September 3, 2026

11 min read

What the NAIC AI Model Bulletin Requires From Insurers and Their AI Vendors

What the NAIC AI Model Bulletin actually is (and isn't)

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is guidance, not federal law, and it only has teeth in a state once that state's insurance department formally adopts it. The National Association of Insurance Commissioners adopted the model bulletin in December 2023, and it tells carriers and MGAs how regulators expect them to govern AI used in underwriting, claims, pricing, and marketing.

Two things trip people up here. First, "model bulletin" means template, not statute. The NAIC doesn't regulate insurers directly; state insurance departments do. So the bulletin only becomes operative when a state issues its own version, which most states have done close to verbatim. Second, it's principles-based rather than prescriptive. As WaterStreet Company points out, it doesn't hand you a specific bias-testing methodology or a required statistical threshold. It tells you that you need a governance structure, that you need to test for unfair discrimination, and that you're responsible for what your AI does. How you satisfy that is left to you, which is either freeing or terrifying depending on how prepared your organization is.

That ambiguity is the whole story if you're building or buying AI for a regulated carrier. A prescriptive rule is easy to check off. A principles-based one means an examiner is going to ask you to explain your reasoning, and "the vendor said it was fine" is not reasoning.

How many states have adopted the NAIC AI Model Bulletin?

More than 20 U.S. jurisdictions have adopted or closely aligned with the model bulletin as of 2025-2026 reporting, and the count keeps rising. Quarles reported "nearly half of states" had adopted it by June 2024, and adoption has continued state by state since, with fresh activity flagged repeatedly through 2025 and into 2026 as more departments issue their own bulletins.

If you write insurance in a single state and that state hasn't adopted the bulletin, you might reasonably think you're off the hook. Don't build a compliance program on that assumption. Most carriers and MGAs are licensed across multiple states, and the moment you sell in even one adopting state, that state's version applies to the business you write there. Multi-state carriers end up governed by a patchwork where some states have adopted the bulletin, some have their own separate AI insurance rules (Colorado's AI-specific insurance regulation predates the NAIC bulletin and runs alongside it), and some have neither yet. The practical response most compliance teams land on is to build one AIS Program to the highest common standard and apply it everywhere, rather than maintaining 40 different governance postures. It's cheaper to build once correctly than to patch state by state later, and it's the same logic we've laid out for teams tracking state-level AI compliance requirements more broadly.

What a written AIS Program actually requires

The bulletin requires every insurer using AI systems in consequential decisions to maintain a written AI Systems (AIS) Program, and that document has to name real people and real processes, not aspirational language. Specifically, regulators expect an accountability structure that spans actuarial, legal, compliance, data science, and underwriting functions, with genuine oversight from senior management or the board, not a rubber stamp buried in a risk committee's annual agenda.

Inside that structure, the bulletin asks for three things that matter architecturally, not just administratively:

  • Risk-tiering by potential consumer harm, so a claims-denial model gets more scrutiny than an internal scheduling tool.

  • Validation, testing, and retesting for bias, data quality, and unfair discrimination, done before deployment and on an ongoing basis after.

  • Documentation that a regulator could pick up cold and understand what the system does, what data trains it, who owns each decision, and what happens when it's wrong.

That last point is the one every legal-alert breakdown mentions and none of them operationalize. "Documentation" sounds like a paperwork exercise until you try to produce it for a system you didn't design to produce it. If your underwriting model runs inside a vendor's black box and outputs a score with no reasoning trail, you can't retroactively generate the audit history the AIS Program wants. You either negotiate that access into the vendor contract up front, or you build the system so the documentation is a byproduct of how it runs, not a report someone writes after the fact once a year.

The NAIC's testing language echoes something insurers outside the AI-native world may already recognize: the NIST AI Risk Management Framework's cycle of map, measure, manage, and govern. If your compliance team already speaks NIST, the bulletin is a familiar shape wearing a different label. That's a useful bridge when you're explaining this to a board that's heard of NIST but not the NAIC's AI work.

The third-party vendor problem: why your vendor's gaps become your exam findings

The bulletin makes insurers fully responsible for AI systems built or operated by third-party vendors and MGAs, and it doesn't matter that you didn't write the code. If a vendor's underwriting model produces a discriminatory outcome, the exam finding lands on the carrier's desk, not the vendor's. That single fact changes how vendor selection should work.

