Published: August 21, 2026 • 11 min read

Why CNA Insurance Started Its Agentic AI Rollout with Governance

agentic governance insurance

Enterprise AI strategy is still being written. Few organizations know yet which capabilities will matter or which pilots deserve to become products, and planning around individual use cases tends to lock in answers before the questions have settled. However, data governance offers a surer path: a way to give that strategy real structure, anchored in repeatable business outcomes, so leaders can move fast but not carelessly.

McIntosh is VP of Global Data Operations at CNA Insurance, one of the largest commercial property and casualty insurers in the United States. With more than twenty years' experience spanning roles at Accenture, Nationwide, and Travelers, she now leads a global team at the intersection of data governance, analytics, and third-party data across the US, UK, Europe, and Canada.

In a recent episode of AI Radicals, she joined host Satyen Sangani to unpack what a first year of moving at "feverish pace" looks like when AI arrives at the same time you do, and what it really takes to make governance work at scale.

The trust problem hiding inside every data challenge

McIntosh traces her conviction about trust to a moment early in her career, sitting down with a group of adjusters in a claims organization to talk through their processes and their reports. "Everybody kinda had some different interpretations, slightly different numbers, and it was that inconsistency that really struck," she recalled. Nobody was doing anything wrong. They were doing what people do when the official source of truth stops feeling reliable: they built their own. Each person had learned which version to trust based on their own experience, and that, as McIntosh put it, "became the system of finding the right pieces of information that helped their story."

"This isn't just a data problem, and it wasn't just a reporting problem, and it wasn't just a technology problem," McIntosh told Sangani. "It was a trust problem." And the lesson she carried forward was stark: once trust in data is gone, people don't stop working. As she put it, they build their own version of reality and navigate by it.

That insight shapes everything McIntosh has built at CNA. Usable data, in her definition, starts with accessibility, meaning the data can actually be consumed in the format it arrives in, whether structured or unstructured. From there it runs straight into the tenets of governance: is the information accurate, is it quality, is it timely, and do people trust it? Have we governed it appropriately, do we understand what we're capturing, and should we be using it for this purpose at all? Data quality and trust sit at the foundation of everything built on top, including AI.

A year of moving fast: From eight BI tools to an AI-ready platform

McIntosh arrived at CNA eleven months ago in one of the organization's first truly global data roles, with a mandate to integrate governance with security and architecture across continents. The pace she set was deliberate: "Lace up your sneakers. We're gonna go at speed."

In the first year, her team delivered a full BI modernization globally, taking eight reporting tools across the organization and streaming that down to use the right technology where it matters. They also established discipline around third-party data. CNA makes significant investments in external data assets, and the team focused on getting traceability and usage properly documented.

Now the focus is AI. CNA is building an AI-enabled reference data platform, laying the groundwork for AI-enabled governance, and working on how to get an organization ready to actually consume AI products. Governance is a natural starting point, she noted, because it has historically been process-based, and process lends itself well to agentic execution.

The build-versus-buy calculus has shifted underneath all of it. "If you asked me three months ago would we build certain capabilities ourselves, I would tell you absolutely not," McIntosh said. "Go to the market and buy a solution." What changed is the tooling: coding agents, OpenAI, and similar technologies have forced a pause and a genuine reconsideration of whether buying is still the obvious answer. "That has changed substantially," she said, describing her team as rewriting the playbook in real time. The answer today is a blend: partner in most places, and stand up internal pods to build capabilities where that makes sense.

Reimagining underwriting instead of replicating it

Working with partners including Alation and Accenture, CNA is applying AI across underwriting and claims, but McIntosh is careful about what that means. In underwriting, the team is looking at everything from submissions to pricing strategies, essentially anything that would normally hit an underwriter's desk. In claims, the question is how to get insights to adjusters faster so they can work from better information. The goal in both cases is not to replicate existing processes at higher speed. "It's not just about process automation. It really is that reimagination."

In practice, that means embedding technical and non-technical team members directly alongside business partners in pod structures. They sit together, identify the actual problem, prototype rapidly while fully prepared to throw the result away, and then, if the idea shows richness, bring in an implementation team to harden it.

Working outcome-first has unlocked something significant: the freedom to question steps that exist only because they always have. "Do you really have to go through all those steps that we historically were doing?" McIntosh challenges her own team on the same question she poses to the business. If a step doesn't contribute to the outcome, why is it there?

