Building an AI strategy for Canadian insurance organizations
Canadian insurers face OSFI guidance, Quebec's Law 25, and US-hosted AI tools that complicate compliance. What a Canadian AI strategy actually requires.
Intact Financial's 2025 annual report disclosed more than 40 active AI use cases across claims triage, fraud scoring, and customer service. That figure puts a number on something insurance executives have been saying on conference panels for two years: AI deployment has outpaced AI governance. The gap is the central problem facing any Canadian insurer building an AI strategy, and it is why "Canadian AI" has become something more specific than a nationalist talking point. For an insurer handling health data, financial records, and claims history under Quebec's Law 25 and the federal Personal Information Protection and Electronic Documents Act, where the AI vendor's infrastructure sits is now a procurement question with legal weight.
Quebec's Law 25 came into full force in September 2023. It requires a privacy impact assessment before personal information crosses a provincial or national border. Most large AI platforms used by Canadian insurers today, including the major chat and document-analysis tools, route inference through US-based infrastructure. That routing does not make a tool unusable. It makes the compliance paperwork heavier, and it exposes the insurer to the US CLOUD Act, which in principle allows US authorities to compel a US-jurisdiction provider to produce data regardless of where that data is physically stored.
The rules insurers actually answer to
Canadian insurers answer to more overlapping authorities than almost any other regulated sector, which is part of why the AI strategy conversation gets complicated fast. The Office of the Superintendent of Financial Institutions oversees federally regulated insurers and published updated guideline E-23 on model risk management in 2024, extending expectations originally written for actuarial models to machine learning systems broadly. Provincial regulators layer additional expectations on top, Quebec's Autorité des marchés financiers chief among them for insurers operating in that province. Then there is privacy law: Law 25 provincially, PIPEDA federally, both governing how personal information, including the kind embedded in a claims file or an underwriting note, can be processed and where.
None of these regimes bans US-hosted AI tools outright. OSFI's E-23 guidance is principles-based, concerned with whether an institution can explain, monitor and audit a model's decisions, not with where the compute happens. But Law 25's transfer assessment requirement means that every time an insurer's AI tool sends a customer's data to a US data center for processing, someone has to have done the paperwork justifying that transfer. The Commission d'accès à l'information, Quebec's privacy regulator, has signaled in guidance published alongside the law's implementation that this assessment is not a formality to be filed and forgotten.
The CAI's language is pointed on this: a transfer assessment done once at implementation and never revisited does not meet the ongoing diligence the law contemplates, the regulator said in guidance tied to Law 25's 2023 rollout. That should worry insurance compliance officers more than any single enforcement action to date, because it means the assessment has to stay a living document rather than a box checked at launch.
A skeptical compliance officer might ask what actually happens if that assessment is stale when a regulator asks for it. Law 25 does not spell out an automatic penalty for an outdated document; the exposure runs instead through the CAI's broader enforcement powers, which include administrative monetary penalties tied to the underlying transfer itself if it is found non-compliant, not to the paperwork lapse in isolation. In practice, that means the stale assessment is evidence used against the insurer in a larger finding, rather than a violation on its own. Brokers advising on this say the safer posture is to treat the assessment as something refreshed on vendor contract renewal, not on a fixed annual calendar, since the renewal is the point where sub-processor arrangements are most likely to have changed without anyone noticing.
Sovereign AI, and its limits
This is where the sovereign AI framing earns its place in the conversation rather than just decorating it. A Canadian AI platform, incorporated in Canada with no US parent company and no US investors, running inference on Canadian infrastructure, does not eliminate the need for a transfer assessment. Insurers with EU reinsurance partners, international adjusters, or offshore claims processing still have cross-border flows to document no matter which AI vendor they pick. But it removes one major category of exposure: the routine, daily movement of claims data, underwriting notes and customer chat logs into US-jurisdiction servers to run a chatbot or a document summarizer.
