Skip to content
AI & Finance

Hiscox's 6,000 AI agents test an insurer's oversight rules

Hiscox staff have built over 6,000 AI agents via Microsoft Copilot. The scale raises UK questions about accountability, data access and third-party risk that existing FCA rules already cover.

By

Published
A towering filing cabinet with dozens of unlabelled drawers, one pulled open and overflowing with loose paper slips.

Employees at Hiscox, the specialist insurer, have collectively built more than 6,000 AI agents using Microsoft Copilot and Copilot Studio, according to a Microsoft UK case study published on 24 September 2026. Hiscox employs around 3,500 people, so the reported agent count exceeds the headcount. That does not mean every worker has built one, or that all 6,000 remain active.

The tools sit inside underwriting, claims, finance and human-resources teams, and Hiscox calls the approach "Citizen AI". James Jackson, the insurer's Data Culture and AI Lead, said the model puts building tools directly in the hands of underwriters, claims professionals and support staff rather than routing every request through a central technology team.

For UK financial services, the case matters less as a productivity story than as a test case. Hiscox is a regulated insurer, and the scale reported here raises a straightforward question: can its own inventory, permission and audit controls keep pace with how quickly staff can build these tools? That gap, between what employees can build and what a firm can see, control and account for, is the story here, not the headline number.

What Hiscox employees have actually built

The published examples are modest in scope. Paul Lawrence, Chief Underwriting Officer for Hiscox London Market, said a tone-of-voice agent saved six or seven hours while helping prepare two board reports. Microsoft said a workflow built by trading manager Jack Gargrave cut a task from around three hours to about 20 minutes. Other agents extract contact information from emails.

These are internal productivity tools: drafting aids, formatting helpers, information extractors. They are not, on the evidence available, systems that price risk, accept or decline cover, settle claims or communicate directly with policyholders. Microsoft describes the agents as able to "complete" tasks rather than simply hold a conversation, but the published examples involve drafting and standardisation work that plausibly remains subject to human review. Nothing in the case study establishes a common level of autonomy across the full set of 6,000, and no evidence shows any employee-built agent taking actions that affect a customer's policy, claim or payment.

Hiscox colleagues reportedly estimate average savings of two to five hours per week, and Jackson estimated that returned productive time and avoided costs had passed seven figures. Neither the currency, the measurement period nor the calculation method was disclosed, so that figure should be read as a self-reported estimate rather than an audited saving.

The citizen-development bargain

Letting staff build their own tools has an obvious appeal: it surfaces repeated business problems quickly. Hiscox treats several employees independently building agents for the same task as a signal that a shared, better-engineered tool is needed. The email contact-extraction agents are one example of this escalation from individual build to a specialist-led project involving data-science, technology, cyber and risk staff.

The same dynamic creates the problems Hiscox itself names: duplication, weak observability across a sprawling estate, governance gaps, and the risk of unsafe access to proprietary or confidential information. A workforce of 3,500 producing more than 6,000 agents implies, on average, close to two tools per employee. The real distribution is unknown, though, since Hiscox has not published how many agents are active, shared, production-approved or connected to any customer-facing process, nor how it defines an "agent" for counting purposes.

How Hiscox says it governs the estate

Hiscox says higher-risk uses go through a process it calls RAISE, which it describes as being refined so that scrutiny increases with assessed risk. The insurer is also introducing Microsoft Agent 365, intended to give central visibility across assistants and agents, identify duplicates and flag potentially risky builds.

Both statements are meaningful commitments, but both are also incomplete as public evidence. Hiscox has not published the RAISE risk taxonomy, its approval thresholds, which committee or role owns escalation decisions, or what testing a higher-risk agent must pass. The Agent 365 rollout is described as being introduced, not completed, so it is not established what proportion of the existing 6,000 agents it can discover, what happens to agents built outside Microsoft's environment, or whether coverage was complete as of the case study's 24 September 2026 publication date.

The UK regulatory position

There is no standalone FCA rulebook for artificial intelligence. The Financial Conduct Authority (FCA) says it does not currently plan additional AI-specific regulations and instead applies its existing principles-based, outcomes-focused framework. That framework still bites: senior-manager accountability rules under the Senior Managers and Certification Regime remain relevant wherever a regulated firm deploys AI, and the FCA has said this accountability applies regardless of the technology involved.

Operational-resilience rules apply directly to insurers. They came into force on 31 March 2022, and in-scope firms had until 31 March 2025 to be able to remain within impact tolerances for their important business services. Where a specific Hiscox entity is in scope of these rules, any employee-built agents that support a service it has identified as important would need to be considered and managed as dependencies within that entity's operational-resilience arrangements, rather than sitting outside them by default.

