Can AI sell insurance?

The regulatory question about AI in an insurance agency is not "is this allowed." It is "at what point does this become the transaction of insurance" — because that point is where a licence is required, and it falls earlier than most people assume.

Most guidance on this splits into two useless halves. Vendors say automate everything. Law firms describe the regulatory landscape without ever saying which specific task is on which side of the line. What an agency owner actually needs is the line.

Here is our read of where it falls. This is not legal advice — licensing rules are state law, they differ, and the technology is moving faster than the rules are. Treat this as a framework for the conversation you should have with your compliance counsel, not a substitute for it.

The line is "advice", not "automation"

Every state licenses the transaction of insurance: soliciting, negotiating and selling. The words vary; the shape doesn't. Scheduling, reminding, collecting information and answering a factual question about your own business are not that. Recommending a product, comparing coverage to a person's situation, quoting a rate as applying to them, or binding anything, is.

The practical consequence is that the automatable surface is large but it ends abruptly. An automated system can do a great deal of work getting to the conversation. It should not be the one having the part of the conversation that constitutes advice.

TaskAutomatableWhy
First response to a new enquiryYesAcknowledging an enquiry and asking what they need is not solicitation.
Factual questions about your agencyYesHours, licensing, what you sell, who you are — statements about your own business.
Qualifying questionsYesCollecting information is not advising on it.
Booking, reminders, reschedulingYesScheduling is administration.
Follow-up on a missed appointmentYesSame conversation, later. Consent and quiet-hours rules still apply.
Summarising a call for the producerYesInternal. The consumer is not the audience.
Quoting a rate for their situationNoA quote applied to a person is part of the sale.
Recommending a productNoThis is the transaction of insurance. Licensed producer.
Comparing coverage to their circumstancesNoAdvice, whatever it is called.
“Is my doctor in network?”NoFeels like a lookup. The answer depends on the plan being recommended to them, so answering it is participating in the recommendation.
Anything that bindsNoAuthority the carrier delegates to a licensed person, not to software.

Our read, not legal advice. Licensing rules are state law and differ — the line above is a framework for the conversation to have with your compliance counsel.

The row worth staring at is "is my doctor in network". It feels like a lookup and it is not — the answer depends on the plan being recommended to that person, and giving it is participating in the recommendation. This is the single most common place we see an automated system quietly cross the line, because it does not feel like advice to whoever built it.

What the NAIC model bulletin actually binds

This is where published guidance is most often misread, so it is worth being precise.

The NAIC, artificial intelligence adopted its Model Bulletin on the Use of Artificial Intelligence Systems in December 2023, and more than half the states have now adopted it or substantially similar guidance. It requires a written AI programme covering governance, risk management, testing and validation, vendor oversight, documentation, and consumer notice.

It is addressed to insurers, not to producers. An agency is not the party the bulletin regulates. That is the fact almost nobody states plainly, and it is genuinely useful to know.

It is also not the end of the matter, for two reasons. First, the bulletin explicitly makes insurers responsible for third-party AI systems they rely on — including audit rights in contracts — so the obligation reaches you through your carrier appointments rather than directly. Second, the rules that do bind an agency directly — producer licensing, unfair trade practices, and the TCPA — never stopped applying because a machine is doing the typing.

The model bulletin is addressed to insurers, not producers — but it makes insurers responsible for the third-party AI systems they rely on, including audit rights in contracts. The obligation reaches an agency through its carrier appointments rather than directly.

NAIC, artificial intelligence

Disclosure isn't optional in practice

Even where no rule compels it, the market has already decided. 85% of policyholders want to be told when AI is involved in handling their business — a finding we covered in our piece on AI adoption. Any product whose value depends on the prospect not realising they are talking to software is building on something that will not hold, and is one screenshot away from being the story.

Disclosure is cheap and it costs almost nothing in conversion. A system that identifies itself as an assistant, is straightforwardly useful, and hands off to a licensed human at the point of advice, is both the compliant design and the one that works.

The other half: TCPA still applies

Automation changes the volume of outreach, not the rules governing it. Consent, quiet hours in the recipient's own time zone, and the revocation rules that changed in April 2025 apply to an automated message exactly as they do to a manual one — and at automated volume, an error that would have been one message becomes several thousand. The specifics are in what you can and can't automate when texting insurance leads.

One thing worth saying twice: an automated sender must be able to stop. If your system cannot honour an opt-out expressed in plain language rather than a keyword, its volume is a liability rather than an advantage.

