The AI Supply Chain Gets a Regulator
NAIC's Third-Party Data and Models (H) Working Group is developing a framework for how state insurance regulators should oversee the third-party vendors supplying data and AI models to insurers. The core objective is straightforward: give regulators more visibility into the vendors supplying AI models and data to insurers. At the same time, insurers remain fully responsible for complying with insurance laws, including prohibitions against unfair discrimination. The current draft focuses on property and casualty pricing and underwriting, with broader lines of business and use cases left for later phases. This is still a live, evolving proposal, not a finished rule.
The framework envisions a registration mechanism under which vendors would provide governance information, model validation and data lineage documentation, fairness testing results, and audit trails, while protecting proprietary information through confidentiality safeguards.
Important implementation details, including whether participation will be mandatory, voluntary, or administered through another mechanism, remain under discussion. Regardless of the final structure, the draft signals that regulators expect governance information to remain current rather than being collected once and forgotten. This isn't a one-time audit. It's an ongoing obligation, closer to continuous governance than a compliance folder a vendor builds once and files away. Vendors that choose not to participate could face reduced market access in jurisdictions that adopt the framework.
None of this changes insurer accountability. Insurers remain responsible for validating models, ensuring data quality, and complying with insurance regulations, regardless of a vendor's registration status. The pressure therefore flows downstream: insurers will increasingly push these same expectations into vendor contracts, on the same cadence regulators expect.
This proposal is currently limited to U.S. property and casualty insurance, and many details remain under discussion. But it reflects a broader regulatory trend: oversight is extending beyond the organizations deploying AI to the vendors building the models and datasets behind them. Similar principles of governance, transparency, auditability, data provenance, and accountability are emerging across financial services, healthcare, and jurisdictions including the EU, UK, Australia, and Singapore.
Standardized, auditable governance documentation is quickly becoming a baseline expectation rather than a differentiator. But documentation alone won't be enough. As AI systems evolve through model updates, agentic workflows, and continuously changing datasets, organizations will increasingly need governance that can demonstrate, on demand, how models were built, validated, updated, and monitored. The competitive advantage won't come from producing governance documentation once; it will come from maintaining governance that continuously generates fresh, auditable evidence.