AI Disclosure Laws for Insurance Agents in 2026 — Tech Savvy Insurance
Article

AI Disclosure Laws for Insurance Agents in 2026

← All articles
Dark cinematic insurance agency desk at dusk with a laptop showing an abstract chat-bubble interface with no readable text, a phone lying face-up showing a soft voice-waveform glow, an ultrawide monitor in the background with a blurred map-of-states graphic, no people visible, green and blue tones

Yes, in a growing number of states, and the honest answer is “it depends on the state, the channel, and whether the lead asked” — which is a worse answer than a one-line yes, because it means a single chatbot script that’s fine in Florida can be a $2,500-per-violation problem in Salt Lake City. Utah already has a live disclosure law on the books. Colorado’s rewritten AI Act takes effect January 1, 2027 and names insurance specifically as a covered use case. The FCC settled the voice-call question back in February 2024. None of these rules talk to each other, none of them were written with a licensed health or life agent’s AI-texting setup in mind, and most agents running an AI follow-up bot today have never read any of them. This article maps exactly what each one requires, the one-line script that satisfies the strictest version of all of them at once, and what Ambrose’s reply-bot and channel-bridge spokes actually do about it if you’d rather not build the review step by hand.

Key takeaways

  • Utah requires any business using generative AI in a consumer transaction to admit it's AI if a person asks (Utah Code 13-75-103(1), effective May 7, 2025) — but the stricter, proactive upfront-disclosure duty only applies to "regulated occupations" licensed by the Department of Commerce, and Utah insurance producers are licensed by a separate Insurance Department instead (Utah Code 31A-2-101).
  • Colorado's rewritten AI Act (SB26-189) takes effect January 1, 2027 and requires "clear and conspicuous notice" at the point of interaction for AI used in a defined list of "consequential decisions" that explicitly names insurance (Colorado General Assembly, SB26-189 bill page).
  • The FCC's February 2024 declaratory ruling already treats an AI-generated voice on a call as an "artificial" voice under the TCPA, triggering the same consent and identification rules as any prerecorded call (FCC, Declaratory Ruling FCC-24-17).
  • Utah's penalties run up to $2,500 per violation administratively or in court, and up to $5,000 per violation for defying an order (Utah Code 13-75-105); TCPA violations run $500 to $1,500 per call under the federal private right of action (47 U.S.C. § 227(b)(3)).
  • As of August 31, 2026, 26 jurisdictions have adopted the NAIC's AI Model Bulletin, which expects a written AI governance program, not a specific consumer-facing script (NAIC, Legal Adoption Map, Aug. 31, 2026).

The pain: a lead asks “am I talking to a real person?” and you don’t actually know the right answer

Picture the setup a lot of agencies already have running. A lead fills out a form after hours, an AI-drafted text goes out within a minute or two to get the conversation started, and a few back-and-forths later the lead types, “wait, is this a real person?” Somebody on your team glances at the thread, isn’t sure what the bot is supposed to say, and either ignores the question or has the bot deflect with something vague. It feels like a minor UX wrinkle. It is actually the exact moment Utah’s law is written around — and if the same bot also places a follow-up call using a synthetic voice, it’s the exact scenario the FCC settled nearly two years ago, with a federal statute’s private right of action sitting behind it.

Most agents didn’t choose to ignore this. There’s no single place that tells you the answer, because there isn’t a single federal disclosure law yet — just a federal voice-call ruling, two live-or-almost-live state laws with genuinely different triggers, and an NAIC bulletin that’s about something else entirely (insurer governance, not chatbot scripts). An agent licensed in three or four states is, in effect, subject to three or four different answers to the same question, and the states most actively legislating this — Utah, Colorado, California — are not necessarily the states where most health and life business gets written, so it’s easy to assume none of it applies and be wrong the one time it does.

The second version of this pain is subtler: you want to disclose, you just don’t know what counts as disclosure. Is a line buried in a website’s terms of service enough? Does a chat widget’s “AI Assistant” label in the header satisfy an upfront, verbal-equivalent duty? Nobody selling AI texting tools to agencies is answering that question for you, because most of them aren’t licensed to practice law and have no reason to tell you where their tool’s default behavior falls short.

