Insurance regulators add AI governance questions to examinations

NAIC updated its AI Risk Evaluation Supplement with exam questions for insurers, replacing a policy-only tool. A 12-state pilot runs through September and will shape version 5.0.

Categorized in: AI News Insurance
Published on: Aug 15, 2026
Insurance regulators add AI governance questions to examinations

Insurance regulators are shifting artificial intelligence governance from policy statements to concrete examination questions. At its Summer National Meeting on Thursday, the National Association of Insurance Commissioners updated its AI Risk Evaluation Supplement, a structured set of questions state regulators can use to examine how insurers oversee AI systems.

The working group renamed the document from the "AI Systems Evaluation Tool" to avoid confusion about its purpose. The supplement is not a certification, a rating system, or a new insurance law. It gives regulators a common framework for gathering evidence about AI use during market conduct reviews, financial examinations, or standalone inquiries.

The practical effect matters more than the name. The NAIC's AI principles and 2023 model bulletin established expectations for responsible AI use. The supplement translates those principles into specific information requests.

Insurers may need to do more than say they govern AI responsibly. They will need to demonstrate how.

What the pilot covers

The pilot includes California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. Participating states have taken different approaches - some folded the supplement into scheduled exams, while others used it as a standalone questionnaire.

The pilot runs through September, though the NAIC said some states may not finish by Sept. 30. State feedback and initial company responses will shape version 5.0, which is expected to get a 30-day public comment period in September. Version 6.0 will undergo a 14-day exposure before regulators consider version 7.0 for adoption at the fall national meeting.

Where regulators are looking

The supplement's scope shows where insurers could face the most scrutiny. Regulators want to understand an AI system's purpose, data sources, training data, validation procedures, and risk classification. They are also examining documentation, performance monitoring, change histories, and whether a company can audit and explain an AI-generated outcome.

Human oversight is part of that review. Regulators are looking at who can approve a model, challenge its output, intervene when performance deteriorates, and document what happened after a system or vendor changes.

That raises the value of a current AI for Insurance inventory for insurers. Companies must identify each system, explain what it does, name the data it uses, and map internal and external dependencies. They must also produce testing results, monitoring records, and evidence that controls work in practice.

Vendor implications

Third-party data is on a parallel track. On Wednesday, the NAIC's Third-Party Data and Models Working Group reviewed feedback on a proposed framework covering outside data and predictive models used in property and casualty pricing and underwriting.

The proposal could require vendors to provide documentation covering model purpose, assumptions, inputs, limitations, validation, and performance. Regulators could also seek data-currency records, fairness testing, change logs, and audit trails. Meeting materials said insurers remain responsible for validating, testing, and monitoring third-party products.

That could create a new dividing line for insurance technology providers. Platforms that supply audit-ready documentation will be easier for regulated companies to adopt. Vendors that treat model details as confidential could create compliance friction for their customers.

The regulator message is direct. An insurer can outsource a model, but accountability stays in-house. That principle applies to AI for Government and regulatory compliance as well.

Why this matters for insurance professionals

Insurance executives, compliance officers, and data teams should expect AI questions to become a routine part of examinations. If your company cannot produce a current inventory of AI systems, explain data sources, or document human oversight, the pilot supplements will expose those gaps.

These findings may prompt adoption discussions for technology teams that evaluate vendor AI tools. Third-party models now need to come with documentation that stands up to a regulator's review. If a vendor obscures the details, insurers absorbed the risk. Preparing for the AI governance era means shipping for the exam room, find the gaps, and documenting before a regulator asks.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)