Martin Higgins, Centric Consulting’s national insurance practice lead, authored an article in Crain’s Cleveland Business on the prompt injection and compliance risks insurers face as AI agent adoption accelerates.
In the piece, “AI Agents Are Easy to Deploy. That’s the Problem,” Higgins warns that insurers are moving faster to deploy AI agents than they are to evaluate whether they should.
Cloud providers have made deployment nearly frictionless, and that ease is creating exposure insurers aren’t accounting for. Prompt injection has emerged as a leading AI security risk, particularly for insurers who deploy agents to handle policyholder communications.
“Someone can send an email with malicious instructions, and your agent may oblige simply because it can’t distinguish your prompts from theirs,” he noted.
Agent identity and access controls carry similar risk, Higgins said, since every system an agent can reach becomes a potential entry point. He pointed to AI agent governance practices such as scoped permissions and regular access reviews as foundational to safe deployment, not optional add-ons.
The financial and reputational stakes are different for carriers than for other industries, Higgins said. “The difference in insurance is that the assets at risk aren’t just operational, they’re policyholder data and underwriting intelligence on which the business is built,” he said.
Regulators are already ahead of most carriers’ internal policies, according to Higgins. Twenty-five states now require written AI governance programs, and the National Association of Insurance Commissioners is piloting an AI Systems Evaluation Tool across 12 states.
Frameworks like NIST’s AI Risk Management Framework are starting to give carriers structure, Higgins wrote, but how insurers answer questions about accountability and access will ultimately shape both their risk exposure and their regulatory standing.
Read the full article in Crain’s Cleveland Business.