Build vs buy claims AI gets argued on licence cost, and licence cost is the one number that stops mattering the moment you want out. The question that decides the outcome is who holds the evidence record behind each claim decision, in what format, and for how long after the contract ends. That question is answered in the contract, not in the architecture diagram, and most buyers negotiate it last or not at all.
The prompt for this is an Insurance Journal piece published on 21 September 2026, covering an Insurance Nerds webinar that made the case for insurers building their own software instead of renting it. John Lucker, EVP at Universal Shield Insurance Group, described rising vendor costs and said the carrier "felt like we were being held hostage, not necessarily by the vendor, but by the situation." Luke Magnan, co-founder of Combined Ratio Solutions, said "the move to SAS type commercial arrangements has taken all the control away from insurers." Nick Lamparelli, who runs Insurance Nerds, offered the synthesis: "now, it can be buy and build, not buy or build."
Their diagnosis is correct and this post concedes it in full. The disagreement is about where control is won. We covered the components-versus-platform version of this question in open-source fraud detection versus commercial platforms; this one is narrower and it is about an artifact rather than an architecture. A claim closed in Rhode Island in 2026 has to be producible through the end of 2030. A three-year subscription signed in 2026 ends in 2029. That one-year gap is what you are actually buying or building against, and no amount of in-house engineering closes it if the paper is silent.
The webinar is right about the problem
Answer
Why are insurers talking about building their own software again?
Because run costs crowd out everything else. A 2025 West Monroe survey of 300 US insurance executives found more than half spend 51% to 75% of IT budget just keeping existing systems running, and 94% had at least one strategic technology program delayed or cancelled for budget reasons in the past year.
Those figures come from a West Monroe survey of 300 US insurance executives. When maintenance eats between half and three quarters of the line and 94% of executives have had something delayed or cancelled, the next renewal notice does not read as a price. It reads as a claim on the only money left.
The "why now" in the piece is that AI has made software development fast enough for a carrier to customise an open-source core itself, and Universal Shield built its Universal Connect portal that way. Lucker's other line, "version one doesn't have to be perfect," is the correct engineering posture and worth borrowing. His analogy, as Insurance Journal renders it, is being locked into a vendor the way a tenant pays for a kitchen renovation in a rented apartment. That is a fair description of what a long implementation on someone else's platform feels like.
Disclose the panel before you borrow the argument
Answer
Who was on the Insurance Nerds build-your-own webinar?
Nick Lamparelli of Insurance Nerds, John Lucker of Universal Shield Insurance Group, and Luke Magnan, co-founder of Combined Ratio Solutions. Combined Ratio sells the services around a no-licence-fee open-source platform, and Universal Shield went live on that platform in April 2026. The argument survives the disclosure, which is why the disclosure is worth printing.
Combined Ratio Solutions publishes CRS OSPolicy, an open-source policy administration system with "no upfront licensing fees," alongside Rebel OPS Services: implementation, configuration, customisation, data migration, integration, custom development, cloud re-platforming, hosting, DevOps and technical support. The homepage positioning is "Full Control. No Boundaries." and "You decide. You build. You launch. You scale. You own." The licence is free and the work around it is the business. That is a legitimate model, and it means the panel had a direct commercial interest in the conclusion it reached.
The carrier on the panel is the vendor's customer. Universal Shield announced on 23 April 2026 that it had gone live on CRS OSPolicy for commercial property and general liability, with the remaining lines due by mid-2026. Lucker in that release: "given the challenges with other platforms in the past, we wanted to have complete ownership and control of our own system." Insurance Journal made the third disclosure itself, as a reporter's observation rather than an editor's note: "the webinar did not indicate how much Combined Ratio or similar firms charge for the core software set-up, hosting and assistance, nor did it reveal whether the company paid a fee to be featured on the show last week."
