The Claim Under Test
Most published rankings of AI agents for insurance rank products an independent agency cannot buy. That is the claim we set out to test, and it survives contact with the evidence easily. Of the vendors that appear most often in agency-facing roundups, six sell to carriers and only to carriers — Sixfold, Federato, Convr, Gradient AI, Sprout.ai and Agentech. A seventh, EvolutionIQ, stopped being an independent vendor entirely when CCC Intelligent Solutions completed its acquisition on 6 January 2025 for total consideration of $674.3 million, and even before that it was a disability and injury claims product for carriers. If you run a retail agency, an MGA or a wholesale brokerage, a list containing those seven without a word of warning was not written for you. It was written for the search engine.
The second thing most rankings get wrong is subtler and more expensive. They rank on accuracy, deflection rate, straight-through processing percentage and ROI — numbers that are, without exception in this market, published by the seller about itself. There is no neutral referee. We looked at more than twenty vendor sites on 23 August 2026 and found no independent, third-party evaluation of any commercial product in insurance distribution. Meanwhile at least one vendor publishes a section of its site under the heading “Accuracy Benchmarks” about its own products, and another publishes an ROI calculator. Both wear the costume of measurement. Neither is measurement.
So this article does something less exciting and considerably more useful. It scores what an agency principal can verify without a sales call: documented integrations, published compliance artefacts, pricing transparency, ownership from public record, whether the product is locked to a suite, and what the vendor declines to disclose. A documented absence — checked on a stated date, on a named page — is a legitimate table cell, and in several places it is the most informative cell in the row. This sits inside our wider look at the AI agent landscape across categories in 2026, but insurance distribution has a constraint most categories do not, and that constraint drives everything below.
The one sentence that governs every product on this page
An AI agent in an insurance agency may prepare, extract, populate, reconcile, compare and queue — but the moment it sells, solicits or negotiates, a licensed producer has to be the one doing it, because every US state licenses the act, not the actor. No amount of model quality changes that, and any vendor that talks around it is selling you an E&O claim with a subscription attached.
There is a third failure worth naming at the top, because it is the one that quietly wastes the most money: a great deal of what is marketed as agentic in this vertical is document extraction, OCR and robotic process automation with a language model bolted to the front. That is often genuinely useful and often the right purchase — statement reconciliation and loss-run chasing do not need autonomy, they need reliability. But it is not autonomy, and you should not pay autonomy prices or accept autonomy risk for it. In the entries below we say plainly, for every product, whether it is an agent, a copilot or automation, and we use the vendor's own words wherever they are more honest than the category label.
How We Ranked, and What We Refused to Score
We scored only attributes a reader can re-check themselves, from a public page, in an afternoon. Everything in the tables below was verified on 23 August 2026 by direct fetch of primary sources: vendor domains and their own trust, security, pricing and integration pages; NAIC model laws and the NAIC state-adoption tracker; the Federal Register; the Bureau of Labor Statistics public API; uscode.house.gov; the Minnesota Revisor of Statutes; CourtListener; SEC EDGAR full-text search; and a federal court order read in full.
Scored — every one of these is checkable by you
- Documented public integrations: named on the vendor's own integration or documentation page, not implied by a logo wall
- Published compliance artefacts: SOC 2, ISO 27001, a DPA, a trust centre — and precisely what type of report is claimed, since Type I and Type II are different things
- Data residency and retention commitments: stated on a trust page or a DPA, or absent
- Pricing transparency: published, or the literal words not publicly disclosed. We never estimate a price
- Locked to a suite versus standalone: from product documentation
- Ownership and corporate status from public record: SEC filings, court captions, footer legal entities, domain redirects
- Whether any independent evaluation exists: in this vertical the answer was, everywhere we looked, none
- Whether the vendor is honest about autonomy: a vendor that says its product requires human oversight scores better with us than one that implies it does not
Refused outright: accuracy, extraction accuracy, straight-through processing rate, deflection, containment, resolution rate, ROI, time saved, hours returned and quote-speed multiples. Every published figure of that kind in this market is vendor marketing about the vendor's own product. We encountered a great many of them during this research — time-to-quote improvements, productivity boosts, cost cuts, retention rates, deployment counts — and not one came with a methodology, a sample or a denominator. They are attributed to the seller in our notes and printed nowhere.
There is a good reason to hold that line rather than treat it as fussiness, and it is not hypothetical. It is the one occasion a US federal regulator actually audited a vendor's published AI performance metrics.
What happened the one time a regulator checked the numbers
In In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Exchange Act Release No. 102177, Admin. Proc. File No. 3-22413 (14 January 2025), the SEC found that a public company had told investors its drive-thru voice AI delivered “over 94% accuracy even in noisy environments” and 95%–99% “automated order completion.” The order found the product “lacked the capability to take orders on their own and required substantial human involvement,” with “human order takers located abroad (primarily in the Philippines and India), who processed the vast majority of drive-thru orders.”
The framing matters and is frequently mangled. Presto consented without admitting or denying the findings. The remedy was a cease-and-desist order with no civil penalty — it was not a fine. The findings are against Presto only; the order's “Supplier A” is a different company against which the SEC made no findings whatsoever. And Presto Automation Inc. is not Presto Phoenix Inc., which bought assets in December 2024. Read the order itself rather than the coverage of it.
The lesson for an insurance buyer is direct. This is what was found the single time anyone with subpoena power looked behind a published AI performance number. That is why we score the boring column instead.
No independent benchmark of AI agents in insurance distribution exists. That is a precise claim, not a rhetorical one, and it is worth stating carefully because in some adjacent fields independent evaluation genuinely does exist — it just measures underlying models or modalities rather than the commercial products being ranked. In insurance distribution we located nothing of either kind as of 23 August 2026: no head-to-head study, no academic evaluation, no trade-body test. Across more than twenty vendor sites, not one linked to a third-party assessment of its output quality. When a category has no referee, the only defensible ranking is one built from documents the buyer can pull up themselves.
We also refused a set of recycled industry statistics, and we want to be exact about why. Numbers such as the share of renewals lost to preventable service failures, the share of a producer's time spent on service work, percentage reductions in submission processing time, and claims-leakage totals in the billions circulate constantly in this market. We could not trace any of them to an origin. Our research budget for open-web search was exhausted before origin-tracing could be completed, so the honest description is that these figures are refused, not debunked. An unsourceable number stays out whether or not we found its author. One example we did encounter directly, on a commission-software vendor's own marketing page, is the claim that insurance agents lose $10,000–$16,000 annually in commission discrepancies. It carries no methodology, no sample and no denominator. We do not print it as fact, and neither should the vendor quoting it to you.
How to re-check this ranking yourself
Open each vendor's /security or /trust page and read what type of report is actually claimed. Open /pricing and see whether a number appears. Open /integrations and count the systems named by name rather than shown as a logo. Search SEC EDGAR full-text for the company name to test ownership claims. Search CourtListener for the legal entity in the footer. Every finding below was produced that way, and every one of them will age — which is why the date is on the page.
Agency-Buyable vs Carrier-Only: The Distinction Every Listicle Blurs
Before any feature comparison matters, one question decides whether a vendor belongs on your shortlist: can you buy it? The AI-in-insurance market has two largely separate demand sides. Carriers buy underwriting triage, portfolio steering, claims adjudication support and fraud detection. Distributors — retail agencies, brokerages, MGAs and wholesalers — buy servicing, submission preparation, quoting access, certificates, renewals and commission accounting. The products are not interchangeable, the buyers are not interchangeable, and a great many rankings written for agency owners are populated entirely from the carrier side.
