A regional P&C carrier decides to take its usage-based auto program from 12 states to 30. The rate filing team already knows what that means: Texas is file-and-use, New York wants prior approval with a full actuarial memorandum, and California treats telematics-derived driving scores as personal information under the CCPA regardless of what the enrollment screen said the driver consented to. Meanwhile the claims side is fighting a separate fire. Three systems (a legacy policy admin platform, a third-party claims management tool, and a spreadsheet the SIU team maintains by hand) feed the same loss ratio report with three different definitions of "open claim." And the base-rate model for the new states was built by an actuarial analyst who left eighteen months ago, no notebook, no data dictionary, a coefficient file nobody currently on staff can explain to a state examiner who asks how the model arrived at a number. That is the real shape of the problem when people ask about AI agents for insurance in 2026. It is not whether a chatbot can draft claims correspondence. It is whether anything can reconstruct 50 states of regulatory exposure and an unauditable model before a Department of Insurance examiner asks the question first.
Why ChatGPT and Cursor stop at the state line
ChatGPT or Claude.ai will give you a reasonable paragraph on what NAIC model laws generally require for a new personal auto filing. What neither will do is hold your specific block of business against 50 jurisdictions simultaneously and flag exactly where your product diverges from each one. Ask a generalist chatbot about your telematics program and California privacy law, and you get a correct but generic answer about the CCPA. It will not cross-reference that answer against your actual data flow (GPS pings every three seconds, hard-braking events, phone-use detection while driving) or notice that Illinois' BIPA arguably reaches driving-behavior biometric inference the same way it reaches a fingerprint scan. Insurance compliance is combinatorial: product times state times data type times filing status. A generalist chatbot answers one cell of that matrix per prompt. It never holds the whole matrix, because holding it requires systematic recon across your actual product and data flows, not a single well-phrased question.
Cursor and GitHub Copilot solve a completely different problem and are close to irrelevant here. They speed up the engineers building the rating engine that ingests claims and underwriting data, but the people who need this work done, compliance officers, actuaries, product managers preparing a rate filing, are mostly not writing code at all. And even for the engineers who are: autocomplete has no model of the regulatory constraint that should have gated a database join before it was written. It will happily suggest the SQL to pull driver location history into a scoring feature. It will not flag that the field triggers a state-specific consent requirement, because that is not a code-completion problem, it is a compliance-inventory problem, and no autocomplete tool tracks compliance inventory.
The mismatch is structural, not a matter of the prompt being insufficiently clever. What insurance needs here is inventory, cross-jurisdictional assessment, and drafting, held as state across a 50-way matrix and produced as a report an examiner or an underwriting committee can actually read. A single-shot chatbot answer does not retain that state. It answers the question in front of it and forgets the other 49 states exist. Getting this right requires an agent purpose-built to hold that structure and work through it systematically.
Shield maps the exposure; Clean and Lens keep the data and models honest
Shield is Tonone's regulatory risk advisor, built to flag exposure before it becomes a fine rather than after. For an insurer, that means treating every new state, every new data field in a rating model, and every new product feature as a compliance question to be answered before launch, not litigated after a market conduct exam. Shield does not replace your outside counsel or your compliance department. It does the systematic first pass, the recon and matrix-building that would otherwise consume a paralegal and a compliance analyst for two weeks, and hands back a structured assessment your legal team reviews and signs off on.
Tonone's Shield surveys a product's actual features and data flows for regulatory exposure before it looks at a single state's statute, so the assessment that follows is grounded in what the product actually does.
Surveying exposure with shield-recon
Before Shield can assess anything state by state, it needs an accurate inventory of what the product actually collects and does. The shield-recon skill surveys the described product's features and data flows: what data is captured (location, driving events, biometric-adjacent signals), where it is stored, what third parties touch it (a telematics vendor, a reinsurer, a claims adjuster network), and what existing disclosures or consent flows are already in place. This step matters because most compliance failures in insurance trace back to an inaccurate inventory, not a misread statute. Legal teams argue about the wrong question when nobody has first confirmed what data the product genuinely touches.
Assessing the new-state matrix with shield-assess
Once the recon is grounded, shield-assess runs the regulatory exposure assessment for the described product against a specified geography, or a batch of them. For a multi-state expansion, that means running the same product description against each target state's insurance code, privacy statute, and filing regime, and returning a structured comparison: which states are file-and-use versus prior-approval, which have a telematics-specific data statute on the books, which treat driving-behavior data as sensitive personal information requiring separate consent, and where the product as currently built creates exposure that has to be remediated before the filing goes in. This is the step that turns "we think we're fine in most states" into a specific, state-by-state answer with citations, which is what a rate filing team and outside counsel actually need to sign off on a launch.
