The ERISA risk nobody talks about: why building benefits AI in-house could be a personal liability problem for your plan sponsor

Nick Cecil

Nick Cecil

CTO

Let AI summarize this content:

Summary

March 30, 2026

I run the engineering team at Avante. We build AI that answers employees' benefits questions. Many assume that the most important reason to buy our benefits AI is that it's very hard to build something accurate and effective themselves. While this is true, there's a risk no one thinks about, but it’s arguably even more important.

If your company is thinking about building benefits AI internally, the biggest risk isn't technical. It's a federal law called ERISA that most engineering teams have never heard of, and that could make the people behind your internal AI tool personally liable for the guidance it gives.

The conversations I keep hearing from prospects follow the same pattern. An engineering leader or CTO hears that the company wants an AI chatbot for benefits questions and thinks: we have an LLM, we have plan documents, how hard can this be? That's a reasonable instinct. It's also a dangerous one.

Key Takeaways

  • ERISA assigns fiduciary status based on function, not intent. If your AI interprets plan language and guides employee decisions, the plan sponsor who authorizes it, and the individuals who deploy it, may have breached their duty of prudence under federal law.
  • Benefits guidance is uniquely high-stakes for AI. A wrong answer about a formulary tier or accumulator during open enrollment can affect thousands of employees. Under ERISA, that exposure is personal, not just corporate.
  • Working with a specialist vendor is a recognized way to meet ERISA's prudence standard. Documented vendor diligence gives your legal and compliance teams a defensible posture. An internal build makes that defense much harder to construct.

What is ERISA, and why should teams building benefits AI care?

ERISA stands for the Employee Retirement Income Security Act. It's a federal law governing employer-sponsored benefit plans, and it establishes fiduciary duties for anyone involved in administering those plans.

Here's what catches most technical teams off guard: fiduciary status under ERISA is based on the functions you perform, not your job title or intentions. The legal term is "functional fiduciary," and it means that if you build an AI tool that exercises discretionary authority in how it interprets plan language and guides employees, the people responsible for that tool, from the plan sponsor who authorized it to the engineering leaders and administrators who deployed it, may have fiduciary obligations whether they designed it that way or not. 

And fiduciary liability under ERISA is personal. It doesn't just land on the company. The plan sponsor is always the fiduciary. But the liability can also reach the individuals who operationally deploy a poorly governed AI tool without adequate expertise or oversight, whether that's a named plan administrator, a benefits committee, or the HR leaders who greenlit the project. That's personal liability, not just corporate exposure, for specific people in your organization. If you're an engineering leader evaluating this project, that should change how you think about the risk.

Why benefits AI is different from every other internal tool you've built

Most internal AI tools operate in a forgiving environment. If a chatbot gives a bad answer about your company's PTO policy, someone catches it and you push a fix. Nobody gets sued. The blast radius of a wrong answer is small and temporary.

Benefits guidance is fundamentally different.

The stakes are financial and medical. When an employee asks "which plan covers my daughter's medication?" or "how does my deductible accumulator work?", they're making real decisions about their family's healthcare and their household budget. A wrong answer can cost someone thousands of dollars or delay necessary medical care.

The scale of impact is different too. If your internal tool misreads a formulary tier or gets accumulator logic wrong during open enrollment, that error doesn't affect one employee. It can affect thousands, all making decisions based on what your tool told them.

And then there's ERISA, which changes the calculus entirely.

The "functional fiduciary" problem

The question that matters under ERISA isn't "did we intend to act as a fiduciary?" It's "did the tool exercise discretion in interpreting plan terms and providing guidance to employees?" If the answer is yes, the people who built and operate that tool may be fiduciaries in the eyes of the law.

Most engineering teams will instinctively respond: "We'd just provide information, not make decisions." I understand the impulse. But the line between informational and discretionary is far blurrier than it appears. If your AI tool takes ambiguous plan language, interprets it, and gives an employee a specific answer about what's covered, what their cost will be, or which plan is the better fit, that looks discretionary. Courts have gone both ways on where exactly the line falls, which is precisely the problem. Ambiguity here means litigation risk.

Another common response: "We'd add a disclaimer." This one worries me more, because it reveals a misunderstanding of how ERISA works. You can't waive fiduciary duties with a terms-of-service page. And adding a 'consult your plan documents' disclaimer doesn't make a “guidance tool” an “information tool” if it's functioning like one. ERISA's protections exist for plan participants, and those protections aren't something you can disclaim in a footer.

What personal fiduciary liability actually means

Under ERISA Section 409, a fiduciary who breaches their duties can be personally liable to make good any losses to the plan resulting from the breach. This isn't theoretical. ERISA litigation is common, and the Department of Labor actively investigates fiduciary breaches.

