{"id":36011,"topic":"ai","source":"Insurance Business","title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","url_hash":"2ed1c856fa95a0fb784dd3f628d87f3a05d99bcd","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMi0AFBVV95cUxNemZ6UU9KaC1TdHBrWGpyZ2VEdmR3SWlIb2JnZ2t2QnlZTTRiZ0pCYnJWN2ZUdDhEZDFvSXVxbng2b21mUU9uNGZyWm82bUotLWlaRXRZT1pidlJqTmdaekJBZUQ0dXNLTGs0QmFYa2haLTBwVTZQdEpiM1NwQ0NPMUtjRlJIRTc5VFBVTVF5eGdjb00tRWh6MFJCZTd0ZXNTNUZLdG0ydDhRem5mSk1YNktCT2VZczMySVY5VWhkam5WZzVia2lxeTlvdHJVUE1O?oc=5\" target=\"_blank\">OSFI maps out AI risk controls for federally regulated insurers</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">Insurance Business</font>","content":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own.\nThe Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations. Generative AI creates content, OSFI notes, while agentic AI adds autonomous reasoning and execution. Both can lift productivity, but they also speed up and scale up cyber and operational risks in ways that test existing risk management frameworks.\nThe bulletin builds on OSFI's earlier work on frontier AI models, and its practices line up with three existing guidelines: B-13 on technology and cyber risk, E-21 on operational risk and resilience, and B-10 on third-party risk.\nOSFI's first concern is governance. AI adoption can move faster than the frameworks meant to oversee it, and systems can operate with little human supervision while leaning heavily on third-party models, data, and application programming interfaces. When senior managers do not fully grasp the technology, OSFI warns, they can lean too hard on vendor assessments. The regulator suggests strengthening management literacy, tying AI strategy to risk appetite, folding AI risk into enterprise risk management, and setting clear limits on how much autonomy a system is given.\nAccuracy is a second theme. Generative AI can produce hallucinated outputs - inaccurate or misleading results - and agentic AI can act on them, triggering downstream actions and data leakage. OSFI advises treating AI outputs as inputs to a decision rather than the decision itself, and keeping a human accountable for material calls.\nThe bulletin also turns to software. Generative AI can write code quickly but may reproduce insecure patterns, and an agent can push flawed code into production on its own. OSFI suggests validating AI-generated code before deployment and enforcing approval checkpoints for high-risk actions.\nOn access, the regulator flags the danger of over-privileged AI agents and shared credentials, pointing to multi-step risks such as data exfiltration through tools or APIs. It recommends unique non-human identities, least-privilege and scoped permissions, and short-lived, just-in-time credentials.\nAI cuts both ways in security, OSFI says. It fuels automated phishing and malicious code, but institutions can also use it to detect and contain threats faster. Finally, the bulletin urges insurers to map their AI dependencies, test outage scenarios, keep manual fallbacks, and require third parties to disclose how they use AI - since a failure in one AI service can ripple across institutions.\nThe full text of the bulletin is available at https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational.","image_url":"https://cdn-res.keymedia.com/cms/images/us/023/0343_639195705667628975.png","lang":"en","published_at":"2026-07-14T03:40:33+00:00","fetched_at":"2026-07-14T05:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}},"news_item":{"id":36011,"canonical_url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","source_url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","source_name":"Insurance Business","author":null,"published_at":"2026-07-14T03:40:33+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMi0AFBVV95cUxNemZ6UU9KaC1TdHBrWGpyZ2VEdmR3SWlIb2JnZ2t2QnlZTTRiZ0pCYnJWN2ZUdDhEZDFvSXVxbng2b21mUU9uNGZyWm82bUotLWlaRXRZT1pidlJqTmdaekJBZUQ0dXNLTGs0QmFYa2haLTBwVTZQdEpiM1NwQ0NPMUtjRlJIRTc5VFBVTVF5eGdjb00tRWh6MFJCZTd0ZXNTNUZLdG0ydDhRem5mSk1YNktCT2VZczMySVY5VWhkam5WZzVia2lxeTlvdHJVUE1O?oc=5\" target=\"_blank\">OSFI maps out AI risk controls for federally regulated insurers</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">Insurance Business</font>","full_text":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own.\nThe Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations. Generative AI creates content, OSFI notes, while agentic AI adds autonomous reasoning and execution. Both can lift productivity, but they also speed up and scale up cyber and operational risks in ways that test existing risk management frameworks.\nThe bulletin builds on OSFI's earlier work on frontier AI models, and its practices line up with three existing guidelines: B-13 on technology and cyber risk, E-21 on operational risk and resilience, and B-10 on third-party risk.\nOSFI's first concern is governance. AI adoption can move faster than the frameworks meant to oversee it, and systems can operate with little human supervision while leaning heavily on third-party models, data, and application programming interfaces. When senior managers do not fully grasp the technology, OSFI warns, they can lean too hard on vendor assessments. The regulator suggests strengthening management literacy, tying AI strategy to risk appetite, folding AI risk into enterprise risk management, and setting clear limits on how much autonomy a system is given.\nAccuracy is a second theme. Generative AI can produce hallucinated outputs - inaccurate or misleading results - and agentic AI can act on them, triggering downstream actions and data leakage. OSFI advises treating AI outputs as inputs to a decision rather than the decision itself, and keeping a human accountable for material calls.\nThe bulletin also turns to software. Generative AI can write code quickly but may reproduce insecure patterns, and an agent can push flawed code into production on its own. OSFI suggests validating AI-generated code before deployment and enforcing approval checkpoints for high-risk actions.