An Artificial Intelligence Policy Is Not an Artificial Intelligence Control System
Insurance agents should recognize that an artificial intelligence policy (AI) is only a starting point, not a complete risk-control system. Agencies need practical controls that identify where AI is used, restrict sensitive data, approve tools by use case, monitor activity and verify outputs with reliable sources. Human review, training, documentation and insurance all matter, but they are insufficient without a managed environment that makes AI use visible, measurable and defensible. As carriers and regulators sharpen expectations around AI-related exposures, agencies that can demonstrate disciplined controls may be better positioned to reduce risk, answer underwriting questions and protect clients.
Insurance agencies are being warned to create artificial intelligence (AI) policies. That is good advice. It is also nowhere near enough.
A policy can establish expectations. It can define acceptable behavior, prohibit certain activities, require human review, and remind employees to protect confidential information. But a policy does not create an operating control system.
It does not show you where AI is already in use. It does not identify the tools employees have opened on personal accounts. It does not tell you which AI capabilities have quietly appeared inside current systems. It does not prevent sensitive information from being entered into the wrong platform. It does not determine which users may perform which activities. And it does not verify whether employees follow the rules.
A policy is a rulebook. A control system determines whether the rules are actually followed.
This distinction is becoming critical because AI is already inside the agency whether anyone formally approved it or not.
Employees are using AI to draft emails, summarize documents, create proposals, generate marketing copy, prepare renewal materials, organize information, compare language, and answer questions. Vendors are adding AI to existing products. Carriers are embedding it in platforms. Software updates may introduce AI capabilities without the agency making a separate purchase decision.
The exposure is not waiting for the agency to finish writing a policy.
Policies Tell People What Should Happen; Controls Help Ensure That It Does
However, an employee can bypass a policy in seconds.
A customer service representative (CSR) receives a declaration page at the agency’s business email address. The CSR wants a fast comparison to the previous year’s policy and uploads the document to a free AI tool through a personal account. The agency’s policy may expressly prohibit that action. The document still left the controlled environment because the rule was written but not enforced.
AI GuardWorks’ Four Walls designed its model to prevent or sharply reduce that failure. Restricted information is categorized. The tool blocks personal email and unapproved public AI destinations. Approved enterprise paths remain available. The model logs attempts and exceptions. The employee is not forced to choose between serving the customer and following an impractical rule; the model builds the approved path into the operating environment.
The opposite direction matters too. A customer sends a declaration page or property photographs to the CSR’s personal phone. The CSR attempts to forward the material into the agency or use a personal AI application. A policy may tell employees not to do that, but it does not automatically screen or separate the path.
The stronger model creates an approved intake route for customer email and outside documents. It can restrict, quarantine, or separately control personal-device traffic. A Bring Your Own Device guest environment can provide managed access, controlled use and monitoring without treating a personal device as if it were part of the agency’s core environment.

The standard response is often to combine the policy with human review and documentation. Again, all are necessary. But each has practical limitations. Human reviews work only when humans know what wrong looks like. Documentation only works when the agency can see the activity. Verification only works when controlling sources and standards are defined. Training only works when it changes daily behavior.
Human in the Loop (HITL) Only Works If the Human Knows What Wrong Looks Like
An AI-generated answer may be polished, professional, and almost correct. It may omit the one endorsement that changes the answer, use outdated carrier information, or lose a critical fact. The reviewer may approve it because nothing obviously looks wrong. A person was involved, but the agency did not necessarily have control.
AI Is a People Pleaser. It May Tell You What You Want to Hear, Not What You Need To Know.
AI is not a static piece of software. Its outputs can change. Its capabilities evolve. It may behave differently depending on the model, account type, prompt, data, workflow and surrounding context. It may be correct today and wrong tomorrow. It may perform well in a single use case and fail in another. It may sound confident in both cases.
That is why approval cannot apply only to a brand name. “ChatGPT is approved” is not a sufficient control. Which version? Which account? Which users? Which use cases? What information may the employee enter? What review is required? Who owns the approval? When must the organization reconsider it?
The use case matters as much as the tool. An AI platform may be appropriate for drafting a meeting agenda and inappropriate for interpreting coverage. The organization may approve it for one department and restrict it for another. It may be acceptable through an enterprise account and prohibited through a free personal account.
Do Not Just Trust AI; Verify It Continuously
A correct prompt does not guarantee a correct answer. A correct first answer does not guarantee a correct final document. AI can lose information or introduce errors across multiple steps. The process should identify what must be verified, which sources control, who performs the verification, what evidence is retained and what activity requires escalation.
If You Cannot Measure It, You Cannot Manage It
An agency that cannot identify where AI is operating cannot credibly claim to control it. It cannot explain what happened after an error. It cannot show which rules applied, which review occurred, or which safeguards the agency had in place.
