For decades, underwriters have followed much the same process. They read the submission, chase missing information and form a view of the risk. AI agents can now do much of the first two steps in minutes, not hours. The bigger question in 2026 is what happens next. How much judgement can be passed to a machine? And where must an underwriter stay in control? Having worked across the submission-to-binding process, I believe that distinction matters more than speed alone.
Where the industry really is
The gap between ambition and delivery is a useful place to start. WTW's 2026 Advanced Analytics and AI Survey covered 59 P&C insurers in the US and Canada. It found that only 16% currently use AI to support human underwriting [1]. Sixty per cent plan to make it a priority by 2028. The direction is clear, but most carriers are still some way from broad use.
Where deployment has begun, progress has been fast. Evident recorded an 87% year-on-year rise in insurance AI deployments. Agentic systems made up one in five public deployments by the fourth quarter of 2025 [2]. Celent found that 22% of insurers expect an agentic solution to be in production by the end of 2026. Only 4% had started that move when surveyed [3]. Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of 2026. That compares with under 5% a year earlier. Yet only around 17% of organisations have deployed an agent so far [4].
The pattern is consistent. Stated intent is running ahead of delivery. Where AI is in use, it is still focused on defined tasks. End-to-end autonomous decisions remain far less common.
AI-assisted and autonomous underwriting are not the same
The difference matters because the two terms are often blurred in vendor marketing. In AI-assisted underwriting, a person still makes the decision. The system may answer questions, extract data or flag issues. But the underwriter remains accountable for the outcome. Swiss Re's Life Guide Scout is a good example. Launched in 2024, it helps an underwriter find information faster. It does not replace the underwriting decision [5].
Autonomous, or agentic, underwriting goes further. A group of agents can run a workflow from intake through to pricing and compliance checks. The system may approve a case within set limits. It may also send the case to a person for review. McKinsey calls this a 'decision orchestrator agent' [6]. It brings together the work of other agents and decides what can proceed. It also decides what needs senior underwriter review. The possible efficiency gain is large. McKinsey estimates that underwriters spend 30–40% of their time on admin, including rekeying submission data. Early agentic deployments are cutting specialty quoting from more than a month to days. Commercial P&C quoting can fall from two or three days to one or two hours.
Lemonade gives one of the clearest public examples of autonomy at scale in a consumer line. At year-end 2025, 96% of first notices of loss were taken by an AI agent without human intervention. A further 55% of claims were resolved fully automatically from start to finish [7] This is real automation at scale. It operates in a line with rich historical data and fairly standard claims patterns. It does not show that the same level of autonomy suits complex commercial or industrial risks.
Cyber underwriting moved first
Cyber insurance moved beyond the static questionnaire earlier than many other lines. The reasons matter because similar ideas are now being applied to operational technology (OT). Coalition, Cowbell, At-Bay and Resilience built models around live signals rather than a once-a-year form [8]. Cowbell assesses more than a thousand signals for each account. Its risk pool covers tens of millions of small and medium-sized businesses. It can quote and bind in under five minutes [8]. Coalition combines continuous monitoring with managed detection and response. This treats exposure as something that changes during the policy period, not as one annual snapshot [ibid].
That model suits high-volume and fairly standard cyber risks. Data is plentiful and patterns repeat. Industrial and OT cyber risk is harder. Legacy assets may not be patchable on a normal cycle. Availability needs can also restrict routine scanning. Losses may be rare, but they can be severe. For that reason, the outside-in scanning model used for SME cyber does not transfer neatly to industrial sites. Marsh McLennan's research shows the scale of the tail risk. In a worst-case scenario, OT cyber incidents could put up to $329.5 billion at risk worldwide each year. Of that, $172.4 billion is linked to business interruption [9].
The next frontier: agentic AI for OT underwriting
DeRISK UWA AgenticThis is where agentic underwriting becomes especially relevant. The same technology used to quote standard SME cyber risks in minutes is now being applied to OT. But OT is a harder problem. IT and OT failures behave differently. Submissions are often incomplete or inconsistent. Losses are less frequent, but can be much larger. That makes optimistic assumptions dangerous. This is the problem that brought me to DeNexus. Our DeRISK UWA Agentic platform launched in May 2026, with Chaucer Group as an early adopter. It can take a submission from raw documents to a full actuarial output in minutes. A manual OT cyber assessment may take ten to thirty hours [10]. One design choice is especially important. Missing evidence of OT controls is treated as a risk signal, not as a neutral blank. The principle is simple: uncertainty should not automatically be read in the insured's favour [ibid]. That is close to how an experienced underwriter reads a thin submission. It also shows the kind of judgement better agentic systems are trying to encode, not remove.
This is not yet a market-wide shift, but it is meaningful. Agentic AI can now support an end-to-end workflow for complex risks. That includes low-volume, high-severity business. Automation is no longer limited to the standard, high-volume lines where it began. Even so, adoption remains early. The evidence should be read in that context.
Governance is not optional
Regulation defines what 'autonomous' can mean in practice. Under the EU AI Act, high-risk duties apply from August 2026 to certain uses of AI. This includes risk assessment and pricing in life and health insurance. The duties cover risk management, data governance, bias testing, human oversight and logging [11]. In the US, the NAIC AI Model Bulletin had been adopted by roughly two dozen states and the District of Columbia by early 2026. It requires insurers to keep a written AI governance programme. This includes third-party oversight and model validation. A formal AI Systems Evaluation Tool has also been piloted across several states during 2026 [12]. EIOPA's 2025 opinion and early-2026 survey found that nearly two-thirds of European insurers had already used generative AI in some form [13]. The governance expected should remain in proportion to the risk. In the UK, the FCA and PRA are doing similar work. This includes a second cohort of AI live testing launched in April 2026 [14].
