Are AI Systems Capturing Insurers' IP?

Insurers risk inadvertently transferring proprietary expertise to AI systems through everyday use, creating a vulnerability beyond traditional cybersecurity concerns.

AI Systems May Be Capturing Your Proprietary Knowledge

For at least the past two years, insurers have focused on an essential question: How can AI make us smarter?

Another concern is beginning to emerge.

Who, exactly, becomes smarter every time we use it?

The insurance industry has spent decades building intellectual capital that doesn't appear on any balance sheet. Underwriting judgment. Claims workflows. Fraud indicators. Distribution strategies. Product pricing logic. Regulatory expertise. Customer communications. The institutional knowledge that carriers, MGAs, and brokerage use to create a distinct competitive advantage from other businesses in their competitive space.

Today, much of that knowledge is quietly flowing into AI systems - oftentimes without the knowledge owners' (or originators') knowledge.

Not through a data breach.

Not through cybercrime.

But through ordinary, everyday business use.

The New Information Leak

When people think about information security, they typically picture hackers wearing hoodies in darkened rooms stealing customer records or ransomware shutting down operations. (Throw in some empty Mountain Dew cans to add extra "flavor" to the image…)

Generative AI introduces a different type of risk actor.

Insurance workers don't simply upload documents into AI systems. They explain how their business works. They refine outputs. They correct mistakes. They describe edge cases. They reveal why one underwriting decision differs from another. They basically fine-tune the model using the organization's life-blood – its processes, judgment, and expertise.

Each prompt adds context. Every correction adds nuance. Any successful interaction between a person and an insurance-trained LLM captures another piece of proprietary institutional knowledge.

Individually, these exchanges seem harmless. Collectively, they represent an organization's most valuable asset.

The Trojan Horse Problem

Spoiler alert for people who are still reading The Iliad before going to theaters to see The Odyssey: The ancient Achaeans didn't breach the gates of Troy by force.

They were invited inside.

That's why the "Trojan horse" analogy has gained traction among AI observers. The concern isn't that foundation model providers are intentionally harvesting proprietary information for competitive purposes. Rather, the architecture of AI creates a fundamental asymmetry: organizations must reveal increasingly detailed information about how they operate to receive increasingly valuable assistance.

The more context AI receives about your operations...

...the more effectively it can replicate (and share) your expertise.

Microsoft CEO Satya Nadella recently framed this as a "reverse information paradox," arguing that organizations effectively pay twice for AI: once financially, and again by revealing proprietary knowledge required to make the models useful. His observation reflects a growing debate across enterprise technology about ownership of prompts, feedback, workflows and organizational know-how.

Whether organizations agree with that assessment, it raises an important governance question for insurance CIOs/CISOs.

Insurance Has More At Stake Than Most Industries

Insurance isn't simply another knowledge business.

It is a judgment business.

Competitive advantages rarely come from a single algorithm or dataset. They're the result of thousands of successful decisions accumulated over years:

  • Why adjusters escalate certain claims.
  • How underwriters evaluate emerging risks.
  • Which variables consistently predict profitability.
  • How service teams de-escalate difficult customer situations.
  • Which regulatory interpretations have proven successful across jurisdictions.

These are not trade secrets, per se, but they are critical operational intelligence.

Unlike customer data, operational intelligence often isn't classified or labeled as confidential. Employees may share it with AI tools because they're simply trying to work faster.

Yet this institutional knowledge may ultimately prove more valuable than the documents themselves. And, not to belabor the Homeric allusions, the safety of this institutional intelligence can be an insurance business's Achilles Heel…

Why Governance Must Expand its Purview Beyond Privacy

Most AI governance discussions inside insurance organizations focus on familiar concerns:

  • Personally identifiable information
  • Regulatory compliance
  • Security controls
  • Model accuracy
  • Bias and explainability

These remain essential elements to a robust governance strategy.

But these may no longer be sufficient as the core of governance.

Organizations should also ask:

  • Which AI platforms retain prompts?
  • Can customer interactions be used to improve future models?
  • What proprietary workflows are employees revealing?
  • Which business processes should never leave controlled environments?
  • When should an organization rely on internally hosted or private AI models instead of public services?

Such questions nudge AI governance beyond compliance and into competitive strategy.

Institutional Knowledge Is Intellectual Property

Historically, insurers have protected code, customer databases, actuarial models, and other vital information.

Tomorrow's competitive asset may be something less tangible: the accumulated knowledge generated every day through interactions between employees and AI.

The irony is striking.

Organizations adopted AI to preserve and amplify institutional knowledge.

Without thoughtful governance, they may also be exporting it.

Insurers' response should not be to slow AI adoption. The lost productivity gains will be consequential across every insurance function from underwriting to claims to policy servicing.

But as organizations race to become AI-enabled, their practices should be centered around the principle that cybersecurity communities have understood for years:

The most valuable information isn't always the data you store. Sometimes it's the knowledge your people create.

The evolution of AI governance won't be defined around cybersecurity, privacy, or compliance concerns. It will also require insurers to identify, classify and protect institutional knowledge as another key strategic asset.

Organizations that rise to this challenge will capture AI's productivity gains without inadvertently teaching competitors how they do business. Those that don't may discover that the greatest risk wasn't exposing customer data; it was giving away the expertise that made them different in the first place.


James Ballot

Profile picture for user JamesBallot

James Ballot

James P. Ballot is an insurance research, thought leadership, and content strategy leader with more than a decade of experience helping industry, regulatory, business, consumer, and higher education audiences understand and navigate complex industry transitions – including the rapid evolution of insurtech and AI-driven automation.

MORE FROM THIS AUTHOR


Diane Brassard

Profile picture for user DianeBrassard

Diane Brassard

Diane Brassard is an operations and AI transformation leader specializing in the insurance industry. With three decades of experience spanning underwriting, claims, and BPO strategy at major carriers, she helps insurers design and execute practical, scalable workflows, whether powered by AI or process redesign, that drive measurable business results.

MORE FROM THIS AUTHOR

Read More