Drafting the regulator response with shield-respond
The exposure map is not the end of the workflow. shield-respond drafts the regulator-facing communication, a response letter to a Department of Insurance information request, a market conduct exam answer, or a filing cover letter that explains a novel rating factor in plain, defensible language. This is where compliance teams lose the most time under deadline pressure: a DOI request lands with a two-week response window, and the first draft usually has to synthesize the same product and data facts Shield already inventoried. Having that draft already grounded in the shield-recon inventory and the shield-assess matrix means the compliance team is editing and refining a response, not starting from a blank page under a ticking clock.
Clean and Lens close the loop Shield surfaces
Regulatory exposure and data quality are not separate problems in insurance, they are the same problem viewed from two angles. Tonone's Clean, the data quality engineer, runs clean-recon to audit the claims pipeline for exactly the kind of silent data loss and inconsistent definitions that turned "open claim" into three different numbers across three systems, then clean-validate designs the validation pipeline (schema checks, range validation, quality metrics) that standardizes the definition going forward so the loss ratio Shield's assessment cites is actually correct. Lens, the data analytics and BI engineer, runs lens-audit to reconstruct what an abandoned underwriting model was actually measuring when the original analyst left no documentation behind, reviewing what exists, what is undefined, and what has to be rebuilt before an examiner can be shown a coherent audit trail. Neither Clean nor Lens replaces Shield's regulatory judgment. They make sure the numbers underneath Shield's assessment, and underneath the model an examiner will eventually ask about, are ones your team can actually defend.
A worked example: 8 new states for a telematics program
Meridian Mutual (a composite, not a real carrier) writes $340M in personal auto premium and is licensed in 12 states. Its usage-based auto product, DriveSense, has performed well enough in its home states that the product team wants to add 8 more within the next two underwriting cycles, targeting roughly $60M in incremental premium within three years. Before the filing team touches a SERFF submission, Shield runs shield-recon against DriveSense's actual feature set: continuous GPS location, hard-braking and hard-acceleration event capture, phone-motion-while-driving detection, and a monthly mileage-based rating adjustment shared with a third-party telematics vendor under a data processing agreement. That inventory becomes the input to shield-assess across the 8 target states.
The assessment output looks roughly like this for a sample of the target states, condensed here to the fields that actually change the launch timeline:
Shield, DriveSense Multi-State Exposure Assessment
Recon basis: continuous GPS, braking/accel events, phone-motion detection,
monthly mileage rating, third-party telematics vendor DPA.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
State Filing type Data statute overlay Flag / next step
───────────────────────────────────────────────────────────────────────
TX File-and-use None telematics-specific Low. Launch-ready
OH File-and-use None telematics-specific pending SERFF.
NY Prior approval Insurance Law 2612 telematics Med. Actuarial memo
disclosure requirement needs explicit
consent language.
CA Prior approval CCPA: driving score = personal High. Consent flow
info regardless of consent must be reworked;
framing at signup opt-out mechanism
currently missing.
IL File-and-use BIPA exposure, biometric- High. Legal review
adjacent reading of behavior needed before IL
inference argued by plaintiffs' filing; precedent
bar in 2 recent suits unsettled.
───────────────────────────────────────────────────────────────────────
Recommendation: File TX/OH immediately (S). Hold NY for actuarial memo
revision (M, ~3 weeks). Escalate CA and IL to outside counsel before
any filing date is set (L, exposure not yet quantified).While Shield's matrix is being reviewed by legal, shield-respond drafts the New York actuarial memo language addressing Insurance Law 2612's telematics disclosure requirement, so the actuarial team is revising a grounded draft rather than starting from the statute text. In parallel, because the CCPA flag depends partly on whether the underlying rating factor is even calculated on clean data, clean-recon audits the claims and telematics ingestion pipeline and confirms the loss-ratio discrepancy: the legacy policy admin system closes a claim on payment, the third-party claims tool closes it on file closure two weeks later, and the SIU spreadsheet uses neither definition consistently. clean-validate specs the fix, a single canonical "claim status" schema with range and consistency checks, so the loss ratio Shield's California consent-cost analysis relies on is the same number the actuarial team is using.
Tonone's Clean designs the data validation pipeline (schema checks, range validation, quality metrics) that turns three conflicting claim-status definitions into one number every downstream team can trust.
Last, because the DriveSense base rate for the new states leans on a model built by an actuarial analyst who is no longer with the company, lens-audit reviews what currently exists: the coefficient file, whatever comments survive in the last notebook version, the dashboards that reference the model's output, and who actually consumes them. The audit comes back with a specific gap list, three of the seven rating factors have no documented formula, the training window is unclear, and two dashboards downstream are quietly using a stale version of the output. That gap list becomes the actuarial team's rebuild punch list, not a vague warning that "documentation is missing." Six weeks later, when a DOI examiner in New York asks how the base rate factor for hard-braking frequency was derived, the answer exists in writing, because Shield's assessment flagged the exposure early enough for Lens to close the documentation gap before the filing, not after the examiner asked.
Before filing in a new state, run /shield-recon against your product's actual data flows first, not the statute. Most multi-state compliance failures in insurance trace back to an inaccurate inventory of what the product collects, not a misread regulation. Get the inventory right, then let shield-assess do the state-by-state comparison.
Shield vs the alternatives, for insurance specifically
None of this is a fair fight in the sense of Shield trying to out-write a chatbot's compliance summary. It is a fight over whether the tool holds structure: a 50-state matrix, a claims-quality gap list, an orphaned model's documentation debt. Generalist tools and autocomplete tools were not built to hold that structure, and it shows the moment the question moves from "what does the CCPA say" to "where exactly does our product create exposure under it."
| Capability | Tonone | Generalist chatbot | Cursor / Copilot |
|---|---|---|---|
| State-by-state exposure matrix for a real product | Yes, shield-recon inventories the product, shield-assess runs it against each target state | No, answers one state's general rule per prompt, no product-specific matrix | No, not a compliance function at all |
| Drafting regulator or DOI response letters | Yes, shield-respond drafts grounded in the same product inventory Shield already built | Partial, generic letter template, not grounded in your specific data flows | No |
| Reconciling claims data across multiple source systems | Yes, clean-recon audits the pipeline, clean-validate specs the standardized schema | No, cannot access or reconcile your actual claims systems | No, autocomplete has no data-reconciliation function |
| Reconstructing documentation for an orphaned underwriting model | Yes, lens-audit reviews what exists and produces a specific gap list | No, no visibility into your model artifacts or dashboards | No |
| Grounding compliance work in the actual product, not the statute alone | Yes, recon-first workflow before any state assessment runs | No, answers from statute text, not your product's data flows | No, not applicable to compliance work |
Tonone's Shield exists to flag regulatory exposure before it becomes a fine, not to draft a generic compliance summary after the fact.
Install and try
Tonone is free and MIT-licensed. Install it once and Shield, Clean, Lens, and the rest of the Tonone team are available in your Claude Code session. You pay only for the Claude Code token usage during the work itself.
1. Add to marketplace
2. Install Shield
Frequently asked questions
What does Tonone's Shield do for insurance companies?+
Shield is Tonone's regulatory risk advisor. For insurers, it inventories a product's actual data flows with shield-recon, assesses regulatory exposure against specific states or geographies with shield-assess, and drafts regulator-facing communication like DOI response letters with shield-respond.
Can AI agents help with multi-state insurance regulatory compliance?+
Yes. Tonone's Shield is built specifically to hold a full state-by-state exposure matrix, comparing filing type, data privacy overlays, and telematics-specific statutes across every target state for a described product, rather than answering one state's rule at a time the way a generalist chatbot does.
How is Shield different from asking ChatGPT about insurance regulations?+
ChatGPT answers from general statute knowledge, one question at a time, with no visibility into your product's actual data flows. Shield first inventories your product's real features and data flows with shield-recon, then runs that inventory against each target state's specific requirements with shield-assess, producing a grounded, product-specific matrix instead of a generic summary.
What AI agent fixes claims data quality issues across multiple systems?+
Tonone's Clean agent handles this. clean-recon audits an existing claims pipeline for missing validation, silent data loss, and inconsistent definitions (such as three systems disagreeing on what counts as an 'open claim'), and clean-validate specs a standardized validation pipeline with schema checks, range validation, and quality metrics.
How do you audit an underwriting model when the person who built it is gone?+
Tonone's Lens agent runs lens-audit, which reviews the model's existing artifacts, dashboards, and definitions to find exactly what is undocumented or undefined, producing a specific gap list the team can rebuild against rather than a general warning that documentation is missing.
Is Tonone free to use for insurance compliance work?+
Yes. Tonone is MIT-licensed and free. You install it once and get Shield, Clean, Lens, and the rest of the Tonone agents in your Claude Code session, paying only for the Claude Code token usage during the actual work.
Can Shield draft a response to a Department of Insurance examination request?+
Yes. The shield-respond skill drafts regulator response letters and DOI communications, grounded in the same product and data-flow inventory built during shield-recon, so the compliance team edits a specific draft instead of starting from a blank page under deadline pressure.
What is the difference between shield-recon and shield-assess?+
shield-recon surveys a product's actual features and data flows to build an accurate inventory of what it collects and does. shield-assess then runs that inventory against a specified state or geography to produce the actual regulatory exposure assessment. Recon comes first because most compliance failures trace back to an inaccurate inventory, not a misread statute.