PART 2

Artificial Intelligence: Bridging the oversight gap between carriers and MGAs

AI tools are already used across insurance for submission intake, document review, underwriting support, claims triage, fraud screening, and administrative work. MGAs matter because they use those tools within delegated authority arrangements. The carrier or Lloyd’s managing agent retains the balance sheet and ultimate risk, but the MGA may control underwriting, administration and sometimes claims. The issue is therefore not only whether AI improves efficiency, but also whether the carrier and the MGA can still identify, supervise, and explain the decisions being made within the delegated arrangement. 

But does AI improve MGA efficiency at the cost of visibility and control? And can AI widen access to niche risks, or make exclusion more efficient, supercharging MGAs’ ability to filter risks more quickly? 

1. Why MGAs are structurally different

MGAs don’t fit neatly into the category of insurer or broker. They typically combine delegated underwriting authority, specialist market knowledge, operational execution, distribution relationships and product input. 

They can focus on a narrow class of risk, build real underwriting expertise in it, and develop processes around it. That might mean a specific industry, an emerging risk, a particular distribution channel, or a part of the market that’s too small or too operationally awkward for a large carrier to handle directly. 

This means the carrier doesn’t make every operational decision itself, and the MGA doesn’t bear the underlying insurance risk itself. Once AI is added, the practical question is who is making the decision, how that decision is made, and who can intervene if something goes wrong. 

2. AI changes: What’s really being delegated?

Historically, what a carrier delegated to an MGA was easier to describe. It delegated underwriting authority, certain administrative functions, sometimes claims functions, and the operation of a specialist book of business. The working assumption was still that judgment sat mainly with underwriters, handlers, and operational teams acting within agreed limits. 

AI can make that less clear. An MGA may still present as a specialist underwriting business, but its day-to-day decisions may depend increasingly on tools that shape outcomes before a human underwriter or claims handler steps in – especially when everyone is promising the efficiency and productivity gains that can be had from AI tools. Those tools may include submission triage, scoring, external data enrichment, document summarization, fraud indicators, prompt-based drafting, workflow routing and portfolio analytics. Some of this may be configured internally, but it’s most likely to come from third-party vendors developing specific insurtech tools. 

This raises the question of who (or what) the underwriter is delegating to: specialist teams at an MGA with deep expertise in an MGA’s market segment, or a thin-on-the-ground team using AI tools for many of their decisions?

The carrier may therefore be relying on the MGA’s AI decision systems. If that’s the case, can the carrier be confident that those AI system are sufficiently capable of being accountable for the decisions they’re making? 

To be clear, this predominantly rhetorical question isn’t intended to knock the use of AI. It's already unrealistic for any company to suggest that it can’t or won’t use AI in its business processes, but the potential concern comes where appropriate governance isn’t keeping in check the elements that should remain within the accountability of human experts.   

In our AI practice, advising clients on their use and deployment of AI systems, we see these questions every day: 

  • Who approved the tool?
  • Who tested it before deployment?
  • Who understands when it shouldn’t be used?
  • Who monitors whether its outputs change over time?
  • Who investigates whether poor outcomes come from the model, the data, the prompt design or the workflow around it?
  • Who can explain later why a decision was reached?  

Those questions were easier to answer in a more traditional IT stack; although certain tasks can be automated and improved, most decisions had to stay with humans. In the context of the tasks performed by MGAs, AI doesn’t remove the fact that, at a regulatory level, a human person will be responsible for decisions along the process – but it makes them harder to determine, because the output may reflect a combination of vendor design, data inputs, thresholds, routing logic, and internal practice, rather than a single identifiable decision-maker.

The point isn't that AI is inherently improper, but that the delegated model becomes harder to supervise when control is distributed across systems that neither party fully sees in one place. A carrier may have approval rights and contractual protections while still lacking a practical understanding of how the delegated business is being shaped. An MGA may believe it is in control because it bought the tool and trained the staff, while still being unable to explain outputs, evidence review or constrain vendor-side changes. 

To bring this to life, here are a few examples:

  • A generative AI tool used to summarize a broker submission and could omit a fact that would have changed the underwriting view.
  • A claims triage tool may route certain files into a more skeptical workflow because it reflects historical patterns that no one has actually revisited.
  • Staff may rely on prompts or workarounds that are widely used but not documented; sometimes we refer to these as “shadow use cases” – AI use cases developed by individuals carrying out discrete tasks without governance oversight or knowledge sharing.
  • A human review step may exist on paper, but amount in practice to a cursory check of outputs that are only rarely challenged. 

These examples also highlight why generic references to human oversight are not enough. Human review matters only if the reviewer has enough information, authority, and time to do something real. If the human role is mainly to confirm what the system has already framed, sorted, or drafted, the review may not add much control. 

3. Where does this leave MGAs and their capacity providers?

From an AI lawyer’s perspective, the following issues are important for carriers and MGAs where an MGA is looking to use AI as a key part of its operations.

What uses of AI fall within the delegated arrangement? Internal notetaking and back-office support (often referred to as “productivity use cases”) raise different issues from underwriting appetite, claims triage, customer-facing correspondence, or fraud escalation. Agreements between carriers and MGAs should distinguish between permitted uses, uses that require consent, and those that are prohibited. 

The carrier should request visibility over the systems that actually shape the delegated business. In other words, an inventory of AI tools used in the arrangement, together with basic documentation on purpose, inputs, outputs, limitations, provider, review steps, and operational role. 

When it comes to testing, the parties need to know what happens before deployment, what counts as validation, who is responsible, and when revalidation is required. With many AI tools it isn’t enough to have a “one and done” risk assessment, especially if AI tools are provided on a constantly evolving software-as-a-service basis (which is often the case). A static scoring model, a continuously updated vendor service, and a prompt-based summarization tool shouldn’t be treated as if they create the same risks. 

Audit rights need to match the operating model. If relevant evidence sits in third-party systems, prompt libraries, testing records, or decision logs, the carrier will need access to that evidence to supervise the arrangement properly. Further, the MGA will need corresponding rights against its vendors. Otherwise, the contract may promise oversight that the operating model cannot deliver.

A common issue is that the MGA will state that they can’t renegotiate their vendor contracts mid-term. In these circumstances, additional assurances should be sought from the MGA for the carrier to get the comfort it needs. 

Human oversight should also be specified in practical terms. When must a person review the output? What decisions require escalation? What does meaningful review involve? When must the reviewer be able to override the system, and how is that recorded? 

Incident management needs similar treatment. AI-related incidents may include unexplained output changes, drift, complaint patterns, unfair routing, vendor outages, or sudden changes in fraud flagging. The agreement should set out what must be escalated, how quickly, and what investigation and remediation steps follow. Suspension rights may also matter where a carrier needs to pause a tool that’s creating concern. 

Vendor dependency is part of the same picture. If the carrier expects transparency, audit support, notice of changes, and evidence of testing, the MGA must be able to obtain those things from its vendors. 

Finally, the contract needs to work on exit as well as during the relationship. If the arrangement ends, what records, logs and supporting material must be handed over? Can past decisions still be explained if challenged later? What happens in run-off if the system is switched off or replaced? We often encounter issues with understanding exactly what is a deliverable created especially for a customer, and what is the know-how of the supplier.

AI fits naturally with what many MGAs already do: operate quickly, specialize in narrow markets, handle complexity, and run books that may be too awkward or too small for a carrier to manage directly. It may improve service and make some risks easier to write. 

At the same time, AI can make the delegated model harder to supervise if too much of the practical decision-making sits in systems, vendors, and workflows that neither party can fully inspect or explain. The main issue is therefore not whether AI works in the abstract; it’s whether the delegated arrangement remains understandable, auditable, and controllable once AI becomes part of the operating model. 

That is where model governance matters most – the point at which legal responsibility, operational control, and customer outcomes meet. A useful AI-enabled MGA model isn’t simply one that is faster. It’s one that can be supervised and explained. 

This guide reflects our understanding of the law and market practice in each jurisdiction as at July 2026. Regulation in this area continues to evolve and individual jurisdictions may have introduced changes since publication. For advice on a specific jurisdiction, please contact that jurisdiction's key contact, or your usual DLA Piper adviser.