Why it happens: three different rulebooks, built for three different problems

Utah built its law around the format of the interaction, not the industry. Utah Code 13-75-103, enacted by S.B. 226 in the 2025 General Session and effective May 7, 2025, splits the disclosure duty into two tiers. Subsection (1) is the baseline: “a supplier that uses generative artificial intelligence to interact with an individual in connection with a consumer transaction shall disclose to the individual that the individual is interacting with generative artificial intelligence and not a human, if the individual asks or otherwise prompts the supplier” — reactive, triggered only by the consumer’s own question (Utah S.B. 226, enrolled, Section 3). Subsection (2) is stricter and proactive — prominent disclosure before the interaction even starts — but it only binds “regulated occupations,” which Section 13-75-101(8) defines as an occupation “regulated by the Department of Commerce” that requires a license or state certification. Insurance producers are licensed under Title 31A, administered by Utah’s own Insurance Department (Utah Code 31A-2-101: “The Insurance Department shall administer the Insurance Code”) — a separate agency from the Department of Commerce. Read literally, that means an insurance agent texting a Utah lead through an AI assistant owes the reactive duty under (1), but not the proactive, prominent, upfront duty under (2) that a Utah-licensed therapist or accountant would owe. That’s a genuinely easy distinction to get backwards if you’ve only read a law-firm summary instead of the statute, which is why this article is citing the enrolled bill text directly rather than someone’s recap of it.

Worth noting precisely, because it looks at first glance like it should sweep insurance back in: Utah’s statute defines a “high-risk artificial intelligence interaction” as one involving the collection of sensitive personal information, including health data, financial data, or biometric data, or the provision of personalized advice someone could reasonably rely on for a significant decision, including financial, legal, medical, or mental health advice (Utah S.B. 226, enrolled, Section 1, defining 13-75-101(5)). A chatbot helping a lead compare Medicare plans or estimate an ACA subsidy is arguably doing exactly that. But the high-risk trigger only matters for the proactive, prominent-disclosure duty in subsection (2) — and that subsection only binds “regulated occupations” in the first place. Since insurance isn’t one under Utah’s definition, the high-risk language doesn’t pull insurance back into the stricter tier; it’s a near-miss worth knowing about rather than an exemption to rely on blindly, especially if Utah’s legislature revisits the regulated-occupation definition in a future session.

Colorado built its law around the decision, not the format. The original 2024 version of Colorado’s AI Act, SB24-205, got delayed twice — first to June 30, 2026, then shelved entirely — before being repealed and reenacted as SB26-189, which takes a narrower “automated decision-making technology” (ADMT) approach with an operative date of January 1, 2027 (Colorado General Assembly, SB26-189 bill page). Instead of regulating “generative AI” as a category, it regulates AI used in a “consequential decision” — and the statute’s own list of consequential-decision domains names insurance outright, alongside education, employment, housing, financial or lending services, health care, and essential government services. The obligation that falls out of that: a deployer using a covered ADMT to help decide something consequential for a Colorado consumer has to give “clear and conspicuous notice to consumers at the point of interaction,” plus, within 30 days of an adverse outcome, a plain-language description of the system’s role in it. Notice that this isn’t about whether your chatbot is “generative AI” in the conversational sense Utah cares about — it’s about whether the output is doing something that shapes a consequential decision, which an AI tool helping triage, pre-qualify, or route a Medicare or ACA lead plausibly is.

The FCC settled the voice-call question in 2024, and it’s older and more binding than either state law. On February 8, 2024, the FCC unanimously adopted a Declaratory Ruling clarifying that the Telephone Consumer Protection Act’s restrictions on “artificial or prerecorded voice” already cover AI-generated voices — it wasn’t writing a new rule, it was confirming the existing one reaches the new technology (FCC, Declaratory Ruling FCC-24-17, released Feb. 8, 2024). Practically, that means a call using an AI voice clone or synthetic voice agent needs the called party’s prior express consent before it goes out, the same as any other prerecorded or artificial-voice call under the TCPA — and the TCPA has real teeth behind it through its private right of action.

Three rulebooks, three different triggers — the format, the decision, and the channel — and none of them cross-reference each other.

