Article

Texas TDI's AI Bulletin: What B-0003-26 Really Requires

← All articles
An empty modern Texas insurance agency office at dusk with a wide monitor showing an abstract document and checklist interface in green and blue tones, no people visible

If you’re a Texas-licensed Health or Life agent and someone in your FMO group chat told you TDI now makes you attest to your AI use on renewal, that’s wrong, and the actual bulletin explains why. Texas Department of Insurance Bulletin B-0003-26, issued June 12, 2026, sets expectations for how “regulated entities and their agents and representatives” govern the use of artificial intelligence (TDI, B-0003-26). It asks for human review of consequential AI decisions, a governance framework, and documentation TDI can request during an exam. It does not create a renewal attestation, a new CE requirement, or a specific penalty schedule. This article walks through exactly what the bulletin says, why the misinformation about it took hold, how Texas’s approach differs from the 25 jurisdictions that adopted the NAIC’s model bulletin instead, and how to build a real, one-page AI governance policy this week.

Key takeaways

  • TDI Bulletin B-0003-26 (issued June 12, 2026) applies to "all regulated entities and their agents and representatives" — Texas agents are named, not exempt.
  • There is no renewal-application AI attestation in the bulletin, and TDI's own agent continuing-education page has no AI-specific CE requirement either.
  • Texas has never adopted the NAIC's Model AI Bulletin. Per NAIC's own April 1, 2026 map, Texas is 1 of just 4 jurisdictions (with California, Colorado, and New York) running its own framework instead.
  • Texas now has two AI-adjacent bulletins: B-0036-20 (2020, third-party data accuracy) and B-0003-26 (2026, AI-specific governance and human review).
  • Ambrose's War Room includes a dedicated Compliance persona, Dr. Elena Reyes, you can ask directly, with every run logged, which is exactly the documentation trail TDI's bulletin describes.

What Texas Bulletin B-0003-26 actually says

B-0003-26 is a short bulletin with a specific ask: Texas-regulated entities, and the agents and representatives who work with them, are expected to make sure AI-assisted decisions comply with existing insurance law, put controls in place that reduce the risk of bad outcomes for consumers, and be ready to describe those controls to TDI on request (TDI, B-0003-26). Issued June 12, 2026 and last updated on TDI’s site July 16, 2026, it’s the first bulletin on TDI’s current bulletin index to name artificial intelligence specifically.

Four things stand out once you read the actual text instead of a summary of a summary:

It names agents directly. The bulletin’s scope isn’t “insurance companies.” It’s “all regulated entities and their agents and representatives,” with expectations that “extend to any third party working with a regulated entity.” If you’re a Texas producer using an AI tool in carrier-facing work, underwriting-adjacent quoting, claims-adjacent communication, or marketing a carrier’s product, you’re inside this bulletin’s scope, not outside it.

It asks for a human in the loop on consequential decisions. TDI expects “a person to review and agree with all decisions before action is taken” where an AI system is driving something that matters to a consumer. That’s the same principle every state and federal AI framework converges on in 2026: the AI can draft, sort, and recommend, but a person signs off before it acts on a consumer.

It doesn’t hand you a template. Unlike the NAIC’s model bulletin, which spells out a formal written program with numbered sections (more on that below), B-0003-26 states expectations, governance frameworks, risk management, data and privacy protections, internal controls, without prescribing a specific document format. TDI says it will monitor AI use “through examinations and product filings,” and it isn’t asking for a particular form to fill out. It’s asking you to be able to describe what you actually do.

It doesn’t create new penalties. The bulletin doesn’t introduce a fine schedule. It states that nothing in it limits TDI’s existing authority to “conduct any regulatory investigation, examination, or enforcement action” under current law. The exposure isn’t a new AI-specific fine. It’s that your existing unfair-trade-practice and market-conduct obligations now explicitly cover how you use AI, and TDI has told you it’s watching.

This is guidance about compliance obligations, not compliance advice

Tech Savvy Insurance is a training and software community, not a law firm or an insurance agency. This article describes what a public regulatory bulletin says. It is not legal advice about how the bulletin applies to your specific book of business, and you should read the primary source yourself and talk to your own compliance counsel or carrier compliance department before changing anything based on it.

