Industries / Insurance · insurers & health insurers
AI protection for insurers, built for secrecy under Art. 35 VAG.
Art. 35 VAG places insurance employees under secrecy obligations analogous to banking, and the EU AI Act classifies risk assessment and pricing for life and health insurance as high-risk from August 2026. The same workflow triggers both.
The AI governance framework for insurance
Six obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen at Swiss insurers
An underwriter pastes a customer's medical history into an LLM to summarize a claim. Health data, a special category of personal data, just left the perimeter under the terms of service of a consumer product.
"How do we justify the decision of a fuzzy LLM classifier to the regulator?", the objection we hear from every insurance CISO. A block you cannot explain is a block you cannot defend.
Insurers are already piloting AI agents that read claim submissions, medical reports and correspondence to triage or pre-assess a claim. Those very documents are untrusted content that can carry a hidden prompt injection, and the agent's response can just as easily carry another claimant's health data out.
Writing policies in natural language instead of regex, that is the key differentiator of NativeAI Guard.
Policies, managed
The rulebook for insurers is already written. You adapt it instead of inventing it.
A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
Can the anonymized fields be restored in the model's answer, so the response is still usable?
Re-identification on the return path is in active development and does not ship today; it sits near the front of our development roadmap because several customers have asked for it. What works today: anonymization preserves context. Identifiers become typed placeholders, so the model still produces a useful, correctly structured answer that your people can complete internally.
How do we justify an AI-based blocking decision to a regulator? An LLM classifier looks fuzzy.
By making the decision reconstructable rather than by claiming the model is infallible. Every decision records which policy applied, which data category was detected, the content that triggered it, the action taken and the model version that made the call, so it can be replayed after the fact. Deterministic rules run alongside the semantic layer, so the obligations you must never miss are not left to a probabilistic judgment. And a human override with a logged justification means the final decision has an accountable owner. Regulators generally ask whether a control is documented, consistently applied and auditable, not whether it is deterministic.
We hold health data, banking data and insurance data under one roof. Can policies differ by business line?
Yes, and they should. Policies are scoped per group, business line or team, so Art. 35 VAG, Art. 84 KVG and the rules for health data can be enforced differently where they apply, rather than flattening everything to the strictest common denominator and blocking work that is perfectly legitimate.
Protect your employees' AI usage from Art. 35 VAG exposure, with a pilot phase that we run for you.
An insurance policy starter pack, plus a report for management on data leaks, shadow AI, AI usage and model costs. Anonymize mode lets underwriters and claims teams work at AI speed while customer and health data stay inside the company.