The table below names the vendors we verified as carrier-first or carrier-only, with the vendor's own framing of its buyer wherever it publishes one. Two entries deserve particular attention. Agentech settles the scope question itself: its own site description reads “QA Complete is AI file review and audit. Claims Ops is claims orchestration. Two independent products, one carrier standard.” When the vendor says carrier standard, that is the answer. EvolutionIQ is the one that produces the most wasted agency hours, because it is still ranked as an independent vendor across a lot of 2024-vintage content. It is not one. CCC Intelligent Solutions completed the acquisition on 6 January 2025, total consideration $674.3 million, 62.4% cash and 37.6% CCC common stock; the deal is documented in CCC's investor release and its Form 8-K exhibit. It is a CCC product line, and it was carrier-side before that.
| Vendor | Buyer, in the vendor's own framing | What it does | Compliance evidence | Why it is not an agency purchase |
|---|---|---|---|---|
| Sixfold (Sixfold AI, Inc.) | Site title: AI for Insurance Underwriters | Underwriting submission triage; launched an AI Underwriter product in June 2026 | Its Security Commitments page describes AWS hosting, an information security policy, quarterly vulnerability scans, annual penetration testing, incident management and disaster recovery — and contains no mention of SOC 2, ISO 27001, a DPA, data residency or retention. Page read in full on 23 August 2026 | The buyer is a carrier. A retail agency has nothing to underwrite |
| Federato | Carriers and MGAs; site nav segments include MGAs and MGAAs | RiskOps, an underwriting portfolio-steering platform | A Trust Center is linked in the footer; contents were not retrievable, so no certification is verified | Carrier and MGA product. Its site banner on 23 August 2026 advertised a $100M Series D, which supersedes the 2024 figures still circulating in older rankings |
| Convr | Commercial P&C carriers | An AI commercial insurance underwriting workbench and a submission ontology, marketed as agentic | No SOC 2, ISO, GDPR or DPA language found anywhere on the homepage, checked 23 August 2026 | Carrier-only. It publishes an ROI calculator, which is a marketing instrument, not evidence |
| Gradient AI | Carriers, MGAs and PEOs | Group health, workers compensation and P&C underwriting and claims models | Footer states Gradient AI is SOC2 compliant and HITRUST certified — self-attested, and the SOC 2 type is not specified | Not an agency product at all |
| Sprout.ai (Sprout.ai Limited) | Insurers | Claims processing from FNOL to settlement, policy coverage checking, fraud detection | ISO 27001, Certificate No. 12285, displayed in the footer. Publishing a certificate number is unusually checkable — a reader can verify it with the issuing body | Carrier-only, and a UK company. For a US agency that is a data-transfer question before it is a product question |
| Agentech (Agentech, Inc.) | Its own site description: two independent products, one carrier standard | QA Complete is AI file review and audit; Claims Ops is claims orchestration | Not verified | The vendor itself says carrier standard. Carrier, TPA and adjuster side |
| EvolutionIQ | Carriers, specifically disability and injury claims | Claims guidance | Not applicable | Not an independent vendor. CCC Intelligent Solutions completed the acquisition on 6 January 2025 for total consideration of $674.3 million. Ranking it for an agency is the classic listicle error |
| Indico Data (Indico Data Solutions, Inc.) | Carrier-first — the site's own assistant text says it helps carriers speed up operations | Intake and orchestration; names a Broker Reconciliation use case alongside submissions, claims, MTAs and billing | Publishes a Trust Center and a Data Processing Addendum linked in the site footer — one of only two publicly linked DPAs we found across this roster | Carrier-first. A very large brokerage is a plausible buyer; a retail agency is not |
The Sixfold row is worth dwelling on, because it demonstrates why we score absences. Sixfold's own Security Commitments page is not a thin page — it describes AWS hosting, an information security policy, network security, quarterly vulnerability scanning, annual penetration testing, incident management and disaster recovery. What it does not contain, anywhere, is a mention of SOC 2, ISO 27001, a data processing addendum, data residency or retention. We read it in full on 23 August 2026. That is not a gotcha; it is a fact a buyer needs, it is dated, and it is re-checkable in thirty seconds. Compare it with Sprout.ai, which publishes an ISO 27001 certificate number in its footer — a claim you can independently verify with the issuing body. Those two pages tell you more about vendor posture than any feature grid.
Two further vendors sit in a genuine grey zone rather than a clean bucket. Indico Data is carrier-first by its own site copy but names a Broker Reconciliation use case, and it is one of only two vendors on the entire roster with a publicly linked Data Processing Addendum. Bevaya, formerly Roots Automation, names carriers, brokers and TPAs as its buyers, and its published workflow map is heavily agency-relevant. Both are plausible for a very large brokerage and implausible for a five-person agency. We say so rather than forcing them into a binary.
Two vendors we will not rank, and why that is the honest answer
NowCerts. The site is live and describes itself as an insurance agency management system. It is a JavaScript application that serves no body content to a direct fetch, so no pricing, feature list or AI capability could be extracted, and /pricing returns the same shell. Third-party listings refer to “Momentum AMP, formerly NowCerts,” while the vendor's own site still says NowCerts and the momentumams.com domain did not resolve for us. We could not confirm a rebrand, so we do not state one, and we do not rank a vendor whose product surface we could not read.
Broker Buddha. The domain redirects to a near-empty placeholder page; the title tag reads “Broker Buddha AI,” and the page's embedded application payload reveals live product objects including a Policy Admin product marked market-ready with a 14-day trial. The company appears to be mid-rebrand onto a .ai domain. No entity, ownership, pricing, compliance or integration fact could be verified. It appears in a great many 2024-vintage rankings, which is exactly the point: a stale roster is the single likeliest error in an article like this one, and a placeholder page is not something to rank.
The Comparison Table
Every vendor in this table is one an independent agency, brokerage, MGA or wholesale broker can actually buy. Every cell is either sourced to a page you can open or contains the words “not publicly disclosed.” There is no accuracy column, no ROI column and no score out of ten, because none of those could be produced honestly. The ordering reflects breadth of verifiable evidence and fit for a typical independent agency — not measured performance, which nobody can measure.
| Vendor (legal entity) | Workflow | Agent, copilot or automation | Pricing, checked 23 Aug 2026 | Compliance evidence on the vendor's own pages | Ownership from public record |
|---|---|---|---|---|---|
| 1. Quandri (Quandri Technologies, Inc.) | Personal-lines renewal review: reads the renewal declaration, compares to the expiring policy, flags changes, supports re-quoting | Automation with human review. The vendor's own framing is automating manual work so brokers can advise — not autonomy | Not publicly disclosed. Demo request only | SOC 2 Type 2 stated on its own security page; encryption in transit and at rest; role-based access; states it never uses customer information to train external or public AI models (self-attested, no report published) | Not disclosed on the vendor's site |
| 2. Comulate (Ardent Labs, Inc. d/b/a Comulate) | Commission and direct-bill statement reconciliation, cash application, carrier payables, revenue intelligence. Self-described market: large brokers | Automation with a human finalisation step — it posts a suspended statement of reconciled transactions for your team to finalize | Not publicly disclosed | Security page states an information security programme that follows the criteria set forth by the SOC 2 Framework — SOC-2-aligned language, not a claim of a completed Type II report. States all data hosted on AWS and GCP databases located in the United States | Not disclosed. Legal entity confirmed from a federal court caption |
| 3. Gaya | Chrome and Edge extension: extracts from carrier portals, AMS, PDFs, ACORD forms, screenshots and handwritten documents, then fills forms across carrier portals and raters | Copilot. The vendor explicitly states it requires human oversight and decision-making — it does not act alone | Published, and the only published price on this roster: a one-time setup fee plus a subscription starting at $300/month, month-to-month (vendor's own homepage FAQ) | SOC 2 Type II claimed on the homepage; encryption in transit and at rest. No trust-centre report retrieved | Not disclosed |
| 4. Qumis (Qumis Inc.) | Citation-backed commercial P&C policy and coverage analysis. Site nav carries a named Brokers and producers solution; also sold to carriers, MGAs and TPAs | Agents claimed. The vendor announced Qumis Certified Agents for July 2026 with sixteen specialists at launch; we did not verify general availability | Not publicly disclosed. A free trial and a demo are offered | Security page claims SOC 2 certified independently audited controls — Type I versus Type II is not stated. Also claims no training on customer data and isolated compute dedicated to each session. A Trust Center is linked | Not disclosed |
| 5. Bevaya (Roots Automation, Inc. dba Bevaya) | Submission intake, loss run processing, ACORD and exposure-schedule extraction, policy comparison, endorsement processing, COI creation, premium audit, claim-file summarisation | Pre-built agents with a named human-in-the-loop review stage on the vendor's own platform map. The most complete published workflow list on this roster | Pricing model published, amounts not: per AI agent pricing, shared credits, then routes to sales | A Trust and Security page exists; its contents were not machine-readable, so no certification is verified here | Not disclosed. rootsautomation.com redirects to bevaya.ai; the footer reads Roots Automation, Inc. dba Bevaya |
| 6. Certificate Hero (Certificate Hero, Inc.) | Certificate of insurance issuance and management end to end, AI contract parsing to read insurance requirements out of a contract, client self-service portal | Automation | Not publicly disclosed. Vendor FAQ: cost depends on certificate type and level of customisation; contact customer service | SOC 2 seals displayed as badge images in the footer awards block only — not a trust page, and the report type is not stated | Not disclosed on the vendor's site |
| 7. Semsee | Small-commercial quoting and market access, with distinct offerings for agents, for carriers and MGAs, and for partners | A quoting and distribution platform — not an AI agent | Not publicly disclosed | None found on the pages retrieved | Not disclosed. Footer copyright reads 2024 although the site is otherwise current |
| 8. Bold Penguin (Bold Penguin Inc., Dublin, Ohio) | Small-commercial appetite matching and quote-to-bind, quote comparison, integrated bind, CMS and AMS integrations, ClauseLink policy checking | A quoting exchange with AI features — not an autonomous agent | Not publicly disclosed | A trust centre exists at trust.boldpenguin.com; it is gated and we could not read its contents | Not disclosed on the vendor's site. We could not confirm a parent company — ask, because a quoting and appetite platform owned by a carrier group would carry an obvious conflict |
| 9. Ascend | Billing and invoicing, premium financing and payments, cash application, direct-bill automation, carrier payables, for agencies, MGAs, wholesalers and carriers | Payments and accounting automation — not an AI agent. Be blunt about this before you budget for one | Not publicly disclosed | Trust page not retrieved | Site footer reads Slash Eureka Inc., which differs from the trading name. We could not establish a corporate relationship to any similarly named company and make no claim about one. Banking services are disclosed as provided by Grasshopper Bank, N.A., Member FDIC |
| 10. Herald | A single API connecting software to commercial carriers for quotes across Workers Comp, BOP, GL and other lines. Infrastructure, not an end-user product | An API. Not an agent, and it should never be ranked as one without saying so | Not publicly disclosed | Not published | Not disclosed. heraldapi.com now redirects to heraldai.com; documentation remains at docs.heraldapi.com |
Three patterns jump out of that table. First, pricing opacity is near-total: exactly one vendor publishes a price, and one more publishes a pricing model without amounts. Second, compliance claims are mostly self-attested and frequently imprecise — “SOC 2 certified” without a type, a badge image instead of a trust page, or language that follows the criteria of the SOC 2 framework, which is not the same as a completed Type II report. Third, ownership is largely undisclosed. Exactly one company on this entire roster has its ownership confirmed by a filed SEC document, and it is not one of the ten — it is Vertafore, listed as a subsidiary of Roper Technologies in Exhibit 21.1 to Roper's Form 10-K.
