AI in insurance, checked dailyThursday 17 September 2026
News, findings and tests. Every item with its source, its evidence and what it means for a book of business.For agencies, MGAs and carriers
GuideAuthored editorial guidance

Before uploading a client document, check the account and the data path

For
Agency · Producer · MGA
Evidence
Authored editorial guidance what this label means
Sources reviewed
2026-09-17
Review cycle
Every 90 days, or sooner when a source changes
Published
2026-09-17T14:18-05:00

In short

The approval question should be more specific than whether a familiar AI brand is allowed. Identify the actual product, account type, settings, connections, task, and information being submitted.

Utica National's agency risk-management guidance recommends protecting confidential information, reviewing provider contracts for how data is used and protected, and updating privacy and retention policies to address AI (Utica National, June 2024). These are risk-management recommendations, not a determination of the requirements applying to a particular agency.

Map what leaves the agency

Describe the input in practical terms: public information, internal operating material, client documents, financial information, or another sensitive category. Determine whether the person proposing the upload is authorized to use it for this purpose.

Record the services involved, including model providers, document processors, storage, connectors, and human support access where applicable. Unknown destinations are questions to resolve, not boxes to mark safe.

Ask account-specific questions

Before approving the workflow, obtain written answers to these proposed questions:

  • Use: Can submitted data or outputs be used for training or other purposes?
  • Retention: What is stored, for how long, and how is deletion handled?
  • Access: Who can view prompts, files, outputs, logs, and support records?
  • Connections: Which other systems can the application read or change?
  • Administration: Who manages access, revocation, and account changes?

Do not assume an answer for one account tier applies to another. This guide does not compare providers or verify any vendor's current contractual terms.

Make the approved boundary easy to follow

Publish a short internal record of the permitted task, account, data categories, prohibited uses, and approval owner. NIST recommends inventories of third parties with access to organizational content and approved technology or service-provider lists (NIST Generative AI Profile).

Use synthetic or appropriately authorized and reviewed redacted examples for initial demonstrations when possible. Do not describe a document as safe merely because a visible name has been removed; have the responsible person review the remaining content and the intended disclosure.

Keep the exception process explicit

When the task needs data outside the approved boundary, stop and seek approval. Avoid informal workarounds such as using a personal account, emailing the file to a vendor contact, or disabling controls to complete a demonstration.

Next: Use the approved AI use register and vendor evidence worksheet. Have appropriate legal, security, and E&O advisers review issues within their scope.