Agency AI Advisors

Guide for insurance agencies

How to write an AI-use policy for your insurance agency

Agency AI Advisors · Published September 21, 2026 · 7 minute read

Your team is probably already using AI. Someone is drafting emails with it, someone is asking it to explain a policy, and someone may be pasting a client's details into a free tool without a second thought. An AI-use policy is a short document that sets the rules before something goes wrong.

It doesn't need to be long or legal-sounding. For most agencies, one or two pages that everyone has read and agreed to will do more good than a thick binder nobody opens. In a 2026 survey by the Big “I”, 55% of independent agents said they had no written AI use policy (source), so writing one puts you ahead of many agencies.

Why your agency needs one

  • Client data can end up in the wrong place. Depending on the tool and its terms, what your staff type in may be stored, reviewed, or used to train the vendor's models.
  • Wrong answers can reach clients. AI can sound confident and be wrong. If an unchecked answer goes to a client or a carrier, your agency is the one answering for it.
  • Informal use is hard to see. Without a policy, every person makes up their own rules, and you find out about the problems afterward.
  • The rules for insurers are changing. The NAIC's model bulletin on AI applies to insurers, not directly to agents, according to law firm summaries. But some state versions remind regulated entities, including their agents and representatives, that they are responsible for accurate data. Requirements vary by state, so check with your state association or an attorney.

The five questions your policy should answer

You can keep a policy simple by making sure it answers five questions in plain language.

1. Which AI tools are approved?

Name the tools your agency has reviewed and allows, and say that everything else is off limits for client work. Personal accounts on free tools should not be used for agency business. Also say how a new tool gets approved, and who decides.

2. What can AI be used for?

A simple three-level list works well. Adapt it to your agency:

LevelExamples
Fine on approved toolsDrafting internal email templates, first drafts of marketing content, summarizing meeting notes that contain no client details, organizing task lists and renewal checklists, rewriting explanations in plainer language.
Allowed with human reviewClient emails and letters, sorting and summarizing quote requests, plain-language summaries of policy documents, renewal follow-up drafts.
Don't hand to AICoverage recommendations, claim guidance, final policy interpretation, anything sent to a carrier or underwriter without a person checking it.

3. What information is off limits?

Be specific, because “confidential information” means different things to different people. A workable rule: do not enter confidential client information into any AI tool unless your agency has reviewed that tool, its terms, and its data protections and approved it for that purpose. List examples such as Social Security numbers, dates of birth, driver's license numbers, bank and payment details, health information, claim details, policy numbers, and passwords.

4. Who reviews AI-generated work?

Every AI-assisted piece of work that goes to a client, carrier, prospect, or underwriter should be reviewed first by a person who knows the subject. A good test: if the agency would be responsible for the answer, a licensed professional should read it before it leaves the agency. Put that in writing, and say who signs off in your agency.

5. How will you document it?

Decide how staff record that AI helped with a task, such as a note in the client file or the management system. You don't need to track everything. You do need to be able to explain later how a document or message was produced, and who checked it.

Questions to ask before approving an AI tool

Before a tool goes on your approved list, get clear answers to these:

  • Is our data used to train the vendor's models?
  • Where is our data stored, and for how long?
  • Who at the vendor, and who in our agency, can see it?
  • Is there a record of what the tool produced and who used it?
  • Does it work inside our agency management system, or do staff have to copy and paste client details into a separate window? Extra copying is where mistakes and leaks happen.

Vague answers on retention or training are a reason to wait. If a vendor can't explain how it handles your clients' data, it doesn't belong on the list.

A starter policy you can adapt

Below is a short template. Replace the bracketed parts, cut what doesn't apply, and add what does. Consider having your E&O carrier or an attorney look it over before you adopt it.

[Agency name] AI-Use Policy

Effective [date]. Owner: [name and role]. Review every six months.

1. Purpose

This policy explains how our team may use AI tools in our work, so we can save time while protecting our clients, our carriers, and our agency.

2. Approved tools

Staff may use only the AI tools on our approved list: [list tools]. Personal or free accounts must not be used for agency work. To request a new tool, contact [name].

3. Approved uses

AI may be used to draft, summarize, and organize. Anything that goes to a client, carrier, prospect, or underwriter must be reviewed by a person before it is sent.

4. Information we never enter

Unless a tool has been approved for that purpose, staff must not enter client personal or financial information, health information, claim details, policy numbers, or passwords into any AI tool.

5. Decisions stay with people

AI does not make coverage recommendations, give claim guidance, or make final decisions. Licensed staff make those decisions.

6. Record-keeping

When AI helps produce client-facing work, staff note it in [system or file] and record who reviewed it.

7. Mistakes and questions

If client information is entered into an unapproved tool by mistake, tell [name] right away. Nobody will be punished for reporting a mistake quickly. When unsure, ask before using AI.

8. Training and acknowledgment

Every team member completes a short training on this policy and signs that they have read it.

Rolling it out

  1. Pick one owner. Someone needs to keep the policy current and answer questions.
  2. Train the whole team. A short session with real examples from your own work is enough. Risk usually comes from casual, informal use, so everyone needs to hear the rules.
  3. Give people a good approved option. If the approved tool is worse than the free one, staff will drift back to the free one.
  4. Review it twice a year. Tools, terms, and state rules change, so a policy written once will go stale.

Mistakes to avoid

  • Banning AI outright. People keep using it, only out of sight, which is worse.
  • Writing something too long to follow. If staff can't remember the main rules, the policy isn't working.
  • Treating it as a one-time task. A signed page in a drawer doesn't change behavior. Training and reminders do.
  • Skipping the review step. The point of human review is to catch what AI gets wrong before a client sees it.

This guide is general information for insurance agencies. It is not legal or compliance advice. Requirements differ by state and carrier, so confirm what applies to you with your state association, your E&O carrier, or an attorney.

Want help writing yours?

We work with insurance agencies and brokerages on AI-use policies and staff training, and on finding where AI will actually pay off. Tell us about your agency and we'll write back with a plan.

Tell us about your agency

Sources and further reading