• About us
  • Services
  • Careers
  • Blog
  • Home
  • -
    Blog
  • -
    Production Without Scale: The Governance Gap Stalling AI in APAC Insurance
Article Content
  • Chapter 1.Key Takeaways
  • Chapter 2.The Number That Matters More Than The Adoption Number
  • Chapter 3.What Separates The 7% From Everyone Else
  • Chapter 4.The Regulatory Floor Is Rising To Meet The Same Problem
  • Chapter 5.A Counterpoint Worth Taking Seriously
  • Chapter 6.A Decision Framework: The Four Gates
  • Chapter 7.The source[code] Perspective
  • Chapter 8.Conclusion
  • Chapter 9.Frequently Asked Questions
  • Chapter 10.Reference List

Production Without Scale: The Governance Gap Stalling AI in APAC Insurance

source[code] | BFSI Technology Insight | 3 September 2026

Key Takeaways

  • Insurance crossed a real threshold in 2026: 73% of carriers now run AI in production, almost double the 37% recorded in 2025 (Datos Insights, 2026). Adoption is no longer the story.

  • Scale is. Only 7% of carriers have reached enterprise-wide AI deployment, and just 33% can point to demonstrable, measured return on their AI investment (Datos Insights, 2026).

  • The stall point is consistent across markets: carriers get an AI system into one production workflow, then hit the same wall trying to extend it - the same wall regulators in Singapore, Hong Kong and Europe are now writing into supervisory expectations.

  • MIT NANDA's 2025 study of enterprise generative AI found a comparable pattern outside insurance - a 95% failure rate for task-specific pilots reaching production - and traced it to weak workflow integration, not weak models (MIT NANDA, 2025).

  • Four decision gates - architecture, oversight, economic proof, and delivery accountability - explain most of the difference between carriers that scale AI and carriers that stay stuck showcasing it.

APAC insurance executive reviewing an AI governance framework, representing the gap between AI pilots and production-scale deployment

The Number That Matters More Than The Adoption Number

For three years, the insurance AI conversation has been dominated by a single question: how many carriers have adopted it. That question is now close to resolved. Datos Insights' 2026 survey of carrier technology leaders found that 73% run AI in production somewhere in the business, up from 37% just a year earlier (Datos Insights, 2026). Deloitte's 2025 survey of insurance executives told a similar story a year earlier still, with 76% reporting generative AI implemented in at least one business function, and adoption running higher in life and annuities (82%) than in property and casualty (70%) (Deloitte, 2025).

By any reasonable measure, insurance has answered the adoption question. What it has not answered is the scale question. Of the carriers Datos Insights surveyed, only 7% had reached enterprise-wide AI deployment. Most sat in a stage the report labels "Hitting Walls" - live in production, but constrained by legacy infrastructure and thin technical talent, with only a third able to demonstrate positive return on the investment made (Datos Insights, 2026). Deloitte's earlier data shows the same shape from a different angle: the largest cluster of initiatives sat not in deployment but in scoping, and the most commonly cited failure factor was not the technology at all - it was a lack of support from the business line that was supposed to own the outcome (Deloitte, 2025).

APAC insurance executive reviewing an AI governance framework, representing the gap between AI pilots and production-scale deployment_2

This is the pattern worth taking seriously in 2026: insurers are not failing to start AI programmes. They are failing to get a second, third and tenth use case through the same door the first one used. That is a scale problem, and scale problems are organisational before they are technical.

What Separates The 7% From Everyone Else

McKinsey's research on gen AI frontrunners in insurance, drawn from carriers that did successfully scale, points to a specific and testable difference: frontrunners do not run more pilots than everyone else, they run fewer, deeper ones. Concentrating gen AI across an entire domain - claims, for example - rather than scattering it across isolated tasks can produce up to fourteen times the impact of a point solution (McKinsey & Company, 2024). The same research is unglamorous about where the actual value sits: an estimated 60 to 80% of the return frontrunners capture comes from traditional AI and automation techniques, not generative AI, which does the narrower job of extending those systems into unstructured data and natural language (McKinsey & Company, 2024).

⏩ Read more about The Underwriting Renaissance: How AI Is Rewiring Insurance Economics Across APAC

The frontrunners also embed risk management from the start of a build rather than adding it once legal asks a question, and they make an explicit, criteria-based call on which components to build and which to buy rather than defaulting to either (McKinsey & Company, 2024). That build-versus-buy discipline turns out to matter more than most technology strategies acknowledge. MIT NANDA's 2025 study of enterprise generative AI deployments - 52 structured interviews, 153 senior-leader survey responses, and an analysis of more than 300 disclosed initiatives across industries - found that AI tools built through an external partnership reached successful deployment 67% of the time, against 33% for internally built tools attempting the same task (MIT NANDA, 2025). The same study is the source of the now widely quoted finding that roughly 95% of task-specific generative AI pilots never reach production or return: not because the underlying models were inadequate, but because the tools lacked persistent memory of context, did not learn from workflow-specific feedback, and were bolted alongside existing processes rather than built into them (MIT NANDA, 2025). That is a description of a delivery and integration failure, not a model failure - and it maps almost exactly onto what Datos Insights and Deloitte separately found inside insurance specifically.

