Page 1 of 1

Methodology (v1.0)

Posted: Sun Oct 11, 2026 1:29 pm
by Fijishi
Fijishi Jurisdiction Index: AI in Insurance Decisions · Methodology, version 1.0 · 12 October 2026

By Akhil Sharma and Preethi Sharma, Fijishi.

What the Index examines

The Fijishi Jurisdiction Index: AI in Insurance Decisions examines how each jurisdiction's own published rules apply to AI used in insurance decisions, such as underwriting, pricing, claims and contact with customers.

Each entry ends in one sourced question that the public record does not yet answer.

This edition has 38 entries across 34 jurisdictions. The United States counts as one jurisdiction with five entries: California, Colorado, Federal, New York and Texas.

The chain behind every entry

Every entry follows the same four steps.
  1. The jurisdiction's own rules: what binds, since when, and which authority checks it.
  2. The market's own record: the published record of a company's AI use or, where none could be tested, the regulator's or government's own published record.
  3. Where the two meet: the point at which the rule and the record bear on the same decision.
  4. One question: a single, sourced question that the public record leaves open.
An entry that could not reach a sourced question would not be published. Every entry in this edition has one.

Tiers: how far a jurisdiction has set out AI rules
  • Tier A - Specified and enforced. A binding instrument that applies to insurers' own use of AI, or an issued regulator document addressed to this insurance market, addresses AI - by name or by an unambiguous description such as "predictive models" or "automated decision system" - and sets out rules or expectations that apply to it; and the regulator has a live mechanism to check or sanction them.
  • Tier B - Specified; enforcement stated, not yet live. AI is specified as for Tier A, and a mechanism to check or sanction it has been stated but is not yet shown to be live.
  • Tier C - Specified, not yet enforced. AI is specified as for Tier A, but no mechanism to check firms against it is stated.
  • Tier D - Not yet specified. No binding instrument that applies to insurers' own use of AI, and no issued regulator document addressed to this insurance market, sets out rules or expectations for AI.
  • What does not count, for any tier: drafts and consultation papers; voluntary economy-wide guidance and policy statements; articles in a regulator's newsletter; rules addressed only to a different kind of licence; material that treats AI only as an external threat; and general data-protection rules on decisions made solely by automated processing. Where one of these bears on an entry's question, the entry shows it.
The tier describes the jurisdiction and applies to every firm operating there, wherever the firm is headquartered.

Tiers are not grades of regulators. A tier records whether AI rules have been set out and whether a mechanism to check them is live; it says nothing about the quality of a regulator's work.

Only issued documents count towards a tier. Drafts, consultation papers and discussion papers appear in entries as dated context, and a jurisdiction is re-tested when the final version is issued.

Bands: how clearly the rules meet the case examined
  • Exposed - The published record of a company's AI use meets a dated rule that binds and names or covers AI, and the question points to one party or one narrow responsibility.
  • Elevated - As Exposed, but one of those two is less firm: the rule is not both binding and AI-specific, or the responsibility is less narrowly pinned.
  • Watching - Both of those are less firm.
  • Contained - No company's published account could be tested, so the question rests on the jurisdiction's own regulatory record and the gap it leaves.
A band follows from two of the five criteria below, and from whether a company's own account could be tested. The two criteria are how firmly a dated, binding rule covers AI, and how precisely the question points to a party or a responsibility. The band is not a separate judgment.

A band applies only to the case examined in its entry. It is never extended to other firms, and it is not a rating of a company, its governance or its financial strength.

We use four descriptive bands, each shown with the finding it belongs to, rather than a letter scale, because the evidence does not support finer grades.

The five criteria
  • Self-sourced specificity: how far the entry's facts come from primary sources, meaning the rule itself, the regulator's own publication or the company's own disclosure.
  • Dated bindingness: a checkable date, or an authoritative statement, shows the rule is live now. It is strongest where the binding rule names AI or covers it, as a rule on automated decisions does.
  • Accountability precision: the question points to a named party or a narrow responsibility boundary.
  • Askability: the party asked could answer in one sentence.
  • Structural novelty: the question has not already been publicly named by the industry concerned.
Each entry states in one line why its band follows.

Who these rules reach

Every entry has a Reach block with three lines: insurers, reinsurers and intermediaries.

Each line says whether the rule the entry relies on reaches that kind of firm directly, and quotes the provision's own words wherever the provision was read. Where that rule is not binding, the line says so.

Where a rule does not reach reinsurers directly, the open question sits with the insurers they reinsure.

