EST. LOS ANGELES · READ WORLDWIDE
AUGUST 2026 · VOL. X
InsurTech.me
Where insurance, technology, and capital meet
← ALL EPISODES
EPISODE 167 · INSURTECH TALKS AUG 11, 2026 · GILAD SHAI

Jeppe Nørregaard, Founder & CEO of InReality

WATCH ON YOUTUBE · ALSO ON SPOTIFY

Stop Trying to Detect Fakes. Prove What’s Real Instead.

Jeppe Nørregaard spent seven years trying to build AI that could detect lies. He started with a simple, almost naive ambition: could AI analyze a political debate in real time and flag when someone was lying?

What he found instead, working across two universities in Denmark and RPI in upstate New York, was that AI was far more useful for the other side. It got better at generating misinformation faster than it got better at catching it. He sat next to researchers trying to deepfake Barack Obama before deepfakes were a mainstream concern. He watched automated bot networks flood social platforms years before most people had heard the term misinformation. He knew where this was heading, and it was, in his words, a bit depressing.

So he flipped the entire problem. Instead of spending energy chasing what’s fake, InReality proves what’s real — cryptographically, at the point of capture, before content ever enters a claims pipeline, a newsroom, or a court record.

In Episode 167 of InsurTechTalk, Jeppe walked me through why he believes detection is a fundamentally losing strategy, how post-quantum cryptography actually works, and why he wants insurance fraud numbers to keep rising rather than fall.

About Jeppe Nørregaard

Jeppe Nørregaard is the Founder and CEO of InReality, a content authenticity platform based in Copenhagen, Denmark. He holds a PhD in AI and spent roughly seven years in academic research on misinformation detection before founding InReality with co-founder Alicia Scott. InReality is backed by Antler and is a member of Deloitte’s Innovation Accelerator. The company is a contributing member of C2PA, the industry coalition working on content provenance standards, and is currently developing what may be one of the first post-quantum secure signing methodologies for live video streaming.

From Detecting Lies to Giving Up on Detection Entirely

Jeppe’s origin story starts with frustration, not ambition. He was drawn to AI and language processing because he was tired of watching politicians lie to each other in debates, in Denmark and internationally, with no real accountability. The early vision: AI that could analyze arguments live, flag inconsistencies, warn people in real time when they were being misled.

What he learned instead reshaped his entire career. AI was extraordinarily good at generating convincing fake content and comparatively weak at reliably catching it. That imbalance is not temporary. It is structural — and it is the exact argument that separates InReality’s approach from the deepfake detection companies most people assume are the obvious answer to this problem.

Why Detection Is an Arms Race You Cannot Win

This is the intellectual core of the conversation, and it deserves to be understood precisely, not just as a marketing tagline.

The “Undetectable AI” Problem

In AI research, there is a specific and important concept: can a generative model produce content with no detectable artifacts — the small telltale signs that let a detector say “this came from AI”? If the answer is yes, detection is not just imperfect. It is finished. There is nothing left to detect, because the fake is statistically and visually indistinguishable from the real thing.

Jeppe’s argument is that we are already close to that point, and the industry needs to plan as though we have arrived. Compounding the problem: while major AI labs generally try to prevent obviously malicious use cases like generating a fake insurance receipt, a well-resourced and technically capable cybercrime industry does not operate under those constraints. Jeppe specifically pointed to deepfake-for-fraud operations based in Cambodia — organizations with real financial resources, operating in jurisdictions where enforcement is effectively unreachable, training their own models specifically to produce fraudulent evidence at scale.

The Alternative: Check, Sign, Verify

Rather than analyzing content after the fact to guess whether it’s real, InReality’s approach is to make authenticity provable from the moment of capture:

  • Check — evaluate the source of content as it is captured
  • Sign — cryptographically sign verified-authentic content
  • Verify — anyone downstream can independently confirm the signature is valid

If content cannot be verified, it gets rejected or routed down a separate, slower review path. If it can be verified, there is nothing left to analyze — the “happy path” for legitimate claims becomes fast precisely because there is no detection algorithm sitting in the way second-guessing real evidence.

Understanding Post-Quantum Cryptography — In Plain Terms

This is worth explaining carefully, because it is the actual technical foundation underneath InReality’s confidence that their approach will not simply become the next thing that needs detecting.

What Quantum Computers Actually Threaten

Quantum computers, as they scale, will eventually be able to break current standard cryptographic methods — the ones securing banks, the broader internet, and most digital infrastructure today. NIST (the National Institute of Standards and Technology) has already proposed next-generation cryptographic standards believed to be resistant to quantum attacks.

The critical insight Jeppe offered: quantum computing is primarily a threat to old systems that don’t upgrade, not to new systems built on the new standard from day one. InReality’s approach is to simply start with post-quantum secure methods now, rather than retrofitting later.

The “Harvest Now, Decrypt Later” Attack

One of the more unsettling details from the conversation: intelligence and criminal groups are already believed to be harvesting encrypted data today — data they cannot currently read — with the expectation that quantum computing will eventually let them decrypt it. Ten-year-old sensitive data, unlocked a decade after capture, can still be extremely valuable. It’s a strange, patient form of attack: steal now, wait, decrypt whenever the technology catches up.

Why AI Cannot Break Cryptographic Proof

This was the sharpest technical point in the episode. A cryptographic proof is a mathematical operation — proving something is correct without revealing the underlying secret. It has been used for years in banking and cryptocurrency (proving you have funds without exposing the account itself). Properly implemented, these proofs cannot be broken through pattern recognition, guessing, or brute-force computation at any practical scale.

