|
|
|
Ayush Soni, MBA Candidate, and Elected Trustee at University of Sheffield, and University of Sheffield Students’ Union – Written Evidence (CIM0008)
AI Declaration: Large language models were used as drafting and editorial aids in the preparation of this submission. All arguments, evidence selection, analysis, conclusions, and recommendations are the sole responsibility of the submitter and reflect the submitter's independent research and judgment. The submitter takes full responsibility for the accuracy of all content.
Responding to Questions 2, 3(b), 4, 4(a), 5, 6, 7, 8, and 8(a)
Ayush Soni, MBA Candidate (University of Sheffield Management School 2025–26);
Elected Trustee, University of Sheffield Students' Union;
Former Compliance Consultant, Sykam Consultancy Services (digital asset regulatory compliance)
Submitted in a personal capacity
June 2026
1.1 The consumer insurance market faces a structural regulatory mismatch. The FCA's framework, anchored in the Consumer Duty (2023) and the Senior Managers and Certification Regime (SM&CR), was designed for a market in which human intermediaries make consequential decisions about pricing, underwriting, and claims. That market is being replaced by one in which algorithmic systems make those same decisions, often opaquely and at scale.
1.2 The Bank of England and FCA's joint 2024 survey of AI in UK financial services found that 95% of insurance firms are already using AI, the highest adoption rate of any financial services sector surveyed[1]. Yet the regulatory framework has not materially evolved since Consumer Duty came into force.
1.3 The EU AI Act, which originally set 2 August 2026 as the compliance date for Annex III high-risk AI systems, has had that deadline deferred to 2 December 2027 following the Digital Omnibus political agreement of 7 May 2026[7]. Annex III explicitly classifies AI used in insurance risk assessment and pricing as high-risk, imposing mandatory conformity assessments, bias testing, explainability obligations, and human oversight requirements[6]. The UK has no equivalent classification, creating a regulatory divergence that simultaneously weakens consumer protection and creates conflicting governance obligations for UK insurers operating cross-border[3].
1.4 This submission identifies three structural gaps in the current framework and makes five specific, implementable recommendations. It draws directly on the official transcripts of evidence presented to this Committee on 10 June 2026, published on parliament.uk on 15 June 2026, and on data from Insurance Datalab, Which?, and primary FCA sources [9][10][8][1][2][3][4][5].
1.5 This submission is structured to address the following questions from the Committee's Call for Evidence directly:
Questions 1, 3(a), and 5(b)–(c) concern the general consumer experience of home and travel insurance, the specific operation of insurance distribution, and the mechanics of cash settlements and outsourced claims handling. The submitter does not have direct professional experience in these areas and does not address them, in order to avoid diluting the evidence where genuine expertise exists.
Summary of recommendations:
2.1 On 10 June 2026, this Committee heard evidence from Matt Scott, Co-Founder and Chief Product Officer at Insurance Datalab, and Matthew Brewis, KPMG Partner and former FCA Director of Insurance[9][10]. The official transcripts of both sessions were published on parliament.uk on 15 June 2026 and form a primary evidential basis for this submission[9][10].
2.2 Drawing on Insurance Datalab's analysis, Scott told the Committee that buildings insurance claims acceptance rates have fallen by nine percentage points since Consumer Duty came into force in 2023, with provider-level acceptance rates ranging from 45% to 85%[9]. Combined buildings and contents policies have fallen six percentage points over the same period[9]. Scott noted the equivalent figure in motor insurance, a market subject to more intensive supervisory scrutiny, stands at approximately 99%[9].
2.3 Scott told the Committee that enforcement, not regulation, was the primary problem: the regulatory framework was looking at the right things, but enforcement had not kept pace with the evidence of harm[9]. Brewis confirmed that customer understanding was one of the main issues identified during the FCA's review of the home insurance market[10].
2.4 This submission accepts that framing and advances a sharper version of it: the enforcement gap is structural, not merely cultural. The FCA cannot enforce what it cannot see. When AI systems make pricing, underwriting, and claims decisions inside opaque models, the current regulatory framework provides the FCA with no mechanism to audit the decision logic, test for bias, or attribute outcomes to accountable individuals with sufficient precision to support enforcement action. The 9-point fall in buildings' insurance claims acceptance since Consumer Duty came into force is not evidence that the framework has failed; it is evidence that the framework cannot yet see the problem clearly enough to fix it. This is why enforcement has not kept pace, not because the FCA lacks will, but because the current framework provides no mechanism for it to audit algorithmic decision logic. The recommendations in this submission are designed to give the FCA the visibility it needs to enforce the rules that already exist.
