What’s new: Openlayer named in the 2026 Gartner Market Guide® for AI Evaluation and Observability Platforms. Learn More

NAIC AI Model Bulletin: What Insurers Must Prepare for in July 2026

Published July 28, 202618 min read

State insurance examiners aren't asking whether you use AI. They're asking whether you can show that your AI systems were tested before deployment, monitored after, and governed by someone with actual authority to act on what the monitoring finds. For carriers operating across multiple states, that bar looks different in each one. Here's where the NAIC model bulletin stands as of July 2026 and what you need to have ready.

TLDR:

  • The NAIC Model Bulletin is guidance, not law; it becomes enforceable only when individual states adopt it through their own regulatory channels.
  • As of July 2026, 25 states have formally adopted the Bulletin, with 8 more in progress; non-adopting states are still applying Bulletin-aligned expectations through market conduct examinations.
  • Bias testing requires measuring demographic parity gaps across protected classes; flag for review when any group's selection rate falls below 80% of the highest group's rate (a gap exceeding 5 percentage points triggers review under the EEOC four-fifths rule).
  • Insurers remain accountable for third-party vendor model outputs; "we don't have access to model internals" is not an accepted response during examination.
  • Openlayer generates versioned audit trails and blocks model promotion when fairness thresholds are not met, producing the evidentiary records state regulators inspect, not policy summaries.

What the NAIC Model Bulletin is and what it isn't

The NAIC Model Bulletin on AI is a guidance document, not a law. The National Association of Insurance Commissioners adopted it to give state insurance regulators a shared framework for overseeing how insurers use AI in decisions affecting policyholders. But because the NAIC has no direct regulatory authority over insurers, the bulletin carries no binding legal weight on its own. It becomes enforceable only when individual states adopt it, either wholesale or with modifications, through their own regulatory channels.

There are a few distinctions worth holding onto as you read coverage of this bulletin.

  • The bulletin applies to insurers, not to AI vendors or third-party model providers. If a carrier licenses a scoring model from an outside vendor, the insurer still bears responsibility for how that model performs in underwriting, claims, or pricing decisions.
  • It covers AI systems broadly, extending beyond LLMs or generative tools. Any automated or algorithmic system that materially influences decisions about policyholders falls within the NAIC's intended scope.
  • Compliance with the bulletin does not satisfy other state or federal obligations. Anti-discrimination statutes, state fair trade practices acts, and applicable federal consumer protection rules exist independently. The bulletin adds a layer; it does not replace existing requirements.

The bulletin's authority also depends heavily on which state is conducting the review. A carrier operating across 30 states may face 30 different interpretations of what the bulletin requires, depending on how each state has integrated its provisions into their existing oversight frameworks.

NAIC AI principles: the regulatory foundation

The NAIC's AI principles predate the model bulletin itself, and understanding them clarifies why the bulletin is structured the way it is. In 2020, the NAIC adopted five core principles for AI use in insurance, drawing from broader international frameworks like the NIST AI RMF while tailoring them to the insurance regulatory context.

The five principles are:

  • Accountability: insurers must be able to identify who is responsible for AI-driven decisions, including decisions made by third-party vendors whose models feed into underwriting or claims workflows.
  • Explainability: AI systems must produce outputs that can be interpreted and communicated to consumers and regulators in plain terms, beyond data scientists internal to the organization.
  • Fairness: AI must not produce outcomes that unlawfully discriminate against protected classes, a requirement with direct teeth given existing state insurance anti-discrimination statutes.
  • Security and Safety: AI systems must be protected against adversarial manipulation and must behave reliably under conditions outside their training distribution.
  • Transparency: insurers must be willing to disclose, to regulators on examination, the nature of AI systems in use and the governance structures surrounding them.

These principles map directly to the bulletin's governance requirements. The bulletin converts accountability into auditable obligations through its responsible AI framework mandate, explainability through documentation requirements for model inputs and decision logic, and fairness through bias testing and adverse impact monitoring obligations. Transparency and security appear in requirements for ongoing monitoring programs and third-party vendor oversight.