Crucially, the FCA has said that using a critical third party does not remove a firm's accountability, nor that of its board and senior management, for operational resilience or compliance with outsourcing requirements. That principle is relevant to Hiscox's reliance on Microsoft, though no evidence reviewed for this article establishes that Microsoft or the specific services Hiscox uses have been designated as a critical third party under the UK regime as at 25 September 2026. The reported 6,000 agents were built using Microsoft Copilot and Copilot Studio; Hiscox is separately introducing Microsoft Agent 365 to give it central visibility and management across that estate, though it is not established that this rollout is complete. Relying on Microsoft's technology, in any of these forms, does not remove Hiscox's accountability, or that of its board and senior management, for how those tools are permissioned, monitored and controlled, regardless of who supplied the underlying technology.

An independent Financial Services AI Adoption Plan, published by HM Treasury on 14 July 2026, found that firms across the sector still struggle to understand how existing UK rules apply to AI and, specifically, to agentic AI use cases, and recommended clearer, joined-up regulatory guidance. That finding is a useful frame for Hiscox's position: the obligations already apply, but firms report genuine difficulty translating them into day-to-day controls over exactly the kind of employee-built, distributed tooling Hiscox has scaled.

Why the Microsoft dependency matters

The employee-built agent programme Microsoft describes runs on one supplier's platform, though it is not established whether Hiscox also has agents built outside that environment. That concentration raises questions that sit squarely within existing UK expectations around third-party and outsourcing risk, even though the packet reviewed for this article did not establish whether Microsoft or the specific services Hiscox uses have been designated as a critical third party under the UK regime. Those questions include what happens if Copilot, Agent 365 or an underlying model changes behaviour or becomes unavailable, how access to policyholder, claims, broker and commercially confidential data is restricted per agent, and what audit trail exists for prompts, data sources, outputs and approvals.

None of these questions has a public answer in Hiscox's own disclosures so far. That is not evidence of a compliance failure — it is evidence that the public record has not yet caught up with the pace of internal adoption.

Putting 6,000 in context

Hiscox's scale is unusual, but rapid AI uptake across UK insurance is not. The Bank of England and FCA's 2024 survey of 118 regulated firms found that insurance recorded the highest sector adoption rate, at 95% of insurance respondents already using AI. Across all 118 respondents, 75% already used AI and a further 10% planned to within three years.

Measure (2024 BoE/FCA survey, published 21 November 2024)Figure
Firms already using AI75% of 118 respondents
Insurance-sector AI adoption95% of insurance respondents
Use cases involving some automated decision-making55%
Fully autonomous use cases2%
Firms with a named accountable person for their AI framework84%
Firms reporting only partial understanding of the AI they use46%

The same survey found that accountability for AI was commonly split across multiple people or bodies even where a named accountable person existed, and that data privacy, quality, security, bias and representativeness dominated firms' perceived current risks. That sector-wide pattern is relevant background for reading Hiscox's case. It shows why named, singular ownership of a distributed agent estate is a live industry problem, but it is not evidence about Hiscox's own compliance position, incident history or risk profile, none of which was disclosed in the material reviewed for this article.

What is not known

Several questions remain open on the public record. It is not established how many of the 6,000 agents are currently active, how many have been approved for production use, or what proportion touch any process connected to underwriting, claims or customer communication. The RAISE process's specific thresholds and the individuals or committees accountable for escalation decisions have not been published. No incident or customer-harm data was disclosed in the case study, so rapid adoption should not be read, on its own, as evidence of a control failure, only as a gap in what has so far been made public.

What to watch next

Two things will tell readers more than Microsoft's case study can. The first is whether Hiscox publishes further detail on Agent 365's coverage once deployment is complete, including how much of its agent estate the system can actually discover and govern. The second is the FCA's incident-reporting and material third-party notification requirements, due to take effect on 18 March 2027, which will sharpen what insurers must tell the regulator when technology dependencies go wrong. Readers wanting the underlying regulatory detail should consult the FCA's own pages on its AI approach and on operational resilience, rather than relying on any commercial account of a firm's compliance position.

Sources

  1. AI and the FCA: our approach (opens in a new tab)

    Financial Conduct Authority · Accessed

  2. Operational resilience (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. Financial Services AI Adoption Plan (opens in a new tab)

    HM Treasury · · Accessed

  4. Artificial intelligence in UK financial services - 2024 (opens in a new tab)

    Bank of England and Financial Conduct Authority · · Accessed

  5. FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience (opens in a new tab)

    Financial Conduct Authority, Bank of England and HM Treasury · · Accessed