3.1 The Bank of England and FCA's Artificial Intelligence in UK Financial Services 2024 survey, published in November 2024, found that 75% of UK financial services firms are already using AI, with a further 10% planning adoption within three years, up from 58% in the 2022 survey [1]. The insurance sector reported the highest adoption rate of any sub-sector at 95% [1].
3.2 The same survey found that 55% of all AI use cases across financial services involve some degree of automated decision-making [1]. Critically, 46% of firms reported having only "partial understanding" of the AI systems they deploy, a figure that rises where models are sourced from third parties, which now account for one third of all AI use cases across the sector [1].
3.3 This is the regulatory context in which buildings insurance claims acceptance rates have fallen nine percentage points since Consumer Duty came into force [1][9]. Consequential consumer decisions, whether a claim is accepted, at what settlement value, under what policy terms, are increasingly made by systems that their own operators do not fully understand [1]. Consumer Duty requires firms to monitor outcomes. It does not require firms to understand, audit, or explain the algorithmic systems producing those outcomes. That gap is where the consumer harm is occurring.
4.1 The Consumer Duty represents a genuine regulatory improvement and this submission does not argue that it has failed. It argues that Consumer Duty was designed for a market that is already being superseded by algorithmic systems, and that three specific structural gaps have emerged as a result.
4.2 Gap 1: Outcome monitoring cannot detect proxy discrimination. Consumer Duty requires firms to monitor outcomes and evidence fair value and good consumer experience. But outcome monitoring is only as effective as a firm's ability to trace poor outcomes back to their causes. When a pricing algorithm produces discriminatory results, charging higher premiums to consumers in certain postcodes because postcode data operates as a proxy for protected characteristics, the outcome may be visible in aggregate data, but its cause inside the model is not. The FCA's own AI Update (2024) acknowledges this risk at paragraph 3.26, stating that "firms using AI technologies in a way that embeds or amplifies bias, leading to worse outcomes for some groups of consumers, might not be acting in good faith for their consumers, unless differences in outcome can be justified objectively[2]." Acknowledging the risk is not the same as providing a regulatory mechanism to detect and remedy it.
4.3 Gap 2: No explainability requirement for AI-driven consumer decisions. Consumer Duty's cross-cutting obligation to act in good faith requires firms to communicate in ways that enable consumers to make properly informed decisions. When a claim is declined and that decision was produced by an algorithmic system, Consumer Duty requires clear communication, but does not require the firm to explain the logic of the underlying model. The FCA's own AI Update is explicit at paragraph 3.35: "our regulatory framework does not specifically address the transparency or explainability of AI systems[2]." This is a gap Consumer Duty does not fill.
4.4 Gap 3: Product governance cannot address dynamic model drift. Consumer Duty requires firms to ensure products deliver fair value, with periodic governance reviews. Machine learning models update continuously as they are trained on new data. A model validated as fair at the point of a product governance review may have drifted materially by the time of the next review, producing systematically different outcomes for certain consumer groups without any intentional change in firm behaviour. Consumer Duty's product governance requirements do not address this dynamic characteristic of AI systems, and the FCA has issued no guidance filling this gap in the insurance context.
5.1 The EU AI Act entered into force on 1 August 2024[6]. Annex III explicitly classifies AI systems used for risk assessment and pricing in relation to natural persons in the case of life and health insurance as high-risk AI[6]. For high-risk systems, the Act mandates conformity assessments before deployment, ongoing bias testing, technical documentation, transparency and explainability obligations, human oversight mechanisms, and registration in a public EU AI database[6]. Following the Digital Omnibus political agreement of 7 May 2026, the compliance deadline for standalone Annex III systems has been deferred from 2 August 2026 to 2 December 2027[7]. The policy architecture, risk classification, conformity assessments, mandatory auditability, is unchanged; only the deadline has moved[7].
5.2 The UK has no equivalent classification for insurance AI[3]. The FCA confirmed on its AI approach page (last updated February 2026) that it does not plan to introduce AI-specific rules, stating its approach "remains technology-neutral, principles-based, and outcomes-focused" and will rely on existing frameworks including Consumer Duty and SM&CR[3].
