Federal regulators are flagging growing risks as Canadian insurers move from AI experimentation to production. A joint assessment by the Office of the Superintendent of Financial Institutions (OSFI) and the Financial Consumer Agency of Canada (FCAC) finds insurers are adopting artificial intelligence for underwriting and claims management, but many are depending on third-party technology providers — a reliance that raises questions about data security, model oversight and operational resilience.
Regulators set out the core concerns
The joint report, released this year, found roughly one-quarter of responding insurers identified underwriting or claims management among their top AI use cases. At the same time, firms are signalling significant investment plans: about 75% expect to invest in AI over the next three years and about 70% plan to use AI models in their operations.
“Every industry is both excited and overwhelmed with the pace of change with technology. Making sure that we’re using it in the most appropriate way, making sure that we’re using it in a secure way,”
The observation came from Greg Smith, president of Crawford & Company (Canada), and encapsulates the balancing act insurers face between innovation and control.
Third-party relationships and concentration risk
OSFI and FCAC flagged that most financial institutions rely on external suppliers for AI models and systems. That dependency can limit visibility into how proprietary models operate and impede an insurer’s ability to confirm the vendor meets internal standards.
Regulators also warned about concentration risk when many firms depend on a handful of large technology providers. Cloud-hosted AI services introduce further concerns about operational disruption and the security of sensitive customer information processed by these systems.
Institutions remain ultimately responsible
The report makes clear that buying or licensing AI tools does not transfer regulatory responsibility. Financial institutions remain accountable for third-party AI systems used in their business, particularly those that affect customers. That means insurers must ensure adequate due diligence, testing, governance and incident response even when a vendor operates the model.
- Key risks identified by institutions: data privacy and security, model risk, legal risk and business risk.
- Common AI use cases: underwriting and claims management were cited among top applications by about one-quarter of insurers.
- Planned adoption: roughly 75% of firms plan to invest in AI in the next three years; about 70% will deploy AI models.
Those figures suggest a broad shift from pilot projects to operational deployment. The regulators’ concerns emphasise that speed of adoption needs to be matched by governance and transparency.
Practical implications for insurers and consumers
For insurers, the regulators’ message is operational: build robust third-party oversight and be able to demonstrate model performance, data handling practices and contingency plans. For consumers, the stakes include how personal data is used and protected, and whether automated decisions are accurate, fair and explainable.
| Indicator | Share of institutions |
|---|---|
| Plan to invest in AI (next 3 years) | ~75% |
| Plan to use AI models | ~70% |
| Identify underwriting/claims as top AI use case | ~25% |
Regulatory scrutiny is likely to influence procurement, vendor contracting and risk-management practices. Insurers may need to negotiate stronger audit rights, require model explainability features, and insist on clearer incident response clauses with suppliers. They will also have to consider the implications of concentration risk when many peers use the same cloud platforms or models.
At a system level, OSFI and FCAC’s findings underscore a policy tension: encouraging digital innovation that can improve efficiency and customer outcomes while ensuring those advances do not introduce systemic vulnerabilities. That balance will shape supervisory guidance, expectations for governance and the types of reporting regulators demand.
As insurers accelerate AI adoption, the regulators’ message is straightforward: innovation cannot outpace oversight. Firms that treat third-party AI as a plug-and-play capability risk regulatory, operational and reputational harm if they cannot demonstrate safe, secure and accountable use.