NAIC AI Bulletin and State DOI Rules: Agency Governance Checklist
A producer AI policy mapped to the NAIC Model Bulletin, NY DFS Reg 187, GLBA, and state DOI bulletins.
- PUBLISHED
- May 13, 2026
- READ TIME
- 7 MIN
- AUTHOR
- ONE FREQUENCY
- Topic
- NAIC AI bulletin, insurance AI compliance, DOI AI rules
- Industry
- insurance
- Published
- May 13, 2026
- Read time
- 7 min
- Word count
- 1,293
Most agency principals we talk to about AI compliance start the conversation in the same place: "I know I need a policy, I don't know what to put in it, and I'm not sure which regulator actually cares." The answer matters because the NAIC Model Bulletin on AI has been adopted in some form by 20+ state insurance departments by mid-2026, GLBA still binds every agency handling NPI, the TCPA binds every outbound SMS and voice, and New York DFS Reg 187 plus California's CCPA layer state-specific privacy rules on top.
The good news: the governance work that protects an independent or captive agency fits on a single page. The bad news: most agencies we audit have done none of it. This article is the operational governance checklist, mapped against each regulatory layer. The broader workflow context is in the insurance AI playbook; the AI enablement engagement delivers the one-page policy.
The four regulatory layers that matter
1. NAIC Model Bulletin on AI
The NAIC Model Bulletin on the Use of AI Systems by Insurers was adopted in late 2023 and has been ratified by 20+ state insurance departments by 2026. It primarily binds insurers, but most state implementations extend documentation, testing, and human-oversight expectations to producers and MGAs.
The bulletin requires:
- Documented AI governance program. Who owns the AI tools, how they are reviewed, what controls exist.
- Testing and validation. Evidence that the AI performs as expected across the populations it touches.
- Human oversight. No fully automated underwriting, binding, or claim decisions.
- Risk management. Document the risks the AI presents and the mitigations in place.
For a 12-staff independent agency, satisfying the bulletin is a one-page document, signed by the principal, kept with the corporate records. AM Best has tracked carrier and producer adoption since 2024.
2. GLBA
The Gramm-Leach-Bliley Act binds every agency handling non-public information (NPI). NPI includes any client identifier tied to coverage, premium, claim, or financial data. The two things GLBA requires from an AI deployment:
- Vendor DPAs. Every AI vendor that touches NPI signs a GLBA-compatible data processing agreement. This is standard on enterprise tiers; never on consumer free tiers.
- No-training language. The vendor cannot use the agency's data to train its general models. Standard in enterprise contracts.
Consumer-tier AI tools (ChatGPT Free, Claude Free, consumer Copilot) fail GLBA the moment any NPI touches them. The agency's IT or office manager should block consumer tools at the policy level.
3. TCPA and state telemarketing
The TCPA binds outbound SMS and voice. State telemarketing rules layer on top. Every AI workflow that originates outbound communication — renewal SMS, cross-sell prompts, claim follow-up — respects:
- Documented opt-in. Captured at bind for any future outbound SMS. The AMS records this.
- STOP-to-unsubscribe. Every outbound SMS includes the opt-out language.
- Quiet hours. No SMS or voice before 8 a.m. or after 9 p.m. local time.
- State-specific opt-in rules. California, Florida, Texas, and a handful of others have stricter requirements.
The vendor default should include these; the principal should verify on contract signature.
4. State DOI producer licensing
Every state DOI treats AI as a tool, not a licensee. The producer of record remains accountable for any quote, recommendation, binding, claim handling, or coverage interpretation. AI configurations must:
- Prevent AI binding. AI quotes, drafts, and submits — the producer binds.
- Prevent AI coverage recommendation without producer review. AI normalizes and drafts the comparison; the producer presents.
- Honor state-specific replacement rules on life and annuity. AI captures the data; the producer issues the replacement notice under their signature.
- Capture AML data on life and annuity sales. AI captures; the producer documents the review.
The one-page agency AI governance policy
The policy fits on a single page. Five sections:
- AI tool inventory. Every AI vendor the agency uses, what data they touch, and which producer or staff member owns the relationship.