The rumor: no, TDI did not add an AI attestation to your renewal

Here’s the version of this that’s actually been showing up in Texas agent group chats and a few AI-generated compliance-calendar posts: that B-0003-26 requires an “AI use attestation” on your license renewal application. It’s a specific, confident-sounding claim, and it doesn’t appear anywhere in the bulletin.

Fetching the bulletin directly from tdi.texas.gov turns up governance language, human-review language, and examination language. It does not turn up an attestation requirement, a new form, or a renewal-cycle checkbox. A separate check of TDI’s own agent continuing-education page shows the same thing: no mention of AI, no AI-specific CE hours, and no tie between AI use and license renewal (TDI, Agent Continuing Education).

This is worth naming directly because it’s a textbook case of the exact trap this site’s sourcing standard exists to catch: a plausible-sounding compliance claim, repeated confidently enough in enough places, that nobody traces back to the actual document. The fix is the same one that applies to every circulating industry statistic. Open the primary source yourself. If a claim about a specific requirement doesn’t show up in the bulletin’s own text, it isn’t a requirement, no matter how many times you’ve seen it repeated.

Where the misinformation likely started

AI search summaries and a handful of compliance-calendar sites have circulated the "renewal attestation" claim without linking the actual bulletin text. It's a plausible-sounding detail for a bulletin that genuinely is about AI, which is exactly what makes it spread. This article traces every claim back to tdi.texas.gov and content.naic.org directly rather than to a secondhand summary.

That doesn’t mean there’s nothing here. It means the actual requirement, human review of consequential AI decisions and a governance framework you can describe on request, is less dramatic than a renewal attestation, but it’s real, and it does reach agents. The rest of this article is about that real requirement.

Why Texas now has two AI-adjacent bulletins, not one

Texas didn’t wake up to AI in insurance in June 2026. TDI issued a bulletin on data accuracy back on September 30, 2020, Bulletin B-0036-20, which put insurers on notice that they remain accountable for the accuracy of data used in rating, underwriting, and claims handling, even when a third party supplied that data, and warned of enforcement action if inaccurate third-party data hurts a policyholder (TDI, B-0036-20). That bulletin doesn’t use the word “AI.” It’s about data accuracy and third-party accountability generally, written before generative AI and large-scale predictive models were the industry conversation they are now.

B-0003-26 is the follow-on, six years later, that names AI specifically and adds the governance and human-review expectations the 2020 bulletin didn’t cover. Both are listed on TDI’s own bulletins index, and neither the 2026 table nor B-0003-26’s own text points to an earlier AI-named bulletin between them (TDI, Bulletins index). Put side by side, the two bulletins show a regulator’s stance evolving in real time rather than a single static rule.

Texas's two AI-adjacent bulletins, side by side
Provision B-0036-20 (2020) B-0003-26 (2026)
Focus Accuracy of third-party data used in rating, underwriting, and claims Governance and use of AI systems generally, across the insurance life cycle
Who it names Insurers ("regulated entities") Regulated entities and their agents and representatives, plus third parties working with them
Core ask Remain accountable for data accuracy even if a third party supplied it Human review of consequential AI decisions; a governance framework you can describe on request
Prescribed format None stated None stated — expectations, not a template
Enforcement mechanism TDI's existing statutory authority TDI's existing statutory authority, exercised via exams and product filings

Infographic titled Texas's Two AI Bulletins comparing TDI Bulletin B-0036-20 from September 2020 covering third-party data accuracy for insurers with TDI Bulletin B-0003-26 from June 2026 covering AI governance and human review naming agents and representatives directly, sourced to tdi.texas.gov

Texas has regulated third-party data accuracy since 2020. What's new in 2026 is a bulletin that names AI, and names agents, directly.

How Texas compares to the 25 jurisdictions that adopted the NAIC model instead

Most of the country took a different route than Texas. The NAIC (National Association of Insurance Commissioners) adopted its own Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023, as a template individual states could adopt directly, with each state’s insurance department filling in its own name and citations (NAIC, Dec. 4, 2023).