There is a scope difference that matters more than any of that. CRS OSPolicy is a policy administration system. Nothing here rebuts Universal Shield's decision to build one, and the build economics of a rules-and-forms platform are not the build economics of a claims investigation engine. A policy admin system writes structured records into a database the carrier already owns. A claims AI system produces something else, and where that something else lives is the whole question.
What the build case costs when you price it honestly
Answer
How often do insurance core system builds and AI projects fail?
BCG puts failure for large-scale transformations at 74% and prices core IT modernisation at 2% to 4% of non-life gross written premium in capex. S&P Global Market Intelligence found 42% of companies abandoned most of their AI initiatives, up from 17% the year before, with 46% of proofs-of-concept scrapped before production.
BCG published both numbers on 12 January 2026. The 2% to 4% of non-life gross written premium figure is the one that reframes the conversation, because it converts a build from a line item into a capital programme with a board sponsor and a multi-year burn. The 74% failure rate is the honest counterweight to a webinar: it is the base rate the build case has to beat, and it is not a vendor talking point.
The AI-specific numbers are worse and more recent in their trend. CIO Dive reported S&P Global Market Intelligence's survey of more than 1,000 respondents in North America and Europe on 14 March 2025: the share of companies abandoning most of their AI initiatives jumped to 42% from 17% the year before, and the average organisation scrapped 46% of AI proofs-of-concept before they reached production. Those are abandonment rates for projects that had already been funded.
Then there is the unit cost of the team. The US Bureau of Labor Statistics puts the median annual wage for data scientists at $120,230 as of May 2025, with employment projected to grow 35% from 2025 to 2035. A build is a standing hiring commitment in a market that is getting tighter, not a one-time delivery.
Give the build case its wins, because it has real ones. Building is the right answer when the capability is a genuine differentiator you intend to maintain for a decade, when you already run a data science function with production discipline, when the artifact is a record you would own anyway in your own database, and when you can absorb a multi-year programme without the 94% outcome. Universal Shield's policy admin decision sits squarely inside those conditions. Claims AI usually does not, for a reason that has nothing to do with engineering difficulty.
Why licence cost is the wrong thing to compare
Answer
Why is licence cost the wrong way to decide build vs buy for claims AI?
Because a claims AI system produces a regulated artifact. A policy administration system writes records into a database you already own. A claims investigation engine produces a reasoning trail that can exist only inside the vendor's platform, and that trail is part of the claim file a regulator can ask you to reconstruct.
Retention rules are where that becomes concrete. Rhode Island regulation 230-RICR-20-60-4, effective 4 January 2022, states at section 4.6(A) that "a claim file and accompanying records shall be maintained for the calendar year in which the claim is closed plus four (4) years." Section 4.6(A)(1) enumerates what a property and casualty claim file has to contain, and investigation records and correspondence are on the list. Accompanying records is the operative phrase: it is not only the decision that has to survive.
The arithmetic, stated as arithmetic
This is a derivation from two published inputs, not a regulator's finding. Input one: Rhode Island requires a closed claim file and its accompanying records to be kept for the closing year plus four years, so a claim closed in 2026 must be producible through the end of 2030. Input two: a three-year SaaS term signed in 2026 expires in 2029. The retention obligation routinely outlives the contract that created the record, by a year in that example and by more in states with longer floors. Check your own states before setting a retention policy, and check them before signing a term.
That is the structural difference between the two artifacts. Hesper runs 15+ investigation phases in parallel on a claim, and every phase leaves evidence behind: what was pulled, from where, when, and what came back clean. Multiply that across a book and the reasoning trail is larger and more detailed than the claim file it supports. What that record has to contain is worked through in what the claim-file rules asked for before AI. This post is the other half of the same question: who gets to keep it.
Build vs buy claims AI, scored on the dimensions that bite
Answer
Is building or buying claims AI better?
Scored on exit rather than on price, the three options rank differently. Building wins custody of the record and avoids contractual lock-in. Buying wins time to first production decision, maintenance ownership and model refresh. Hybrid, meaning buy the engine and own the record by contract, wins where the artifact outlives the arrangement.
