Carriers in 24 states plus DC now have to run a written AI program that includes oversight of their third parties. You are one of those third parties. Meanwhile, more than half of independent agencies have no written AI policy at all. AboveBoard closes that gap with forty controls, an independent review and a badge your carriers, your state department of insurance and your E&O underwriter can check.
The NAIC Model Bulletin on the Use of AI Systems by Insurers requires insurers to maintain a written AI systems program covering governance, controls, consumer notice and third-party vendor due diligence (Quarles, Apr 2025). Agencies and MGAs that quote, service or market with AI are third parties, and NAIC work on a third-party vendor framework continues (Mayer Brown, Apr 2026). The obligation reaches you as a questionnaire, a contract addendum or a request for your AI policy.
The bulletin tells insurers to expect regulators to ask about their AI program during examinations, and about the third parties they rely on. Market conduct and consumer-complaint reviews are where an agency's AI use surfaces first: a mis-quoted premium, an automated declination, a chatbot that said something the policy does not.
Colorado SB 26-189 (effective Jan 1, 2027) covers insurance decisions: pre-use notice, a plain-language explanation within 30 days of an adverse outcome, a right to meaningful human review, and three years of records (Seyfarth, May 2026). Texas TRAIGA (Jan 1, 2026) applies to anyone doing business in Texas and treats substantial compliance with the NIST AI RMF as an affirmative defense (Baker Botts, Jul 2025). The FTC's July 7, 2026 policy statement treats undisclosed steering of AI outputs as deceptive when accuracy is implied.
ISO introduced a generative-AI exclusion for commercial general liability policies in January 2026, and carriers across professional lines have added AI questionnaires and endorsements (Fenwick, Jun 2026). The renewal application now asks whether you use AI and whether you police it. A blank answer is an answer.
AI features inside agency management systems and comparative raters, policy comparison and coverage summaries, renewal-review automation, certificate generation and endorsement processing. These touch nonpublic personal information on every transaction.
Website chatbots, AI phone agents and call transcription, email drafting in Outlook or Gmail, text-message follow-ups and claims first-notice intake. The Big I survey's top concerns were data privacy and compliance (24%) and inaccurate outputs (22%), and this is where both live.
ChatGPT, Copilot and Gemini for proposals, social content and internal memos; AI-generated marketing copy that may claim things about coverage; spreadsheet and commission-reconciliation assistants. Often on personal accounts.
Forty controls, eight per domain, scored on evidence. Here is how they read when your regulator is a department of insurance and your biggest clients are carriers.
A written AI policy adopted by the principals, a named owner (often the operations manager or compliance lead) with authority to switch off a tool, an inventory of AI tools and use cases, and a register of the NAIC-bulletin states and carrier requirements you are subject to.
Evidence examples: the approved policy; the AI register listing your AMS features, chatbot, raters and general assistants with an owner for each; the obligations register mapping each appointed carrier's AI addendum and each state's bulletin status.
Nonpublic personal information, driver's license and health data classified so staff know what may never be pasted into a chatbot, an approved-tool list with enterprise terms that prohibit training on your data, single sign-on, retention rules for transcripts and prompts, and inclusion of AI tools in your cyber-insurance disclosures.
Evidence examples: the one-page classification with insurance-specific examples (applications, loss runs, medical questionnaires); the vendor terms review log for your AMS AI features and any chatbot vendor; the cyber application showing AI tools were disclosed.
A licensed human reviews any AI-drafted coverage explanation, proposal or quote before it reaches an insured; chatbot conversations are logged and sampled; the incident plan covers an AI tool leaking NPI or misstating coverage; carrier and vendor changes are monitored.
Evidence examples: the review rule and a sample sign-off from a producer; the monthly chatbot transcript sampling log with corrections; the incident-plan section that maps an AI data exposure to your state breach-notification duties.
Training completed by 90%+ of producers, CSRs and back-office staff, role-specific modules, reviewer training for the people who check AI output, signed acknowledgments and a principal-level governance briefing.
Evidence examples: the completion report; the acknowledgment file; the agenda and minutes from the principals' governance session. Academy Foundations is included in every tier.
Insureds are told when they are talking to an AI, marketing claims about "AI-powered" quoting are reviewed for substantiation, carrier questionnaires are answered from a standard bank, and complaints involving AI have an owner and a response time.
Evidence examples: the chatbot disclosure banner and the human-handoff rule; the claims-review sign-off on your website copy; the last three carrier AI questionnaires, answered consistently.
No firm is listed at any level with a zero on G1 (written policy), D3 (vendor terms reviewed) or O1 (human review before client-facing output). For an agency, these are also the first three items on a carrier's third-party questionnaire.
Read the full rubricWhen a carrier's vendor-management team sends the AI section, you answer from verified evidence and point to your registry entry.
The application's AI questions map to G1, D2, D3, O1, O3 and W1. Attach the report and the year-stamped badge; the underwriting decision remains the carrier's.
A plain-English report by domain with gaps and fixes. Agency acquirers are beginning to ask about AI governance in diligence; a verified score is a clean answer.
AboveBoardAI issues a score and a verification under a private, voluntary standard; it is not a regulatory approval, not an NAIC or DOI program, and not a guarantee of compliance. It verifies that your AI governance practices exist and are evidenced on the review date. See What is an AI audit?
Take the free Snapshot. List every AI feature you have switched on in your AMS, rater, phone system and website, plus the general assistants your team uses. That is your register.
Adopt an AI acceptable-use policy (our template is built for agencies too). Move approved tools onto agency accounts with enterprise terms. Write the rule for NPI: what never goes into a consumer chatbot.
Require a licensed human to sign off on AI-drafted coverage language. Add the AI disclosure to your website chat. Roll out Academy Foundations and collect acknowledgments.
Draft standard answers to the AI questions your carriers ask, tied to evidence. Start the full assessment; Snapshot answers carry over.
Growth Firm (50–249) $18,000; Established Firm (250–999) $42,000; Enterprise (1,000+) from $75,000. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy Foundations. Associations, carriers and brokers can refer members under a 15% first-year referral arrangement.
The bulletin is addressed to insurers, not agencies. But it requires insurers to run a written AI systems program that includes due diligence and oversight of third parties, and agencies and MGAs that use AI in quoting, servicing or marketing are third parties. In practice the obligation arrives as a carrier questionnaire, a contract addendum or a request during a state examination.
As of the NAIC Spring 2026 national meeting, 24 states plus the District of Columbia had adopted the model bulletin, and four more states had issued their own AI insurance regulation or guidance (Mayer Brown, Apr 2026). The list keeps growing; our state AI law tracker is updated as adoptions are announced.
Yes, with controls. Disclose that the visitor is talking to an AI, keep it away from binding coverage statements, log conversations, and give people a fast path to a licensed human. In Moffatt v. Air Canada (Feb 2024) a tribunal held the airline liable for its chatbot's incorrect advice after the company argued the bot was a separate legal entity (ABA Business Law Today, Feb 2024). An agency chatbot that misstates coverage is the same problem with a coverage dispute attached.
AboveBoard makes no promise about coverage or premium; those decisions belong to your carrier. What the report gives you is a dated, independently reviewed answer to the AI questions now appearing on applications: policy, approved tools, human review, training and incident response. Carriers have been adding AI questionnaires and exclusions since 2025 (Fenwick, Jun 2026).
AboveBoardAI is priced annually by headcount: $7,500 for agencies of 1 to 49 people, $18,000 for 50 to 249, $42,000 for 250 to 999 and from $75,000 for 1,000 or more. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy training for all staff. See pricing.