Alongside the ten, three more names will come up in every conversation you have this year. None of them is an AI agent in the sense the marketing implies, and two of them are the platform your agency already runs on.
| Vendor | What it actually is | Ownership from public record | Why it is in this conversation |
|---|---|---|---|
| AgentSync (AgentSync, inc.) | Producer licensing and appointment compliance automation against real-time NIPR data, plus a contracting product for agency producer-to-carrier contracting. It is not an AI agent, and it is routinely listed as one | Not disclosed on the vendor's site | It enforces the actual binding constraint in this article. Integrations documented: NIPR and Salesforce. AMS integrations are not documented. Pricing is not published — /pricing returns the homepage |
| Vertafore (Vertafore, Inc.) | The agency management suite — AMS360, Sagitta, ReferenceConnect — now marketing a Velocity AI Platform and ReferenceConnect AI, described on the vendor's site as agentic AI built specifically for insurance | Listed as a subsidiary of Roper Technologies, Inc. in Exhibit 21.1 to Roper's Form 10-K. The only SEC-confirmed ownership on this entire roster | The suite option. Note that Vertafore's own homepage says only that it is part of a $51B company and does not name Roper — the 10-K exhibit does. Its trust centre is customer-gated. Pricing is not published |
| Applied Systems (Applied Systems, Inc.) | The other suite incumbent — Epic, and Ivans, which serves Applied's own copyright notice and is frequently listed as a separate vendor. The homepage features Cytora, described there as an agentic AI platform for carriers | Privately held, no SEC filings. We could not verify ownership, and we could not verify the Applied–Cytora corporate relationship. Do not assume an acquisition | The buy-the-suite answer, and the plaintiff in the litigation discussed below. A security page exists; pricing is not published |
The Ten, Entry by Entry
Each entry below covers the same six things: what it does, what is verifiable, what the vendor does not disclose, who it fits, who it does not fit, and what we could establish about ownership. Where the vendor is more honest than the category label, we quote the vendor.
1. Quandri — personal-lines renewal review, and the cleanest compliance page of the ten
What it does. Quandri Technologies, Inc. positions itself as “Renewal Intelligence for Personal Lines,” with platform pillars named Analyze, Quote and Connect. The workflow is the one every personal-lines agency does by hand and hates: read the renewal declaration, compare it to the expiring policy, flag what changed, support a re-quote, drive the client communication.
What is verifiable. Its own security page states SOC 2 Type 2 — specifying the type, which most of this roster does not — along with encryption in transit and at rest, role-based access, daily backups, AWS-based monitoring, and the statement that it never uses customer information to train any external or public AI model. That last commitment is self-attested and no report is published, but it is stated plainly enough to put in front of a carrier auditor and ask the vendor to stand behind contractually.
What is not disclosed. Pricing (demo request only). Data residency and retention. And, importantly for a buyer, a complete integration list: the site references AI-powered requoting in Applied Epic, but we found no published list, so do not assume AMS360, EZLynx or HawkSoft support until the vendor confirms it in writing.
Agent or automation? Automation with human review. The vendor's own framing is that it automates manual work so brokers can advise. That is the honest label and we use it.
Fits: personal-lines-heavy independent agencies and brokerages in the US and Canada with a real renewal book. Does not fit: commercial-only shops, and anyone expecting the tool to make the renewal decision.
2. Comulate — the best-documented integrations on the roster, and an active federal court file
What it does. Ardent Labs, Inc. d/b/a Comulate handles commission and direct-bill statement reconciliation, cash application, carrier payables and revenue intelligence. Its own footer describes the market as “Accounting Automation & Revenue Intelligence for Large Brokers” — note large brokers. This is not a small-agency purchase and the vendor does not pretend otherwise.
What is verifiable. The best integration documentation we found anywhere in this research. Its integrations page names Applied Epic, BenefitPoint, AMS360, Microsoft Dynamics and Salesforce by name, and states that Comulate reads and writes to your AMS and ERP, which remain the source of truth. That is an unusually specific and unusually checkable claim. Its security page publishes something rarer still: data residency. All data is hosted on AWS and GCP databases located in the United States. Only one other vendor across this whole roster publishes residency at all.
The precision point. The same security page describes an information security programme that follows the criteria set forth by the SOC 2 framework, with independent third-party assessments and annual penetration testing. That is SOC-2-aligned language. It is not an explicit claim of a completed SOC 2 Type II report, and you should not read it as one. Ask for the report.
Agent or automation? Reconciliation automation with a human finalisation step — the product posts a suspended statement of reconciled transactions for your team to finalize. Not autonomous, and better for it.
The buyer-risk caveat. Comulate is a defendant in active federal litigation brought by Applied Systems, and a preliminary injunction was entered on 11 February 2026. That is discussed in full further down this page, with the status precision it requires. Nothing about it is a finding of liability, and none of it is a reason to write the product off — but an agency evaluating an AMS-integrated tool whose vendor is in court with the AMS incumbent is taking on integration risk that belongs in the decision.
3. Gaya — the only vendor on this roster that publishes a price
What it does. A Chrome and Edge browser extension. “Super Copy” extracts from carrier portals, the AMS, PDFs, ACORD forms, screenshots and handwritten documents; “Super Paste” fills forms across carrier portals and comparative raters. It is the least architecturally ambitious product here and, for a small agency, possibly the most immediately useful, because it meets producers inside the portals they already live in rather than asking them to move.
What is verifiable, and it is genuinely rare. Gaya publishes a price. The vendor's own homepage FAQ states a two-part model — a one-time setup fee plus a monthly subscription starting at $300 per month, month-to-month with no long-term contract. That is a vendor-published starting price, checked 23 August 2026, and it is the only one we found across the entire roster. It tells you nothing about whether the product works, and everything about how the company expects to be evaluated.
What to treat carefully. Its integration list — roughly 500 carrier portals, comparative raters including EZLynx, PL Rater and TurboRater, AMS platforms including Applied Epic, AMS360, Salesforce and HawkSoft, plus Zapier, Zoho and API/webhooks — is the vendor's own claim with no third-party documentation URL behind it. Its SOC 2 Type II claim is a homepage assertion with no trust-centre report retrieved. And its published quote-speed multiples are testimonial marketing; we do not reprint them.
Agent or copilot? Copilot, explicitly. The vendor says the product requires human oversight and decision-making. That framing is not only honest, it is the legally correct one for anything that touches a quote — see the licensing section below.
4. Qumis — the only vendor here that publishes an abstention principle
What it does. Qumis Inc. sells “Coverage Intelligence for the Business of Insurance” — attorney-built, citation-backed policy analysis for commercial P&C. It is genuinely broker-facing: the site nav carries a solution headed “Brokers & producers — Win and keep complex accounts with command of the coverage.” It also sells to carriers, MGAs and TPAs.
What is worth crediting. The vendor states that if the system cannot cite it, it says so, and describes this as abstention by design. For a workflow that sits one inch from giving coverage advice, refusing to answer is the single most valuable behaviour a product can have, and almost nobody in this market builds toward it. Credit where due — while noting it is self-attested and we did not test it.
What is verifiable. Its security page claims SOC 2 certified independently audited controls, no training on customer data, isolated compute dedicated to each session, and encryption in transit and at rest with access logged. A Trust Center is linked. The precision point: “SOC 2 certified” does not state Type I or Type II. Do not upgrade it in your own notes.
