Insurance growth is a data problem now
The contest has moved from price to the customer relationship, and that relationship runs on the most sensitive data an insurer holds. Where the AI that personalises it may run is settled as much by GDPR and the AI Act as by economics.
Insurance runs on exactly the data and exactly the decisions the regulator watches most closely: health, lifestyle, and the models that now personalise acquisition, quote journeys, and retention around them. After the Reset, the capability to do this with AI is abundant; the question is where it may run. For an insurer, that question is answered as much by GDPR Article 9 and the AI Act as by economics.
The pre-Reset posture, keep AI at arm's length from the customer, or pilot it cautiously on a US cloud, is now both unnecessary and exposed. Sovereign, auditable AI over policyholder data is procurable, and it is the only posture that lets you personalise acquisition and retention on the most sensitive data there is without a transfer problem.
The regulatory weather for the customer stack
Article 9, the AI Act, distribution and conduct rules all converge on control of the customer data.
GDPR treats the health and lifestyle data behind acquisition and retention as special-category, raising the bar on consent, transfer, and minimisation. The AI Act names insurance risk-and-pricing personalisation as high-risk, pulling in documentation, human oversight, and data governance, and it reaches personalised acquisition wherever it profiles. Distribution and conduct rules add suitability and non-discrimination duties to any targeting or personalisation.
Every one of those obligations is easier to meet on infrastructure you control. A retention or acquisition model whose data, logs, and decisions live inside your perimeter is one you can explain to a regulator, a policyholder, and an ombudsman. The same model behind a third-country API is a compliance argument you do not want to have.
Share of customer AI workloads by placement, weighted by how personal the data is and its GDPR/AI-Act exposure. A Rindogatan-modelled benchmark to calibrate per institution, not survey data.
What goes where for an insurer
Acquisition, retention and cross-sell go home. The non-personal creative edge can reach for frontier capability.
At the sovereign end: retention and churn models, acquisition personalisation, cross-sell and next-best-action, and analytics over policyholder data, high-value, high-sensitivity, and best run on self-hosted, governed models. At the frontier edge: broker and agent marketing content, research synthesis, and internal drafting against non-personal material, where capability earns its place. The recommended split tilts roughly seventy per cent sovereign, close to banking, for the same fundamental reason: the customer data is the asset.
Claude is the preferred frontier model where the data is non-personal; sovereign local inference on European soil is the default the moment a real policyholder is involved. The US data platforms are the EU-resident data layer and cited evidence, never the home of personal data or the inference itself.
“The data that personalises how you win and keep a policyholder is the most sensitive there is. An insurer cannot outsource the relationship it runs on to a jurisdiction it cannot audit.”
The insurer's 90 days
Four moves, anchored on the customer workloads where a few points of retention move the P&L.
Inventory and classify every customer-AI use against GDPR Article 9 and the AI Act, flagging retention, acquisition personalisation, and cross-sell on policyholder data as sovereign-by-default. Move them to sovereign infrastructure where their consent basis, documentation, and explainability can actually be delivered.
Pilot one sovereign retention or acquisition workload to prove the model, then make placement a standing governance decision so every new customer model is born compliant rather than retrofitted under audit.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.