CultureAI
Insurance

Enabling GenAI for underwriters without exposing policyholder data

Underwriters were using GenAI to summarise submissions and draft responses. The insurer needed to know what data was going in, and to stop the risky cases without slowing the desk down.

Industry
Specialty insurance
Size
2,800 employees
Region
UK and Europe
0+

AI tools discovered in the first two weeks

0%

reduction in high-risk data submissions

0 day

from deployment to live detection

The challenge

The underwriting teams had found GenAI on their own: summarising broker submissions, comparing policy wordings, drafting client responses. Productivity was up, and so was the volume of policyholder and claims data flowing into tools the security team had never assessed.

The existing proxy and DLP could see traffic to a handful of known AI domains, but nothing about what data was inside a prompt, and nothing at all about the AI features embedded in the SaaS tools the business already used.

The approach

Discover, control, detect, prove

01

Discover

A free two-week AI Risk Assessment surfaced 240+ AI tools in use, three times the approved list, and showed exactly which desks were sharing sensitive data.

02

Control

Policies warn underwriters in real time when policyholder data appears in a prompt, and block the highest-risk combinations of data and destination.

03

Detect

Context-aware detection recognised claims data, policy schedules and personal data in prompts and uploads from day one.

04

Prove

Interaction-level audit trails now feed the quarterly risk committee pack, turning AI governance from a policy statement into evidence.

The results

  • High-risk data submissions to AI tools fell 87% within two months, with most events resolved by a warning the underwriter accepted in the moment.
  • Underwriting kept every tool that was genuinely helping; only the highest-risk flows were blocked, so there was no productivity backlash to manage.
  • The risk committee now reviews real usage data each quarter instead of relying on an acceptable-use policy nobody could verify.
app.culture.ai· AI applicationsLast 90 days
Total apps
105
High risk
34
Active today
67
ChatGPT
chatgpt.com
High Risk
Microsoft Copilot
m365.cloud.microsoft
High Risk
Canva
canva.com
Medium Risk
Grok AI
grok.com
High Risk
Google Translate
translate.google.com
Medium Risk
OpenAI Playground
platform.openai.com
Low Risk
The assessment showed us three times more AI than we had on the approved list. Two weeks of data did more for the business case than six months of policy discussion.
CISO, specialty insurer

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.