If you’re a Texas-licensed Health or Life agent and someone in your FMO group chat told you TDI now makes you attest to your AI use on renewal, that’s wrong, and the actual bulletin explains why. Texas Department of Insurance Bulletin B-0003-26, issued June 12, 2026, sets expectations for how “regulated entities and their agents and representatives” govern the use of artificial intelligence (TDI, B-0003-26). It asks for human review of consequential AI decisions, a governance framework, and documentation TDI can request during an exam. It does not create a renewal attestation, a new CE requirement, or a specific penalty schedule. This article walks through exactly what the bulletin says, why the misinformation about it took hold, how Texas’s approach differs from the 25 jurisdictions that adopted the NAIC’s model bulletin instead, and how to build a real, one-page AI governance policy this week.
Key takeaways
- TDI Bulletin B-0003-26 (issued June 12, 2026) applies to "all regulated entities and their agents and representatives" — Texas agents are named, not exempt.
- There is no renewal-application AI attestation in the bulletin, and TDI's own agent continuing-education page has no AI-specific CE requirement either.
- Texas has never adopted the NAIC's Model AI Bulletin. Per NAIC's own April 1, 2026 map, Texas is 1 of just 4 jurisdictions (with California, Colorado, and New York) running its own framework instead.
- Texas now has two AI-adjacent bulletins: B-0036-20 (2020, third-party data accuracy) and B-0003-26 (2026, AI-specific governance and human review).
- Ambrose's War Room includes a dedicated Compliance persona, Dr. Elena Reyes, you can ask directly, with every run logged, which is exactly the documentation trail TDI's bulletin describes.
What Texas Bulletin B-0003-26 actually says
B-0003-26 is a short bulletin with a specific ask: Texas-regulated entities, and the agents and representatives who work with them, are expected to make sure AI-assisted decisions comply with existing insurance law, put controls in place that reduce the risk of bad outcomes for consumers, and be ready to describe those controls to TDI on request (TDI, B-0003-26). Issued June 12, 2026 and last updated on TDI’s site July 16, 2026, it’s the first bulletin on TDI’s current bulletin index to name artificial intelligence specifically.
Four things stand out once you read the actual text instead of a summary of a summary:
It names agents directly. The bulletin’s scope isn’t “insurance companies.” It’s “all regulated entities and their agents and representatives,” with expectations that “extend to any third party working with a regulated entity.” If you’re a Texas producer using an AI tool in carrier-facing work, underwriting-adjacent quoting, claims-adjacent communication, or marketing a carrier’s product, you’re inside this bulletin’s scope, not outside it.
It asks for a human in the loop on consequential decisions. TDI expects “a person to review and agree with all decisions before action is taken” where an AI system is driving something that matters to a consumer. That’s the same principle every state and federal AI framework converges on in 2026: the AI can draft, sort, and recommend, but a person signs off before it acts on a consumer.
It doesn’t hand you a template. Unlike the NAIC’s model bulletin, which spells out a formal written program with numbered sections (more on that below), B-0003-26 states expectations, governance frameworks, risk management, data and privacy protections, internal controls, without prescribing a specific document format. TDI says it will monitor AI use “through examinations and product filings,” and it isn’t asking for a particular form to fill out. It’s asking you to be able to describe what you actually do.
It doesn’t create new penalties. The bulletin doesn’t introduce a fine schedule. It states that nothing in it limits TDI’s existing authority to “conduct any regulatory investigation, examination, or enforcement action” under current law. The exposure isn’t a new AI-specific fine. It’s that your existing unfair-trade-practice and market-conduct obligations now explicitly cover how you use AI, and TDI has told you it’s watching.
This is guidance about compliance obligations, not compliance advice
Tech Savvy Insurance is a training and software community, not a law firm or an insurance agency. This article describes what a public regulatory bulletin says. It is not legal advice about how the bulletin applies to your specific book of business, and you should read the primary source yourself and talk to your own compliance counsel or carrier compliance department before changing anything based on it.
