Blog
Oct 1, 2026

Build, Buy, or Partner: The Strategic AI Decision Facing Insurers

Est.
min read
Upcoming Event
-

Build vs. buy is an old question. AI changed the answer. Here is how four insurance leaders draw the line, from a panel at ITC Vegas 2026.

What do we build, what do we buy, and what do we partner on? That question was at the center of a conversation at ITC Vegas 2026 with Sai Vishnubhatla (USAA), Richard Pluschau (Falcon Risk Services), Itai Ben-Zaken (Honeycomb Insurance), and ZestyAI's own Founder and Chief Product Officer Kumar Dhuvur, moderated by Eugenio Gonzalez of Plug and Play.

The discussion made one thing clear: AI does not fit neatly into the traditional build-vs.-buy playbook. Models and capabilities are evolving quickly, specialized talent is difficult to scale, and insurers face growing expectations around transparency and governance. Just as importantly,

How do insurers decide what AI to build in house?

The panelists approached the build decision differently, but each came back to the same underlying question: is this capability important enough to justify owning it over the long term?

At USAA, that starts with a three-part litmus test. Sai Vishnubhatla said the company considers whether a capability is already commoditized, whether it has the talent to build it internally, and whether that talent will still be relevant as the technology evolves. That last point is especially important in AI, where models and capabilities are changing quickly. Building something in house is not just a question of whether you can develop it today, but whether you can continue to support, govern, and improve it over time.

That is also why USAA does not think about the decision simply as build versus buy. Vishnubhatla described the preferred relationship as an ally: a partner that brings expertise while helping the internal team become more capable in the process.

For Falcon Risk Services, the decision is shaped heavily by the operational burden that comes with ownership. Richard Pluschau noted that companies of different sizes will naturally draw the line in different places. Falcon, for example, has no interest in owning and operating a data center or taking on the staffing required for 24/7 uptime and support. What matters more is retaining IP and control over the capabilities that are strategically important, without taking on infrastructure the company does not need to own.

Honeycomb Insurance takes a similarly strategic view, but from the perspective of a disruptor. Itai Ben-Zaken said the key question is whether the company truly needs to own a capability. Honeycomb would rather buy something that already exists than recreate it internally, but that comes with an important counterweight: if the company buys too much of what makes the product distinctive, does it risk giving up its own differentiation?

Kumar Dhuvur framed the decision in terms of prioritization. A carrier may have 20 things it could build, he said, but choosing to build one means deciding that it belongs among the organization’s top one or two priorities. If it does not rank that highly, building it internally is difficult to justify.

And the commitment does not end when development is complete. Maintenance means continuing to add capabilities as the technology evolves, not simply keeping the system running. For models that touch rating, that commitment can also include navigating regulatory approval across multiple states.

What costs does the build business case leave out?

When the panel turned to total cost of ownership, time to value, and ROI, the discussion surfaced several costs that are easy to underestimate in a build business case.

Operationalization is one of them. Falcon's Richard Pluschau pointed to master data management as an example. The upfront cost of building the capability is visible, but the longer-term costs of governance, data quality, support, and service-level expectations can be much harder to account for. As Pluschau put it, if you build it, you "better damn well have the mechanisms in place to support it."

Regulatory approval can be another major factor. ZestyAI's Kumar Dhuvur noted that if a model affects rating or underwriting, the business case has to account for the regulatory process as well. That can add a year or more before the model begins producing value. A vendor that already has direct standing with regulators through a rating and advisory organization may have already absorbed much of that work across states.

Then there is time itself. USAA's Sai Vishnubhatla called it the most valuable resource in the room, while Pluschau noted that Falcon is willing to give up some flexibility if it means getting to value faster. The point was simple: the business outcome matters more than owning every part of the solution.

Vishnubhatla added an important caveat. Even when an insurer chooses to buy or partner, the investment should still leave the organization stronger. The internal team should learn from the work and build new capabilities along the way. A partner that does all the thinking may deliver a solution, but it does not necessarily make the carrier more capable. That is another reason USAA prefers the word ally.

Dhuvur brought the discussion back to the core question: is this capability central enough to the product to justify building it yourself? If not, the fastest path to value may be to partner rather than build.

What should insurers demand from an AI vendor?

Honeycomb's Itai Ben-Zaken framed the decision around a useful question: what can we afford not to do on our own? The answer helps insurers preserve internal resources for the capabilities that truly differentiate them, while looking to partners for areas where ownership creates less strategic value.

But choosing to partner is not the same as simply buying a license. Much of the discussion focused on what a durable AI partnership actually requires, particularly when the technology becomes embedded in critical business processes.

Start simple and build trust over time. ZestyAI's Kumar Dhuvur recommended beginning with straightforward, API-based integrations, allowing both the value of the partnership and the trust behind it to grow over time.

Keep the roadmaps aligned. Falcon's Richard Pluschau highlighted the risk of a carrier and vendor gradually moving in different directions. A vendor may expand broadly while the carrier needs greater depth in a particular area. Avoiding that divergence requires transparency on both sides and regular conversations about where each roadmap is headed.

