The common assumption
- “Adopt an AI platform and the intelligence follows.”
AI's Hidden Prerequisite
Executive Summary
Artificial intelligence is genuinely transformational. It reads unstructured documents, drafts correspondence, triages claims and reasons across evidence at a speed no operating team can match. Global AI spending is forecast to exceed $409 billion in 2026.1 In a 2024 survey, 72% of organizations used AI in at least one business function.2
Research also points to barriers beyond model capability. Research found that 62% of organizations reported governance challenges, while 67% lacked full trust in their data.3 The models are not the constraint. Reaching the authoritative record is.
This paper argues that AI does not remove the need for sound enterprise architecture. It raises the premium on one part of it: a complete, secure, documented and governed API layer over the systems of record. Where that layer exists, AI can be grounded in live data and permitted to act. Where it does not, AI is confined to what can be exported, scraped or re-keyed.
The question is not which AI model an insurer adopts, but whether the systems underneath it can be reached with fidelity.
The Requirement
Every useful enterprise AI capability resolves into three requirements. None of them is a model problem. All three are interface problems, and all three are satisfied, or blocked, by the same layer.
A model with no interface to the system of record can only reason about what someone exported or pasted, plausible output about an approximate world, not a basis for a decision.
Context, access and action are not three projects. They are three properties of one API layer.
The Ladder
Core platforms exist on a scale of openness of access. They sit on a ladder. An insurer's realistic AI ambition is capped by the rung its core system occupies, and moving up a rung is a platform decision, not a project decision.
Extract and approximate. AI can summarize; it cannot be trusted with a decision.
Ground and act. AI reads the live record, cites it, and executes transactions.
Most of the value gap between insurers running AI today is not explained by AI budget or talent. It is explained by which rung their core platform sits on, and by whether moving up it requires a vendor project or is simply available.
A platform two rungs lower does not deliver AI two years later. It delivers a permanently lower ceiling.
The Architecture
Enterprise AI is a three-layer stack: an experience layer of assistants, copilots and agents; an API and event layer carrying identity, policy, orchestration and observability; and the core capabilities of policy, claims, billing, rating and accounting. The middle layer is where control lives.
These standards assume an API layer exists. They do not create one.
An AI strategy without an API strategy is an interface without a control plane.
The Evidence
The adoption debate is settled. A 2024 survey found that 72% of organizations used AI in at least one business function.2 Separately, 78% have a generative AI application live. What separates the organizations reporting measurable return from those still reporting pilots is not model access, every buyer has that.
Retrieval-based grounding, the dominant pattern for trustworthy enterprise AI, depends entirely on being able to retrieve. A platform that cannot serve the record programmatically cannot participate in the pattern at all.
The AI divide is turning into an access divide.
Two insurers can license the same model in the same month and end the year with materially different capability. The variable is the platform underneath.
The Control Plane
Insurance is a regulated business. Any AI capability touching policyholder data must answer to the same standards as the systems it draws from: who accessed what, under what authority, on what basis, and with what result. None of those questions can be answered by a model. All of them are answered at the interface.
Where access is granted through shared service accounts, exported files or screen automation, the audit trail breaks at the point regulators care about: the data no longer carries the user's permissions.
Every workaround for a missing API is a workaround for governance.
This is the quiet risk in “AI-enabled” claims built on platforms without a true programmatic interface. The capability may demonstrate well. The control evidence behind it may not survive an audit.
The Workarounds
When a core platform lacks an effective API, the work does not stop. It is displaced into substitute patterns: nightly extracts into a warehouse, screen-scraping and robotic process automation, vendor-mediated custom interfaces quoted per request, flat-file exchange with brokers and partners, and staff re-keying between systems.
Each of these can be made to function. None of them can be made to deliver fidelity, because each introduces the same three defects: the data is a copy, the copy is old, and the copy has lost the permissions and context of its source.