The Regulatory Floor Is Rising To Meet The Same Problem

While carriers have been discovering this the hard way, APAC and European supervisors have converged on a strikingly similar checklist - arrived at independently, through the lens of prudential and conduct risk rather than delivery performance.

APAC insurance executive reviewing an AI governance framework, representing the gap between AI pilots and production-scale deployment_3

The Monetary Authority of Singapore's AI Risk Management Toolkit, developed with banks, insurers and capital markets firms and rolled out through 2026, organises expectations around governance structures with clear AI oversight roles, human oversight of AI-driven decisions, systematic risk assessment and inventory of AI use, and controls applied across the full AI lifecycle rather than at launch alone (Rajah & Tann Asia, 2026). The European Insurance and Occupational Pensions Authority's opinion on AI governance, published in August 2025, takes a risk-based and proportionate approach to the same territory, asking insurers already subject to Solvency II and the Insurance Distribution Directive to extend existing standards on data governance, fairness, cybersecurity, explainability and human oversight to AI systems specifically, rather than treating AI as exempt from principles that already apply to every other technology decision (EIOPA, 2025).

Hong Kong has gone further than guidance: in August 2026, the HKMA, the Securities and Futures Commission and the Insurance Authority jointly opened the first cohort of the GenA.I. Sandbox++, selecting 36 use cases from close to 100 proposals across 30 financial institutions and 27 technology partners, spanning banking, securities, insurance and pensions, with claims handling named explicitly among the workflows under live supervisory observation (OpenGov Asia, 2026). The Securities and Futures Commission's Julia Leung framed the programme's premise directly: greater system autonomy has to be "underpinned by sound governance and clear accountability" to be allowed to run at all (OpenGov Asia, 2026). Accenture's 2026 insurance predictions put the same expectation in operating terms carriers can actually build against: humans need to function as "a control point, not a formality," with explicit approval thresholds, exception handling and audit trails attached to any AI decision with real consequence (Accenture, 2026).

Read the toolkit, the opinion and the sandbox conditions side by side and the overlap is not a coincidence. Three supervisors working independently arrived at the same four requirements: named governance ownership, human oversight at defined points, explainability, and controls that run through the system's full lifecycle rather than a one-time sign-off. That is precisely the architecture McKinsey's agentic AI research says a modern AI system needs regardless of what any regulator asks for - "human-in-the-loop approvals at stage gates" and full traceability, because an agentic system is being asked to act inside "a living socio-technical system" of decades-old, sparsely documented business rules that nobody fully trusts on day one (McKinsey & Company, 2026).

The practical implication cuts against the instinct to treat governance as a tax on speed. In every dataset examined here, the carriers that built oversight and explainability into the system from the outset were the same carriers reporting production deployment and measurable return. Governance is not competing with scale for the same budget. In 2026, it is a precondition of it.

A Counterpoint Worth Taking Seriously

None of this should be read as an argument that more process automatically produces more scale - that claim does not survive contact with the data either. Deloitte's research found that carriers already burdened by legacy infrastructure and thin data foundations struggled to scale gen AI even where governance and executive sponsorship were present, because the underlying systems simply could not support what the AI initiative asked of them (Deloitte, 2025). And MIT NANDA's finding that internally built tools succeeded only half as often as partnered ones is not an argument that insourcing is wrong; several of the "Hitting Walls" carriers in the Datos Insights cohort had genuine in-house engineering capability, but had not resourced the specific, less interesting work of integration, monitoring and lifecycle maintenance that separates a working pilot from an operated system (Datos Insights, 2026). The differentiator in both datasets is not who writes the code. It is whether governance, data architecture and delivery accountability were designed in from the first sprint or discovered as gaps once the regulator, the auditor or the customer complaint arrived.

A Decision Framework: The Four Gates

Carriers trying to work out why a specific AI initiative is stuck can usefully test it against four gates, each one owned by a different member of the buying and governance committee rather than by the technology team alone.

APAC insurance executive reviewing an AI governance framework, representing the gap between AI pilots and production-scale deployment_1

The architecture gate (CTO/CDO). Is the initiative integrated end-to-end into an owned business workflow, or does it sit beside the workflow as a demo? McKinsey's fourteen-times impact gap between domain-wide and point-solution deployments is, in practice, a measure of how well this gate is cleared (McKinsey & Company, 2024).

