Cyber & Insurance Technology

NAIC AI Model Bulletin Explained: Governance Expectations for Insurers Using AI

The NAIC AI Model Bulletin sets regulatory expectations for insurers using AI systems. Learn what it says about governance, risk management, data, testing and compliance with existing insurance laws.

Computer screens displaying software code, illustrating artificial intelligence governance and insurance technology oversight
Photo: Jakub Zerdzicki / Unsplash
Short answer: The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers is a regulatory framework that reminds insurers that decisions supported by AI must comply with existing insurance laws and sets expectations for governance, risk management, documentation, testing and regulator access to information. It is not a federal AI law and does not replace state insurance statutes.

Artificial intelligence is now used across underwriting, pricing, claims, fraud detection, customer service and other insurance functions. The regulatory challenge is that a model can operate at machine speed while still producing outcomes that are subject to long-standing requirements involving unfair discrimination, claims practices, privacy, market conduct and solvency.

What the NAIC Model Bulletin does

The NAIC says the bulletin was adopted in December 2023. It establishes regulatory expectations for insurers that develop, deploy or use AI systems and reminds them that AI-supported decisions remain subject to all applicable insurance laws and regulations.

Because U.S. insurance is primarily state regulated, the bulletin serves as a model for state insurance departments rather than a single nationwide statute. Insurers must monitor the actual requirements and guidance in each jurisdiction where they operate.

Governance is the core idea

The bulletin expects insurers to maintain a written AI systems program appropriate to the nature, scale and complexity of their use of AI. Governance should address accountability, oversight, risk management, internal controls and documentation. The goal is not merely to know that an algorithm exists, but to understand who is responsible for its outcomes and how risks are identified and controlled.

Governance area Practical question for an insurer
Accountability Who owns the AI use case and who can stop or change it?
Data Where do training and input data come from, and how are quality and relevance assessed?
Testing How is the system validated before launch and monitored after deployment?
Consumer impact Could outputs create unfairly discriminatory or otherwise unlawful outcomes?
Third parties How does the insurer oversee vendor models, data and services?
Documentation Can the insurer explain the system and produce information requested by regulators?

Third-party AI is still an insurer risk

Buying a model, data set or AI service from a vendor does not eliminate regulatory responsibility. The NAIC has continued work on third-party data and models because insurers may rely on external systems that affect underwriting, claims or consumer interactions. Contractual controls, due diligence, change management and monitoring can therefore be important parts of AI governance.

AI does not create an exemption from existing law

The bulletin’s central principle is that an insurer remains responsible for compliance when AI supports a decision. A pricing model, automated claims triage system or underwriting engine cannot lawfully produce a result merely because it was generated by software. Existing state laws on unfair trade practices, discrimination, data, claims and other insurance activity continue to apply.

What insurers should document

  • Inventory of material AI systems and their business purposes.
  • Roles and responsibilities for model ownership, compliance and independent review.
  • Data sources, data-quality controls and relevant limitations.
  • Validation, testing, performance monitoring and change-management records.
  • Processes for detecting and addressing potentially unfair outcomes.
  • Vendor due diligence and contractual oversight for third-party models.
  • Incident, complaint and exception handling where AI contributes to a decision.

What regulators may ask to see

The NAIC describes the bulletin as advising insurers about information a department may request during an investigation or examination. In 2025-2026, NAIC working groups continued developing tools for regulators to evaluate AI systems, governance, risk mitigation, high-risk models and data inputs. That direction reinforces the practical need for documentation that exists before an exam begins.

Why this matters for underwriting and claims teams

AI governance is not only an IT function. Underwriters, actuaries, claims leaders, compliance teams, legal teams, data scientists and vendor managers can all affect the control environment. A model may be technically accurate while still creating a compliance problem if it uses inappropriate data, is applied outside its intended purpose or is not monitored for changing outcomes.

Frequently asked questions

Is the NAIC AI Model Bulletin a federal law?

No. It is an NAIC model bulletin designed for state insurance regulatory use. Actual legal obligations depend on the applicable jurisdiction.

Does it ban insurers from using AI?

No. It focuses on responsible governance and compliance with existing insurance laws when AI is used.

Does the bulletin apply only to internally built models?

No. Third-party data and models can also create governance and compliance risks that insurers must manage.

Can an insurer rely only on a vendor’s explanation of a model?

That can be inadequate. Insurers should maintain oversight appropriate to the use case and be able to respond to regulator questions about material systems and outcomes.

Reviewed October 3, 2026. State adoption, guidance and examination practices can differ; insurers should verify requirements in each applicable jurisdiction.