CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

August 20, 2026 14 min read

What the NAIC AI model bulletin actually asks insurers to prove

In the NAIC's most recent line-of-business survey on insurer AI use, 92% of the 93 health insurers surveyed reported that they currently use, plan to use, or plan to explore AI or machine learning models in their operations. Those responses may seem broad, but they describe a market where the technology has reached the decisions regulators examine faster than the controls that would document how they were made.

The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023, and more than half of U.S. states, plus the District of Columbia, have adopted it since. California, Colorado, New York, and Texas run their own insurance-specific AI frameworks instead, built on the same core expectation with different adopted text.

The legal standard governing AI-driven insurance decisions has not changed, but the documentation an insurer must produce to demonstrate compliance with it has.

That documentation burden is specific. Section 4 of the bulletin lists what a department may request during an investigation or market conduct action, and it is the right place for audit, risk, and compliance teams to start.

For now, no formal enforcement action under an adopted bulletin has been publicly reported as of the first quarter of 2026, though the examination infrastructure is being built now: the NAIC began piloting its AI Systems Evaluation Tool, since renamed the AI Risk Evaluation Supplement, with 12 participating states in March 2026, with formal adoption anticipated at the 2026 Fall National Meeting. The pressure here is exam readiness rather than imminent enforcement.

Governance: a written program with a name attached to it

The bulletin asks insurers to develop, implement, and maintain a written program for the responsible use of AI systems, which it calls an AIS Program. Responsibility for developing, implementing, monitoring, and overseeing that program should sit with senior management, accountable to the board or an appropriate committee of the board.

That accountability moves AI governance out of the model risk corner and into the reporting structure that already carries corporate governance annual disclosure obligations, because the bulletin is explicit that CGAD and CGAD-R requirements reach any part of a carrier's governance framework addressing AI-supported decisions that affect consumers.

On structure, the bulletin points to committees drawing representatives from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance, and legal. Its governance guidelines also ask the framework to consider:

  • Chains of command, scope of authority, and decisional hierarchies
  • The independence of decision-makers at successive stages of an AI system's life cycle
  • Monitoring, auditing, escalation, and reporting protocols
  • Ongoing training and supervision of personnel
  • Documentation requirements built with Section 4 in mind, so the record answers the questions an examiner will actually ask

The scope runs broadly in two directions. Horizontally, the program should cover AI across the insurance life cycle: product development and design, marketing, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection. Vertically, it should cover every phase of an AI system's own life cycle, from design and development through validation, implementation, use, ongoing monitoring, updating, and retirement. An AI governance policy that covers only underwriting models is too narrow in both directions.

Knowing the required scope is the easier half. Most AI governance programs stall between a drafted policy and an operating one, and AI governance implementation: A practical guide covers the failure points that cause it: unclear ownership, fragmented tooling, and no way to prove oversight after the fact.

Risk, controls, and testing: build a time series, not a document

To identify errors and bias in predictive models and AI systems, the bulletin encourages the development and use of verification and testing methods. Those same methods should also surface the potential for unfair discrimination in the outcomes those systems produce.

The word doing the most work there is "retesting." Section 3.4 asks for validating, testing, and retesting to assess how outputs generalize after implementation. The definitions section names model drift as the decay of a model's performance over time as the data it runs on diverges from the data it was trained on.

Together, those set the evidentiary standard. A single point-in-time bias study, however rigorous, cannot show that a model still behaves the way it did at validation. Drift is a time-series concept, so assessing it takes repeated observations at a defined cadence, documented results, and thresholds for action set in advance.

That is the difference between a carrier that can produce a bias test and one that can produce a monitoring record. An examiner asking about model drift wants the latter.

Data practices carry a parallel expectation. The bulletin asks the program to address data currency, lineage, quality, integrity, bias analysis and minimization, and suitability, then lists them again in Section 4 as documentation a regulator may request for any model under examination. Lineage is the one most often reconstructed after the fact, and it shows.

Third-party oversight and documentation: the vendor's model is your model

The bulletin treats third-party data and third-party-built AI systems the same way it treats internally developed ones. Each AIS Program should address the process for acquiring, using, or relying on both, with due diligence designed to confirm that decisions supported by those systems will meet "the legal standards imposed on the Insurer itself."

That phrase settles where responsibility sits. Buying a model does not transfer the compliance obligation attached to the decisions it supports.

