Zusammenfassung
The insurer is modelled as a constrained optimisation entity under solvency, legal, ESG and operational boundaries, then decomposed into specialised agents for capital, underwriting, claims, compliance and fraud. Human-in-the-loop roles enter through tiered access control, with an orchestrator enforcing regulatory admissibility across the set.
Introduction
In this paper, we develop a theoretical framework to formalise the core institutional functions of insurance companies operating in Austria and Germany. Our objective is to represent these firms as systems of constrained optimisation problems, suitable for implementation via a decentralised multi-agent architecture. We deliberately avoid task-level AI applications and instead focus on the structural transformation of insurance firms into formal agent-based systems governed by economic objectives and regulatory constraints. The analysis is restricted to profit-oriented private insurers, enabling the derivation of objective functions consistent with utility or surplus maximisation under bounded rationality. This work contributes to a foundation for applying advanced AI systems to insurance by grounding agent behaviour in firm theory rather than heuristic rule sets or isolated prediction models.
Institutional Scope: Insurance Markets in Austria and Germany
Austria and Germany constitute two of the most developed and stringently regulated insurance markets in Europe. Both jurisdictions operate under the Solvency II framework, characterised by high market penetration, standardised supervisory practices, and formally codified capital adequacy regimes. The German market includes a significant share of mutuals and public-law insurers, whereas Austria exhibits stronger concentration among private joint-stock firms. Regulatory supervision is exercised by BaFin in Germany and the FMA in Austria, under harmonised EU directives. These institutional similarities—amplified by coercive and normative isomorphic pressures within the EU regulatory field—permit a joint theoretical treatment of profit-driven insurer behaviour (DiMaggio and Powell 1983). Capital requirements and solvency constraints are explicitly quantified under Solvency II, making it possible to model insurance firms as surplus-maximising entities operating under regulatory risk boundaries (Boonen 2017).
Taxonomy of Insurance Firms
Insurance firms in Austria and Germany can be categorised according to ownership structure, legal form, and regulatory mandate. Broadly, three types dominate the institutional landscape: (i) public-law insurers, such as statutory health insurance providers; (ii) mutual insurers, owned by their policyholders; and (iii) joint-stock companies, operating under shareholder control. While all entities are subject to Solvency II and supervised by national authorities, their internal objectives differ substantially. Public-law insurers are typically constrained by statutory duties and fixed benefit structures, with limited discretion over pricing or capital strategy. Mutuals operate under collective ownership, often prioritising member benefits over profit maximisation. In contrast, joint-stock insurers pursue surplus generation under market competition, subject to regulatory capital and risk constraints (Schmeiser and Gründl 2002; Biener and Eling 2012). These differences affect the formalisation of objective functions and admissible decision sets. Given this divergence, the subsequent analysis focuses exclusively on profit-driven private insurers, for which the firm can be modelled as a utility-maximising entity operating under solvency and compliance constraints.
Contribution
This paper contributes a theoretical framework that formalises the core institutional functions of profit-driven insurance firms as constrained optimisation problems grounded in economic theory. Building on established models of utility, risk, and contract theory, we decompose insurer operations into analytically distinct subfunctions aligned with firm-level objectives. These subfunctions are then mapped onto a multi-agent system architecture, in which autonomous agents operate under bounded rationality, institutional constraints, and shared utility goals. Unlike task-oriented AI applications, the proposed structure enables systemic modelling of insurance firms as distributed decision systems, opening a path toward compliant, architecture-level AI implementation in regulated environments.
Formal Modelling of Insurance Firm Functions
The formal behaviour of an insurance company can be represented as an optimisation problem in which the firm seeks to maximise surplus or expected utility, subject to a set of internal and external constraints. The objective reflects the insurer’s economic role as an intermediary that transforms individual risks into collective stability through pooling and capital management. Constraints arise from capital requirements, risk boundaries, and regulatory compliance obligations, which delimit the admissible decision space. In regulated environments such as Austria and Germany, these constraints include solvency directives such as Solvency II, which formalise market-consistent valuation, capital adequacy, and risk-based supervision (Starita and Malafronte 2014; Rae et al. 2017), consumer protection rules under the Insurance Distribution Directive (IDD), which aim to enhance transparency, improve advisory standards, and strengthen product governance in insurance distribution (European Insurance and Occupational Pensions Authority 2022; Werner 2021), and increasingly also algorithmic accountability derived from the AI Act, the GDPR, and ESG-related regulatory frameworks (European Commission 2021; European Parliament and Council 2020). This abstraction reduces the insurance firm to a constrained optimisation entity, forming the analytical basis for decomposing its internal functions into subcomponents represented by decision agents. As a baseline, the firm’s behaviour can be formalised as the following maximisation problem:
In this formulation, denotes the vector of firm-level decisions, including pricing, underwriting, claims handling, investment allocation, and governance policies. The function represents the surplus or profit generated by these decisions, while is the firm’s utility function, potentially reflecting risk-neutral or risk-averse preferences.
