20 Jul 2026

10% of Insurers Outperform Their Peers by 21% Thanks to AI. It's Not a Matter of Technology.

The AMF’s 2026 artificial intelligence guideline establishes clear expectations for governance, risk management and accountability, making AI oversight a responsibility that extends far beyond IT teams.
gft-contact-christophe-cogno.png
Christophe Cogno
Insurance & AI Business Architect
blogAbstractMinutes
blogAbstractTimeReading
Man in business attire holding a jacket over his shoulder, standing in a minimalist white architectural setting, looking upward with a confident expression.
AI
Compliance Regulation
Blog
2026
contact
share
Imagine the scene. At the next executive committee meeting, your Chief Compliance Officer asks: “Who is accountable for all AI systems deployed throughout the organization? And how many are there exactly?” Silence. Glances are exchanged. This is precisely the situation the AMF is trying to prevent.

With its Guideline for the use of artificial intelligence, published in March 2026, the Autorité des marchés financiers (AMF) does not treat artificial intelligence as a technological issue to be delegated to IT teams. Instead, it makes it an explicit matter of institutional governance, integrated risk management and business conduct, applicable to all uses within the institution, not just customer-facing applications.

Accountability Starts at the Top

First and foremost, the AMF places responsibility at the highest level of governance. The board of directors must understand the issues related to artificial intelligence systems (AIS), be regularly informed of trends, risks and changes affecting them, and exercise effective oversight. In line with this approach, the AMF also requires that a senior management member be accountable for all AIS within the institution. Not the IT director, not Chief Data Scientist, but a senior management member in the corporate governance sense.

This requirement is not insignificant. It means that:

  • Decisions regarding AIS fall under the same level of authority as strategic, financial and compliance decisions;
  • The board of directors must be regularly informed of trends, risks and changes related to AIS;
  • The board’s collective expertise must be sufficient to understand the risks involved, particularly when the institution uses AIS for critical activities.

In other words, AI is no longer something that can be delegated to a technical team. It is a matter of governance, oversight and leadership.

The Gap Between Technology Investment and Organizational Transformation

Capgemini's latest World Property and Casualty Insurance Report 2026 confirms this reality on a global scale. The figures speak for themselves:

Indicator Value
Share of AI investments directed towards technology 72%
Share directed towards change management 28%
Insurers not measuring any AI-related KPIs 42%
Insurers still in the POC or exploration phase 60%
Employees reporting unchanged daily routines after 18 months of access to AI 47%

 

This imbalance explains why most AI programs remain stuck in the pilot phase. Investments are made in tools without transforming the organization. Technology creates capability; it is change management that determines whether this capability translates into performance.

The problem is not technological. It is organizational.

An International Convergence Toward Business Governance

The AMF is part of a global regulatory movement. Frameworks such as the NIST AI RMF, the EU AI Act, IAIS publications on AI oversight, Bank of England‘s Statement SS1/23 and the NAIC Model Bulletin all share the same core principle: AI must be governed throughout its entire lifecycle using a risk-based approach, with requirements for transparency, human oversight, robustness and control of third-party dependencies.

The NIST AI RMF proposes a structured approach to identifying, assessing, managing and mitigating AI-related risks throughout its lifecycle, through four functions: Govern, Map, Measure, and Manage.

For high-risk AI systems, the EU AI Act mandates a documented, ongoing and iterative risk management system, as well as requirements for human oversight, transparency, data, robustness and cybersecurity.

The IAIS positions AI as an extension of the existing prudential framework, while the Bank of England, through SS1/23, explicitly integrates risks specific to AI and machine learning into a broader discipline of model risk management.

The NAIC reiterates that decisions supported by AI systems must remain compliant with applicable laws, particularly regarding unfair discrimination and unfair business practices.

The AMF favors a principles-based, risk-oriented approach that aligns with these international frameworks, while also adapting it to the characteristics of the institutions it regulates. It does not create an isolated or technology-centric regime. Rather, it translates into concrete expectations a phenomenon that, in many organizations, remains fragmented across innovation, IT, data science, compliance and risk management. The AMF incorporates AI into existing disciplines (governance, risk, compliance and customer protection).

What Sets the AMF Apart in the Regulatory Landscape

The AMF goes beyond several reference frameworks, in three respects.

    1. Explicit Accountability at the Executive Level

The board must be regularly informed of trends, risks and changes related to AIS. Senior management must designate an accountable executive for the entire AI portfolio. This level of organizational clarity is more concrete than most general, principles-based approaches.

    1. Well-Equipped Governance

The AMF does not stop at mere intentions. It requires:

  • A centralized registry of all AIS deemed to pose significant risk;
  • A risk rating assigned to each AIS;
  • Adjustments to validation, documentation, approval and oversight, based on risk level.

This is very close to a prudential operating model, not just an ethical framework.

    1. An Explicit Link to Third-Party Risk

The Third-party Risk Management Guideline, published simultaneously, emphasizes that third parties can amplify existing risks, create new ones and affect operational resilience due to concentration, outsourcing and supply chain transparency.