Insurers are expected to run genuine due diligence before onboarding an AI vendor: understanding what data trains the model, what testing the vendor has done for bias and accuracy, and what happens when the model's outputs drift. Contracts need audit rights baked in, meaning the insurer can actually inspect the vendor's testing records and methodology, not just take a marketing one-pager at face value. And that oversight has to be ongoing, not a one-time intake questionnaire that gets filed and forgotten. Most vendor contracts written before 2023 have none of this. If you're renewing an AI vendor relationship this year, that renewal is the moment to fix it, and it's worth working from a structured list rather than winging it. We put together an AI vendor risk assessment checklist for exactly this conversation, because "what should I ask before I sign" is a different exercise than "what should I ask before I renew," and the bulletin makes both questions mandatory for regulated carriers now.

Here's the part vendors won't volunteer: a lot of AI underwriting and claims tools on the market today were built for speed to market, not audit defensibility. They can tell you the model's accuracy on a holdout set. They usually cannot tell you why a specific policyholder was scored the way they were, which is exactly the question an examiner asks when a complaint triggers a market conduct exam.

What the NAIC AI Systems Evaluation Tool means if you're ever examined

The AI Systems Evaluation Tool is NAIC's pilot mechanism for standardizing how state regulators actually test insurers against the model bulletin during market conduct exams, and its existence is why "principles-based guidance" is becoming a live audit rather than a paper exercise. As Holland & Knight describes it, the tool gives participating state insurance departments a structured way to evaluate a carrier's high-risk AI systems, the data sources feeding them, and the governance framework wrapped around them, rather than leaving each examiner to improvise.

Practically, that means an examiner is likely to ask for specific artifacts: the written AIS Program, the risk tier assigned to a given system, the testing and retesting records, the vendor due diligence file, and evidence of board or senior management oversight. Plante Moran's read on how the bulletin is evolving is that enforcement is moving from "do you have a program" toward "does your program actually work," which is a meaningfully harder bar. A binder with a policy in it doesn't survive that kind of scrutiny. Live testing records, versioned model documentation, and a demonstrable decision trail do.

This is also where the low search competition around this topic makes sense. It's a genuinely new compliance surface. The people searching for it right now, general counsel, compliance officers, heads of ops at carriers and MGAs, are trying to figure out what an exam actually looks like before they're sitting across from an examiner asking for a document they don't have.

Build, buy, or augment: what the bulletin means for your AI architecture decisions

The bulletin doesn't ban any particular architecture, but it makes the audit trail a hard requirement, and audit trails are far easier to produce when you own the system than when you're renting a black box. This is the piece every legal-alert breakdown skips, because law firms tell you what the rule says, and nobody on that SERP has actually had to build the thing the rule is asking for.

A SaaS underwriting AI you buy off the shelf is usually optimized for the vendor's roadmap, not your exam file. You get an API and a score. Getting the reasoning behind that score, the training data lineage, and version history of every model update usually means asking the vendor nicely and hoping their contract allows it. Compare that to a system built (or built with real audit access negotiated in) where every decision logs its inputs, the model version that produced it, and a confidence score that routes low-confidence or high-risk cases to a human before anything touches a policyholder. That second pattern isn't more expensive to build correctly from day one; it's expensive to retrofit after the fact.

This is also why self-hosting matters more in insurance than in most industries. Genta AI Solutions runs open-source models on a client's own infrastructure with zero data retention for exactly this kind of regulated, data-sensitive work, because when an examiner asks "where does this data go and who else can see it," the honest answer needs to be "nowhere, and no one." That's a much easier compliance conversation than explaining a third-party API call to a model provider you don't control.

None of this means every carrier needs to build everything in-house. It means the build-versus-buy decision for AI in insurance has to weight auditability as a first-class requirement alongside cost and speed, the same way a carrier weighs solvency risk in a reinsurance decision. We've written about where AI agent projects in carriers actually stall operationally in our piece on AI agents in insurance, and the regulatory floor described here is exactly what those projects have to clear before they scale past a pilot. If you're also thinking about the liability side of this, meaning how your architecture choices affect what an insurer will charge you to cover your own AI risk, that conversation is the mirror image of this one and we cover it in our AI liability insurance guide.

