Delegated authority does not delegate liability: the exam reaches you, not your MGA.
What is already moving
Delegated authority, live now
When a carrier delegates underwriting authority to an MGA or coverholder, the work moves but the oversight obligation stays with the carrier. Regulators are explicit that AI governance responsibility extends to AI a delegate runs on your behalf. Binder due diligence has always checked premium, claims and bordereaux quality. It has never asked to see a delegate's AI governance program, or where a human signs off.
Nikhil Rathi, FCA
As AI moves from supporting decisions to making them, accountability has to stay clear. The regulator's direction of travel is explicit: firms will be judged on how fast they surface problems once they know something has gone wrong, not on whether a policy document existed.
FCA, ongoing
Fair value and good outcomes have to be evidenced, not asserted. If AI plays any part in pricing, underwriting screening or claims triage, the firm needs to be able to show how that output was reviewed, not just that a human theoretically could have looked.
NAIC, pilot through Sep 2026
The NAIC's AI Systems Evaluation Tool is being piloted across a dozen US states, with formal adoption expected at the Fall 2026 National Meeting. The NAIC's AI Model Bulletin has already been adopted by more than half of US states. Governing AI use in insurance is shifting from principle to an actual exam item on both sides of the Atlantic.
EU AI Act, deadline moved to 2 Dec 2027
Annex III of the EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high risk, by name, not by inference. The Digital Omnibus agreement pushed the compliance deadline from August 2026 to December 2027. Sixteen extra months is not the same as no obligation. The system named in the regulation is still the system named in the regulation, and a governance record built now is worth more than one built the month the new date arrives.
Already changing
Renewal questionnaires increasingly ask about AI controls directly. A timestamped review trail is the difference between a standard premium and an uncomfortable conversation with your own insurer.
Active now
Broker and MGA websites are advertising. Unsubstantiated claims, comparison rates and urgency wording are regulated the same way for insurance intermediaries as for anyone else.
Cryptographically sealed. Not just stored.
Each check and each sign off is written into a hash chain using SHA-256. Edit, delete or backdate any record and the break is provable. Nobody has to take your word for it, including a carrier auditing your delegated authority.
High value records are sealed with an RFC 3161 trusted timestamp from an independent authority. Anyone can verify it with standard tools, without trusting our database or yours.
We publish a live verification page. Open a real audit record, check the chain, confirm nothing was altered. No account, no sales call. If you would not accept unverifiable evidence from a delegate, do not accept it from software either.
Every check produces a PDF with the score, the flags, the reviewer and the timestamp. Built to be handed to a carrier, an insurer, a compliance file or a regulator without a covering explanation.
Specific, not vague
A carrier delegating underwriting authority remains responsible for the AI governance of whoever holds that authority, including MGAs and coverholders.
What we check
A sealed governance record naming who owns the AI decision, what it's allowed to do, and when that authority expires or needs renewal.
Fair value and good outcomes have to be evidenced when AI plays any part in pricing, underwriting or claims screening.
What we check
Named reviewer, timestamped decision, sealed record, not a policy document nobody can point to.
Adopted by more than half of US states. Requires a documented AI governance program with accountable ownership, for firms with a US book.
What we check
Same underlying evidence, jurisdiction mapped, so one governance record answers both sides of the Atlantic.
Names life and health insurance risk assessment and pricing directly as high risk AI. The compliance deadline moved to 2 December 2027, the obligation did not disappear.
What we check
A sealed record naming who owns the pricing or risk model, what it is allowed to do, ready well ahead of the new date rather than the month it arrives.
Broker and MGA marketing claims, comparison rates and urgency wording are regulated advertising, the same as any other sector.
What we check
Fake discount patterns, manufactured urgency, testimonial and comparison claims, the core of our 30 risk categories.
Marketing emails need a lawful basis, honest sender identification and a working opt out.
What we check
Email compliance checks on outbound marketing copy.
And the honest scope line: we are not your MGA, your carrier or your reinsurer. We cover the published word and the AI governance record, the two places where the evidence either exists or it does not.
Inside the binder
MGA and coverholder principals
Underwriters are already using AI screening tools, with or without a governance record. The question a carrier will ask is whether you can prove oversight when it matters. This turns an unmanaged risk into a documented, supervised process.
Compliance and risk officers
When a carrier or the FCA asks how AI is controlled, the answer needs dates, names and records. The governance assessment maps your gaps across 6 dimensions, and every subsequent check builds the evidence file for you.
Underwriters
Binder reviews have always checked premium, claims and bordereaux quality. A sealed AI governance record is the difference between a routine renewal and a delegated authority that gets pulled.
Marketing and BD teams
Check any page or client communication against 30 risk categories across 11 jurisdictions in under 60 seconds, with every flag explained in plain English before it publishes.
Start with the free checks. The evidence file builds itself from there.
The difference
Without a record
✕AI oversight happens in email threads and memory
✕No timestamp, no named reviewer
✕The carrier asks, you reconstruct
✕Renewal questionnaire arrives, you hope
✕One incident, no defence
With Red Flag AI Pro
✓Every check logged with reviewer and timestamp
✓Records sealed into a SHA-256 hash chain
✓RFC 3161 trusted timestamps on key events
✓PDF evidence ready for a carrier, insurer or regulator
✓One incident, instant answer
Know where you stand in 5 minutes
The governance assessment scores your AI oversight across 6 dimensions and shows the single biggest gap. The compliance check reads any page or document against 30 risk categories across 11 jurisdictions in under 60 seconds. Free, no account, results instantly.
Rolling this out across your delegated authorities, with client workspaces, white label reports and a managed audit trail? Talk to us about Sentinel, scoped and priced to your book.