AI Governance & Responsible AI: What CISOs Need to Get Right Before LLMs Touch Insurance Data

AI Governance & Responsible AI: What CISOs Need to Get Right Before LLMs Touch Insurance Data

Craig Hangartner

NavaJeevan Rajaiah

AI adoption in P&C insurance is accelerating faster than most governance programs can keep pace with. LLMs are being deployed for underwriting support, claims processing, data migration, and customer-facing interactions, often before formal AI governance frameworks, access controls, and monitoring practices are fully in place.

For CISOs, this creates real exposure. An LLM deployment without proper governance isn't just a compliance gap, it's a new category of security risk: prompt injection, unmonitored data exposure through model outputs, and AI systems making or influencing decisions without adequate human oversight or audit trail. Responsible AI governance has to be a security program requirement, not something addressed after deployment.

Why AI Introduces Security Risks Traditional Controls Don't Cover

LLM deployments create risk categories that standard application security practices weren't designed to address:

Prompt injection and manipulation. LLMs can be manipulated through carefully crafted inputs to bypass intended constraints or extract information they shouldn't expose, a risk category with no direct equivalent in traditional software security.

Sensitive data exposure through model outputs. An LLM with access to policy, claims, or underwriting data can inadvertently surface sensitive information in a response, even without a traditional data breach occurring, if output filtering and access controls aren't properly enforced.

Unclear decision accountability. When an AI system contributes to an underwriting decision, a claims determination, or a data classification, there needs to be a clear, auditable record of what the AI did versus what a human reviewed and decided, particularly important in a regulated industry.

Shadow AI usage. Employees and teams may adopt AI tools independently, outside formal procurement and security review, creating AI usage in the environment that the security team has no visibility into or control over.

Model access as a new privileged access category. Who can query a given LLM, what data it can access, and what actions it can take on the insurer's behalf all need access control treatment similar to any other privileged system, which many organizations haven't yet formalized for AI specifically.

What Responsible AI Governance Requires

A functioning AI governance program for insurance needs several components working together:

Formal governance framework. Clear policies defining what AI systems are approved for use, what data they can access, and what decisions they're permitted to influence versus make outright.

Secure LLM deployment practices. Ensuring models are deployed within controlled environments with appropriate data access boundaries, rather than sending sensitive insurance data to external, less-controlled AI services.

Prompt filtering and input validation. Technical controls that reduce the risk of prompt injection and manipulation, particularly for any AI system with access to sensitive data or decision-influencing capability.

Continuous AI usage monitoring. Ongoing visibility into how AI systems are being used across the organization, including detecting unauthorized or "shadow" AI adoption outside approved tools.

AI-specific access controls. Treating access to AI systems and the data they can query as a distinct, formally managed access category, with the same rigor applied to any other system handling sensitive insurance data.

Human-in-the-loop enforcement, not just policy. Ensuring AI-assisted processes actually route through human review at defined checkpoints, with that oversight enforced structurally rather than left to individual practice.

Why the "Autonomous Decision" Question Matters Most

Of all the AI governance questions a CISO needs answered, the most consequential is simple: does this AI system make decisions, or does it inform decisions that a human makes? The answer changes the entire risk profile.

An AI system that autonomously approves claims, denies coverage, or takes action on sensitive data without human review carries substantially higher regulatory, security, and liability exposure than one that surfaces recommendations, mappings, or analysis for a human to evaluate and act on. Any AI vendor or internal deployment should be able to answer this question clearly and specifically, not with a general assurance that "humans are involved somewhere in the process."

How InsOps Helps

InsOps is built around AI governance principles that are foundational to the product, not added as a compliance layer after the fact.

Never autonomous, always human-in-the-loop. LiLa, our insurance-trained AI model, assists with data mapping, migration, and integration tasks, but it never acts autonomously or makes decisions on its own. Every output is validated by human review before it's used, providing a clear, consistent accountability boundary between what the AI does and what a human approves.

Secure deployment inside your environment. LiLa runs inside the insurer's own controlled infrastructure. Sensitive policy, claims, and underwriting data is never sent to an external service to be processed, closing off one of the more significant exposure points in typical LLM deployments.

Purpose-built for insurance, not a generic model with insurance data layered on top. LiLa is trained specifically on insurance domain logic, data relationships, and regulatory frameworks like NAIC, HIPAA, and GDPR, which supports more predictable, governable behavior than a general-purpose LLM applied to insurance use cases without that grounding.

Clear scope of what the AI actually does. InsOps is explicit about LiLa's role across each capability, data mapping and transformation, migration assistance, anonymization support, rather than presenting broad, undefined AI capability that's harder to govern and audit.

A defensible answer to the accountability question. Because LiLa never operates autonomously, CISOs evaluating InsOps have a clear answer to the most important AI governance question: every output is a human-reviewed recommendation or transformation, not an independent decision made on the insurer's behalf.

For CISOs building or maturing an AI governance program, InsOps's design reflects the standard that any AI deployment touching sensitive insurance data should meet: human oversight enforced structurally, data kept inside controlled infrastructure, and a clear, auditable boundary between AI-assisted work and human decision-making.

FAQ

Why does prompt injection matter for insurance-specific AI deployments? Any LLM with access to sensitive policy, claims, or underwriting data is a potential target for prompt injection attacks designed to extract that data or bypass intended constraints. This is a security risk category with no direct equivalent in traditional application security, requiring dedicated filtering and validation controls.

What is "shadow AI," and why is it a governance concern? Shadow AI refers to AI tools adopted by employees or teams outside formal procurement and security review. It's a concern because the security team has no visibility into what data these tools access or how they're being used, creating ungoverned risk in the environment.

Why is the distinction between AI that decides and AI that informs a decision so important? Because it fundamentally changes the risk profile. An AI system making autonomous decisions, approving claims or denying coverage without human review, carries significantly higher regulatory and liability exposure than one that provides recommendations or analysis for a human to evaluate and act on.

What does "human-in-the-loop" actually require to be effective, beyond a stated policy? It requires structural enforcement, defined checkpoints where human review is a mandatory, built-in step in the process, not just an assumption that a human happens to be involved somewhere. Effective human-in-the-loop design makes bypassing that review difficult or impossible by design.

Does deploying an LLM inside a controlled environment eliminate AI-specific security risk? It significantly reduces one category of risk, sensitive data leaving controlled infrastructure, but it doesn't eliminate all AI-specific risks. Prompt injection, output validation, and access control considerations still apply even when a model runs entirely within the insurer's own environment.

How should AI-specific access controls differ from standard system access controls? AI access controls need to account for what data a given AI system can query, what actions it can take or recommend, and how its outputs are used downstream, treating model access as a distinct privileged access category rather than applying the same generic access rules used for standard applications.

Craig Hangartner

NavaJeevan Rajaiah