The oversight gate (Risk/Compliance). Can the system show named governance ownership, a defined human-oversight point, and an explainability trail that would satisfy MAS's toolkit, EIOPA's opinion, or the HKMA sandbox's conditions - whichever regime applies? This is no longer a differentiator; it is the entry ticket every regulator examined here now expects (MAS, 2026; EIOPA, 2025; HKMA, 2026).

The economic-proof gate (CFO). Is there a measured, attributable return, or an assumption that efficiency gains exist? Two-thirds of carriers in production today cannot clear this gate, which is precisely why it stops board-level expansion even where the technology itself works (Datos Insights, 2026).

The delivery-accountability gate (Procurement/Engineering). When the system makes a wrong call, who is accountable for the fix, and does the delivery model - in-house, vendor, or blended - have the discipline to build monitoring and lifecycle controls in from day one rather than retrofit them under supervisory pressure? The gap between partnered and internally built success rates in the MIT NANDA data is, in effect, a measurement of how well organisations have historically cleared this gate (MIT NANDA, 2025).

An initiative that clears the architecture and economic gates but not the oversight gate will demo well and then stall the moment risk and compliance are asked to sign off on wider rollout - which is exactly the stage-three-to-four pattern carriers, and their technology partners, keep running into. An initiative that clears oversight but never proves economic return will survive audit and never survive the next budget cycle.

The source[code] Perspective

Across the AI and insurance-technology engagements we support in APAC, the initiatives that make it past a single production use case are rarely the ones with the most sophisticated model.

They are the ones where governance, data lineage and monitoring were treated as delivery requirements from the first sprint plan, not as a compliance addendum bolted on before go-live. That is a delivery-capability question as much as an AI question - it depends on engineering teams who have actually built audit trails and human-in-the-loop controls into production systems before, not only into prototypes.


For organisations evaluating whether to build an AI capability in-house, extend an existing team, or bring in a delivery partner, the honest evaluation criterion is not "can this vendor build the model" - most credible partners can. It is whether they can demonstrate they have taken a governed AI workflow through exactly the kind of regulatory scrutiny MAS, EIOPA and the HKMA are now formalising, on a comparable production system, before.

Conclusion

Insurance's AI story in 2026 is not an adoption story anymore.

73% of carriers have already answered that question. It is a governance-as-infrastructure story: the carriers reaching enterprise scale are the ones that built oversight, explainability and lifecycle controls into the initiative before a regulator, an auditor or a board member asked for them, and the ones stuck in "Hitting Walls" are disproportionately the ones that didn't. The four gates - architecture, oversight, economic proof, and delivery accountability - are a reasonable diagnostic for any carrier or technology leader asking why a specific initiative has stalled between an impressive pilot and an operating system the business actually trusts.

For a CTO, CDO, Head of Claims or Chief Risk Officer weighing the next AI decision, the more useful question in 2026 is no longer "should we adopt AI." It is which of these four gates their current initiative has not yet cleared - and what would need to be true, organisationally rather than technically, for it to.

If your AI initiative has cleared the architecture and economic gates but stalled at oversight or delivery accountability, we're happy to walk through the four-gate framework against your specific programme - no deck required, just the initiative you're stuck on. Talk to us!

Frequently Asked Questions

What is the "pilot-to-production gap" in insurance AI? It describes the pattern where an AI initiative is successfully built and tested but fails to move into full production use or enterprise-wide scale. In 2026, 73% of insurance carriers report running AI in production, but only 7% have scaled it enterprise-wide (Datos Insights, 2026).

Why do most AI programmes stall before reaching enterprise scale? The recurring causes across independent studies are weak workflow integration, thin data foundations, lack of committed business-line ownership, and the absence of governance and human-oversight controls designed in from the start rather than added later (Deloitte, 2025; MIT NANDA, 2025).

What do APAC regulators require for AI governance in insurance? Singapore's MAS Toolkit, Hong Kong's GenA.I. Sandbox++ conditions and Europe's EIOPA opinion converge on the same core requirements: named governance ownership, defined human-oversight points, explainability, and controls applied through the AI system's full lifecycle (MAS, 2026; HKMA, 2026; EIOPA, 2025).

Does stronger AI governance slow down scaling? The available evidence suggests the opposite. Carriers and use cases that built governance and human oversight in from the outset are disproportionately represented among those that reached production and could demonstrate return, while those that treated governance as an afterthought are concentrated in the "stuck" category (Datos Insights, 2026; McKinsey & Company, 2024).

Should insurers build AI capability in-house or bring in a delivery partner? The evidence does not favour one model outright - MIT NANDA found externally partnered AI deployments succeeded roughly twice as often as internal builds attempting comparable tasks, but the deciding factor in both cases was whether the team involved had genuine experience taking a governed AI workflow through to a monitored, audited production system (MIT NANDA, 2025).