The agent claim. The vendor announced “Qumis Certified Agents arrive July 2026 — a specialist for every line,” with sixteen specialists at launch. That is the vendor's own launch claim and we did not verify general availability. Ask for a reference account on your lines before you plan around it.
Fits: commercial brokerages fighting for complex accounts where coverage command wins the business. Does not fit: personal lines, and any workflow where the output would be handed to a client as advice without a producer reading it.
5. Bevaya (formerly Roots Automation) — the most complete published workflow map, and a name change most rankings missed
Start with the name. Roots Automation is now Bevaya. The vendor's own footer, fetched 23 August 2026, reads “© 2026 Roots Automation, Inc. dba Bevaya,” and rootsautomation.com redirects to bevaya.ai. The site title is “Bevaya | The AI Agent Platform Built for Insurance.” The InsurGPT model brand survives the rename. We could not establish the exact date of the change and do not state one. Any 2026 ranking still listing “Roots Automation” as a current product name is running a stale roster.
What it does. The published workflow list is the most complete on this roster and it is heavily agency-relevant: submission intake, loss run processing, ACORD form extraction, exposure schedule extraction, policy renewal handling, policy-to-policy comparison, endorsement processing, COI creation, premium audit processing, plus a claims-side set covering FNOL and FROI setup, claim-to-policy comparison, claim indexing, legal demands and medical bills extraction, invoice payment processing and claim file summarisation.
What is verifiable. The platform structure is published in detail — Workflow Canvas, AI Assistant, InsurGPT, Document Intelligence, pre-built AI agents, Workspaces and Live Runs, a named Human-in-the-Loop review stage, grounded explainability, governed automation, integrations, and org and admin controls. The pricing model is published: per AI agent pricing, shared credits, scales as you grow. The amounts are not. That is a real distinction and worth noting in a shortlist.
What to discount. The site publishes an “Accuracy Benchmarks” section and a results-and-ROI section under its own labs brand. A vendor publishing its own benchmark is not an independent benchmark, and this is the cleanest live illustration of that distinction anywhere in the vertical. Its trust and security page exists but was not machine-readable to us, so no certification is verified here.
Fits: large brokerages and TPAs with document volume that justifies per-agent pricing. Does not fit: small agencies, who will not clear the floor.
6. Certificate Hero — narrow, valuable, and the highest regulatory exposure on this page
What it does. Certificate Hero, Inc. issues and manages certificates of insurance end to end, with AI contract parsing to read the insurance requirements out of a contract, real-time policy data, and a client self-service portal. It is sold to insurance brokers and their clients.
What is not disclosed. Pricing — the vendor FAQ says the cost depends on the type of certificate and the level of customisation required, and routes to customer service. Integrations: the site claims real-time integrations with leading agency management systems and names none, so do not assume Epic, AMS360, HawkSoft or EZLynx support. Compliance: SOC 2 seals appear as badge images in a footer awards block rather than on a trust page, with no report type stated. Ownership is not disclosed.
Why it needs its own risk paragraph. COI issuance is directly regulated by statute in roughly thirty states. An agent that parses a contract's insurance requirements and produces a certificate is doing precisely the thing those statutes govern, and one bad inference away from a document that amends, extends or alters coverage. That is not a criticism of this vendor — it is the nature of the workflow, and it applies equally to a build. The worked example below runs the exposure in detail.
7. Semsee — a quoting platform with a genuinely checkable carrier panel
What it does. Small-commercial quoting and market access, with distinct offerings for agents, for carriers and MGAs, and for partners.
What is verifiable, and it is better evidence than most integration claims. Semsee publishes its carrier panel on the homepage. The partial list visible in the page markup on 23 August 2026 includes Acuity, AF Group, AmTrust, Arch, At-Bay, Auto-Owners, AXIS, Berkley, biBerk, CFC, Chubb, Clear Spring, CNA, Coalition, Coterie, Counterpart, CoverWhale, Cowbell, Donegal, Employers, Great American, Guard, The Hanover, Liberty Mutual, MAPFRE, Markel, Merchants, Nationwide, Pie Insurance, Quincy Mutual, Travelers, US Assure and Utica First. You can check that list against your own appointments in five minutes. Most “integrations” claims in this market cannot be checked at all.
What is not disclosed. Ownership, pricing and any SOC 2 or ISO claim, on the pages we retrieved. The footer copyright reads 2024 although the site is otherwise current and the panel is populated; /about returns a 404. Stale footer years are common and not by themselves alarming, but they are a reason to confirm the company's current status directly.
Agent or not? A quoting and distribution platform. Not an AI agent. It earns a place because market access is frequently the actual bottleneck in small commercial, and no amount of agentic document processing fixes a thin panel.
8. Bold Penguin — small-commercial quote-to-bind, with one question you must ask
What it does. Bold Penguin Inc., of Dublin, Ohio, runs small-commercial appetite matching and quote-to-bind — quote comparison, integrated bind, CMS and AMS integrations, market intelligence — and advertises ClauseLink policy checking and a smart upload feature.
The question to ask. The site does not name a parent company, and we could not verify its ownership. It is widely believed to be owned by a carrier group; we could not confirm that and therefore do not assert it. We flag it because it matters: a quoting and appetite-matching platform owned by a carrier has an obvious structural conflict with an independent agency's duty to shop the market, and you deserve to know that we could not settle the question. Ask the vendor directly, in writing, and get the answer before you route volume through it.
What else is verifiable. A trust centre exists at trust.boldpenguin.com; it is gated and we could not read its contents. The vendor states on its own site that it acquired SquareRisk, though we could not confirm a date. Pricing is not publicly disclosed. Its published growth figures are vendor marketing and are not reprinted here.
Agent or not? A quoting exchange and marketplace with AI features, not an autonomous agent.
9. Ascend — payments and accounting automation, ranked on its own attributes
What it does. Billing and invoicing, premium financing and payments, cash application, direct-bill automation and carrier payables. The site describes itself as the only complete financial operations platform built for agencies, MGAs, wholesalers and carriers. For an agency drowning in accounts-receivable admin, that is a real and specific pain.
The entity anomaly, reported as a fact and nothing more. The site footer reads “© Slash Eureka Inc.,” fetched 23 August 2026, which differs from the trading name. A separate business-banking company operates under a similarly formed but different entity name. We could establish no corporate relationship between them and we assert none. We report the footer because corporate identity is a due-diligence input, not because it implies anything. Ask the vendor which entity your contract will be with.
Other verifiable facts. The site discloses that Ascend is a financial technology company, not a bank, and that banking services are provided by Grasshopper Bank, N.A., Member FDIC — the right disclosure to make and worth crediting. In May 2026 Ascend and premium-finance provider Honor Capital announced an agreement to merge, with the combined company to continue under Ascend's leadership. Status precision: an announced agreement to merge is not a completed merger, and we could not verify completion. Compliance artefacts were not retrieved and pricing is not disclosed.
Agent or not? Largely payments and accounting automation, not an AI agent. Buy it for the receivables workflow if that is your bottleneck; do not buy it expecting autonomy.
10. Herald — infrastructure, not a product, and it should always be labelled that way
What it does. A single API that connects software to commercial carriers for quotes across Workers' Compensation, BOP, General Liability and other lines. heraldapi.com now redirects to heraldai.com, with the site title “Herald — AI-enabled placement at scale”; documentation remains at docs.heraldapi.com, and the company also publishes an Insurance API Index.
Who the buyer actually is. This is infrastructure, not an end-user product. The buyer is an agency with developers, or the software vendor that serves agencies. If your agency does not employ or contract engineers, Herald is not something you deploy — it is something the platform you buy might be built on. Ranking it as an agent without saying that is exactly the kind of category error this article exists to correct.
What is not disclosed. Compliance artefacts, pricing and data residency were not verified. Its documentation site exists but is JavaScript-rendered and we could not extract its contents, so we make no claim about which carriers are live today — ask for the current list against your lines and states.
The blunt summary of all ten
Two are quoting platforms. One is an API. One is a payments system. Three are document extraction and workflow automation with a human review step the vendors themselves describe. One is a browser copilot that says out loud that it needs a human. One is a coverage-analysis tool whose best feature is knowing when to refuse. Exactly one markets named agents to brokers, and announced them two months ago. That is the actual state of agentic AI in insurance distribution in August 2026 — and it is a perfectly good state to buy in, provided you buy what is there rather than what the category label implies.
The Binding Constraint: Producer Licensing
Producer licensing, not model capability, decides what an AI agent may do in your agency. The NAIC Producer Licensing Model Act (#218), Section 3, states it without qualification: “A person shall not sell, solicit or negotiate insurance in this state for any class or classes of insurance unless the person is licensed for that line of authority in accordance with this Act.” The question that follows is not whether an AI can do the work well. It is whether the work is one of those three verbs.
