What IRDAI Actually Set Up on 19 June 2026
On 19 June 2026 the Insurance Regulatory and Development Authority of India constituted a seven-member working group on artificial intelligence, chaired by Sandeep K. Shukla, director of IIIT Hyderabad, with IRDAI general manager and chief information security officer Deepak Gaikwad as member convener. The group was given a three-month deadline, which puts its report in the Authority's hands around September 2026. Business Standard reported the formation on 18 June under the heading "Irdai sets up working group to guide AI adoption in insurance sector", and Insurance Business Asia carried the composition and terms of reference on 23 June.
Two things about that setup matter to a commercial buyer. The first is who is chairing it. An academic computer scientist and the Authority's own CISO is a technical pairing, not a market-conduct pairing, which suggests the output will be framed around model behaviour, controls and auditability rather than around fresh policyholder entitlements. The second is the clock. Three months is short for a subject this wide, and short timelines tend to produce a framework document that insurers then have to operationalise over the following year. The gap between the report landing and any of it binding an insurer's claims department is where this renewal cycle sits.
That gap is the argument of this piece. A commercial policyholder placing or renewing cover between now and the first supervisory instrument does not have to wait for IRDAI to define what an explainable AI claim decision looks like. The questions are answerable today, and the answers belong in the placing file.
The Terms of Reference Point Straight at Claims
The working group's brief is not a general study of AI in insurance. Its terms of reference, as reported, include:
- Proposing a framework for ethical, transparent and explainable AI use, with focus on claims processing and fraud detection.
- Developing an audit framework covering both pre-deployment and post-deployment requirements.
- Prescribing security controls against AI-driven automated attacks.
- Examining whether sector-wide stress tests are needed for AI-related failure exposure.
Read that list from a buyer's chair. The named use cases are the two where a model output can cost a policyholder money directly: the decision on a claim, and the decision to treat a claim as suspicious. The audit framework is split across the model's life, which means the regulator is thinking about evidence that exists before a model goes live (validation, documentation, testing) and evidence generated while it runs (logs, overrides, drift). The stress-test question treats AI failure as a systemic exposure, in the same register as a capital or cyber event.
None of this sits in a vacuum. The MeitY India AI Governance Guidelines, released on 5 November 2025, set India's approach as sectoral: individual regulators frame AI rules for their own sectors rather than an omnibus statute doing it centrally. That is exactly what IRDAI is now doing for insurance, and the wider architecture of that choice explains why the insurance-specific instrument matters so much. There is no parallel horizontal AI law to fall back on if the sectoral rules land narrow.
Ask Which Decisions in Your Programme Are Model-Assisted
Start with a map, not a principle. For each line in your programme, ask the insurer to state in writing which decision points involve a model, and what the model does at each one. The useful granularity is decision-level, because "we use AI in claims" is not an answer you can act on.
The decision points worth naming explicitly:
- Intimation triage. Is the first routing of a commercial claim (fast-track, standard, investigate) produced or ranked by a model?
- Fraud and anomaly scoring. Does a score attach to the claim file, does it have thresholds, and does crossing a threshold change who handles the file or how long it takes?
- Surveyor and investigator allocation. Is the choice of surveyor or the decision to appoint an investigator model-driven?
- Document and evidence assessment. Are loss documents, invoices or repair estimates read by an extraction or vision model whose output feeds the adjuster's assessment?
- Reserving and settlement recommendation. Does a model suggest a reserve or a settlement band that the adjuster then works from?
- Underwriting and renewal terms. Are loadings, deductible changes or declinature at renewal informed by a model reading your loss history?
The last one matters more than buyers usually credit. A fraud score generated on a claim in year one can travel into the renewal decision in year two, and the explainability expectations now attaching to AI underwriting are the reason to ask whether claim-side model outputs are used as underwriting inputs at all.
Ask the same question of the intermediary chain. TPAs, investigation agencies and claims platforms deploy their own tooling. An insurer that answers honestly about its own stack may still not know what its vendor's triage engine does, which is itself information worth having on the record.
Ask Where the Human-in-the-Loop Sits, and Whether It Is Real
Every insurer will tell you a human makes the final call. The follow-up questions separate a genuine control from a signature at the bottom of a model output.
- At which score or flag does a human review become mandatory, and who is that human? A named role and grade, not "the claims team".
- Can that person override the model, and what is required to do so? If an override needs approvals the adjuster rarely gets, the override path exists on paper only.
- How often is the model overridden in practice? An override rate near zero on a portfolio of commercial claims either means the model is unusually good or means nobody is really reviewing. Ask for the number.
- Does the reviewer see the reasons, or only the output? A reviewer shown a score with no drivers cannot meaningfully disagree with it.
- What is the escalation path when the insured disputes a model-influenced position? Name the desk, the turnaround, and the point at which it leaves the claims team.