Mike Moore

The NAIC’s AI Model Bulletin is a fourth thing entirely, and it’s easy to conflate with the first three. Adopted by the NAIC’s Executive Committee and Plenary on December 4, 2023, the bulletin sets expectations for how a licensed insurer governs its own use of AI systems — a written AI program, documented testing and monitoring, human oversight, and vendor accountability that a state insurance department can ask to review during an exam or investigation. As of August 31, 2026, 26 jurisdictions — 25 states plus the District of Columbia — have adopted some version of it (NAIC, Legal Adoption Map: AI Model Bulletin, status as of Aug. 31, 2026). It’s a governance standard aimed mostly at carriers, not a script requirement for an individual agent’s chat widget, but it’s the piece that matters if your state’s insurance department ever asks how your agency supervises the AI tools it uses — which is a different question from what your bot says to a lead, and agents regularly mix the two up.

Four rulebooks, four different triggers
Rule What triggers it Who it binds Effective date
Utah Code 13-75-103(1) The consumer directly asks if it's AI Any "supplier" in a consumer transaction, insurance included May 7, 2025
Utah Code 13-75-103(2) Any interaction, proactive and prominent "Regulated occupations" licensed by Dept. of Commerce only — not insurance May 7, 2025
Colorado SB26-189 AI materially influences a "consequential decision" Deployers of covered ADMT, including insurance coverage, pricing, or claims January 1, 2027
TCPA, per FCC ruling FCC-24-17 Placing a call using an AI-generated voice Any caller, insurance included — same as any artificial/prerecorded voice rule Feb. 8, 2024 (ruling date; TCPA itself predates it)

What it costs: per-violation, not per-incident

$2,500
per-violation fine Utah's Division of Consumer Protection can impose administratively
Utah Code 13-75-105(4)(a), S.B. 226 (2025)
$5,000
per-violation civil penalty for defying an order already issued under the statute
Utah Code 13-75-105(7)(a), S.B. 226 (2025)
$500–$1,500
per-call TCPA exposure for an undisclosed AI voice call made without consent
47 U.S.C. § 227(b)(3)

Stat card graphic showing three large sourced penalty figures in green and blue: 2,500 dollars Utah administrative fine per violation, 5,000 dollars Utah civil penalty for violating an order, and 500 to 1,500 dollars TCPA exposure per call, each labeled with its statutory source

The number that should actually worry a multi-state agency is “per violation,” not the dollar figure itself. Utah’s statute gives its Division of Consumer Protection the power to impose an administrative fine of up to $2,500 for each violation, and separately lets a court impose a fine of up to $2,500 per violation in an enforcement action it brings, plus attorney fees, court costs, and investigative fees awarded to the division if it wins (Utah Code 13-75-105(4)-(6)). If a person or agency then violates an order already issued over that conduct, the civil penalty jumps to up to $5,000 per violation (Utah Code 13-75-105(7)(a)). Run an AI texting sequence against a thousand-lead list with a script that never discloses AI use, and “per violation” is doing a lot of work in that sentence — it is not obviously capped at one fine for the whole campaign.

Per-violation exposure, not a flat fine

Maximum penalty per individual violation under each statute (not an aggregate cap)

TCPA, willful (treble)
$1,500
TCPA, standard
$500
Utah, order violation
$5,000
Utah, administrative/court
$2,500

Sources: Utah Code 13-75-105 (S.B. 226, 2025); 47 U.S.C. § 227(b)(3). Fetched October 2026. Figures are per individual violation, not an aggregate or campaign-level cap.

Run the Utah figures against a realistic lead list to see why “per violation” is the operative phrase. An agency running an AI text sequence that never discloses AI use against a thousand-contact list isn’t automatically looking at one $2,500 fine for the whole campaign — read literally, each contact that violated the statute is its own violation, which is how a sloppy script scales from a four-figure problem to something far larger before a single letter from the Division of Consumer Protection arrives. That’s a hypothetical built from the statute’s own per-violation structure, not a claim that any specific enforcement action has happened at that scale — but it’s the math worth doing before assuming a fine “wouldn’t really add up to much.”

The TCPA side is the one with an actual enforcement track record behind it. Because the FCC’s 2024 ruling treats an AI-generated voice as an “artificial” voice under the statute, a call placed without the called party’s prior express consent exposes the caller to a private right of action: the called party can sue for actual monetary loss or $500 in statutory damages per violation, whichever is greater, and a court can increase that award up to three times — $1,500 per violation — if the violation was willful or knowing (47 U.S.C. § 227(b)(3)). That’s per call. A voicebot calling a list of 500 leads without documented consent isn’t one violation if something goes wrong; depending on the facts, it can be read as up to 500.

