Blog & newsroom BlogRegulation

Open insurance is coming the way open banking did: slowly, then by regulation

Yasmina EditorialEditorial team15 August 20266 min read

Europe’s FiDA framework would make insurers share customer data through APIs on request. What open insurance means, why regulators are pushing it, and what the GCC should take from the story.

Open banking followed a predictable arc: banks ignored it, resisted it, were regulated into it, and then discovered the ecosystem it created was where growth lived. Insurance is now at the start of the same arc. "Open insurance" — customer-permissioned sharing of policy and claims data through standard APIs — has moved from discussion papers into draft European law, and the direction of travel matters well beyond Europe.

What open insurance actually means

At its core: your insurance data belongs to you, and you can direct your insurer to share it — with another insurer for a better quote, with an adviser for a coverage review, with an app that shows every policy you hold in one dashboard. EIOPA, the EU's insurance supervisor, has been studying exactly such use cases for years, including the "insurance dashboard" — a single view of all of a customer's policies across providers.

The EU's Financial Data Access framework (FiDA) is the legislative vehicle. In its proposed shape it extends open-banking-style data access across financial services, insurance included: firms would need to expose customer-permissioned data through APIs to licensed "financial information service providers," under a consent and liability regime that legal analysts are still mapping onto insurance's messier data. Scope and timelines have shifted through the legislative process — final obligations remain a moving target — but the political commitment to the principle has survived every redraft.

Why regulators want it

The supervisory logic is consistent across markets. Data portability attacks the inertia that keeps customers in poorly-fitting products. Comparison gets easier, switching gets easier, and the market's discipline improves. Regulators also get something subtler: standard APIs create standard audit trails, and a supervised data-sharing regime is far easier to police than screen-scraping and PDF email chains.

The lesson open banking already taught

The first-order prediction — customers rushing to switch banks — mostly didn't happen. The second-order effect changed everything: standard APIs made banking data available to products, and embedded finance was built on that availability. Expect the same shape here. The dashboard app is the demo; the durable consequence is that quoting, claims history and coverage verification become programmable primitives that any product can build on. Open insurance is, in that sense, embedded insurance's supply chain.

Reading it from the GCC

Nothing obliges Gulf regulators to copy FiDA, and none has. But the regional trajectory rhymes: Saudi Arabia and its neighbours pushed open banking frameworks early and aggressively, and the Kingdom's insurance supervision is consolidating under an Authority with a clear digital-distribution agenda. A market that already runs unified health-insurance data flows and mandatory motor databases has, in practice, several of open insurance's rails already laid. Platforms building embedded journeys in the region should treat customer-permissioned data access as the direction of regulatory gravity — and design consent, logging and data minimisation as first-class features now, not as retrofits when the circular arrives.

What to do about it

  • If you are an insurer: inventory which customer data you could expose cleanly today. The gap is your integration debt, and it is now measurable.
  • If you are a platform: build consent UX as carefully as checkout UX. Permissioned data is a feature only when the permission feels honest.
  • If you are neither: watch FiDA's final scope and the first GCC consultation that cites it. The second one is the starting gun.
Open insuranceRegulationAPIsEurope