01
Your AI assistant can now open a browser and act. Treat it like a new joiner.
Anthropic added a built-in browser to Claude Desktop and Code, so it can click, type and work across websites with an approval prompt for each new site. A separate 1Password integration lets Claude log into systems without exposing the password itself. The assistant has moved from advising to acting.
CaseFlow angle. Before an acting agent touches a live system such as your case management platform, insurer portal or shared inbox, define the access boundary first. Name which systems it may reach, who approves each new one, and where the action log lives. Onboard it like a member of staff, not as an app.
02
The meter is running on frontier AI. Put a cost code on it.
Anthropic moved Claude Fable 5 off flat-rate plans and onto pay-per-token billing, and OpenAI shipped a routed GPT-5.6 family spanning speed, cost and capability. Cost now attaches to the task, so a careless default can run up a bill fast.
CaseFlow angle. Treat AI spend like a disbursement. Attach a cost code at the matter or claim level, set a rule for which jobs run on the cheaper model and which earn the frontier one, and reconcile it back to the file like counsel or expert fees.
03
You can pay for AI twice, once in fees and once in leaked know-how.
Microsoft's Satya Nadella warned of a double payment risk, where firms pay for AI while feeding proprietary knowledge into it through prompts. Grok Build was reported to have uploaded entire private code repositories to cloud storage, and researchers flagged prompt-injection and context bombing as live attack routes on agents.
CaseFlow angle. Confidential material can leak through what people paste in and through what an agent can reach. Set a paste rule and a reach rule, and put both in your confidentiality and data protection notices.
04
Frontier-grade models you can run in-house are arriving. Ask where your data sits.
Moonshot AI's Kimi K3 landed as a near-frontier open-weights model, 2.8 trillion parameters with a very long context window and open weights due 27 July, and Databricks published research on open-weight cost savings. Capable models are no longer only a rented, cloud-only option.
CaseFlow angle. Open weights mean a capable model can run inside your own boundary, keeping confidential case data off a third party's servers. Ask suppliers where your data sits when the model runs, and whether it can run in an environment you control. Data residency is now a buying criterion.
05
Agentic AI went live in underwriting this week. Claims is next.
Duck Creek bought Send to build an agentic underwriting-to-core platform, Hyperexponential launched a tool that takes a submission from email to a priced risk, and Cytora said the Zurich deployment proves agentic AI is past the pilot stage. The same decisioning pattern is heading for claims and recoveries.
CaseFlow angle. Decide now which claims decisions an agent may draft and which a person must own, and build the audit trail before the tool arrives, not after a complaint lands.