Yagub Rahimov, Founder & CEO of Polygraf.ai
The Problem Is Not the Technology. It Is the People Using It.
When a bank CISO told Yagub Rahimov that his organization had addressed the shadow AI problem by making every employee sign a letter promising not to send client data to AI tools, Yagub could not stop laughing.
“Did you tell them you’d tell their mom if they passed the data to AI?”
That moment captures the core of what Polygraf.ai was built to solve. Organizations are trying to govern AI behavior with paperwork, while employees use their personal Claude or ChatGPT accounts to upload policyholder data, sensitive claims records, and client information — every day, at every level of the organization.
In Episode 165 of InsurTechTalk, Yagub joined the show to connect his platform directly to a thread that has been running through several previous episodes: the AI content liability gap, the shadow AI crisis, and the coming wave of deepfake claims fraud. The answer to all three, he argues, is the same: behavioral control at the point of data, running locally, with zero third-party exposure.
About Yagub Rahimov
Yagub Rahimov is the Founder and CEO of Polygraf.ai, an AI behavioral control platform serving finance, insurance, healthcare, defense, and the public sector. He identifies as a libertarian and capitalist, sits on the board of the Academy for Capitalism, and describes Polygraf’s mission as enabling organizations to use whatever AI technology they choose without exposing private or privileged data to third parties. On the day of this recording, Polygraf announced Meeting Guard, a new product identifying deepfake voices, AI-assisted interview cheating, and protecting private data in voice communications.
The Bridge From Episode 161: Who Verifies AI-Generated Content?
Four episodes ago, Cheri Martinen revealed something alarming: GL policies are now being updated to exclude AI-generated content from standard coverage. The gap does not simply move to cyber — many cyber policies are not covering it either.
The question she left unanswered was the right one: if GL does not cover AI-generated content and cyber may not either, who verifies whether a piece of content was AI-generated in the first place when a claim arises?
Yagub’s answer starts with a distinction most people miss: AI-generated and AI-assisted are not the same thing, and the line between them matters enormously. Taking a photo of a car and asking an LLM to add a dent and make it appear red is malicious. Using AI to clean background noise on a call — including the very call this episode was recorded on — is not. Polygraf is a contributing member of C2PA, the coalition working on watermarking standards and policy frameworks to define that distinction formally across the industry.
What Polygraf AI Actually Is
Yagub describes Polygraf as an AI Behavioral Control Plane — a category distinct from AI security, AI governance, and traditional data loss prevention.
The distinction matters. Here is why: 96% of cyber failures are not caused by technology breaking down. They are caused by people — either not knowing the rules, not following them, or deliberately circumventing them. Only 2 to 3% of breaches are technology failures. The rest are behavioral failures, and roughly a quarter of major cyber failures trace back to negligence rather than malicious intent.
Traditional security solutions — DLP, regex-based pattern matching, perimeter controls — are built to catch technology failures. They are remarkably bad at catching behavioral failures, for a specific and underappreciated reason.
The Beverly Hills Problem
Yagub explained it with a concrete example. Traditional DLP using regex looks for patterns that resemble sensitive data — an email address has an @ sign, a beginning, and an ending. But what happens when someone writes “Beverly lives in Beverly Hills and she’ll be at the airport next Thursday, 10 minutes past midday?”
Traditional systems might flag Beverly as a person, but they will miss Beverly Hills as a location, miss “next Thursday” as a date, and miss “10 minutes past midday” as a time identifier — because these do not match the literal pattern of what sensitive data is supposed to look like.
The average accuracy of regex-based DLP for something as simple as email address detection is 68%. That means 32% of email-related data leakage goes undetected by the tools most organizations are relying on today.
Polygraf’s approach is contextual, not pattern-based. It understands that Beverly is a person, Beverly Hills is a location, and next Thursday at midday is a date-time reference — regardless of how that information is phrased or formatted.
The Local Deployment Difference
Every major AI vendor is cloud-first. Polygraf is the opposite.
Yagub’s framing: “You pay AI twice — first with your money, second time with your data.” Microsoft’s Satya Nadella said the same thing publicly the same week this episode was recorded — an alignment that validated the thesis from an unlikely direction.
Polygraf deploys entirely within the customer’s own infrastructure — edge devices, local networks, AWS, Azure, GCP — anywhere with 8 gigabytes of RAM and 1.3 gigahertz of CPU. Zero API exposure. Air-gapped when required. The Polygraf team has no visibility into customer data unless the customer explicitly opens their screen and shows them.
This is not just a privacy preference — it is the only approach that works in regulated environments. An insurance carrier cannot send PHI, PCI data, or policyholder records to a third-party AI platform for analysis. Polygraf eliminates that exposure by running the analysis locally and returning the result without the data ever leaving the enterprise environment.
The technical approach for sensitive data is adapted from a World War II-era encryption methodology: data is anonymized before being sent to any LLM, and the anonymization mapping is held locally. When the result returns, the original information is restored locally. The LLM never sees the real data. The analyst sees the complete result.
Yagub was also clear about what this is not solving through elimination: an analyst with legitimate authority to view sensitive data — but not to transmit it — needs to see the actual information in context, not a redacted version. His point on anonymization taken too far: “hidden number one plus hidden number two” does not produce a usable answer. Nothing plus nothing is still nothing. The goal is controlled visibility, not blind redaction.