The rumor: no, TDI did not add an AI attestation to your renewal
Here’s the version of this that’s actually been showing up in Texas agent group chats and a few AI-generated compliance-calendar posts: that B-0003-26 requires an “AI use attestation” on your license renewal application. It’s a specific, confident-sounding claim, and it doesn’t appear anywhere in the bulletin.
Fetching the bulletin directly from tdi.texas.gov turns up governance language, human-review language, and examination language. It does not turn up an attestation requirement, a new form, or a renewal-cycle checkbox. A separate check of TDI’s own agent continuing-education page shows the same thing: no mention of AI, no AI-specific CE hours, and no tie between AI use and license renewal (TDI, Agent Continuing Education).
This is worth naming directly because it’s a textbook case of the exact trap this site’s sourcing standard exists to catch: a plausible-sounding compliance claim, repeated confidently enough in enough places, that nobody traces back to the actual document. The fix is the same one that applies to every circulating industry statistic. Open the primary source yourself. If a claim about a specific requirement doesn’t show up in the bulletin’s own text, it isn’t a requirement, no matter how many times you’ve seen it repeated.
Where the misinformation likely started
AI search summaries and a handful of compliance-calendar sites have circulated the "renewal attestation" claim without linking the actual bulletin text. It's a plausible-sounding detail for a bulletin that genuinely is about AI, which is exactly what makes it spread. This article traces every claim back to tdi.texas.gov and content.naic.org directly rather than to a secondhand summary.
That doesn’t mean there’s nothing here. It means the actual requirement, human review of consequential AI decisions and a governance framework you can describe on request, is less dramatic than a renewal attestation, but it’s real, and it does reach agents. The rest of this article is about that real requirement.
Why Texas now has two AI-adjacent bulletins, not one
Texas didn’t wake up to AI in insurance in June 2026. TDI issued a bulletin on data accuracy back on September 30, 2020, Bulletin B-0036-20, which put insurers on notice that they remain accountable for the accuracy of data used in rating, underwriting, and claims handling, even when a third party supplied that data, and warned of enforcement action if inaccurate third-party data hurts a policyholder (TDI, B-0036-20). That bulletin doesn’t use the word “AI.” It’s about data accuracy and third-party accountability generally, written before generative AI and large-scale predictive models were the industry conversation they are now.
B-0003-26 is the follow-on, six years later, that names AI specifically and adds the governance and human-review expectations the 2020 bulletin didn’t cover. Both are listed on TDI’s own bulletins index, and neither the 2026 table nor B-0003-26’s own text points to an earlier AI-named bulletin between them (TDI, Bulletins index). Put side by side, the two bulletins show a regulator’s stance evolving in real time rather than a single static rule.
| Provision | B-0036-20 (2020) | B-0003-26 (2026) |
|---|---|---|
| Focus | Accuracy of third-party data used in rating, underwriting, and claims | Governance and use of AI systems generally, across the insurance life cycle |
| Who it names | Insurers ("regulated entities") | Regulated entities and their agents and representatives, plus third parties working with them |
| Core ask | Remain accountable for data accuracy even if a third party supplied it | Human review of consequential AI decisions; a governance framework you can describe on request |
| Prescribed format | None stated | None stated — expectations, not a template |
| Enforcement mechanism | TDI's existing statutory authority | TDI's existing statutory authority, exercised via exams and product filings |

How Texas compares to the 25 jurisdictions that adopted the NAIC model instead
Most of the country took a different route than Texas. The NAIC (National Association of Insurance Commissioners) adopted its own Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023, as a template individual states could adopt directly, with each state’s insurance department filling in its own name and citations (NAIC, Dec. 4, 2023).
Per the NAIC’s own implementation map, dated April 1, 2026, 24 states plus the District of Columbia, 25 jurisdictions total, have adopted that model bulletin more or less as written, starting with Alaska in February 2024 and, as of the map’s date, most recently Hawaii in December 2025 (NAIC, implementation map, Apr. 1, 2026). Four jurisdictions instead run their own insurance-specific AI or algorithmic-data regulation: California (Bulletin 2022-5, issued June 30, 2022), Colorado (3 CCR 702-10, effective November 13, 2023, with amendments effective October 15, 2025), New York (Insurance Circular Letter No. 7, issued July 11, 2024), and Texas (Bulletin B-0036-20, issued September 30, 2020, per the same NAIC map). That leaves 22 states, per the same map, with no formal AI-specific insurance bulletin or regulation on the books yet.
