Document every AI-assisted decision for
Insurers applying AI to claims, underwriting, and pricing do so under a framework the NAIC Model Bulletin has expanded across roughly 24 states, with the NAIC AI Evaluation Tool now piloting in 12. Igris protects policyholder data at the proxy layer, documents every AI-assisted decision in a form examiners accept, and tracks cost down to each line of business.
AI Claims Processing
Claims documents contain social security numbers, medical diagnoses and treatment histories, banking details, property assessments, and litigation histories. When this material reaches an external LLM provider without documented redaction controls, the insurer faces a HIPAA breach notification event for medical data in health and life claims, a GLBA Safeguards Rule violation for financial information, and GDPR or DPDP Act 2023 exposure for claims involving EU or Indian policyholders. The NAIC Model Bulletin, adopted in approximately 24 states, establishes that insurers are responsible for documenting how third-party AI vendors govern policyholder data. The NAIC AI Evaluation Tool, currently being piloted across 12 states in 2026, is giving state examiners a structured framework to ask exactly these questions. An insurer that cannot produce a documented record of how policyholder data was governed does not have a documentation gap. It has a regulatory examination exposure.
Guard applies PII redaction policies to every claims document prompt before it reaches the LLM provider, stripping social security numbers, medical record identifiers, banking details, and financial account references. Encrypted body logging preserves a compliance-ready record of every AI-assisted claims interaction. The Igris audit trail records every AI-assisted decision: which model was used, which connection it routed through, which policy was applied, and what was detected and redacted — creating the per-decision documentation the NAIC AI Evaluation Tool and state examiner reviews require. Igris Lens tracks cost per claims line connection, giving operations and finance teams the per-line AI spend data for auto, health, and life claims.
Policyholder SSNs, medical records, and financial details are governed by a technical enforcement control before they reach any external provider. The regulatory examination package exists in the audit trail before the examiner asks for it. When a state examiner using the NAIC AI Evaluation Tool asks for documentation of how policyholder data was governed in AI-assisted claims processing, the answer is a governance log.
AI Underwriting Assistant
Underwriters analyzing risk profiles work with applicant data spanning multiple sensitive categories simultaneously: health records and treatment histories for life and health lines, credit scores and financial history for property and casualty lines, and property assessments carrying both data protection and fairness testing obligations. Two distinct risks operate at the same time. The data exposure risk: if an underwriter sends a full applicant file as context, the prompt contains HIPAA-protected health data, GLBA-protected financial data, and GDPR or DPDP Act-covered personal data for EU and Indian applicants — all transmitted without documented controls. The model governance risk: the NAIC Model Bulletin requires insurers to document which AI systems are used in underwriting decisions, validate that those systems meet fairness and accuracy standards, and maintain third-party vendor oversight records. The Colorado AI Act, effective February 1, 2026, adds state-level requirements for bias prevention and documented governance procedures.
Guard content guard policies prevent sensitive financial scores, credit references, and insurance-specific risk identifiers from reaching LLM providers, enforcing GLBA data minimisation requirements at the call level. Token limits cap the maximum applicant file size that can be sent as prompt context. An allowed model list on each underwriting connection restricts which LLMs can be used for risk analysis, creating the documented third-party vendor oversight record the NAIC requires. The Igris audit trail records every underwriting AI interaction — model, policy, redactions — giving each underwriter a personal interaction record that satisfies per-underwriter compliance documentation requirements.
Applicant health records, financial scores, and full risk profiles are governed by a documented technical control on every underwriting AI interaction. The model allowlist creates the third-party vendor oversight documentation the NAIC Model Bulletin requires. The audit trail gives the compliance team a per-underwriter AI usage record ready for the NAIC AI Evaluation Tool review or a state examiner's request.
AI Fraud Detection for Claims
Insurers using LLMs to detect fraudulent claims patterns operate high-volume pipelines that combine HIPAA-protected medical information with GLBA-protected financial data on every health and life claims call. A runaway pipeline creates a cost event and a data exposure event simultaneously at pipeline scale. The NAIC AI Evaluation Tool will ask how fraud detection AI governance is documented. The answer the examiner needs is a per-call technical control log, not a process description.
Guard applies multi-category PII detection to every fraud analysis prompt, stripping medical record identifiers, financial data references, and policyholder identifying information before any prompt reaches the LLM provider. Rate limiting holds the fraud detection pipeline within its defined allocation during fraud spike events. Lens cost anomaly detection distinguishes a genuine fraud pattern from a misconfigured pipeline. The full audit trail records every fraud analysis call and every redaction event — the NAIC documentation the AI Evaluation Tool requires and the HIPAA Security Rule audit control evidence the compliance team needs.
Fraud detection pipelines run at volume with documented PII controls on every call. Runaway patterns are caught by anomaly detection before they become billing events. The NAIC examiner's documentation request has a complete answer in the audit trail.
AI Policy Renewal and Pricing Assistant
Insurers using LLMs to assist with policy renewal analysis and pricing recommendations operate AI systems in a context the NAIC Model Bulletin specifically flags as requiring fairness testing and bias documentation. Pricing recommendations using claims history, financial data, and geographic identifiers can produce proxy discrimination — outcomes correlating with protected characteristics even without explicit demographic inputs. The Colorado AI Act requires documented governance procedures specifically to prevent bias in insurance AI pricing decisions.
Guard applies content policies to pricing AI prompts, stripping demographic-adjacent identifiers and financial scores not required for the specific renewal analysis task — reducing the proxy discrimination inputs the NAIC fairness testing framework requires documentation for. The allowed model list restricts pricing AI to validated, approved LLMs, creating the documented third-party vendor oversight the NAIC Model Bulletin requires. The Igris audit trail records every pricing AI interaction — model, policy, redactions — providing the documentation foundation that satisfies NAIC Evaluation Tool requirements, Colorado AI Act governance obligations, and GDPR and DPDP Act data protection obligations.
AI-assisted pricing support runs with documented data controls that reduce proxy discrimination inputs and satisfy NAIC fairness testing documentation requirements simultaneously. The compliance team has the per-decision audit trail the NAIC AI Evaluation Tool review requires. When a state examiner asks how pricing AI decisions were governed throughout the year, the audit trail provides the complete record.
Make every AI decision examination-ready
See how insurers redact policyholder data on every call and produce NAIC, HIPAA, GLBA, and Colorado AI Act documentation automatically.