AI Insurance News

AI Policy Template for Insurance Agencies: One Page, Ten Rules

John Marks, AI Strategist & Co-Founder John Marks AI Strategist & Co-Founder •

Your agency already has an AI policy. Right now it is whatever each person on your team decided on their own. This one-page template replaces that with ten rules your staff can follow and a carrier reviewer can read: which tools are approved, what client information may go where, who checks AI output before a client sees it, and what to do when something goes wrong.

We wrote it for independent and captive agencies of five to twenty people, in October 2026. It is a starting point, not legal advice. Your carrier agreement, your state’s rules, and your E&O carrier’s requirements come first. Copy it, change it, and put your agency’s name on it.

Why one page beats a long policy

We open our agency training sessions with two questions. Who has used ChatGPT or a similar tool for work this month? Most hands go up. Who has been given written rules for it? Almost every hand goes down.

The fix is not a 20-page document. A long list of bans gets ignored, and people keep using AI on their personal accounts where you can’t see it. A short policy that says “here is how to use AI safely here” gets followed. That is the whole design goal of this template: short enough to read in five minutes, specific enough to settle real questions.

Why agencies need this now

  • Carriers are asking. When Farm Bureau Insurance Company of Idaho reviewed our tools, we gave a live walkthrough to its technical services and security team, answered its vendor security worksheet in writing, and documented every Microsoft 365 permission we request. The approval named specific tools. Agencies should expect similar questions about the tools they use.
  • Regulators expect oversight of AI vendors. Roughly half of the states have adopted the NAIC model bulletin on insurers’ use of AI. It is aimed at carriers, but it expects oversight of third parties, and agencies are part of that chain. Our AI regulation guide for insurance agents has the state-by-state picture.
  • The real risk is already in the office. As we explain in Is AI safe to use with client data?, the biggest exposure is usually a personal AI account someone is already using, not the vendor you are evaluating.

The template

Fill in the brackets. Keep the numbering so people can refer to “rule 5” in a team meeting.

[Agency name] AI Use Policy · Version [1.0] · Effective [date] · Policy owner: [name]

1. What this covers. This policy applies to everyone who works for [agency name], including owners, producers, service staff, and temporary help. It covers any AI tool used for agency work, including AI features built into email, phone, CRM, and document software.

2. Use approved tools only. Use only the tools on the Approved AI Tools list below, on the account type listed. Do not use personal AI accounts for agency work. Business accounts must have training on our data turned off where the tool offers that setting.

3. Carrier rules come first. If a carrier we represent has rules about AI, vendors, or its data, those rules override this policy. Do not connect any AI tool to a carrier system or carrier-provided data until [policy owner] confirms it is allowed.

4. Follow the data rules. Green: no client information (marketing drafts, general questions, training) may use any approved tool. Yellow: client names, policy details, and notes may go only into tools approved for client data. Red: Social Security numbers, driver’s license numbers, full dates of birth, bank or card numbers, health information, and passwords never go into an AI tool unless that tool is specifically approved for that data.

5. A licensed person reviews before a client sees it. Any AI output about coverage, eligibility, price, or claims is reviewed by a licensed team member before it reaches a client. AI does not bind, change coverage, or decide whether something is covered.

6. Tell people when AI or recording is involved. Announce recording at the start of every recorded call or meeting. When people are in different states, follow the stricter consent rule. Tell clients when they are talking to an automated assistant.

7. Messages follow our normal rules. AI-drafted emails and texts follow the same consent, opt-out, and advertising rules as anything else we send. Automated texts or calls go only to people who have given the consent the law and our carriers require.

8. Ask before adding a tool. Anyone may suggest a new AI tool. [Policy owner] approves it after checking how the vendor uses our data, how long it keeps it, who it shares it with, how we delete it, whether it requires multifactor sign-in, and what account permissions it requests. Approval is added to the list with a date.

9. Report mistakes the same day. If client information goes into an unapproved tool, or AI output reaches a client without review, tell [policy owner] the same day. Reporting quickly will not get anyone in trouble. Hiding it will.

10. Review every quarter. [Policy owner] reviews this policy every quarter and whenever we add a tool or a carrier issues new guidance. Each team member signs the current version.