Across these regimes, the common themes are human oversight, explainability and accountability. They do not give firms a licence to remove people from the process. In a regulated line, 'autonomous underwriting' in 2026 is better seen as human-governed autonomy. It needs a full audit trail. It is not unsupervised machine decision-making. A credible agentic platform should therefore trace each output back to its source document, model version and workflow step. The decision can then be rebuilt for internal review, audit or a regulator if needed.
Where the sceptics have a point
The caution is justified. A NAIC survey of 93 health insurers, released in mid-2025, found that 92% use or plan to use AI. Nearly a third do not test their models regularly for bias [15]. A pending lawsuit against a major insurer alleges that algorithmic claims screening disadvantaged Black homeowners. The case survived a motion to dismiss and remains in discovery [16]. Regulators are also focused on model drift. This is the risk that a model becomes less accurate as the world changes from the one on which it was trained The emerging view is that agentic AI should support underwriters, not simply replace them. That is not based on sentiment. It reflects the need for clear responsibility, an audit trail and human control. Those needs become more important as decisions move beyond simple, low-limit cases.
What this means for insurers and reinsurers
The most useful way to think about agentic AI in underwriting is by risk complexity, not by the hype cycle. High-volume, well-understood and standard risks are where real autonomy has moved furthest. Lemonade's claims data shows what that can look like at scale. Complex, low-frequency and high-severity risks need a different model. Industrial OT is a good example. Here, agents can gather evidence, find gaps and quantify risk faster and more consistently. The underwriter can still keep responsibility for the final decision. Both models are meaningful progress, but they are not the same thing.
For insurers and reinsurers, two tests are especially useful. First, can the platform produce a clear decision trail at short notice? Could that trail be explained to a regulator, auditor or senior underwriting committee? Second, does the platform become more useful as the risk becomes more complex? Or does it simply process easy cases faster? If the answer to the first two questions is yes, the technology is supporting underwriting judgement. If not, it may only be speeding up the uncertainty that already exists in the process.
For more on DeRISK UWA Agentic's five-agent architecture, see the launch announcement and our Learn portal's Agentic AI FAQ, including how autonomy levels and the Sound of Silence mechanism actually work. For the OT maturity signal this kind of underwriting increasingly depends on, see How to Assess OT Cybersecurity Maturity and our earlier work on translating maturity scores into insurance underwriting signals. For the threat data shaping what these systems need to assess in the first place, see our ENISA Threat Landscape analysis.
See it in practice. DeRISK UWA Agentic takes an OT cyber submission from raw documents to a full actuarial output in minutes — with every figure traced back to its source document, model version and workflow step, so the decision can be rebuilt for audit or a regulator. Missing evidence of a control is treated as a risk signal, not a neutral blank. Augment your underwriting team with OT cyber specialist capability — without hiring one.
Explore the DeRISK Platform → https://www.denexus.io/derisk-platform
References
[1] WTW. 2026 Advanced Analytics and AI Survey. Mar. 2026.
[2] Evident. AI Use Case Tracker: Insurance. Q4 2025.
[3] Celent. Third Annual Generative AI in Insurance Survey. 2026.
[4] Gartner, Inc. Enterprise AI agent adoption forecast, 2026.
[5] Swiss Re. "Swiss Re Launches Swiss Re Life Guide Scout, a Generative AI-Powered Underwriting Assistant." Swiss Re Press Release, 2024, www.swissre.com.
[6] McKinsey & Company. "Agentic AI in Insurance Underwriting." McKinsey Insights, June 2026.
[7] Lemonade, Inc. Year-end 2025 shareholder letter and claims automation disclosures.
[8] Cowbell Cyber. "Cowbell Factors: A Defining Milestone in Cyber Risk Quantification." Cowbell Blog, 2023, cowbell.insure/cowbell-factors-2023/.
[9] Marsh McLennan. OT cyber risk exposure modeling, cited in Dragos and Marsh McLennan, OT Security Financial Risk Report, Aug. 2025.
[10] DeNexus. "DeNexus Launches DeRISK UWA Agentic — the First Agentic AI Underwriting Platform for Industrial Cyber Insurance." DeNexus Press Release, 11 May 2026, www.denexus.io/resources/denexus-launches-derisk-uwa-agentic-the-first-agentic-ai-underwriting-platform-for-industrial-cyber-insurance.
[11] European Union. Artificial Intelligence Act (Regulation (EU) 2024/1689), high-risk provisions effective 2 Aug. 2026.
[12] National Association of Insurance Commissioners (NAIC). AI Model Bulletin. Adopted 4 Dec. 2023; state adoption tracker updated Mar. 2026.
[13] European Insurance and Occupational Pensions Authority (EIOPA). Opinion on Artificial Intelligence Governance. 6 Aug. 2025; follow-up survey, Feb. 2026.
[14] UK Financial Conduct Authority (FCA). AI Live Testing, second cohort, Apr. 2026.
[15] National Association of Insurance Commissioners (NAIC). Health AI/ML Survey. May 2025.
[16] Federal class action against State Farm, algorithmic claims-screening allegations, filed 2022, in discovery as of 2026.