A practical readiness checklist before your next exam

Most compliance leads don't need another 40-page framework. They need to know what to fix this quarter. Here's the condensed version we walk clients through:

  • Confirm which states you write business in have adopted the bulletin, and build your AIS Program to the strictest version among them rather than maintaining separate postures per state.

  • Write down, in one document, who owns AI governance across actuarial, legal, compliance, data science, and underwriting, and confirm the board or senior management actually reviews it, with a paper trail showing they did.

  • Risk-tier every AI system touching underwriting, claims, or pricing by potential consumer harm, and prioritize testing and documentation on the highest tiers first.

  • Pull every AI vendor contract and check for audit rights. If a vendor won't grant you access to their testing methodology and data lineage, that's a renewal conversation, not a footnote.

  • Run a mock documentation request: pretend an examiner asked for testing records, model versioning, and a decision trail for your top three AI systems today, and see how long it takes to assemble. If it takes weeks, that's your real risk exposure, not the bulletin's text.

If you're working through this decision, this is exactly what our Discovery phase at Genta AI Solutions maps out before we build or audit anything, and if you want a second set of eyes on where your current AI systems stand against this, our enterprise AI page outlines how we approach it, or we're happy to compare notes.

Frequently asked questions

What is the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers?

It's a template regulatory bulletin the NAIC adopted in December 2023 that tells state insurance departments what to require of carriers and MGAs using AI. It requires a written governance program, risk-tiered testing, and third-party vendor accountability, but only becomes legally binding once a state formally adopts its own version.

How many states have adopted the NAIC AI Model Bulletin, and does it apply if my state hasn't adopted it yet?

More than 20 states had adopted or aligned with it as of 2025-2026, up from "nearly half of states" reported by Quarles in June 2024. If you write business in any adopting state, that state's version applies to business written there, regardless of your home state's status.

What does the NAIC AI Systems Evaluation Tool actually check during an exam?

It's a pilot tool letting state insurance departments standardize how they evaluate high-risk AI systems during market conduct exams, checking data sources, governance structure, and testing records against the bulletin's expectations. Examiners increasingly ask for live documentation, not just a written policy, per Holland & Knight's breakdown.

Does the NAIC Model Bulletin hold insurers responsible for AI built by third-party vendors and MGAs?

Yes. Insurers remain fully responsible for AI systems they didn't build, which means vendor due diligence, contract audit rights, and ongoing monitoring aren't optional extras. If a vendor's model produces a discriminatory outcome, the exam finding lands on the carrier, not the vendor.

What are the NAIC's core principles for AI governance in insurance?

The bulletin centers on accountability (a documented governance structure with senior oversight), fairness (testing and retesting for bias and unfair discrimination), transparency (documentation an examiner can follow), and third-party accountability. It's principles-based per WaterStreet Company's analysis, leaving specific methodology up to the insurer.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

September 3, 2026

11 min read

What the NAIC AI Model Bulletin Requires From Insurers and Their AI Vendors

What the NAIC AI Model Bulletin actually is (and isn't)

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is guidance, not federal law, and it only has teeth in a state once that state's insurance department formally adopts it. The National Association of Insurance Commissioners adopted the model bulletin in December 2023, and it tells carriers and MGAs how regulators expect them to govern AI used in underwriting, claims, pricing, and marketing.

Two things trip people up here. First, "model bulletin" means template, not statute. The NAIC doesn't regulate insurers directly; state insurance departments do. So the bulletin only becomes operative when a state issues its own version, which most states have done close to verbatim. Second, it's principles-based rather than prescriptive. As WaterStreet Company points out, it doesn't hand you a specific bias-testing methodology or a required statistical threshold. It tells you that you need a governance structure, that you need to test for unfair discrimination, and that you're responsible for what your AI does. How you satisfy that is left to you, which is either freeing or terrifying depending on how prepared your organization is.

That ambiguity is the whole story if you're building or buying AI for a regulated carrier. A prescriptive rule is easy to check off. A principles-based one means an examiner is going to ask you to explain your reasoning, and "the vendor said it was fine" is not reasoning.

How many states have adopted the NAIC AI Model Bulletin?