For an engineering leader, this creates an uncomfortable situation. You build an AI tool as a technical project. It starts answering benefits questions. It gets something wrong about an HSA contribution limit, or it misinterprets a plan's coordination of benefits rules, or it gives incorrect guidance about a prior authorization requirement. Employees rely on that guidance and make decisions based on it.

Now a plaintiff's attorney, or the DOL, starts asking: What benefits expertise did the team that built this have? How did you validate the accuracy of the guidance? What's your ongoing monitoring process? Who is accountable for the outputs?

The engineering team created the risk. But the fiduciary exposure lands on the plan sponsor, and on the individuals responsible for plan administration, who put an ungoverned tool into production. Those questions are much harder to answer when the tool was an internal engineering project than when it was a vetted vendor relationship with documented diligence.

The domain complexity compounds the legal risk

Even setting ERISA aside, benefits AI is genuinely hard to build well. I know this because my team does it full-time, and the complexity still surprises us.

Benefits plan documents are dense, inconsistent, and full of provisions that interact with each other in non-obvious ways. A Summary Plan Description for a single medical plan might be 80 pages. A large employer might have dozens of plans across medical, dental, vision, life, disability, FSA, HSA, EAP, commuter benefits, legal plans, and more. Each has its own rules, its own edge cases, and its own interaction effects with the others.

Then there's the problem of change. Plans update annually, sometimes more often. Carrier formularies change quarterly. Regulatory requirements shift. An AI system that was accurate in January might give wrong answers in March if it hasn't ingested the latest formulary update or plan amendment.

Generic LLMs, even very good ones, don't understand the structure of a benefits ecosystem. They don't know how an accumulator interacts with a deductible, how a coordination of benefits clause works when both spouses have employer coverage, or how to navigate the difference between allowed amount, billed amount, and member responsibility. These aren't things you can solve with better prompting. They require purpose-built document parsing, domain-specific validation, and continuous monitoring against ground truth.

When you combine this technical complexity with ERISA's fiduciary framework, the risk profile of an internal build becomes clear. You're not just building software that might have bugs. Bugs can trigger personal legal liability for the plan sponsor and for the individuals responsible for plan administration who deployed it.

How working with a specialist vendor changes the equation

The plan sponsor is always the fiduciary. Working with a specialist vendor doesn't transfer that obligation. What it does is give you the documented diligence and operational rigor that satisfies ERISA's prudence standard, the same defense that protects plan sponsors who work with TPAs, PBMs, and carriers.

ERISA's prudence standard requires fiduciaries to act with the care and diligence of a knowledgeable person in similar circumstances. One of the recognized ways to meet that standard is to select a qualified expert, document your diligence process, and monitor the vendor on an ongoing basis.

This is the same pattern benefits teams already follow for every other critical vendor relationship. When a plan sponsor gets challenged on a decision, their defense is: "Here's our process. Here's how we evaluated options. Here's the expert we hired. Here's how we monitored them." That paper trail is what protects them.

You're still the fiduciary. But working with a specialist vendor converts 'we built it in-house and hope we got it right' into something benefits counsel will immediately recognize: a rigorous selection and monitoring process with a domain specialist. That's a defensible posture, and it's exactly what ERISA's duty of prudence contemplates.

Build it internally, and that defense gets much harder to construct. You're still responsible either way, but one path gives you a well-documented diligence process and the other leaves you explaining why your engineering team was qualified to interpret plan language at scale.

What I'd tell an engineering leader evaluating this decision

The technical challenge is solvable. I wouldn't be doing this work if I didn't believe that. But solving it requires a level of domain investment, specialized infrastructure, and ongoing validation that goes far beyond wiring up an LLM to a document store.

The ERISA dimension adds a layer that's entirely outside how most engineering teams think about risk. I'm not a lawyer, and I'm not trying to play one in this post. But I've spent enough time in the benefits world to know that the intersection of AI and fiduciary duty is a conversation you want to have with your legal and compliance teams before you greenlight an internal build, not after.

If you tell a good engineering team "don't build that, it's too complicated," you're risking someone thinking "challenge accepted." I get it. I've been that person. But the ERISA angle isn't about complexity. It's about a federal regulatory framework that assigns personal liability based on the functions your software performs, regardless of who built it or what they intended. That's not a risk you can engineer your way out of. It's a risk you mitigate by working with someone who's already built the domain expertise, accuracy infrastructure, and operational rigor around it.

See how we built our enterprise AI benefits platform

Hear how AI is transforming benefits

Sign up to receive industry insights, thought leadership, event invites, blog highlights and Avante company updates.