How to fix it: the state-by-state rules and the one script that clears all of them

Nothing below requires a membership, a developer, or anything beyond a text editor. This is the complete manual method, not a preview of a paid version.

Step 1: Know which rule actually governs your setup

Infographic titled Which AI Disclosure Rule Applies, showing three columns: Utah with a chat bubble icon labeled if asked admit it is AI and consumer transaction law, Colorado with a document icon labeled notice up front and effective January 1 2027, and Federal TCPA with a phone icon labeled AI voice equals artificial voice and consent required for calls

Which AI disclosure rule applies, by channel and state
Your setup Governing rule What it requires
AI chat or text, lead based in Utah Utah Code 13-75-103(1) Must truthfully confirm it's AI if the lead asks — reactive duty, no proactive script required for insurance specifically
AI chat or text, lead based in Colorado, used to triage or pre-qualify (a "consequential decision") Colorado SB26-189, effective Jan. 1, 2027 Clear and conspicuous notice at the point of interaction that it's an AI system
AI-generated voice on an outbound or follow-up call, any state TCPA, per FCC Declaratory Ruling FCC-24-17 Prior express consent before the call, same as any artificial or prerecorded voice call
How your agency governs and supervises any AI tool touching clients NAIC AI Model Bulletin (adopted in 26 jurisdictions as of Aug. 31, 2026) Written AI governance policy a regulator could request — not a consumer-facing script

For Colorado specifically, the harder judgment call is deciding whether your bot is making a “consequential decision” at all. A chatbot that only books an appointment or answers an FAQ about office hours is doing something closer to scheduling than deciding. A bot that pre-qualifies a lead, recommends a specific plan type, or tells someone they likely do or don’t qualify for a subsidy is shaping an outcome that affects the person’s access to or cost of insurance — squarely inside the statute’s own list of consequential-decision domains. When a tool sits in that gray area, the safer read is to treat it as covered rather than find out otherwise after January 1, 2027.

The practical read: if you only sell in a handful of states and none of them are Utah or Colorado, you’re not off the hook — you’re just not yet bound by a state-specific chatbot law. You’re still bound by the federal TCPA rule the moment a synthetic voice touches a phone call, and you’re still the one who has to answer honestly if any lead, anywhere, asks whether they’re talking to a bot, because several more states have similar bills moving through committee this session and a script built state-by-state is a script you’ll be rewriting every few months.

Step 2: Write one disclosure line that satisfies the strictest version of every rule

Rather than maintaining a different script per state, write to Colorado’s “point of interaction” standard, since it’s the strictest trigger of the three (upfront, not reactive) and layer in the voice-specific consent language for calls:

For chat or text, at the very first message:

“Hi, this is an AI assistant for [Agency Name]. I can help you get started, answer quick questions, or connect you with a licensed agent — just ask, and I’ll always tell you straight whether you’re talking with AI or a person.”

For an AI-generated voice call, at the start of the call, before anything else:

“Hi, this is an AI assistant calling on behalf of [Agency Name] about the information you requested. If you’d rather speak with a licensed agent directly, just say so.”

Both lines do three things at once: they satisfy Colorado’s point-of-interaction notice requirement before it’s even legally required, they automatically satisfy Utah’s reactive if-asked duty because the answer is already given, and the voice version doubles as the kind of up-front identification that keeps a consent-based TCPA call defensible instead of ambiguous. Build it into the first message of every sequence and the first line of every script, and the “wait, am I talking to a real person?” moment from the opening of this article never happens, because the lead already knows.

A disclaimer buried in a privacy policy is not disclosure

Colorado's standard is "clear and conspicuous notice... at the point of interaction," and Utah's proactive standard (for the occupations it covers) requires disclosure delivered verbally at the start of a verbal interaction or in writing before a written one. A sentence in a website's terms of service, a tiny "AI" badge a lead has to notice on their own, or a disclosure mentioned three messages into a thread doesn't meet either bar. Put it first, in the message itself.