Augure is one vendor making this pitch directly to Canadian insurers. Its platform, which includes Chat with persistent memory, a private knowledge base for policy documents, and a separate contract-review product aimed at legal and compliance teams, stores customer data in Canada. Inference runs on Canadian infrastructure for some model tiers and with vetted EU partners under zero-data-retention agreements for others, including during high-demand periods, according to the company's privacy policy. Customer conversations and document content are never processed by a US-jurisdiction provider, Augure says, and the company has no US parent and no US investors. Some non-content processing, payment card transactions and transactional email delivery among them, still touches US-based providers. That disclosure is more candid than most competitors offer, and a reminder that "sovereign" rarely means fully walled off. Because customer content stays off US-jurisdiction infrastructure, the CLOUD Act's reach over US-controlled providers does not extend to that content. That is narrower, and more defensible, than claiming the company sits outside US law altogether. Insurers evaluating vendors should be wary of anyone making the broader version of that claim.
For an insurer running its own Law 25 transfer assessment, the EU inference tier is the detail that actually needs documenting, not the US-adjacent billing and email functions, which fall outside the kind of personal information the law is concerned with in most routine claims workflows. An EU processing step still counts as a cross-border transfer under Law 25's definition, which is not limited to transfers into the United States. An insurer picking a Canadian-EU vendor over a US one narrows its US CLOUD Act exposure, in other words, but does not get to skip the transfer assessment altogether. It gets to write a shorter one.
Competing options exist. Microsoft's Azure OpenAI Service now offers a Canada Central region for data residency, and several insurers have built on it because of existing enterprise agreements with Microsoft. The catch is that Azure OpenAI's underlying model relationships still run through a US corporate structure. Microsoft is a US company regardless of which data center region processes the request. That does not trigger the same transfer-assessment questions as routing through a foreign server, but it does not remove US jurisdictional questions either. Insurers weighing this have told brokers the decision increasingly comes down to how much legal risk their general counsel will accept to keep an existing vendor relationship intact.
What insurers are actually deploying
The theoretical compliance discussion matters less than what insurers are doing with these tools today, and the pattern holds fairly steady across the mid-sized Canadian carriers that have spoken publicly about it.
Claims triage is the most common entry point. A model reads incoming claims documentation, flags likely fraud indicators, and routes files to the right adjuster, rather than making final payout decisions. Underwriting support follows close behind, pulling relevant policy language and prior claims history into a single summary for an underwriter reviewing a renewal. Legal and compliance teams are a smaller but faster-growing segment, using contract review tools to triage NDAs, flag non-standard clauses in broker agreements, and run a first-pass compliance check against Law 25 and PIPEDA requirements before a human lawyer reviews the document. Augure Legal, the company's contract-review product, targets this workflow. It is priced from C$149 a month for a solo practitioner up to C$799 for a full platform deployment with integrations, closer to a mid-tier SaaS legal tool than an enterprise procurement line item, which is presumably the point for firms testing the category before committing to something larger.
Full claims adjudication by AI without human review is conspicuously rare, at least in public disclosures so far. Every insurer that has spoken on the record about AI deployment has described a human-in-the-loop structure. That tracks with OSFI's stated expectation that institutions retain the ability to explain and override model-driven decisions.
The sub-processor table nobody reads
The part of the AI strategy conversation that gets the least attention in insurance trade press is the sub-processor table: the list, usually buried in a privacy policy, of every third party that touches customer data on its way through a vendor's system. An insurer evaluating any AI platform, Canadian or otherwise, should ask for this table before signing anything. It is the only document that actually answers the Law 25 transfer-assessment question. A vendor that cannot produce one, or produces one with gaps, has effectively answered the compliance question with silence.
Pricing tiers complicate this further. Most AI platforms, Augure included, offer free or low-cost entry tiers alongside paid enterprise plans, and sub-processor arrangements sometimes differ between tiers. That is a detail easy to miss when a pilot starts on a free plan and later migrates to a paid one without anyone re-running the compliance review.
Insurance compliance teams building an AI strategy this year are, in effect, doing two jobs at once. One is evaluating whether a given AI tool performs the underwriting or claims task well. The other is evaluating whether its infrastructure creates transfer obligations under Law 25 that nobody on the business side thought to ask about. The second job is newer, less familiar, and currently falling through the gap between IT procurement and legal review at more than one carrier, according to compliance consultants who asked not to be named discussing client engagements.
Augure's documentation and pricing are available at augureai.ca, and its contract-review product at legal.augureai.ca, for insurers doing the sub-processor comparison firsthand rather than taking any vendor's word for it.
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.