The New York Department of Financial Services just told insurers their AI use will be examined like capital reserves. For UK mid-market firms, this is not a US problem—it is your regulatory roadmap arriving three years early.
AI Governance  Trovix AriaInsurance · Financial Services · Legal

On 21 May 2026, NYDFS issued a formal advisory on frontier AI models and cyber risk. The message was unambiguous: regulators will inspect how insurers govern AI and automated decision-making. This is not soft guidance. It signals that UK regulators—the FCA, PRA, and ICO—will follow. Already, PRA SS1/23 on third-party risk and the FCA's Consumer Duty (PS22/9) create examination-ready expectations for firms using AI in underwriting, claims, and pricing. For a mid-market insurer or broker, this means: your AI tools will be audited. Your models will be challenged. Your governance framework will determine whether you pass.

This story reveals a pattern that has been building since 2023. Regulators have moved from 'AI is coming, prepare yourselves' to 'show us your governance or face enforcement action'. The EU AI Act's classification of high-risk AI in insurance has already set the tone. US regulators are following suit. UK regulators are watching both and hardening their own stance. The shift is from AI-as-novelty to AI-as-infrastructure that must be auditable, explainable, and controlled. Firms that treat AI adoption as a technology procurement exercise—buy the tool, plug it in, hope it works—will fail examination. Firms that treat it as a governance problem will survive it.

Here is the hard truth: most AI products in the market today do not help you govern AI. They help you deploy it. Tools like Microsoft Copilot or Harvey generate output fast, but they do not give you the audit trail, the decision logging, the model performance tracking, or the bias detection that regulators will demand. Even good document intelligence tools like Luminance excel at pattern-finding but are not designed to produce the examination-ready governance artefacts the FCA and PRA expect. Trovix takes a different view. Trovix Audit was built explicitly to close the gap between deployment and governance—giving mid-market firms the compliance dashboard, decision history, and model performance reporting that examiners will ask for. This is not a nice-to-have. It is the difference between passing and failing your next regulatory review.

Do not wait for the FCA to issue a formal advisory. Act now. First: map every AI decision in your firm—underwriting, claims triage, pricing, investment, claims reserving. Second: document your governance framework for each one, using PRA SS1/23 and ICO UK GDPR as your baseline. Third: implement tooling that produces auditable records. This is not onerous. It is the cost of operating AI responsibly. Mid-market firms that build governance first and capability second will be the ones writing the rulebook. The rest will be explaining themselves to examiners.

Source: Hinshaw & Culbertson LLP

Related Trovix product:

Trovix Aria →Book a demo →