Sponsored trade guidance from Applied Systems CIO/CISO reframes is AI safe? into three risks small agencies can actually govern: PII handling, prompt safety, and audit trails.

Via Insurance Journal (EZLynx): AI Without the Risk: A Small Agencys Guide to AI Governance and Data Security
Most growth-focused insurance agency owners want automations efficiency. Many still stall on one question: is AI safe to use with client data? In a July 16, 2026 Insurance Journal sponsored series post for EZLynx, Tanner Randolph-Chief Information Officer and Chief Information Security Officer at Applied Systems-answers with a practical reframing rather than a product hymn (though the piece is explicitly sponsored and promotes EZLynx Virtual Assistant).
His opening premise is the one that matches owner-led reality: if your independent agency has a team of 10 or fewer, you probably do not have in-house IT, a compliance officer, or a CISO to vet every new tool. Protecting client privacy falls on the principal. The useful move is not fear AI; it is splitting AI risk into three addressable categories.
1) Personally identifiable information (PII) handling. How the tool manages sensitive client information-drivers license numbers, dates of birth, policy details-and where that data lives. Randolphs good standard: AI that operates on data already inside the agency management system (AMS), without copy-paste hops between browser windows, and vendors that can state plainly that customer data is never used to train public models.
2) Prompt safety. What staff actually type. The greatest small-agency data risk, he argues, rarely comes from outside attackers; it comes from employees pasting client history into a general-purpose chatbot to summarize a policy. Embedded workflow AI reduces that temptation by removing the need to export data.
3) Audit trails. The operational safety net: what the AI did, which user authorized it, and where that history is permanently recorded for E and O protection. Human-in-the-loop is the default: AI suggests; the licensed agent reviews, edits, and approves before anything enters the record. The AI did it is not a defense file.
Randolph contrasts built-in AMS AI (inherits existing security and logs) with bolted-on consumer chatbots, browser extensions, or loose third-party integrations that move data outside the AMS perimeter. The sponsored ETAC framing-ethical, transparent, accountable, compliant-translates into buyer questions any agency can ask regardless of vendor:
Applieds piece states (vendor-reported) that EZLynx AI models are developed in-house in environments Applied owns or controls, that Applied does not use public AI offerings for that stack, and that identifying information is not used to train a model / no information is used to train a third-party model. Treat those as vendor claims to verify in contracting-not as industry-wide facts.
Red flags Randolph lists travel well beyond EZLynx: vague data-retention answers; tools that force paste into separate windows; AI features that move client data outside the AMS; open chat windows for daily work; missing role-based access; systems that fail to separate personal queries from agency-owned data; autonomous tools without a human checkpoint; invisible AI actions after the fact; and logs that cannot identify which user triggered an action.
Notice what he does not ask you to do: invent a five-year transformation roadmap. He asks you to evaluate architecture-where data lives, whether prompts leave the building, and whether a human signature still exists when E and O counsel calls.
If your independent agency has a team of 10 or fewer, you probably dont have in-house IT, a compliance officer or a CISO to vet every new piece of software.
The checklist is solid even if you never buy EZLynx. The failure mode for small agencies is still shadow paste-into-ChatGPT while the AMS sits unused. AgentsROI.ai is a managed AI services provider for owner-led SMEs-vendor-neutral, so I can pressure-test any AMS or bolt-on against Randolphs three risks.
Shadow-AI Risk Assessment finds where client PII already leaves the AMS via personal accounts and browser tools. Fractional AI Officer turns the three-risk frame into written decision rights, vendor questions, and E and O-defensible review habits. Managed AI Operations keeps approved workflows from quietly reintroducing copy-paste shortcuts six weeks after training.
For agencies evaluating any vendor-including Applied-put Randolphs three risks into the RFP: show us PII data flows, show us how prompts never need to leave the AMS, and show us an immutable log that names the human who approved the AI suggestion. If the salesperson cannot answer in plain English, that is your answer.
Randolphs sponsored guide is useful precisely because it refuses mystique: small agencies do not need a cybersecurity degree; they need PII boundaries, prompt hygiene, and human-labeled audit trails. Adopt AI on those terms, or you are buying busywork reduction with a privacy invoice attached.
If you are the ten-person CISO by default, start with a Shadow-AI Risk Assessment. Book a no-pressure assessment before the next chatbot becomes your unofficial AMS.
This article summarizes publicly reported information and is for general informational purposes only. It does not constitute legal, tax, financial, investment, security, or compliance advice. AgentsROI.ai is not a law firm, accounting firm, or registered investment adviser. Facts, pricing, statistics, and product capabilities cited here reflect the sources listed at the time of writing and may change. Readers should verify current information independently and consult qualified professionals regarding obligations specific to their industry, jurisdiction, and circumstances-including applicable New York State and New York City requirements. AgentsROI.ai may have commercial relationships with vendors mentioned; where material, such relationships are disclosed. Nothing in this article is an endorsement of any specific AI product, model, or provider.