Blog

NAIC MODEL BULLETIN-USE OF ARTIFICIAL INTELLIGENCE SYSTEMS BY INSURERS

Written by Diane Nesbit, CPA | 20 Aug 2026

NAIC Model Bulliten: Use of Artificial Intelligence Systems By Insurers

August 20, 2026

Article Summary

The National Association of Insurance Commissioners (NAIC) Membership adopted the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers during the 2023 Fall National Meeting. As of April 1, 2026, there were 25 states that had adopted the bulletin and 4 states that have insurance specific regulation and guidance covering artificial intelligence use by insurers. The NAIC model bulletin makes one thing clear: regulators are not waiting for new laws before examining how insurers use AI. If AI influences underwriting, pricing, claims, fraud detection, marketing, or customer interactions, regulators expect insurers to have governance, oversight, documentation, and controls in place today.

This article breaks down what the NAIC model bulletin means for insurance organizations, where regulators are likely to focus their attention, and how insurers can prepare before questions start arriving from examiners.

AI Innovation Is Moving Fast. Regulators Expect Governance to Keep Up.

AI is already embedded across the insurance lifecycle. It helps identify fraud, streamline claims, refine underwriting, automate customer service, and personalize products.

The NAIC recognizes those benefits.

What regulators are focused on is the downside: inaccurate decisions, unfair discrimination, weak oversight, data vulnerabilities, and AI systems that nobody can fully explain.

The bulletin makes it clear that insurers remain responsible for every consumer-facing decision, regardless of whether that decision was made by an employee, a predictive model, or a third-party AI platform.

In other words, "the algorithm made the decision" will not be a regulatory defense.

The Biggest Shift: AI Governance Becomes a Formal Expectation

The centerpiece of the bulletin is the expectation that insurers establish a written Artificial Intelligence Systems Program, or AIS Program.

Think of it as an enterprise-wide governance framework for AI.

The NAIC is not prescribing a single template. Instead, regulators expect insurers to create controls that match their level of AI use and the potential harm consumers could experience if something goes wrong.

For some insurers, that may mean strengthening existing enterprise risk management and model governance processes. For others, it may require creating entirely new oversight structures.

The message is straightforward: if AI influences regulated insurance decisions, governance should be formalized and documented.

Every Stage of the Insurance Lifecycle Is in Scope

Many organizations think about AI primarily in underwriting or pricing.

The bulletin takes a much broader view.

Regulators expect insurers to evaluate AI use across:

  • Product development
  • Marketing and distribution
  • Underwriting
  • Rating and pricing
  • Policy servicing
  • Claims administration
  • Fraud detection

The expectation extends beyond internally developed models.

Third-party software, vendor platforms, external datasets, and embedded AI capabilities fall under the same scrutiny.

If a vendor's AI creates a compliance problem, regulators will still look to the insurer for answers.

Documentation May Become Your Greatest Risk Control

One theme appears repeatedly throughout the bulletin: documentation.

Regulators may request evidence showing how an insurer:

  • Approved AI systems for use
  • Evaluated model risk
  • Tested for bias and unfair discrimination
  • Monitored accuracy and performance
  • Addressed model drift
  • Governed third-party vendors
  • Protected consumer data
  • Escalated issues when problems were identified

Most insurers already maintain documentation around actuarial models, internal controls, and compliance processes.

The challenge is that many AI initiatives originated outside traditional governance frameworks. Data science teams often move quickly. Business units adopt new tools. Vendors continuously embed AI functionality into existing platforms.

Regulators are signaling that informal oversight may no longer be enough.

If governance activities occur but cannot be demonstrated, examination findings become much more likely.

Third-Party AI Is Not a Shortcut Around Accountability

Some of the bulletin's strongest language focuses on third-party vendors.

That is not surprising.

Many insurers now rely on external providers for predictive analytics, automated decision engines, consumer data, and generative AI tools.

The NAIC expects insurers to perform due diligence before adopting those solutions and maintain ongoing oversight after implementation.

That includes evaluating:

  • Vendor controls
  • Data sources
  • Bias testing practices
  • Audit rights
  • Security protections
  • Cooperation obligations during regulatory reviews

Most firms already perform financial and cybersecurity due diligence on critical vendors.

AI governance may soon become another required layer of that process.

Model Drift Is No Longer Just a Data Science Problem

A model that performed well last year may not perform well today.

The bulletin specifically highlights model drift and ongoing validation requirements.

Economic conditions change. Consumer behavior changes. Data sources evolve.

An AI model trained on historical information can gradually become less accurate over time, creating the risk of inappropriate underwriting decisions, pricing outcomes, or claims determinations.

Regulators expect insurers to monitor these changes continuously, not simply validate models during initial implementation.

For organizations managing dozens or even hundreds of predictive models, this can become a significant governance challenge.

Internal Audit Has a Seat at the AI Table

One of the most important takeaways for boards, executives, and audit leaders is the bulletin's repeated emphasis on internal controls and audit functions.

AI oversight is not solely an IT responsibility.

Compliance, legal, risk management, actuarial, operations, internal audit, and executive leadership all have roles to play.

The bulletin envisions governance structures that include cross-functional oversight, defined accountability, monitoring processes, escalation procedures, and ongoing reporting.

For many insurers, internal audit may become one of the primary lines of defense in assessing whether AI governance is operating as designed.

Where Compliance Ends, the Real Work Begins

The bulletin does not create entirely new legal obligations.

Instead, it reinforces an important principle: existing insurance laws still apply when AI is involved.

Insurers must continue to avoid unfair trade practices, unfair discrimination, improper claims handling, and other conduct prohibited under state insurance laws.

What has changed is the regulator's expectation for proving that AI systems are being governed appropriately.

That means organizations should begin asking questions now:

  • Do we have a documented inventory of AI systems and predictive models?
  • Can we explain how decisions affecting consumers are made?
  • Are we testing for bias, drift, and accuracy?
  • Do we have adequate oversight of third-party AI vendors?
  • Would we be ready if regulators asked for documentation tomorrow?

For insurers using AI across underwriting, claims, pricing, or customer interactions, those questions are quickly moving from best practice to regulatory expectation.

Need help evaluating your AI governance framework? Larson & Company works with insurance organizations that need practical risk management, compliance, internal audit, and governance solutions that stand up to real regulatory scrutiny.  Please reach out to Larson Insurance Team for additional guidance.

Frequently Asked Questions

Does the NAIC bulletin ban the use of AI in insurance?

No. The bulletin explicitly recognizes the benefits of AI and encourages innovation. The focus is on governance, risk management, transparency, and compliance with existing insurance laws.

Do the expectations apply only to generative AI?

No. The bulletin covers a broad range of AI technologies, including predictive models, machine learning systems, automated decision tools, and generative AI applications.

Are third-party AI vendors responsible for compliance?

Vendors have responsibilities, but regulators will ultimately hold insurers accountable for decisions that affect consumers. Using a third-party platform does not transfer regulatory responsibility.

What insurance functions are most likely to receive scrutiny?

Underwriting, pricing, claims handling, fraud detection, marketing, and consumer communications are all areas specifically discussed in the bulletin because they directly affect policyholders and applicants.

What should insurers do first?

Start with an inventory. Identify where AI, predictive models, machine learning, and automated decision tools are being used throughout the organization. Most governance gaps become visible once insurers understand the full scope of their AI footprint.