pancucci.pro

The AI Act deadline moved. Your AI readiness work should not.

AI readiness in (re)insurance within the boundaries of DORA and data governance.

Contents
  1. AI readiness is an operations problem, not a technology problem
  2. What I would do with the extra eighteen months

In June 2026 the EU gave its final green light to the “Digital Omnibus” package, deferring the AI Act obligations for high-risk systems from August 2026 to December 2027. In many boardrooms I can already hear the collective sigh of relief: eighteen more months.

I think that is the wrong way to read it.

If you sit on the board or the executive team of a regulated (re)insurer, the uncomfortable truth is that most of what “AI readiness” requires of you is not in the AI Act at all. It is in rules that are already binding: DORA, applicable since January 2025; GDPR, with us since 2018; the Solvency II system of governance; and, since August 2025, EIOPA’s Opinion on AI governance and risk management, which tells national supervisors exactly how to read AI use within the existing framework. The deadline moved. The supervisory expectations did not.

AI readiness is an operations problem, not a technology problem

The gap is real. Nearly two thirds of European insurers already use generative AI, according to EIOPA’s latest market monitoring, yet most are still at proof-of-concept stage. Bain sees the same pattern in P&C globally: 78% adoption, 4% scaled across the organisation, and measured savings that for the largest group of firms stop at 10% or less. Having led the DORA operational and ICT resilience programme of a global reinsurer as COO, and having sat through the supervisory dialogues that come with it, my view on why is simple: AI readiness is 20% about models and 80% about the foundations underneath them. Four foundations in particular.

Know where AI already is. Most insurers do not have an AI adoption problem; they have an AI visibility problem. AI enters the house through vendors: the claims platform that added a fraud-scoring module, the CRM with a generative assistant, the document-processing tool in technical accounting. If your outsourcing register and your DORA Register of Information do not capture these capabilities, you are already using AI you have not assessed. The first deliverable of any AI readiness programme is an honest inventory, including what I call shadow AI: features switched on by suppliers inside tools you already run.

Treat AI as ICT, because DORA does. An AI system embedded in underwriting, claims or reserving is ICT supporting a critical or important function. That triggers obligations you already know: due diligence and contractual provisions for the provider, inclusion in the register, incident reporting when it fails, resilience testing, and a credible exit strategy. Exit is the one I press hardest. The market of foundation-model providers is concentrated in a handful of firms; concentration risk that would be unacceptable for a data centre is somehow accepted for models that price risk. It should not be.

Fix data governance before scaling models. Every AI ambition eventually collides with the same wall: data ownership nobody wants, lineage nobody documented, quality nobody measures. GDPR already requires lawfulness, minimisation and accountability for the personal data feeding your models; EIOPA’s Opinion adds proportionate expectations on data quality, bias monitoring, explainability and human oversight. In practice, a reinsurer that cannot trace which cedant data flows into which model, under which legal basis, is not AI-ready no matter how good the pilot looks.

Make accountability boring and explicit. The three-lines-of-defence model does not need reinventing for AI; it needs applying. A named business owner for every material AI use case. Risk and actuarial functions equipped to challenge model outputs, not just admire them. Internal audit with access to documentation. And a board that has spent real time on the topic, because under the AI Act accountability for how a system is used sits with the deployer and cannot be outsourced to the vendor.

What I would do with the extra eighteen months

The postponement to December 2027 is not a pause; it is cheap preparation time. Used well, it buys three things.

It keeps predictive models running. Pricing and risk-assessment systems in life and health, which will be high-risk when the obligations land, can stay in production while the compliance framework around them matures, instead of being frozen or stripped back to meet a deadline.

It buys clarity. EIOPA and national supervisors now have time to publish workable guidance on data governance and on how the AI Act interlocks with the rules we already live under; firms, in turn, have time to test their algorithms against bias properly, as an engineering discipline rather than a last-minute attestation.

And it buys efficiency. Compliance investment can be spread across the 2026 and 2027 budgets instead of landing on one, at a time when BCG expects AI spending as a share of revenue to triple. AI controls can be folded into the DORA and IT-security audit cycles you already run, one integrated assurance plan instead of two parallel ones, which also avoids paying twice for consulting and technology audits. And structured AI literacy programmes can reach the whole organisation rather than a task force. One caution on that last point: do not read the Omnibus as permission to slow down on training. The formal literacy obligation on firms was softened in the final package, but a board that cannot interrogate its own models will not enjoy the benefit of the doubt in front of a supervisor.

The sequence I recommend to boards is deliberately unglamorous. Inventory all AI in use, vendor features included. Classify each use case against the AI Act risk tiers anyway, because life and health pricing and risk assessment will be high-risk when the obligations land, and retrofitting compliance is always more expensive than building it in. Extend the outsourcing and ICT registers to capture AI explicitly. Assign data ownership for the domains that feed material models. Pilot where materiality is low and learning is high, with human oversight designed in rather than promised. And train the board: not on how transformers work, but on which decisions in the value chain are being delegated to systems, and on what evidence exists that those systems behave.

Firms that treat December 2027 as the starting gun will end up doing compliance twice: once in a rush for the deadline, once again to fix what the rush produced. Firms that build the foundations now will discover something more interesting: the same registers, lineage and accountability that regulators ask for are exactly what makes AI adoption faster and safer, because you finally know what you have, what it touches and who answers for it. That is where the 50 to 70 billion dollars of additional industry revenue McKinsey attributes to generative AI will actually be earned: not by the firms with the most pilots, but by the firms whose foundations let pilots become production.

Readiness is not something you declare in a policy. It is something your operating model either has or does not.

I would be interested to hear how other operators and board members in the (re)insurance market are approaching this. If you are working through the same questions, my door is open.

This is the edition of record of the article first published on LinkedIn on 3 July 2026.