Where the text does not say, the line reads "not stated". We do not infer reach.

Sourcing rules
  • Every fact in a question comes from a primary source, except where section 4 of the entry names a substitute. Press reports, law-firm notes and suppliers' accounts appear only where they are labelled as such.
  • At most one verbatim quotation is taken from any one source. Other provisions are paraphrased and given a pinpoint, such as a section, paragraph or page, so that they can be checked.
  • Quotations in an entry's Reach block are an exception: they give a provision's exact words, are labelled as such, and are never spliced.
  • Where a rule or disclosure is not in English, we work from the original-language text and mark any English as our rendering.
  • Every source is shown with its type and, where one was found, the date printed on it. A document that carries no date is shown as undated.
  • Where a primary document could not be opened directly, the entry says so and names the substitute used.
  • Statements that something is absent are limited to what we searched. An entry says "has not publicly said" or "we found no", never that something does not exist.
  • A company's figures are reported as the company states them. We do not verify them independently.
  • Where it matters to the question which group entity uses the AI, the entry says how that entity was identified, or that it could not be.
  • Codes follow ISO 3166 where practical; UK and EU follow common usage.
Hard calls in this edition

These are the judgements that most affected where an entry landed. Each is applied the same way in every entry.
  1. Drafts do not count. Bermuda's tier rests on the Bermuda Monetary Authority's issued letter of 9 February 2026, not on its consultation of 14 August 2026.
  2. A review of how firms use AI is not a check against AI rules. The Financial Conduct Authority's plan to assess how insurers use AI, and what holds adoption back, leaves the United Kingdom in Tier C.
  3. A tier cannot rest on the answer to the entry's own question. Whether the Central Bank of Ireland can already act on the AI Act's transparency duty is the question Ireland's entry asks, so Ireland is Tier B.
  4. Industry rules enforced by industry bodies are not a regulator's mechanism. Taiwan's insurance associations' AI rules do not place Taiwan in Tier A.
  5. A provincial law does not set a national tier. Quebec's rule on automated decisions anchors Canada's Quebec-scoped question, but Canada's tier follows the insurance regulators' AI guidelines, which take effect on 1 May 2027.
  6. A statute that names AI specifies it, even where it only asks firms to try. Japan's AI Act, in force since 1 September 2025, asks businesses to strive to use AI and to cooperate with government measures, and carries no penalties; Japan is Tier C.
  7. AI rules for a different kind of licence do not set the insurance tier. Mauritius's binding rules for AI-driven advisory licensees do not reach insurers.
  8. A regulator's newsletter article is context, not an issued instrument. The Hong Kong Insurance Authority's 2023 article on chatbots is cited in that entry's question but does not change the tier.
  9. Material about AI as an outside threat does not set rules for insurers' own use of AI. A reported letter from Israel's insurance regulator on offensive-AI cyber threats would change Israel's tier only if it also covered insurers' own AI use.
  10. General data-protection rules on decisions made solely by automated processing bear on an entry's question, not on its tier. This applies in South Africa and Cameroon.
  11. Guidance does not supply a binding AI-specific rule where its own regulator says the binding rules beneath it are technology-neutral. This is why Switzerland's case is Elevated rather than Exposed.
Glossary
  • Case examined: the company whose own published account of its AI use shows that the entry's question is live.
  • Question to: the regulator or government an entry's question is put to, where no company's account could be tested.
  • Tier: how far a jurisdiction has set out AI rules and whether it checks them. It applies to every firm in the jurisdiction.
  • Band: how clearly the rules meet the case examined. It applies to that case alone.
  • Reach: whether the binding rule an entry relies on applies directly to insurers, reinsurers and intermediaries.
  • Primary source: the rule itself, the regulator's own publication or the company's own publication.
  • Issued document: final guidance, a circular, a letter, an FAQ or a rule, as opposed to a draft or consultation.
  • Live mechanism: a way for the regulator to check or sanction firms against AI rules that is running now, such as examination, pre-approval, attestation, fines or requested self-assessments.
  • Not stated: the rule's text does not say, and we have not inferred an answer.
  • Undated: the document carries no printed date.
Versions, timing and updates

This is version 1.0 of the Methodology. Any change to it receives a new version number and date and is logged in Corrections and new evidence.

The Index is published each year on the second Monday of October. The next edition is due on 11 October 2027.

Between editions, we check every entry each quarter and re-verify every entry each October before publication. Corrections are made at any time and logged publicly.