The key takeaway: the institution remains ultimately responsible for activities entrusted to a third party. Using a third-party model, platform or AI solution does not transfer either risk or liability. It shifts risk, but accountability remains internal.

Two Concrete Insurance Examples

Life and Health Insurance: AI-Powered Underwriting or Pricing

A life insurer is using an AIS to support underwriting or pricing for disability or health insurance.

The AMF expects this institution to be able to:

  • Justify their use of this AIS and document used data;
  • Assess risks of bias, discrimination, transparency or privacy breaches;
  • Provide validation, monitoring and, if necessary, human intervention;
  • Clearly and simply explain any decision that might impact customers.

These expectations are not IT responsibilities. They fall under the responsibility of the business line using the AIS, with support from risk and compliance functions.
 

​​​​​​​P&C Insurance: Claims Triage Through a Third-Party Provider

A P&C insurer is using a third-party AI tool to automatically classify auto or home insurance claims and provide an initial estimate.

The stakes go beyond the model’s performance. The AMF expects comprehensive third-party risk management, including:

  • Assessment of the agreement's criticality and risk level;
  • Provider due diligence;
  • Contractual clauses covering data governance, business continuity and exit strategies;
  • Continuous monitoring of performance and incidents;
  • Management of the provider's subcontractors.

The institution cannot simply make sure that the tool works. It must demonstrate that it governs the business relationship and that it can regain control if necessary.

Characteristics of Successful Organizations

The Capgemini report identifies approximately 10% of insurers, referred to as intelligence trailblazers, that outperform their peers:

  • +21% revenue growth over three years;
  • +51% market capitalization over the same period.

What sets them apart is not their spending levels, but their strategic posture:

Characteristic

Mainstream

Trailblazers

AI is viewed as...

A technology project

An operational capability

Investment in change management is...

Marginal (28% on average)

A priority (43%)

AI experimentation is...

Informal

Systematically documented

Teams are organized...

In functional silos

Around shared impact KPIs

AI explainability is...

Nice-to-have

A trust infrastructure

Trailblazers simultaneously align strategy with talent, technology and organizational adoption. They do not deploy more AI; they govern differently.

Are You Ready? Five Questions to Ask Yourself

  1. Can we produce a complete list of all in production AIS within our organization in less than 48 hours?
  2. Does each AIS have a designated manager, a risk rating and a validation file?
  3. Has our board of directors received an AI briefing within the past 12 months?
  4. For AIS provided by third parties, do we have a tested exit strategy?
  5. If a customer were to challenge a decision made with the assistance of an AIS tomorrow, could we explain it clearly and simply?

If you answered "no" or "I don't know" to more than two questions, your AI governance framework falls short of the AMF’s expectations.

GFT: A Partner Aligned with the AMF's Requirements

GFT’s stance on responsible AI aligns with the AMF’s expectations. In its public commitment to responsible AI, GFT states that artificial intelligence systems must be designed to be fair, explainable and secure; three pillars that directly align with the principles of transparency, explainability, and robustness required by the Quebec guideline.

For Quebec insurers, GFT offers a distinctive combination:

  • Deep Industry Expertise: GFT has been supporting financial institutions and insurers worldwide for over 35 years, with a thorough understanding of the prudential, regulatory and operational challenges specific to the industry;
  • Governance-First Approach: Rather than starting with technology, GFT structures its
    interventions around governance and risk management frameworks: exactly what the AMF expects;
  • Integrated Privacy-by-Design and AI Governance Practices: These practices are documented in GFT's internal guidelines and embedded in the platforms and tools used for client mandates;
  • Local Presence in Canada: GFT has teams capable of supporting Quebec institutions within their specific regulatory and linguistic environment.

The challenge for insurers is not finding an AI technology provider. It is to find a partner capable of helping senior management and business lines build a credible governance framework before the guideline comes into effect.

The Cost of Inaction

  • Regulatory Risk: Failure to meet the AMF’s expectations during a prudential examination;
  • Reputational Risk: Discriminatory AI-driven decision made public without the ability to explain it;
  • Operational Risk: Failure of a third-party AI provider without a tested exit strategy;
  • Competitive Risk: 21% growth gap between AI leaders and the rest of the industry.

May 1st, 2027 is not an administrative compliance deadline. It is the moment when the gap between prepared institutions and those that are not will become visible to the regulator, to customers and to the markets.

Key Takeaways

AI is no longer a topic that can be confined to technology teams. The AMF has included it within the scope of prudential regulation, on par with model risk management and third-party management.

Three concrete actions to add to the agenda of your next executive committee meeting:

  1. Request a comprehensive inventory of all AIS in production and in development;
  2. Formally designate the accountable member of senior management;
  3. Assess the gap between your current system and the AMF’s expectations, prioritizing high-risk AIS;

Are you currently working on AI governance within your organization? I would be curious to discuss the approaches that work, and those that don’t. Do not hesitate to comment or contact me directly.

The organizations that succeed are not the ones that deploy the most AI. They are those that govern it from a business perspective.

Got Questions? We’re Happy to Help.

gft-contact-christophe-cogno.png

Christophe Cogno

Insurance & AI Business Architect
message
dataProtectionDeclaration