For a claim of any size, the practical control is a pre-agreed escalation trigger: an undertaking that where a model-generated flag materially affects the handling of a claim above an agreed threshold, the file is reviewed by a named senior authority before any communication of repudiation or reduction. That is a commercially ordinary ask. It costs the insurer nothing when the model is right.
Ask What Evidence You Get if an AI-Flagged Claim Is Repudiated
This is the question that most needs asking before the loss rather than after it. If a commercial claim is declined or reduced and a model influenced that outcome, what will the insurer produce, and to whom?
A workable evidence ask has four parts:
- Disclosure that a model was involved. A simple statement in the repudiation letter that automated or model-assisted analysis contributed to the assessment, and at which stage.
- The reasons in business language. Not model weights or code. The factors that drove the flag, stated so that your risk manager can check them against the facts: the mismatch the system found, the documents it compared, the pattern it matched against.
- The human record. Who reviewed the output, when, what they were shown, and whether they varied it. This is precisely the post-deployment evidence the working group's audit framework is meant to make routine, so asking for it now is asking for something the insurer will likely need to hold anyway.
- A correction route. Where a flag rests on a factual error (wrong entity matched, wrong prior claim linked, a document misread by an extraction model), a defined process for putting the corrected fact back into the file and getting the assessment redone.
The fourth is the one buyers forget. Extraction and matching errors on commercial claim files are ordinary. Invoices are misread, group entities are confused with each other, a prior claim from an unrelated company with a similar name is attached to your history. If there is no mechanism to correct the input, the model's output stands on a fact that was never true, and the argument you end up having is about the claim rather than about the error.
Also ask what the insurer will disclose if the model's output is the subject of a dispute later. An insurer that commits at placement to produce its decision record on request has given you something concrete. An insurer that says the model is proprietary and its outputs are internal has also told you something, and that answer belongs in your placement comparison.
The Limit: Repudiation Still Runs Through the Wording
Now the counterweight, because the buyer-side case here can be overstated. An AI model does not repudiate a claim. An insurer does, and it does so under the terms of the contract you bought.
A repudiation has to rest on a ground the policy wording supports: an exclusion, a breach of condition, a warranty failure, non-disclosure, or a finding that the loss falls outside the insuring clause. A model flag is not a ground. It is a reason the insurer looked harder. If the insurer cannot point to the clause, the presence or absence of a model in the file is beside the point, and if it can point to the clause, an explainability argument does not cure a genuine coverage failure. The first question on any declined commercial claim remains the same one it was before any of this: which words in the contract are being relied on, and do the facts fit them.
The same discipline applies to the redress route. A commercial policyholder disputing a repudiation works through the insurer's grievance redressal officer, then the Authority's grievance machinery, then whatever contractual dispute mechanism the wording provides, and then the courts. The IRDAI working group is not building a new forum, and its report will not create a right of appeal against a model. What it can realistically do is make the insurer's internal evidence better organised and more producible, which helps you inside the forums that already exist.
Where explainability actually earns its keep is at the margin: a repudiation that is arguable on the wording, where the insurer's file shows the position was substantially set by a model flag that nobody senior interrogated. That is a weaker case for the insurer than one built by an adjuster on documents, and it is a case worth pressing.
So the ask is not "give me the algorithm". It is: tell me where models sit, who checks them, and what you will show me. Those are answerable now, they do not depend on the report, and they improve your position whatever the report says.
What to Do at This Renewal
A practical sequence for a risk manager or broker working a programme between now and the framework landing.
Before the renewal meeting
- Ask each incumbent and each quoting insurer, in the submission questionnaire, to identify model-assisted decision points across claims, fraud detection and renewal underwriting.
- Ask whether third parties in the chain (TPAs, investigators, claims platforms) deploy their own models, and whether the insurer has visibility of them.
- Ask for the human-review threshold, the override authority, and the escalation path for disputed model-influenced positions.
At placement
- Record the answers in the claims service standard or slip annexure rather than in correspondence.
- Negotiate a senior-review trigger for material claims where a model flag affects handling.
- Agree what the insurer will disclose on request when a model-assisted assessment leads to repudiation or reduction, and agree a correction route for factual errors in model inputs.
Two habits are worth keeping through the year.
- Log every instance where a claim is delayed or reduced with an unexplained "system flag" or "verification" step. Patterns across a programme are more persuasive at renewal than a single grievance.
- Track the working group's output when it publishes, and reopen the questions the framework makes newly answerable.
The wider point is that AI governance in your insurance programme is a wordings and service-standards exercise, in the same family as the governance work insurers and brokers are already being asked to build and the triage models already running on commercial claims. Treated that way, it fits into a renewal without waiting for a circular. Treated as a compliance topic for someone else, it arrives as a surprise on the first claim that is declined with a reason nobody can explain.