Data Report · By Chris Sowa · Published
Last updated
Can an Insurer Use OpenAI Dots on Claim Files?
An insurer needs to verify the data flow, third-party terms and approval record before enabling Dots on claims. Launch safeguards alone do not establish the carrier's required controls for claimant information.

An insurer needs to verify the data flow, third-party terms and approval record before enabling Dots on claims. Launch safeguards alone do not establish the carrier's required controls for claimant information. A claim file can combine identity details, medical information, coverage facts and payment instructions. A rule allowing a reserve update says little about which of those values the model received. This article examines the documented action controls against the evidence a carrier needs for its AI governance and third-party oversight. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.
Key findings
- OpenAI's safety write-up describes what the model sees as webpage text and document content within connected apps; only credentials are kept out.
- The NAIC Model Bulletin had been adopted in 24 states as of March 2025, per Quarles & Brady. It asks for a written AI program covering governance, risk management, third-party oversight and documentation for examiners.
- The Insurance Data Security Model Law (#668) requires an information security program, oversight of third-party service providers and notification of cybersecurity events.
- A dot's boundary-and-approval model "has not yet been tested at scale in production enterprise environments," per Tech Insider.
- A successful prompt injection collects what the agent can read, per OWASP LLM01:2025: the claim file from an agent that reads the page, CLAIMANT_001 from an agent that reads tokens.
What does a dot see on a claims screen?
The parent page carries the Dots facts in full. A dot performs assigned work from a cloud computer OpenAI operates, with a browser that opens the claims platform, the industry databases and the estimating tools an adjuster's session can open. Custom Rules set what it may do on its own and what requires approval; Auto-review checks planned actions; secure sign-in keeps the adjuster's credentials out of the model. What the model receives from each page is the page.
A claim runs from first notice of loss to payment across several screens, each carrying identifiers the task does not need. The claims platform shows the claimant's name, SSN, address and date of birth. The loss database shows prior claims under the same identifiers, the estimating tool the property address, the payment screen the claimant's bank account. The Guidewire page and the Duck Creek page walk the screens platform by platform. A dot reads all of it. The workspace default of not training on content governs what happens afterward, not what the model held during the run.
What does the NAIC Model Bulletin ask of an insurer's AI program?
The NAIC Model Bulletin sets out regulators' expectations for insurers' use of AI systems in decisions affecting consumers, adopted in 24 states as of March 2025 per Quarles & Brady. It asks each insurer for a written AI systems program covering governance, risk management and internal controls. The program must also cover oversight of third parties that supply AI systems or data, and documentation the department can request in an examination.
Three of those expectations meet the dot directly. Governance asks who decided the AI could read the claim file; a dot's Custom Rules are set by the adjuster who enabled it, a user setting rather than an insurer's program. Third-party oversight asks what the insurer knows about the vendor whose model holds the claimant's data; OpenAI's launch material names no certification for Dots. Documentation asks for a record of what the AI did on a claim; Dots keeps that in Activity View, inside ChatGPT. Each is simplest to answer when the insurer's own record shows three things: the model received CLAIMANT_001, a named claims manager confirmed the exposure policy, and every payment carries an adjuster's name.
What does the Insurance Data Security Model Law require for third-party service providers?
The Insurance Data Security Model Law (#668) requires a licensee to maintain a written information security program based on a risk assessment. The licensee must exercise due diligence over third-party service providers, require appropriate safeguards for its nonpublic information, and notify the commissioner of a cybersecurity event. Nonpublic information includes the identifiers and health information a claim file carries.
A model that reads the claim file in the vendor's cloud is a third-party service provider holding nonpublic information. The oversight obligation follows what it holds. When the model receives the page, the provider holds the claimant's SSN, bank account and medical detail for every claim the agent touched. When the model receives tokens from an environment the insurer owns, with keys the insurer holds, the provider holds CLAIMANT_001 and ACCT_001. An event at the model vendor exposes tokens with no meaning outside the environment. Separation of model and control is what makes the second design possible.
