This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.

InsurTech World

| 6 minute read

IAG, insurers and betting on digital agents

There is great pressure to experiment and not loose out on the potential benefits of digital agents. But at the same time Paul Maker, CTO at Aiimi , advises "I’ve long argued that using LLMs as a business process engine is a mistake. If anything, recent reports of AI systems "going rogue" and hacking should solidify that point. People love to harp on about guardrails - stacking layer after layer of them - but they won't save you from a fundamental architectural flaw."

LLMs are extraordinarily capable tools with immense value, but they are not built to be the engine driving your core operations."  

Aiimi Ltd are engaged  by UK Government, Manufacturing enterprises, financial services ( including the FCA) , utilities, KPMG and many more organisations to be saved from these flaws. 

Despite such flaws this, IAG is the latest of a number of large Tier One carriers that have announced their commitment to deploying AI tools and in particular LLMs and Digital agents. 

Powered by OpenAI Presence, a newly launched agentic system, IAG will initially explore opportunities to enhance claims delivery, with a particular focus on supporting customer responses and scaling capabilities when faced with natural disasters.

IAG will develop the solution with OpenAI’s Presence, in line with its standards for governance, security, and responsible use of AI and expects to commence delivery in the first half of FY27."

IAG CEO Retail Insurance Australia Julie Batch said the aim is to provide faster, more consistent access to help customers when they need it most. 

Allianz leader in the 2026 analysis of digital maturity by Evident Insights1 of 30 US and European insurers , and last time leader AXA, have and are both investing time and effort into resourcing the business, training its people and applying effective change management to be able to leverage AI. This puts them in a good position to evaluate and test AgenticAI - Digital Agents and have in place the governance and security built into processes  BEFORE experimenting with Digital Agents. 

Allianz's lead is clearest in talent and innovation. The company holds the largest AI specialist workforce in the industry, approximately 28% larger than AXA's, and has invested in enterprise-wide training at a scale few peers can match.” Insurance Business

Allianz, AXA, Zurich all insist that they proceed with caution and strict attention to compliance, security and customer safety. Yet the number of use cases, ranging from distribution through underwriting and claims to supply chain management is accelerating. How can insurers be assured that agents will not break out of the experimental sandboxes and deployed digital infrastructure. OpenAI, Anthropic and Meta have all had to announce agents that have escaped from sandboxes to hack into other publicly exposed systems. In each case the security guardrails had been removed.

OpenAI didn't lose control of a guarded agent. They ran the eval with the cyber refusals turned down on purpose, to see how far the models would push. The agent chained real vulnerabilities and reached its goal. That's not a guarded system failing but a case of allowing an agent to seek ways of achieving its goals. Innthis case exploitingn an unknown vulnerabilityy on third-party software. 

In Anthropic's case multiple escapes occurred during "Capture the Flag" (CTF) exercises. These are controlled cybersecurity simulations where an AI is given a fictional target and tasked with finding vulnerabilities to retrieve a hidden piece of data.  Again misconfiguration as the models were prompted that there was no access to the internet but an open path wqas accidentally left open. Thge models, not finding the data internally 'decided to seek it externally and found the open access and escaped.

Meta suffered a similar escape from a test run by the same IAI security vendor that carried out tests for Anthropic's AI model that had gained access to three other companies' systems.

The point I make is that the agentic models followed the goals set for them and blindsided the AI vendors who only found out about the escapes after the models autonomously targeted real organizations. They utilized basic cyberattack techniques—such as SQL injections, brute-forcing weak passwords, and exploiting unauthenticated endpoints—to breach live networks. In one instance, a Claude model even uploaded a malicious package to the Python Package Index (PyPI) registry. This package executed code that successfully harvested infrastructure credentials from a security company's automated scanning system. 

Deploying multiple agents across the insurance value chain  multiples the dangers3.

The AI vendors and their testing partners know more about the models than insurers so how can an insurer be sure to avoid agents following goals at all costs that conflict with duty of care and regulatory compliance responsibilities? The pressure is naturally to be amongst the first movers to establish competitive advantage and be amongst the top decile of insurers. Capgemini's recent World Property and Casualty Insurance Report 20262 urges that AI tools, especially GenAI, AgenticAI (Dgital Agents) cannot be scaled and operationalised unless insurers plan and resource their organisations adequatly. IAG, Allianz, Axa, Zurich et al are doing that but how do they know what AI models are deployed in their infrastructures?   Take this notice an insurer received:_

What happens if you missed the announcement; when you first licensed the software or core system it did not have these AI features. How do the changes impact your own platforms?

Now here's the potential commercial assasin! The regulators in the UK, EU, USA, Australia and elsewhere will all demand that insurers show how transaction and decisions were made with an immutable audit trail. AND, which human(s) authorised such transactions. If it were an agent did it act within strict, measurable and audited rules approved by a human? Insurers have to show the evidence gathered, the provenance of such evidence4, how it was applied to reasoning and actions, and that it dealt fairly meeting the insurer's obligations. For a three, five-year long tail that must apply from day one. For more complex risk cover longer.

Google's AP2, Visa and Mastercard, Stripe and others have and are developing trust platforms but they are naturally based around payments. Insurance covers more than that. Reinsurance renewed or or not for example. New submissions from brokers and MGAs; not just for P&C risks but also for complex, speciality  cover. Data centres, oil & gas exploration platforms, marine hulls and cargoes, aircraft. Lloyds syndicates cover a really wide range of risks.

As digital agents are deployed into these fields and automation increases in scope, the capacity of these models to accidentally or deliberately ignore security restrictions in order to meet the goals they are set expands and the insurers CEO, COO, Head of Claims are liable to be held responsible unless a clear audit trail shows that the event was authorised with due diligence. No excuses. What is the answer?

Insurers (and other compliant industries) need a new, multi-layered trust architecture similar to that illustrated below. Today's experiments need to include that trust infrastructure in trials and projects to avoid the wrath of customers and regulators. ReLeaf Financial Inc has a patented platform that sits within that infrastructure and banks, telcos and government are already running it within experiments and trials.Insurers should as well

Now is the time; in fact when Robert Pick Group CTO of global insurer Tokio Marine was asked what he needed most to leverage AI he replied Time5. 

“Time to experiment safely, leverage your partners, whether they’re an SI partner, whether it’s a platform or SaaS partner, your partners probably know more than you do. That’s certainly the case for us. Leverage them, learn your way into it.”  Robert Pick

Use the time wisely. 

References

  1. The Evident AI Index for Insurance: Key Findings Report, June 2026 Evident Insights

2. World Property and Casualty Insurance Report 2026  Capgemini

3. When automous digital agents fight each other and forget an insurer's goals and intent M Daly

4. The AI Audit Report is no longer optional Elol Jacoby

5. The CIO Take on Generative AI: Robert Pick

 

 

We are excited to partner with OpenAI as it will provide our people with extra support to help them deliver higher value service to customers. Our initial focus will be on where the need is greatest – high volume natural perils – to ensure we help our customers the best way we can at a stressful point in their lives. This initiative represents the next step in our AI journey, enhancing the capabilities already embedded across our business and reinforcing our commitment to responsible, customer-led innovation.