The Direct Answer: What the NAIC AI Model Bulletin Actually Requires

The NAIC AI Model Bulletin requirements stem from the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the NAIC Executive Committee and Plenary in December 2023. The bulletin is not itself binding law; it is a template that state insurance regulators adopt into their own examination and market conduct frameworks. By mid-2026, the practical effect is that insurers operating in states that have incorporated the bulletin's language face documented expectations around AI governance, risk management, internal controls, and third-party vendor oversight when they use artificial intelligence systems in underwriting, pricing, claims handling, marketing, and consumer communications.

Also worth reading: What are the stability requirements for travel insurance and how do they affect your coverage? · Can non-citizens in the United States purchase life insurance, and what are the specific requirements for eligibility? · How do US expats navigate car insurance requirements and options when moving abroad?

The core requirement is straightforward to state and difficult to execute: an insurer that uses AI systems must be able to demonstrate, on demand during an examination or market conduct review, that it has a written governance framework covering how those systems were developed, acquired, tested, monitored, and retired. Regulators expect this documentation before they ask questions about any specific algorithm. The bulletin draws heavily on the NAIC's Principles for Artificial Intelligence (adopted August 2020) and borrows its structure from the NAIC's existing Insurance Data Security Model Law (#668) and its triennial risk assessment approach, which means many compliance teams will recognize the scaffolding even as the subject matter changes.

For brokers, MGAs, and carriers alike, the bulletin signals a shift from asking whether AI is being used to asking whether anyone can explain and defend how it is being used. That shift explains why explainability has become the dominant theme in regulatory discussions through the 2025 and 2026 national meetings.

Why the NAIC Issued the Bulletin and How It Fits Existing Law

The bulletin exists because regulators identified a gap: rate and form filings under prior approval statutes already give commissioners visibility into pricing decisions, but they do not reveal the inner workings of machine learning models that generate those rates. A gradient-boosted tree ensemble can produce a filing-compliant rate plan while encoding proxies for protected characteristics that no human reviewer would approve explicitly. The bulletin addresses this by extending the regulator's traditional market conduct authority into the model development lifecycle rather than waiting for discriminatory outcomes to surface in complaint data.

Legally, the bulletin operates through existing authority. When a state adopts it, examiners invoke it under their general power to examine insurer affairs (typically codified in each state's insurance code) and under unfair trade practices statutes such as those modeled on the NAIC Unfair Trade Practices Act. Colorado went further earlier than most: its Division of Insurance adopted Regulation 10-1-1 on quantitative testing of external consumer data and information sources (ECOAS) in life insurance, finalized in September 2023, which functions as the hardest-edged implementation of the bulletin's philosophy anywhere in the country. New York's Department of Financial Services issued Circular Letter No. 7 (2024) addressing AI in insurance underwriting and pricing, adding supervisory expectations for admitted carriers in the largest domestic market.

The distinction matters for planning purposes. The bulletin is guidance-shaped; Colorado's regulation is rule-shaped with specific statistical testing obligations. Insurers that build to the stricter standard generally satisfy the softer ones, which is why many multistate carriers treat Colorado-style testing as their internal floor.

The Four Pillars of Compliance Under the Bulletin

The bulletin organizes expectations into four areas, and understanding them as pillars rather than a checklist helps because regulators evaluate them together. First is governance: a board-level or senior-management-owned AI program with defined roles, escalation paths, and a named accountable executive. Second is risk management: identification of AI use cases, classification by risk level, and controls proportionate to that classification. Third is internal controls: documentation standards, validation protocols, change management, and audit trails sufficient for an examiner to reconstruct why a model produced a given output. Fourth is third-party risk management: contractual and oversight mechanisms for vendors whose models the insurer deploys, since the bulletin makes clear that buying a model does not transfer accountability.

Each pillar has teeth in examination practice. An examiner following the bulletin's framework can request the insurer's AI inventory, ask how each system was classified, request validation reports for high-risk classifications, and then test whether the claimed controls actually operated — for example, by tracing a sample of claims decisions back through the model version, input data snapshot, and override logs. Insurers that cannot produce this chain typically receive findings under market conduct examination standards, which can escalate to consent orders and, in serious cases, administrative penalties that vary widely by state but commonly run from $1,000 to $25,000 per violation per day depending on jurisdiction and intent findings.