Related content

No items found.
Accuracy, compliance, and ethics in AI

Article

Accuracy, compliance, and ethics in AI

AI safety
Compliance & security
decorative

Case Study

How Samsung’s benefits team became AI-native

Challenge

A benefits program running on disconnected data

Samsung Semiconductor’s benefits team was running a multi-million-dollar program, but their data couldn’t tell them whether it was working the way they intended, or help them shape strategy and make the case for change to leadership. Claims, Rx, dental, vision, point solution, and wellness data all arrived directly from vendors, each source on its own, never reconciled, leaving the team no way to reason across them.

The pressure came to a head at renewal. Samsung’s point solution contracts were all up at once, and the performance guarantees underneath them rested on each vendor’s own anticipated ROI, quantified largely from employee attestations rather than objective data. Sarah Schutzberger, Samsung Semiconductor’s Benefits and Wellness Sr. Manager, who is responsible for the entire program, wanted to stop relying on fragmented information and tie every point solution back to actual claims. At the same time, with the team scaling for growth and employees increasingly expecting AI-grade speed, she wanted to modernize the employee experience too.

“Everything before Ava was fragmented. We relied a lot on the data being provided directly to us from our vendors. Now we’re able to connect the dots between each of our benefits to truly understand the employee impact.”

Sarah Schutzberger
Benefits and HR Operations Sr Manager, Samsung

Solution

Two agents, one connected platform

Samsung Semiconductor deployed Avante’s AI-native benefits intelligence platform. It securely brings together claims and eligibility, point solution data, plan documents, and the vendor contracts behind them into the Vault, and two purpose-built AI agents sit on top of that shared foundation. For most benefits teams, those sources never connect. With Avante, they do.

Ava

Ava, the agent for the benefits team, reasons over all of it, reconciling vendor contracts and reports against the actual claims on demand. It can generate reports and build branded presentations. The team can bring its own data too, uploading spreadsheets, PDFs, and files into a conversation. It acts like an expert benefits teammate that knows the company, its programs, and its goals, and delivers objective, near real-time insights when they’re needed. “I was looking for a data warehouse,” said Sarah, “and this is so much better. Instead of static dashboards or sending requests to an analyst, I have real-time insights at my fingertips on any question I have.”

Screens are illustrative. Names and data shown are fictional to protect user privacy.

Carly

Carly, the agent for employees, gives Samsung’s workforce real-time, accurate answers to benefits questions, and prompts the right next step rather than answering only the literal question. It helps employees find and use benefits they did not even know they had, at the exact moments they need them most.

Screens are illustrative. Names and data shown are fictional to protect user privacy.

Together, the two agents give the entire company a complete picture of its own benefits, making the use cases below possible for the first time.

Results

What the team does with Ava

The use cases are virtually endless, from building reports to making the case for new programs, from developing customized communications to pressure-testing plan redesign decisions. These are just a few the team acted on in its first three months with Ava.

Use case 1: 66% increase in Lyra utilization

Lyra had traction, with strong engagement and a high share of employees in care relative to its book of business. But when the team dug into behavioral health using Ava, they were able to compare utilization across Lyra and the medical plan, the EAP and the carrier, two datasets that almost never get connected. They surfaced a gap they could not have seen before: a large share of dependents, especially children, were routing through the medical plan for behavioral health instead of starting with Lyra, where the team wants people to begin. The stakes are meaningful: care comes in on day one through Lyra, versus waits of two weeks or more through the medical plan.

The team used Ava to draft communications for that exact parent-and-dependent population, timed to Mental Health Awareness Month, and sent them that week. They also took the finding back to Lyra so it could sharpen its own outreach, and opened a conversation with the medical plan provider about surfacing Lyra first inside the portal. The result: from the first communications in May through the end of June, engagement with the dependent population improved and utilization increased 66%.

“It was a ten-minute chat with Ava that gave us key insights, so we could make targeted communications and address the exact gap instead of throwing spaghetti at the wall and sending out marketing materials that weren’t necessarily hitting.”

Cara Ayala, RD, CPT, CHC
Wellness and Benefits, Associate Manager, Samsung

Use case 2: Making the case for healthier food options

As dietitians, Sarah and Cara had wanted to address nutrition through the company café for years, and the project kept getting pushed aside. Working from the claims data, they pulled the disease states most influenced by nutrition, gave Ava their clinical guidance (whole-foods-first, plant-forward, lean proteins, healthy fats, and a simple green/yellow/red system employees could follow), and used Ava to produce an evidence-based meal program.

The café team now plans to use this framework during the current RFP process to ensure the new vendor is able to execute successfully. Additionally, the team will track the changes in their food program along with medical claims to see the impact. A project that had waited years came together in a single 2-hour planning session.