\nOn access, the regulator flags the danger of over-privileged AI agents and shared credentials, pointing to multi-step risks such as data exfiltration through tools or APIs. It recommends unique non-human identities, least-privilege and scoped permissions, and short-lived, just-in-time credentials.\nAI cuts both ways in security, OSFI says. It fuels automated phishing and malicious code, but institutions can also use it to detect and contain threats faster. Finally, the bulletin urges insurers to map their AI dependencies, test outage scenarios, keep manual fallbacks, and require third parties to disclose how they use AI - since a failure in one AI service can ripple across institutions.\nThe full text of the bulletin is available at https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational.","excerpt":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 3027 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","summary":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations.","source":"Insurance Business","date":"2026-07-14T03:40:33+00:00","content":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own.\nThe Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations. Generative AI creates content, OSFI notes, while agentic AI adds autonomous reasoning and execution. Both can lift productivity, but they also speed up and scale up cyber and operational risks in ways that test existing risk management frameworks.\nThe bulletin builds on OSFI's earlier work on frontier AI models, and its practices line up with three existing guidelines: B-13 on technology and cyber risk, E-21 on operational risk and resilience, and B-10 on third-party risk.\nOSFI's first concern is governance. AI adoption can move faster than the frameworks meant to oversee it, and systems can operate with little human supervision while leaning heavily on third-party models, data, and application programming interfaces. When senior managers do not fully grasp the technology, OSFI warns, they can lean too hard on vendor assessments. The regulator suggests strengthening management literacy, tying AI strategy to risk appetite, folding AI risk into enterprise risk management, and setting clear limits on how much autonomy a system is given.\nAccuracy is a second theme. Generative AI can produce hallucinated outputs - inaccurate or misleading results - and agentic AI can act on them, triggering downstream actions and data leakage. OSFI advises treating AI outputs as inputs to a decision rather than the decision itself, and keeping a human accountable for material calls.\nThe bulletin also turns to software. Generative AI can write code quickly but may reproduce insecure patterns, and an agent can push flawed code into production on its own. OSFI suggests validating AI-generated code before deployment and enforcing approval checkpoints for high-risk actions.\nOn access, the regulator flags the danger of over-privileged AI agents and shared credentials, pointing to multi-step risks such as data exfiltration through tools or APIs. It recommends unique non-human identities, least-privilege and scoped permissions, and short-lived, just-in-time credentials.\nAI cuts both ways in security, OSFI says. It fuels automated phishing and malicious code, but institutions can also use it to detect and contain threats faster. Finally, the bulletin urges insurers to map their AI dependencies, test outage scenarios, keep manual fallbacks, and require third parties to disclose how they use AI - since a failure in one AI service can ripple across institutions.\nThe full text of the bulletin is available at https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 3027 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/36011","export_markdown":"/api/items/36011/export?format=markdown","export_json":"/api/items/36011/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx"},"formats":{"full":{"id":36011,"title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","source":"Insurance Business","author":null,"published_at":"2026-07-14T03:40:33+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations.","full_text":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own.\nThe Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations. Generative AI creates content, OSFI notes, while agentic AI adds autonomous reasoning and execution. Both can lift productivity, but they also speed up and scale up cyber and operational risks in ways that test existing risk management frameworks.\nThe bulletin builds on OSFI's earlier work on frontier AI models, and its practices line up with three existing guidelines: B-13 on technology and cyber risk, E-21 on operational risk and resilience, and B-10 on third-party risk.\nOSFI's first concern is governance. AI adoption can move faster than the frameworks meant to oversee it, and systems can operate with little human supervision while leaning heavily on third-party models, data, and application programming interfaces. When senior managers do not fully grasp the technology, OSFI warns, they can lean too hard on vendor assessments. The regulator suggests strengthening management literacy, tying AI strategy to risk appetite, folding AI risk into enterprise risk management, and setting clear limits on how much autonomy a system is given.\nAccuracy is a second theme. Generative AI can produce hallucinated outputs - inaccurate or misleading results - and agentic AI can act on them, triggering downstream actions and data leakage. OSFI advises treating AI outputs as inputs to a decision rather than the decision itself, and keeping a human accountable for material calls.\nThe bulletin also turns to software. Generative AI can write code quickly but may reproduce insecure patterns, and an agent can push flawed code into production on its own. OSFI suggests validating AI-generated code before deployment and enforcing approval checkpoints for high-risk actions.