Employee plans have embraced the use of AI to personalize communications, perform routine administrative tasks, to process benefit claims and appeals, and also to review plan investments. It may sometimes seem like a new world in which many tasks can simply be outsourced, and the time savings are undeniable. Yet we all know that AI can make mistakes and that AI programs can have hidden biases. Since ERISA plan fiduciaries will be responsible for AI’s mistakes, they need to have a clear understanding of the limits ERISA imposes on their ability to outsource to AI and their own responsibilities to review AI-created work product. Even if the fiduciaries are not using AI internally for administration they should not assume they are unaffected by these changes, since their recordkeeper and other third party providers are very probably doing so.
Here is a list of issues that can arise in the most common uses of AI—
1. Communications and Education. Personalized communications are welcomed by many participants, but it is important to remember that the IRS, DOL and PBGC all have regulations that govern the timing and content of required disclosures. A disclosure that fails to include required information could be determined to fail to satisfy the distribution requirement, subjecting the plan sponsor and other responsible fiduciaries to penalties. A seriously deficient Form 5500 could similarly be subjected to penalties for failure to file and even incomplete or inconsistent answers can trigger an audit. In addition, if material information is omitted from communications or misstated, participants may be able to claim additional benefits. See my recent post for an example. All of these documents require human review.
2. Claims and Appeals. The most common use of AI appears to be by third party administrators processing group health plan claims and appeals. The service agreement may indicate that the TPA is a fiduciary for this purpose, but the consequences of wrong decisions or decisions based on biased data still directly affect the workforce whose coverage for treatment may be denied and plan sponsor fiduciaries. Participants can and do sue if they believe their claims and appeals have been improperly denied. If the responsible fiduciaries did not hire a TPA with appropriate procedures or that uses appropriate algorithms to make decisions, they can be liable for imprudently hiring the service provider. Since group health plans must also comply with HIPAA’s Privacy and Security Rules, fiduciaries should also determine whether the use of AI creates additional risks of unauthorized use of protected health information (PHI).
3. Investment Selection and Review. There are vendors with programs that will review a plan’s investment menu, compare performance metrics with other similar investment options, suggesting appropriate changes. While plan sponsor fiduciaries often want help in selecting investments, they should consider whether these services should replace rather than supplement the services of a 3(21) investment adviser or an investment manager described in Section 3(38) of ERISA. These live fiduciaries know the plan and its participants, can attend their committee meetings and personally answer questions. These programs can compare performance against benchmarks quickly and produce lots of comparative data, but fiduciaries should ask questions about the time frame for data, the appropriateness of the chosen benchmarks, and whether there are inherent conflicts of interest. These programs are not fungible.
4. Committee Minutes. Most AI-generated committee minutes I review are deficient. They either read like verbatim recordings of the conversations, which will provide comments that plaintiffs’ lawyers can easily take out of context, or are so short that they leave out legally significant points. That creates litigation risk. If AI is being used to create a first draft, the draft should not just be edited for style. Someone who attended the meeting should make sure nothing significant was left out or misstated, and especially if litigation is anticipated, the minutes should be reviewed by outside counsel.
5. Confidentiality. Fiduciaries should be cognizant of the fact that client confidentiality may be violated If a plan’s non-public personal information is used with features such as “summarize for me”. If agentic AI is being used, AI programs will have direct access to files. This issue can impact plan sponsor or participant information and could even result in HIPAA violations..
6. New Service Agreement Options. Just as many hiring fiduciaries now insist on including provisions on cybersecurity in their service agreements, including their right to examine system audit and penetration test reports, to receive prompt notification of breaches and to insist that the vendor have cybersecurity insurance coverage, hiring fiduciaries should be thinking about negotiating specific provisions on AI in their agreements. These negotiations should include a clear explanation of the purposes for which a vendor uses AI and the review process the vendor uses to test results and catch errors, as well as how the vendor maintains data security. They should also provide for prior plan sponsor review of participant communications and plan filings.
Fiduciaries don’t need to avoid available AI tools that help them work faster and do their job better. However, they should never lose sight of their review responsibilities and the current limitations of AI.
Copyright 2026 Cohen & Buckmann P.C.