AI Agent Governance Statistics for Insurance Carriers
There is currently no verified, insurance-specific quantitative data on AI agent adoption rates, control implementation, or incident counts within a recent 12-month window. What is confirmed is regulatory: the NAIC Model Bulletin on AI Systems, adopted by a growing number of state insurance departments, requires carriers to maintain a documented AI Program covering governance, risk management, and accountability for AI systems used in underwriting, pricing, claims, and marketing. Governance leaders should treat this bulletin as the baseline compliance driver and build internal measurement programs rather than relying on external benchmarks that do not yet exist in verifiable form.
What Is Actually Known Today
A brief summary of the confirmed regulatory baseline, the current data gap, and the compliance expectation carriers face right now.
NAIC Model Bulletin adopted by multiple state insurance departments, applying to underwriting, pricing, claims, and marketing AI use.
No confirmed statistics exist yet on carrier-level AI agent adoption, control coverage, or incident rates.
Insurers are expected to document accountability structures and risk management processes for AI systems.
Full Article
Why Benchmark Data Is Scarce
Governance leaders in insurance are being asked to justify AI agent security investments with numbers that do not yet exist in verifiable form. Vendor surveys and industry commentary circulate adoption percentages and incident counts, but these figures are frequently unsourced, self-reported, or extrapolated from small samples that do not isolate insurance carriers specifically. This guide does not repeat those numbers. Instead, it documents what is actually confirmed through regulatory record, and explains why the absence of hard data is itself a governance signal worth acting on. A market that cannot measure its own agent risk exposure is a market where governance programs are being built on assumption rather than evidence.
The NAIC Model Bulletin as the Current Baseline
The most concrete governance-relevant development affecting insurance carriers is the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. Multiple state insurance departments have adopted or referenced this bulletin, and it applies across core insurance workflows including underwriting, pricing, claims handling, and marketing rather than being limited to a single function. The bulletin directs insurers to maintain a written AI Program that addresses governance, risk management, and internal controls, and to designate personnel accountable for AI system oversight. This creates a compliance-driven starting point for agent governance even where technical benchmarks are unavailable. Carriers operating across multiple states should note that adoption has been uneven, meaning baseline documentation requirements can differ by jurisdiction.
Why the Bulletin's Scope Matters for Agentic AI
The NAIC bulletin predates widespread deployment of autonomous and semi-autonomous AI agents and was written with AI systems generally in mind, not agentic architectures specifically. Its applicability to agent-based deployments is inferred from its broad language on AI system oversight, not explicitly confirmed by regulatory text. This matters operationally. An AI agent that can call tools, access underwriting data, or take actions in a claims system introduces oversight questions that a static predictive model does not: who authorized the agent's permissions, what actions did it take, and can those actions be reconstructed after the fact. Governance leaders should not wait for regulators to issue agent-specific language before applying the bulletin's accountability and documentation expectations to their own agent inventories.
The core inference gap
The bulletin's accountability language was not written with agentic AI in mind, so its application to agents is a reasonable extension, not a confirmed regulatory requirement. Treat it as the floor, not the ceiling, for agent governance.
What Carriers Should Be Measuring Internally
In the absence of external benchmarks, insurance carriers need internal measurement discipline. This means building an inventory of which AI agents operate in underwriting, claims, and servicing workflows, what data and systems each agent can reach, and what evidence exists to demonstrate oversight. Practical measurement starts with identity: does each agent have a distinct, attributable identity rather than shared service credentials. It continues with permissions: is agent access scoped to the minimum required for its task, or does it inherit broad standing access. It ends with auditability: can the carrier reconstruct what an agent did, when, and under whose authorization if a regulator or internal auditor asks. These are not abstract best practices. They are the practical translation of the NAIC bulletin's accountability language into something a governance team can actually produce on request.
Where Runtime Governance Fits
Regulatory documentation requirements describe what carriers must be able to show. Runtime governance is the mechanism for actually producing that evidence at the point where agents operate, rather than reconstructing it after an incident. This includes enforcing agent identity so actions are attributable to a specific agent rather than a shared credential, applying least-privilege permissions so an agent's access matches its intended task, requiring tool approval workflows for higher-risk actions, and maintaining audit logs that capture agent behavior in a form suitable for regulatory review. Trussed AI provides runtime governance and security controls for enterprise AI agents, including agent identity, permissions, tool approval workflows, and audit logging, which map directly to the accountability and oversight expectations described in the NAIC bulletin. This is offered as context for how these controls apply operationally, not as a substitute for a carrier's own compliance assessment.
Readiness Questions for Governance Leaders
Use these questions to assess whether your carrier's current documentation and controls would hold up under regulatory review.
- Have you mapped which AI agent deployments fall within the scope of your state's adopted NAIC AI Model Bulletin requirements?
- What documentation exists to demonstrate accountability and oversight for each AI agent operating in underwriting, claims, or servicing workflows?
- Can you produce audit-ready logs of AI agent actions and tool calls if requested by a state regulator?
- Have you assessed whether third-party AI agent vendors meet your carrier's AI Program governance obligations under applicable state guidance?
- What is your process for identifying and reporting AI agent related incidents, even where no explicit regulatory reporting requirement yet exists?
Build Your Own Governance Evidence Base
Reliable industry-wide statistics on AI agent risk in insurance do not yet exist. What carriers can control is their own inventory, documentation, and runtime evidence for every AI agent in production.
Talk to an Expert