The cost is rarely visible as a line item. It appears as integration projects that take quarters instead of weeks, and as AI initiatives that quietly narrow until they are pilots about documents rather than programs about operations.
A workaround is not a slower path to the same destination.
The Economics
Restricted API access does not present itself as a cost. It presents itself as a series of unremarkable project estimates. Aggregated across a decade, the pattern is consistent enough to name.
The four taxes compound. Each new point solution, each new AI pilot and each new partner integration pays them again, because nothing built for the previous initiative is reusable by the next. An API layer inverts that: the cost is incurred once and amortized across everything that follows.
An API layer is not an IT expense line. It is the only integration investment that gets cheaper every time it is used.
The Market
Core platforms serving mutual and mid-market insurers tend to fall into four recognizable architectural archetypes. The labels are deliberately generic; the point is the pattern, which any buyer can test against the vendors on their own shortlist.
Those costs must ultimately be recovered through customer pricing. From a strategic standpoint, it may become difficult for niche providers to consistently match the economics of hyperscale AI ecosystems.
Domain depth without an API caps the ceiling. An API without domain depth delays the floor. Insist on both, and on evidence.
The Fidelity Gap
Fidelity is the degree to which an AI system's view of the business matches the business itself. It cannot be added later by a better model. It is determined by the channel through which the model reaches the record.
The gap is not theoretical. It shows up in the specific questions an executive most wants answered: what is our current exposure in this postal code, why did this claim reserve move last week, which renewals are at risk this month. Each requires the live record, joined across entities, under the asker's permissions.
The Standards
None of this requires bespoke invention. The industry has converged on a small, stable set of interface standards. REST carries roughly 93% of public APIs4, with OpenAPI as the de facto contract format; GraphQL sits at the enterprise tier as an aggregation layer.
Agent protocols sit on top of that foundation rather than replacing it. The Model Context Protocol, published as an open standard in November 20245, standardizes how a model discovers and invokes a capability, but the capability must already exist as an addressable, governed operation.
In Practice
The practical expression of an effective API layer is not a document of endpoints. It is a governed connector layer the insurer can actually use: supported integrations surfaced inside the policy, claim and contact workflows where the work already happens. Cognition+ delivers this as an integrations marketplace within the platform. Connectors appear as a tab on the policy, claim and contact screens; credentials are managed centrally; broker connectivity and rating bridges reduce duplicate entry at intake; enrichment services return structured results into the workflow rather than into a separate tool.
This is what turns an architectural claim into an operational one. The same layer that lets a connector reach in is the layer that lets an AI capability reach in, which is why the connector estate is the most honest available proxy for a platform's AI readiness.
Once the API layer exists, AI stops being a separate destination and becomes a step in the work. The Cognition+ Risk Intelligence capability illustrates the pattern: the platform calls an AI service as part of the normal user workflow, sends the relevant policy content for analysis, and renders the structured result back inside the Cognition+ interface.
Note what the insurer does not have to do. There are no prompts to design, no orchestration layer to configure, no model behavior to maintain and no library of custom agents to govern. That burden stays with the platform, because the API layer is where it belongs. The insurer receives an outcome inside a workflow they already run.
Apply domain knowledge to specific workflows, and deliver the outcome inside the platform.
Decision Framework
AI capability is easy to demonstrate and hard to verify. The following questions are deliberately about the interface rather than the intelligence, because the interface is what determines the ceiling. Ask for evidence, documentation, a sandbox, a live call, rather than a statement of intent.
If a vendor answers most of these with a date rather than a demonstration, that date is the earliest your AI ambition can begin.
Conclusion
AI is transformational, and that is precisely why the unglamorous question matters more than ever. Every capability an insurer will want from AI, grounded answers, automated triage, agentic execution, ecosystem participation, resolves back to whether the systems of record can be reached with fidelity and under governance.
The insurers who get most from AI will not be those who bought the best model, but those whose core systems could be reached.