5.3 This divergence has two consequences the Committee should consider together. First, it creates a consumer protection gap: UK consumers purchasing home and travel insurance may be subject to AI pricing and underwriting decisions that would require mandatory auditability, bias testing, and documented human oversight if the same system were deployed for EU customers, but face none of those requirements under UK regulation. Second, it creates a compliance burden for UK insurers operating across both jurisdictions, who must meet EU AI Act high-risk system obligations for EU operations while operating under a wholly different governance framework in the UK. The absence of a UK position on AI risk classification in insurance is not a neutral stance, it is a policy choice with material consequences for consumer protection and market competitiveness.
5.4 This submission does not argue the UK should replicate the EU AI Act. The principles-based approach has genuine advantages in a fast-moving environment. It argues that the FCA should explicitly assess whether a risk-based classification approach, identifying the AI use cases in insurance that carry the highest potential for consumer harm and attaching specific governance requirements to those use cases, would better serve consumers than the current uniform application of Consumer Duty to all AI use cases regardless of potential impact.
6.1 The FCA's SYSC 4.1.1R requires firms to have "robust governance arrangements, which include a clear organisational structure with well defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor and report the risks it is or might be exposed to, and internal control mechanisms, including sound administrative and accounting procedures and effective control and safeguard arrangements for information processing systems[5]." Under SM&CR, accountability for technology systems in insurance firms typically rests with SMF24 (Chief Operations) and SMF4 (Chief Risk)[5]. The FCA's AI Update confirmed at paragraph 3.40 that "any use of AI in relation to an activity, business area, or management function of a firm would fall within the scope of a SMF manager's responsibilities[2]."
6.2 This submission challenges the adequacy of that position in the specific context of consumer insurance decisions made by outsourced AI systems. SM&CR was designed to create clear accountability for human decision-making. When an underwriter declines a claim, a human chain of oversight can in principle be traced to a responsible individual. When an outsourced algorithm makes the same decision, accountability under SM&CR attaches to a Senior Manager who may have approved deployment of the vendor model, but who did not, and could not, approve the specific decision. Scott's evidence to the Committee on 10 June 2026 referenced the FCA's July 2025 review of outsourced claims handling, which identified concerns around claims outcomes[9]. The question this Committee should put to the FCA is: in the context of AI-driven claims decisions, who is concretely accountable, and what evidence does the FCA have that named individuals understand the systems for which they are responsible?
6.3 The Bank of England and FCA's own 2024 survey found that 46% of firms have only "partial understanding" of the AI systems they use, with accountability typically split across three or more individuals or bodies[1]. SYSC 4.1.1R requires "well defined, transparent and consistent lines of responsibility[5]." That standard is not being met when nearly half of firms operating these systems cannot fully account for how they work. To remedy this, firms should be required to document in Senior Managers' Statements of Responsibilities which named individual holds oversight of each AI system making consumer-facing decisions, and to maintain records demonstrating that this individual has sufficient technical understanding to discharge that responsibility meaningfully.
7.1 The Committee's inquiry rightly considers the role of Price Comparison Websites (Q3b). For many consumers, PCWs are the primary point of comparison for home and travel insurance. While PCWs have increased market transparency on price, they do not meaningfully aid consumer understanding of policy terms, exclusions, or the quality of claims service, the factors that matter most at the moment of claim. Scott told this Committee that the industry's drive to make the quote process "quicker and easier" has come at the expense of consumer understanding: customers frequently discover exclusions, limitations, and policy conditions only when they attempt to make a claim[9].
7.2 Algorithmic personalisation presents a foreseeable and significant risk to the PCW model. While the full effects are not yet observable in aggregate data, the trajectory is clear: when AI underwriting generates bespoke policy terms for individual consumers, varying excesses, exclusions, and coverage limits in real time based on behavioural and demographic data, the ability to make a meaningful comparison on a price-focused platform will collapse. Consumers comparing algorithmically customised products on a PCW will be comparing products that are not, in any meaningful sense, comparable. This is an emerging risk requiring pre-emptive regulatory attention.