Test for reliability and plan for continuity. Ben-Zaken pointed to reliability, hallucination rates, business continuity planning, and rigorous testing before AI reaches production. Because replacing an embedded partner can be costly and disruptive, insurers need to evaluate not only how a solution performs today, but how resilient that relationship will be over time.

Protect ownership and access to data. Pluschau emphasized the contractual protections that become critical in a long-term partnership, including concentration risk, code escrow, and clear data transfer agreements. As he put it, "That's our inventory." If a carrier ever needs to move to another provider, its ability to retain and transfer that data matters enormously.

Finally, a true partner should be willing to share accountability for the deployment. USAA's Sai Vishnubhatla argued that vendors should co-own the risk rather than simply deliver the technology and step away. That extends to governance as well: it should be built into the relationship and the product from the beginning, not treated as a compliance exercise added later.

That distinction — between providing technology and sharing responsibility for its success — is ultimately what separates an AI vendor from an AI partner.

Where does AI differentiation actually come from?

A recurring theme across the discussion was that differentiation does not come from the model alone. It comes from how effectively the organization is set up to use it.

USAA's Sai Vishnubhatla made that point through the lens of the operating model. USAA can build or buy almost anything, he noted, but the more important question is whether the organization is ready to put that technology to work effectively. Without the right processes around it, even a strong model can end up layered onto an inefficient workflow rather than improving it.

Falcon's Richard Pluschau made a similar point with a familiar hierarchy: people, process, and technology — in that order. Technology comes last because the value of the tool depends on the organization around it.

That aligns closely with what we see at ZestyAI. The carriers that get the most value from property risk models are not simply the ones with strong data science teams. They are the ones that have changed how underwriters, agents, and pricing actuaries use risk insights in day-to-day decisions. The model matters, but the operating model determines how much value it creates.

What are insurers missing in AI vendor evaluation?

One of the final points raised in the discussion was that many insurers still evaluate AI too broadly. ZestAI's Kumar Dhuvur noted that carriers often use a single AI questionnaire for technologies as different as computer vision, machine learning, and generative AI, even though each comes with different considerations.

That means the questions should change depending on the technology: where and how it is being used, which external stakeholders may care about that use, and how the vendor will adapt as regulatory and governance expectations evolve.

It is a useful way to frame the broader build, buy, or partner decision. The question is not simply who writes the code. It is which capabilities and risks an insurer wants to own, which it is better positioned to share, and whether the organization is ready to put the technology to work.

FAQ: Build, buy, or partner for AI in insurance

Should insurers build, buy, or partner for AI?
Insurers should generally reserve in-house development for capabilities that are strategically important enough to justify the talent, maintenance, governance, and regulatory burden that comes with ownership. For other capabilities, buying or partnering can provide faster access to specialized expertise, proven technology, and ongoing support without requiring the insurer to build and maintain everything internally.

What is the difference between buying AI and partnering with an AI vendor?
Buying typically means acquiring access to a technology or capability. A strong partnership goes further, with shared roadmaps, ongoing collaboration, knowledge transfer, governance support, and greater accountability for how the technology performs in practice. For insurers, that can be especially important when AI becomes embedded in underwriting, pricing, or other critical decisions.

What costs are often missed in an AI build-vs.-buy analysis?
Development cost is only part of the equation. Insurers also need to account for ongoing model maintenance, data governance, support and service levels, specialized talent, regulatory filings, and the opportunity cost of internal teams. A partner with established infrastructure, domain expertise, and regulatory experience may already have absorbed many of those costs.

How can regulatory approval affect an in-house AI model?
For models used in rating or underwriting, regulatory review can materially extend the path to value. Insurers should factor in not only development time, but also the work required to support filings, explain model methodology, respond to regulators, and maintain approvals across states. Working with a partner that already has regulatory experience can reduce that burden and accelerate deployment.

What should insurers look for in an AI partner?
Insurers should look beyond technical performance alone. A strong partner should offer reliability, clear data ownership, business continuity planning, roadmap transparency, governance support, and the ability to evolve as regulatory and business requirements change. The strongest relationships also help the insurer build internal capability rather than simply outsourcing the work.

Where does AI differentiation come from in insurance?
The model itself is only part of the advantage. Differentiation comes from how effectively an insurer integrates AI into its people, processes, governance, and decision-making. The right technology partner can help accelerate that integration while allowing the insurer to focus internal resources on the capabilities that are most strategic to the business.

The build, buy, or partner decision ultimately comes down to where an insurer creates the most value by owning a capability itself — and where the right partner can accelerate progress.  

ZestyAI's Risk Decision Platform brings together property-level data, AI models, and agentic AI capabilities to help insurers make faster, more informed decisions across underwriting, pricing, risk management, and regulatory strategy.

See how insurers are putting ZestyAI to work.

No items found.