Per the NAIC’s own implementation map, dated April 1, 2026, 24 states plus the District of Columbia, 25 jurisdictions total, have adopted that model bulletin more or less as written, starting with Alaska in February 2024 and, as of the map’s date, most recently Hawaii in December 2025 (NAIC, implementation map, Apr. 1, 2026). Four jurisdictions instead run their own insurance-specific AI or algorithmic-data regulation: California (Bulletin 2022-5, issued June 30, 2022), Colorado (3 CCR 702-10, effective November 13, 2023, with amendments effective October 15, 2025), New York (Insurance Circular Letter No. 7, issued July 11, 2024), and Texas (Bulletin B-0036-20, issued September 30, 2020, per the same NAIC map). That leaves 22 states, per the same map, with no formal AI-specific insurance bulletin or regulation on the books yet.

How the 50 states plus D.C. regulate insurer AI, as of April 1, 2026

51 jurisdictions total.

Adopted the NAIC Model Bulletin
25
Own insurance-specific AI/data framework (CA, CO, NY, TX)
4
No formal AI-specific insurance guidance yet
22

Source: NAIC, Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers, status as of April 1, 2026.

Stat card showing three sourced figures on a dark green and blue background: 25 jurisdictions adopted the NAIC AI Model Bulletin, 4 states including Texas run their own framework instead, and 22 states have no formal AI specific insurance guidance yet, all sourced to the NAIC implementation map dated April 1 2026

The full national picture behind Texas's choice to run its own bulletin instead of adopting the NAIC model.

Worth being precise about the NAIC map’s own caveat here: it notes that it “represents state action or pending state action addressing the topic of the model” and doesn’t determine whether a state’s actual rule contains every element of the model bulletin. Texas landing in the “own framework” column doesn’t mean B-0036-20 and B-0003-26 together equal the NAIC’s model word for word. It means Texas chose its own path rather than adopting NAIC’s language, and the map is current as of a date before B-0003-26 even existed, since B-0003-26 wasn’t issued until June 12, 2026.

The four states running their own AI framework instead of the NAIC model
State Its own framework Issued / effective
California Bulletin 2022-5 Issued June 30, 2022
Colorado 3 CCR 702-10 (implementing SB 21-169) Effective Nov. 13, 2023; amended Oct. 15, 2025
New York Insurance Circular Letter No. 7 Issued July 11, 2024
Texas Bulletin B-0036-20, now paired with B-0003-26 Issued Sept. 30, 2020; B-0003-26 added June 12, 2026

Colorado is worth a closer look because it’s the most prescriptive of the four. Its underlying law, SB 21-169, “Restrict Insurers’ Use of External Consumer Data,” signed July 6, 2021, bars insurers from using external data, algorithms, or predictive models that unfairly discriminate against consumers based on protected characteristics, and requires insurers to disclose the external data sources behind their algorithms, run a documented risk-management assessment, and have their chief risk officer attest to compliance (Colorado General Assembly, SB 21-169). Texas hasn’t gone that far. B-0003-26 asks for governance and human review; it doesn’t require a CRO attestation or a specific risk-assessment filing the way Colorado’s regulation does. That gap is exactly why a Texas agent shouldn’t assume “my state didn’t adopt the strict NAIC model” means “my state doesn’t regulate this at all.” It means Texas regulates it its own, shorter way, and the bar can move.

What it actually costs you to get this wrong

There’s no dollar figure to print here, and this site doesn’t invent one where none exists. B-0003-26 doesn’t carry a stated fine schedule, so there’s no “$X per violation” number to cite honestly. The real cost is different, and it’s worth being precise about it rather than reaching for a scarier number that isn’t sourced.

The bulletin states plainly that TDI will monitor AI use “through examinations and product filings,” and that nothing in the bulletin limits its existing authority to investigate, examine, or take enforcement action under current law. That’s the mechanism. If you’re using AI in carrier-facing work, quoting, marketing, underwriting-adjacent communication, and an exam or a filing review asks how that AI use is governed, “we don’t have anything written down” is a materially worse answer than a one-page policy you can hand over. The exposure isn’t a new AI-specific penalty. It’s your existing unfair-trade-practice and market-conduct obligations, the same ones that have always applied to how you handle a consumer’s information and a carrier’s product, now explicitly extended to cover AI-assisted work, with a regulator on record saying it’s paying attention.

