Insurance AI Compliance
NAIC Model Bulletin on AI: A Compliance Guide for Insurers
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, is guidance that state insurance regulators can adopt to require insurers to maintain a written, risk-based AI governance program covering the full AI lifecycle, hold insurers accountable for third-party AI tools, and document testing and monitoring sufficient to support regulatory examination. It is not binding law on its own; it takes effect only where a state insurance department adopts, references, or modifies it.
Key Takeaway
The bulletin is guidance, not self-executing law. It becomes binding for an insurer only when that insurer's state insurance department adopts, references, or modifies it, and its core expectations center on a written governance program, third-party vendor accountability, and examination-ready documentation.
At a Glance
| Item | Detail |
|---|---|
| Adopted | December 2023, NAIC Fall National Meeting |
| Applies To | Underwriting, rating, claims, marketing, fraud detection |
| Structure | Written, risk-based governance program across the AI lifecycle |
| Vendor Scope | Insurer remains accountable for third-party AI tools |
| Legal Status | Not self-executing; effective only where states adopt it |
What the NAIC Model Bulletin Is
The National Association of Insurance Commissioners adopted the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers at its Fall 2023 National Meeting in December 2023. The bulletin is guidance that state insurance regulators can use when engaging with insurers about their use of AI. It defines AI systems broadly as machine-based systems that generate outputs such as predictions, recommendations, or decisions that influence real or virtual environments. The bulletin applies to AI used in underwriting, rating, claims handling, marketing, and fraud detection wherever there is potential consumer impact. Importantly, the bulletin is not independently binding on insurers. It becomes operative in a given state only when that state's insurance department adopts, references, or issues its own version of it. This structure means compliance obligations differ depending on where an insurer writes business, and multi-state carriers need a process for tracking which states have adopted the bulletin and in what form.
Governance Program Requirements
The bulletin directs insurers to develop, implement, and maintain a written AI governance program that is proportionate to their use of AI and to the potential for consumer harm. Governance expectations span the full AI system lifecycle, including development or acquisition, testing and validation, deployment, and ongoing monitoring. The bulletin recommends that accountability for this program sit at the board or senior-management level rather than resting solely with technical teams. This risk-based structure mirrors the core functions found in the NIST AI Risk Management Framework (govern, map, measure, and manage), though the bulletin does not prescribe specific technical testing methods such as particular bias metrics. Insurers retain discretion over methodology as long as it is documented within a formal governance program. For compliance leaders, this means the governance program itself, its scope, ownership, and lifecycle controls, becomes the primary artifact regulators will examine, not a single technical test result.
Third-Party AI Vendor Oversight
A central feature of the bulletin is that insurers remain accountable for compliance with insurance laws and regulations even when AI systems, data, or models are developed or supplied by third-party vendors. Using a vendor's AI tool does not transfer regulatory responsibility to that vendor. The bulletin expects insurers to perform due diligence on third-party AI vendors, including reviewing vendor testing practices and data sourcing, and to address AI oversight directly in vendor contracts. In practice, this means compliance and procurement teams need to evaluate vendor contracts for audit rights, testing disclosures, and compliance representations related to AI, and to maintain oversight of vendor-supplied models on an ongoing basis rather than treating vendor certification as sufficient on its own.
State-by-State Adoption and Timelines
Because the bulletin is not self-executing, its practical effect depends entirely on state-level action. Some states had existing AI or algorithm-specific insurance regulation before the bulletin was adopted; Colorado's life insurance underwriting algorithm rules under SB21-169 are one example, illustrating the variation the bulletin is intended to help harmonize. The exact list of states that have adopted, proposed, or modified the bulletin, along with specific compliance deadlines, changes over time and should be confirmed directly with each state insurance department rather than assumed from a single national standard. Compliance teams operating in multiple states need an ongoing mapping process that tracks adoption status, any state-specific modifications to the bulletin's language, and applicable effective dates, rather than relying on a one-time compliance assessment.
Where Runtime Oversight Fits Into Compliance
The bulletin's expectations around ongoing monitoring, third-party accountability, and examination-ready documentation point to an operational gap that many insurers face once AI systems move from pilot to production: sustaining oversight as models run, are updated, or interact with vendor systems. Runtime governance capabilities, including policy enforcement, monitoring, agent permissions, and audit logging, are relevant here because they generate the kind of continuous, retrievable evidence the bulletin's documentation expectations imply, particularly for AI systems supplied or operated by third parties. This is a narrow, supporting role. The governance program itself, its written policies, risk tiering, and accountability structure, remains the compliance foundation the bulletin describes.
Documentation and Audit-Readiness Practices
Regardless of a given state's adoption status, the following practices help insurers stay prepared for regulatory examination of AI systems.
- Maintain a written AI governance program describing roles, risk tiers, and lifecycle controls, scaled to consumer impact
- Keep a current inventory of AI systems in use, including third-party and embedded vendor models
- Document AI system design, testing, validation, and monitoring contemporaneously so records are retrievable during a market-conduct examination
- Review and update vendor contracts to include AI-specific representations and audit rights
- Designate a board or senior-management owner accountable for the AI governance program
- Track state-by-state adoption status and any modified bulletin language across every state of operation
Operationalize AI Governance Beyond the Policy Document
Written governance programs satisfy the NAIC Model Bulletin on paper. Sustaining oversight of AI systems and third-party AI vendors in production requires ongoing runtime visibility and control.
Request a Demo