Nearly three out of four financial institutions cannot say which of their vendors use artificial intelligence. The 2026 State of Third-Party Risk Management Survey from risk and compliance firm Ncontracts found that 72 percent of institutions were only partially aware of vendor AI use, and 9 percent had not assessed it at all.
That blind spot now poses a sharper third-party risk for insurance carriers than the AI itself, said John Romano, a principal at Baker Tilly in Philadelphia who leads the accounting and advisory firm's insurance regulatory practice.
A managing general agent (MGA) that uses generative AI to summarize claims files sits at the low end of any risk scale, Romano said. A partner that runs proprietary models to select risks, set pricing, triage claims, score severity, or refer fraud sits far higher.
"If it affects price, if it affects coverage, if it affects claims outcomes, if it affects fraud [or] any customer communications that are regulatory bound, then it deserves heightened oversight," Romano said.
One commercial insurer's AI chatbot approved a claim at the wrong figure - ten times too large. "It was supposed to be $50,000, but the chatbot said $500,000," he said. The carrier had disclosed the tool, but the error still triggered a costly back-and-forth, the kind of regulatory scrutiny and customer-trust damage that turns efficiency into a liability.
The questions carriers should ask their vendors
The gap does not stem from missing policy. Grant Thornton's 2026 AI Impact Survey of 950 executives found that over one in two insurance leaders reported their boards had set AI governance policies, yet nearly half (44 percent) still traced project failure or underperformance to governance and compliance gaps. The harder task is not writing a policy but seeing - and judging - each vendor's own AI and data-governance practices.
Romano starts with an inventory. A carrier should be able to say where a vendor uses AI across its process, what kinds of decisions the system makes, where it runs autonomously, and where people stay in the loop. A polished governance document rarely answers those questions. "It's very important to understand the process connections," he said.
When Romano assesses how a vendor uses AI, he pushes past the written policy to the decision itself. "Tell me about the decisioning process. Maybe there's a flowchart. Where exactly is the agent actually performing?" he said. He wants to know how the vendor trained the model, what data it draws on, whether it touches customer data, and how the vendor gets comfortable with accuracy, explainability, and bias.
Bias worries him because the data often carries it from the start, and model drift compounds the problem as a system learns and ingests more data over time. Romano also presses vendors on their own third and fourth parties. A carrier's oversight has to reach the subcontractors its vendor relies on, not stop at the first contract.
Carriers that need to map vendor AI risk across their operations can turn to dedicated AI for Insurance training to build that capability. Leadership teams setting governance strategy will find relevant guidance in AI for Executives & Strategy resources.
An express lane, not a toll booth
Romano's central advice reframes governance itself. Too many carriers assess vendors through a "toll booth" style of scrutiny: every vendor, whatever its AI does, must clear the same questionnaire, the same legal review, the same documentation. As AI spreads into nearly every tool, that approach stalls the business.
"You want to refer to it not as a toll booth, but an 'express lane' with specific guardrails," Romano said. Carriers should define their AI risk appetite up front, then let low-risk cases move quickly while high-consumer-impact uses draw deeper review.
That express lane cannot live in procurement alone, Romano stressed. Business owners need to weigh in, and compliance, legal, and technology all belong in the loop.
What sorts a vendor into the fast lane or the slow one is how deeply that provider's own AI and data governance reach into consumer decisions. Romano tiers by consumer impact and the sensitivity of the data a vendor handles, not by spend. An MGA with delegated authority sits at the top of that risk pyramid: "Essentially you're giving the pen to another," he said. Delegated underwriting authority enterprises wrote $108.7 billion in direct premiums in 2025, up from $92.3 billion in 2024, and carriers granted underwriting authority in more than 75 percent of MGA contracts, according to AM Best data drawn from NAIC filings.
Below the MGAs, Romano ranks third-party administrators, then claims-technology providers that touch part of a claim - handing over a first-cut reserve or payment recommendation, say - and then any outside firm a carrier leans on to build its own proprietary models.
At the other end, uses that stay clear of consumer decisions earn the thinnest review. A vendor that runs AI only to draft marketing copy, or to help analyze geography, distribution, and sales inside the business, belongs in the express lane, Romano said. The test he keeps returning to is whether the vendor only advises or actually holds the pen - as decision authority climbs, the guardrails tighten.
Where regulators are heading next
Romano expects regulators to sharpen their focus on third-party governance without strangling innovation. He pointed to the National Association of Insurance Commissioners (NAIC), which is field-testing an AI Systems Evaluation Tool through a 12-state pilot running from March to September 2026. California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin are participating. Examiners use the tool during market conduct and financial exams to map where an insurer uses AI, how it governs those systems, which models carry the most risk, and what data feeds them - with third-party use a core focus. The NAIC expects to weigh the tool for adoption at its fall 2026 national meeting.
The tool builds on the NAIC's 2023 model bulletin on the use of AI systems, which roughly 25 states have now adopted and which states plainly that existing insurance laws apply whether a decision comes from a human, an algorithm, or a third-party vendor. A separate model law on third-party data and models, anticipated later in 2026, could go further, potentially carrying licensing requirements for the vendors that sell models into the industry. Regulators "don't want to stifle innovation," Romano said, and they keep working with the industry as they bring in more subject-matter experts.
The direction of travel, as Romano reads it, runs from documentation toward evidence. Regulators will move past "we have an AI governance policy and an inventory" and start asking carriers to show support for the specific controls that matter most - above all in underwriting, pricing, and claims, where AI reaches consumers directly.
Why this matters for insurance professionals
For carriers, the practical takeaway is to build a tiered vendor review process now, before examiners ask for it. Map where each vendor uses AI, identify which decisions touch policyholders, and reserve the deepest scrutiny for the vendors that hold the pen on underwriting, pricing, or claims. Carriers that treat a signed governance policy as proof may find the pen was never fully in their hands.
Your membership also unlocks: