What AI Still Gets Wrong About Commercial Insurance in India
AI in Indian insurance stopped being a talking point this year and became a regulatory priority. In June 2026, IRDAI formed a seven-member working group tasked with building the country’s first formal AI governance framework, with a mandate that explicitly names claims processing and fraud detection as the areas of greatest concern — including the open question of who is liable when an automated decision gets it wrong. That question doesn’t have an answer yet. Regulation is catching up to deployment, not the other way around.
That’s the right context for asking what AI actually still struggles with here — not in the abstract, but in the specific texture of India’s insurance market.
Most AI underwriting progress, in India and globally, works by getting better at reading data that already exists — transaction history, digital footprints, structured financial records. That’s a real capability. It’s also not the same problem as underwriting a business that produces almost no usable data at all.
This is India’s actual bottleneck. Riskcovry — one of the country’s more established insurtech infrastructure players — has said as much in its own research: small and micro businesses are a market insurers generally struggle to distribute to and gather data on, precisely because they’re informal and undocumented. That’s not a competitor being modest. It’s an honest description of why the vast majority of India’s small businesses still carry no property or disaster insurance at all, despite standardized products like IRDAI’s own Bharat Sookshma Udyam Suraksha having existed for years. The product isn’t the missing piece. The data pipeline underneath it is.
There’s a second, quieter tension specific to India right now. IRDAI’s 2025 Regulatory Sandbox Regulations explicitly list AI and machine learning in underwriting as an innovation area the regulator wants to see tested — but its own legal commentary flags the obvious friction with India’s Digital Personal Data Protection Act: the more predictive an underwriting model tries to be, the more granular the personal data it tends to want, whether that’s lifestyle signals, biometric indicators, or visual data.
That’s not a hypothetical concern for anyone building alternative underwriting methods in India — it’s a live design constraint. Any approach that substitutes physical or visual signals for financial paperwork has to be built with real consent and real data discipline from day one, not bolted on after the fact once a regulator asks.
AI is only as good as the data feeding it, and Indian insurance data has had a rough couple of years on that front. In August 2024, Star Health — one of India’s largest health insurers — suffered a breach affecting over 31 million customers and roughly 7.24 terabytes of sensitive data. Whatever the cause, the underlying point holds broadly across the industry: AI needs clean, structured, well-governed data to be trustworthy, and insurance data in India is often exactly the opposite — fragmented across legacy systems, inconsistently labelled, unevenly secured.
An AI model can be well-designed and still produce bad outcomes if the data infrastructure underneath it isn’t. That’s as true for a large listed insurer as it is for any startup proposing a new underwriting method.
None of this is a case against AI in Indian insurance — IRDAI standing up a dedicated working group is a sign the sector is maturing, not stalling. But most of the visible progress so far has been about processing existing data faster and more accurately. It hasn’t touched the harder, more specific problem: how do you responsibly extend coverage to a business that has never generated the kind of data traditional underwriting — AI-assisted or not — was built to read?
That’s not a bigger-model problem. It’s a question of what should count as evidence of risk in the first place, built with the same seriousness IRDAI is now asking of AI governance generally: transparent, consent-driven, and honest about what it doesn’t yet know.