How the 50 states plus D.C. regulate insurer AI, as of April 1, 2026
51 jurisdictions total.
Source: NAIC, Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers, status as of April 1, 2026.

Worth being precise about the NAIC map’s own caveat here: it notes that it “represents state action or pending state action addressing the topic of the model” and doesn’t determine whether a state’s actual rule contains every element of the model bulletin. Texas landing in the “own framework” column doesn’t mean B-0036-20 and B-0003-26 together equal the NAIC’s model word for word. It means Texas chose its own path rather than adopting NAIC’s language, and the map is current as of a date before B-0003-26 even existed, since B-0003-26 wasn’t issued until June 12, 2026.
| State | Its own framework | Issued / effective |
|---|---|---|
| California | Bulletin 2022-5 | Issued June 30, 2022 |
| Colorado | 3 CCR 702-10 (implementing SB 21-169) | Effective Nov. 13, 2023; amended Oct. 15, 2025 |
| New York | Insurance Circular Letter No. 7 | Issued July 11, 2024 |
| Texas | Bulletin B-0036-20, now paired with B-0003-26 | Issued Sept. 30, 2020; B-0003-26 added June 12, 2026 |
Colorado is worth a closer look because it’s the most prescriptive of the four. Its underlying law, SB 21-169, “Restrict Insurers’ Use of External Consumer Data,” signed July 6, 2021, bars insurers from using external data, algorithms, or predictive models that unfairly discriminate against consumers based on protected characteristics, and requires insurers to disclose the external data sources behind their algorithms, run a documented risk-management assessment, and have their chief risk officer attest to compliance (Colorado General Assembly, SB 21-169). Texas hasn’t gone that far. B-0003-26 asks for governance and human review; it doesn’t require a CRO attestation or a specific risk-assessment filing the way Colorado’s regulation does. That gap is exactly why a Texas agent shouldn’t assume “my state didn’t adopt the strict NAIC model” means “my state doesn’t regulate this at all.” It means Texas regulates it its own, shorter way, and the bar can move.
What it actually costs you to get this wrong
There’s no dollar figure to print here, and this site doesn’t invent one where none exists. B-0003-26 doesn’t carry a stated fine schedule, so there’s no “$X per violation” number to cite honestly. The real cost is different, and it’s worth being precise about it rather than reaching for a scarier number that isn’t sourced.
The bulletin states plainly that TDI will monitor AI use “through examinations and product filings,” and that nothing in the bulletin limits its existing authority to investigate, examine, or take enforcement action under current law. That’s the mechanism. If you’re using AI in carrier-facing work, quoting, marketing, underwriting-adjacent communication, and an exam or a filing review asks how that AI use is governed, “we don’t have anything written down” is a materially worse answer than a one-page policy you can hand over. The exposure isn’t a new AI-specific penalty. It’s your existing unfair-trade-practice and market-conduct obligations, the same ones that have always applied to how you handle a consumer’s information and a carrier’s product, now explicitly extended to cover AI-assisted work, with a regulator on record saying it’s paying attention.
There’s a second, quieter cost: getting spooked by the misinformation and either ignoring AI entirely, and falling behind agents who use it well, or dismissing the whole bulletin as noise because the one claim you heard about it (the renewal attestation) turned out to be false. Both reactions throw out a real, if modest, requirement along with a fake one. The accurate read is narrower and more useful than either extreme: there’s a real human-review and governance expectation that reaches you as an agent, it’s not hard to satisfy, and it isn’t the dramatic thing the rumor made it sound like.
The bulletin that actually exists is smaller and more reasonable than the rumor about it. That's usually true, and it's exactly why reading the primary source instead of the group chat is worth five minutes.