The capital adequacy constraint ensures that expected liabilities do not exceed available capital . Risk exposure is formalised via a Value-at-Risk condition at confidence level , such that , where is the firm’s Solvency II risk threshold. The admissible decision space is further bounded by legal and institutional requirements. The legal constraint enforces compliance with supervisory regimes such as the AI Act (European Commission 2021), the General Data Protection Regulation (GDPR), and the Insurance Distribution Directive (IDD) (European Insurance and Occupational Pensions Authority 2022). ESG admissibility is introduced via two distinct constraint sets: denotes environmental eligibility under instruments such as the EU Taxonomy Regulation (EU) 2020/852 (Parliament and Council 2020) and the Sustainable Finance Disclosure Regulation (SFDR) (Parliament and Council 2019), including measurable thresholds like carbon intensity per revenue unit or share of taxonomy-aligned investments. ensures that actions meet minimum social and governance criteria, including metrics such as board diversity ratios, executive pay dispersion, transparency of grievance mechanisms, and policyholder participation in governance. guarantees that all selected actions remain within the firm’s technical and procedural capabilities.
This formulation expresses the insurer’s decision logic as a constrained optimisation problem: maximising expected utility while navigating capital limits, solvency thresholds, regulatory boundaries, and ESG accountability. It reflects the institutional reality that insurance firms are not profit-maximising entities in a vacuum, but regulated intermediaries embedded within a system of legal, financial, and sustainability norms. The constraint structure provides a formal foundation for balancing these competing obligations within an integrated decision architecture. The constrained optimisation problem can be reformulated using a Lagrangian representation, which incorporates the firm’s decision space and associated constraints into a single augmented objective:
In this formulation, denotes the vector of non-negative Lagrange multipliers associated with the respective constraints. The indicator functions take the value 1 when the corresponding constraint is violated, and 0 otherwise. This representation allows each binding constraint to be interpreted as an implicit cost component: a marginal penalty or trade-off that reduces the firm’s attainable utility. The multipliers quantify the shadow price of each constraint — i.e. how much expected utility would improve if that constraint were marginally relaxed.
Put differently, this expression formalises the reality that insurers are not just maximising profit; they are doing so under legal, financial, and institutional boundaries, each of which carries a hidden opportunity cost. The formulation makes those trade-offs explicit and measurable.
This prepares the ground for decomposing the global optimisation problem into analytically tractable subcomponents, each corresponding to a distinct functional domain within the firm. These subcomponents will later be mapped to autonomous decision agents, coordinated within a multi-agent system aligned with the firm’s overall objective.
The formal constraint structure outlined above provides a general decision-theoretic foundation. To refine it, we now examine how different theoretical frameworks contribute distinct modelling perspectives to insurer behaviour. We begin with Arrow’s treatment of risk-bearing institutions. Arrow’s analytical framework interprets insurance as a mechanism for transferring individual uncertainty into collective stability through risk pooling under conditions of incomplete information and risk aversion (Arrow 1963).
Within this view, the firm functions as a utility-transforming intermediary, accepting idiosyncratic risks from clients and aggregating them into diversified portfolios whose outcomes are more predictable at the collective level. Risk-averse agents maximise the expected utility of their final wealth, implying that the insurance contract must improve the expected utility of the insured while maintaining the insurer’s solvency. The firm’s objective thus incorporates a concave utility function, and optimal contract design becomes a question of balancing marginal utility across risk classes subject to regulatory and capital constraints. This foundation legitimises the use of expected utility in the global model and provides a formal link between micro-level risk aversion and firm-level surplus transformation.
Following the expected utility framework established by Arrow (1963), if denotes the insurer’s terminal wealth and the aggregate uncertain claim distribution, the firm solves:
where is a strictly concave utility function reflecting risk aversion, and represents the net realised liabilities from pooled insured risks. This structure underpins the expected utility formulation applied in the global optimisation model.
A second theoretical perspective relevant to insurer modelling derives from principal–agent theory, which formalises the implications of asymmetric information between contracting parties. In insurance, such asymmetries are structural: the policyholder holds private information about risk type (adverse selection) and actions taken post-contract (moral hazard) (Rothschild and Stiglitz 1976). This leads to inefficiencies in underwriting, pricing, and claims settlement, where the insurer must design mechanisms to extract truthful signals or induce appropriate behaviour.
Within the firm itself, principal–agent problems arise in governance structures, where shareholders (principals) must align the actions of executives and operational units (agents) under limited observability and incentive misalignment (Cummins and Weiss 1999). In the modelling context, principal–agent theory justifies the use of informational constraints in the firm’s decision space. These constraints restrict the feasible set of actions not only by regulation and capital, but by the need to maintain incentive compatibility.
The global optimisation problem is thus shaped by contracts and internal mechanisms that ensure delegated decisions align with firm objectives despite decentralised knowledge and interests. Following the principal-agent framework formalised by Rothschild and Stiglitz (1976), an incentive-compatible mechanism can be expressed as:
where is the equilibrium action, is the agent’s utility, and is the agent’s private type. This structure embeds information asymmetry into the admissible decision structure of the firm. Similarly, Nash equilibrium provides the formal language to describe strategic interactions among insurers in competitive markets, as outlined by Dickson and Drekic (2004). Each firm chooses a strategy that maximises its objective given the strategies of others.
This strategic context introduces equilibrium constraints into the firm’s optimisation problem, particularly in areas where regulatory frameworks permit competition under capital requirements and fair disclosure. Premium rates, for example, are not solely determined by loss expectations, but also by competitive pressures and reactions. Similarly, capital allocation and reinsurance retention levels are shaped by the structure of rival firms’ positions. In this setting, the insurer’s feasible set is partially endogenous: constrained not only by internal and external norms, but by strategic stability.
Following the Nash equilibrium framework as applied to insurance markets by Dickson and Drekic (2004), the equilibrium condition can be formalised as:
where each firm maximises its own expected utility conditional on the strategies of its competitors. This condition defines a Nash equilibrium in which no insurer has an incentive to deviate unilaterally from its chosen action.
The three modelling perspectives outlined above—Arrow’s utility-based risk pooling (Arrow 1963), principal–agent theory under asymmetric information (Rothschild and Stiglitz 1976), and Nash equilibrium in strategic competition (Dickson and Drekic 2004)—each contribute distinct structural constraints and behavioural mechanisms to the insurer’s decision space. Together, they represent a layered interpretation of insurance firm behaviour: risk transformation, incentive design, and interdependent strategy selection.
To capture this multidimensional structure, we now introduce a unified formulation in which the firm is modelled as a distributed decision system composed of interdependent subfunctions. This approach allows each theoretical lens to be encoded as a constraint or objective component in a global architecture that reflects the institutional and economic realities of regulated insurance markets. It also provides a formal foundation for decomposing the firm into agent-level components in later sections. We define the unified model as follows:
Here, the firm is composed of subfunctions or decision units, each denoted by index . Each represents a vector of decisions associated with a particular function (e.g. pricing, underwriting, claims). The function denotes the financial contribution of function , which may depend on its own decisions as well as those of other units (interdependencies). is the local utility function, potentially reflecting risk preferences or performance targets. Constraint Eq. 6 ensures local capital adequacy; Eq. 6 imposes incentive compatibility under private information; Eq. 6 enforces strategic consistency in the presence of inter-agent competition or coordination; and Eq. 6 collects external admissibility constraints from regulatory, environmental, governance, and operational domains.
This structure treats an insurance company as a system made up of smaller expert units. Each unit has its own job and goals, but they all work together within a shared set of rules and limits. Some rules come from regulators (like Solvency II or the AI Act), others from the market or the firm’s own governance. The model shows how each part makes decisions, while still aligning with the company’s overall direction. This formalisation sets the stage for implementing a multi-agent system that reflects how real insurers actually function under legal, financial, and strategic constraints.
Functional Decomposition and Agent Architecture
Given the regulatory, confidentiality, and institutional constraints of the insurance sector, we argue that enterprise AI systems must be implemented as proprietary infrastructures rather than built on open, general-purpose platforms. This requirement arises from the intersection of data protection obligations (GDPR), auditability under regulatory supervision (IDD, AI Act), and the need for institution-specific objective functions. Within this context, we propose a decentralised multi-agent architecture as the appropriate system design, in which autonomous decision agents operate under a global regulatory and strategic logic enforced by an overseeing orchestrator agent.
The complexity of modern insurance firms necessitates a modular architecture, where distinct functions operate as autonomous, goal-directed subunits. This decomposition enhances both analytical tractability and system design, particularly when formalising insurer behaviour as a multi-agent system. Each agent is assigned a specific functional role, operating under local decision rules bounded by firm-level constraints. While agents such as underwriting, capital management, and claims settlement act semi-independently, they are coordinated through a global optimisation logic that enforces regulatory admissibility, risk exposure boundaries, and capital adequacy. Human-in-the-loop agents are integrated through a tiered access system, structuring data visibility and decision authority based on user roles, ensuring both regulatory compliance and operational alignment.
In addition to technical operations, the firm must satisfy ESG-related obligations, particularly in the social and governance (S&G) domains. This includes traceable decision accountability, inclusive stakeholder access, and transparent reporting structures. To this end, some agents may not optimise financial flows directly, but rather enforce compliance, track governance metrics, or interface with external actors. Large language models (LLMs) provide a natural interface layer for employee- and client-facing communication, enabling agents to interact with users in transparent, interpretable terms. These LLM-enabled agents can also serve stakeholders such as shareholders or regulators by offering on-demand conversational access to policy logic, performance summaries, and risk assessments. In this setting, natural language becomes both a user interface and a compliance instrument, supporting the broader governance objectives of the firm.
As a profit-oriented institution, the insurance firm seeks to maximise financial surplus subject to internal and regulatory constraints.
Capital Management Agent
The capital management agent is responsible for maintaining solvency while supporting business growth. Its function is to allocate capital across risk-bearing units, ensure compliance with solvency requirements (e.g. Solvency II), and buffer against adverse shocks. The agent does not generate profit directly but enables all other agents to operate within admissible financial boundaries. Its decision problem balances reserve levels, liquidity availability, and capital costs. Formally, the capital agent solves:
Here, denotes the capital buffer allocated by the agent, and is a convex function representing the opportunity cost or regulatory friction of holding capital. is a weighting coefficient that captures the trade-off between safety and efficiency. is the random variable denoting aggregate liability. The solvency constraint Eq. 7 ensures that the probability of insolvency remains below a predefined risk threshold (e.g. 99.5% for Solvency II). Constraint Eq. 7 imposes a reserve floor, and Eq. 7 limits decisions to available financial resources.
In plain terms, this agent decides how much capital the insurer should hold in reserve so that it can stay solvent during bad years, while also not tying up too much money that could otherwise be used for business. It plays a safety role in the system, making sure the company doesn’t fall below legal or supervisory thresholds, while maintaining sufficient financial flexibility to support underwriting and operational activities.
Underwriting Agent
The underwriting agent is tasked with selecting, pricing, and classifying risks submitted to the insurer. Its goal is to accept profitable risks, reject adverse ones, and allocate fair premiums in line with expected losses and capital requirements. This agent faces information asymmetries due to incomplete or biased disclosures by applicants, and must therefore rely on observable indicators or probabilistic models. It interacts closely with the pricing function, fraud detection, and capital allocation. Formally, the underwriting agent solves:
In this formulation, indexes the incoming applications, is the proposed premium, is the stochastic loss for applicant , and is the observable feature vector. is a binary variable that indicates whether the policy is accepted. The agent maximises expected underwriting profit across accepted applications while ensuring that no individual risk exceeds an expected loss threshold and that aggregate accepted risks do not violate the firm’s capital limit under VaR-based solvency requirements.
Put simply, this agent decides which applications to accept and at what premium. It tries to find a balance: avoiding customers likely to generate large losses, pricing correctly for those accepted, and keeping the portfolio within the firm’s risk capacity. It acts as the firm’s first line of financial defence.
Claims Handling Agent
The claims handling agent is responsible for assessing, verifying, and settling claims made by policyholders. Its role is to ensure fair and timely payment of legitimate claims while preventing overcompensation, delay-induced escalation, or exposure to fraudulent activity. It operates under uncertainty due to incomplete documentation and the stochastic nature of claim sizes and timing. It coordinates with the fraud detection agent, legal interface, and capital management unit. Formally, the claims agent solves:
Here, is the payout for claim as a function of latent claim type , which is uncertain at the time of processing. and denote the policy’s minimum and maximum payout obligations. represents cost associated with processing time (which may include penalties or legal escalation). The fraud score is an externally or internally computed index bounded by , above which claims are flagged for additional screening.
In simple terms, this agent manages the decision of how much to pay out and when. It tries to fulfil the firm’s promises to policyholders but must be careful not to pay more than contractually required—or too quickly if the claim appears suspicious. Its job is about fairness, vigilance, and legal correctness under time pressure.
Fraud Detection Agent
The fraud detection agent operates in parallel with the claims and underwriting processes, monitoring for anomalous patterns or inconsistent declarations that may indicate intentional misrepresentation. Its purpose is to identify and flag high-risk cases for further review, thereby reducing exposure to internal and external manipulation. It leverages probabilistic models, anomaly detection algorithms, or learned patterns to assess the integrity of incoming data. This agent is preventive in nature and does not directly affect financial outcomes but modifies the decision space of other agents. Formally, the fraud agent solves:
In this formulation, and represent the expected true and false positives for claim or policy under the agent’s detection regime. is a penalty parameter on false positives to discourage excessive filtering. is a predictive model mapping observable features to a fraud score. Claims or applications are flagged if their score exceeds a risk threshold .
In simple terms, this agent watches for red flags. It uses data to guess which claims or applications might be fake or manipulated. If the score is too high, the case gets flagged for deeper review. It helps protect the insurer from bad actors without blocking genuine customers.
Compliance and Legal Agent
The compliance and legal agent ensures that all internal decisions and external product features adhere to applicable regulations and governance norms. It enforces admissibility under frameworks such as Solvency II, the Insurance Distribution Directive (IDD), the General Data Protection Regulation (GDPR), the AI Act, and ESG-related disclosure rules. This agent does not optimise profit directly, but constrains the action space of all other agents by validating whether decisions are legally and ethically permissible. Formally, the agent implements a filtering operator:
Here, denotes the proposed action from agent , and is the admissible action after legal and ethical screening. The operator enforces exclusion if any rule—legal, environmental, social, or governance—is violated. ESG-S&G includes procedural fairness, transparency, stakeholder inclusion, and traceability of decisions.
In simple terms, this agent acts as the internal regulator. It checks whether actions suggested by other agents—such as new products, capital decisions, or underwriting rules—are legally allowed and ethically sound. If not, the action is blocked. It ensures the company plays by the rules and maintains reputational integrity.
Employee Interface Agent
The employee interface agent serves as a controlled gateway between personnel and the AI-based decision architecture of the insurance system. Its objective is to maximise the individual work utility of each employee by providing context-relevant access to agent outputs—such as those from underwriting, claims, or compliance—while enforcing strict internal control over data visibility, traceability, and policy adherence. Each employee operates within an organisational role , which defines their permitted query set and data access tier. The agent facilitates system interaction through a filtered interface, while ensuring compliance with data protection obligations (e.g. GDPR), internal governance rules, and audit requirements. Formally, the agent solves the following constrained optimisation problem for each employee:
Here, denotes a query submitted by employee , and is the filtered view of the agent system state accessible under role . The global state comprises all structured outputs from other agents. The function is the LLM interface that maps decision-relevant data to human-readable outputs. The utility function reflects the employee’s expected task efficiency or decision quality from receiving this response. Constraint Eq. 12 ensures that the role is authorised; Eq. 12 enforces tier-based data isolation; and Eq. 12 requires that every query is logged, timestamped, and auditable.
In simpler terms, this setup ensures that each employee gets exactly the information they need to do their job—no more, no less. Their role in the company defines what they are allowed to see. All their requests are checked, filtered, and recorded so that sensitive data stays protected and everything remains transparent and traceable. To operationalise the tiered system, the agent applies a conditional access mapping:
This structure ensures that only admissible query–role combinations produce responses. For example, a call centre employee might access only claim-level summaries or policy status updates, whereas compliance officers can view audit logs, and executives are granted high-level system metrics and inter-agent coordination summaries. Role hierarchies are enforced dynamically through the internal access control engine, which references and monitors all activity under . In functional terms, the employee interface agent enables precise, lawful, and productive human-AI interaction across the organisational hierarchy.
Put simply, the system checks who is asking and only gives an answer if the person’s role allows it. A junior employee might see only the basics needed for their task, while senior staff get broader insights. Everything is filtered automatically so that access always matches the person’s position and responsibility in the company.
Stakeholder Interface Agent
The stakeholder interface agent manages external access to the AI system by institutional and individual actors such as policyholders, regulators, auditors, shareholders, and business partners. Each stakeholder class is assigned a predefined visibility tier based on its contractual position, regulatory entitlement, or information rights. The agent ensures that external queries are resolved within lawful, contract-compliant, and context-specific boundaries, reflecting obligations under ESG-S&G standards—particularly explainability, procedural fairness, and inclusive governance. The objective of the stakeholder interface agent is to maximise the relevance and interpretability of information provided to authorised external users, without breaching confidentiality or exceeding regulatory limits. Each stakeholder is mapped to a visibility tier, which governs their admissible query set and contextual scope. Formally, the agent solves:
Here, is a structured query submitted by stakeholder , and is the set of queries permitted at that stakeholder’s access level. is the filtered agent context available to that tier, constrained by , the complete internal state. The function maps internal decisions into legally intelligible responses, adapted to jurisdiction, stakeholder contract, and purpose. The expected utility function captures the relevance and decision-usefulness of the returned information. Constraint Eq. 14 enforces access authentication; Eq. 14 restricts data exposure; and Eq. 14 ensures full supervisory traceability.
In simpler terms, this agent answers stakeholder questions using only the data they are legally allowed to see. It ensures that every external user—whether a customer, regulator, or investor—receives information that is relevant to their role, without exposing internal logic or private data. All interactions are tracked and audited to ensure lawful and accountable communication.
Stakeholder queries are processed under a conditional access mapping, where each stakeholder is assigned to a predefined access tier that determines which parts of the system they are permitted to view. This tiered structure reflects legal rights, contractual roles, and regulatory status, ensuring that each query is resolved only within the boundaries of the stakeholder’s assigned level.
This logic guarantees that each authorised stakeholder receives precisely the subset of information necessary for their role. A policyholder can access personal contracts, coverage parameters, and claim status. A regulator is entitled to solvency compliance data, ESG indicators, and audit trails. A shareholder may view profitability breakdowns, capital allocation, and long-run portfolio structure. Smart contract enforcement and role registries dynamically govern access rights under .
Put simply, this rule acts like a smart filter. Only stakeholders with proper authorisation receive tailored answers to their questions. Everyone else gets nothing. This prevents unauthorised access and ensures that each user sees only what they are meant to—no more, no less.
Client Service Agent
The client service agent governs interactive access for existing policyholders, enabling personalised communication regarding policy coverage, claim progression, premium adjustments, renewals, and contractual terms. Its objective is to maximise customer clarity and decision-readiness while ensuring that all disclosures remain compliant with legal, contractual, and data protection boundaries. Each client is associated with a current contract, a policy data record , and a visibility tier based on policy status and jurisdiction. Formally, the client service agent solves:
Here, is a query submitted by client , and is the set of permitted queries under their active contract. The variable represents their personalised policy attributes (e.g. coverage limits, deductibles, renewal terms), while includes dynamic operational information such as claim updates or payment schedules. The LLM interface converts structured internal data into accessible, legally compliant responses. The utility function reflects perceived information value, clarity, and support for action by the client. Constraints Eq. 16 and Eq. 16 limit visibility to entitled content only, while Eq. 16 ensures that all exchanges are auditable.
In simpler terms, the system checks whether a person is a valid, active customer and then tailors the response based on their contract. It helps them understand their rights, monitor their claims, and make informed choices—while keeping a clear record of every request and answer. To implement this logic, the agent applies a conditional access mapping:
This structure ensures that only currently entitled policyholders receive access to personalised, contract-linked information. The visibility scope depends on the client’s policy type, current status (e.g. in-claim, pending renewal), and applicable legal protections. For example, a health insurance client in an open claim may query reimbursement timelines, while a property policyholder near renewal can request premium comparisons. The filtering logic reflects a tiered access model tied to dynamic contract context and compliance policy.
Put plainly, this agent acts like a personalised digital advisor: it checks if someone is still an active client and then answers questions based only on what they are allowed to see. It keeps things clear, relevant, and legal—without ever showing what doesn’t belong to them.
Client Acquisition Agent
The client acquisition agent is responsible for engaging potential customers, mapping product offerings to prospect profiles, and pre-filtering applications for underwriting relevance. It operates upstream of the underwriting agent and integrates with marketing, pricing, and legal modules. Its role is to generate qualified leads, screen suitability, and deliver regulatory pre-contractual information in accessible language. The agent is constrained by marketing compliance rules and fairness requirements under anti-discrimination directives.
Formally, the agent implements a pre-qualification mapping:
Here, contains declared or inferred features of a potential customer (e.g. age, location, coverage needs), and maps these features to a product recommendation , subject to legal filters (e.g. no discriminatory profiling, marketing restrictions). The agent also exposes LLM interfaces for interactive product comparison, consent dialogue, and onboarding FAQs.
In effect, this agent serves as the public face of the firm’s system, converting prospects into compliant applications. It educates, filters, and prepares the ground for underwriting by delivering structured pre-application guidance, all while ensuring that acquisition processes are transparent, equitable, and regulatorily compliant.
System Orchestrator Agent
The system orchestrator agent serves as the supervisory layer responsible for ensuring global consistency, strategic alignment, and institutional coherence across all subordinate agents. It oversees multi-agent coordination, verifying that local decisions—while independently optimised—collectively satisfy the legal, financial, and operational constraints of the organisation. The orchestrator does not perform direct optimisation; instead, it acts as a global validator of admissibility, equilibrium, and inter-agent alignment. Formally, the orchestrator monitors whether the system-wide agent state respects both the global objective structure and admissibility envelope:
Its role is to verify system-wide admissibility and consistency and to authorise or reject execution based on validation:
The orchestrator integrates several supervisory mechanisms to enforce institutional coherence. First, it performs constraint propagation across agent boundaries, ensuring that local admissibility conditions do not conflict when aggregated at the system level. Second, it verifies role-permission consistency across agents, maintaining uniformity in how organisational roles are mapped to actions and data access within different subsystems. Third, it monitors for cross-agent conflicts—such as contradictory objectives, redundant actions, or mutual constraint violations—and triggers resolution logic when necessary. Finally, the orchestrator aligns internal agent decisions with external supervisory expectations and the firm’s strategic objectives, ensuring that the AI system acts in accordance with institutional goals and regulatory mandates.
