The AI Use Policy for an Independent Insurance Agency
What to write, who signs off, and how to keep it from sitting in a drawer.
Why most agencies do not have one
Your team is already using these tools. The question is whether they are doing it against a rule you wrote or a rule they guessed at.
In the same survey, two thirds of agencies said they plan to increase their AI use in the next twelve months. Thirty eight percent said very likely, thirty percent said somewhat likely.
So the use is going up and the written rules are not.
That same report asked agencies what worries them. Data privacy and compliance risk came first at twenty four percent. Inaccurate outputs came second at twenty two percent.
Kasey Connors, executive director of ACT, put it this way in the release: agents are not worried about the price of AI, they are worried about the cost of getting it wrong.
Both of those concerns are handled by a policy, not by a product. No tool decides for you what a CSR is allowed to paste into a chat window. No tool decides who checks an AI drafted email before it reaches a client. Those are your rules, and if they are not written down, every person on your staff is making them up on their own.
- Tells your team what is allowed, so they stop guessing.
- Tells them what is never allowed, so the worst outcome is off the table.
- Names who is accountable for checking output before it leaves the agency.
That is the whole job. It does not need to be long.
What goes in the policy
There are nine sections. Each one answers a question your staff is already asking silently.
1 Which tools are approved
List them by name. A tool that is not on the list is not approved.
This sounds strict and it is the most useful line in the document. Without it, your staff is using whatever free tool they found, and you have no idea where your client data is going.
Include the version or account type. A paid business account and a free consumer account of the same product often handle your data differently. Name which one you mean. Review the list quarterly, because tools change their terms.
2 What data never goes into an AI tool
This is the section that prevents the worst day.
Client names paired with policy details. Dates of birth. Social Security numbers. Tax identification numbers. Driver license numbers. Bank or payment information. Loss run detail tied to a named insured. Anything from a client file that would identify the client.
Say what to do instead. Most work can be done with the identifying details stripped out. An AI tool can draft a renewal email without knowing the client's name. It can summarize a policy form without the insured's address attached.
If a tool is approved specifically for client data because you have reviewed how that vendor stores and handles it, say so by name in this section. Otherwise the default is no.
3 What AI is allowed to do
Be specific. Vague permission produces vague behavior.
Approved uses in most agencies look like this: drafting a first version of an email, summarizing a long document into plain language, cleaning up notes after a call, drafting a checklist, answering a general question about a coverage concept, and reformatting information the agency already has.
Notice what all of those have in common. The AI produces a draft that a person then reads. Nothing on that list reaches a client or a carrier without a human in between.
4 What AI is never allowed to do
Just as specific.
AI does not bind coverage. AI does not issue a certificate without a person reviewing it. AI does not send anything to a client, a carrier, or a claimant without a named person approving it. AI does not give a client a coverage answer directly. AI does not make a decision your license makes you responsible for.
The line is simple to state. The tool drafts, the licensed person decides.
5 Who checks the output, and what they check for
This is the section most policies skip, and it is the one that matters when something goes wrong.
Name the role, not the person. The account manager checks the certificate. The producer checks the client email. The person whose name is on the work checks the work.
Then say what they are checking, because people read for tone instead of accuracy. The checker confirms every number against the source document. Limits, dates, premiums, policy numbers, named insureds.
AI states a wrong number with the same confidence as a right one, and it does not flag its own mistakes. Reading for fluency will not catch it. Only comparing to the source will.
6 What gets documented
If the work touched a client file, note that AI was used to produce the draft and who reviewed it. One line in the file is enough.
This costs almost nothing at the time and it is the difference between being able to show your process later and not being able to.
7 Who owns the policy
Name a person, not a committee. That person keeps the approved tool list current, answers questions when something is not covered, and reviews the policy twice a year.
A policy with no owner stops being true within a few months and nobody notices.
What to do after you write it
A policy nobody has read is the same as no policy.
Walk your team through it once, in a meeting, out loud. Fifteen minutes. Take questions, because the questions show you what you left out. Have every person sign it and keep the signed copies. Add it to onboarding so new hires get it in week one.
Put a date on it and review it every six months. The tools change fast enough that a year old policy is describing an agency you no longer run.
The one page version
If the full document is more than you want to start with, write these five lines and expand later.
- These are the AI tools we use. Nothing else.
- Client identifying information never goes into any of them.
- AI writes drafts. People approve anything that leaves the agency.
- Every number in an AI draft gets checked against the source before it goes out.
- [Name] owns this policy and reviews it every six months.
That is a real policy. It is shorter than most and it covers the failures that happen.
2026 Big "I" Agents Council for Technology Tech Trends Report, released February 19, 2026, based on a national email survey of independent agency members of varying sizes. Reported by IA Magazine and Agency Checklists.
This guide covers agency operations and internal process. It is not legal advice and it does not address coverage, licensing, or claims handling. If your state has specific requirements for AI disclosure or record retention in insurance transactions, confirm those with your own counsel or your state association.
See how AI handles the work, on a sample book
Run it yourself on a sample book. See how AI handles a renewal, a quote request, and a 7pm certificate.
Get the Handoff Map for your agency
Walk me through a normal Tuesday and I send back a one page map of every handoff in your agency, which ones can run on their own, and the one costing you most. Free, and yours to keep either way.