Mike MooreThe manual method: build a one-page AI governance policy this week
None of what follows requires software, a membership, or a compliance department. B-0003-26 doesn’t hand you a template, so borrow the most thoroughly worked one that exists: the NAIC’s Model Bulletin, even though Texas hasn’t adopted it. The NAIC’s full text lays out a written “AIS Program” (AI Systems Program) with specific elements (NAIC, Model Bulletin full text, adopted Dec. 4, 2023), and those elements map directly onto what B-0003-26 asks for in plainer language. Here’s how to build your own version in an afternoon.
Name an owner
The NAIC's language is "senior management accountable to the board." For a solo agent or small shop, that's just you, in writing: "I am responsible for how AI is used in this agency." One sentence, and it's the first thing an exam looks for.
Write down what AI may and may not do
One page. AI may draft client communications, qualify leads, summarize plan documents, and schedule. AI may not send client communication unreviewed, make a coverage recommendation, or submit an application without your review. This single page is most of what "governance" means in practice.
Put a human on every consequential decision
This is the literal ask in B-0003-26: "a person to review and agree with all decisions before action is taken." Anything that reaches a consumer, a quote, a plan comparison, a marketing message, gets a human read before it goes out. Say so in your one-pager.
Log what you did
The NAIC's documentation requirement is "requirements adopted by the Insurer to document compliance with the AIS Program." For a small agency, that can be as simple as a dated note each time you review your AI-drafted materials, or a folder of "reviewed and approved" copies. It doesn't need to be fancy. It needs to exist.
Check your AI vendors like any other vendor
The NAIC bulletin calls this "due diligence" on third-party AI systems and data. In practice: know what tool you're using, whether it's built for insurance or a general consumer product, and whether the vendor can tell you how it handles client data. A vendor who can't answer that isn't a vendor to build your governance around.
Revisit it when the rules move
Texas added B-0003-26 six years after B-0036-20. The NAIC's map changes every few months as more states act. Put a reminder on your calendar, quarterly is enough for most small agencies, to check tdi.texas.gov's bulletin index and the NAIC's own map for changes.
What most agencies have today
Nothing written down. AI tools adopted one at a time, whichever agent liked the demo. No one could name who "owns" AI governance in the shop, and no record exists of anyone reviewing what the AI drafted before it went to a client.
What B-0003-26 is actually asking for
A one-page written policy naming an owner, a human-review step before anything reaches a consumer, a simple log of that review, and a short answer for what AI tools you use and whether their vendors can speak to how they handle data.
This is the whole method
Name an owner, write the one-pager, keep a human in the loop, log the review, check your vendors, and set a quarterly reminder. That's a genuinely complete, defensible answer to "how do you govern AI in this agency," and it costs nothing but the afternoon it takes to write it.
A worked example: applying the one-pager to a real Texas scenario
Abstract policy language is easy to nod along to and hard to actually picture in your own agency. Here’s the concrete version, using a scenario that’s common for a Texas Health agent in 2026: you use an AI tool to draft outbound marketing messages and to help summarize plan documents for prospects.
Start with the ownership line. If you’re a solo agent, that’s you: write “I am the person responsible for how AI tools are used in this agency, including reviewing anything they draft before it reaches a client.” If you have a small team, name the specific person, not “the team,” the same way TDI’s bulletin expects a regulated entity to be able to name who’s accountable.
Next, the one-page scope. Write down, specifically, what the AI tool is allowed to do in your shop: draft an outbound message, summarize a plan document’s benefits into plain language, suggest talking points for a follow-up call. Then write down what it isn’t allowed to do: send a message without your review, state a plan’s coverage details without you checking them against the plan document, or make an eligibility or suitability recommendation. This is the exact distinction B-0003-26’s human-review language is getting at, “a person to review and agree with all decisions before action is taken.”
Now put the review step into your actual workflow, not just your policy document. Before an AI-drafted marketing message goes out, you read it, check it against the plan’s actual benefits and against your compliance obligations, and either approve it or edit it. That review is the part regulators actually want to see evidence of, not a document sitting in a drawer.
