
Every insurance CIO knows the core has to change, and almost none have found a safe way to do it. This is the defining paradox of insurance technology, and it has held for the better part of two decades. The core systems that run policy administration, claims, and billing were built years or decades ago, and they still work.
Buried inside them, however, is a system containing documented business rules, batch processing windows, custom interfaces, and data semantics that have drifted from their original meaning.
The data-migration slice is even more brutal: Gartner has long held that 83% of data-migration projects either fail outright or exceed their planned budget and schedule, with cost overruns averaging roughly a third and schedule slippage around 40%.
Why Insurance Legacy Is Uniquely Sticky
Insurance legacy is not like other legacy. For instance, a retailer can retire a fifteen-year-old commerce platform once it archives its data. For an insurer, it is difficult because the product it sold decades ago is still a live obligation. Life policies written today create liabilities 30 to 50 years out; long-tail liability lines can generate claims decades after the policy period.
The data behind those policies must remain accessible and accurate for the entire life of the contract, and regulators require it. That single fact—that the past never fully closes in insurance—is what makes the core so hard to move.
Underneath that sit the mechanics: insurance cores still run heavily on COBOL and mainframe platforms, many dating to the 1970s and 1980s, and the engineers who understand them are retiring faster than they can be replaced.
The business rules governing a twenty-year-old book of business are frequently undocumented—sometimes they exist only in the head of a senior underwriter. A disproportionate share of any migration's cost lies not in writing code but in understanding and reconciling those rules, converting data, and stabilising operations after cutover.
When you weigh all of this (the failure rates, the write-off risk, the vanishing skills, the regulatory record-keeping burden), the cost, risk, and complexity of full modernisation routinely outweigh the economic benefit.
Agentic AI Changes the Calculus
With agentic AI now making waves across industries, it is the right time to ask this question. Is the insurance industry ready for agentic AI?
Fortunately, Agentic AI does not require the core to be replaced, but to be reachable.Agents pursue a goal, break it into tasks, use tools and context, and iterate under defined controls. Applied to the modernisation problem itself, agentic AI attacks precisely the bottlenecks that sink replacement programs. Agents can read code written in archaic languages, reverse-engineer the embedded logic, and translate it into plain-English business rules.
Through orchestration, agentic AI can operate across legacy and modern systems at once. It’ll call APIs where they exist, working through integration layers where they do not, and orchestrating multi-step journeys that touch the mainframe, the cloud platform, the data warehouse, and third-party data providers in a single workflow.
The legacy core is relegated to what it is genuinely good at: holding records, transactions, financials, and the regulatory state of truth. The differentiating, intelligence-heavy work moves to a layer of agents around it. The legacy estate does not have to become fully modern. It has to become modern enough that a patchwork of AI and orchestration layers can work on top of it.
What "Modern Enough" Actually Requires
"Modern enough" is a threshold, and it is worth being precise about what clears it. An agent operating on a core needs three things the mainframe was never designed to provide.
- Access: an API or data-access layer that lets agents read and write to the system of record without a human rekeying between screens.
- Current state: event streams or near-real-time data feeds, because agents reason against live state, not nightly batch backfills.
- Semantics: a structured representation of what the data actually means, so an agent is not guessing at the meaning of a field whose definition drifted a decade ago.
One of the main reasons for agents failing is that we connect them to incompatible systems. Legacy PAS environments held together by hundreds of point-to-point integrations introduce new failure points the moment agents try to read and write across them without a modern API layer to manage them. "Modern enough" is the work of building that layer, and it is a far smaller, lower-risk investment than a core replacement.
The Risks are Equally Real
Though it’s possible to run agentic AI on brittle foundations, the undocumented logic and decision points
get omitted from the process. Moreover, the context isn’t fully related to agentic workflows, as the crucial information governing legacy processes lives inside stakeholders’ heads.
It just isn’t a formal part of the workflow, and what isn’t part of the workflow cannot be transferred to AI. Even wrapping the workflows with APIs does not fix the undocumented logic. It can defer the problem while agents automate and scale a broken process, leading to flawed outcomes.
Governance is the harder constraint, and in insurance it is not optional. Regulators require insurers to maintain a documented AI Systems Program covering governance, risk management, bias testing, and third-party vendor oversight.
Not all use cases are under the same level of scrutiny. For instance, the EU AI Act classifies risk assessment and pricing in life and health insurance as high-risk, making risk management, data governance, logging, human oversight, and post-market monitoring some of the core obligations.
How to Earn Readiness?
The path is staged, and each stage has a threshold that tells you how to proceed.
Make the Core Data and Information Reachable
Stand up an API and data-access layer over the systems of record and expose the highest-value read/write operations first. An agent should be able to retrieve and write a policy or claim record without a human rekeying between screens.
Make Data Ingestable
Next, attack the document and intake edges, where value arrives the fastest. Deploy agents on submission intake and document extraction before touching consequential pricing or coverage decisions. Automating this aspect ensures measurable reduction in high-volume, low-stakes workflows.
Make a Semantic Layer
Invest in an ontology or business data model and near-real-time feeds so agents reason against live, well-defined state. The benchmark: an agent can correctly interpret a field whose meaning has drifted without a subject-matter expert in the loop.
Make governance formal
A model inventory, cross-functional oversight, bias testing, explainability, third-party vendor controls, and end-to-end audit trails, and map high-risk use cases against the applicable AI regulations. The benchmark: every AI-influenced regulated decision can be reconstructed and defended to an examiner.
Make modernisation a portfolio
Once reusable agents exist for discovery, data mapping, testing, and reconciliation, apply them across product lines and the long tail of satellite systems, and let declining marginal cost—not a single business case—drive sequencing. The signals that should change your plan: if agent pilots repeatedly stall before production, the blocker is almost always the enabling layer (access, data quality, governance), not the model—fix that before buying more capability. If a vendor's product requires your teams to log into a new portal or creates a second source of truth, it is another system to integrate, not a solution to integration; decline it.
Conclusion
The insurance sector is ready for agentic AI only where it has made its core reachable, its data intelligible, and its decisions governable.
The opportunity is not to hand autonomy to a model or force another risky core replacement. It is to place tightly controlled agents around systems of record, begin with observable, low-consequence workflows, and expand only as evidence, controls, and trust accumulate.
For CIOs, the decisive question is no longer whether every legacy platform can be modernised. It is whether the organisation can expose enough context, impose enough discipline, and learn fast enough to modernise safely.





.png)




.png)



.png)