The Act defines all three, and the definitions are unusually clean for drawing a technical boundary:
“Negotiate” means the act of conferring directly with or offering advice directly to a purchaser or prospective purchaser of a particular contract of insurance concerning any of the substantive benefits, terms or conditions of the contract, provided that the person engaged in that act either sells insurance or obtains insurance from insurers for purchasers. “Sell” means to exchange a contract of insurance by any means, for money or its equivalent, on behalf of an insurance company. “Solicit” means attempting to sell insurance or asking or urging a person to apply for a particular kind of insurance from a particular company.
— NAIC Producer Licensing Model Act (#218), Section 2 — definitions
One more definition settles the question people most often ask about AI and licensing. The Act defines “person” as “an individual or a business entity.” An AI system is neither. It cannot hold a licence, it cannot be a licensee, and there is no pathway by which it becomes one. The licensed actor is always the agency or the human producer. The agent is a tool a licensee uses, and the licensee owns everything that tool does — every extraction, every draft, every email, every certificate.
The Act also tells you where an agent can safely operate, through the exemption in Section 4.B(1) for officers, directors and employees of an insurer or producer who receive no commission on policies written or sold. The exemption covers activities that are “executive, administrative, managerial, clerical or a combination of these, and are only indirectly related to the sale, solicitation or negotiation of insurance”; functions relating to “underwriting, loss control, inspection or the processing, adjusting, investigating or settling of a claim”; and acting as a special agent or agency supervisor whose activities are “limited to providing technical advice and assistance to licensed insurance producers.” That is a precise description of the safe operating envelope for automation, and it is why the boundary table below writes itself.
| Task | Where it falls under NAIC Model Act #218 | Verdict |
|---|---|---|
| Extract data from an ACORD form into the AMS | Clerical and administrative; only indirectly related to sale, solicitation or negotiation | Agent may act |
| Reconcile a commission or direct-bill statement | Administrative | Agent may act |
| Order and index loss runs | Clerical | Agent may act |
| Compare the expiring policy to the renewal and flag differences | Clerical, or technical assistance to a licensed producer | Agent may act; the producer reviews |
| Populate a submission across carrier portals and raters | Clerical | Agent may act |
| Draft an endorsement request for producer sign-off | Clerical | Agent may prepare; the producer sends |
| Recommend a coverage, a limit or a carrier to a client | Negotiate — offering advice directly to a purchaser about substantive benefits, terms or conditions | Licensed producer only |
| Urge a client to apply for a particular policy from a particular company | Solicit | Licensed producer only |
| Bind coverage | Sell | Licensed producer only, and within binding authority |
| Answer the question: am I covered for this? | Negotiate — advice on substantive terms | Licensed producer only |
One caveat, and it is not a formality. #218 is a model, not the law. States adopt it with variations, and the Act itself provides that it does not apply to excess and surplus lines agents and brokers except as provided in two specified sections. Check your own state's enacted statute and your own lines of authority, and never cite a model act, a bill analysis or a department press summary as the law. Read the enacted text.
The design rule this produces
Build agents that produce artefacts a producer approves, not communications a client receives. A drafted email, a populated submission, a flagged renewal difference, a reconciled statement in a suspended state — all of these are administrative work product. The moment the same system gains an outbound channel to a client and the ability to characterise coverage, you have moved from clerical support to negotiating, and the licence is yours.
Which Rules Actually Bind an Agency
The rule everyone talks about does not bind you, and the rule almost nobody mentions does. Getting this backwards is the most common error in agency-facing AI content, so it is worth being exact.
The NAIC AI Model Bulletin binds insurers, not producers
The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted by the NAIC on 4 December 2023. Per NAIC's own adoption map, status as of 6 August 2026, it has been adopted by 25 jurisdictions — 24 states plus the District of Columbia. That count has risen steadily, with adoptions landing as recently as December 2025, so treat it as a dated reading and re-check the map rather than quoting this article in two years.
NAIC separately tracks four jurisdictions that regulate AI in insurance under their own instrument without adopting the bulletin: California (Bulletin 2022-5, 30 June 2022), Colorado (3 CCR 702-10, effective 13 November 2023, with amendments effective 15 October 2025), New York (Insurance Circular Letter No. 7, 11 July 2024) and Texas (Bulletin B-0036-20, 30 September 2020). Those four are a separate category — do not fold them into the 25. Counting both, 29 jurisdictions have something on the books.
But the bulletin is directed at insurers. It does not by its terms bind an independent agency. What it does is require insurers to run an AI systems programme with governance, risk management and — decisively for you — third-party AI vendor oversight. Your carriers will push those obligations down through appointment agreements, audits and questionnaires. In practice you will meet this bulletin as a vendor questionnaire, not as a regulation. Prepare for it that way.
NAIC Model Law #668 is the one aimed at you
The Insurance Data Security Model Law (#668) defines “Licensee” as any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered pursuant to the insurance laws of the state. A licensed insurance agency is a Licensee. Section 4.F states the duty plainly:
(1) A Licensee shall exercise due diligence in selecting its Third-Party Service Provider; and (2) A Licensee shall require a Third-Party Service Provider to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information that are accessible to, or held by, the Third-Party Service Provider.
— NAIC Insurance Data Security Model Law (#668), Section 4.F
That is the strongest argument in this entire article for scoring the boring compliance column. In every state that has enacted #668, due diligence in vendor selection is a legal duty of the agency — and it is discharged with exactly the artefacts this ranking scores: a trust page, a SOC 2 report, a DPA, a residency commitment, a documented subprocessor list. A vendor's accuracy claim discharges nothing. Section 4.G additionally requires the Licensee to monitor, evaluate and adjust its information security programme as technology and business arrangements change, which plainly includes adopting AI. We could not verify the state-by-state adoption count for #668 and do not state one; the honest phrasing is “the many states that have enacted it.”
The Unfair Claims Settlement Practices Act reaches agents — and frequency is the trigger
The NAIC UCSPA (#900) defines “Insurer” as a person, reciprocal exchange, interinsurer, Lloyd's insurer, fraternal benefit society, and any other legal entity engaged in the business of insurance, including agents, brokers, adjusters and third party administrators. Under the model, an agency that touches a claim is inside the Act.
Section 3 makes a listed act an improper claims practice if it is committed flagrantly and in conscious disregard of the Act, or if it is committed with such frequency as to indicate a general business practice. A systematised AI agent is, definitionally, frequency. A human who misstates a policy provision twice has made two mistakes; an agent that misstates it in four thousand automated replies has established a general business practice. The Section 4 acts most reachable by an agent are the obvious ones: knowingly misrepresenting relevant facts or policy provisions relating to coverages at issue; failing to acknowledge pertinent communications with reasonable promptness; failing to promptly provide a reasonable and accurate explanation of the basis for a denial or compromise offer; and failing to provide claim forms within fifteen calendar days of a request.
Two precision points. Section 1 states the Act is not intended to cover claims involving workers' compensation, fidelity, suretyship or boiler and machinery insurance, and that nothing in it creates or implies a private cause of action. And state enactments vary substantially — many predate the 1990 model, and some do not include agents and brokers in the definition of insurer. Cite the model as the model; read your statute.
New York adds two layers. Insurance Circular Letter No. 7 (2024), issued 11 July 2024, governs the use of AI systems and external consumer data in underwriting and pricing. Read its scope carefully before you worry about it: it applies to insurers authorised to write in New York, Article 43 corporations, HMOs, licensed fraternal benefit societies and the New York State Insurance Fund. By its terms it does not apply to producers, and it is scoped to underwriting and pricing — not servicing, not certificates, not claims chasing. Separately, and more directly relevant, 23 NYCRR Part 500 does reach you: DFS defines a Covered Entity as any individual or organisation operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under the Banking Law, the Insurance Law or the Financial Services Law. A New York-licensed agency is a Covered Entity, subject to the limited exemptions in § 500.19. Part 500 was promulgated 1 March 2017; we did not verify the post-2023-amendment compliance dates and deliberately print none, because several widely quoted versions of them are wrong.
Colorado is the jurisdiction to watch. SB 21-169 became law on 6 July 2021 and prohibits insurers from using an external consumer data and information source, algorithm or predictive model in a way that unfairly discriminates on protected characteristics; it requires disclosure of external data sources, a risk-management framework, assessments, ongoing monitoring and a chief risk officer attestation. Its implementing regulations sit at 3 CCR 702-10. The quantitative-testing regime began with life insurers' use of external data in underwriting. Whether it has been extended to other lines by August 2026 we could not verify, and we will not guess in either direction — check the current scope of 3 CCR 702-10 before assuming it does or does not reach your line. What is clear is that the Division is actively regulating in this space: its announcements index shows an 11 August 2026 request for comment on draft proposed emergency regulations and an 18 August 2026 request on a revised bulletin concerning aerial imagery in insurer decision-making. That last one is instructive on its own — this regulator has already moved on to the next data source.