The Shadow AI Crisis in Insurance
James Benham described it in Episode 150. The CISO story Yagub told confirmed it is happening everywhere.
Employees are using personal Claude, ChatGPT, or Gemini accounts — sometimes on company credit cards, sometimes on their own — to process claims data, summarize medical records, draft policyholder communications, and run quality assurance on call center recordings. The data leaves the enterprise. The carrier has no visibility. The compliance violation is immediate.
Polygraf’s solution operates inline — monitoring AI prompts in real time and blocking any prompt containing PII, PHI, PCI, or regulated content before it reaches a third-party LLM. Employees get a safe alternative. Security teams get full visibility into violations. The CISO no longer has to rely on a signed letter and hope for the best.
Yagub also flagged specific weak points in current insurance AI deployments: call center QA that routes audio through one LLM for transcription and another for analysis, with only credit card disclosure moments excluded from recording — leaving the rest of the conversation unprotected. And AI-generated document comparison tools that fail to distinguish between malicious manipulation and benign AI assistance, like sharpening a blurry image or removing background noise.
Deepfake Claims Fraud: The Emerging Threat
The fastest-growing problem Polygraf is working to address in insurance is not shadow AI — it is deepfake fraud in claims.
AI tools have made it trivially easy to generate realistic-looking medical records, accident reports, vehicle damage photos, and supporting documentation for fraudulent claims. The cost of fabricating a credible submission is approaching zero.
Polygraf’s multimodal detection — across text, images, and voice — is designed to catch this. Their platform can identify AI-generated claims documents, AI-manipulated photos, and synthetic audio submitted as evidence.
Yagub was candid about one limitation: the ability to identify which specific AI model generated a piece of content — distinguishing DeepSeek from ChatGPT from Claude — is becoming harder as models distill from each other during training. Polygraf was the first company in the world able to distinguish between DeepSeek and OpenAI’s models by name, but that naming accuracy is declining as models increasingly train on each other’s outputs. He pointed to the Alibaba lawsuit alleging distillation from Claude as evidence the industry is watching the same trend. His honest assessment: current model-attribution accuracy is moderate, not the 95% some vendors claim.
Fraud Ring Detection
The more significant capability Polygraf is developing is not identifying individual fraudulent documents — it is mapping the connected network of fraud activity. Their approach, refined through work with the American Security Fund detecting coordinated networks of anti-Semitic bots, applies the same logic to insurance fraud: individual fraudulent submissions rarely come from isolated actors. They come from coordinated rings of parties systematically extracting money from carriers.
Polygraf’s models can map these connections — identifying that multiple seemingly unrelated claims submissions are in fact connected by the same coordinated party. That shift from document-level detection to network-level detection is where the real impact lies: not just catching one fraudulent claim, but exposing the ring behind it, and ultimately reducing the premium increases that fraud passes on to every policyholder.
The Airbnb Lesson: Context Is Everything
Yagub’s personal experience — booking what turned out to be a nonexistent Airbnb property during a trip to the Middle East, with his family counting on the accommodation — illustrated the final point of the conversation with striking clarity.
When he tried to file a claim under Airbnb’s embedded “secure your booking” insurance, the insurer had no mechanism to understand what actually happened. Drop-down menus. Checkbox inputs. A form that had no way to capture that his life may have been endangered, that he arrived in a foreign city with his family and found nothing at the address, that the host disappeared after extracting a wire transfer. The resolution offered: a refund and a $50 Airbnb credit.
The insurer either overpays or underpays because they never understand the context of the claim. The same AI capability that Polygraf uses to extract contextual meaning from unstructured data — understanding Beverly as a person, Beverly Hills as a location, next Thursday as a date — is exactly what insurance claims processing needs to understand what actually happened to a policyholder, not just which box they checked on a form.
Yagub extended this to host diligence directly: the same fraud-ring detection approach used for claims could flag a host as connected to a known malicious network before they are ever allowed onto a platform, forcing a secondary onboarding review rather than waiting for a victim to file a claim after the fact.
What the Industry Is Not Talking About Enough
Yagub’s answer to the standard closing question was direct: insurance companies are not reading the context of submissions. They are reading the form inputs. And that gap — between what a checkbox captures and what actually happened to a policyholder — is where claims get underpaid, fraud goes undetected, and customer trust gets destroyed.
AI can close that gap, but only if insurers invest in understanding what they are actually trying to accomplish before they deploy it. The ones doing it right start with a clear scope, take baby steps, measure each one, and accumulate progress. The ones doing it wrong announce AI initiatives, plug in tools, and wonder why nothing improves — while fraudulent actors are doing the exact same incremental testing, adding small amounts of fraud at a time to see what gets caught.
Key Takeaways
- 96% of cyber failures are behavioral, not technical — and most insurance security tools are built for the 4%
- Regex-based DLP misses 32% of email-related data leakage and far more for unstructured or contextually embedded sensitive data
- The GL exclusion on AI-generated content creates an immediate need for verification technology — Polygraf is one of the only platforms that can provide that verification
- Local deployment is not a preference — it is the only approach that works in regulated insurance environments where data cannot leave the enterprise
- Deepfake claims fraud is moving from isolated incidents to coordinated rings — detection needs to move from document-level to network-level to match the sophistication of the threat
- Context is the missing layer in insurance claims processing — checkbox forms cannot capture what actually happened to a policyholder, and AI that understands context can