FOR NEW YORK INSURANCE AGENCIES

AI is already in your agency.

Many agency owners I speak with had no idea their staff was already using AI tools, and no idea of the risk that comes with having no use policy to follow.

Walter Contreras
Walter Contreras
I wrote this guide myself.
New York State approved cybersecurity instructor
CEO of Motiva Networks, Garden City
Acting CISO for the agencies we serve
Everything in it comes out of work I do inside agencies like yours.
Lead capture form goes here
(build with Webflow's native Form element)

DFS has written to agencies about AI twice. And every April 15th you sign your name saying you have it handled.

Neither one created a new rule. People hear that and relax. They shouldn't — no new rule means it was already in there, and you have been signing for it every April since.

OCT 2024
Cybersecurity Risks Arising from Artificial Intelligence
The AI inside your agency. Deepfakes, client information getting out, and AI showing up through vendors you already use. All of it already sits under Part 500.
MAY 2026
Heightened Cybersecurity Risks Associated with Frontier AI Models
The AI being used against your agency. The same tools you have, the hackers have too — and they are finding weaknesses faster than before.
APRIL 15
You certify material compliance every year. Can you show the proof?
Part 500 makes you certify, and you have to be able to produce the documentation behind it. AI risk now sits inside that certification. Most agency owners I sit with cannot produce a single page on it.

Four steps to get your AI use ready for April 15.

You don't need your IT company for this. Most of them won't know what this is.

01
Find out what your employees are using
Ask them. Don't audit them. You'll hear more than you expect.
02
See what they're putting into it
Client applications, tax documents, claim files. That's PII, and it's the part that matters.
03
Put an AI policy in place
One page, plain language, handed out at your next team meeting.
04
Plan how your agency uses AI on purpose
This is where we come in. Our AI Exposure Assessment shows you what's exposed underneath the tools your team is already using, and the policy template comes with it.

Two ways to find out

One you run yourself this week. One I run for you.

THE GUIDE · FREE DOWNLOAD
The Agency AI Playbook
The four questions that surface what your team is actually using
A one-page AI use policy you can hand out at your next meeting
What DFS has written about AI since 2024, in plain English

You run it yourself. About twenty minutes, and it starts by asking your own team, which costs you nothing.

Download above ↑
THE ASSESSMENT · COMPLIMENTARY
The AI Exposure Assessment
Client files sitting unencrypted
Passwords from your agency already out on the dark web
Someone's everyday email account holding admin rights over your whole Microsoft 365 — which is exactly where Copilot pulls from

Takes your team a few minutes. I walk you through what we find, live, in about 20 minutes. I don't email the findings — if somebody's already sitting in your mailbox, a list of your gaps is the last thing you want in there.

Request an assessment
If I waste your time, I'll donate $100 to your favorite charity.

Your IT company keeps you running. That is not the same as being compliant with DFS.

Most IT providers are built for general small business. An agency under Part 500 is not a general small business.

TAUGHT, NOT JUST SOLD
A New York State approved cybersecurity instructor

I teach this material to the industry. When I sit down with you about Part 500, it is the same material I stand up and teach.

AUDITED OURSELVES
SOC 2 Type II

We are examined on the same class of controls we ask you to hold. Report available on request.

25 YEARS
Independent agencies, not general small business

Two and a half decades inside agencies — the systems they run on, the way they actually work, and what regulators ask them for.

I'm not here to tell you AI is good or bad. It's already in your agency. You should know what it's doing.

Walter Contreras — New York State approved cybersecurity instructor, Motiva Networks

Find out what other New York agencies already learned.

Twenty minutes to read. And if you'd rather I walk you through it in person or on Zoom, just say so.

“Cavallino Risk would not have survived the economic turmoil of the great recession or the disruptive technology that has occurred in the retail insurance marketplace without the support of Motiva.”

Frank Caponi
President, Cavallino Risk Management

“The thing that sets Motiva apart is that they shine through and are there for you when needed.”

William Libardi
President, Libardi Service Agency

“They follow up to make sure the issues were handled to our satisfaction; I have never had a tech company do that.”

Robert Stone
Managing Director, Stone Insurance
Get the Playbook