If any part of your follow-up stack places outbound calls using a synthetic or AI-cloned voice, confirm you have the same prior express consent you’d need for a prerecorded message before the FCC’s 2024 ruling existed — a checked box, a signed form, or a clearly disclosed opt-in that names the specific number being called, not an assumption that a lead who filled out a web form implicitly agreed to an AI phone call. This is the exact gap the FCC’s ruling closed: tools marketed as “AI voice agents” aren’t a new unregulated category just because the voice isn’t a recording of a specific human being.

Step 4: Keep a record of what every lead was actually told

Save the exact script version that was live on the date each lead was contacted, not just the current one. If a complaint or inquiry comes in six months later, “here’s exactly what the bot said and when” is a materially stronger position than “we’re pretty sure it said something like that.” A simple dated folder of script versions, or a CRM note logging which template fired on which date, does this with zero additional tooling.

A test you can run this week

Open your AI texting or chat tool right now and type "are you a real person?" as if you were a lead. Read exactly what comes back. If it dodges the question, changes the subject, or answers something adjacent instead of a straight yes-or-no, that's the gap to fix today — before a real lead finds it first.

Everything above works whether you ever touch Ambrose or join anything. It’s four scripts and a filing habit, not a purchase.

How Ambrose’s reply-bot and channel-bridge spokes build the disclosure in instead of hoping someone remembers it

The manual version works, and it also depends entirely on every teammate who edits a bot template remembering to leave the disclosure line in. That’s the exact failure mode Ambrose’s review-first design is built around. The reply-bot spoke, documented as drafting AI-generated responses across email, SMS, and chat channels, defaults to a per-team “needs-review” setting rather than auto-send — Ambrose’s own documentation puts it as “Auto-send vs needs-review is a per-team toggle. Default = needs-review” — and pairs every draft with a confidence score and a “why this draft” trace so whoever approves it can actually see the reasoning, not just the output (Ambrose docs, spoke-reply-bot, fetched October 2026). Its three tools are reply_draft (generates the candidate response), reply_send (dispatches an approved draft through channel-bridge), and reply_book_appointment (schedules the follow-up meeting).

The channel-bridge spoke is the actual outbound dispatcher underneath it — “the single place messages actually leave your account,” exposing bridge_send_email and bridge_send_sms, and it runs in drafts mode by default too, holding messages for review until auto-send is deliberately turned on at the agent or team level (Ambrose docs, spoke-channel-bridge, fetched October 2026). Outbound message bodies route through the PHI Gateway automatically whenever the destination isn’t on the agency’s BAA allowlist, which matters here specifically because a lead’s question about whether they’re “talking to a real person” often arrives in the same thread where they’ve also shared a health condition or a Medicare number.

Manual workflow

The four-step method from this article

  • You write the disclosure line into every template by hand
  • Every teammate who edits a script has to remember to keep it
  • You manually log which script version was live on which date
  • Works today, in any texting tool, at zero cost
Ambrose reply-bot + channel-bridge

The same disclosure, built into a reviewed draft

  • reply_draft generates the response; a human approves before reply_send fires it
  • needs-review is the default, not an opt-in setting you have to remember
  • Every scrub event and send is logged with a timestamp for later review
  • Non-BAA destinations route through the PHI Gateway automatically

Be precise about what this is and isn’t. Neither spoke knows, on its own, that Colorado requires upfront notice while Utah’s is reactive — that judgment, and writing the actual disclosure line into the template, is still yours to make, the same as it is in the manual version. What the needs-review default removes is the mechanical failure mode: a teammate editing a script at 11pm and accidentally deleting the one sentence that matters, with nobody catching it until a lead asks the wrong question to the wrong bot in the wrong state.

What you get by joining

One Ambrose seat comes with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, founding rate locked in while the membership stays active. That includes weekly Zoom calls with open Q&A and build-with-you sessions, 30-plus hours of recorded training, pre-built AI templates and bot deployments, Meta Ads and marketing training built for this industry specifically, and a free annual in-person member workshop — plus an explicit no-recruiting rule, so a question about getting your disclosure line right doesn’t turn into someone else’s downline pitch.

Ambrose usage is separate from the $97 seat

The membership includes one Ambrose seat; usage inside Ambrose runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise. See the full Spokes catalog for what reply-bot and channel-bridge sit alongside.