Third-Party Vendor Requirements: Where Most Insurers Are Weakest

The bulletin devotes explicit attention to AI systems developed or provided by third parties, and industry surveys throughout 2025 consistently showed vendor oversight as the weakest area of carrier readiness. The logic is uncompromising: if an insurer uses a vendor's scoring model in underwriting, the regulator treats the insurer as fully responsible for that model's fairness, accuracy, and explainability. "The vendor won't tell us" is not a defense, and several state examiners have said so publicly at NAIC meetings.

Practically, this means procurement contracts signed before 2024 are often inadequate. They may lack provisions requiring the vendor to disclose training data provenance, provide model documentation comparable to SR 11-7-style validation packages used in banking, notify the insurer of material model changes, or permit regulatory access to documentation during examinations. Remediation typically involves contract amendments or addenda covering at minimum: model purpose and intended use, data sources including any ECOAS, performance metrics disaggregated where feasible, bias testing results or the insurer's right to conduct its own, version control and change notification windows (30 days is a common negotiated term), and cooperation clauses for regulatory inquiries.

Brokers and MGAs sit in an awkward middle position here. Many distribute carrier-built tools while also using their own quoting algorithms, and both activities can draw bulletin-based scrutiny. A broker-facing consequence is that carriers increasingly flow down AI governance attestations through appointment agreements, meaning a broker's compliance posture now affects its carrier relationships directly.

Comparing the Regulatory Options: Bulletin Adoption vs. Hard Rules vs. Waiting

Insurers face genuinely different regulatory environments depending on where they operate, and the differences are large enough to affect product strategy. The table below summarizes the three main postures states have taken as of mid-2026.

FeatureBulletin Adoption StatesHard-Rule States (e.g., Colorado)Non-Adopting / Watching States
Legal forceGuidance incorporated into exam standardsBinding regulation with testing mandatesGeneral market conduct authority only
Documentation burdenWritten AI program + use case inventoryFull ECOAS testing plans, statistical disparity analysisStandard exam response suffices today
Explainability expectationProportionate to risk classificationQuantitative justification requiredComplaint-driven inquiry
Timeline pressureOngoing, exam-triggeredDeadlines tied to filing cyclesUncertain; could adopt at any time
Cost profileModerate: policy + process workHigh: data science + actuarial testingLow now, potentially retroactive later
Risk of surprise findingMediumLow if compliant, high if ignoredHighest, because no roadmap exists
The strategic takeaway is that building to the strictest applicable standard is usually cheaper over a five-year horizon than maintaining fifty different compliance postures. Several large carriers announced internally in 2025 that they would apply Colorado-grade testing nationally for exactly this reason. The counterargument, worth taking seriously, is that hard-rule compliance consumes actuarial and data science capacity that smaller insurers cannot spare, and for a regional carrier writing in non-adopting states, bulletin-level governance may be the rational ceiling rather than the floor.

Common Mistakes Insurers and Brokers Make With the Bulletin

The first recurring mistake is treating the bulletin as an IT problem. It is not primarily about technology; it is about decision accountability. Programs housed solely in IT departments routinely fail because they document infrastructure but not business decisions — who approved the model for underwriting use, what alternatives were considered, what happens when the model conflicts with an underwriter's judgment. Examiners want the business record, not the architecture diagram.

The second mistake is inventory incompleteness. Insurers frequently list their proprietary models but omit embedded AI inside vendor platforms: the fraud scoring inside a claims platform, the chatbot in customer service, the lead-scoring tool in marketing automation. Each of these is an AI system under the bulletin's definition, and discovering them mid-examination damages credibility more than the underlying gap itself. A useful discipline is defining "AI system" broadly in your inventory policy — anything making, materially informing, or automating a decision affecting consumers — and letting exclusions be justified rather than assumed.

The third mistake is static compliance. Teams write the governance framework once, pass a board resolution, and never update it. Models drift, vendors push updates, and use cases expand. Regulators increasingly ask for evidence of ongoing monitoring: periodic revalidation cycles (annual for high-risk systems is becoming conventional), incident logs, and minutes showing the AI governance committee actually met and decided things. A framework with no meeting minutes after twelve months reads as theater.