The bulletin also points to three things worth securing in vendor contracts:

  • Audit rights, or the right to receive audit reports from qualified auditing entities
  • Vendor cooperation with regulatory inquiries and investigations
  • Confirmation that the vendor is meeting its contractual and, where applicable, regulatory obligations

All three carry a qualifier: the bulletin asks for them where they are appropriate and available. That does real work in a market where the largest model vendors hold most of the negotiating leverage, and it does not relieve the insurer of the underlying obligation. Where audit rights cannot be obtained, the diligence record should show what was requested, what was declined, and what compensating assurance was accepted instead. A gap with a documented rationale reads very differently from a gap.

What an examiner may ask for

Section 4 is the part to read with a highlighter:

  • The written AIS Program and documentation evidencing its adoption
  • The program's scope, including any AI systems deliberately left outside it
  • Policies, procedures, guidance, and training materials
  • Pre-acquisition and pre-use diligence on third-party data and AI systems
  • Vendor contracts, including terms on data sourcing, confidentiality, intellectual property, and cooperation with regulators
  • Audits or confirmation processes are performed on vendor compliance
  • Documentation of validation, testing, and auditing, including evaluation of model drift

Consumer notice

The bulletin asks the AIS Program to include processes providing notice to affected consumers that AI systems are in use, and to give access to appropriate levels of information based on the phase of the insurance life cycle involved. That means an owner, a trigger, and a record. In practice, it tends to be the requirement carriers have thought about least.

One program, not four

A carrier writing in 20 states may face 20 separately issued bulletins whose adopted text is similar but not identical, plus Colorado's binding regulation, plus, for groups with European operations, the EU AI Act.

The bulletin anticipates this. It states that an AIS Program may adopt, incorporate, or rely upon, in whole or in part, a framework or standards developed by an official third-party standard organization, and names the NIST Artificial Intelligence Risk Management Framework, Version 1.0, as its example. That is explicit permission to build one control set and map it outward. ISO 42001 is a common complement in practice, though the bulletin does not name it.

The European parallel is structural, not jurisdictional

The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on July 24, 2026, and entered into force three days later. It moved high-risk obligations for standalone Annex III systems to December 2, 2027, and for AI embedded in regulated Annex I products to August 2, 2028. Article 50 transparency obligations were largely untouched.

None of this reaches a U.S.-only carrier. The vocabulary is the same one the NAIC bulletin uses: risk management, technical documentation, logging, and human oversight.

Waiting for federal preemption is a bad bet

Some carriers are holding off on program build-out until the federal preemption question resolves. Three things make that a bad bet.

  1. No preemption statute has been enacted. There is nothing to wait for yet.
  2. Insurance is among the least likely domains to be reached. The McCarran-Ferguson Act requires an act of Congress specifically relating to the business of insurance before federal law can displace state insurance regulation, and no such act exists.
  3. Preemption would not touch private litigation. Unfair-discrimination claims survive it, and that is where much of the exposure sits.

Governance built to the bulletin holds up under every one of these outcomes.

A practitioner checklist

The bulletin covers more ground than any one team can act on at once. These six artifacts carry the most weight in an examination, and they are where a program that does not yet exist should start.

  • A written AIS Program with senior management ownership and board accountability
  • An AI system inventory covering internal and third-party systems, with named owners and risk classification
  • Documented, repeatable bias and error testing with a defined retesting cadence
  • Vendor due diligence and audit rights in contracts, with documented rationale where those rights cannot be obtained
  • Evidence tied to specific controls and ready to produce on request
  • A documented consumer notice process with a defined owner

How Optro helps

AI Governance. Optro centralizes AI model intake, reviews, and approvals in one place, replacing scattered manual governance activity with a single system of record. It also centralizes ISO 42001, NIST AI RMF, and EU AI Act requirements in one hub, which reduces the administrative cost of tracking multiple frameworks separately.

Risk, controls, and testing. Intelligent risk scoring and suggested control mappings move risk tracking off spreadsheets, giving teams prioritized mitigation steps and ongoing visibility into risk and control status. This is prioritization support. The bias and disparate-impact testing itself remains with your actuarial and data science teams.

Third-party oversight and documentation. The same AI model inventory that tracks internal systems also captures vendor-identified applications, so third-party AI does not sit on a separate manual track. Connecting each model to its relevant policies, risks, and controls produces the documentation trail an examiner would ask for.

Evidence, not a snapshot
See Optro's AI governance platform

You may also like to read

man in glasses sitting at desk
AI governance

AI governance definitions: The complete glossary for GRC teams

LEARN MORE
bridge in a forest
AI governance

AI procurement policy: A practical guide for enterprises

LEARN MORE
Report cover for the agentic ai report
AI governance

Agentic AI governance: 6 questions GRC teams keep asking

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional