Insurance AI
D

Duck Creek Technologies

Duck Creek is one of the two enterprise core platforms property and casualty insurers actually run on, and this record grades the agentic layer it built on top of that position. The core suite covers policy, billing, claims, rating, loss control, reinsurance, distribution management and payments, delivered through its OnDemand cloud service on Microsoft Azure, with the company repositioning itself from a system of record to what it calls an intelligent core.

The artificial intelligence line launched on 28 April 2026 as an insurance native agentic platform for deploying, orchestrating and governing agents across the insurance lifecycle, alongside two first applications, an Agentic Underwriting Workbench and an Agentic First Notice of Loss experience. The architecture is described in named layers covering intelligence, orchestration and governance, with traceability and auditability built in and the chief executive stating human in the loop explicitly. Two technical claims are more specific than this category usually offers: neuro symbolic reasoning as the mechanism letting agents operate inside carrier workflows and regulatory constraints, and a proprietary insurance domain ontology giving them context.

Two architectural choices are worth noting because they cut against incumbent instinct. The data foundation integrates natively with the company's own systems of record and is stated to support integration with other core systems, meaning a carrier on a competitor's core can still use it. And the gateway layer is an open framework with a marketplace and registry supporting the model context and agent to agent protocols, so agents built by the company, its partners or its customers connect on published standards.

Named customers span specialty, global and regional carriers across four continents. The company holds analyst quadrant leader standing and publishes an unusually complete trust surface, including obtainable certification and audit documents and a whitepaper on European operational resilience requirements.

Founded 2000, headquartered in Boston, and owned by Vista Equity Partners since 2023.

Last VerifiedAugust 25, 2026
Compare Duck Creek Technologies with other vendors
Founded
2000
Headquarters
Boston, Massachusetts, United States
Categories
insurance-ai
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 10 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

A core platform with an agentic layer added in April 2026, and the launch material describes the relationship precisely. The platform is stated to leverage existing customer data, manuscripts, configurations and interfaces, to support embedded and headless deployment while preserving prior technology investments, and to embed intelligent automation directly into core insurance workflows. Every one of those phrases describes something placed on top of a system that already works.

Remove the models and what remains is the business: policy administration, billing, claims, rating, loss control, reinsurance, distribution management and payments, all deterministic and all predating the agents by decades. The company's own repositioning acknowledges the direction of travel, contrasting competitors that merely cloud host legacy logic with its own architecture unifying data, workflows, automation, governance and artificial intelligence, but a system of record described as a system of intelligence is still a system of record with intelligence attached.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Human in the loop stated at chief executive level and supported by architecture, with the marketplace leaving the same accountability question this index has recorded elsewhere. The commitment is explicit rather than implied, with the chief executive describing agents that operate with full context, governance, traceability and human in the loop, and governance named as one of the platform's architectural layers rather than a feature within one.

Traceability means an agent's actions can be reconstructed, which is the precondition for meaningful oversight. Two things hold it below the top band. Neither of the launch applications publishes a boundary: an agentic underwriting workbench and an agentic first notice of loss experience both sit at decision points affecting applicants and claimants, and nothing states what an agent may complete unattended or what a person must approve. And because the gateway hosts agents built by partners and customers alongside the vendor's own, nothing describes what governance obligations attach to an agent the vendor did not build.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Architecture described, performance not measured. On the transparency side the disclosure is better than most: the technique is named as neuro symbolic reasoning combined with insurance specific models and a proprietary domain ontology, the platform layers are enumerated, and traceability and auditability are stated as built in controls rather than aspirations, which gives a carrier's model risk function something to interrogate. What is absent is any number.

Across two passes no accuracy figure, error rate, validation methodology, benchmark, sample or observation period was located for the platform or either launch application, which is unsurprising four months after launch but leaves a buyer with nothing to assess.

The one large figure in the launch material belongs to someone else and describes the market rather than the product, being a consultancy's projection of up to 80 billion dollars in annual artificial intelligence impact across United States insurance, and should not be mistaken for a result.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Strong evidence for the platform, thin evidence for the artificial intelligence line this record grades. On the platform side customers are named across tiers and continents, including a large specialty insurer, a Bermuda based global specialty carrier whose global chief information officer appears on the record, a South African group, a Canadian carrier, a European assistance business and two United States regionals, with analyst quadrant leader standing and a partner ecosystem independently cited at more than 2,000 integrations.

Ownership by a major software investor and a customer conference with an analyst panel drawn from three named research houses add further external validation. On the agentic side the record is early: the platform launched in April 2026 with no named customer, no quantified outcome and no adoption figure.

The single artificial intelligence award cited is a hackathon run by the company's own private equity owner among its portfolio companies, which is an internal competition rather than industry recognition and should not be read as the latter.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Governance treated as architecture rather than as a policy statement, with one technical claim that would matter if evidenced. The platform is described in named layers including a governance layer, with built in controls for traceability and auditability, and the launch positions the whole product around transparent, auditable and extensible decisioning.

The technical claim is neuro symbolic reasoning, presented as the mechanism allowing agents to operate within existing carrier workflows and regulatory constraints. That is a meaningful thing to claim, because a symbolic component can encode a rule an agent must not violate in a way a purely learned system cannot, and combined with a proprietary insurance domain ontology it describes constraint by construction rather than by instruction.

It is asserted without technical detail, evaluation or demonstration. Absent across two passes: model card, evaluation methodology, red team result, incident disclosure and acceptable use boundary for either first party or marketplace agents.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

Four named regulatory regimes across three continents, each with a document behind it, which is broader published coverage than anything else in this lane. The cloud service is stated to support the European data protection regulation, the Australian prudential regulator's standards, and the payment card security standard at the self assessment level for service providers, with an attestation document listed as obtainable.

A whitepaper on the European operational resilience regime for financial entities is published separately. Architectural commitments are specific rather than general, including encryption with customer specific security keys, continuous threat monitoring, and a documented shared responsibility model setting out which controls belong to the vendor and which to the carrier, which is the artefact a buyer's risk function actually needs.

What is absent is the American financial privacy statute, which is not named anywhere, along with any retention schedule or subprocessor list, and nothing separately describes what data the agents may access.

Security Certifications and Trust Center
AA on Security Certifications and Trust CenterCertifications named with their type and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

The strongest security disclosure located in this lane and among the best in this index, because the documents themselves are obtainable rather than the credentials merely asserted. A dedicated trust page is structured into overview, shared responsibility, physical security, security operations, architecture, compliance and resources.

Credentials are named specifically: the international information security management standard, annual independent audits of both service organisation control types at the second level, and the payment card security standard at the self assessment level for service providers. Annual risk assessments and internal audit are stated.

Crucially the artefacts are enumerated and reachable, covering a security whitepaper, the certification document, both audit reports, the card attestation and an operational resilience whitepaper, downloadable by existing customers and partners from a solution centre and available to others on request from a published security address. That is a working route to evidence rather than a badge.

One drafting inconsistency belongs on the record: the trust page describes the offerings as compliant with the information security standard while the product page describes them as certified, and those are different claims.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

No licence, and the broadest published regulatory engagement in this lane. Three regimes are supported and documented rather than mentioned: the European data protection regulation, the Australian prudential regulator's standards for outsourced material business activities, and the payment card security standard with an attestation obtainable.

The distinguishing item is a published whitepaper on the European operational resilience regime for financial entities, which is a substantive position on a regime that makes information technology suppliers to European insurers part of their customers' regulatory perimeter, and almost no vendor graded in this index has published one. Multi country platform layers and a stated commitment to the London specialty market indicate the same regulatory literacy applied commercially.

The conspicuous absence is the newest regime and the one closest to this record: no position on the European artificial intelligence regulation was located, despite the company shipping agentic underwriting into European markets where insurance risk assessment is designated high risk.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Governance here answers questions about process and record, not about whether outcomes fall evenly. Everything published concerns traceability, auditability, orchestration and control: whether an agent's actions can be reconstructed, which workflows it may enter, and that a human remains in the loop. Those are real and well specified. None of them addresses fairness. The exposure sits in both launch applications.

An agentic underwriting workbench shapes decisions about who is offered cover and on what terms, and an agentic first notice of loss experience shapes how a claim is characterised at the moment it is reported, which influences everything downstream for the claimant. Across two passes no bias testing, fairness metric, disparate impact analysis, model card or conformity assessment under the European artificial intelligence regulation was located. The neuro symbolic architecture could in principle support fairness constraints expressed symbolically, and nothing published indicates whether it does.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

A service level agreement exists and is referenced publicly, which lifts this above the vendors in this index that publish nothing, and it covers the wrong thing for this axis. The company states that its commitment is backed by a service level agreement structured for around the clock availability, disaster recovery and dynamic growth in business capacity, and disaster recovery commitments appear in the trust material. Those address whether the platform runs.

Across two passes no warranty, indemnity, liability cap or terms of service was located, and nothing addresses whether the platform was right. The uncovered exposure is specific to the new products: an agentic underwriting workbench that shapes who is offered cover and an agentic first notice of loss experience that shapes how a claim is characterised both produce consequences for applicants and claimants who are not the customer.

And because partner and customer built agents run inside the same gateway, nothing published describes how responsibility divides when an agent the vendor did not build causes harm inside its governance layer.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

More technical disclosure than this category usually offers, with the model provider itself left unnamed. On the disclosed side: the cloud and infrastructure partner is named, with that partner's own financial services general manager appearing on the record about the collaboration; the reasoning approach is named as neuro symbolic rather than described vaguely as artificial intelligence; a proprietary insurance domain ontology is identified as the context layer; and the interoperability protocols are named as open standards, which tells a buyer exactly how third party components attach.

The marketplace and registry make the existence of partner and customer built agents explicit rather than presenting a monolithic platform. What is not disclosed is whose foundation models sit inside the agents. No provider, family or version is named for the learned component, and no supply chain information at all attaches to the partner agents that can run in the same environment, so a carrier adopting one inherits a dependency it cannot see.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

Two architectural choices here work against the vendor's own commercial interest, which is what earns the grade. First, the data foundation integrates natively with the company's own systems of record and is explicitly stated to support integration with other core systems, so a carrier running a competitor's core can still adopt the agentic layer. A core vendor building its newest product to work on rival cores is deliberately declining a lock in it could have taken.

Second, the gateway layer is an open integration framework with a marketplace and registry supporting the model context protocol and agent to agent protocol by name, meaning agents built by the vendor, its partners or the carrier itself connect over published open standards rather than proprietary interfaces. Naming those protocols is unusually forward for enterprise insurance software.

Around them sit a partner ecosystem independently cited at more than 2,000 integrations, embedded and headless deployment options, and explicit anti lock in positioning. Counter evidence belongs on the record: analyst peer reviewers describe the data architecture as difficult for integration and analysis.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

A documented cloud model with a named hyperscaler and a genuine shared responsibility artefact, short of an explicit residency commitment. The cloud service runs on Microsoft Azure, named openly, and the trust material publishes a shared responsibility model setting out which controls the vendor holds and which remain with the carrier, which is the document a third party risk function needs and which most vendors in this index never produce.

Availability, disaster recovery and capacity growth are stated as covered by a service level agreement. Support for the Australian prudential standards and European data protection implies regional processing capability, and multi country platform layers indicate localisation work. The agentic platform adds deployment flexibility on top, supporting embedded and headless models so a carrier can adopt it inside existing workflows or alongside them. What is missing is specificity: across two passes no named region list, explicit residency commitment or tenancy description was located.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No price, unit or tier is published for the core suite or the agentic platform, and two passes across the company's site, its press archive, marketplace listings and third party directories produced nothing. The company has been privately held since 2023, so no financial reporting substitutes for it.

What independent review data does supply is a consistent warning rather than a number: analyst peer reviews record implementation cost, timeline and complexity as the most common negative themes for this vendor, and separately note that version upgrades with heavy customisations frequently take many months and require expert assistance. That is a real total cost of ownership signal for a buyer, and it comes from customers rather than the vendor.

For the agentic platform specifically, nothing indicates whether it is licensed separately from the core, whether it is available to carriers running a competitor's core despite being stated to integrate with other systems, or how marketplace agents from partners are charged.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Genuine international and segment breadth within property and casualty, evidenced by named customers rather than claimed. The roster spans a large United States specialty insurer, a global specialty carrier, a South African insurance group, a Canadian property and casualty company, a European assistance and travel insurer, and United States regional and specialty carriers, which covers personal, commercial and specialty lines across four continents.

Product depth reaches the whole operating estate rather than one function, covering policy, billing, claims, rating, loss control, reinsurance, distribution management and payments, so a carrier can run its core operations from one supplier. Recent expansion is directed at markets requiring local adaptation, with multi country layer enhancements and a stated commitment to support the London specialty market. Two limits: the scope is property, casualty and general insurance only, with no life or health lines, and no customer count is published for any market.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface for the core suite or the agentic platform
Not published on any vendor surface. The estate spans policy, billing, claims, rating, loss control, reinsurance, distribution management and payments, delivered through a cloud service and available on a standalone or full suite basis, with an agentic platform and two agentic applications layered above it, and nothing published indicates whether charging follows premium under management, policies in force, transactions, modules, seats or a platform subscription. The stated availability of solutions individually or as a suite indicates modular commercial packaging without describing the basis, and no marketplace pricing is published for partner built agents. No tiered data protection terms are published, and commitments are made at platform level with documents obtainable rather than sold by tier. The cloud service is stated to support the European data protection regulation, the Australian prudential standards and the payment card security standard, with encryption using customer specific security keys and continuous threat monitoring. A shared responsibility model is published setting out which controls sit with the vendor and which with the carrier. Obtainable documents include a security whitepaper, the information security certification, both service organisation control reports, the card attestation and an operational resilience whitepaper. No retention schedule or subprocessor list was located, and nothing separately describes what data the agents may access. No implementation, configuration or professional services fee is published, and independent evidence indicates this is the largest cost variable in the decision. Analyst peer reviewers identify implementation cost, timeline and complexity as the most frequently raised negatives, and describe version upgrades involving heavy customisations as taking many months with expert assistance required, which is the recurring cost of ownership rather than a one off. The company's own positioning addresses that history directly, marketing an evergreen cloud model intended to eliminate upgrades and reduce technical debt, and a customer statement published by the vendor describes the cloud service as removing the burden of platform and infrastructure upgrades and template updates. For the agentic platform specifically the design intent is minimal incremental work for existing customers, since it draws on their current data, configurations, manuscripts and interfaces, and supports embedded or headless adoption without displacing prior investment. None of it is quantified or priced. Vendor Published

Two passes across the company's site, its press archive, marketplace listings and third party directories produced no price, unit or tier for the core suite or the agentic platform. The company has been privately held since 2023 so no financial reporting fills the gap.

What independent review data supplies instead is a consistent cost warning from customers rather than a figure: analyst peer reviewers record implementation cost, timeline and complexity as this vendor's most common negative themes, and separately note that version upgrades with heavy customisations frequently run to many months and require expert assistance.

For a core platform decision that is arguably more useful than a licence price, because the implementation and upgrade burden usually exceeds it. Three questions remain open on the agentic platform, all of them commercial: whether it is licensed separately from the core, whether carriers on a competitor's core can buy it despite the stated cross core integration, and how marketplace agents built by partners are charged.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746