One distinction worth keeping in mind: these principles are aspirational in isolation. The bulletin converts them into auditable obligations with specific deliverables regulators can review and inspect.

State adoption: where the Bulletin stands as of July 2026

As of July 2026, 25 states have formally adopted the NAIC Model Bulletin, with another 8 actively moving through legislative or regulatory approval processes. The remaining states fall into two camps: those that have issued informal guidance referencing the Bulletin's principles without formal adoption, and those that have taken no public position yet.

Adoption is not uniform in scope. Some states adopted the Bulletin verbatim; others modified key provisions around algorithmic accountability documentation or third-party vendor oversight requirements before enacting their own versions. That variation matters for insurers operating across state lines, since a compliance program built around one state's version may leave gaps in another, a challenge covered in depth by AI model governance frameworks for enterprise teams.

Where the gaps are concentrated

The states that have moved slowest tend to share a few characteristics:

  • Smaller insurance markets where AI adoption among carriers is less widespread, reducing regulatory urgency relative to other priorities.
  • States that have passed or are considering broader consumer data protection legislation, creating uncertainty about whether AI-specific insurance rules will be subsumed into that broader framework or run in parallel.
  • States where the department of insurance has signaled preference for federal preemption, effectively waiting to see whether a federal AI governance standard takes shape before committing to a state-level regime.

Insurers should not treat non-adoption as a safe harbor. Several non-adopting states have signaled through market conduct examination activity that they are applying Bulletin-aligned expectations informally, even without a formal enactment on the books.

The AIS program: what the Bulletin actually requires

The bulletin structures its requirements around a formal Artificial Intelligence System (AIS) program that insurers must build and maintain. The obligations fall into several distinct categories, and understanding each one is the starting point for any compliance effort.

Here is what the bulletin requires:

  • Accountability and governance: Insurers must designate a responsible person or committee to oversee AI use, with documented lines of authority connecting AI decisions to senior leadership. This is not a checkbox role; the designated function must have actual visibility into which AI systems are active and what decisions they are influencing.
  • Written AIS program documentation: A formal written program must exist, covering how the insurer selects, validates, monitors, and retires AI systems. The document must be available to regulators on request, which means it needs to reflect current practice, not aspirational policy.
  • Third-party model governance: When insurers rely on vendor-supplied models, including scoring algorithms from data aggregators, the bulletin holds the insurer responsible for those systems' outputs. Vendors cannot be used as a compliance shield.
  • Ongoing monitoring and testing: AI systems must be tested before deployment and monitored after, with particular attention to unfair discrimination across protected classes. The bulletin does not specify exact metrics, but state examiners will expect insurers to show evidence of regular review.
  • Consumer protection documentation: Insurers must be able to explain adverse actions driven by AI to affected consumers, connecting back to existing state insurance law obligations around adverse action notices.

The AIS program requirement is where most insurers will feel the most immediate practical pressure, since many have deployed AI systems without the documentation infrastructure to satisfy a regulatory examination.

AI in insurance underwriting, claims, and beyond

AI touches nearly every function in insurance now. Underwriting engines score risk from hundreds of variables without a human reviewer seeing the file. Claims systems flag fraud, estimate severity, and route decisions automatically. Pricing algorithms adjust premiums in real time based on telematics, behavioral data, and third-party feeds.

The breadth of these applications is exactly why the NAIC moved. When AI informs a coverage denial or a premium increase, it sits squarely in consequential decision territory, and the regulatory question moves from "is AI being used" to "can you show the system behaved fairly and as intended." That move is structural: it is no longer sufficient to show that a model was accurate on average at the time of deployment. Regulators expect carriers to show that the system was validated across demographic subgroups, that outcome disparities were measured against a defined threshold, and that someone with authority to act on the results was actually monitoring them. The NAIC Bulletin translates that expectation into a documented governance program -- the Artificial Intelligence System program -- with specific deliverables examiners can inspect. For carriers that have deployed AI broadly across underwriting, claims, and pricing without that documentation infrastructure, the gap is not a policy question. It is an evidentiary one: the records either exist or they do not.