Federal action has not swept any of this away
Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence,” was signed 11 December 2025 and published 16 December 2025 at 90 FR 58499. Section 3 directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws; Section 4 orders a Commerce evaluation of state AI laws within 90 days; Section 5 conditions eligibility for remaining BEAD non-deployment funds. It preempts nothing. Preemption requires Congress or a court. The word “insurance” appears zero times in the order. And 15 U.S.C. § 1012(b) provides that “No Act of Congress shall be construed to invalidate, impair, or supersede any law enacted by any State for the purpose of regulating the business of insurance … unless such Act specifically relates to the business of insurance.” Even a future federal AI statute would not displace state insurance AI rules unless it specifically related to the business of insurance. Anyone telling you the federal government has cleared the field is describing something that did not happen.
On E&O, we have to be honest about what does not exist. As of 23 August 2026 we located no reported court decision addressing an insurance agency's professional liability for an AI agent's error. There is no case law to point at, and any article implying otherwise is inventing it. That absence is itself the useful finding: the allocation of this risk is being settled right now in policy wordings and vendor contracts rather than by judges. The practical instruction is the one a senior consultant actually gives — ask your E&O carrier, in writing, whether the policy responds to an error made by an automated system acting under the agency's licence, and get the answer in writing before you deploy. It costs nothing and it is the highest-value hour you will spend on the project.
Buyer Risk: A Vendor in Court With Your AMS
The binding practical risk in buying an AMS-integrated AI tool is not model quality — it is that the AMS vendor can litigate the integration away. That is not speculation, and it is the single most operationally useful fact on this page for an agency shortlisting vendors this quarter. We are going to describe it with more status precision than you will find anywhere else, because the merits are not ours to characterise and the states of a case are not interchangeable.
On 11 February 2026, in Applied Systems, Inc. v. PBC Consulting Inc. and Ardent Labs, Inc. d/b/a Comulate, No. 1:25-cv-14251 (N.D. Ill.), the court entered a preliminary injunction (Dkt. 82). We read the order in full rather than either party's description of it, and the distinction matters. The order states that Applied Systems “has demonstrated a likelihood of success on the merits of its claim against PBC Consulting Inc. and Ardent Labs, Inc., d/b/a Comulate for breach of contract (Count II).”
Four things this is not
1. The injunction rests on Count II, breach of contract, only. It does not rest on the trade-secret, fraud, unjust-enrichment or Computer Fraud and Abuse Act claims that Applied also pleads. Applied's own webpage describes the case more broadly than the order does. Follow the order.
2. A preliminary injunction is not a liability finding. “Likelihood of success” is the standard for interim relief. It is a predictive ruling made early, on an incomplete record. Nobody has been found liable of anything, and it would be wrong to write that anyone was.
3. The claims in Applied's amended complaint of 2 January 2026 are allegations, and the plaintiff's account of its own case is a party document, not a court document.
4. Comulate filed its own suit against Applied in the same district on 19 January 2026, No. 1:26-cv-00591, alleging anticompetitive conduct. Nothing in that complaint has been adjudicated, and we do not repeat or characterise its allegations here. A complaint is one side's assertion. Note also that the docket date is 19 January 2026; a vendor page gives a different day, and the docket governs.
What the order actually did is the part a buyer needs. Within seven days, Ardent Labs d/b/a Comulate was ordered to cease use of any information obtained through PBC's access to Applied's Epic software system or software development kit, and to immediately cease the sale or provision of any products developed, tested or trained using such information to any entities other than existing joint customers of Applied and Comulate. Applied was ordered to post $1,000,000 in security. Read that middle clause again, because it is the commercial fact: a court order has, on an interim basis, restricted which customers certain products may be sold to.
Now the generalisable lesson, which is the reason this is in the article. Your AI vendor's access to your agency management system is governed by a contract between two parties, neither of which is you. Litigation, a terms change, a certification lapse or an acquisition between those two parties can restrict or end that access with no reference to your renewal date. This is not unique to any one vendor pair and it is not a reason to avoid AMS-integrated tools — it is a reason to negotiate for the specific thing that protects you.
Four questions to put in writing before you sign an AMS-integrated AI contract
- What is the legal basis for your access to our AMS?: A published partner programme, a certified integration agreement, credentials we supply, or screen automation? Each has a different failure mode, and only one of them is ours to control.
- What happens to our data and our workflow if that access stops?: Ask for the answer as a contractual export right with a defined window, not as reassurance in a sales call.
- Are you currently in litigation, arbitration or a dispute with our AMS vendor?: And will you notify us within a set number of days if that changes during the term?
- Which legal entity are we contracting with?: Compare it to the footer of the vendor's own website. On this roster, more than one trading name differs from the entity in the footer, and at least one is confirmed only by a federal court caption.
Worked Example: The Certificate of Insurance Agent
Certificates of insurance are the best worked example in this vertical because the statute is explicit, the workflow is high-volume, and the failure mode is exactly the behaviour a language model produces by default: being helpful. Consider a commercial agency issuing 900 certificates a month for construction and professional-services accounts, with two CSRs spending most of their week on it. That is a textbook automation candidate, and it is also the workflow most likely to generate a statutory problem.
Minnesota's statute is a fair example of the regime; roughly thirty states have COI statutes, several make fraudulent issuance a criminal offence, and we verified only Minnesota. Minn. Stat. § 60A.39 subd. 1 provides that a certificate “does not convey any contractual rights to the certificate holder.” Subdivision 2 is the prohibition:
An insurer or licensed producer shall not issue a certificate of insurance or other document or instrument that either affirmatively or negatively amends, extends, or alters the coverage provided by an approved policy, form, or endorsement without the written approval of the commissioner.
— Minn. Stat. § 60A.39, subd. 2 (2025 Minnesota Statutes)
Subdivision 3 requires the certificate to carry the statement that it does not affirmatively or negatively amend, extend or alter coverage. Subdivision 4 bars promising a cancellation notice exceeding the statutory or policy notice. Subdivision 5 requires an insurer not using the standard ACORD or ISO certificate form to file an alternative with the commissioner before use, and provides that filed forms may not be amended at the request of a third party. And subdivision 6 is the one aimed squarely at a language model:
A licensed insurance producer may not issue, in lieu of a certificate, an agent's opinion letter or other correspondence that is inconsistent with this section.
— Minn. Stat. § 60A.39, subd. 6
Now run the agent. A general contractor emails your certificates inbox: “We need the COI to show blanket additional insured and 30 days' notice of cancellation, and can you confirm the policy covers subcontractor work?” A helpful, well-built, well-intentioned document agent has four ways to fail here, and three of them are statutory rather than technical. It can add an additional-insured description the policy does not support, which alters coverage. It can promise a 30-day notice the policy does not provide, which subdivision 4 addresses directly. It can amend the filed form at a third party's request, which subdivision 5 forbids. Or it can simply reply to the email explaining what is covered — which is an opinion letter under subdivision 6, and negotiating under Model Act #218, in a single sentence, sent under your licence, at machine speed, to every certificate holder who asks.
The architecture that survives this
The agent parses the contract and produces a requirements summary for a producer, not a certificate. It maps each stated requirement to a policy provision, and where it cannot find one it says so and stops — abstention, not inference. It populates only the standard ACORD or ISO form with fields drawn from policy data, generating no free text. It has no outbound email channel to the certificate holder at all; every coverage question routes to a named licensed producer queue. And a producer approves issuance, with that approval recorded and timestamped. You keep most of the labour saving and you never generate the document that gets you a market-conduct exam.
We have built this shape of constraint before, on the client-facing side rather than the back office. In our work with an independent Connecticut insurance broker, the AI chatbot we shipped was built around prohibited-language filtering for CMS Medicare marketing compliance, screening both user inputs and the AI's own outputs before anything reached a visitor. The compliance rule was designed in from the start rather than bolted on afterwards, which is the whole point: for insurance, the interesting engineering is rarely what the model can say. It is what the system is structurally incapable of saying. Every architectural decision above is the same idea applied to certificates.
One arithmetic note, offered as a scenario rather than a result. If the agency above spends two full-time-equivalent CSR weeks a month on certificates, and a constrained agent removes the parsing and population work while leaving producer approval intact, the saving you should model is the parsing and typing, not the review. Review is the control that makes the rest defensible, and any business case that assumes review disappears has assumed away the reason the project is legal. We are deliberately not attaching a percentage to that saving, because we would be making it up — and a ranking that refuses unsourceable industry statistics does not get to invent its own.