The pace of this prototyping is genuinely new. Work that used to take three months now takes a day, two days, three days. The volume of what can be produced has changed the game, which is exactly why McIntosh emphasizes time boxing and a clear definition of done. Speed without intentionality is dangerous: "You can get down a rabbit hole very quickly, and if you have incorrect information, you can get in a bad spot very quickly."

The distinction between automating a decision and improving one

Sangani raised a distinction he credits to McIntosh, and her answer was crisp enough to be worth repeating: there is a difference between automating a decision and improving one.

Automation, she explained, is fundamentally about speed, getting through the decision process as fast as possible. Improvement is something different: "Can I bring additional information? Can I bring additional insights? Can I arm the individual with better information to make those decisions at scale?"

The financial case flows from that distinction. Automation gets you efficiency, and in McIntosh's view that alone doesn't improve the financial picture of the organization. Improve the quality of a decision rather than just its pace, she argues, "then I'm gonna actually win in the marketplace."

McIntosh is equally clear-eyed about how ROI gets measured, or misattributed. Data organizations don't operate independently, and data for the sake of data doesn't solve a problem. The value gets produced in concert with the underwriting, claims, and operations functions the data team serves, so the real ROI shows up in reduced cycle times, improved underwriting decisioning, and better customer experiences in claims. Anchoring on those business outcomes is the only measurement frame that holds up, and the harder question her team is still working to answer is the cost of getting it wrong: what are the implications of poor quality data when AI is consuming it at speed?

Agentic governance: Throwing out the playbook

Perhaps the most striking portion of the conversation centers on governance, and McIntosh's conviction that the way it has historically been practiced needs to be discarded.

The critique she hears is familiar to anyone who has worked in the field. "You've talked about governance for a long time now. Nothing's really changed in the governance space," is how she summarized it, along with the follow-up questions about how it will actually work, scale, and improve. Governance organizations have failed along the way, she acknowledged. The adage that governance is slow and bureaucratic has been earned. Stewardship is a hard job, and after about two years, stewards typically move on to other things, which leaves a sustainability problem behind them. Adoption has met resistance because governance reads as a burdensome task.

CNA's response is to stop depending on humans and process for work that agents can execute at scale. The vision McIntosh described is a cockpit for stewards, a centralized view where lineage, quality signals, metadata, and compliance information converge instead of sitting in scattered technologies that never came together holistically. Alation's data catalog and lineage are a key piece of that infrastructure, she noted, with the subcomponents brought together so smarter decisions can be made on top of them.

Sangani pushed on the obvious objection. CNA is in the business of pricing risk, and AI is stochastic. How does a conservative industry justify handing governance to agents? McIntosh's answer starts from an honest accounting of the baseline: in the spaces where an organization isn't governing today, there's nothing to disrupt. "So the risk of doing something is better than not doing anything in this space," she said. "And I really hate saying that, but that's really where we're at." The scope matters too. These agents run in internal governance channels, not customer-facing ones, which makes it a relatively safe place to start. Human direction comes first, with the ability to toggle it back as confidence builds.

Three areas are the immediate targets. The first is stewardship and data ownership, where agents can assist stewards or, in some cases, become them. The second is compliance, where agents can help interpret documents like GDPR and secrecy acts and guide the team through them. The third is engaging the catalog to serve up quality insights that guide stewardship, rather than waiting for a steward to go looking.

"Our intent is that while we'll have human in the loop, human on the loop, but eventually the agents will be driving a lot of our governance," McIntosh said, with those agents surfacing insights strong enough for other agents to act on, including anomalies in the data and anomalies in the marketplace. The end state is governance that runs continuously, with human judgment applied where it adds the most value rather than where it's the only option available.

The future of BI, and what comes next

On the future of business intelligence, McIntosh's answer splits in two. Insurance will still need structured reporting, the standardized monthly and quarterly packages where pixel-perfect information is simply how the business operates. Visualizations, dashboards, and ad hoc analysis are a different story, and that's where she expects significant change. Her caution is shaped by hard experience. She remembers when PowerPoint decks were supposed to die, replaced by Power BI and Tableau. That didn't happen. Organizations move slower than the technology implies they should.

