The wrong response to increasing AI risk is to stop people using AI.
That does not remove the risk. It often pushes AI use underground, encourages employees to experiment with unapproved tools and leaves the organisation with less visibility over its data, models and third-party dependencies.
APRA’s 2026–27 Corporate Plan sends Boards a more balanced message: embrace the productivity and innovation opportunities presented by AI, but make sure governance, risk management and operational resilience keep pace.
For private health insurers, that message is particularly important.
APRA describes the industry as well capitalised and profitable overall, but facing sustained pressure from an ageing population, rising health claims costs and affordability challenges for policyholders. Its conclusion is direct: insurers will need to rethink established approaches and build new capabilities.
AI can be part of that response—if Boards, executives and risk leaders create the conditions for it to be used confidently and responsibly.
The 30-second take
APRA’s plan should not be read as a reason for insurers to slow down AI adoption.
It should be read as a call to become better at it.
Boards should expect management to demonstrate that:
- AI is connected to business strategy and genuine organisational or member value.
- AI use is aligned with clearly articulated risk appetite and tolerance settings.
- Employees have safe, approved and practical ways to use AI.
- High-risk decisions retain appropriate human judgement and accountability.
- AI-supported critical operations have credible fallback arrangements.
- Third- and fourth-party AI dependencies are understood.
- Cybersecurity, privacy, data, model and operational risks are managed together.
- Reporting covers both the benefits being achieved and the risks being accepted.
This creates an important opportunity for risk leaders. Their role is not to become the organisation’s AI braking system. It is to help design the road, establish the guardrails and make it safer for more people to move forward.
The strategic challenge for insurers
Insurers are trying to manage several competing pressures at once.
Claims costs are increasing. Policyholders are sensitive to further premium increases. Demographic changes affect membership and claims experience. Technology investment is required, but every additional cost ultimately places pressure somewhere else in the system.
AI cannot solve these structural challenges on its own. It can, however, support insurers in areas such as:
- Claims processing and triage.
- Fraud, leakage and anomaly detection.
- Member or customer service and communication.
- Provider and service-pattern analysis.
- Operational forecasting and workforce planning.
- Software development and testing.
- Knowledge management and employee productivity.
- Identification of emerging risks and control weaknesses.
The strategic question for the Board is therefore not, “Should we allow AI?”
AI is already being used—formally or informally—across most organisations.
The better questions are: Where can AI create the most value? What could cause material harm? What conditions must be met before particular use cases proceed? How will we know if AI is operating outside expectations?
APRA expects more from Boards
In its April 2026 industry letter on AI, APRA observed that many Boards were still developing the technical literacy needed to challenge management effectively. It also identified an overreliance on vendor presentations without sufficient examination of unpredictable model behaviour, third-party dependencies and potential impacts on critical operations.
APRA expects Boards to maintain sufficient AI understanding to set strategic direction and provide effective challenge. It also expects them to oversee an AI strategy aligned with risk appetite, supported by effective monitoring, reporting and clear intervention triggers.
That does not mean every director needs to become a data scientist.
It does mean the Board should be able to understand:
- Where AI is being used across the organisation.
- Which use cases could materially affect policyholders or critical operations.
- What data is being used and where it is going.
- How model performance, drift, bias and unexpected behaviour are monitored.
- When human involvement is mandatory.
- Who is accountable when an AI-supported process produces the wrong outcome.
- What happens if a critical AI provider becomes unavailable or changes its service.
- Whether assurance functions have the skills and tools required to test the controls.
AI literacy is increasingly part of effective risk oversight—not a specialist technology topic that can be delegated entirely to management.
Operational resilience must include AI
APRA’s Corporate Plan places operational resilience at the centre of its 2026–27 supervisory agenda.
Insurers should expect CPS 230 implementation to be assessed through evidence, not policies or project-status reporting.
Where AI supports claims processing, member servicing, provider payments, cybersecurity or another critical operation, management should understand how the operation will continue if:
- The AI service becomes unavailable.
- A model update produces unexpected outcomes.
- A supplier materially changes the product.
- Data quality deteriorates.
- A cyber incident compromises the model or its supporting systems.
- The organisation needs to suspend the AI and revert to a manual process.
A fallback process that exists only in a document is not a credible fallback.
It must be practical, adequately resourced and tested under severe but plausible conditions.