What Breaks First
The failures that matter in an agency deployment are quiet ones — the workflow keeps running and the output is wrong. Loud failures get fixed on the day. Silent failures accumulate across a renewal cycle and surface as an E&O question. Here is what actually goes wrong, what the signal looks like and how you get back.
| Failure mode | What it looks like in an agency | Detection signal | Rollback |
|---|---|---|---|
| The AMS integration is withdrawn or restricted | A workflow that has been running for months stops mid-month, or a vendor tells you a feature is no longer available to non-joint customers | Vendor release notes, a change to your AMS contract at renewal, or a court order restricting a third party's use of AMS-derived data | Keep the manual path documented and staffed at low volume. Never let the only copy of a reconciliation live inside the vendor |
| Silent extraction drift after a carrier changes a form | Dec pages from one carrier start extracting a limit into the wrong field. Nothing errors. The renewal review looks complete and is wrong | Field-level acceptance rate per carrier per week; a sudden change in how often a human corrects one specific field | Per-carrier kill switch. Fall back to human review for that carrier only, rather than pausing the whole workflow |
| Prompt injection through an inbound document or email | A submission attachment or a certificate request contains instructions the model follows — exfiltrating a client list, or sending an unauthorised reply | Outbound volume anomalies, any outbound message not matched to an approved draft, credential use outside the expected scope | Revoke the agent credential rather than pausing the code. Assume anything the agent could read has been read |
| A retried write becomes a duplicate | A statement posts twice, or an endorsement request is sent twice to a carrier, because a retry generated a new identifier | Nightly reconciliation against the system of record; duplicate-key alerts in your own dedupe table | Reverse the duplicate through the normal accounting process, then fix the key derivation before re-enabling |
| The vendor is acquired, renamed or repriced | Your roster is stale. The product you bought is now a line in someone else's suite, and the roadmap you were sold belongs to a different company | A footer entity change, a domain redirect, an SEC filing, a press release, or a renewal quote that moves without explanation | Contractual: data export rights and a defined exit window, agreed before signature rather than after the announcement |
| A carrier vendor-oversight questionnaire arrives and you cannot answer it | Your appointment terms now require you to name your AI vendors, their subprocessors and their data handling — and you do not have the artefacts | The questionnaire itself; a new clause at appointment renewal | Collect the trust page, DPA, SOC 2 report and residency commitment before deployment, not after the questionnaire. If the vendor has none, that is the answer |
Prompt injection deserves its own paragraph, because it is unsolved. An insurance agency is a near-perfect target environment: your agents read submission emails, broker-of-record letters, loss runs, contracts and certificate requests, all of which arrive from outside and none of which you control. An attacker does not need to breach anything — they need to send you a document. The workable posture is blast-radius reduction, which we set out in detail in our guide to prompt injection and the OWASP LLM Top 10: never let one session hold both untrusted content and a write credential; give the reading agent a read-only credential and no outbound send; make writes reversible and reconcile them nightly against the system of record; log every action with attribution to the agent and to the human it acted for; and revoke credentials rather than pausing code when something looks wrong. Treat any vendor advertising a detection rate against injection with suspicion — in security, a number in the nineties is a failing grade, not a selling point.
The second underrated failure is roster rot in your own vendor stack. Two of the corporate-status findings on this page — a rename with a domain redirect, and an acquisition that closed in January 2025 — are the kind of change that quietly invalidates a procurement decision made eighteen months earlier. Put a calendar entry against every AI vendor renewal that says: re-read the footer, re-read the trust page, re-check EDGAR and CourtListener for the legal entity, and confirm the integration list still names your AMS. It takes twenty minutes and it is the cheapest control in this article.
The Human-in-the-Loop Boundary
This is the table to print and put on the wall, because it converts the licensing analysis into an engineering specification. Three columns matter operationally: what the agent may do alone, what needs a human commit, and what no agent should ever touch under your licence. The fourth column is the control that makes the boundary real, because a boundary that exists only in a system prompt is not a boundary.
| Action | Who may do it | Why the line is there | The control that makes it real |
|---|---|---|---|
| Read, classify, extract, index and route documents — loss runs, dec pages, ACORD forms, statements | Agent alone | No write into a system of record and no communication leaves the agency. A wrong extraction is caught by the next step | Read-only credential, separate agent identity, no outbound send capability, sampled human review against a labelled set |
| Reconcile a commission or direct-bill statement into a suspended or draft state | Agent alone with reconciliation | The suspended state is the artefact a human can inspect. This is exactly how the better vendors already do it | Idempotency key derived from business intent, not a fresh identifier per retry; nightly read-back against the accounting system of record |
| Draft a client email, an endorsement request, a submission or a renewal summary | Agent alone up to send | A draft exists nowhere but your own store until a person approves it. Sending is the irreversible act, not drafting | Draft state outside the AMS until approved; approver identity captured in the audit log with a timestamp |
| Issue a certificate of insurance | Human commits, always | COI issuance is directly regulated by statute in roughly thirty states, and the statutory language reaches the document, not the person who typed it | Standard ACORD or ISO form only; no free-text additions generated by a model; producer approval recorded before issuance |
| Answer a certificate holder or a client asking what is covered | Never the agent | That is negotiating under Model Act #218, and in Minnesota it is also an opinion letter barred by § 60A.39 subd. 6 | Hard refusal in the system prompt is not enough — remove the outbound channel, or route every coverage question to a named licensed producer queue |
| Recommend a coverage, a limit, a carrier or a policy change | Never the agent | Negotiate and solicit are licensed acts. The licence attaches to the act, and a system is neither an individual nor a business entity | No credential and no template that can produce a recommendation; the agent may present a difference, never a preference |
| Bind, cancel, reinstate or non-renew | Never the agent | These are the acts your binding authority governs, and they carry notice obligations with statutory clocks | No write credential to the binding surface is issued to any agent identity, at any scope |
| Deny, decline or characterise a claim outcome | Never the agent | The model UCSPA definition of insurer includes agents and brokers, and an automated system produces frequency, which is the statutory trigger | Agent may assemble the file and draft a factual summary; a qualified human owns the communication and the explanation |
Notice the pattern in the final column. Every enforceable control is structural — a credential that does not exist, an outbound channel that was never wired, a form that accepts no free text, a reconciliation job that runs whether anyone remembers it or not. None of them is an instruction to the model. Instructions are how you get good behaviour most of the time; architecture is how you get it on the day someone sends you a hostile PDF. Build the controls first and the prompt second.
Cost, Timeline and Build vs Buy
Buy the commodity workflow; build the one that is specific to how your agency actually operates. Statement reconciliation, loss-run chasing, ACORD extraction and portal form-filling are commodities — several vendors on this page do them and none of them is a competitive differentiator for you. A build earns its cost when the workflow encodes something particular: your carrier panel, your niche programme, your submission standards, your referral rules, or an integration nobody sells because your systems are an unusual pair. We work through that decision in more depth in our build versus buy analysis for AI agents, and the short version is that the question is rarely cost — it is whether the workflow is yours or everyone's.
Buying has one obstacle specific to this market: you cannot compare prices, because there are almost none to compare. Exactly one vendor on the roster publishes a starting price, and one more publishes a pricing model without amounts. Everything else routes to sales. Budget for a procurement cycle rather than a price, ask for a written quote against a defined volume, and refuse to sign anything with usage-based pricing whose unit you cannot measure yourself.
For a senior-led custom build, here are our bands. They are our scoping figures, not an industry benchmark, and you should read them the way you should read every other number a vendor gives you.
| Engagement | Range | Timeline | What it includes |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | Workflow inventory across the AMS, the accounting system, the raters and the carrier portals; licensing-boundary mapping for each candidate workflow; vendor artefact collection; a prioritised shortlist with a measurement baseline |
| Single-workflow agent | $28k–$70k | 4–9 weeks | One workflow end to end — renewal review, statement reconciliation, loss-run chasing or submission preparation — with read integration, a human commit step, idempotency and reconciliation, audit logging, and a review queue instrumented for timing |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks | Several workflows, read and write paths where the AMS actually supports them, an evaluation harness against your own labelled documents, schema-drift tests in CI, and a reporting pack you can hand to a carrier auditor |
| Enterprise / multi-site / regulated build | $180k–$420k+ | 14–24 weeks | Multi-location or multi-entity rollout, per-tenant isolation, a full audit pipeline with attribution that survives a compliance review, step-up authorisation for privileged actions, disaster recovery and restoration testing, and the documentation package |
Alongside those: senior-led work at $150–$225/hr, ongoing retainers at $2,500–$9,500/month, a 30-day post-launch warranty, a fixed-price phased proposal within 5 business days of discovery, and full source-code and IP ownership transfer on delivery. Frenchy Digital is a senior-led Black-owned agency in Los Angeles; you can reach us on +1 (424) 272-5601 or book directly at calendly.com/frenchydigital/discovery-call.
One budgeting point that consistently gets missed: whichever way you go, the compliance artefact work is not optional and it is not free. Collecting trust pages, DPAs, SOC 2 reports, subprocessor lists and residency commitments, and building the vendor register your carriers will eventually ask to see, is a real line item. Under Model Law #668 it is also a legal duty rather than a nice-to-have. Put it in the plan at the start, where it costs a few days, rather than at the point a carrier questionnaire lands and it costs a deployment.
