AI Insurance News

Is AI Safe to Use With Client Data? A Straight Answer for Insurance Agencies

John Marks, AI Strategist & Co-Founder John Marks AI Strategist & Co-Founder • August 14, 2026

This is the second of the two objections we hear in nearly every first meeting. The first is whether AI is going to replace the staff. This one is quieter and kills more projects: "I'm not comfortable putting client information into something I don't understand."

Good. That instinct is correct, and we would rather work with an agency that has it. But it usually gets pointed at the wrong target.

Our position. In most agencies we walk into, the largest AI data exposure is not the vendor being evaluated in the conference room. It is the consumer AI account somebody on staff has already been using for six months, with no written rules, on their own login. The vetting conversation is happening about a tool that hasn't been installed yet, while the actual risk is running unmanaged down the hall.

So before you evaluate anybody — us included — find out what your team is already using and on what kind of account.

Ask the Room

We open our agency training sessions with two questions. First: who here has used ChatGPT or something like it for work in the last month? Most hands go up. Then: keep it up if anyone has given you written rules about what you're allowed to put into it.

The hands drop. Every time.

That gap — real usage, zero governance — is the actual security problem in agency AI today. It is not exotic and it is not a vendor problem. It is a twenty-minute-of-paperwork problem that almost nobody has done.

The One Account Setting That Matters Most

Consumer AI accounts may use what you type to improve the model. Business and enterprise tiers contractually do not. That is the whole distinction, and it is the single highest-value thing to fix in an agency this week.

If anyone at your agency is using AI on anything client-related, they need to be on a business tier. It is not expensive. It is the difference between a policy violation and a normal Tuesday — and it is a change you can make today without buying anything from a vendor like us.

The Never-Paste List

Regardless of tier, some things do not go into a general-purpose AI chat box:

  • Social Security numbers
  • Dates of birth
  • Driver's license numbers
  • Full policy or account numbers
  • Medical or health information
  • Payment card or bank details
  • Anything you would not write on a postcard

That last line is the one worth memorizing, because it generalizes to the cases the list does not name.

Now the important half, because a security rule that only prohibits things gets ignored by week three: nearly every task an agent wants AI help with can be reframed without the identifiers. Describe the situation generically — "a homeowner in a wildfire-scored area with a detached shop and a prior claim" — get the answer, then apply it to the actual file yourself. You lose nothing. The identifiers were never what made the answer useful.

Point that out when you write your agency's rules. A policy framed as "here's how to keep getting help safely" survives; a policy framed as a list of prohibitions gets routed around.

"Connect Your Email" — What You're Actually Approving

The riskiest click in agency AI is not a chat box. It is the permission screen when a tool asks to connect your mailbox, because most people approve it without reading what they granted.

Here is the distinction that matters. Delegated permissions mean the application acts only on behalf of the individual person who signed in, bounded by that person's own mailbox and calendar. Application-level or tenant-wide permissions — scopes named Mail.Read.All, Directory.Read.All, Files.Read.All, Sites.Read.All — mean the vendor can reach mailboxes belonging to people who never connected anything and never agreed to anything.

A reasonable request reads the mailbox of the person approving it. A request that should stop you cold asks for the whole organization's mail, or grants access with no way for you to revoke it. Confirm you can revoke from your own side — an individual user at their Microsoft account settings, and an administrator tenant-wide from the Entra admin center — without needing the vendor's cooperation to do it.

For our part: AgencyIQ requests delegated permissions only and no tenant-wide scopes at all. We removed MailboxSettings.ReadWrite in August 2026 rather than ask administrators for write access to mailbox configuration to support one convenience feature. The complete scope-by-scope table, with the reason for each, is published on our trust center.

Five Questions for Any AI Vendor

Ask these of every vendor, including us. Write the answers down.

  1. Do you train your models on our data? The answer must be no, in writing.
  2. Where does our data physically live, and who else touches it? You want a named list of subprocessors, not "the cloud."
  3. Can we delete everything, and get proof it's gone?
  4. What exactly can your system see — and can it cross into another agency's records? Ask how that is enforced. "Our code checks" is a weaker answer than "the database enforces it."
  5. What happens to our data if we cancel, or if you go out of business?

The tell is not whether a vendor answers yes or no. It is whether they answer specifically. "Enterprise-grade security," "bank-level encryption," and "military-grade" are adjectives, not answers — and a vendor reaching for adjectives on question four is usually a vendor who has not enforced isolation at the database layer.

What a Good Answer Looks Like

Here is the part most vendors skip: a company should tell you plainly what it does not have.

Ours, stated plainly: Applied AI Partners has not completed a SOC 2 Type II audit. It is on our roadmap. Our core infrastructure providers — Vercel, Supabase, AWS, Twilio, and Stripe — are SOC 2 Type II certified today, and we are glad to complete a carrier's own vendor security questionnaire in the meantime.

We put that in writing on a public page because a vendor who will not say "no, we aren't certified for that" is a vendor who will tell you what you want to hear about everything else. If a security page has no gaps listed anywhere on it, you are reading marketing.

