AI in insurance, checked dailyThursday 17 September 2026
News, findings and tests. Every item with its source, its evidence and what it means for a book of business.For agencies, MGAs and carriers
Working resourceAuthored editorial guidance

Approved AI use register

For
Agency · MGA
Evidence
Authored editorial guidance what this label means
Sources reviewed
2026-09-17
Review cycle
Every 90 days, or sooner when a source changes
Published
2026-09-17T14:18-05:00

In short

“We use this tool” is not a precise operating rule. An approval should say which account may perform which task, using which information, with which review and access restrictions.

Download the blank approved-use register. Use one row per combination of tool, account or workspace, and approved workflow, rather than one row for a vendor's entire product range.

Record the scope

  • Owner and account: Name the internal business owner, administrator, and relevant business account or workspace reference. Never record passwords or secret keys.
  • Permitted task: Describe the allowed input and output. List prohibited uses and actions separately.
  • Data boundary: Record approved data categories and the reference to the decision about provider terms, retention, access, and use of submitted data.
  • Permissions: List integrations and allowed read/write/send actions. Record who can grant or revoke access.
  • Review: Name the review role, required checks, escalation route, and release authority.
  • Lifecycle: Record approval status, effective date, next review trigger, manual fallback, and suspension owner.

Utica's carrier risk guidance recommends an AI policy identifying allowable and nonallowable uses and attention to confidentiality, provider terms, verification, and employee education (Utica National). OWASP separately recommends limiting AI-enabled systems' functionality, permissions, and autonomy (OWASP Excessive Agency). This register adapts those ideas; it does not establish legal compliance or insurance coverage.

Make approval specific

An invented example might approve a business workspace for internal drafting from public reference material, while prohibiting client uploads and external sending. That decision does not approve a personal account, another integration, or uploading policy documents.

If the tool changes its account terms or adds access to a new system, review the affected scope before treating the old approval as sufficient. The register should point to the supporting decision rather than claim that a product is inherently safe.

Maintain the boundary

Make the current register available to the people expected to follow it. Remove ambiguity by recording suspended and retired uses instead of deleting their history from the working record.

Read Before uploading a client document and Your AI assistant needs a permission boundary. Get qualified legal, security, and insurance advice when the decision depends on those areas.