Vendor AI is still the insurer’s risk
One of the most important messages in APRA’s plan is its increasing focus on common technology platforms and material service providers.
AI capabilities are now embedded in software, cloud platforms, development tools and customer-service products. An insurer may therefore be using AI without having made a deliberate decision to implement a standalone AI system.
The underlying model, training data or supporting infrastructure may also be provided by fourth parties that are not immediately visible to the insurer.
Risk leaders should help management move beyond a traditional supplier register and understand the complete dependency chain:
- What AI capability does the supplier provide?
- What information does it receive or generate?
- What model or platform sits behind the service?
- Can the supplier change the model without approval or notification?
- What assurance and audit rights exist?
- How are security incidents and material model changes communicated?
- Is the insurer dependent on the same provider across multiple important processes?
- Could the service be substituted or exited within an acceptable period?
Outsourcing the technology does not outsource accountability.
Give employees a safe way to use AI
Employee use of AI is one of the areas where risk leaders can make the greatest positive difference.
A policy that simply tells employees not to enter sensitive information into public AI tools is necessary—but insufficient.
Employees need practical alternatives.
A strong employee AI program could include:
- Approved enterprise AI tools with appropriate security and data protections.
- Simple categories showing which activities are permitted, require review or are prohibited.
- Role-specific examples relevant to claims, finance, risk, actuarial, technology, marketing and member service teams.
- Safe environments for experimentation and development.
- Clear requirements for checking AI-generated work.
- Additional controls for decisions affecting policyholders.
- Easy ways to report unexpected outputs, data concerns or potential incidents.
- AI champions who can support teams and share better practices.
- Training focused on practical use, limitations and accountability—not merely policy acknowledgement.
- A process through which promising employee ideas can become governed organisational use cases.
If employees understand the boundaries and have useful approved tools, they are more likely to experiment safely and share what they learn.
That gives the organisation greater visibility and creates a stronger foundation for innovation.
The opportunity for risk leaders
Risk leaders should not be positioned as the final approval point for every AI activity.
That model is not about effective business performance, will quickly become a bottleneck and may cause the organisation to route around the risk function.
Instead, risk leaders must help build a scalable system of permission and accountability.
This means:
- Creating clear risk tiers.
Low-risk productivity uses should move quickly. Uses affecting policyholders, health information, critical operations or regulated decisions should receive deeper assessment. - Embedding controls into delivery.
Privacy, security, legal, data, model and operational-resilience requirements should be incorporated into design and procurement—not applied shortly before launch. - Connecting AI to existing frameworks.
AI should be integrated into risk appetite, CPS 220, CPS 230, CPS 234, change management, third-party risk and assurance processes. - Enabling informed experimentation.
Teams should be able to test ideas within controlled environments without navigating an approval process designed for full production deployment. - Measuring value and risk together.
Board and executive reporting should show productivity, service and member benefits alongside incidents, overrides, control failures, supplier concentration and emerging exposures. - Building continuous assurance.
AI models can change, drift or behave differently as their environment changes. Point-in-time approval is not enough. Monitoring and assurance must continue throughout the lifecycle.
Questions the Board should ask now
- Where is AI already being used, including through suppliers and embedded software?
- Which AI opportunities could materially improve affordability, productivity or member experience?
- Are employees being given approved and useful alternatives to public AI tools?
- Which AI-supported activities could affect policyholders or critical operations?
- Are our risk appetite, governance and reporting keeping pace with actual adoption?
- Could we maintain critical services if a major AI or technology provider failed?
- Do management, risk and internal audit have the capability to assess AI effectively?
- Are we measuring the benefits of AI as rigorously as we measure its risks?
Governance should create confidence to act
APRA is not asking Boards to eliminate AI risk.
It is asking them to make sure governance, risk management, assurance and operational resilience develop at the same speed as adoption.
For private health insurers facing claims-cost and affordability pressures, choosing not to engage with AI may itself become a strategic risk.
The organisations that respond best will not be those with the longest AI policies or the most approval committees. They will be those that establish clear boundaries, empower employees, understand their dependencies and create sufficient confidence for responsible innovation to move at pace.
That is where risk leaders can make their greatest contribution.
Not by standing between the organisation and AI—but by helping the organisation use AI well.
Read APRA’s 2026–27 Corporate Plan
Read APRA’s industry letter on AI
For more practical insights on governance, operational resilience and emerging risk, visit the Innovation of Risk Reading Room.

