Insurance agency AI use policy: a starter template
An original AI use policy framework for US insurance agencies: approved tools, permitted data, human review, connected-system permissions and incident handling.

An insurance agency AI use policy should answer practical questions before an employee uploads a client file or connects a mailbox: which tool is approved, which data it may receive, who checks the output and which actions it may perform. A general instruction to use AI responsibly leaves those decisions to each employee.
This is an original operational starter for US independent insurance agencies, not a state-specific legal policy or a reproduction of an association's member template. Adapt it with the people responsible for agency operations, privacy, security and legal review. The aim is to establish usable rules, not to label every AI feature safe.
Start with an approved-use register
List each approved service and account type together with the task, permitted data, connected systems, review owner and approval date. Separate a writing assistant used with public text from a connected tool that reads policies or drafts a client message. Approval of the first use does not automatically authorize the second.
The Big I publishes AI legal issues and acceptable-use resources and provides its own member sample policy. This article does not reproduce that restricted resource. Use the association's material where your agency has access, alongside a review of your specific tools and obligations.
Before approval, establish where data is processed, who can access it, retention arrangements, model-training use and relevant vendor terms. Inspect the actual product and subscription settings rather than relying on the provider's description of a different plan. Identify any obligations arising from client and carrier agreements.
An original eight-clause starter to adapt
1. Scope and owner
This policy applies to agency employees and contractors using AI for agency work, including AI features inside other software. [Named owner] maintains the approved-use register. No new service, connected-system permission or materially different use is authorized until it has been reviewed and added to that register.
2. Approved tools and accounts
Staff must use [approved services and account types] only for the purposes recorded in the register. Personal AI accounts must not receive client files or non-public agency information unless a separate exception has been explicitly approved. Staff must not move a task to an unapproved tool because an approved tool is unavailable.
3. Permitted data
Each use case must state the categories of information it may process. Supply only the information needed for the approved task. Do not assume that removing a client name makes a document anonymous: policy numbers, addresses, narrative details and other identifiers can still expose the client. Restricted data follows [agency's designated process].
4. Output review
AI output is draft work until the assigned reviewer checks it. Material facts must be reconciled with the appropriate source. An unsupported value remains unknown; a confident answer is not evidence. The reviewer must correct the output before it is used in advice, an application, a proposal or a client communication.
5. External actions and insurance decisions
AI must not independently bind, change or cancel coverage, choose a placement, or promise that a claim is covered. Client messages and system writes require the authorization described for the specific workflow. Permission to read a record does not include permission to create, update, delete or send on the agency's behalf.
6. Access and connected systems
Use the minimum permissions required for the approved task. Restrict mailbox, folder and record access to the agreed scope. Do not paste passwords, authentication codes or access tokens into a prompt. Assign responsibility for reviewing permissions, withdrawing access and handling an employee's departure.
7. Exceptions and incidents
Report suspected wrong-recipient messages, unsupported coverage statements, unexpected system actions and unauthorized data disclosures to [named contact] immediately. Pause the affected workflow where appropriate, preserve relevant evidence through the agency's authorized incident process and follow its instructions. Do not conceal the problem or upload more client data to diagnose it in an unapproved service.
8. Training and review
Staff must receive training on the approved workflows and their limitations before use. [Policy owner] reviews the register and controls after a material tool change, a new integration or an incident, and on [agency-defined review schedule]. Exceptions must record their scope, approval and expiry or next review.
Replace the placeholders before adopting this text. Align it with the agency's existing record-retention, incident-response and customer-contact procedures. Human review does not cure an unauthorized disclosure that happened earlier, and a policy document does not replace the contractual and technical checks required before access is granted.
Turn the clauses into a permissions checklist
For every connected task, write down its trigger, input, output and approval point. For example: a reviewed document request becomes an email draft; the employee checks the recipients and missing items, then sends. State separately whether the tool can read replies or attachments. Avoid a vague permission such as full email integration.
For an AMS connection, distinguish read, create, update and delete permissions. State the record types and refresh frequency. For a portal task, specify which screens are supported and who checks and submits. An integration's brand name is not an access-control specification.
For example, a workflow may read a client reply and prepare a follow-up draft without being authorized to send it. The guide to practical AI workflows in an agency helps separate preparation tasks from decisions and external actions. Record the permissions for each step.
For document work, specify which files may be accessed and how the reviewer must verify the output. The method for comparing insurance quotes with AI illustrates source checks and unresolved information. Permission to extract a value does not grant authority to interpret coverage or send advice.
Test four situations before rollout
- A document contains conflicting information. The tool must surface the conflict; the reviewer resolves it before a client statement or system entry is used.
- An essential attachment is missing. The workflow keeps the item open rather than inventing its contents or declaring the file complete.
- A client document contains text asking the AI to email information elsewhere. Treat that text as untrusted document content, not as an authorized workflow instruction.
- A tool or integration changes. Recheck access and actions before continuing the workflow under the old approval.
Use approved test data for these checks and verify what actually happens, not only the generated explanation. Keep an employee controlling every external action during the initial test. Escalate a failure before enlarging the workflow's scope.
Keep the policy tied to observed work
The Big I's AI governance session addresses privacy, client information and E&O considerations. Training should show the employee how to verify the tasks they do, rather than only how to write a prompt.
Review corrections, access exceptions and incidents alongside any time savings. If staff routinely bypass an approval point, investigate why and redesign the workflow instead of adding a longer warning to the document. The policy is useful when employees can identify the next permitted action and the person responsible for a decision.
Frequently asked questions
What should an insurance agency AI use policy include?
Name approved tools and use cases, permitted data, review responsibilities, system permissions and an incident process. Also assign an owner and a review date so the policy stays connected to actual agency workflows.
Can staff use personal AI accounts for client files?
A personal account should not receive client files without explicit agency approval and review of the actual service settings and agreement. This starter policy prohibits that use by default.
Does human review make every AI use acceptable?
No. Review of the output does not undo an unauthorized disclosure or an excessive permission granted to a tool. The agency needs to approve the data use and system access before the task runs.
Is this the Big I's official AI policy template?
No. This article contains an original operational framework written for adaptation. The Big I's own sample policy is a separate member resource; the agency should use qualified advice to review its final policy.


