Most coverage of AI regulation in insurance is written for compliance officers at carriers, in language that assumes you already know what a market-conduct exam is. Independent agents are affected by these rules too — just indirectly, through what carriers start requiring of their distribution partners. This is an attempt to explain the actual regulatory landscape in terms that matter to an agent, not a compliance department.

This content is educational, not legal advice. Regulatory adoption status changes regularly — confirm current requirements with your state Department of Insurance or legal counsel before making compliance decisions based on this article.

What the bulletin actually requires

The National Association of Insurance Commissioners (NAIC) adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023. In broad terms, it asks insurers to:

  • Establish a written program governing how AI systems are developed, acquired, and used, particularly for decisions affecting consumers (underwriting, pricing, claims handling, and marketing).
  • Be able to explain and defend the outcomes their AI systems produce, especially where those outcomes affect whether someone gets coverage or what they pay.
  • Monitor AI systems on an ongoing basis for unfair discrimination, not just at the point the system is first deployed.
  • Maintain documentation that regulators can review during examinations.

It’s a “bulletin,” not a binding statute passed by a legislature — but state insurance departments that adopt it treat it as the standard they’ll examine insurers against, which gives it real practical force even without the force of law in the same sense as a statute.

Which states have adopted it

By mid-2026, an estimated 25 states plus the District of Columbia had formally adopted the NAIC bulletin, with roughly 8 more states working through adoption. This is not a static number. State adoption of NAIC model bulletins typically happens gradually over one to three years after the model is first published, and new states continue to adopt it as their legislative and regulatory calendars allow.

Do not treat the count above as current by the time you’re reading this. Check your own state’s Department of Insurance website, or ask your carrier partners directly which regulatory framework applies in your state — they track this closely because it affects their own compliance obligations.

Why this matters to agents, not just carriers

The bulletin binds insurers, not agents, directly — an independent agent isn’t the one who has to write the AI governance program or defend a pricing model to a regulator. But three practical effects flow downstream to agents:

Carriers are starting to ask more of their distribution partners. As carriers build out AI governance programs to satisfy their own regulatory obligations, some extend requirements to how appointed agents can use AI tools when interacting with prospective and current policyholders — for example, requiring disclosure when a chatbot rather than a human is responding, or restricting which third-party AI tools can be connected to carrier systems.

Market-conduct exams increasingly ask about the whole distribution chain. Regulators examining a carrier’s AI practices may ask how the carrier’s agents use AI in client-facing work, not just what happens inside the carrier’s own underwriting systems.

“I didn’t know” is a weak position. If a carrier’s appointment agreement is updated to restrict certain AI uses, or a state adds a disclosure requirement for AI-assisted client communication, agents who aren’t tracking this risk finding out only after a compliance issue arises.

The four states running their own frameworks

Four states have chosen to build their own AI-specific insurance regulations instead of, or in addition to, adopting the NAIC bulletin: California, Colorado, New York, and Texas. Each approaches the issue somewhat differently, but Colorado is worth a specific mention because its rule includes something the NAIC bulletin itself does not: Colorado’s insurance-specific regulation (3 CCR 702-10) includes an outcomes-based testing requirement — meaning insurers must actually test whether their AI systems produce discriminatory outcomes, not just document their intentions — that became enforceable in June 2026.

If your agency writes business in any of these four states, or your carrier partners are licensed there, it’s worth asking your carrier contacts specifically how that state’s framework (rather than the NAIC bulletin) affects what’s expected of you.

Questions worth asking your carrier partners

Rather than trying to become a regulatory expert, most agents will get more practical value from asking their carrier partners directly:

  • “Has our appointment agreement been updated with any new requirements around AI tools we use with clients?”
  • “Do you require disclosure when a chatbot, rather than a human, is handling part of a client interaction?”
  • “Are there restrictions on which third-party AI tools we can connect to your systems or use for FNOL intake?”
  • “Has your compliance team flagged anything specific to our state’s framework that we should know about?”

Carrier compliance teams generally want their appointed agents informed about this — a compliance gap at the agent level becomes the carrier’s problem too during an exam — so this is usually a welcome conversation, not an awkward one.

Where to go next

For how these regulatory considerations connect to a specific workflow, see AI vs. manual underwriting support. For the broader adoption picture, see the complete guide to AI tools for independent agents.