7.3 The challenges of algorithmic opacity are most acute for vulnerable consumers (Q4 and Q4a). Where AI pricing models use data inputs that correlate with vulnerability characteristics, such as postcode, device type, or browsing patterns, the risk of systematic exclusion or overpricing is significant and may be entirely invisible to the consumer. The FCA's own 2026 Insurance Regulatory Priorities Report identifies improving access for vulnerable groups, including renters and travellers with pre-existing medical conditions as a priority[4]. Similarly, Which? has documented cases of consumers with pre-existing medical conditions being denied travel insurance by algorithmic underwriting systems that cannot explain their decisions, leaving consumers unable to challenge or understand why they have been excluded from the market[8]. Without requirements to test AI models specifically for differential impact on these groups not merely monitor aggregate outcomes, this aspiration cannot be consistently delivered.
8.1 Which?'s analysis of over 8,500 final FOS complaint decisions about home, travel, motor, and pet insurance, published in June 2024, found that the FOS cited distress and inconvenience to consumers 1,321 times in 2023, appearing in 64% of upheld complaints, up from 53% in 2019[8]. The FOS found that insurers caused unfair delays in 800 complaints that year, both the highest number and highest proportion since 2019[8]. Which? used artificial intelligence to analyse the text of those 8,500 decisions, identifying patterns in the Ombudsman's reasoning, an approach that itself illustrates how AI tools, applied with transparency and methodological rigour, can expose systemic consumer harm that aggregate data alone would not reveal[8].
8.2 Brewis told this Committee that customer understanding was one of the main issues identified in the FCA's home insurance review[10]. Scott noted that consumers often discover exclusions only when attempting to claim[9]. A policy with terms generated by an algorithm and differing materially from the standard market product worsens this problem, and a consumer who cannot understand what they purchased cannot meaningfully challenge an adverse decision.
8.3 For the FOS, the consequence is structural (Q7). The FOS resolves disputes based on what is fair and reasonable in the circumstances. When the decision under dispute was made by an algorithmic system whose logic the firm cannot or will not explain, the FOS is materially disadvantaged in assessing fairness. As AI-driven claims handling scales, the FOS will have progressively less information with which to assess the fairness of decisions, unless the regulatory framework requires firms to maintain and disclose decision logic.
9.1 The FCA has stated it will not introduce AI-specific rules, preferring to rely on existing frameworks[3]. This submission does not argue that the FCA should abandon its principles-based approach. It argues that the FCA should interpret and apply its existing principles to the specific governance challenges posed by AI through targeted guidance, not new legislation. Every recommendation in this submission is achievable within the existing legislative framework.
9.2 A second counterargument is that algorithmic audits would impose disproportionate costs, particularly on smaller firms. This submission recommends a tiered, proportionate approach: the most demanding requirements should apply only to the highest-risk systems, those that make autonomous decisions about coverage, pricing, or claim acceptance. AI used in customer service or fraud detection that does not make final consumer decisions should face lighter-touch requirements.
9.3 A third counterargument is that the EU AI Act's deferral to December 2027 suggests even the EU is struggling to implement high-risk AI requirements[7]. This submission notes that the deferral reflects the time needed to finalise harmonised technical standards, not a retreat from the underlying policy of risk-based classification. The architecture, conformity assessments, bias testing, mandatory auditability, is unchanged. The UK has an opportunity to learn from the EU's implementation experience and design a more agile, proportionate framework. But only if it begins that process now[7].
9.4 A fourth counterargument, the FCA's most frequently cited defence, is that its rules are "technology-neutral" and therefore already apply to AI[3]. This argument is superficially attractive but fundamentally flawed. A rule that is technology-neutral is not a rule that is technology-effective. The principle that firms must act to deliver good outcomes for retail customers does not automatically translate into a mechanism for auditing a black-box pricing algorithm or for holding a Senior Manager accountable for a model they only "partially understand." As the evidence in this submission demonstrates, applying these principles to the specific governance challenges of AI requires explicit guidance. Technology neutrality, in this context, is not a safeguard, it is a governance gap dressed as one.
10.0 The following recommendations are underpinned by a clear principle of proportionality. The regulatory burden should be commensurate with the potential for consumer harm. The most demanding requirements, pre-deployment conformity assessments, annual bias testing, and third-party validation, should apply only to the highest-risk systems: those that make autonomous or semi-autonomous decisions about coverage, pricing, or claim acceptance. Lower-risk applications, such as customer service chatbots or fraud detection systems that flag cases for human review rather than making final decisions, should face lighter-touch requirements such as basic documentation and annual reporting. This tiered approach ensures consumer protection is enhanced without imposing disproportionate costs, particularly on smaller firms.