A fourth mistake, common among brokers, is assuming the bulletin applies only to carriers. Market conduct exams reach producers, and several 2025–2026 enforcement discussions have centered on agent-side use of generative AI in consumer communications, including hallucinated coverage descriptions and unapproved comparative statements. If your brokerage lets producers use public chatbots to draft client emails without a policy governing that use, you carry real exposure.

Practical Steps: Building a Compliant Program in 90 Days

A realistic implementation sequence for a mid-sized insurer starts with a 30-day discovery phase: inventory every AI system touching underwriting, rating, claims, fraud, marketing, and consumer service, including vendor-embedded capabilities, and classify each by consumer impact. Days 31 through 60 should establish the governance skeleton — a charter, a named executive owner, a cross-functional committee spanning compliance, actuarial, IT, and legal, and a written risk-classification scheme with defined control tiers. Days 61 through 90 focus on the highest-risk two or three use cases: pull together whatever validation documentation exists, run a gap analysis against bulletin expectations, and remediate the worst gaps first, which for most organizations means vendor contract amendments and decision-audit logging.

Two artifacts deserve disproportionate effort because examiners request them early. One is the AI use case register: a living document listing each system, its owner, its risk tier, its validation status, and its next review date. The other is the model documentation package for your top-risk models, containing purpose, data lineage, performance testing, fairness testing where applicable, limitations, and human oversight design. Organizations that can produce these two items within days of an examiner's request report materially smoother examinations than those assembling documents ad hoc.

Budget expectations vary with size. A small regional carrier can often reach bulletin-level readiness with existing staff plus outside counsel and a consultant, spending somewhere in the low six figures across a year. Large multistate carriers running full ECOAS-style testing programs have reported multi-million-dollar annual programs once dedicated data science time is costed honestly. Brokers typically spend far less — mostly policy drafting and producer training — but should not budget zero, since carrier flow-down requirements make some investment unavoidable.

Where Regulation Is Heading After Mid-2026

The NAIC's Innovation, Cybersecurity and Technology (H) Committee has spent the 2026 meeting cycle debating whether the bulletin approach is sufficient or whether a formal model law and a disclosure standard should follow. Reporting from the Spring 2026 National Meeting indicated genuine division among members: some regulators argue voluntary adoption has been too slow and uneven, while others warn that prescriptive rules will freeze innovation and push smaller insurers out of AI adoption entirely. Both camps agree on one thing — the current patchwork is unstable, and multistate insurers should expect movement within the next 12 to 24 months.

Three developments look probable. First, more states will convert the bulletin into binding examination standards, shrinking the set of "watching" jurisdictions. Second, disclosure expectations will grow, likely starting with consumer-facing transparency about AI's role in claims denials and premium increases, echoing broader federal conversations about automated decision-making. Third, explainability demands will harden from documentation exercises into substantive testing requirements, following Colorado's lead. Insurers that built flexible governance programs — ones that can absorb new testing mandates without structural rework — will find these transitions manageable. Those that wrote minimal policies to check a box will find the next round expensive.

When to Act and What It Costs to Wait

The right time to act was before your last examination; the second-best time is now, and the calculus differs by organization type. Carriers writing in bulletin-adoption or hard-rule states already have exposure and should treat remediation as urgent, particularly if any AI touches ratemaking or claims adjudication. Carriers in watching states have breathing room but should note that market conduct exams are backward-looking — a 2027 exam can examine 2025 behavior, so waiting for a rule to arrive does not protect past conduct. Brokers and MGAs should move within the next two quarters, driven less by direct regulatory risk than by carrier flow-down requirements that are already appearing in appointment and MGA agreements.

The cost of waiting compounds in ways that are easy to underestimate. Findings in market conduct exams become public, appear in ratings considerations, and follow an insurer into subsequent exams. Consent orders impose multi-year reporting obligations that consume compliance capacity indefinitely. And retrofitting documentation onto models already in production costs multiples of what building documentation alongside development would have cost — a pattern familiar to anyone who lived through cybersecurity compliance maturation after the Insurance Data Security Model Law spread. The bulletin era rewards insurers who treat AI governance as an operating discipline rather than a filing exercise, and penalizes everyone else slowly, then suddenly.