More than 20 U.S. jurisdictions have adopted or closely aligned with the model bulletin as of 2025-2026 reporting, and the count keeps rising. Quarles reported "nearly half of states" had adopted it by June 2024, and adoption has continued state by state since, with fresh activity flagged repeatedly through 2025 and into 2026 as more departments issue their own bulletins.

If you write insurance in a single state and that state hasn't adopted the bulletin, you might reasonably think you're off the hook. Don't build a compliance program on that assumption. Most carriers and MGAs are licensed across multiple states, and the moment you sell in even one adopting state, that state's version applies to the business you write there. Multi-state carriers end up governed by a patchwork where some states have adopted the bulletin, some have their own separate AI insurance rules (Colorado's AI-specific insurance regulation predates the NAIC bulletin and runs alongside it), and some have neither yet. The practical response most compliance teams land on is to build one AIS Program to the highest common standard and apply it everywhere, rather than maintaining 40 different governance postures. It's cheaper to build once correctly than to patch state by state later, and it's the same logic we've laid out for teams tracking state-level AI compliance requirements more broadly.

What a written AIS Program actually requires

The bulletin requires every insurer using AI systems in consequential decisions to maintain a written AI Systems (AIS) Program, and that document has to name real people and real processes, not aspirational language. Specifically, regulators expect an accountability structure that spans actuarial, legal, compliance, data science, and underwriting functions, with genuine oversight from senior management or the board, not a rubber stamp buried in a risk committee's annual agenda.

Inside that structure, the bulletin asks for three things that matter architecturally, not just administratively:

  • Risk-tiering by potential consumer harm, so a claims-denial model gets more scrutiny than an internal scheduling tool.

  • Validation, testing, and retesting for bias, data quality, and unfair discrimination, done before deployment and on an ongoing basis after.

  • Documentation that a regulator could pick up cold and understand what the system does, what data trains it, who owns each decision, and what happens when it's wrong.

That last point is the one every legal-alert breakdown mentions and none of them operationalize. "Documentation" sounds like a paperwork exercise until you try to produce it for a system you didn't design to produce it. If your underwriting model runs inside a vendor's black box and outputs a score with no reasoning trail, you can't retroactively generate the audit history the AIS Program wants. You either negotiate that access into the vendor contract up front, or you build the system so the documentation is a byproduct of how it runs, not a report someone writes after the fact once a year.

The NAIC's testing language echoes something insurers outside the AI-native world may already recognize: the NIST AI Risk Management Framework's cycle of map, measure, manage, and govern. If your compliance team already speaks NIST, the bulletin is a familiar shape wearing a different label. That's a useful bridge when you're explaining this to a board that's heard of NIST but not the NAIC's AI work.

The third-party vendor problem: why your vendor's gaps become your exam findings

The bulletin makes insurers fully responsible for AI systems built or operated by third-party vendors and MGAs, and it doesn't matter that you didn't write the code. If a vendor's underwriting model produces a discriminatory outcome, the exam finding lands on the carrier's desk, not the vendor's. That single fact changes how vendor selection should work.

Insurers are expected to run genuine due diligence before onboarding an AI vendor: understanding what data trains the model, what testing the vendor has done for bias and accuracy, and what happens when the model's outputs drift. Contracts need audit rights baked in, meaning the insurer can actually inspect the vendor's testing records and methodology, not just take a marketing one-pager at face value. And that oversight has to be ongoing, not a one-time intake questionnaire that gets filed and forgotten. Most vendor contracts written before 2023 have none of this. If you're renewing an AI vendor relationship this year, that renewal is the moment to fix it, and it's worth working from a structured list rather than winging it. We put together an AI vendor risk assessment checklist for exactly this conversation, because "what should I ask before I sign" is a different exercise than "what should I ask before I renew," and the bulletin makes both questions mandatory for regulated carriers now.

Here's the part vendors won't volunteer: a lot of AI underwriting and claims tools on the market today were built for speed to market, not audit defensibility. They can tell you the model's accuracy on a holdout set. They usually cannot tell you why a specific policyholder was scored the way they were, which is exactly the question an examiner asks when a complaint triggers a market conduct exam.

What the NAIC AI Systems Evaluation Tool means if you're ever examined

The AI Systems Evaluation Tool is NAIC's pilot mechanism for standardizing how state regulators actually test insurers against the model bulletin during market conduct exams, and its existence is why "principles-based guidance" is becoming a live audit rather than a paper exercise. As Holland & Knight describes it, the tool gives participating state insurance departments a structured way to evaluate a carrier's high-risk AI systems, the data sources feeding them, and the governance framework wrapped around them, rather than leaving each examiner to improvise.