It may override, veto, or delay decisions that would introduce institutional incoherence, constraint violations, or regulatory breaches. While the legal/compliance agent enforces rule-level admissibility for individual actions, the orchestrator governs **system-level integration** and strategic consistency. LLM modules attached to this agent may generate system summaries, policy explanations, or audit statements for institutional stakeholders (e.g. board, regulators).
In simpler terms, this agent makes sure that the AI system behaves like one coordinated organisation—not a set of disconnected bots. It checks that all decisions fit together, follow the rules, and support the company’s overall strategy before anything gets executed.
Unified Agent System and Communication Logic
To complete the agent-based system architecture, we introduce a unified optimisation structure that integrates both internal decision agents and human interface agents within a single analytical expression. This formulation provides a consistent basis for verifying system-wide admissibility, equilibrium, and institutional alignment. It enables the orchestration layer to assess the joint admissibility of all agent actions and user queries before any execution occurs. The integration of human-in-the-loop components into the agent architecture does not require the introduction of a separate communication agent. Instead, the dedicated interface agents—employee, stakeholder, and client—already serve as structured access points under role-based governance. These agents enforce strict admissibility rules through data filtering, role-tier mappings, and audit logs. Their outputs are routed through the System Orchestrator Agent, which validates whether all resulting actions and queries cohere with the institutional constraints of the firm. This routing logic preserves modular clarity while avoiding the control fragmentation that would result from parallel coordination layers. Introducing an additional communication core would dilute accountability, obscure institutional logic, and conflict with the compliance-by-design principles underlying the system. Formally, the global optimisation problem can be written as:
Here, denotes the action vector of internal agent and is the agent-specific decision function, potentially dependent on the actions of other agents. The function measures the expected utility of the action, incorporating performance, compliance, or risk-based criteria. Each query is submitted by a human-facing interface agent and evaluated through a large language model applied to a filtered context , drawn from the global agent state . The function captures the informational or operational utility returned to the user. The admissibility conditions restrict each internal action to the intersection of legally, environmentally, socially, and operationally permitted domains. Interface queries must be issued under valid role authorisations , conform to data access constraints, and remain fully traceable. The orchestrator confirms that the combined set of actions and queries is admissible, non-contradictory, and institutionally consistent.
In simple terms, this equation brings all agent decisions—both machine-made and human-triggered—into one system-wide logic. Each agent tries to do its job well, and each user-facing agent responds only within allowed limits. Nothing proceeds until the orchestrator has checked that every action and answer fits together without breaking any legal or operational rule. This avoids having too many control layers and ensures the AI system behaves like one coherent institution.
Protocols and Agent Integration in Enterprise AI
The deployment of multiple agents in enterprise AI arises from the functional decomposition of insurance firms into distinct domains—capital allocation, underwriting, compliance, and claims handling—each governed by specific constraints, data privileges, and decision logic. Decentralisation alone is insufficient. To ensure coherence, regulatory admissibility, and shared utility optimisation, agents must be coordinated via protocol layers that standardise context propagation, state transfer, and inter-agent reasoning. This necessitates interoperability frameworks such as the Model Context Protocol (MCP) and Agent-to-Agent (A2A) messaging standards. Enterprise AI systems operate asynchronously across heterogeneous components with divergent compute schedules, partial observability, and uneven access to real-time data. Synchronous coordination introduces latency and fragility. Asynchronous architectures mitigate these issues by decoupling data availability from execution. Tadi (Tadi 2022) shows that asynchronous data handling enhances Progressive Web Application robustness, supporting offline operation and non-blocking updates—critical for agent continuity in intermittently connected environments. At the training level, asynchronous federated learning enables model updates without central synchronisation (Hou et al. 2024a), reinforcing system resilience. Beyond architectural theory, empirical studies demonstrate that agent communication latency increases with message size and agent count. Berna-Koes et al. (Berna-Koes et al. 2004) show that message delays can grow non-linearly in multi-agent networks unless efficient backchannel protocols are implemented. Further, in delay-sensitive coordination tasks, latency-aware communication models such as DACOM (Yuan et al. 2022) significantly enhance performance by adapting decision logic to inter-agent delays. Lei et al. (Lei et al. 2022) provide a framework for synchronising asynchronous perceptual features in collaborative systems, improving agent robustness in high-latency environments. In regulated domains such as insurance, empirical auditability standards further constrain system design. The UK Financial Conduct Authority requires AI systems to provide traceable decision logs within 24–72 hours of execution (Authority 2022). The Financial Stability Board emphasises the importance of explainability and audit resilience to manage systemic risks in AI-driven financial services (Board 2017). These empirical thresholds reinforce the need for persistent state management and protocol-level