top of page
Wavy Abstract Background

From Stale Reports to Agentic Workflows: Six shifts data governance programs should make in 2026

Writer: Marc Staros
Marc Staros
Jul 31
4 min read

AI is already moving into the core of P&C operations: claims assistants that surface the right endorsement and help adjusters work faster, agents that summarize claim notes and update records, and integration tooling that turns the slowest stages of onboarding an acquired book into machine-proposed work that stewards simply validate.


Every carrier can buy that capability. Only a few will have the governed data, trusted context, and controls required to turn it into a competitive advantage, and that gap is what data governance decides.

Gartner predicts that organizations prioritizing semantics in AI-ready data will increase agentic AI accuracy by up to 80% and reduce costs by up to 60%. Most governance programs, however, were designed to document, review, and remediate data issues on human timescales. To stay relevant, programs must now perform a dual role:


  • Supply trusted context and enforce controls inside AI-enabled workflows


  • Bring speed and scale to traditional governance capabilities


Only then can carrier AI function in a safe, cost-effective manner. Six shifts get programs there, and they build on each other.


1. Govern the business context itself


Catalog coverage, a popular metric among established governance programs, says little about whether an AI system can use the data. AI has to know which source is authoritative for a given purpose, what the grain is, and which joins are valid. The complexity of insurance data makes this task unusually hard. Billing, accounting, and statutory reporting all use premium data, but meaning and rules vary in critical ways.


Enter semantic layer governance: the discipline of managing business definitions, metric logic, and relationship rules so source data can be used consistently across analytics and AI workflows. It turns cataloged context into executable context that AI systems can apply at runtime.


Carriers should treat context as a runtime capability. A catalog can define metrics like "written premium," but a semantic layer applies those definitions at query time, while a policy layer enforces security and masking. Define context once, expose it through governed consumption paths, and enforce it wherever data is queried, retrieved, or used by AI.


2. Decide what agents are allowed to do


Traditional access governance was built around human access to data. Agents introduce a second dimension.


Agent authority should be governed separately from data access. A read-only agent that summarizes claim notes belongs in a different control tier from one that can update records or trigger downstream actions.


Getting there requires agent identity, delegated authority, and tool permissions. But technical controls are only half the battle. Agent governance is cross-functional and still largely uncharted, so carriers should assess whether their data governance programs have the operating model and change-management capability to keep pace.


3. Treat provenance as a risk control


Carriers are about to produce a deluge of AI-generated content. Gartner expects half of organizations to adopt a zero-trust posture toward data by 2028, driven by the spread of unverified AI-generated content.

To maintain order, AI provenance flags are likely to become standard metadata alongside sensitivity, quality, and trust indicators.


At minimum, provenance should show the source of the content, the role AI played in creating it, and whether it has been reviewed or restricted for use. Where stakes justify it, provenance should become an audit trail: what evidence was used, which model-prompt version produced the output, and who approved it.


4. Push governance into pipelines and platforms


Attestations and quarterly reviews were built around human timescales. AI can act across systems around the clock. Forums and stewards can still set standards, but manual review can no longer be the primary enforcement mechanism.


Full policy-as-code can wait. Start by making governance part of delivery. A change in how premium transactions flow from policy administration into billing, finance, and actuarial environments should trigger a lineage analysis, quality checks, and a review of impacted AI workflows.


5. Bring unstructured knowledge into the governance perimeter


Many high-value insurance AI use cases depend on unstructured content that traditional data governance programs have barely touched. AI now retrieves and reasons over that content inside core workflows. The upside is real, but so is the exposure: the same claims assistant that surfaces the right endorsement can just as easily retrieve a superseded handling guide or a privileged litigation memo.

AI-ready governance programs must actively manage unstructured content, not merely classify it for security. The governance model should define approved sources, freshness rules, and privilege filters for AI retrieval.


6. Point AI at the governance program itself


Every shift above creates more work for data governance programs. To keep up, carriers should embrace AI as a tool to scale their program.


Data governance programs have long struggled with stewards assigned on paper without time or authority, lineage breaks from legacy to cloud platforms, and pipelines changing faster than metadata gets reviewed.


AI-powered data governance changes the operating model. The council sets policy, the platform enforces controls, and stewards handle what still requires judgment.


AI can enrich metadata, infer lineage, detect anomalies, monitor quality, and recommend or automate remediation where controls allow.


The leverage shows up fastest where governance work is most repetitive. For a global multiline carrier that grows through acquisition, we helped build a data integration playbook that uses Palantir to automate source-to-target mapping, often one of the slowest, most analyst-intensive stages of onboarding an acquired book. Each integration now starts from machine-proposed mappings that stewards validate, rather than blank spreadsheets they fill.


Where to start


The most useful thing a CDO can do in 2026 is find where AI ambition has outrun governance readiness. Pick your highest-value AI workflows and ask seven questions of each:


  1. Does the AI system have the business context to interpret the data correctly?


  2. Is the authoritative source clear for this specific use?


  3. Can you prove where the data or content came from?


  4. Are action boundaries defined for the agent, beyond access rights?


  5. Are quality, lineage, and usage controls embedded in the workflow itself?


  6. Is the unstructured knowledge it retrieves governed at all?


  7. Is AI reducing the cost and effort required to govern this workflow?


Where the answers get uncomfortable, you have found your governance priorities. That’s where the real AI advantage will be built.


The carriers that pull ahead in 2026 will not be the ones with the most AI pilots. They will be the ones whose adjusters, actuaries, and underwriters can act on AI output without stopping to ask whether the data behind it can be trusted. That confidence is manufactured, and governance is where it gets made.


 
 
 

Recent Posts

See All
Will Your AI Pilot Stall at the Data Layer?

AI-Ready by Architecture, part 1 Premira Mutual is a composite. The carrier is fictional; the problems are real. The demo went great. Premira Mutual, a $1.2 billion regional mutual writing commercial

 
 
 

Comments


Logo

Follow Us On LinkedIn

  • LinkedIn

159 North Sangamon Street

Suite 200

Chicago, IL 60607

(312) 767-2580

iq@premiumiq.com

© 2026 PremiumIQ LLC

bottom of page