structural approach: it classifies AI systems used for risk assessment and pricing in life and health insurance as "high-risk" under Annex III, which triggers a substantial compliance regime — conformance assessments, human oversight requirements, data governance standards, and documentation obligations — before those systems can be deployed in the EU market. Notably, the Act's high-risk classification is narrower than "all insurance AI"; it's specifically anchored on the underwriting and pricing decisions that affect access to coverage, not, say, a fraud-detection flag or a photo damage estimate.
And then there's the case that made this all concrete for a lot of people outside the industry: the widely reported 2023 lawsuits against UnitedHealthcare and its subsidiary NaviHealth, which alleged that an AI algorithm called nH Predict was used to systematically deny or cut short post-acute and rehabilitation care for Medicare Advantage patients, allegedly overriding physician recommendations with a model-generated length-of-stay estimate. It's important to be precise about what this is: reported litigation with serious allegations, not a proven or adjudicated fact, and the companies involved have disputed the characterization of how the tool was used. But regardless of how the litigation resolves, it's become the reference point the entire industry uses — internally and in front of regulators — for what happens when an AI system's output functions as a de facto denial decision without adequate human review. It's the clearest illustration of the thesis: nobody sues over an AI-flagged fraud investigation or a computer-vision hail damage estimate. They sue when the model's number is the reason someone didn't get care or didn't get paid.
If you're evaluating AI insurance claims about "AI-powered underwriting" or "AI claims processing," the useful question isn't whether the vendor has a model — everyone does — it's where in the decision chain the model sits. A tool that speeds up damage estimation, extracts data from a form, or flags a claim for human fraud review is operating in the part of the industry where AI adoption is real, competitively necessary, and comparatively low-risk. A tool whose output directly determines a price, a denial, or a coverage decision is operating in the part of the industry that regulators in Colorado, the NAIC's member states, and the EU have all decided needs testing, documentation, and human oversight before you trust it — and where, as the NaviHealth litigation shows, the absence of that oversight is exactly what ends up in a courtroom. Ask which side of that line any specific "AI in insurance" claim actually sits on before you evaluate whether it's impressive or concerning.