There’s a second, quieter cost: getting spooked by the misinformation and either ignoring AI entirely, and falling behind agents who use it well, or dismissing the whole bulletin as noise because the one claim you heard about it (the renewal attestation) turned out to be false. Both reactions throw out a real, if modest, requirement along with a fake one. The accurate read is narrower and more useful than either extreme: there’s a real human-review and governance expectation that reaches you as an agent, it’s not hard to satisfy, and it isn’t the dramatic thing the rumor made it sound like.

The bulletin that actually exists is smaller and more reasonable than the rumor about it. That's usually true, and it's exactly why reading the primary source instead of the group chat is worth five minutes.

Mike Moore

The manual method: build a one-page AI governance policy this week

None of what follows requires software, a membership, or a compliance department. B-0003-26 doesn’t hand you a template, so borrow the most thoroughly worked one that exists: the NAIC’s Model Bulletin, even though Texas hasn’t adopted it. The NAIC’s full text lays out a written “AIS Program” (AI Systems Program) with specific elements (NAIC, Model Bulletin full text, adopted Dec. 4, 2023), and those elements map directly onto what B-0003-26 asks for in plainer language. Here’s how to build your own version in an afternoon.

Name an owner

The NAIC's language is "senior management accountable to the board." For a solo agent or small shop, that's just you, in writing: "I am responsible for how AI is used in this agency." One sentence, and it's the first thing an exam looks for.

Write down what AI may and may not do

One page. AI may draft client communications, qualify leads, summarize plan documents, and schedule. AI may not send client communication unreviewed, make a coverage recommendation, or submit an application without your review. This single page is most of what "governance" means in practice.

Put a human on every consequential decision

This is the literal ask in B-0003-26: "a person to review and agree with all decisions before action is taken." Anything that reaches a consumer, a quote, a plan comparison, a marketing message, gets a human read before it goes out. Say so in your one-pager.

Log what you did

The NAIC's documentation requirement is "requirements adopted by the Insurer to document compliance with the AIS Program." For a small agency, that can be as simple as a dated note each time you review your AI-drafted materials, or a folder of "reviewed and approved" copies. It doesn't need to be fancy. It needs to exist.

Check your AI vendors like any other vendor

The NAIC bulletin calls this "due diligence" on third-party AI systems and data. In practice: know what tool you're using, whether it's built for insurance or a general consumer product, and whether the vendor can tell you how it handles client data. A vendor who can't answer that isn't a vendor to build your governance around.

Revisit it when the rules move

Texas added B-0003-26 six years after B-0036-20. The NAIC's map changes every few months as more states act. Put a reminder on your calendar, quarterly is enough for most small agencies, to check tdi.texas.gov's bulletin index and the NAIC's own map for changes.

What most agencies have today

Nothing written down. AI tools adopted one at a time, whichever agent liked the demo. No one could name who "owns" AI governance in the shop, and no record exists of anyone reviewing what the AI drafted before it went to a client.

What B-0003-26 is actually asking for

A one-page written policy naming an owner, a human-review step before anything reaches a consumer, a simple log of that review, and a short answer for what AI tools you use and whether their vendors can speak to how they handle data.

This is the whole method

Name an owner, write the one-pager, keep a human in the loop, log the review, check your vendors, and set a quarterly reminder. That's a genuinely complete, defensible answer to "how do you govern AI in this agency," and it costs nothing but the afternoon it takes to write it.

A worked example: applying the one-pager to a real Texas scenario

Abstract policy language is easy to nod along to and hard to actually picture in your own agency. Here’s the concrete version, using a scenario that’s common for a Texas Health agent in 2026: you use an AI tool to draft outbound marketing messages and to help summarize plan documents for prospects.

Start with the ownership line. If you’re a solo agent, that’s you: write “I am the person responsible for how AI tools are used in this agency, including reviewing anything they draft before it reaches a client.” If you have a small team, name the specific person, not “the team,” the same way TDI’s bulletin expects a regulated entity to be able to name who’s accountable.

Next, the one-page scope. Write down, specifically, what the AI tool is allowed to do in your shop: draft an outbound message, summarize a plan document’s benefits into plain language, suggest talking points for a follow-up call. Then write down what it isn’t allowed to do: send a message without your review, state a plan’s coverage details without you checking them against the plan document, or make an eligibility or suitability recommendation. This is the exact distinction B-0003-26’s human-review language is getting at, “a person to review and agree with all decisions before action is taken.”

Now put the review step into your actual workflow, not just your policy document. Before an AI-drafted marketing message goes out, you read it, check it against the plan’s actual benefits and against your compliance obligations, and either approve it or edit it. That review is the part regulators actually want to see evidence of, not a document sitting in a drawer.

Then log it. The simplest version that satisfies the NAIC’s “documentation requirements” language, borrowed here as the more detailed template, is a dated note: “Reviewed and approved outbound message X on [date].” A shared folder of approved copies with dates works. A spreadsheet with one row per review works. The format doesn’t matter. Having something to show, instead of nothing, is the entire point.

Finally, check the tool itself. If you’re using a general-purpose AI chatbot with no insurance-specific guardrails, that’s a due-diligence gap under the NAIC’s third-party framework, and arguably under B-0003-26’s own governance language, since the bulletin’s expectations “extend to any third party working with a regulated entity.” A tool built for insurance, with your industry’s marketing rules and disclosure requirements already baked into what it drafts, closes that gap by design instead of by remembering to check it every time.

That’s the whole worked example. None of it required buying anything. It required about the same amount of time as writing a single client email, and it produces a policy that actually answers the question an exam or a filing review would ask.

If you sell Medicare in Texas: this stacks with CMS’s rules, it doesn’t replace them

B-0003-26 is a state insurance-regulator bulletin about AI governance. It is not a Medicare marketing rule, and it doesn’t touch, relax, or replace the federal rules that already govern how you market Medicare Advantage, Part D, or Medicare Supplement plans in Texas. If you’re using an AI tool anywhere in your Medicare marketing funnel, drafting scripts, running an AI voice or chat intake, generating follow-up messages, you’re stacking two separate compliance layers, not choosing between them.

The federal layer doesn’t move because a state bulletin exists. Any AI-assisted call or communication that markets specific Medicare plan benefits still has to open with the required Third-Party Marketing Organization (TPMO) disclaimer, still has to be handled under the CMS Medicare Communications and Marketing Guidelines, and still requires the licensed agent, not the AI tool, to own the recommendation and the sale. An AI system can qualify a lead, draft a follow-up, and log the interaction. It cannot be the thing that decided what plan to recommend, and it cannot skip the disclaimer because a human didn’t remember to add it to the prompt.

Practically, that means your one-page AI policy for a Texas Medicare book needs two review gates, not one: the state-level gate this article walks through (human review, documentation, vendor diligence) and the federal gate that’s always applied to Medicare marketing regardless of AI (TPMO disclaimer present, call recorded and retained, licensed agent owns the enrollment). We cover the federal layer in far more depth, TPMO specifics, CMS retention rules, and the liability question, in our guide to AI compliance for insurance agents in 2026. Treat B-0003-26 as an addition to that existing obligation, not a replacement for any part of it.

How Ambrose’s War Room Compliance persona handles this

Everything above works with a blank document and no membership. Where a tool actually helps is having someone to ask when a specific question comes up, “does this outbound message hold up,” “is this vendor’s data handling actually documented,” without waiting for your next call with counsel.

Inside Ambrose OS, the War Room is a chat surface for a fixed roster of nine executive AI personas: type a question, and Ambrose decides which head answers, or convenes a small group, and synthesizes a response in your agency’s own voice (Ambrose docs, War Room). One of those nine is Dr. Elena Reyes, the Compliance persona, alongside a Chief of Staff and named CMO, COO, CCO, CFO, CRO, CTO, and Research roles (Ambrose docs, What is Ambrose). You can ask her directly, in plain English, whether a piece of client-facing language or a workflow decision holds up, the same first-pass check a governance-minded agency would want before anything reaches a consumer. The War Room’s own documentation shows an expandable tool-call timeline and contributor attribution on every answer, which is itself a form of the run-level record that B-0003-26’s “documentation you can produce on request” language describes.

That’s not a substitute for your own judgment, your carrier’s compliance department, or actual legal counsel, and this article isn’t claiming otherwise. What it replaces is the manual version of the same job: you, alone, trying to remember whether a specific piece of outbound copy or a specific AI-assisted workflow decision is one you already reviewed and approved, with nothing written down if you didn’t.

The other half of this is data handling. Every read and write inside Ambrose is scoped to the agency’s own tenant (Ambrose docs, Architecture), and Ambrose’s PHI Rail checks whether a destination is on the agency’s BAA allowlist before a prompt reaches it: if it is, the request passes through; if it isn’t, the PHI Gateway scrubs identifiers into typed aliases first and re-hydrates the real values on the response, using the original hydration map (Ambrose docs, PHI Rail architecture). We describe that as HIPAA-aware by default, not a HIPAA certification, because no AI vendor should claim to be “HIPAA certified,” and Tech Savvy doesn’t make that claim on Ambrose’s behalf either. What it means practically is that the “don’t paste a client’s health detail into a general AI tool” rule from the FAQ above is the default behavior inside Ambrose, not a discipline you have to remember to apply every time.

Name the mechanism, not just "AI"

The specific thing worth naming here is the War Room's Compliance persona and the run-level record it leaves behind, not a general claim that "AI helps with compliance." A generic chatbot doesn't know what B-0003-26 says or who your agency's designated owner is. A persona built for this, inside a system scoped to your own tenant, does.

What you get by joining

One Ambrose seat, including War Room access and the Compliance persona referenced above, comes included with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, with the founding rate locked in while the membership stays active. Ambrose usage itself runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, more than 30 hours of recorded training, Meta Ads and marketing training built for this industry, pre-built AI templates and bot deployments, and a free annual in-person member workshop. It’s also an explicit no-recruiting zone, you can ask a real compliance question without ending up on someone’s downline pitch list an hour later, which isn’t true of most agent Facebook groups.

Close

Read the actual bulletin before you believe the version of it that’s circulating: TDI’s B-0003-26 asks Texas agents and the carriers they work with for human review of consequential AI decisions and a governance framework you can describe on request, not a renewal attestation. Build the one-page policy above this week, whether or not you ever join anything, name an owner, write down what AI may and may not do, keep a human on every consumer-facing decision, and log it. If you’d rather have a Compliance persona to run that same question by, with people building the same policy alongside you on a Tuesday call, one Ambrose seat comes with a Tech Savvy membership: https://techsavvyinsurance.com/. See also our guide on AI compliance for insurance agents in 2026 for the national NAIC picture, and our pillar guide on AI for insurance agents in 2026.

Before you act on any of this

Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. You are responsible for your own licensure and for complying with all applicable TDI, NAIC-derived state, CMS, HIPAA, and carrier rules, including TPMO disclaimer and Medicare marketing requirements where they apply. AI-generated outputs may contain errors, always verify against the current primary source, including reading B-0003-26 yourself at tdi.texas.gov, before changing anything based on this article. Results may vary.