Red Flags When Evaluating a Vendor
The strongest signals in a vendor evaluation are about candour, not capability. Every item below is something you can observe in a single meeting or from a public page, and each one has a matching good answer worth listening for.
Refuse to proceed on these
- A published accuracy, straight-through or ROI figure offered as neutral fact: Ask for the methodology, the sample and the denominator. If those do not exist, the number does not either. A vendor publishing its own section headed Accuracy Benchmarks is publishing marketing, and a vendor-supplied ROI calculator is a sales tool wearing a lab coat.
- SOC 2 claimed without a type, or a badge image in place of a trust page: Type I and Type II are materially different assurances. Language that follows the criteria of the SOC 2 framework is not a completed report. Ask for the report under NDA; a real one arrives.
- Integrations shown as logos rather than named in documentation: A logo wall is not an integration list. Ask which specific systems, which specific operations, read or write, and where that is documented publicly.
- Any suggestion that the product can quote, recommend, advise or bind on its own: That is either a misunderstanding of producer licensing or a willingness to let you carry the consequence. Neither is a vendor you want inside your licence.
- No answer on where data is stored, how long it is retained, or whether it trains a model: Two vendors on this entire roster publish data residency. Being asked is not unreasonable; being unable to answer is.
- Reluctance to name the contracting legal entity: Compare whatever they tell you to the footer of their own website. On this roster the trading name and the footer entity differ more than once.
- No written answer on what happens to your data if the integration is withdrawn: Export rights and an exit window belong in the contract, not in a reassurance.
- A trust centre you cannot open: Gated and customer-only trust centres are common and sometimes reasonable. But you are being asked to perform vendor due diligence you have a legal duty to perform, using documents you are not allowed to read. Push.
And the inverse — the signals that a vendor is worth your time. It states plainly that its product requires human oversight. It names its integrations specifically and says which are read and which are write. It publishes a certificate number rather than a badge. It publishes data residency. It tells you what it does not do. It describes a human-in-the-loop stage as a designed feature rather than a limitation. And when it cannot answer something, it says so instead of improvising. On this roster, the vendors that describe their own products most conservatively were consistently the ones whose public documentation held up best under checking, and that correlation is not an accident.
Limitations and What We Could Not Verify
This ranking has real limits and they belong on the page rather than in a footnote. Here is everything that constrains what you have just read.
Method limits
- Vendor discovery was constrained: Our open-web search budget was exhausted after four queries, so discovery was limited to candidates verifiable by direct fetch of their own domains. There may well be agency-facing vendors that are not on this sheet. Absence from this list is not a judgement about a vendor; it may simply mean we did not surface it.
- The recycled industry statistics are refused, not debunked: We could not complete origin-tracing for the widely quoted figures on renewal loss, producer time allocation, submission-processing improvement or claims leakage. We did not find their authors and we do not print them. Saying we debunked them would overstate what we did.
- Everything here is dated 23 August 2026: Trust pages change, prices appear, companies rename, dockets move and adoption counts rise. Re-check before you rely on any cell. The NAIC adoption figure in particular is explicitly a status-as-of number.
- We did not test any product: Nothing in this article is a performance assessment. We assessed what vendors publish about themselves and what public records show. That is a different exercise, and it is the only one we could do honestly.
Specific facts we could not establish
- Whether Colorado's quantitative-testing regime has extended beyond life insurance: The Division's announcement pages and the Secretary of State's CCR browse endpoints were not retrievable. We will not guess in either direction.
- The state-adoption count for NAIC Model Law #668: We could not find the adoption map, so we say the many states that have enacted it rather than naming a number.
- Post-2023 compliance deadlines under 23 NYCRR Part 500: Not retrievable from the page we fetched. Several widely circulated versions are wrong, so we print none.
- Ownership of Applied Systems, and Bold Penguin's parent: Neither is disclosed publicly in a form we could verify. Bold Penguin's is the one that matters commercially, and you should ask.
- The Applied Systems and Cytora corporate relationship: Applied's site features Cytora prominently; Cytora's own pages do not state the relationship in the content we retrieved. Do not assume an acquisition.
- Ascend's corporate identity, and whether its announced merger closed: The footer entity differs from the trading name, and an announced agreement to merge is not a completed merger.
- The exact date Roots Automation became Bevaya: The rename is confirmed by the vendor's own footer and a domain redirect; no dated announcement was retrieved, so we state no date.
- NowCerts' current branding, pricing and AI feature set, and Broker Buddha's entity and product availability: Both sites defeated direct fetch in different ways. Neither is ranked, and that is the correct outcome rather than a gap.
- Trust-page contents for Federato, Bevaya, Vertafore, Bold Penguin and Indico's certification list: Variously customer-gated, Cloudflare-gated or JavaScript-rendered. Where we could not read a page we say so rather than inferring what is on it.
- Whether any independent third-party evaluation of any vendor in this category exists: We checked every vendor's own site and found none across more than twenty companies. In this vertical that is not a rhetorical claim — it is a verified absence, and it is the reason this ranking is built the way it is.
None of this argues against buying. It argues for buying in the right order: work out which vendors you can actually purchase, then which workflows sit safely on the clerical side of the licensing line, then which vendors can produce the compliance artefacts your carriers and Model Law #668 will require of you, and only then which product you like the look of. The agencies that get value from this technology in 2026 are the ones that found out what they were permitted to automate before they found out what the demo could do.
And the boundary holds throughout, whichever vendor you choose. An agent may read, extract, reconcile, compare, populate and draft. A licensed producer sells, solicits, negotiates, advises and binds. Every state licenses the act, not the actor — and the licence, along with everything the tool does under it, is yours.
Want an Honest Read on Your Agency's Workflows?
Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. You leave with a workflow inventory across your AMS, accounting system, raters and carrier portals, a producer-licensing boundary map for each candidate workflow, a vendor artefact checklist, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.
Want an Honest Read on Your Agency's Workflows?
Book a free 60-minute discovery call. You leave with a workflow inventory, a licensing-boundary map for each candidate, a vendor artefact checklist, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1NAIC — Producer Licensing Model Act (#218), full text↗
- 2NAIC — Unfair Claims Settlement Practices Act (#900), full text↗
- 3NAIC — Insurance Data Security Model Law (#668), full text↗
- 4NAIC — Implementation of the AI Model Bulletin: state adoption map, status as of 6 August 2026↗
- 5NAIC — Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted 4 December 2023)↗
- 6NY DFS — Insurance Circular Letter No. 7 (2024), issued 11 July 2024↗
- 7NY DFS — Cybersecurity Resource Center (23 NYCRR Part 500)↗
- 8Minnesota Office of the Revisor of Statutes — Minn. Stat. § 60A.39, Certificates of Insurance↗
- 9Colorado General Assembly — SB 21-169 (enacted 6 July 2021)↗
- 10Federal Register — Executive Order 14365, 90 FR 58499 (16 December 2025)↗
- 11Office of the Law Revision Counsel — 15 U.S.C. § 1012 (McCarran-Ferguson Act)↗
- 12U.S. Bureau of Labor Statistics — OEWS, Insurance Sales Agents (41-3021), May 2025↗
- 13Preliminary Injunction Order, Dkt. 82, entered 11 February 2026 — Applied Systems v. PBC Consulting & Ardent Labs (N.D. Ill.)↗
- 14CourtListener — docket, Applied Systems, Inc. v. Ardent Labs, Inc., No. 1:25-cv-14251 (N.D. Ill., filed 21 November 2025)↗
- 15CourtListener — docket, Ardent Labs, Inc. v. Applied Systems, Inc., No. 1:26-cv-00591 (N.D. Ill., filed 19 January 2026)↗
- 16Applied Systems — Applied v. Comulate litigation page (vendor's own account)↗
- 17SEC EDGAR — Roper Technologies, Form 10-K Exhibit 21.1 (Subsidiaries), listing Vertafore, Inc.↗
- 18SEC EDGAR — CCC Intelligent Solutions, Form 8-K exhibit on the EvolutionIQ acquisition↗
- 19CCC Intelligent Solutions — completion of the EvolutionIQ acquisition, 6 January 2025↗
- 20SEC — In the Matter of Presto Automation Inc., Securities Act Release No. 11352 (14 January 2025)↗
- 21Quandri — security page (vendor-published SOC 2 Type 2 claim)↗
- 22Comulate — integrations page (vendor-published AMS and ERP list)↗
- 23Comulate — security page (vendor-published SOC 2 Framework alignment and US data residency)↗
- 24Qumis — security page (vendor-published SOC 2 claim and abstention-by-design description)↗
- 25Sixfold — Security Commitments page, cited for the absence of any SOC 2, ISO or DPA claim↗

