← All editions

Weekly Edition

7 September 2026 · 8 min read

#45: Should ChatGPT be regulated as an insurance distributor?

#45: Should ChatGPT be regulated as an insurance distributor?
Edition #45 · 7 September 2026

Should ChatGPT be regulated as an insurance distributor?

ChatGPT as insurance distributor · Decision-grade data on open finance · AI governance playbooks · Supervising AI · Five areas where open finance may need mandates

By Andres Lehtmets · 7 September 2026
Editor’s note

I hope your autumn season has started well. On my side, this newsletter is now back on a regular rhythm, and I intend to keep it that way.

Which makes this a good moment for a small ask. If you read this newsletter, I would love to hear from you: do you find it useful, and what would be worth changing? Just reply to this email. I read every response.

Article 01

Should ChatGPT be regulated as an insurance distributor? The question reached Parliament.

On 2 September the House of Lords Financial Services Regulation Committee put a pointed question to the FCA in its evidence session on the consumer insurance market: should AI platforms such as ChatGPT be regulated as insurance distributors?

The logic behind the question is simple. People already ask AI whether a policy covers what they need and how it compares with others. That is what price comparison websites do, and those are regulated. So why not the AI platform?

The FCA’s answer was clear, and in my view legally correct. Price comparison websites are regulated because you can transact through them and they earn from it. AI platforms answer questions and give factual information. No execution, no personal recommendation, no regulated activity by way of business.

Or…? With agentic AI, execution through the platform may well become possible. And even today, depending on the platform and your prompting skills, you can get something that looks very similar to regulated advice. The line is blurring, and it is fair to ask whether consumers realise they lose the classical safeguards when they rely on it. The FCA said it will monitor this closely, but widening the perimeter is a matter for Parliament and the Treasury, not the regulator. In the same session it also signalled willingness to write new rules on customer understanding if industry and consumer groups cannot agree on a way forward.

The other questions raised in the session are ones every supervisor will face soon, and the same ones we have been discussing with regulators in the capstone projects of the Cambridge CCAF AI in Financial Services course. Should authorities warn consumers that these tools are unregulated and not always right, as they have done with finfluencers?

The EU is running the same debate one procedural step ahead. An EIOPA Q&A asking whether publicly accessible AI chatbots fall within insurance distribution under the IDD has been forwarded to the European Commission, and I expect the answer to give some direction as early as this autumn. If not, the IDD review, probably under the next Commission, will be the moment to settle it. I wrote up the EU side in this analysis. The session page · watch the full hearing.

Article 02

The FCA’s open finance verdict on mortgages: more data is not the answer, decision-grade data is

In September the FCA published the outcomes of its Mortgages and Open Finance Policy Sprint, which brought together around 80 stakeholders in June as the first test case under the Open Finance Roadmap. Mortgages went first because lending decisions depend on evidence scattered across banks, public bodies and organisations outside finance.

Participants saw real potential across the mortgage lifecycle:

  1. Mortgage-readiness tools built on rental and savings data.
  2. Affordability evidence drawn from verified income, tax and employment records instead of document gathering.
  3. Earlier warnings of payment pressure from current account data, before arrears occur.
  4. Later-life planning that brings insurance, pensions and savings data together.

The headline conclusion is that more data does not solve the problem. Data has to be decision-grade: accurate, current, standardised and capable of being recognised as evidence a lender can actually rely on. Participants also doubted that voluntary participation would be enough, and named five areas where mandation may be needed: participation, minimum datasets, technical standards, recognition of evidence and scheme rules.

Next up for the FCA’s Smart Data Accelerator: data-sharing architecture, identity and verification, and the interdependencies between agentic AI and open finance. Familiar territory if you read the OECD paper on AI and open finance covered in edition #43. Read the outcomes report.

Article 03

Two practical AI governance playbooks for financial services

The Actuaries Institute and the UTS Human Technology Institute published new practical guidance this week on AI risk management in the financial services sector. It comes from Australia, but the principles are universal: accountability, classification, quantification and controls, built to fit into existing risk management rather than replace it. In the EU, read it through the AI Act lens first and then your sectoral legislation.