10.1 Recommendation 1: Mandatory tiered algorithmic audit requirements.
The FCA should introduce a tiered algorithmic audit requirement for AI systems used in consumer insurance pricing, underwriting, and claims handling. The highest-risk systems should be subject to: pre-deployment conformity assessments; annual bias testing against protected characteristics and vulnerability indicators, with results reported to the FCA; mandatory audit log retention for a minimum of seven years including training data sources, model versions, and all material consumer decisions; and third-party validation where systems have been shown to produce materially different outcomes for different consumer groups.
10.2 Recommendation 2: SM&CR guidance for automated consumer decisions.
The FCA should publish explicit guidance on how SM&CR accountability applies when automated systems make consumer-facing insurance decisions. This guidance should require firms to document, in Senior Managers' Statements of Responsibilities, which named individual has oversight of each AI system that makes consumer-facing decisions; maintain a decision log for each material consumer decision recording the model version, key inputs, and output; and ensure Senior Managers have sufficient technical understanding of the systems they oversee, with any gap documented as a risk.
10.3 Recommendation 3: UK-EU AI regulatory alignment assessment.
The Committee should recommend that the FCA undertake and publish a comparative assessment of the EU AI Act's Annex III risk classification approach and its applicability to the UK consumer insurance market, specifically assessing whether the UK's current principles-based approach provides equivalent consumer protection to the EU's risk-based classification, and whether UK insurers operating in both jurisdictions face conflicting or duplicative obligations.
10.4 Recommendation 4: Dynamic model governance under Consumer Duty. Consumer Duty product governance requirements should be updated to require firms to assess and evidence the ongoing fairness of AI systems that update continuously implementing fairness drift monitoring, regular testing to ensure models fair at deployment remain fair as they learn from new data, and reporting material model changes to the FCA within a specified timeframe with a documented consumer impact assessment.
10.5 Recommendation 5: FOS AI dispute capability.
The FCA and FOS should jointly develop guidance on how the FOS will approach disputes involving AI-driven decisions, establishing that proprietary or commercially sensitive AI logic cannot be used as a basis for refusing to explain a decision to the FOS, and clarifying the evidential burden on firms to explain automated decisions in FOS proceedings.
[1] Bank of England and Financial Conduct Authority, Artificial Intelligence in UK Financial Services 2024, November 2024. Available at: https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024
[2] Financial Conduct Authority, AI Update: How Our Rules Apply to AI in Financial Services (2024). Available at: https://www.fca.org.uk/publication/corporate/ai-update.pdf
[3] Financial Conduct Authority, AI and the FCA: Our Approach, last updated 13 February 2026. Available at: https://www.fca.org.uk/firms/innovation/ai-approach
[4] Financial Conduct Authority, Regulatory Priorities Report: Insurance, February 2026. Available at: https://www.fca.org.uk/publication/regulatory-priorities/insurance-report.pdf
[5] Financial Conduct Authority, FCA Handbook: SYSC 4.1.1R, Senior Management Arrangements, Systems and Controls. Available at: https://www.handbook.fca.org.uk/handbook/SYSC/4/1.html
[6] European Union, Regulation (EU) 2024/1689 (the EU AI Act), Annex III. Available at: https://artificialintelligenceact.eu/annex/3/
[7] European Commission, Digital Omnibus on AI — Political Agreement, 7 May 2026; confirmed by Gibson Dunn analysis. Available at: https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
[8] Which?, Complaint Upheld: Delay, Distress and Inconvenience Caused by Insurers, June 2024. Available at: https://www.which.co.uk/policy-and-insight/article/complaint-upheld-delay-distress-and-inconvenience-caused-by-insurers-a0tIy1M7GqFs
[9] House of Lords Financial Services Regulation Committee, Oral Evidence: Matt Scott (Insurance Datalab), 10 June 2026, published 15 June 2026. Available at: https://committees.parliament.uk/oralevidence/17729/html/
[10] House of Lords Financial Services Regulation Committee, Oral Evidence: Matthew Brewis (KPMG), 10 June 2026, published 15 June 2026. Available at: https://committees.parliament.uk/oralevidence/17730/html/
22 June 2026
|
|
|