Practically, that means an examiner is likely to ask for specific artifacts: the written AIS Program, the risk tier assigned to a given system, the testing and retesting records, the vendor due diligence file, and evidence of board or senior management oversight. Plante Moran's read on how the bulletin is evolving is that enforcement is moving from "do you have a program" toward "does your program actually work," which is a meaningfully harder bar. A binder with a policy in it doesn't survive that kind of scrutiny. Live testing records, versioned model documentation, and a demonstrable decision trail do.

This is also where the low search competition around this topic makes sense. It's a genuinely new compliance surface. The people searching for it right now, general counsel, compliance officers, heads of ops at carriers and MGAs, are trying to figure out what an exam actually looks like before they're sitting across from an examiner asking for a document they don't have.

Build, buy, or augment: what the bulletin means for your AI architecture decisions

The bulletin doesn't ban any particular architecture, but it makes the audit trail a hard requirement, and audit trails are far easier to produce when you own the system than when you're renting a black box. This is the piece every legal-alert breakdown skips, because law firms tell you what the rule says, and nobody on that SERP has actually had to build the thing the rule is asking for.

A SaaS underwriting AI you buy off the shelf is usually optimized for the vendor's roadmap, not your exam file. You get an API and a score. Getting the reasoning behind that score, the training data lineage, and version history of every model update usually means asking the vendor nicely and hoping their contract allows it. Compare that to a system built (or built with real audit access negotiated in) where every decision logs its inputs, the model version that produced it, and a confidence score that routes low-confidence or high-risk cases to a human before anything touches a policyholder. That second pattern isn't more expensive to build correctly from day one; it's expensive to retrofit after the fact.

This is also why self-hosting matters more in insurance than in most industries. Genta AI Solutions runs open-source models on a client's own infrastructure with zero data retention for exactly this kind of regulated, data-sensitive work, because when an examiner asks "where does this data go and who else can see it," the honest answer needs to be "nowhere, and no one." That's a much easier compliance conversation than explaining a third-party API call to a model provider you don't control.

None of this means every carrier needs to build everything in-house. It means the build-versus-buy decision for AI in insurance has to weight auditability as a first-class requirement alongside cost and speed, the same way a carrier weighs solvency risk in a reinsurance decision. We've written about where AI agent projects in carriers actually stall operationally in our piece on AI agents in insurance, and the regulatory floor described here is exactly what those projects have to clear before they scale past a pilot. If you're also thinking about the liability side of this, meaning how your architecture choices affect what an insurer will charge you to cover your own AI risk, that conversation is the mirror image of this one and we cover it in our AI liability insurance guide.

A practical readiness checklist before your next exam

Most compliance leads don't need another 40-page framework. They need to know what to fix this quarter. Here's the condensed version we walk clients through:

  • Confirm which states you write business in have adopted the bulletin, and build your AIS Program to the strictest version among them rather than maintaining separate postures per state.

  • Write down, in one document, who owns AI governance across actuarial, legal, compliance, data science, and underwriting, and confirm the board or senior management actually reviews it, with a paper trail showing they did.

  • Risk-tier every AI system touching underwriting, claims, or pricing by potential consumer harm, and prioritize testing and documentation on the highest tiers first.

  • Pull every AI vendor contract and check for audit rights. If a vendor won't grant you access to their testing methodology and data lineage, that's a renewal conversation, not a footnote.

  • Run a mock documentation request: pretend an examiner asked for testing records, model versioning, and a decision trail for your top three AI systems today, and see how long it takes to assemble. If it takes weeks, that's your real risk exposure, not the bulletin's text.

If you're working through this decision, this is exactly what our Discovery phase at Genta AI Solutions maps out before we build or audit anything, and if you want a second set of eyes on where your current AI systems stand against this, our enterprise AI page outlines how we approach it, or we're happy to compare notes.

Frequently asked questions

What is the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers?

It's a template regulatory bulletin the NAIC adopted in December 2023 that tells state insurance departments what to require of carriers and MGAs using AI. It requires a written governance program, risk-tiered testing, and third-party vendor accountability, but only becomes legally binding once a state formally adopts its own version.

