Managing AI risk in insurance agencies
A cybersecurity expert does a deep dive into AI risks and how to mitigate them in your agency.
AI tools can create real efficiency gains for insurance agencies. But while efficiency is great for business, it can be bad for cybersecurity.
Everything insurance agencies do to make data more accessible, connect tools and processes, and automate tasks creates areas of cyber risk as a tradeoff for the efficiency gained. AI didn’t create any new risks here (this is inherent with technology), but the speed and power of AI take it to a new level. The risk is not just about malicious actors, and it’s not even all about data exposure. There’s much more at stake.
AI risk is manageable, but in my cybersecurity consulting work, I’ve seen that many agents think there is a small probability of things going wrong and neglect to consider what’s actually possible.
Before we look at how things go wrong and how agencies can protect against risks, it’s important to start by understanding those risks.
The risk of exposing personal information
A compromise of confidentiality is what happens when data is exposed to someone it wasn’t intended for (malicious or accidental). When agents have sensitive information like personal identifiable information (PII), payment card information (PCI), protected health information (PHI), or other types of information that needs to stay private, they need to think about what happens if it is exposed.
With AI, this is particularly important, because data entered into an AI tool may end up feeding back to the AI training model, where it can no longer be managed or protected. Even when the AI is not training on your data, it’s still often in the hands of a third party.
As seen in recent news, AI models have been unpredictable and broken out of controlled environments. We are not yet at a level of advancement to have total confidence in the guardrails that contain AI tools to be able to trust that segmentation of data is reliable.
Insurance agents have a responsibility to protect and properly handle regulated data and ensure the third parties they choose can do the same.
How to protect confidentiality
Even if you’re paying for a version of an AI tool that is not “supposed to” be passing your data to training models, the fact is that mistakes and bugs can happen. To protect confidentiality, you may need your AI tools to run in their own environment where they can’t connect to the internet.
You can also remove the sensitivity by anonymizing data to remove anything “identifiable” prior to having AI get involved.
The risk of breaking trust
A compromise of integrity is when trust is broken. Just as with other areas of risk, trust can be broken maliciously when data or processes are manipulated, but it can also happen accidentally when there’s an error.
Errors can occur for many different reasons, but when AI is being used to generate text, errors typically happen because large language models (LLMs) use probability to choose what word to say next. When the tool doesn’t know an answer, it often will “hallucinate” or make up an answer. Without proper oversight, an agency could experience issues with customer-facing AI, incorrect data or reports, or sharing of misinformation that could lead to an E&O risk.
How to maintain integrity
It’s not always immediately obvious when there is a compromise of integrity with an AI tool. This is where it’s important to have a human-in-the-loop to make sure information is correct and automations are checked and working correctly.
It’s also important to review information written by LLMs to make sure it’s not making things up or creating other issues, especially when advising on something that requires a licensed representative to carefully share advice and information.
The risk of depending on one system
A compromise of availability is the dreaded down time that can come from an attack or outage. Ransomware is a great example, but it can happen in many ways. In June 2025, OpenAI had an outage for several hours that affected many businesses using ChatGPT.
If you just automated a bunch of manual tasks, you are now dependent on those new processes and the related technology. Let’s say you use a new AI model to build out a full customer experience from prospect to bind to renewal, but national security risks cause the provider to have to disable the model.
Even a short outage could have rolling impacts across different parts of your business, some that may even impact customer experiences or that could cause issues with the third parties your agency works with.
How to preserve availability
Just like you’d have a backup to restore if your other systems were down, consider redundancies and alternative processes that can take over if your automations are broken.
Consider keeping notes on human-based processes just in case you need to jump back into something you automated.
Building out connected technology systems can be great for efficiency, and in cybersecurity, adding efficiency usually means an increase in cyber risk. It usually means there are more hands in the data that needs to stay confidential, more places where integrity and trust have to be verified, and more tools agencies depend on to be able to optimize their work.
None of these risks mean agencies need to avoid AI. Agencies can protect these areas of risk with careful planning and awareness.
Visit our AI resources for more insights on AI in agencies.
How things go wrong with AI and cybersecurity
After understanding what’s at stake, agencies should analyze how problems actually happen and the avenues that could lead to a compromise.
AI security can’t be treated in isolation. In most cases, attackers are looking for the easiest path in. That doesn’t always mean “hacking” an AI tool directly. More often, attacks come through weak spots like compromised email accounts, reused credentials, or overly broad access. If other parts of your business are compromised, chances are that your AI resources will be accessible to that bad actor as well.
For example, if you use Microsoft for email and have a business email compromise, the same account may provide access to your SharePoint and Copilot resources. The AI tools that drive your efficiency can do the same for the attacker that finds them and uses them to their advantage.
These weak spots can be within your agency’s systems and processes or through third-party providers you work with, including AI companies or other technology vendors. That’s why it’s important to set up strong protections on the agency side and to ask your third-party vendors about their security practices. Unless you can isolate and host your own tool, the control of security is often in the hands of third parties, so you must do your due diligence to ensure security practices are appropriate.
Tips to build a secure AI-based agency and mitigate risk
- Start with a strong foundation and get on top of your cybersecurity practices as a whole.
- As you get started, include your IT and cybersecurity teams in conversations around your plans for AI. There is a lot that goes into carefully planning and designing safe and secure AI tools for your office.
- Define clear policies for AI use
- Create clear documentation for your staff with an acceptable use policy for AI. Without this, it’s the wild west. Check for laws or contracts that may require you to do more.
- Create a policy for AI governance that describes how you will determine which tools are appropriate, do your due diligence, manage and monitor your tools, and how you will decommission anything you’re no longer using.
- Check for laws or contracts that may require you to do more.
- Set boundaries around AI access
- Before you give AI access to anything, control what is visible and what it can edit (this may include dialing this in for each user account). Define clear boundaries for what the AI can or cannot do by implementing policies to control how it should behave.
- Be ready to detect and respond to incidents quickly.
- Know what to watch for (keep that human in the loop) and investigate anything suspicious. Breaches (and other incidents) can get costly fast, and there is a direct correlation to the increase in cost based on how long it takes to detect and contain incidents.
- Establish an incident response plan that you can follow to minimize the incident and isolate anything that could create a bigger problem for you.
- Get good cyber liability insurance. Check your limits and restrictions to make sure there won’t be an issue if you have a claim related to anything AI.
Moving forward with intentional AI use
AI has the potential to help insurance agencies work more efficiently and free up time for higher-impact work. However, just like with any technology tool, the benefits come with risks. The agents that benefit the most from AI tools will be those who weigh the risks and rewards and take a thorough and intentional approach to implementation.
Think of your AI cybersecurity plans like you approach risk mitigation conversations with clients: The goal is not to avoid risk entirely, it’s to understand where risks exist so you can make informed, proactive decisions to protect against them.
Used thoughtfully, AI can be a powerful addition to an agency’s technology stack. The key is pairing innovation with awareness so efficiency doesn’t come at the expense of confidentiality, trust, or service continuity.
Want to learn more about how to build a strong cybersecurity program for your agency? Join ReadyState Cybersecurity’s webinar on September 18. Register now.