Level 3 taught you to run AI-assisted agency work as an operation many people repeat across many accounts and carriers. Level 4 asks you to govern it across the whole agency, and to defend what you decided to a department of insurance, a carrier's audit team, an errors-and-omissions insurer and your clients. It is written for agency principals and owners, designated responsible licensed producers, agency executives, compliance and risk leaders, heads of personal lines, commercial lines and life and benefits, and leaders of agency networks and clusters who own AI policy for a distribution business.

Modules one to four place accountability and map what binds the agency. Module one explains why an agency of producers, staff, vendors and carriers spreads responsibility for AI until nobody holds it, what producer licensing law places on the business entity and its designated producer, what regulators tell insurers about third-party AI, read only as an analogy, and what no tool, vendor or carrier can hold. Module two writes a governance programme sized to the agency, with a permitted-use inventory, decision rights, stop authority, supervision and a review cycle, ready for the questions carriers ask under their own written AI programmes and organised, if the agency chooses, under voluntary frameworks never presented as law. Module three keeps the decision record, the AI inventory and its version history, sets retention by the record-keeping rules that already apply, and keeps the record alive through staff turnover, tool retirement and a sale or perpetuation of the agency. Module four builds the regulatory map: state insurance and privacy law, the FCC ruling on AI voices, the Medicare Advantage agent and broker rule, FINRA's notice for registered persons, the Colorado and Texas AI statutes kept apart from insurance regulation, and the carrier column, showing how carrier obligations reach the agency.

Modules five to seven cover what the agency buys. Module five decides when an AI supplier is a third-party service provider, a privacy service provider or a business associate, runs a four-domain assessment of data handling, security, testing evidence and change management, and tells an answer from an evasion. Module six reads provider claims, benchmarks, experiments, working papers and regulator surveys for what was measured, by whom and on what data, and designs an acceptance test the principals set before seeing results. Module seven contracts for data use and training, audit rights and vendor breach notice, model and terms changes with re-approval, and a sunset or exit that returns client data and proves its deletion.

Modules eight and nine handle security and impersonation from the defender's side. Module eight places each AI tool inside the written information security programme under the state data security law as enacted, explains New York Part 500 with its limited exemption, adds the risks AI introduces, and uses NIST CSF 2.0 and the FTC Safeguards Rule as comparison checklists. Module nine ranks the instructions most exposed to synthetic voice, video and text, writes call-back and out-of-band verification staff follow under time pressure, chooses authentication a deepfake cannot pass, and reads the FCC ruling for what it does and does not govern.

Modules ten and eleven cover clients and money. Module ten reconciles agency AI use with privacy notices, health information authorizations and Medicare and Marketplace consents, decides who owes the reasons for an adverse underwriting decision an algorithm shaped, prepares for Colorado's explanation duty arriving in 2027, and answers a client who restricts AI use honestly. Module eleven shows how free and ranking tools can bend a producer's objectivity, and applies annuity best interest, compensation disclosure and rebating rules as states enact them.

Modules twelve to fourteen make the agency answerable. Module twelve designs independent verification, identifies the records examiners and carrier auditors could ask for, explains how regulators are preparing to examine insurers' AI, and builds an evidence pack a carrier can use when its own examiner asks. Module thirteen treats producers' objections as evidence, briefs staff with findings that cut both ways and measures adoption honestly. Module fourteen sequences the programme from low-risk uses outward, reviews each use before deployment and on a schedule, counts what could get worse, and prepares the capstone: an AI Governance Programme, Scenario Defence and Ownership Report for a fictional agency.

Statements of authority say whom they bind: insurance is regulated by the states, an NAIC model binds nobody until a state enacts it, instruments addressed to insurers never impose duties on an agency, codes bind their members and voluntary frameworks bind no one. Where authority is unsettled, the level teaches a method of reasoning rather than a confident answer. It ships with a printable workbook and ten templates, and the examination draws forty scenario questions from a reviewed bank.

Everything here is professional education. It is not legal, regulatory or coverage advice, and it does not replace producer licensing, carrier appointments, counsel or the insurance, privacy and consumer protection laws of any state. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It is not a licence, an appointment or a line of authority, carries no continuing-education hours, and satisfies no state, CMS or carrier training requirement.