How many states have adopted the NAIC AI Model Bulletin, and does it apply if my state hasn't adopted it yet?

More than 20 states had adopted or aligned with it as of 2025-2026, up from "nearly half of states" reported by Quarles in June 2024. If you write business in any adopting state, that state's version applies to business written there, regardless of your home state's status.

What does the NAIC AI Systems Evaluation Tool actually check during an exam?

It's a pilot tool letting state insurance departments standardize how they evaluate high-risk AI systems during market conduct exams, checking data sources, governance structure, and testing records against the bulletin's expectations. Examiners increasingly ask for live documentation, not just a written policy, per Holland & Knight's breakdown.

Does the NAIC Model Bulletin hold insurers responsible for AI built by third-party vendors and MGAs?

Yes. Insurers remain fully responsible for AI systems they didn't build, which means vendor due diligence, contract audit rights, and ongoing monitoring aren't optional extras. If a vendor's model produces a discriminatory outcome, the exam finding lands on the carrier, not the vendor.

What are the NAIC's core principles for AI governance in insurance?

The bulletin centers on accountability (a documented governance structure with senior oversight), fairness (testing and retesting for bias and unfair discrimination), transparency (documentation an examiner can follow), and third-party accountability. It's principles-based per WaterStreet Company's analysis, leaving specific methodology up to the insurer.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

September 3, 2026

11 min read

What the NAIC AI Model Bulletin Requires From Insurers and Their AI Vendors

What the NAIC AI Model Bulletin actually is (and isn't)

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is guidance, not federal law, and it only has teeth in a state once that state's insurance department formally adopts it. The National Association of Insurance Commissioners adopted the model bulletin in December 2023, and it tells carriers and MGAs how regulators expect them to govern AI used in underwriting, claims, pricing, and marketing.

Two things trip people up here. First, "model bulletin" means template, not statute. The NAIC doesn't regulate insurers directly; state insurance departments do. So the bulletin only becomes operative when a state issues its own version, which most states have done close to verbatim. Second, it's principles-based rather than prescriptive. As WaterStreet Company points out, it doesn't hand you a specific bias-testing methodology or a required statistical threshold. It tells you that you need a governance structure, that you need to test for unfair discrimination, and that you're responsible for what your AI does. How you satisfy that is left to you, which is either freeing or terrifying depending on how prepared your organization is.

That ambiguity is the whole story if you're building or buying AI for a regulated carrier. A prescriptive rule is easy to check off. A principles-based one means an examiner is going to ask you to explain your reasoning, and "the vendor said it was fine" is not reasoning.

How many states have adopted the NAIC AI Model Bulletin?

More than 20 U.S. jurisdictions have adopted or closely aligned with the model bulletin as of 2025-2026 reporting, and the count keeps rising. Quarles reported "nearly half of states" had adopted it by June 2024, and adoption has continued state by state since, with fresh activity flagged repeatedly through 2025 and into 2026 as more departments issue their own bulletins.

If you write insurance in a single state and that state hasn't adopted the bulletin, you might reasonably think you're off the hook. Don't build a compliance program on that assumption. Most carriers and MGAs are licensed across multiple states, and the moment you sell in even one adopting state, that state's version applies to the business you write there. Multi-state carriers end up governed by a patchwork where some states have adopted the bulletin, some have their own separate AI insurance rules (Colorado's AI-specific insurance regulation predates the NAIC bulletin and runs alongside it), and some have neither yet. The practical response most compliance teams land on is to build one AIS Program to the highest common standard and apply it everywhere, rather than maintaining 40 different governance postures. It's cheaper to build once correctly than to patch state by state later, and it's the same logic we've laid out for teams tracking state-level AI compliance requirements more broadly.

What a written AIS Program actually requires

The bulletin requires every insurer using AI systems in consequential decisions to maintain a written AI Systems (AIS) Program, and that document has to name real people and real processes, not aspirational language. Specifically, regulators expect an accountability structure that spans actuarial, legal, compliance, data science, and underwriting functions, with genuine oversight from senior management or the board, not a rubber stamp buried in a risk committee's annual agenda.