Frequently asked questions

It reaches both. TDI's own bulletin text says its expectations apply to "all regulated entities and their agents and representatives," and that they "extend to any third party working with a regulated entity." So if you're a Texas-licensed agent using AI tools in work you do for or with a carrier, you're inside the scope of this bulletin, not a bystander to it.
No. That claim is circulating, and it is not in the bulletin. TDI's Bulletin B-0003-26, fetched directly from tdi.texas.gov, contains no renewal-application attestation requirement of any kind. A separate check of TDI's own agent continuing-education page turned up no AI-specific CE or licensing requirement either. If someone tells you Texas now makes you sign an AI attestation to renew your license, ask them to point to the sentence in the bulletin. There isn't one.
No, and it never has. Per the NAIC's own April 1, 2026 implementation map, Texas is one of four jurisdictions, alongside California, Colorado, and New York, that regulate insurer AI through their own separate framework rather than adopting the NAIC's model language. Texas's own framework is TDI Bulletin B-0036-20, issued back in September 2020, and now B-0003-26 sits alongside it as a second, AI-specific bulletin.
Per TDI's bulletin text, regulated entities and their agents are expected to keep AI-assisted decisions compliant with existing insurance law, put controls in place to reduce the risk of bad outcomes for consumers, have a person review and agree with consequential AI-driven decisions before anything happens, and maintain governance, risk management, data and privacy protections, and internal controls they can describe to TDI on request. There's no prescribed form or checklist. It's expectations, not a template.
The bulletin doesn't create a new fine schedule. It states that TDI will monitor AI use through examinations and product filings and that nothing in the bulletin limits TDI's existing authority to investigate, examine, or take enforcement action. In practice, that means the risk isn't a specific fine for a missing document. It's that if TDI or a carrier asks how your AI-assisted work is governed during an exam or a filing review and you have nothing to show them, you're relying on existing unfair-trade-practice and market-conduct law doing the rest of the work for you.
The NAIC's model, adopted by 24 states plus the District of Columbia, 25 jurisdictions total as of the NAIC's own April 1, 2026 map, is far more detailed. It spells out a formal written "AIS Program" with named sections on governance, risk management, third-party oversight, and exactly what documentation a regulator can request. Texas's B-0003-26 sets the same broad expectations, human review, governance, documentation on request, in a shorter bulletin without that level of prescribed structure. If you want a fully worked template to build from, the NAIC's is the most detailed one on paper, even though Texas hasn't adopted it.
Anything that identifies a specific client alongside health, claim, or underwriting detail. That's a HIPAA exposure with no business associate agreement behind a consumer AI tool, and it's a separate risk from the AI-governance question B-0003-26 raises. Keep client-identifying detail out of general-purpose AI tools, and if a workflow genuinely needs to touch real client data, use a platform built with that handled by design rather than left to a busy agent's judgment on a Tuesday afternoon.
Yes, and the full method is in this article: name an owner, write down in one page what AI may and may not do in your shop, keep a human reviewing anything that touches a consumer decision, log what you did, and check your third-party AI vendors the way you'd check any other vendor. None of that requires software. What a Tech Savvy membership adds is an Ambrose seat with a War Room Compliance persona you can ask directly, plus a room of agents building the same one-pager alongside you.

Sources

  1. Texas Department of Insurance — Bulletin B-0003-26, Use of Artificial Intelligence (June 12, 2026) — tdi.texas.gov
  2. Texas Department of Insurance — Bulletins index — tdi.texas.gov
  3. Texas Department of Insurance — Bulletin B-0036-20, Insurers' Use of Third-Party Data (Sept. 30, 2020) — tdi.texas.gov
  4. Texas Department of Insurance — Agent Continuing Education — tdi.texas.gov
  5. NAIC — Members Approve Model Bulletin on Use of AI by Insurers (Dec. 4, 2023) — content.naic.org
  6. NAIC — Model Bulletin: Use of Artificial Intelligence Systems by Insurers (full text, adopted Dec. 4, 2023) — content.naic.org
  7. NAIC — Implementation of NAIC Model Bulletin: Use of AI Systems by Insurers (status as of Apr. 1, 2026) — content.naic.org
  8. Colorado General Assembly — SB 21-169, Restrict Insurers' Use of External Consumer Data — leg.colorado.gov
  9. Ambrose docs — What is Ambrose — app.hiambrose.com
  10. Ambrose docs — War Room — app.hiambrose.com
  11. Ambrose docs — System architecture (the Brain, tenant isolation) — app.hiambrose.com
  12. Ambrose docs — PHI Rail architecture (BAA allowlist, aliasing, rehydration) — app.hiambrose.com

Ready to put this into practice?

Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.

Join Tech Savvy — $97/month