Who approves the payment?
In Dots, the user does, under Custom Rules that can allow some actions to run on their own, with Auto-review as a check inside OpenAI's system. In the insurer's governed environment, a named adjuster with existing payment authority approves the indemnity payment, every time. The real bank account resolves only at the payment screen at the moment of the approved action, and the approval lands in the record with the adjuster's name. Who Approves an AI Agent's Claim Payment? sets out why the answer has to be a person.
What would a state examiner find in each design?
| Control | Dots | RedactSure governed environment | What the examiner asks |
|---|---|---|---|
| Claimant identifiers in model context | Name, SSN, date of birth, bank account | CLAIMANT_001, SSN_001, ACCT_001; real values resolve only at approved destinations | What did the model receive for this claim? |
| Medical detail in an injury claim | Provider notes in full, name attached | Identifiers tokenized; clinical facts in clear where policy says so | Was the minimum necessary applied? |
| Third-party oversight evidence | Launch material; no certification named | Insurer-owned environment; the model vendor holds tokens | What does the provider hold? |
| Examiner-readable record | Activity View in ChatGPT | AI Control Record, exported to the insurer's SIEM | Produce the record for CLAIM_001 |
| Who approves the payment | The user; some actions may run on their own | A named adjuster, every time, on the record | Whose name is on the payment? |
| Injection collects | The page, credentials excepted | Tokens; the payment stops for the adjuster | What can a bad page reach? |
| Keys | Not disclosed | Insurer-held; RedactSure holds ciphertext it cannot decrypt | Who can decrypt the claim data? |
| Model | GPT-6 Astra | Any, swappable without moving the controls | Can we change vendors and keep the controls? |
The rows are one question asked eight ways: what left the insurer's control, and can the insurer show it? In the first column the answer is the claim file, kept in the vendor's log, approved under a user's settings. In the second it is tokens, kept in the insurer's SIEM, approved by a named adjuster.
Where does RedactSure sit?
RedactSure's environment is built for the second column. AI co-workers do real work across the insurer's applications inside a governed environment, with no per-application integration and no change to user permissions. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model receives the claim's fields rather than a picture of the screen, so the claimant's SSN, bank account and medical detail never enter the model. Amounts, dates and loss details stay in clear where the policy says so. The Planner sets which values are tokenized and what the agent may do on each screen. A named claims manager confirms that policy, and a named adjuster approves every payment and record change while it runs, which is Supervised Delegation.
That is what the insurer avoids: an examination in which the third-party oversight file, the record and the payment approval all sit with a vendor. Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the insurer's SIEM. The environment runs in the cloud the insurer's posture requires, with keys the insurer holds, and works with any model. Insurance deployments are in pilot.
Methodology and limitations
The page rests on OpenAI's "How we build safety, security and privacy into dots" (September 29, 2026), cited with their dates. The regulatory instruments are the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and the Insurance Data Security Model Law (#668). Both are cited from the NAIC's text, with the bulletin's adoption map. OWASP's LLM01:2025 entry is cited from its text. Quarles & Brady's March 2025 count and Tech Insider's 2026 comparison are cited as those authors' views. State enactments are not surveyed. Where OpenAI's documentation is silent, the page says so rather than inferring. All sources were read as of September 30, 2026.
No hands-on testing of Dots was performed; what a dot receives from a claim screen is OpenAI's own description. OpenAI refers to a system card and enterprise terms not available for this reading; those could disclose certifications, key management, training defaults or an activity export. The count of 24 adopting states is a law firm's figure as of March 2025 and has likely changed. The two instruments take effect only as each state adopts them, with variations. Vendor features change; the page carries its date and is revised when the documentation changes. The claim file examples describe a record type, not any insurer; no customer or prospect is described.
Whether a deployment meets the NAIC bulletin's expectations belongs to the insurer's counsel and compliance officer, not to this page.