Inside that structure, the bulletin asks for three things that matter architecturally, not just administratively:

  • Risk-tiering by potential consumer harm, so a claims-denial model gets more scrutiny than an internal scheduling tool.

  • Validation, testing, and retesting for bias, data quality, and unfair discrimination, done before deployment and on an ongoing basis after.

  • Documentation that a regulator could pick up cold and understand what the system does, what data trains it, who owns each decision, and what happens when it's wrong.

That last point is the one every legal-alert breakdown mentions and none of them operationalize. "Documentation" sounds like a paperwork exercise until you try to produce it for a system you didn't design to produce it. If your underwriting model runs inside a vendor's black box and outputs a score with no reasoning trail, you can't retroactively generate the audit history the AIS Program wants. You either negotiate that access into the vendor contract up front, or you build the system so the documentation is a byproduct of how it runs, not a report someone writes after the fact once a year.

The NAIC's testing language echoes something insurers outside the AI-native world may already recognize: the NIST AI Risk Management Framework's cycle of map, measure, manage, and govern. If your compliance team already speaks NIST, the bulletin is a familiar shape wearing a different label. That's a useful bridge when you're explaining this to a board that's heard of NIST but not the NAIC's AI work.

The third-party vendor problem: why your vendor's gaps become your exam findings

The bulletin makes insurers fully responsible for AI systems built or operated by third-party vendors and MGAs, and it doesn't matter that you didn't write the code. If a vendor's underwriting model produces a discriminatory outcome, the exam finding lands on the carrier's desk, not the vendor's. That single fact changes how vendor selection should work.

Insurers are expected to run genuine due diligence before onboarding an AI vendor: understanding what data trains the model, what testing the vendor has done for bias and accuracy, and what happens when the model's outputs drift. Contracts need audit rights baked in, meaning the insurer can actually inspect the vendor's testing records and methodology, not just take a marketing one-pager at face value. And that oversight has to be ongoing, not a one-time intake questionnaire that gets filed and forgotten. Most vendor contracts written before 2023 have none of this. If you're renewing an AI vendor relationship this year, that renewal is the moment to fix it, and it's worth working from a structured list rather than winging it. We put together an AI vendor risk assessment checklist for exactly this conversation, because "what should I ask before I sign" is a different exercise than "what should I ask before I renew," and the bulletin makes both questions mandatory for regulated carriers now.

Here's the part vendors won't volunteer: a lot of AI underwriting and claims tools on the market today were built for speed to market, not audit defensibility. They can tell you the model's accuracy on a holdout set. They usually cannot tell you why a specific policyholder was scored the way they were, which is exactly the question an examiner asks when a complaint triggers a market conduct exam.

What the NAIC AI Systems Evaluation Tool means if you're ever examined

The AI Systems Evaluation Tool is NAIC's pilot mechanism for standardizing how state regulators actually test insurers against the model bulletin during market conduct exams, and its existence is why "principles-based guidance" is becoming a live audit rather than a paper exercise. As Holland & Knight describes it, the tool gives participating state insurance departments a structured way to evaluate a carrier's high-risk AI systems, the data sources feeding them, and the governance framework wrapped around them, rather than leaving each examiner to improvise.

Practically, that means an examiner is likely to ask for specific artifacts: the written AIS Program, the risk tier assigned to a given system, the testing and retesting records, the vendor due diligence file, and evidence of board or senior management oversight. Plante Moran's read on how the bulletin is evolving is that enforcement is moving from "do you have a program" toward "does your program actually work," which is a meaningfully harder bar. A binder with a policy in it doesn't survive that kind of scrutiny. Live testing records, versioned model documentation, and a demonstrable decision trail do.

This is also where the low search competition around this topic makes sense. It's a genuinely new compliance surface. The people searching for it right now, general counsel, compliance officers, heads of ops at carriers and MGAs, are trying to figure out what an exam actually looks like before they're sitting across from an examiner asking for a document they don't have.

Build, buy, or augment: what the bulletin means for your AI architecture decisions

The bulletin doesn't ban any particular architecture, but it makes the audit trail a hard requirement, and audit trails are far easier to produce when you own the system than when you're renting a black box. This is the piece every legal-alert breakdown skips, because law firms tell you what the rule says, and nobody on that SERP has actually had to build the thing the rule is asking for.