Jeppe’s framing: the only theoretically plausible way an AI could break such a proof would be for the AI to invent a working quantum computer first. That is not a near-term threat — it reframes the entire premise of an “AI arms race” as inapplicable to this specific defense mechanism.

Why Not Blockchain?

InReality deliberately does not use blockchain — and the reason is a genuinely important, underappreciated technical detail with direct regulatory implications.

Blockchain’s core property, permanence, is also its core liability under GDPR. If a piece of evidence is provably recorded on a blockchain, it cannot be deleted without breaking the entire chain. But GDPR grants individuals the right to be forgotten — the right to have their data deleted. A cryptographic proof welded permanently into an immutable ledger is fundamentally incompatible with that right.

InReality’s cryptographic system, by contrast, is specifically designed to support permanent deletion of a cryptographic proof when required — a detail Jeppe described as niche but critical if the technology is meant to be usable at scale within the EU regulatory environment. The company is currently running a year-long research project with a Danish research group specifically focused on this privacy dimension, with publications expected to follow.

How This Actually Works for an Insurance Claim

Jeppe walked through a concrete example: a policyholder gets a small dent in their car and opens their insurer’s app to submit a photo for a claim.

  • The photo is captured through the insurer’s existing app — no separate download, no new user experience
  • Cryptographic signing happens as close to the camera sensor as technically possible — some newer camera hardware is beginning to build this capability in natively
  • The resulting proof travels with the content through the entire claims pipeline — to the special investigative unit if needed, to legal, to court if it comes to that
  • To fake a photo under this system, someone would need to physically compromise the camera’s microchip itself — not spoof a network request, not manipulate a file, but break into hardware at a physical level
  • That doesn’t make it theoretically impossible for a sufficiently resourced actor (a state intelligence agency, or theoretically the chip manufacturer itself) — but it puts real-world insurance fraud entirely out of reach for the vast majority of bad actors

Where the Fraud Pressure Is Coming From

Jeppe cited a striking statistic: Admiral reported a 71% rise in insurance fraud in 2025, per BBC coverage. His explanation is straightforward — it has simply gotten dramatically easier.

The New First Point of Contact

One detail worth sitting with: for younger policyholders in particular, the first response to an insurance incident is increasingly not a call to their insurer — it’s a question to an AI chatbot. “My car has a dent, the other driver left, I don’t know my policy details, what do I do?” That AI will often read the policyholder’s own documentation and coverage details back to them, potentially including guidance on what claims are likely to be rejected — information that sits uncomfortably close to a roadmap for what to manipulate to improve the outcome.

Separately, Jeppe noted that as of June 2026, Cloudflare reported that the majority of their HTTP traffic was bot traffic, not human — a broader signal of how much of the internet’s baseline activity is no longer people at all.

Where InReality Is Deploying Today

InReality’s most mature use case is currently in news and media — professional camera signing, and a live-streaming post-quantum video signing project developed in partnership with other companies. Insurance is newer: the company is currently working with its first insurance carrier partner as a proof point for the methodology, with smartphone-captured claims evidence as the primary use case rather than professional camera equipment.

Jeppe was candid that this is genuinely early-stage in insurance specifically, and that a meaningful part of the current work is translating his AI and misinformation research background into insurance-specific operational reality — learning the industry’s actual claims workflows, not just building the cryptographic layer in isolation.

The Honest Limitation

Asked directly where the system could fail, Jeppe didn’t dodge. Any digital system built by people can be implemented incorrectly. The underlying cryptographic methodology is the same class of technology securing the banking system — theoretically sound and not expected to break. But the harder challenge isn’t technical: it’s convincing an industry that detection — which is intuitive, familiar, and fits existing workflows — needs to be replaced by a fundamentally different mindset. Detection is like asking a trusted friend “is this real?” It’s easy to understand and implement. It’s also asking that friend to keep pace indefinitely with the fastest-moving technology category in history.

The Closing Insight: Watch for the Number to Drop

Jeppe’s answer to what the industry should be talking about more circled back to that 71% fraud increase statistic — with an inversion most people wouldn’t expect.

He is not worried while that number keeps climbing. He’s worried about the moment it starts to fall — because fraudsters are not going to spontaneously stop generating fake claims. A declining fraud statistic in this environment would mean one thing: the industry has stopped catching it, not that it stopped happening.

Key Takeaways

  • Detection-based fraud prevention is structurally a losing arms race once AI-generated content becomes visually and statistically indistinguishable from real content (“undetectable AI”)
  • Post-quantum cryptography is primarily a defense against old, unpatched systems — new systems built on current NIST-proposed standards are not meaningfully threatened by quantum computing
  • Cryptographic proofs, properly implemented, cannot realistically be broken by AI — the only theoretical path would require inventing a working quantum computer first
  • Blockchain’s permanence is incompatible with GDPR’s right to be forgotten — InReality’s alternative is specifically designed to support deletion
  • A well-resourced, jurisdictionally protected cybercrime industry (with specific examples in Cambodia) already has the capability to generate fraudulent claims evidence at scale, independent of what major AI labs choose to restrict
  • Insurance fraud reportedly rose 71% in 2025 (Admiral, via BBC) — and a future drop in that number should be read with suspicion, not relief