memory that can support post-hoc review under institutional supervision. The Agent-to-Agent (A2A) protocol, introduced by Google, standardises inter-agent messaging across frameworks such as LangGraph, CrewAI, and AutoGen by defining shared syntax for intention, memory, and task state. A2A allows agents built in distinct runtime environments to exchange structured content—decisions, delegation requests, alerts—while decoupling role semantics from implementation. In heterogeneous enterprise settings, where agents vary in logic paradigms or regulatory models, A2A enables coordination between, for example, an LLM-based compliance module and a rule-based pricing agent. As noted in (Analytics Vidhya Editorial Team 2025), A2A promotes composability by providing a shared abstraction for communication, aligning objectives under constrained interoperability. While A2A addresses syntactic and messaging compatibility, the Model Context Protocol (MCP) governs semantic coherence and memory persistence. MCP structures context propagation and state retention, enabling agents to reason over shared histories, hierarchical goals, and environmental signals. Krishnan (Krishnan 2025) highlights MCP’s capacity to encode long-range dependencies, allowing agents to retain mission-critical knowledge—e.g., regulatory thresholds, prior decisions, or user interactions—vital in financial or legal workflows. MCP functions as the institutional memory layer, necessary for consistency, justification of contingent decisions, and compliance transparency. Narajala and Habler (Narajala and Habler 2025) further underscore MCP’s role in auditability, enabling ESG alignment and AI Act compliance by preserving reasoning chains and allowing decision context replay. A2A and MCP are not substitutes but complements: A2A ensures technical interoperability and communication reliability; MCP secures semantic alignment and persistent memory. Together, they constitute a dual-stack foundation for robust, auditable multi-agent systems. Protocol-level design is thus not a technical convenience but a regulatory and operational necessity. The Agent-to-Agent (A2A) protocol, introduced by Google, standardises inter-agent messaging across frameworks such as LangGraph, CrewAI, and AutoGen by defining shared syntax for intention, memory, and task state (Google Developers 2025). A2A allows agents built in distinct runtime environments to exchange structured content—decisions, delegation requests, alerts—while decoupling role semantics from implementation. In heterogeneous enterprise settings, where agents vary in logic paradigms or regulatory models, A2A enables coordination between e.g., an LLM-based compliance module and a rule-based pricing agent. As noted in (Analytics Vidhya Editorial Team 2025), A2A promotes composability by providing a shared abstraction for communication, aligning objectives under constrained interoperability. While A2A addresses syntactic and messaging compatibility, the Model Context Protocol (MCP) governs semantic coherence and memory persistence. MCP structures context propagation and state retention, enabling agents to reason over shared histories, hierarchical goals, and environmental signals (Hou et al. 2024b). Krishnan (Krishnan 2025) highlights MCP’s capacity to encode long-range dependencies, allowing agents to retain mission-critical knowledge—e.g., regulatory thresholds, prior decisions, or user interactions—vital in financial or legal workflows. MCP functions as the institutional memory layer, necessary for consistency, justification of contingent decisions, and compliance transparency. Narajala (Narajala and Habler 2025) further underscores MCP’s role in auditability, enabling ESG alignment and AI Act compliance by preserving reasoning chains and allowing decision context replay. A2A and MCP are not substitutes but complements: A2A ensures technical interoperability and communication reliability; MCP secures semantic alignment and persistent memory. Together, they constitute a dual-stack foundation for robust, auditable multi-agent systems (Hou et al. 2024b; Google Developers 2025). MCP ensures that agent interactions are contextually meaningful; A2A ensures they remain operable across environments.
Protocol-level design is thus central to enterprise AI. The insurance architecture proposed here builds upon this dual-protocol paradigm, combining asynchronous operation with explainable, persistent decision memory to meet institutional and regulatory demands.
Conclusion
This paper presents a formal architecture for implementing enterprise AI in regulated insurance firms, grounded in firm theory, constrained optimisation, and institutional logic. The insurer is modelled as a structured decision system subject to solvency constraints, legal admissibility, ESG obligations, and internal feasibility limits. This framework enables a principled decomposition of the firm’s behaviour into analytically distinct subfunctions aligned with regulatory and strategic demands.
A multi-agent architecture defines each functional domain—capital management, underwriting, claims, and compliance—as a bounded rational agent operating within a shared constraint environment. Local decision models integrate directly into the firm’s institutional structure, ensuring that optimisation occurs strictly within admissible legal, financial, and ESG boundaries.
An orchestrator agent enforces system-level coherence, validating inter-agent alignment, propagating global constraints, and maintaining institutional consistency. Protocol-level infrastructures such as asynchronous coordination, memory persistence, and semantic interoperability via MCP and A2A support structured communication across heterogeneous agent modules.
This framework advances the structural modelling of regulated firms by embedding regulatory, operational, and governance constraints into the decision logic itself. Unlike conventional models that treat compliance as an external layer, this architecture integrates institutional constraints into core decision processes, forming a foundation for building auditable, compliant AI systems in high-stakes institutional domains where formal accountability and systemic coherence are essential.