Still, she sees genuine change ahead in ad hoc analysis, natural language querying, insight generation, and graphical recommendations. CNA is already piloting copilot technologies that let people who were never exposed to development tools build their own dashboards, a culture shift that moves development capability closer to the business. The AI-for-BI push comes next quarter.

The same modernization work is where McIntosh sees feedback loops forming, around semantic models and the consumption of data products. Her team keeps getting asked whether agents could review data product development or BI reports. Her answer reframes the question entirely: "You could, but why not just have it develop it for you the right way from the beginning?" Write to the process and the standard on the first pass, and the review step stops being necessary. What will determine adoption isn't the tool's quality but the trust in the data underneath it: "It all comes down… to do you trust, and is the data behind those tools consistent? How you're interacting, and do we get deterministic responses from the tools?"

As for the road ahead, McIntosh declined to forecast five years out, reasonably, given that the foundation feels less like solid ground and more like a dust storm shifting month to month. The eighteen-month horizon is clear: get the global governance body stood up and running agentically, then see what the next wave of capability makes possible.

Her quick-hit closing answers deserve to stand on their own. The most dangerous misconception about AI is that it's a technology. The thing companies should stop immediately is focusing on a pilot instead of thinking about how to scale a solution. The biggest waste of time and money is seeking perfection instead of progress. And the belief about governance that's simply wrong? That it's slow. "Good data governance is actually effective. Bad data governance is actually slow and burdensome."

Curious to learn how Alation's data catalog and governance capabilities can support your AI readiness strategy? Book a demo with us today.


Frequently asked questions about agentic AI in insurance

What is agentic AI in insurance?

Agentic AI describes systems that carry out multi-step work on their own initiative instead of waiting for a prompt at each step. In insurance, that looks like agents pulling a submission, verifying it against internal and third-party data, flagging exceptions, and handing a decision-ready package to an underwriter or adjuster. The distinction that matters operationally is authority: what the agent is permitted to initiate on its own, and which calls stay with a person.

What is agentic data governance?

Agentic data governance applies AI agents to governance work itself, including maintaining metadata, monitoring data quality, interpreting policy, and surfacing anomalies before anyone goes looking for them. Erin McIntosh, VP of Global Data Operations at CNA Insurance, is building toward this at a global commercial P&C carrier, describing a cockpit for stewards where lineage, quality signals, metadata, and compliance information converge in a single view rather than sitting in disconnected tools. Her stated intent is that agents eventually drive much of the governance program, with humans in the loop and on the loop.

Can AI agents replace data stewards?

In some cases, yes, and CNA is starting there deliberately. McIntosh's first target for agentic governance is stewardship and data ownership, creating agents that assist stewards and, where it works, become them. The driver is sustainability rather than headcount: stewardship is a hard job, stewards typically move on after about two years, and governance programs spend their lives restarting. Human judgment stays where it adds the most value instead of where it is the only option available.

How does agentic governance support NAIC AI compliance?

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers asks carriers to maintain a written AI Systems Program covering senior-management and board accountability, risk controls, model validation and testing, and oversight of third-party AI.¹ More than 20 jurisdictions had adopted it by mid-2026, and a multistate pilot of the NAIC's AI Systems Evaluation Tool now gives examiners a structured way to review those programs during market conduct exams.² The practical consequence is that AI governance claims have to be evidenced, which is where documented lineage, metadata, and data ownership stop being hygiene and become exam material.

  • AI
  • Active Data Governance
  • Customer Stories
  • Data Governance
  • Digital Transformation
  • Modern Data Stack

Keep reading

More from the data desk

  • Supply Chain Analytics: Turning Fragmented Data Into Real-Time Visibility

    AI

    Supply chain analytics fails when data has no shared meaning. How four global supply chains built real-time visibility,…

  • Snowflake Alation partnership - blog hero

    Snowflake Intelligence and Alation: Why the Best AI Answers Need Both

    Active Data Governance

  • data abstract (data residency)

    Introducing Critical Lineage: End-to-End Lineage for Regulatory Filings and Critical Reports

    Active Data Governance

  • legal consideration of ISO 42001

    ISO 42001: The AI Compliance Certification Guide For Enterprise Leaders

    Data Governance

    ISO/IEC 42001 is the first international standard for AI management systems (AIMS) , published December 2023. It…

Let us help you get it right.