AI has collapsed the cost of building software, which makes the old build-vs-buy question worth reopening. The economics aren't what they were, but that doesn't make the decision easier.
KPMG frames this as three paths rather than two, adding borrowing, where a firm co-develops with a partner, alongside the familiar build and buy. Borrowing, they argue, suits organisations that need to move quickly without internal engineering capacity, want to minimise capital expenditure, and need something tailored without funding a full build. To that list, insurance adds one more: needing a partner who can integrate with an estate that still speaks SOAP.
That describes a lot of mid-market insurers and MGAs looking at AI distribution right now.
What none of the three paths changes is who carries the regulatory risk. That stays with the carrier. What does change, in this channel, is that the controls carriers normally rely on to manage that risk have nothing to attach to.
Why is this different from distributing through a PCW?
Carriers already run both models. Direct books, where the interaction is entirely theirs, and intermediated books, where an aggregator or a broker holds it. Both are mature and both are governed, just differently: the direct journey is designed, tested and signed off in-house, while the intermediated one is controlled through the agreement with the intermediary and the product governance arrangements built around it.
An AI assistant looks, at first glance, like the second case. Someone else holds the interface and your product is sold inside it. The difference is that neither of the two mechanisms that make intermediated distribution governable attaches to it.
The first is the counterparty. An aggregator or a broker is an authorised firm, with its own permissions, a terms of business agreement, and a defined place in a distribution chain your product governance arrangements already cover. An AI assistant has none of that. OpenAI is not your appointed representative. Whether an assistant that surfaces and compares quotes sits inside the regulated perimeter at all is unsettled, and the Mills Review recommends the FCA resolve exactly that within three to six months. That is a question about the assistant's status rather than yours. However it lands, your obligations as manufacturer don't move.
The second is the fixed journey. An aggregator journey is a form: the same questions, in the same order, with the same disclosure, for every customer. You review it once and the review holds until the journey changes, and you find out it has changed because someone tells you. An LLM composes a different conversation for each customer, and its behaviour shifts every time the model underneath it updates. There is no single path to certify and no sign-off that stays valid.
That leaves the controls with nowhere to sit except in software. Call it the production layer: the code between the assistant and your pricing and underwriting systems that governs what the agent may say, what it has to confirm, and what it may bind on your behalf. It looks like plumbing, which is why it looks cheap to build. It is where the controls for your conduct obligations have to live now.
AI will get you the first 90% of that build in a sprint. The last 10% is the regulated part, and it doesn't compress.
What does the last 10% look like in insurance?
An AI assistant is built to be helpful. Leave it unscoped and it will have a go at an answer, offer an opinion, and fill gaps with detail that sounds right.
Ask an unscoped agent whether you're covered for escape of water and it will tell you, confidently, without having read your schedule. Mention you've been claim-free for a few years and it will apply a no-claims discount your underwriters never authorised. Describe a converted flat above a takeaway and it will quote it, because declining is unhelpful and being helpful is what it was trained to do. In a regulated sale, every one of those instincts is a conduct problem.
Holding them in check is the production layer's job. Every field the agent assembles gets validated against your own underwriting rules before a premium comes back. Disclosure lands in the right order. Advice is scoped out. An audit trail records what was said, when, and on what basis.
Getting that split right matters more than it sounds. Whether a quote conforms to your underwriting rules isn't a judgement call, so it shouldn't be left to a model to decide. Deterministic decisions belong in rules, wired to the agent through the APIs you already have. Blur that line and you're relying on a model's output to meet obligations that sit squarely with you: Consumer Duty outcomes on consumer understanding and support, ICOBS disclosure requirements, and the financial promotion rules governing how a price can be presented in the first place.
And the target keeps moving. Models update monthly, platform policies shift, and regulation is moving alongside them. The same Mills Review names data access, interoperability, identity, mandates, liability and audit as the foundations agentic finance is currently missing, and recommends the sector build them collaboratively. That's a regulator describing the production layer, and saying nobody should be building it alone.
What does building actually commit you to?
The build case is a reasonable one to make. A prototype is genuinely within reach in-house, sometimes inside a sprint, and for an API-first MGA with a strong technical team the pull is real.
What's worth pricing honestly is everything that comes after the prototype. Building means running a regulated distribution channel indefinitely: owning the production layer, re-testing against every model update, tracking platform policy changes across ChatGPT, Claude and Gemini, and defending the whole thing to compliance. The prototype is a sprint. The channel is a permanent line on the engineering roster. Without a dedicated AI team, that's a standing tax on a small technical bench, paid out of the same budget cycle that's under pressure to show something working.
Then there's the question of what the build is for. Usually the business needs something live and credible to put in front of a capacity provider, an investor or the board, as proof it's moving on AI distribution. A prototype that can't answer compliance questions stays a prototype. And those questions come at every step, from the build itself through to the customer journey.
Does partnering mean outsourcing your compliance?
It's the strongest objection to partnering, and it deserves a straight answer.
Deloitte's compliance practice leans towards building, and their reasoning is worth taking seriously. In a regulated industry you have to be able to explain every decision, and most AI compliance tooling is, in their words, a black box: "you feed data in, they spit out alerts, and you have no visibility into how they make their decisions." Buy one of those and you've outsourced your compliance judgement to a third party. Their recommendation is to own the logic, understand how your agents make decisions and control the guardrails, using partners to build and pre-train.
Read closely, that's an argument against buying rather than against partners. A black box is what buying looks like: a finished product whose rules you can't see. Borrowing is the other thing. You keep the logic, the rules stay legible to your compliance team, and the partner carries the engineering and the maintenance. Deloitte's own prescription, own the logic and use partners to build and pre-train, is a description of borrowing.
Which gives you a simple test to put to any AI distribution vendor: can your compliance team read the rules the agent follows, before anything goes near a customer?
It's why the Agent-Mediated Insurance Standards are published openly, free to read and build on, rather than kept behind a door. What an agent may say in a regulated insurance sale, what it has to confirm, what it may bind, all written down and open to inspection. If a vendor can't show you that, you're buying a black box, and Deloitte's objection applies.
Their observation about the firms taking longest is worth thinking about, too: "The ones moving slowest are still debating whether to build or buy." The bar keeps rising while that decision stays open, and it stays open partly because the frame has a path missing from it.
What does partnering with Marrow look like?
A bespoke-branded agent deployed through Marrow typically goes live in weeks. Your pricing and underwriting systems stay the source of truth, and nothing gets re-platformed. Marrow maps your existing API fields, legacy SOAP and XML endpoints included, to a canonical schema. More on how that works here.
Accountability stays where it belongs. You remain the manufacturer. The rules the agent follows are the published Standards plus your own underwriting appetite, and both are open to your compliance team before launch. The audit trail of every conversation is yours.
We're running this in production today across multiple partners. Aviva is live in ChatGPT, powered by Marrow, one of the first insurers live inside an AI assistant. We track the rest of the field in our ChatGPT insurance app directory.
Get started
Book a call to talk through what build, buy or borrow looks like for your business.