Then log it. The simplest version that satisfies the NAIC’s “documentation requirements” language, borrowed here as the more detailed template, is a dated note: “Reviewed and approved outbound message X on [date].” A shared folder of approved copies with dates works. A spreadsheet with one row per review works. The format doesn’t matter. Having something to show, instead of nothing, is the entire point.
Finally, check the tool itself. If you’re using a general-purpose AI chatbot with no insurance-specific guardrails, that’s a due-diligence gap under the NAIC’s third-party framework, and arguably under B-0003-26’s own governance language, since the bulletin’s expectations “extend to any third party working with a regulated entity.” A tool built for insurance, with your industry’s marketing rules and disclosure requirements already baked into what it drafts, closes that gap by design instead of by remembering to check it every time.
That’s the whole worked example. None of it required buying anything. It required about the same amount of time as writing a single client email, and it produces a policy that actually answers the question an exam or a filing review would ask.
If you sell Medicare in Texas: this stacks with CMS’s rules, it doesn’t replace them
B-0003-26 is a state insurance-regulator bulletin about AI governance. It is not a Medicare marketing rule, and it doesn’t touch, relax, or replace the federal rules that already govern how you market Medicare Advantage, Part D, or Medicare Supplement plans in Texas. If you’re using an AI tool anywhere in your Medicare marketing funnel, drafting scripts, running an AI voice or chat intake, generating follow-up messages, you’re stacking two separate compliance layers, not choosing between them.
The federal layer doesn’t move because a state bulletin exists. Any AI-assisted call or communication that markets specific Medicare plan benefits still has to open with the required Third-Party Marketing Organization (TPMO) disclaimer, still has to be handled under the CMS Medicare Communications and Marketing Guidelines, and still requires the licensed agent, not the AI tool, to own the recommendation and the sale. An AI system can qualify a lead, draft a follow-up, and log the interaction. It cannot be the thing that decided what plan to recommend, and it cannot skip the disclaimer because a human didn’t remember to add it to the prompt.
Practically, that means your one-page AI policy for a Texas Medicare book needs two review gates, not one: the state-level gate this article walks through (human review, documentation, vendor diligence) and the federal gate that’s always applied to Medicare marketing regardless of AI (TPMO disclaimer present, call recorded and retained, licensed agent owns the enrollment). We cover the federal layer in far more depth, TPMO specifics, CMS retention rules, and the liability question, in our guide to AI compliance for insurance agents in 2026. Treat B-0003-26 as an addition to that existing obligation, not a replacement for any part of it.
How Ambrose’s War Room Compliance persona handles this
Everything above works with a blank document and no membership. Where a tool actually helps is having someone to ask when a specific question comes up, “does this outbound message hold up,” “is this vendor’s data handling actually documented,” without waiting for your next call with counsel.
Inside Ambrose OS, the War Room is a chat surface for a fixed roster of nine executive AI personas: type a question, and Ambrose decides which head answers, or convenes a small group, and synthesizes a response in your agency’s own voice (Ambrose docs, War Room). One of those nine is Dr. Elena Reyes, the Compliance persona, alongside a Chief of Staff and named CMO, COO, CCO, CFO, CRO, CTO, and Research roles (Ambrose docs, What is Ambrose). You can ask her directly, in plain English, whether a piece of client-facing language or a workflow decision holds up, the same first-pass check a governance-minded agency would want before anything reaches a consumer. The War Room’s own documentation shows an expandable tool-call timeline and contributor attribution on every answer, which is itself a form of the run-level record that B-0003-26’s “documentation you can produce on request” language describes.
That’s not a substitute for your own judgment, your carrier’s compliance department, or actual legal counsel, and this article isn’t claiming otherwise. What it replaces is the manual version of the same job: you, alone, trying to remember whether a specific piece of outbound copy or a specific AI-assisted workflow decision is one you already reviewed and approved, with nothing written down if you didn’t.