It pairs well with the CRO Forum’s August paper on AI governance and compliance for insurers, which reads the EU AI Act alongside the leading international frameworks, including NIST’s AI Risk Management Framework, ISO/IEC 42001, MAS FEAT and Hong Kong supervisory expectations, and translates them into practice. Its eight focus areas in condensed form: a complete AI inventory with documented classification rationale, gap analysis against AI Act deadlines, formal approval before any high-risk deployment goes live, an explicit AI risk appetite, integration into existing enterprise risk management, stronger third-party governance, independent model validation and using AI to strengthen the risk function itself.

The common thread is the important part. Neither playbook builds a parallel compliance universe. Both embed AI risk in the structures firms already run, which is the realistic path for anyone facing the AI Act’s high-risk deadlines. The Actuaries Institute guidance · the CRO Forum paper.

Article 04

Can supervisors keep up with AI? The OECD and the FCA on what actually works

On 3 September the OECD published a piece by Iota Kaousar Nassr (OECD) and Henrike Mueller (FCA) asking whether the finance sector can oversee AI innovation while maintaining its rapid progress, drawing on the OECD’s Supervision of Artificial Intelligence in Finance paper.

The supervisory challenges it lists will be familiar: model risk management and validation, limited explainability, fairness benchmarks, data governance and making human-in-the-loop oversight work in practice rather than on paper.

More interesting is what it says about responses. The direction of travel is interpretative guidance on existing rules rather than new prescriptive regulation, and the FCA’s AI Live Testing programme is highlighted as a novel supervisory approach: a discovery phase followed by live testing, with structured engagement between the regulator and firms. One caveat stands out for the agentic era: agentic AI systems challenge pre-deployment testing because their execution paths multiply and become unpredictable, which pushes supervision closer to runtime behaviour and further from one-off model approval. Read the article and the underlying paper.

Quick links
The FSB Chair writes to the G20 on frontier AI

On 28 August FSB Chair Andrew Bailey wrote to G20 finance ministers and central bank governors. The vulnerability list: sovereign debt fragilities, private credit interconnectedness and opacity, stretched AI-related valuations and rising equity market leverage. The AI highlight: frontier AI could materially alter the speed, scale and economics of cyber risk, with concentrated third-party providers as the amplifier, and many jurisdictions still lack protocols for safe model release. Same direction of travel as the ESAs’ statement covered in edition #44. Read the letter.

The OECD builds a typology for financial scams and frauds

The OECD’s report on protecting consumers from financial scams and frauds looks at what is driving the rise in scams and what works to prevent and detect them, drawing on views of policymakers, regulators and supervisors globally. The underrated part is the proposed typology of scams and frauds targeting consumers: you cannot risk-base your supervision, regulation or mitigation on what you cannot categorise. And the policy community cannot do it alone; it takes cooperation with market participants and serious engagement with regtech and suptech. Read the report.

Central Bank of Ireland: informing effectively is not a tick-box exercise

The Central Bank of Ireland shared takeaways from its webinar on the informing effectively obligation under the modernised Consumer Protection Code: put consumer understanding and financial wellbeing at the centre of communications, treat the obligation as a mindset shift rather than a compliance exercise, measure whether communications actually work and keep improving them. Inspections and reviews on this topic continue into 2027 and beyond. Acting in the best interests of consumers is not a compliance exercise; it is the foundation of a sustainable financial services business. The webinar slides.

Number of the week
5

The number of areas where participants in the FCA’s open finance policy sprint said voluntary participation may not be enough and mandation may be needed: participation, minimum datasets, technical standards, recognition of evidence and scheme rules. What does it tell us when the market itself asks the regulator for mandates? FCA.

Andres Lehtmets Advisory Newsletter

Weekly briefing on financial innovation and regulation. Join 5,000+ fintech, insurance and regulatory professionals.

Subscribe
Working together

Advisory for regulators, boards and fintech leaders navigating digital finance policy and regulation. See how I can help.

Selectively considering sponsorship for this newsletter. Reach 5,000+ decision-makers in financial innovation and regulation. Enquire.

Andres Lehtmets

Andres Lehtmets

Independent advisor on financial regulation and digital innovation. Former Senior InsurTech Expert at EIOPA. Research Analyst at Cambridge Centre for Alternative Finance. Writing weekly for 4,700+ professionals.

Get the newsletter

Weekly insights on financial innovation and regulation. Join 4,700+ professionals.