Artificial intelligence is now used across underwriting, pricing, claims, fraud detection, customer service and other insurance functions. The regulatory challenge is that a model can operate at machine speed while still producing outcomes that are subject to long-standing requirements involving unfair discrimination, claims practices, privacy, market conduct and solvency.
What the NAIC Model Bulletin does
The NAIC says the bulletin was adopted in December 2023. It establishes regulatory expectations for insurers that develop, deploy or use AI systems and reminds them that AI-supported decisions remain subject to all applicable insurance laws and regulations.
Because U.S. insurance is primarily state regulated, the bulletin serves as a model for state insurance departments rather than a single nationwide statute. Insurers must monitor the actual requirements and guidance in each jurisdiction where they operate.
Governance is the core idea
The bulletin expects insurers to maintain a written AI systems program appropriate to the nature, scale and complexity of their use of AI. Governance should address accountability, oversight, risk management, internal controls and documentation. The goal is not merely to know that an algorithm exists, but to understand who is responsible for its outcomes and how risks are identified and controlled.
| Governance area | Practical question for an insurer |
|---|---|
| Accountability | Who owns the AI use case and who can stop or change it? |
| Data | Where do training and input data come from, and how are quality and relevance assessed? |
| Testing | How is the system validated before launch and monitored after deployment? |
| Consumer impact | Could outputs create unfairly discriminatory or otherwise unlawful outcomes? |
| Third parties | How does the insurer oversee vendor models, data and services? |
| Documentation | Can the insurer explain the system and produce information requested by regulators? |
Third-party AI is still an insurer risk
Buying a model, data set or AI service from a vendor does not eliminate regulatory responsibility. The NAIC has continued work on third-party data and models because insurers may rely on external systems that affect underwriting, claims or consumer interactions. Contractual controls, due diligence, change management and monitoring can therefore be important parts of AI governance.
AI does not create an exemption from existing law
The bulletin’s central principle is that an insurer remains responsible for compliance when AI supports a decision. A pricing model, automated claims triage system or underwriting engine cannot lawfully produce a result merely because it was generated by software. Existing state laws on unfair trade practices, discrimination, data, claims and other insurance activity continue to apply.
What insurers should document
- Inventory of material AI systems and their business purposes.
- Roles and responsibilities for model ownership, compliance and independent review.
- Data sources, data-quality controls and relevant limitations.
- Validation, testing, performance monitoring and change-management records.
- Processes for detecting and addressing potentially unfair outcomes.
- Vendor due diligence and contractual oversight for third-party models.
- Incident, complaint and exception handling where AI contributes to a decision.
What regulators may ask to see
The NAIC describes the bulletin as advising insurers about information a department may request during an investigation or examination. In 2025-2026, NAIC working groups continued developing tools for regulators to evaluate AI systems, governance, risk mitigation, high-risk models and data inputs. That direction reinforces the practical need for documentation that exists before an exam begins.
Why this matters for underwriting and claims teams
AI governance is not only an IT function. Underwriters, actuaries, claims leaders, compliance teams, legal teams, data scientists and vendor managers can all affect the control environment. A model may be technically accurate while still creating a compliance problem if it uses inappropriate data, is applied outside its intended purpose or is not monitored for changing outcomes.
Frequently asked questions
Is the NAIC AI Model Bulletin a federal law?
No. It is an NAIC model bulletin designed for state insurance regulatory use. Actual legal obligations depend on the applicable jurisdiction.
Does it ban insurers from using AI?
No. It focuses on responsible governance and compliance with existing insurance laws when AI is used.
Does the bulletin apply only to internally built models?
No. Third-party data and models can also create governance and compliance risks that insurers must manage.
Can an insurer rely only on a vendor’s explanation of a model?
That can be inadequate. Insurers should maintain oversight appropriate to the use case and be able to respond to regulator questions about material systems and outcomes.
Sources & further reading
Reviewed October 3, 2026. State adoption, guidance and examination practices can differ; insurers should verify requirements in each applicable jurisdiction.