The readiness gap

Vertafore, building confidence in your agency’s tech stack (2026 Agency Trends Outlook)'s 2026 survey of more than 1,300 independent agency professionals found 46% felt only somewhat or not at all prepared to keep pace with technology and market change — rising to 55% at agencies of six or fewer staff. Very few agencies of any size have a written AI policy.

The gap that matters is not enthusiasm. It is that AI is being used without anyone having written down what it may do, who checks it, and what happens when it is wrong.

A governance checklist you can actually complete

Scaled to an agency, not to a carrier. This is a morning's work, and it is the difference between using AI and being able to explain how you use AI.

The controlWhat it answers
1Write down what the AI may and may not doThe scope question. One page. Where the handoff to a licensed producer happens.
2Sample its output on a scheduleDrift. Read ten real threads a week. This is the only control that catches a system going slightly wrong before a customer does.
3Name who can switch it offThe stop question — and make sure that person actually can, without an engineer.
4Keep every message, retrievable per leadThe evidence question. If you cannot show what was said, nothing else here matters.
5Disclose that it is an assistantIn the conversation, not in a footer.
6Tell your carriers what you runThe appointment question. Vendor-oversight clauses are how the bulletin reaches you.

Scaled to an agency, not a carrier. A morning's work, and the difference between using AI and being able to explain how you use it.

The item people skip is the second one. An AI that starts doing something slightly wrong keeps doing it at volume until a human happens to read a thread — so the sampling review is not bureaucracy, it is the only control that catches drift before a customer does.

What good looks like

A defensible design has four properties, and they are all architectural rather than procedural — which means you either have them or you don't:

It identifies itself. Not buried in a footer. In the conversation.

It has a hard stop at advice. The handoff to a licensed producer is a rule in the system, not an instruction in a prompt that a model may or may not follow. A prompt is a preference; a gate is a control.

It is logged and reviewable. Every message, retrievable per lead. If you cannot show a regulator or a carrier what was said, nothing else on this list matters.

It can be turned off. Per agent, per campaign, immediately, by someone who is not an engineer.

Common questions

Can AI sell insurance?

No. Soliciting, negotiating and selling insurance require a licensed producer in every state, and that does not change because software is doing the typing. AI can do a great deal of the work that precedes a sale — responding to an enquiry, answering factual questions, qualifying, scheduling, following up — but recommending a product, applying a quote to a person's situation, or binding coverage is the transaction of insurance and needs a licensed human.

Does the NAIC AI model bulletin apply to insurance agencies?

The bulletin is addressed to insurers, not to producers, so an agency is not the party it directly regulates. It reaches agencies indirectly but reliably: it makes insurers responsible for third-party AI systems they rely on, including audit rights in contracts, so the obligations arrive through carrier appointments. Rules that do bind an agency directly — producer licensing, unfair trade practices and the TCPA — apply regardless.

Do I have to tell customers when AI is involved?

Disclosure requirements vary by state and are still developing, so check your own. In practice the question is settled by the market rather than the rules: 85% of policyholders say they want to be told when AI is involved. A system that depends on people not realising they are talking to software is fragile whatever the rule says, and disclosure costs very little.

What insurance tasks are safe to automate?

The reliable test is whether the task involves advice. First response to an enquiry, answering factual questions about your agency, collecting information, qualifying, scheduling, reminders, follow-up on a missed appointment, and internal summarisation are all clear of the line. Recommending a product, comparing coverage to someone's situation, quoting a rate as applying to them, and anything that binds are all on the far side of it.

Can AI answer 'is my doctor in network'?

Treat it as advice, not lookup. The answer depends on which plan is being recommended to that specific person, which makes answering it part of the recommendation rather than a factual statement about your business. It is the most common place we see an automated system cross the line, precisely because it does not feel like advice to whoever built it.

Does an insurance agency need a written AI policy?

No rule currently requires most agencies to have one, and very few do. It is still worth an hour: write down what the system may and may not do, who reviews a sample of its output and how often, who can switch it off, and what your carriers have been told. The purpose is not compliance theatre — it is being able to answer those questions when a carrier or a regulator asks, which they increasingly do.

Virtual Closer's AI is built to this line: it identifies itself as an assistant, hands off to a licensed producer at the point of advice as a rule in the system rather than an instruction in a prompt, logs every message against the lead, and has per-agent and per-campaign kill switches.