An actuary can build an artificial intelligence (AI) agent over a weekend, but understanding it may take longer than building it. The standards do not ask who built the model, only whether the signing actuary can explain it and identify what would make it wrong. Generative AI has made building the model easy; governing it remains the harder task.
By "understanding" we mean something specific and testable: The signing actuary can explain why the model does what it does, predict what it will do on a case not yet run, and state what would make it wrong, even if they do not understand every line of code. This creates a gap between what is built and what is understood, one that can widen as systems evolve, ownership changes, and documentation drifts.
The same issue underlies the build-versus-buy question in this new AI agent world. What matters in regulated work is not the cost of building, but the cost of staying able to defend it. An organization may wish to buy the AI agents that must operate inside the governed platform and remain defensible over time: the ones that read your model code, retrieve governed method knowledge, and leave a reproducible audit trail. Conversely, organizations may choose to build the agents that reflect their own experience, assumptions, and narrative.
Regulators will continue to redraw where this applies, and none of it changes the test. Accountability does not transfer with a software contract, and it does not sit with the tool. Whatever the frameworks say in five years, someone still has to put their name on the number and be ready to explain it.