The other half of this is data handling. Every read and write inside Ambrose is scoped to the agency’s own tenant (Ambrose docs, Architecture), and Ambrose’s PHI Rail checks whether a destination is on the agency’s BAA allowlist before a prompt reaches it: if it is, the request passes through; if it isn’t, the PHI Gateway scrubs identifiers into typed aliases first and re-hydrates the real values on the response, using the original hydration map (Ambrose docs, PHI Rail architecture). We describe that as HIPAA-aware by default, not a HIPAA certification, because no AI vendor should claim to be “HIPAA certified,” and Tech Savvy doesn’t make that claim on Ambrose’s behalf either. What it means practically is that the “don’t paste a client’s health detail into a general AI tool” rule from the FAQ above is the default behavior inside Ambrose, not a discipline you have to remember to apply every time.
Name the mechanism, not just "AI"
The specific thing worth naming here is the War Room's Compliance persona and the run-level record it leaves behind, not a general claim that "AI helps with compliance." A generic chatbot doesn't know what B-0003-26 says or who your agency's designated owner is. A persona built for this, inside a system scoped to your own tenant, does.
What you get by joining
One Ambrose seat, including War Room access and the Compliance persona referenced above, comes included with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, with the founding rate locked in while the membership stays active. Ambrose usage itself runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, more than 30 hours of recorded training, Meta Ads and marketing training built for this industry, pre-built AI templates and bot deployments, and a free annual in-person member workshop. It’s also an explicit no-recruiting zone, you can ask a real compliance question without ending up on someone’s downline pitch list an hour later, which isn’t true of most agent Facebook groups.
Close
Read the actual bulletin before you believe the version of it that’s circulating: TDI’s B-0003-26 asks Texas agents and the carriers they work with for human review of consequential AI decisions and a governance framework you can describe on request, not a renewal attestation. Build the one-page policy above this week, whether or not you ever join anything, name an owner, write down what AI may and may not do, keep a human on every consumer-facing decision, and log it. If you’d rather have a Compliance persona to run that same question by, with people building the same policy alongside you on a Tuesday call, one Ambrose seat comes with a Tech Savvy membership: https://techsavvyinsurance.com/. See also our guide on AI compliance for insurance agents in 2026 for the national NAIC picture, and our pillar guide on AI for insurance agents in 2026.
Before you act on any of this
Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. You are responsible for your own licensure and for complying with all applicable TDI, NAIC-derived state, CMS, HIPAA, and carrier rules, including TPMO disclaimer and Medicare marketing requirements where they apply. AI-generated outputs may contain errors, always verify against the current primary source, including reading B-0003-26 yourself at tdi.texas.gov, before changing anything based on this article. Results may vary.
Frequently asked questions
Sources
- Texas Department of Insurance — Bulletin B-0003-26, Use of Artificial Intelligence (June 12, 2026) — tdi.texas.gov
- Texas Department of Insurance — Bulletins index — tdi.texas.gov
- Texas Department of Insurance — Bulletin B-0036-20, Insurers' Use of Third-Party Data (Sept. 30, 2020) — tdi.texas.gov
- Texas Department of Insurance — Agent Continuing Education — tdi.texas.gov
- NAIC — Members Approve Model Bulletin on Use of AI by Insurers (Dec. 4, 2023) — content.naic.org
- NAIC — Model Bulletin: Use of Artificial Intelligence Systems by Insurers (full text, adopted Dec. 4, 2023) — content.naic.org
- NAIC — Implementation of NAIC Model Bulletin: Use of AI Systems by Insurers (status as of Apr. 1, 2026) — content.naic.org
- Colorado General Assembly — SB 21-169, Restrict Insurers' Use of External Consumer Data — leg.colorado.gov
- Ambrose docs — What is Ambrose — app.hiambrose.com
- Ambrose docs — War Room — app.hiambrose.com
- Ambrose docs — System architecture (the Brain, tenant isolation) — app.hiambrose.com
- Ambrose docs — PHI Rail architecture (BAA allowlist, aliasing, rehydration) — app.hiambrose.com
Ready to put this into practice?
Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.
Join Tech Savvy — $97/month