Reference List

Accenture (2026) 5 predictions for the insurance industry in 2026. Available at: https://insuranceblog.accenture.com/5-insurance-predictions-2026 (Accessed: 3 September 2026).

Datos Insights (2026) AI Implementations in 2026: From Pilots to Production. Available at: https://datos-insights.com/reports/ai-implementations-in-2026-ins-2026-102370/ (Accessed: 3 September 2026).

Deloitte (2025) Are insurers truly ready to scale gen AI? Available at: https://www.deloitte.com/us/en/insights/industry/financial-services/scaling-gen-ai-insurance.html (Accessed: 3 September 2026).

European Insurance and Occupational Pensions Authority [EIOPA] (2025) EIOPA publishes Opinion on artificial intelligence governance and risk management. Available at: https://www.eiopa.europa.eu/eiopa-publishes-opinion-ai-governance-and-risk-management-2025-08-06_en (Accessed: 3 September 2026).

Hong Kong Monetary Authority [HKMA] (2026) Regulators launch GenA.I. Sandbox++ to foster A.I. innovation across financial services. Available at: https://www.hkma.gov.hk/eng/news-and-media/press-releases/2026/03/20260305-3/ (Accessed: 3 September 2026); cohort details corroborated via OpenGov Asia (2026) Hong Kong Regulators Launch First GenA.I. Sandbox++ Cohort. Available at: https://opengovasia.com/hong-kong-regulators-launch-first-gena-i-sandbox-cohort/ (Accessed: 3 September 2026).

McKinsey & Company (2024) The potential of gen AI in insurance: Six traits of frontrunners. Available at: https://www.mckinsey.com/industries/financial-services/our-insights/insurance-blog/the-potential-of-gen-ai-in-insurance-six-traits-of-frontrunners (Accessed: 3 September 2026).

McKinsey & Company (2026) Can agentic AI (finally) modernize core technologies in insurance? Available at: https://www.mckinsey.com/industries/financial-services/our-insights/can-agentic-ai-finally-modernize-core-technologies-in-insurance (Accessed: 3 September 2026).

Monetary Authority of Singapore [MAS] (2026) MAS Partners Industry to Develop AI Risk Management Toolkit for the Financial Sector. Available at: https://www.mas.gov.sg/news/media-releases/2026/mas-partners-industry-to-develop-ai-risk-management-toolkit-for-the-financial-sector (Accessed: 3 September 2026); requirements corroborated via Rajah & Tann Asia (2026) Best Practices for AI Governance and Risk Management Published for Singapore Financial Sector. Available at: https://www.rajahtannasia.com/viewpoints/best-practices-for-ai-governance-and-risk-management-published-for-singapore-financial-sector/ (Accessed: 3 September 2026).

MIT NANDA (2025) The GenAI Divide: State of AI in Business 2025. Challapally, A., Pease, C., Raskar, R. and Chari, P. Available at: https://cloudelligent.com/wp-content/uploads/2026/02/v0.1_State_of_AI_in_Business_2025_Report.pdf (Accessed: 3 September 2026).

Related articles

25/08/2026

The Scam Liability Shift: How APAC Banks Must Rebuild Payments Defense Under Mandatory Reimbursement

24/08/2026

Responsible AI Governance in APAC BFSI: The Control That Cannot Say No

28/08/2026

Bancassurance 2.0: The Digital Compact Redefining APAC Bank-Insurer Distribution

03/09/2026

Production Without Scale: The Governance Gap Stalling AI in APAC Insurance

31/08/2026

The Digital Identity Trust Layer: Why Verifiable Credentials Are the Next Balance-Sheet Item for APAC BFSI

21/08/2026

AI Claims Readiness Assessment For APAC Insurance

26/08/2026

The Voice AI Inflection: Rebuilding the APAC BFSI Service Layer with Agentic Conversational AI

20/08/2026

The SME Credit Reset: Closing APAC's Financing Divide with AI-Native Underwriting

19/08/2026

We Went Looking for the State of AI in APAC Insurance. This Is Everything That Actually Exists

27/08/2026

The Data-Rich Payment: Turning ISO 20022 From Compliance Deadline Into APAC BFSI Growth Engine

Navigating the Future of Software

linkedin
About usResources
SolutionssBrainChatbotVoicebotVoice RecognitionFace Recognition
Blog and InsightsAI & Blockchain Trends Industry Case Studies Thought Leadership Articles Success Stories & Client Spotlights 
Legal Privacy Policy Terms of Service 
linkedin

Australia - Malaysia - Vietnam

Copyright © 2026 source[code].

Australia - Malaysia - Vietnam