Lamparelli's "buy and build, not buy or build" is the column that wins most often for claims, and the reason is in row two rather than row one. You are not building the investigation engine. You are building, or negotiating, the custody arrangement around it. The cost categories that make a full build expensive are itemised in the hidden integration costs of legacy claims AI, and none of them are the licence.
Two honest notes on row eight. First, the public Guidewire ClaimCenter page promotes developer tools, SDKs and API documentation. It does not address data ownership, export procedures, export formats or post-termination rights, and that is not a criticism: the product page describes integration and the contract describes ownership. Nobody publishes their contract. Second, some lock-in is structural and no clause removes it. ISO ClaimSearch is a contributory cross-carrier database, which means its value comes from being shared. You cannot port a network out of a network, and a buyer who pretends otherwise will negotiate the wrong clause.
Lock-in is almost never a clause saying you cannot leave. It is the four clauses nobody wrote: export format, export window, custody of the audit trail, and what survives termination.
The exit and portability clauses to negotiate before you sign
Answer
What has to be in the contract for you to still hold the record in 2030?
Nine clauses cover it: ownership of the evidence record, export format and completeness, export SLA and API access during the term, transition assistance, survival of access after termination, rights to models trained on your data, deletion and certified return, audit rights and regulatory cooperation, and sub-processors plus escrow.
Every clause below costs a vendor close to nothing to agree before signature and is close to unobtainable afterwards. That asymmetry is the entire negotiating position. It is also why this is a different exercise from the third-party risk review: the review decides whether to proceed, the clauses decide what you are holding in 2030.
Clause four has a drafting benchmark, and it is the only place these terms are written into law anywhere. The European Commission's Data Act fact page and Regulation (EU) 2023/2854 set, in Chapter VI, a mandatory maximum transitional period of 30 calendar days to complete a switch, extendable to a maximum of seven months where it is technically unfeasible, a minimum 30-day window to retrieve data afterwards, erasure of exportable data once retrieved, and the removal of all switching charges including data egress fees from 12 January 2027. The Act has applied since 12 September 2025. A US-only buyer gets none of this by operation of law and all of it by asking.
Clause nine needs a caveat its sellers rarely volunteer. Classic source-code escrow was designed for on-premise software; escrow providers now describe SaaS deposits that include build instructions, deployment configurations and infrastructure credentials, which is a vendor-published description rather than a neutral standard. The escrow agent is itself a third party that can change hands: Iron Mountain's intellectual property management business was acquired by NCC Group in 2021, now trades as Escode, and was sold again in May 2026. "We have escrow" is the start of the question. Who runs the review that tests all nine of these is a separate job, mapped in the procurement and vendor-risk review for AI claims investigation.
What US regulators have and have not said about your vendor's data
Answer
Does any US insurance regulator give you a right to your vendor's data?
Not directly. US insurance regulators have written vendor-oversight and audit-rights expectations and almost no data-portability right. The NAIC model bulletin tells insurers to put audit rights and a regulatory-cooperation duty into third-party contracts. The obligation runs to the insurer, not the vendor, and the contract is where it gets discharged.
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is the governing text, and the cleanest readable primary is a state adoption of it. The Wisconsin OCI bulletin of 18 March 2025 carries the model language on third-party AI systems and data, asking for "the inclusion of terms in contracts with third parties that: a) Provide audit rights and/or entitle the Insurer to receive audit reports by qualified auditing entities. b) Require the third party to cooperate with the Insurer with regard to regulatory inquiries and investigations related to the Insurer's use of the third-party's product or services." Lift that into clause eight and stop paraphrasing it.
The same bulletin lists what a department may request in an AI-focused investigation or market conduct action, and two of those items are your paperwork rather than your model: due diligence conducted on third parties and their data, models or AI systems, and contracts with third-party AI system, model or data vendors. Your vendor contract is itself a producible document, so write it as though someone will read it in an exam.