The answer is not to build a proprietary cybersecurity product from scratch. Commercial technology already exists for identity and access, managed devices, browser restrictions, data-loss prevention, monitoring, logging, alerts, and exception handling. The challenge is coordinating those tools around the agency’s AI rules and risk decisions.
The Control Cannot Be Only The Human Standing Behind AI. The Control Must Be The Environment Surrounding AI
That environment must continue to evolve. New tools appear. Vendors add features. Employees discover new uses. Incidents reveal weaknesses. Questions expose ambiguity. Carrier expectations change. Every question, exception, incident, new tool and new use case should improve the policy, training, controls, and review requirements.
A Control System Needs a Living Support Model
A policy and control design are only the beginning. AI governance is not a one-time project because the governed environment does not stand still. New tools appear, approved tools add capabilities, vendors change terms, employees develop new workflows and incidents reveal gaps that were invisible during implementation.
Agencies need an ongoing source of subject-matter expertise to answer questions and guide decisions as they arise. The advisor should help evaluate new tools and use cases, interpret review thresholds, address exceptions, guide incident response, update policies and controls, and turn lessons learned into better training. This is not about creating bureaucracy. It is about preventing employees from inventing the rules under deadline pressure.
Every question, exception, incident, new tool and new use case should feed the learning loop. If the same question is asked repeatedly, the policy or training is unclear. If employees repeatedly seek an unapproved workaround, the approved path may be impractical. If an incident occurs, the response should improve the control rather than end with a reminder to be more careful.
Insurance Is Beginning to Draw the Boundary
Insurers are also beginning to draw clearer boundaries around AI risk. State departments of insurance have approved AI-related filings in multiple jurisdictions. AI-related exclusions, endorsements, sublimits and specialized coverage are appearing across commercial insurance. Major carriers including AIG, W.R. Berkley, Great American, Chubb, Travelers and others reportedly may initiate AI-related forms or negotiated coverage terms.
This development should change the way organizations think about governance. A business should not assume that an existing E&O, cyber, general liability, D&O, or other policy automatically covers every loss involving AI. Some policies may remain silent, some may provide limited affirmative coverage, some may apply a sublimit or endorsement, and others may exclude certain AI-related losses. The exact policy and endorsements control.
The evolution resembles cyber insurance. Cyber exposure initially lived—often awkwardly—inside traditional policies. As the risk grew, insurers introduced exclusions, endorsements, underwriting requirements, dedicated limits and eventually standalone cyber policies. AI may be following the same path because insurers see the possibility of opaque, correlated and potentially systemic, catastrophic losses.
This does not make insurance the control system. Insurance transfers part of the financial risk after a covered event. Operational controls reduce the likelihood, severity and uncertainty before the event. The two should reinforce each other. An organization that shows approved tools, controlled data, risk-based review, verification, logging, exceptions and continuous improvement is better prepared to answer the questions that underwriters, brokers, clients, regulators and courts are likely to ask.
As the market matures, that evidence may have direct economic value. Safe-driving and telematics programs reward documented lower-risk behavior. Cyber underwriters already use specific controls to influence eligibility, limits and pricing. A certified or independently validated AI control system could become the equivalent for AI risk: proof that the organization is not merely claiming responsible use, but can demonstrate approved tools, controlled data, qualified review, monitoring and continuous improvement. That may lead to discounts or preferred terms. For some risks, insurers may eventually require such controls before offering coverage or meaningful limits. This remains an emerging possibility rather than a universal market practice, but it is a reasonable direction for underwriting to take.
The goal is not to eliminate AI risk. No system eliminates all risk. The goal is to make the use of AI visible, intentional, measurable, and defensible.
Treat an AI policy as the beginning of the process, not the end.
About the Author
Gregory Marholin is Executive Advisor, Strategy & Growth at AI GuardWorks, a managed AI risk and controls system designed to help insurance agencies move beyond policies and procedures and establish practical controls around how AI is actually used. AI GuardWorks has also collaborated with one of the preeminent AI and technology thought leaders, who is a Certified Chief AI Officer, and global executive whose leadership experience includes IBM, Verizon, DXC Technology, Cognizant, and Toptal.
Disclaimer
The views expressed in this article are those of the author and do not necessarily reflect the views of IIABA or its members or affiliates. Publication of this article does not constitute an endorsement. This article is for informational purposes only and does not constitute professional advice; consult qualified professionals for advice about your specific circumstances
Callouts: Let me know if you have problems doing these
The goal is not to eliminate AI risk. No system eliminates all risk.
AI is not a static piece of software. It may be correct today and wrong tomorrow.
Copyright © 2026, Big “I” Virtual University. All rights reserved. No part of this material may be used or reproduced in any manner without the prior written permission from Big “I” Virtual University. For further information, contact nancy.germond@iiaba.net.