- Approved vendors. Enterprise tier only. Names of approved vendors. Process for adding new vendors (DPA review, security review, principal sign-off).
- Scope of AI authority. What AI can do (intake, draft, normalize, route) and what it cannot do (bind, recommend without review, deny coverage, settle claims).
- Outbound communication rules. TCPA opt-in, opt-out, quiet hours, state-specific rules.
- Audit and review cadence. Quarterly review of AI activity logs; annual review of the governance policy itself.
The principal signs it; the staff acknowledges; the document lives with the corporate records. Some E&O carriers ask to see it on the annual application — having it on hand makes the renewal conversation easier.
Vendor due diligence checklist
For every new AI vendor before signing:
- GLBA-compatible DPA on file.
- No-training language confirmed in writing.
- Data residency disclosed (US-based for most agencies).
- SOC 2 Type II report available on request.
- Sub-processor list disclosed.
- Breach notification timeline (typically 72 hours).
- Right to audit clause.
For most enterprise-tier vendors, all seven items are standard. For smaller insurtech vendors, the agency should review each carefully before NPI moves.
NY DFS Reg 187 and state-specific privacy
New York DFS Reg 187 imposes a "best interest" standard on life and annuity sales. AI-driven cross-sell prompts on life and annuity must:
- Document the suitability analysis. AI captures; the producer documents.
- Honor the replacement notice rules. State-specific timing and content.
- Not advertise products without carrier authorization. AI marketing copy must clear carrier approval.
California's CCPA imposes additional data-handling and disclosure requirements on personal-lines clients. The vendor DPA should reference CCPA compliance explicitly. Other states (Colorado, Connecticut, Virginia, Utah) have similar laws; the DPA language usually covers them generically.
What good compliance looks like at 90 days
- AI governance policy: signed and filed.
- Vendor inventory: complete with DPAs on file for every vendor touching NPI.
- TCPA opt-in confirmation: captured at bind for 95%+ of active clients.
- Quarterly AI activity review: scheduled on the principal's calendar.
- E&O renewal application: governance policy referenced.
FAQ
Q: Do I have to do anything specific for the NAIC Model Bulletin? A: It depends on your state's adoption. As of 2026, 20+ states have adopted some form. The one-page governance policy covers what every state's adopted version requires. Check with your state DOI for any state-specific reporting.
Q: Will my E&O carrier ask about AI? A: Increasingly yes, on the annual application. Underwriters ask about AI tool inventory, governance policy, and scope of authority. Having the one-page policy on hand makes the renewal smooth.
Q: What happens if a consumer-tier AI tool sees client data? A: Technical violation of GLBA. Not catastrophic if it happens once and is remediated, but it is the kind of finding that gets called out on an E&O audit. Block consumer tools at the policy level.
Q: How does TCPA apply to AI-drafted SMS? A: Same as any other agency SMS. Opt-in, opt-out, quiet hours, state-specific rules. The vendor default should handle these; verify on contract signature.
Q: What about producer licensing across state lines? A: AI is a tool of the producer; the producer remains responsible for licensing in every state where they write business. AI does not change cross-state licensing rules.
Q: How often should the governance policy be reviewed? A: Annually at minimum. Quarterly if new AI tools come online during the year. The review is a 30-minute principal task; it does not need to be a full audit.
If you want a one-page AI governance policy drafted against your specific agency — your AMS, your AI tools, your state mix — reach out. The policy is part of the AI enablement engagement. Or see the full engagement on AI for insurance.
Cited and consulted.
- 01AM Best Review — Industry Analysisambest.com · accessed May 8, 2026
- 02Insurance Journal — National Industry Coverageinsurancejournal.com · accessed May 8, 2026
- 03NU Property Casualty 360 — Industry Benchmarksnupropertycasualty360.com · accessed May 8, 2026
- 04Big "I" Independent Agent Magazine — Agency Operationsindependentagent.com · accessed May 8, 2026
Ready to ship the next outcome?
One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.