NYDFS Insurance Circular Letter No. 7, issued 11 July 2024, says much the same on contract terms, asking for provisions that give "audit rights or entitle the insurer to receive audit reports by qualified auditing entities," and it makes the non-delegable point explicitly: insurers are responsible for anti-discrimination compliance "irrespective of whether they themselves are collecting data and directly underwriting consumers, or relying on ECDIS or AIS of external vendors." It also states its own limit, which has to be quoted rather than glossed: "this Circular Letter also is not intended to address phases of the insurance product lifecycle other than underwriting and pricing." Useful as a drafting source, not as claims authority.
Colorado's amended Regulation 10-1-1 took effect 15 October 2025 and reaches individual life insurers, private passenger automobile insurers and health benefit plan insurers using external consumer data and ECDIS-based algorithms and predictive models "in any insurance practice," which is the phrase that makes it claims-adjacent. The honest caveat: its quantitative-testing requirement is an individual-life-underwriting requirement, and it is not a claims-specific rule. For the count of jurisdictions now carrying AI supervisory expectations, we keep that number current in the procurement post rather than restating it here.
Put the two bodies of law side by side and the gap is the finding. The US tells you to supervise your vendor and to be able to answer for what it did. The EU tells your vendor it has to let you leave. Neither one tells a US carrier how long it keeps reading its own claim reasoning after a subscription lapses. That sentence has to be written by the buyer, into the order form, before signature.
Where Hesper lands on this
Answer
What is Hesper's position on data ownership and exit?
Hesper AI is an AI claims resolution platform: agents take a claim from first notice to final recovery with investigation-grade evidence behind every decision. On exit, the posture is that the evidence record belongs to the customer and is exportable, and that Hesper does not train models on customer data.
We would rather be portable than sticky, and the reason is commercial as much as principled: a record a carrier cannot take with it is a record its compliance function cannot rely on. Hesper integrates into the claims system of record - Guidewire, Duck Creek, Majesco and others - rather than replacing it. Claim data is persisted for the subscription term, the security posture is SOC 2 Type I, and built-in fraud detection means Hesper runs standalone or alongside FRISS, Shift and Verisk where a carrier already has them. The operational case is unchanged by any of it: manual SIU investigation runs 14+ days per case against 200+ cases per investigator, coverage of flagged claims moves from 25% to 100%, and the file arrives in hours, not weeks. Evidence behind every decision. Where each stage sits on the claim path is mapped in the guide to automating the claims lifecycle, and the honest way to test any vendor on this post is to ask for the export schema and a sample file before you ask for a price. See how the platform works.
Key takeaways
- The Insurance Nerds panel's control argument is legitimate and the panel had a direct commercial interest in it: Combined Ratio Solutions sells the implementation, hosting and support around its no-licence-fee platform, Universal Shield went live on that platform in April 2026, and Insurance Journal noted the webinar disclosed neither pricing nor whether a fee was paid to appear.
- Building genuinely wins on custody of the record and on avoiding contractual lock-in, and it genuinely loses on time, maintenance and failure rate, with BCG putting large-scale core transformation failure at 74% and S&P Global finding 42% of companies abandoned most of their AI initiatives, up from 17% the year before.
- For claims AI the deciding variable is not licence cost but who holds the evidence record, because a Rhode Island claim closed in 2026 must still be producible through the end of 2030 while a three-year contract signed in 2026 ends in 2029.
- US insurance regulators have written vendor-oversight and audit-rights expectations into the NAIC model bulletin and NYDFS Circular Letter No. 7 but almost no data-portability right, which is why portability has to be negotiated clause by clause rather than assumed.
- The negotiable version of the build-your-own argument is nine contract clauses covering ownership, export format, export SLA, transition assistance, post-termination access, model-training rights, deletion, audit and regulatory cooperation, and sub-processors and escrow.