\nOn access, the regulator flags the danger of over-privileged AI agents and shared credentials, pointing to multi-step risks such as data exfiltration through tools or APIs. It recommends unique non-human identities, least-privilege and scoped permissions, and short-lived, just-in-time credentials.\nAI cuts both ways in security, OSFI says. It fuels automated phishing and malicious code, but institutions can also use it to detect and contain threats faster. Finally, the bulletin urges insurers to map their AI dependencies, test outage scenarios, keep manual fallbacks, and require third parties to disclose how they use AI - since a failure in one AI service can ripple across institutions.\nThe full text of the bulletin is available at https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational.","reading_time_min":2,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 3027 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}},"actions":{"read":"/item/36011","export_markdown":"/api/items/36011/export?format=markdown","export_json":"/api/items/36011/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx"}},"digest":{"id":36011,"title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","source":"Insurance Business","topic":"ai","published_at":"2026-07-14T03:40:33+00:00","excerpt":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence,…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 3027 characters.","reading_time_min":2,"cluster_id":null},"card":{"display_title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","subtitle":"Insurance Business · 2026-07-14","summary":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July…","badges":["quality:high"],"links":{"read":"/item/36011","original":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","diagnose":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx"},"quality_warning":null},"export":{"title":"OSFI maps out AI risk controls for federally regulated insurers - Insurance Business","url":"https://www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","summary":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own. The Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations.","source":"Insurance Business","date":"2026-07-14T03:40:33+00:00","content":"Canada's financial regulator wants insurers to keep their controls in step with AI systems that can now reason and act on their own.\nThe Office of the Superintendent of Financial Institutions released a bulletin in July 2026 on generative and agentic artificial intelligence, setting out sound practices to help federally regulated institutions - insurers among them - manage the technology's effect on their operations. Generative AI creates content, OSFI notes, while agentic AI adds autonomous reasoning and execution. Both can lift productivity, but they also speed up and scale up cyber and operational risks in ways that test existing risk management frameworks.\nThe bulletin builds on OSFI's earlier work on frontier AI models, and its practices line up with three existing guidelines: B-13 on technology and cyber risk, E-21 on operational risk and resilience, and B-10 on third-party risk.\nOSFI's first concern is governance. AI adoption can move faster than the frameworks meant to oversee it, and systems can operate with little human supervision while leaning heavily on third-party models, data, and application programming interfaces. When senior managers do not fully grasp the technology, OSFI warns, they can lean too hard on vendor assessments. The regulator suggests strengthening management literacy, tying AI strategy to risk appetite, folding AI risk into enterprise risk management, and setting clear limits on how much autonomy a system is given.\nAccuracy is a second theme. Generative AI can produce hallucinated outputs - inaccurate or misleading results - and agentic AI can act on them, triggering downstream actions and data leakage. OSFI advises treating AI outputs as inputs to a decision rather than the decision itself, and keeping a human accountable for material calls.\nThe bulletin also turns to software. Generative AI can write code quickly but may reproduce insecure patterns, and an agent can push flawed code into production on its own. OSFI suggests validating AI-generated code before deployment and enforcing approval checkpoints for high-risk actions.\nOn access, the regulator flags the danger of over-privileged AI agents and shared credentials, pointing to multi-step risks such as data exfiltration through tools or APIs. It recommends unique non-human identities, least-privilege and scoped permissions, and short-lived, just-in-time credentials.\nAI cuts both ways in security, OSFI says. It fuels automated phishing and malicious code, but institutions can also use it to detect and contain threats faster. Finally, the bulletin urges insurers to map their AI dependencies, test outage scenarios, keep manual fallbacks, and require third parties to disclose how they use AI - since a failure in one AI service can ripple across institutions.\nThe full text of the bulletin is available at https://www.osfi-bsif.gc.ca/en/risks/technology-cyber-risk-management/technology-risk-bulletin/generative-agentic-artificial-intelligence-implications-technology-cyber-security-operational.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.insurancebusinessmag.com/ca/news/legal-insights/osfi-maps-out-ai-risk-controls-for-federally-regulated-insurers-582166.aspx","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 3027 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3027 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3027,"summary_length":420,"usable_text_length":3027,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3027,"summary_length":420}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}