Know which rule actually applies

Utah's reactive duty, Colorado's upfront duty, and the federal voice rule aren't the same rule.

One script, not fifty

Write to the strictest standard and it clears the rest automatically.

Consent before an AI voice ever dials

The FCC already treats a synthetic voice as an artificial voice under the TCPA.

Keep a dated record

Know exactly what every lead was told, and when.

A reviewed draft, not a blind auto-send

reply-bot and channel-bridge both default to human review before anything fires.

A logged audit trail

PHI Gateway routing and scrub-event logging back up what you can show a regulator.

Stop guessing which disclosure rule applies

The manual script above works whether you ever join anything or not. If you'd rather have it built into a reviewed draft on your own follow-up stack, with someone watching your screen while you set it up, one Ambrose seat comes with the Tech Savvy membership.

Join Tech Savvy — $97/month

The close

A lead who asks whether they’re talking to AI deserves a straight answer, and getting there is one sentence written into a template, not a legal overhaul. Write it to the strictest standard you’re subject to, put it first instead of burying it, get documented consent before any synthetic voice dials out, and keep a dated record of what every version actually said. If you’d rather have that built into a reviewed draft instead of a template everyone has to remember to protect, that’s the kind of thing we work through on a Tuesday call in the Tech Savvy community — $97 a month, cancel anytime, and nobody will pitch you a downline: https://techsavvyinsurance.com/.

Before you change your AI disclosure scripts

Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. Whether a specific script, call flow, or state law applies to your exact setup is a judgment call you and, where appropriate, your own counsel need to make. You are responsible for your own licensure and for complying with all applicable CMS, HIPAA, TCPA, state, and carrier requirements. When Medicare marketing is involved, your TPMO disclaimer obligations and CMS's marketing rules still apply on top of everything in this article. Never paste a client's protected health information into a general-purpose AI tool without a Business Associate Agreement in place — that's exactly the gap Ambrose's PHI Rail is built to close. AI outputs may contain errors — always verify. Results may vary.