The Approved AI Tools list

Rule 2 only works if the list is specific. “ChatGPT” is not specific enough. “ChatGPT Business, agency workspace, training on our data turned off” is. Keep the list on the same page as the policy.

Approved AI Tools list (example layout)
Tool and account typeUsed forClient data allowed?Approved by and date
[General AI assistant, business tier]Drafting, summaries, trainingGreen only[Name, date]
[Agency CRM with AI features]Client notes, tasks, follow-upGreen and yellow[Name, date]
[Policy document tool]Coverage questions, renewal comparisonsGreen and yellow[Name, date]
[Meeting recording tool]Meeting notes after consentGreen and yellow[Name, date]

Our own lesson from a carrier review applies here: approvals are specific. Idaho Farm Bureau Insurance approved three of our tools by name. Your list should be just as precise, so nobody assumes one approval covers every tool a vendor sells.

Captive agencies: add one more step

If you represent a single carrier, rule 3 does most of the work. Before you finalize the list, ask your carrier three questions:

  1. Do you keep a list of approved AI vendors, or a process for reviewing one?
  2. Which of your systems and data may an outside tool connect to, if any?
  3. Are there limits on recording calls, texting clients, or using AI in marketing?

Write the answers and the date on your policy. If the answer is “we don’t have a rule yet,” write that down too. For more on where the carrier’s boundary sits, read what to check when the carrier dictates your tech stack.

Roll it out in one week

A one-week rollout for a small agency
DayTaskTime
MondayAsk each person which AI tools they use for work and on what account.15 minutes
TuesdayMove anyone using a personal account to a business account, or stop that use.30 minutes
WednesdayFill in the template and the Approved AI Tools list. Send carrier questions if you are captive.45 minutes
ThursdayWalk the team through the ten rules with two real examples from your office.20 minutes
FridayCollect signatures and put the next review date on the calendar.10 minutes

That is about two hours in total. The Thursday meeting matters most. Use examples like “can I paste this renewal into the chatbot?” and answer them with the rule numbers. For prompt templates your team can use on day one, see our free guide, What Your Staff Is Already Doing with ChatGPT.

What the policy looks like in daily work

Here is one example. A service rep wants help explaining a renewal increase to a client. Under this policy, the rep uses the approved policy document tool, not a personal chatbot (rules 2 and 4). The tool compares the expiring and renewal declarations, and a licensed agent reviews the explanation before it is sent (rule 5). Our renewal review checklist walks through that exact workflow.

Applied AI’s own controls, subprocessors, and permission details are on our security page, written for carrier reviewers. Use it as an example of what to ask any vendor on your list, including us.

Want help putting this in place? Our AI training for insurance agencies starts with exactly this conversation, or you can talk with us about your agency’s tools. Bring your current list of tools, even if it is just “we think a few people use ChatGPT.”

Quick Answers

Does an insurance agency need a written AI policy?

Yes, if anyone in the office uses AI for work, and in most agencies someone already does. Without written rules, each employee decides alone what client information goes into which tool. A one-page policy sets the approved tools, the data rules, and who reviews AI output before it reaches a client. Carriers and vendor reviewers increasingly ask to see one.

What should an insurance agency AI policy include?

At minimum: who and which tools it covers, an approved-tools list with account types, data rules for what client information may go where, a human-review rule for anything touching coverage, price, or claims, recording and disclosure rules, a process for approving new tools, a way to report mistakes, and a review date. Captive agencies should also state that carrier rules come first.

Can insurance agents put client information into ChatGPT?

Not into a personal account, and not without agency rules that allow it. Consumer AI accounts may allow the provider to use what you submit to improve its models, while business tiers generally contract not to. Even on an approved business account, information like Social Security numbers, driver’s license numbers, bank or card numbers, and health details should stay out unless the tool is approved for that data.

Do captive agents need carrier approval to use AI tools?

Often, and you should assume the carrier’s rules apply until you confirm otherwise. Requirements vary by carrier, state, and agent agreement. Some carriers review vendors centrally and approve specific tools; approval of one tool does not cover another. Ask before connecting any AI tool to carrier systems or carrier-provided data.

How often should an agency update its AI policy?

Review it at least every quarter, and whenever you add a tool, a carrier issues new guidance, or something goes wrong. Date each version and keep the old ones. A short policy that is current is worth more than a long one nobody has read since it was written.