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026)
- NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adoption map
- NAIC, Insurance Data Security Model Law (#668)
We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.
What the record shows
An insurer needs to verify the data flow, third-party terms and approval record before enabling Dots on claims. Launch safeguards alone do not establish the carrier's required controls for claimant information. For one claim, identify the fields the model receives and the person or policy authorizing each payment or record change.
Frequently asked questions
What does a dot see in Guidewire ClaimCenter?
The screen, as text: the claimant's name, SSN, address, date of birth, policy number, the loss description and, on the payment screen, the bank account. OpenAI describes what the model receives as webpage text and document content. Can an AI Agent Work Guidewire Claims Without PII? shows the same screens with identifiers as tokens and the loss facts in clear.
Does the NAIC bulletin apply to an agent an adjuster enables on their own?
The bulletin addresses the insurer's use of AI systems in decisions affecting consumers, however the system arrived. An adjuster who enables a dot on claim files has put an AI system into a claims decision, and the governance, third-party oversight and documentation expectations attach to the insurer. Whether its policy permits such enablement at all is the first question its program should answer.
Can the fraud unit still see the full record?
Yes. Permissions do not change; a special investigator with access to the full claim file keeps it, in the claims platform, exactly as today. What changes is what the AI sees: the agent works on CLAIMANT_001 and ACCT_001, and the operator watching the run inside the environment sees the same tokenized stream.
What about medical records inside an injury claim?
An injury claim carries provider notes and diagnoses alongside the claimant's identifiers. In a dot the model reads the notes with the name attached. In a RedactSure environment the identifiers are tokenized before the model reads the screen. The clinical facts the reserve needs stay in clear where policy says so, which keeps the exposure aligned with the minimum necessary standard.
Who is the third-party service provider, OpenAI or the environment owner?
Under Model Law 668, any third party that maintains, processes or is otherwise permitted access to the licensee's nonpublic information through its services. With a dot, OpenAI's model and cloud computer hold the claim file. With a RedactSure environment the insurer owns, the model vendor receives tokens and RedactSure holds ciphertext it cannot decrypt, so the oversight obligation follows far less data.
What does a successful prompt injection collect from a claims agent?
Whatever the agent can read. OWASP LLM01:2025 describes injection as instructions arriving through content the model processes. A claims agent processes correspondence, uploaded documents and web pages. Against a dot, it collects the page, credentials excepted. Against a tethered agent reading tokens, it collects CLAIMANT_001 and ACCT_001, and the payment still stops for a named adjuster.
Sources
Vendor documentation
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
Regulation and standards
- NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adoption map. https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
- NAIC, Insurance Data Security Model Law (#668). https://content.naic.org/sites/default/files/model-law-668.pdf
- OWASP, LLM01:2025 Prompt Injection. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
Independent analysis and press
- Quarles & Brady, "Nearly Half of States Have Now Adopted NAIC Model Bulletin" (March 2025). https://www.quarles.com/newsroom/publications/nearly-half-of-states-have-now-adopted-naic-model-bulletin-on-insurers-use-of-ai
- Tech Insider, "OpenAI Dots vs Meta Muse" (2026). https://tech-insider.org/openai-dots-meta-muse-enterprise-agent-2026/
RedactSure documents
- RedactSure, "Secure AI Across the Insurance Value Chain" (2026). https://redactsure.com/blog/secure-ai-across-the-insurance-value-chain/
- RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
- RedactSure Research, "Can an AI Agent Work Claim Files in Guidewire Without Exposing PII?" (2026). https://redactsure.com/research/ai-agent-claims-guidewire-pii
- RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
- RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
- RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
- RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
- RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; Guidewire and ClaimCenter are trademarks of Guidewire Software; Duck Creek is a trademark of Duck Creek Technologies; named to identify the product. Compliance determinations belong to the organization's counsel.
See it on your workflow.
Bring one billing, collections, claims or patient-account workflow and your questions.
Book a demo



