Industry Event Analysis
What Insurtech Security Leaders Should Evaluate at BrokerTech Connect Chicago 2026
A due-diligence checklist for insurance security leaders attending BrokerTech Connect Chicago 2026, focused on the runtime controls that separate a good demo from a deployable AI agent product.
BrokerTech Connect Chicago 2026 runs Sept 1-2 in Chicago and brings together insurance and insurtech leaders, but booth demonstrations alone will not answer whether an AI agent product is safe to deploy against policyholder or claims data. CISOs attending should carry a consistent set of questions covering agent identity, least-privilege permissions, tool-call logging, and containment, and should treat post-event procurement as a security review, not a business handshake.
Event Snapshot
- Event
- BrokerTech Connect Chicago 2026, organized by BrokerTech Ventures
- Dates
- Sept 1-2, 2026
- Location
- Chicago, IL
- Audience
- Insurance carriers, brokerages, and insurtech vendors
- Security lens
- Runtime governance for AI agent products shown on the floor
Architecture Signals Worth Probing in a Vendor Meeting
These five signals separate a scoped, revocable agent deployment from one that quietly holds standing access to underwriting, claims, or policyholder systems. Ask about each one directly during a booth conversation rather than inferring it from a demo.
- 1
Non-human identity
The agent should have a unique identity that can be authenticated, scoped, and revoked separately from any human operator's credentials.
- 2
Task-scoped permissions
Access should be limited to what the specific task requires rather than standing access to underwriting, claims, or policyholder systems.
- 3
Real-time enforcement
Permission boundaries should be enforced during a live session, not only configured once through static role assignments.
- 4
Individual tool-call logging
Each agent-initiated call to an external system should be logged with enough detail to reconstruct what happened and why.
- 5
Contained blast radius
A compromised agent session should be revocable on its own, without requiring a system-wide access shutdown.
Five Questions to Ask Every AI Agent Vendor on the Floor
Use the same question set at every booth so answers can be compared like for like once the event is over.
- What unique identity does the agent use, and can it be authenticated and revoked separately from human credentials?
- Are permissions scoped to the specific task, or does the agent hold standing access to underwriting, claims, or policyholder systems?
- Are permission boundaries enforced in real time during a live session, or only configured once through static roles?
- Is every agent-initiated tool call logged with enough detail to reconstruct what happened and why?
- Can a single compromised session be contained and revoked without a system-wide shutdown?
What Is Confirmed About the Event
BrokerTech Connect Chicago 2026 is organized by BrokerTech Ventures and scheduled for Sept 1-2, 2026 in Chicago. The event has been announced publicly as a gathering of insurance and insurtech leaders, with the organizer's own materials describing it as a venue for connecting carriers, brokerages, and technology vendors. Publicly available announcements confirm the event name, dates, location, and organizer, but do not yet list a confirmed sponsor roster, exhibitor names, or session-level agenda. That absence of published detail is itself useful information for a security leader: it means the value of attendance will come less from pre-reading a program and more from how effectively each vendor conversation is structured on the floor. This article focuses on that structure rather than speculating about which specific companies or products will appear.
The Gap Between a Good Demo and a Deployable Product
Insurtech vendor demonstrations at industry events are built to show functional capability: an underwriting assistant that drafts a quote, a claims agent that triages a file, a broker copilot that answers coverage questions in seconds. None of that is evidence of security architecture. A live demo can look identical whether the underlying agent operates under a shared service account with broad standing access or under a scoped, individually revocable identity. The difference only becomes visible when someone asks about it directly. This matters because procurement conversations that start at a conference booth often move into contract negotiation without a security architect in the room, and by the time a CISO is looped in, commercial terms may already be set. Treating the event as a due-diligence opportunity means asking runtime security questions at the same table where the product is being pitched, not after a term sheet is drafted.
Turning Floor Conversations Into a Defensible Procurement Record
- Ask for a live demo of enforcement: Request an unscripted demonstration of permission boundaries rather than relying on a security slide in the pitch deck.
- Trace the full task lifecycle: Ask the vendor to show how agent access is provisioned, monitored, and de-provisioned from start to finish, not just at setup.
- Confirm log ownership: Establish whether audit logs can be exported to your own SIEM or GRC tooling instead of remaining only in a vendor dashboard.
- Bring security into the room: Ensure a CISO or security architect is part of post-event vendor conversations before any contractual commitment is made.
- Use one checklist for every vendor: Apply the same question set consistently across every booth meeting so responses can be compared like for like.
Governance Considerations Beyond the Event Floor
Carriers and brokerages operate under state insurance department expectations around data handling and third-party vendor oversight, and those expectations extend to any AI agent vendor that will touch policyholder or claims data. Vendor risk assessment processes should treat AI agent runtime permissions as their own review category, separate from standard data security and privacy questionnaires, since agent behavior involves multi-step actions that static questionnaires do not capture well. Any resulting contract should specify audit log retention periods, the buyer's right to access those logs on request, and incident notification timelines specific to agent-related security events. It is also worth documenting, in writing, exactly which security questions were asked at the event and how each vendor responded. That record becomes useful later, both for internal procurement governance and as a reference point if a vendor's answers on the floor do not match what is delivered in a signed agreement.
Turning Vendor Answers Into a Procurement Checklist
The value of a floor conversation holds up only if it is carried into a formal review. These items translate the governance considerations above into steps a security or procurement team can act on after the event.
- Treat AI agent runtime permissions as their own vendor risk review category, separate from standard data security and privacy questionnaires.
- Specify audit log retention periods and the buyer's right to access those logs on request in any resulting contract.
- Define incident notification timelines specific to agent-related security events before signing.
- Document, in writing, which security questions were asked at the event and how each vendor responded.
- Compare each vendor's floor answers against what is actually delivered once the agreement is signed.
Prepare a Runtime Security Checklist Before You Walk the Floor
If your team is evaluating AI agent products at BrokerTech Connect Chicago 2026, a consistent runtime governance checklist makes vendor comparisons defensible after the event, not just interesting during it.
Explore Runtime Governance