# AI security and governance built for insurers.

> AI governance for insurers, in ColossalX, means one owned inventory of the models, agents and AI vendors in underwriting, claims and service, policyholder data redacted from prompts and answers, an owner and a second approver before an agent is admitted, IRDAI cyber circulars mapped beside India DPDP, and evidence graded by how it was obtained.

Govern the AI in underwriting and claims, keep policyholder data out of prompts and show auditors evidence graded by how it was obtained.

Canonical page: https://colossalx.tech/solutions/insurance · Last reviewed: 6 Oct 2026

*Illustration:* Policyholder data · at the gateway: claims-bot held for a person before ColossalX (payout); underwriter to ColossalX; service-bot refused before ColossalX (injection); ColossalX with data redacted, to provider A (health ID redacted).

## Why insurers are looking hard at AI now.

BFSI is attacked more often, financial services pay the most for a breach, and AI controls are still being built.

- 1.6 times: the global average: the rate at which Indian banking, financial services and insurance are attacked (DSCI-BCG, 28 May 2026, https://www.dsci.in/files/content/press-release/2026/cyber-threats-escalate-across-indian-financial-institutions-as-ai-reshapes-the-cybersecurity-landscape.pdf)
- INR 40.9 crore: average cost of a breach in Indian financial services (INR 409 million), the highest of any sector in India (IBM Cost of a Data Breach India 2026, 3 Aug 2026, https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026)
- 58%: of executives surveyed reported an AI-related security issue or close call in the last 12 months (Okta, AI Agents at Work 2026, 27 May 2026, https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/)

DSCI and BCG found that AI-specific controls such as formal AI governance, agent monitoring and runtime guardrails are "still being built across the sector" (DSCI-BCG, Indian BFSI cyber threat study, 28 May 2026, https://www.dsci.in/files/content/press-release/2026/cyber-threats-escalate-across-indian-financial-institutions-as-ai-reshapes-the-cybersecurity-landscape.pdf)

## Where AI meets policyholder data, and what holds it.

Four places where AI meets policyholder data, each held by a control.

- **The threat:** Nobody can say which policyholder data reached which outside model. **The control:** Lineage from gateway traffic shows which agent sent which kinds of personal data to which model. [Data lineage](https://colossalx.tech/platform/data-lineage)
- **The threat:** A claims agent approves a payout with nobody looking. **The control:** A risky tool call waits for a named person; if the check cannot run, it waits. [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)
- **The threat:** An underwriting agent goes live before anyone owns or reviews it. **The control:** Registered is not approved: an owner, a second approver and guardrails come first. [Agent identity](https://colossalx.tech/platform/agent-identity)
- **The threat:** Third-party AI vendors are in use, but nobody assessed them. **The control:** The AI vendor inventory flags each vendor in use but not assessed. [Risk quantification](https://colossalx.tech/platform/risk-quantification)

## What regulators ask for, and how ColossalX relates.

Mapped frameworks, what each asks of an insurer, and the dates that matter.

| Instrument | What it asks for | How ColossalX relates |
| --- | --- | --- |
| IRDAI cyber circulars | Information and cyber security governance, controls and incident reporting for insurers. | Mapped to |
| India DPDP | Consent and purpose limits for personal data, with consent managers. | Mapped to |
| EU AI Act | For insurers serving the EU: life and health pricing AI is high-risk. | Mapped to |
| ISO/IEC 42001 | An AI management system: policy, roles, risk and controls. | Mapped to |
| NIST AI RMF | Govern, map, measure and manage AI risk across its life. | Mapped to |
| GDPR | Lawful basis, purpose limits and rights for EU personal data. | Mapped to |

### Regulatory clock

- 13 Nov 2026: India DPDP consent manager rules start (PIB, DPDP Rules 2025, https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
- 13 May 2027: India DPDP core obligations start (PIB, DPDP Rules 2025, https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
- 2 Dec 2027: EU AI Act Annex III high-risk obligations apply (Gibson Dunn, https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/)

## What you see, and what you can show an auditor.

An agent caught calling through the gateway before anyone owned it, beside the evidence pack an auditor can check.

- Which agents run in underwriting and claims, who owns each, and how each one entered the inventory.
- Each redaction, refusal and approval hold, with the policy that made it.
- AI vendors in use but not assessed, carried into the risk register as owned work.
- Evidence graded A to D by how it was obtained, verified by a second person.

*Illustration:* An illustrative agent dossier for a claims triage agent found in gateway traffic: its own identity and trust zone, an admission checklist with a guardrail profile, an accountable owner and a second approver, and the controls to suspend, quarantine or kill it.

*Illustration:* Evidence pack · an outline: Inventory Models, agents and vendors, owned; Admission Owner and second approver, recorded; Runtime Redactions, refusals, approval holds; Audit A sealed, timestamped archive. Graded A to D.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## What ColossalX does not do

- Monitor-then-enforce rollouts let an unadmitted agent keep serving under a time-boxed exception.
- Redaction finds the identifiers its presets and your own patterns describe, not ones nobody defined.
- Jurisdiction-pack content is a starting point for your counsel to review, not legal advice.
- ColossalX holds no certification and is delivered as SaaS only.

*Illustration:* Admission · monitor, then enforce: Day 0 Agent seen in traffic (not yet registered); Day 0 Time-boxed exception (monitor mode, still serving); Day 30 Exception expires (owner and approver needed).

## Questions

### How should insurers govern AI used in underwriting and claims?

Start with an inventory of the models, agents and AI vendors used in underwriting and claims, with an owner for each. Then control what they do with policyholder data, hold high-impact actions such as payouts for a named person, test the defences and keep the evidence. ColossalX covers each step, from inventory to graded evidence.

### Does ColossalX map the IRDAI cyber circulars?

Yes. ColossalX maps its controls to the IRDAI cyber circulars alongside India DPDP, ISO/IEC 42001, NIST AI RMF, the EU AI Act, SOC 2 and GDPR, and assesses them from live signals. Frameworks are mapped to and assessed against, never certified; ColossalX holds no certification of its own, and jurisdiction-pack content is a starting point for your counsel.

### How is policyholder data protected in AI prompts?

Guardrails at the AI gateway detect personal data in prompts and answers and redact it, using presets for India DPDP, EU GDPR, US HIPAA, PCI DSS and others, plus your own identifiers such as policy numbers. Data lineage then shows which agent sent which kinds of personal data to which model.

### How do we prove AI controls to auditors?

Hand them evidence that collects itself from runtime signals, graded A to D by how it was obtained, verified by a second person and timestamped daily. Withdrawn evidence is kept, not deleted, and an audit runs from a risk-based plan to a sealed, timestamped archive, with findings carried into the risk register.

### Can we track third-party AI vendors that are in use but not assessed?

Yes. The AI vendor inventory in the risk register flags vendors that are in use but not assessed, and findings about them become owned work. Threat intelligence matched to your vendors and models turns a warning about a model into a recorded decision, which can become a restriction at the gateway.

## Sources

- Regulation (EU) 2024/1689, the EU AI Act, Annex III point 5(c) (EUR-Lex), 13 Jun 2024: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
