Somewhere in your distribution channel this morning, a producer pasted a prospect's declarations page into ChatGPT and asked for a plain-English summary. An account manager drafted a coverage explanation in Claude. Someone on the claims side wrote up a loss narrative in Copilot, because it came with the Microsoft license. Nobody at the agency decided which tools were approved, what client data could leave the building, or who'd read the output before it reached the insured, because nobody was asked to decide.
That's rarely recklessness. In most agencies it's a decision no one owns.
Elsewhere in the industry, generative artificial intelligence is being treated like any other emerging risk. Last fall, ISO gave carriers three optional endorsements that exclude generative AI losses from the standard commercial general liability policy, which is the industry's way of saying it considers AI a distinct peril. Roughly half the states have adopted the NAIC's model bulletin on how insurers use AI. Inside carriers and MGAs, governance programs are being written so there's something to show an examiner. That's all good work. None of it reaches the agency down the street that sells your policies.
The Big "I" ACT 2026 Tech Trends Report found that 55% of independent agencies have no written AI use policy, and another 23% are still drafting one. Those agencies are your distribution channel.
I spend most of my time inside independent agencies, generally shops of 10 to 50 people, which is how I know that scene doesn't need a name attached. It looks about the same in most of them, and the people doing it are good at their jobs.
It'd be convenient if this stayed the agency's problem. Three things make it yours.
When an AI-drafted coverage summary tells a policyholder something the policy doesn't say, the errors and omissions claim lands on the agency. Your name is on the policy, though, and it tends to show up on the complaint too. What a chatbot wrote in a few seconds becomes a mark on the agent's E&O history and on your market conduct record at the same time.
There's also the data itself. Every application and loss run your agencies handle carries information you're obligated to protect, and the consumer versions of these tools generally keep what's pasted into them. Few agencies know which version they're on. A breach that starts in an agency's browser tab ends up in a regulator's file under the name on the policy, not the name on the agency's door.
Then there's where the regulators are heading. The NAIC bulletin already holds a carrier responsible for AI that a vendor built and runs on its behalf. Agents using AI on carrier data is the same principle one step further out, and regulators haven't taken that step yet. State examiners are piloting a standard set of AI questions for carriers across a dozen states this year, with a broader version expected this fall, and those questions cover the AI carriers themselves use. Nothing in them asks about the distribution channel. I wouldn't plan on that lasting.
Here's the thing: banning AI in agencies would be the wrong response, and most executives know it. The tools are on every desk already, and the agencies using them well are the ones you most want distributing your products. Treat AI use in the channel the way you already treat E&O coverage — as something you require, verify, and help agencies obtain.
Four requirements cover most of the exposure.
A written acceptable-use policy, as a condition of appointment. One page will do. It names the approved tools, says what data can never be entered into them, and identifies who reviews AI-generated material before a client sees it.
A yearly sign-off. Agencies already send you proof of E&O coverage on a schedule. Ask them to confirm the AI policy is in place on the same cycle, and the mechanism costs you nothing new.
A named owner for every tool in use, meaning a person inside the agency whose name sits on the output. AI belongs on an organization's chart, with someone accountable for it, rather than in the tech stack as one more subscription nobody supervises. That's manageable inside your own walls. Across a few hundred agencies you don't employ, it only happens if you require it.
A template alongside the mandate. Agencies without a written policy aren't resisting governance. Most have never been handed a policy they could adopt in an afternoon, and a carrier or field marketing organization that supplies one will close more of the gap than any contract clause. It's also the kind of help agencies remember when they decide where to place business.
Verification can start well before anyone commissions an audit. Before the next renewal cycle, put one question to your 20 largest agencies: who reads what the AI writes before a client does? The answers will tell you where you actually stand.
