Acquire and retain on customer data that never leaves the perimeter.
In insurance, growth is won on the customer relationship: acquiring the right policyholders, converting quotes, and holding them through renewal. Every one of those moments runs on health, lifestyle, and risk data. That is the most sensitive category there is, and the customer stack built on it cannot be allowed to leak.
The shifts our research is tracking, named, current, cited.
BCG's 2026 analysis argues AI is rewiring insurance growth around always-on, personalised retention rather than one-off acquisition, and the economics are stark: retaining a policyholder costs a fraction of winning a new one.
BCG →Singapore's Income Insurance rebuilt on a consent-first, first-party data foundation and reported a 40% reduction in CPA and a 452% increase in online revenue year over year, taking a Drum award with it. Privacy-led is not the cautious version of growth; it is the version that wins.
Merkle / Income Insurance →AXA runs a layered predictive→generative→agentic strategy with 60+ agentic use cases in testing or deployment; Zurich and Allianz have put customer and claims agents into production. Agentic engagement has moved from pilot to core.
AXA (reported) →DORA (in force since January 2025) requires documented cloud-exit strategies and control over critical ICT third parties, and residency is not sovereignty: EU-region data of a US provider, including customer and marketing data, stays reachable under the US CLOUD Act.
DORA (Reg. 2022/2554) →In insurance, the customer relationship, not the policy engine, is where AI and sovereignty compound: acquisition and retention run on data too sensitive to hand over.
Insurance growth is a marketing problem now: acquiring the right policyholders, converting quotes, and holding them through renewal. Every one of those runs on health, lifestyle, and risk data, the most sensitive category there is. Personalising on it is the growth engine; letting it out of your control is the one risk in the book you cannot underwrite.
Personalise acquisition, quote journeys, and retention on sovereign, first-party data and you get sharper targeting and higher renewal without a consent or transfer problem, on the workloads where a few points of retention move the whole P&L. Run them on an opaque US API instead and you have automated the leak of your policyholder relationships.
We build the sovereign marketing and customer-data stack: first-party acquisition, personalised retention, and cross-sell decisioned on EU compute, with frontier speed reserved for non-personal creative. In insurance, the customer relationship is the asset; sovereignty is how you keep it growing.
| Workload | Placement | Rationale |
|---|---|---|
| Acquisition personalisation | Sovereign | Targeting built on first-party customer data, never shared with a third party. |
| Quote & renewal journeys | Hybrid | Frontier drafts the copy; the customer's data and decisioning stay sovereign. |
| Retention & churn prediction | Sovereign | Runs on sensitive policyholder history; belongs on EU compute. |
| Broker & agent marketing content | Frontier | Non-personal creative, fast iteration. |
Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.
Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.
A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?
Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.
Claims narratives, medical reports, and broker submissions are your book and nobody else's. Fine-tuned on them, an open-weight model reads your risk better than any general model can.
This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.
Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.
The same four layers we ship in legal, instantiated for an insurer, where the data that makes the business work is exactly the data that must not travel.
An underwriting and claims triage workspace, a broker and agent copilot grounded in your own wordings, and retention decisioning that a pricing team can inspect line by line before it goes live.
Policy wordings, exclusions, claims-handling standards, fraud signals, and vulnerable-customer rules compiled into skills with a severity rubric, so every automated judgment can be traced back to a position someone signed.
Health, biometric, and claims narrative data is pinned to local inference by architecture. Frontier models are reachable only for anonymised, non-special-category work, under zero-retention terms, and never on a consumer tier.
Your data centre, an isolated managed instance on sovereign infrastructure, or dedicated hardware in the underwriting and claims estate itself.
The application layer here is built for you, not bought. The pattern is the one we already ship, as a product, in legal.
The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.
Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.
Teams that want proof before capital expenditure.
The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.
Small teams, and anyone who wants to inspect the source before trusting it.
An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.
Organisations without an infrastructure team to spare.
Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.
In insurance the appliance is usually the answer for special-category data: it runs the models that read claims files without any of them leaving the building.
Work that cannot leave the building, ever.
Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.
We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.