Frequently asked questions

It depends on where the lead lives and what the bot is doing, and the patchwork is real. Under federal law, if you're placing an AI-generated voice on a call, the FCC's 2024 declaratory ruling already treats that voice as an "artificial" voice under the TCPA, which triggers the TCPA's consent and identification rules the same as any prerecorded call (FCC, Declaratory Ruling FCC-24-17, released Feb. 8, 2024). For text and chat, Utah requires any business using generative AI in a consumer transaction to admit it's AI the moment a person asks (Utah Code 13-75-103(1), effective May 7, 2025), and Colorado's rewritten AI law requires a "clear and conspicuous notice to consumers at the point of interaction" for AI systems used in a list of consequential decisions that explicitly names insurance, effective January 1, 2027 (Colorado SB26-189, leg.colorado.gov). There is no single federal chatbot-disclosure law yet, which is exactly why a script that only satisfies one state is a liability everywhere else.
Two different duties, and most agents only know about one. Utah Code 13-75-103(1) gives every business a reactive duty: if a person directly asks whether they're talking to AI, you have to tell them the truth. Separately, 13-75-103(2) gives a stricter, proactive duty — prominent disclosure up front, verbally at the start of a call or in writing before a text or chat exchange — but only to "regulated occupations," defined in 13-75-101(8) as occupations regulated by Utah's Department of Commerce. Insurance producers in Utah are licensed and regulated by the Insurance Department, a separate agency created under Utah Code 31A-2-101, not the Department of Commerce — so the proactive, upfront-disclosure duty does not apply to insurance sales there. The reactive, if-asked duty under 13-75-103(1) still does, because it applies to any "supplier" in a "consumer transaction," insurance included.
Not yet, and the timeline has moved twice. The original Colorado AI Act (SB24-205) was signed in May 2024 with a February 2026 start date, then delayed to June 30, 2026, then replaced entirely by SB26-189, which repeals and reenacts the law around "automated decision-making technology" (ADMT) with an operative date of January 1, 2027 (Colorado General Assembly, SB26-189 bill page). When it takes effect, it requires deployers to give consumers "clear and conspicuous notice" at the point of interaction with a covered ADMT used in a "consequential decision," and insurance is one of the decision categories the statute names outright.
Not illegal outright, but they're regulated the same as any prerecorded or artificial-voice call under the TCPA, and that's a meaningful difference from how a lot of agencies have been treating AI voice tools. The FCC's February 2024 declaratory ruling confirmed that an AI-generated voice is an "artificial" voice for TCPA purposes, which means the call needs the called party's prior express consent before it goes out (FCC, Declaratory Ruling FCC-24-17, Feb. 8, 2024). Calling or texting without that consent exposes you to the TCPA's private right of action: actual damages or $500 per violation, whichever is greater, which a court can increase to as much as $1,500 per violation for a willful or knowing violation (47 U.S.C. § 227(b)(3)).
The NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023, is governance guidance rather than a consumer-facing disclosure statute — it sets the expectation that a licensed insurer maintain a written AI program with documented testing, human oversight, and vendor accountability, which state insurance regulators can request to see during an exam. As of August 31, 2026, 26 jurisdictions — 25 states plus the District of Columbia — have adopted some version of it (NAIC, Legal Adoption Map: AI Model Bulletin, status as of Aug. 31, 2026). It doesn't tell you what to say to a lead on a chat widget. It does mean your agency should be able to produce a written policy on how AI is used and supervised if your state's insurance department ever asks.
Write to the strictest rule you're subject to rather than maintaining fifty scripts. A disclosure that's clear and conspicuous at the very start of the interaction, in writing for a chat or text thread and spoken aloud at the start of a call, satisfies Colorado's point-of-interaction standard, Utah's if-asked standard automatically, and gives you a defensible answer if a client later says they didn't know. Something close to: "Hi, this is an AI assistant for [Agency Name] — I can help you get started or connect you with a licensed agent. Just ask, and I'll always tell you when you're talking with AI versus a person." That one line, used every time, is the full manual method this article walks through.
Ambrose doesn't have a one-click "add legal disclosure" button, and this article isn't going to claim one exists. What its documentation confirms: the reply-bot spoke defaults to "needs-review" rather than auto-send, pairing each AI-drafted reply with a confidence score and a "why this draft" trace so a human sees the exact wording before it goes out (Ambrose docs, spoke-reply-bot, fetched October 2026); the channel-bridge spoke is the single place outbound messages actually leave the account, and it runs in drafts mode by default too (Ambrose docs, spoke-channel-bridge, fetched October 2026). That human-review step is where an agent builds the disclosure line into the template once, instead of trusting an autonomous bot to remember it on every send.
It varies by which rule you tripped. Utah's Division of Consumer Protection can impose an administrative fine of up to $2,500 per violation, a court can impose a separate fine of up to $2,500 per violation in an enforcement action, and violating an order already issued under the statute carries a civil penalty of up to $5,000 per violation (Utah Code 13-75-105(4)-(7), enacted by S.B. 226, 2025). On the federal voice side, an undisclosed AI-generated call made without consent is a TCPA violation exposing you to $500 to $1,500 per call under the private right of action in 47 U.S.C. § 227(b)(3). None of these are one-time fines — they're per-violation, which turns a sloppy bot script running against a whole lead list into a real number fast.

Sources

  1. Utah S.B. 226 (2025), enrolled — enacts Utah Code 13-75-101 through 13-75-106 — le.utah.gov
  2. Utah Code 31A-2-101 — General duties (The Insurance Department) — le.utah.gov
  3. Colorado General Assembly — SB26-189 bill page — leg.colorado.gov
  4. FCC — Declaratory Ruling FCC-24-17, AI-Generated Voices in Robocalls (released Feb. 8, 2024) — fcc.gov
  5. 47 U.S.C. § 227(b)(3) — Telephone Consumer Protection Act, private right of action — law.cornell.edu
  6. NAIC — Legal Adoption Map: Model Bulletin, Use of Artificial Intelligence Systems by Insurers (status as of Aug. 31, 2026) — content.naic.org
  7. Ambrose docs — spoke-reply-bot — app.hiambrose.com
  8. Ambrose docs — spoke-channel-bridge — app.hiambrose.com
  9. Ambrose docs — PHI Rail architecture — app.hiambrose.com

Ready to put this into practice?

Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.

Join Tech Savvy — $97/month