“Revamping our cafe and food options has been a passion project of ours, but it’s a project that gets pushed to the wayside year after year. But with Ava, it is now possible to move forward.”

Cara Ayala, RD, CPT, CHC
Wellness and Benefits, Associate Manager, Samsung

Use case 3: Building an airtight sabbatical program ROI proposal

Hortencia Alcazar, the Senior Benefits Analyst at Samsung Semiconductor, had built a sabbatical analysis by hand about two years ago. It took two to three weeks of research, formatting, and modeling. She rebuilt it this year with Ava, and it came together in a few hours. Ava pulled in turnover, mental health burnout claims, replacement cost, and tenure assumptions to model ROI at different vesting points, then packaged the work as an executive summary and slides ready for leadership. What stuck with Hortencia and the team was that when they tried to trick it with the data, it held its logic and double-checked them, reasoning exactly as they would have. The proposal is now slated for Samsung’s 2027 program.

“I’d classify Ava as a thought partner and an analyzer.”

Hortencia Alcazar
Senior Benefits Analyst, Samsung

Endless possibilities for AI-native teams

In addition to the use cases above, the team:

  • Built a custom manager support guide for mental health crises in minutes by combining Samsung’s own mental health crisis-response document with materials from Lyra
  • Assessed whether their preventative care solution was reducing cardiovascular disease and diabetes and found low engagement among comorbid members who need it most, driving targeted communications
  • Explored redesigning the medical plan for next year, including options such as a migration from the OAP to an HDHP, which will inform future negotiations
  • and more…
Results

What Carly does for employees

Before Carly, an employee who wrote to the shared service center could wait more than 48 hours for a reply, and often got an answer to only the exact question they had asked. Carly answers in real time, meeting the employee where they are with personalized guidance. 16% of questions come in after hours, when the benefits team isn’t available, meeting an employee at the exact moment they need support.

It also prompts the right next step. For example, when an employee asks about mental health coverage under the medical plan, Carly also points them to Lyra, the path the team wants people to take first. Every employee question becomes a chance to drive awareness of the benefit they should be using, at the moment they need it. In the last four months alone (February – May), Carly instantly and accurately answered over 1,500 employee questions, saving the benefits team approximately 930 hours.

Open enrollment, when question volume is highest, was a key point in the year to prove Carly’s efficacy and impact. According to Sarah Schutzberger, “It was the smoothest open enrollment we’ve ever had. The amount of time it saved our team was extraordinary.”

“Avante is transforming our employees’ experience, is giving our benefits team time back, and has yielded insights resulting in impactful interventions, which are having a positive impact on the health and wellbeing of our team.”

Kevin O’Connell
Senior Director, Total Rewards & HR Operations, Samsung

Screens are illustrative. Names and data shown are fictional to protect user privacy.

How the work itself changed

With Carly fielding the day-to-day employee questions, the team reclaimed the hours it once lost to repetitive inbox support and redirected them to strategy and program development.

The team spends that reclaimed time with Ava, now its first stop for any question, communication, or decision. They use Ava to answer real-time questions in a standing Friday meeting with leadership and bring it to events to pressure-test ideas on the spot.

Ava gives them more strategic insight, faster, and it’s backed by data they trust. In its first few months, the team reclaimed hundreds of hours using Ava to build leadership and employee-facing deliverables and run dozens of cross-source claims analyses that used to take weeks by hand, or days waiting on vendors. That level of visibility and ownership also changes what gets approved. Walking into leadership with the data and the reasoning behind a recommendation moves more initiatives forward, and gives the team the confidence to put program and plan redesign recommendations on the table.

“It’s easier to push things through leadership when you have the data and the why behind the strategy.”

Sarah Schutzberger
Benefits and HR Operations Sr Manager, Samsung

“I don’t know what I did before Ava.”

Cara Ayala, RD, CPT, CHC
Wellness and Benefits, Associate Manager, Samsung

Look ahead

For Samsung, these are the early innings. On the roadmap: bringing their own drug-utilization data to PBM negotiations; connecting LOA, short-term disability, Lyra, and medical claims to forecast and prevent leaves; and next year’s medical plan design.

Benefits clarity for employees and HR

Samsung Semiconductor runs a generous benefits program, including several point solutions, focused on emotional, social, financial, and physical health and wellness for their employees and dependents.

“If you don’t have AI on your benefits team, you’re already behind. Especially in our industry, our employees are so used to using AI in everything they do, from coding to drafting. It’s everywhere. If we don’t have it, how can we stay aligned with the technology and the experience they’re already used to?”

Benefits strategy
Employee experience
Benefits transformation

See what enterprise AI can do for benefits