The rest of ours, in short form:

  • U.S.-only data residency. Hosting, database, and document and audio storage all run in United States regions, and customer data is not replicated outside the U.S.
  • Encryption. AES-256 at rest, TLS 1.2 or higher in transit, with no unencrypted path into the application. Mailbox refresh tokens get a second application-level AES-256-GCM layer under a key held outside the database, so a stolen database copy alone does not yield a usable mailbox credential.
  • Isolation enforced by the database. Every tenant-scoped table runs PostgreSQL row-level security. An authenticated query physically cannot return another agency's rows even if application code contained a bug. Tables default to deny.
  • No training, no sale. Customer data is never used to train AI models — ours or any provider's — and is never sold, rented, or brokered.
  • Two-factor authentication via TOTP, which an agency owner can require for every member of the agency.
  • Staff access. We do not browse customer records. Production access happens only when an agency opens a support request that requires it, limited to what that request needs.

Every one of those is stated in more detail, with the named subprocessor list, on the trust center — written to be read by a carrier's vendor-security reviewer, not just by a prospect.

One More Thing Worth Checking: Recording Consent

If you are adopting AI note-taking, the AI question and the recording question are separate, and the second one is governed by state law rather than by your vendor. Some states require only one party to consent to a recording; others require all parties. Idaho is a one-party-consent state; other states where your clients live may not be, and the rules can turn on where the client is rather than where you are.

Confirm your own situation against your state's statute and your carrier's guidance before you turn recording on across a team. It is a five-minute check that is very unpleasant to do retroactively.

The Twenty Minutes That Actually Fixes This

You do not need to buy anything to close most of this gap. Write down five things and give them to your team:

  1. Approved tools — which AI products are allowed, and on which account tier.
  2. The never-paste list — the one above, adapted to your agency.
  3. The review rule — nothing reaches a client unread by a licensed person.
  4. Who to ask — one named owner for the rules and the approved-tools list.
  5. When it gets revisited — quarterly. These tools change fast enough that an annual review is stale on arrival.

If your carrier publishes its own AI guidance, that leads and this fills the gaps it does not cover. For captive agencies especially, check with your field leadership before connecting any tool to company systems — the boundary between carrier-controlled and agency-controlled systems is worth drawing on paper once.

Do that, and you have addressed more real exposure in one afternoon than most agencies address in a year of vendor evaluations. Then evaluate vendors — with the five questions, and with the expectation of specific answers.

If you want to run those questions at us directly, get in touch, or read the trust center first and come with the hard ones.

Quick Answers

Is it safe to use AI with insurance client data?

It depends entirely on which AI and on which account tier. The largest exposure in most agencies is not a vetted vendor at all — it is a staff member pasting client details into a personal consumer AI account with no written rules around it. Consumer tiers may permit using what you submit to improve the model; business and enterprise tiers contractually do not. Before evaluating any AI product, find out what your team is already using and on what kind of account, because that is where the actual risk currently sits.

What should you never paste into an AI chatbot at an insurance agency?

Social Security numbers, dates of birth, driver's license numbers, full policy or account numbers, medical or health information, and payment card or bank details. The general test is simpler than the list: do not paste anything you would not write on a postcard. Nearly every task an agent wants help with can be reframed without those identifiers — describe the situation generically, get the answer, then apply it to the actual file yourself. The point is capability, not prohibition.

What questions should an insurance agency ask an AI vendor about security?

Five. Do you train your models on our data, and will you say no in writing? Where does our data physically live, and who else touches it? Can we delete everything and get proof it is gone? What exactly can your system see, and can it cross into another agency's records? What happens to our data if we cancel or you go out of business? A vendor who answers all five specifically is worth continuing with. A vendor who answers in adjectives — enterprise-grade, bank-level, military-grade — has not answered.

What Microsoft 365 permissions should an AI tool be allowed to request?

Delegated permissions only, meaning the application acts solely on behalf of the individual person who signed in and is bounded by that person's own mailbox and calendar. What should stop you cold is any request for application-level or tenant-wide scopes such as Mail.Read.All, Directory.Read.All, Files.Read.All, or Sites.Read.All — those let a vendor reach mailboxes belonging to people who never connected anything. Also confirm that access can be revoked from your side, both by the individual user and tenant-wide by a Microsoft 365 administrator, without needing the vendor's cooperation.

How does Applied AI Partners protect insurance agency data?

Customer data is stored only in United States regions across hosting, database, and object storage. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, and mailbox refresh tokens receive an additional application-level AES-256-GCM layer under a key held outside the database. Agencies are isolated by PostgreSQL row-level security enforced by the database rather than by application code. Customer data is never used to train AI models by Applied AI or any provider, and is never sold, rented, or brokered. Microsoft 365 access is delegated-only and revocable by the agency at any time. Applied AI Partners has not completed a SOC 2 Type II audit; its core infrastructure providers are SOC 2 Type II certified. Full detail is published at appliedaijax.com/security.