A SaaS underwriting AI you buy off the shelf is usually optimized for the vendor's roadmap, not your exam file. You get an API and a score. Getting the reasoning behind that score, the training data lineage, and version history of every model update usually means asking the vendor nicely and hoping their contract allows it. Compare that to a system built (or built with real audit access negotiated in) where every decision logs its inputs, the model version that produced it, and a confidence score that routes low-confidence or high-risk cases to a human before anything touches a policyholder. That second pattern isn't more expensive to build correctly from day one; it's expensive to retrofit after the fact.

This is also why self-hosting matters more in insurance than in most industries. Genta AI Solutions runs open-source models on a client's own infrastructure with zero data retention for exactly this kind of regulated, data-sensitive work, because when an examiner asks "where does this data go and who else can see it," the honest answer needs to be "nowhere, and no one." That's a much easier compliance conversation than explaining a third-party API call to a model provider you don't control.

None of this means every carrier needs to build everything in-house. It means the build-versus-buy decision for AI in insurance has to weight auditability as a first-class requirement alongside cost and speed, the same way a carrier weighs solvency risk in a reinsurance decision. We've written about where AI agent projects in carriers actually stall operationally in our piece on AI agents in insurance, and the regulatory floor described here is exactly what those projects have to clear before they scale past a pilot. If you're also thinking about the liability side of this, meaning how your architecture choices affect what an insurer will charge you to cover your own AI risk, that conversation is the mirror image of this one and we cover it in our AI liability insurance guide.

A practical readiness checklist before your next exam

Most compliance leads don't need another 40-page framework. They need to know what to fix this quarter. Here's the condensed version we walk clients through:

  • Confirm which states you write business in have adopted the bulletin, and build your AIS Program to the strictest version among them rather than maintaining separate postures per state.

  • Write down, in one document, who owns AI governance across actuarial, legal, compliance, data science, and underwriting, and confirm the board or senior management actually reviews it, with a paper trail showing they did.

  • Risk-tier every AI system touching underwriting, claims, or pricing by potential consumer harm, and prioritize testing and documentation on the highest tiers first.

  • Pull every AI vendor contract and check for audit rights. If a vendor won't grant you access to their testing methodology and data lineage, that's a renewal conversation, not a footnote.

  • Run a mock documentation request: pretend an examiner asked for testing records, model versioning, and a decision trail for your top three AI systems today, and see how long it takes to assemble. If it takes weeks, that's your real risk exposure, not the bulletin's text.

If you're working through this decision, this is exactly what our Discovery phase at Genta AI Solutions maps out before we build or audit anything, and if you want a second set of eyes on where your current AI systems stand against this, our enterprise AI page outlines how we approach it, or we're happy to compare notes.

Frequently asked questions

What is the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers?

It's a template regulatory bulletin the NAIC adopted in December 2023 that tells state insurance departments what to require of carriers and MGAs using AI. It requires a written governance program, risk-tiered testing, and third-party vendor accountability, but only becomes legally binding once a state formally adopts its own version.

How many states have adopted the NAIC AI Model Bulletin, and does it apply if my state hasn't adopted it yet?

More than 20 states had adopted or aligned with it as of 2025-2026, up from "nearly half of states" reported by Quarles in June 2024. If you write business in any adopting state, that state's version applies to business written there, regardless of your home state's status.

What does the NAIC AI Systems Evaluation Tool actually check during an exam?

It's a pilot tool letting state insurance departments standardize how they evaluate high-risk AI systems during market conduct exams, checking data sources, governance structure, and testing records against the bulletin's expectations. Examiners increasingly ask for live documentation, not just a written policy, per Holland & Knight's breakdown.

Does the NAIC Model Bulletin hold insurers responsible for AI built by third-party vendors and MGAs?

Yes. Insurers remain fully responsible for AI systems they didn't build, which means vendor due diligence, contract audit rights, and ongoing monitoring aren't optional extras. If a vendor's model produces a discriminatory outcome, the exam finding lands on the carrier, not the vendor.

What are the NAIC's core principles for AI governance in insurance?

The bulletin centers on accountability (a documented governance structure with senior oversight), fairness (testing and retesting for bias and unfair discrimination), transparency (documentation an examiner can follow), and third-party accountability. It's principles-based per WaterStreet Company's analysis, leaving specific methodology up to the insurer.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.