Where AI is concentrated in insurance operations

Three areas carry the most regulatory weight under the NAIC framework:

  • Underwriting: AI models assess applicant risk using variables that may move in step with protected characteristics even when those characteristics are not inputs. A model trained on geographic and behavioral data can produce outcomes that differ systematically by race or income without ever seeing those fields explicitly.
  • Claims processing: Automated severity scoring and fraud detection models make or inform payment decisions at scale. A miscalibrated fraud flag that disproportionately delays legitimate claims from certain zip codes is an adverse impact problem, regardless of intent.
  • Pricing and rating: Telematics and usage-based insurance models introduce continuous feedback loops. Without monitoring, a model's outputs can drift from its validated baseline as driving behavior data changes seasonally or demographically.

Each of these use cases requires documentation, testing, and ongoing monitoring under the NAIC Bulletin, because each one produces outcomes with direct financial consequences for consumers.

Bias testing and unfair discrimination: the technical requirement

Bias testing sits at the heart of the NAIC Model Bulletin's fairness requirements. Regulators expect insurers to go beyond acknowledging that AI systems may produce discriminatory outcomes and instead run structured tests that produce documented, auditable evidence.

The core obligation is adverse impact analysis across protected classes. For underwriting and pricing models, the operative question is whether a protected characteristic or a proxy for one is driving outcome differences at a rate that crosses the regulatory threshold. The EEOC's four-fifths rule is the standard reference point for AI fairness metrics: configure an alert when any group's selection rate falls below 80% of the highest-performing group's rate, meaning a gap of more than 5 percentage points triggers review.

There are three categories of bias that insurers need to test for:

  • Proxies embedded in input features: variables like ZIP code, occupation, or credit attributes can track closely with race or national origin even when those characteristics are never passed to the model directly. Testing requires measuring the outcome distribution after removing the suspected proxy; removing the protected class label alone is insufficient.
  • Disparate impact in model outputs: the model's predictions produce outcome differences across groups at a rate that exceeds the regulatory floor, even when no discriminatory intent exists. Measure the demographic parity gap across each protected class and flag for review when that gap exceeds 5 percentage points (example threshold; calibrate to your state regulator's floor and your institution's risk appetite).
  • Calibration gaps across groups: a model that is accurate on average may be systematically miscalibrated for a specific subgroup. Measure calibration error by group and in aggregate before any deployment decision is finalized, aggregate accuracy alone can mask subgroup failures.

Documentation is what converts testing into regulatory evidence, and structuring that documentation correctly is covered in detail in an AI model audit complete guide. Each test run should produce a record that includes the input data used, the protected class breakdown, the metric values computed, the threshold applied, and the reviewer who cleared or escalated the result. A fairness test that ran but was never written to an audit trail carries no weight during an examination.

Third-party vendor management: the look-through problem

When insurers buy an AI-powered underwriting engine or claims scoring model from a vendor, the NAIC Model Bulletin does not let them hand off accountability along with the contract. The insurer remains responsible for the model's outputs, its fairness properties, and its compliance posture, regardless of who built it.

This is the look-through problem: regulators look through the vendor relationship and hold the insurer liable for what the model does in production.

There are a few specific obligations this creates:

  • Insurers must obtain sufficient documentation from vendors to assess the model's intended use, training data sources, known limitations, and performance characteristics across protected classes. "We don't have access to the model internals" is not an accepted response to a regulatory examination.
  • Vendor contracts must include audit rights, data access provisions, and incident notification clauses. A vendor that cannot support an insurer's examination obligations is a vendor that creates regulatory exposure.
  • Ongoing monitoring cannot stop at the vendor's API boundary. If a third-party scoring model begins producing disparate outcomes after a vendor-side update, the insurer is accountable for detecting that drift and acting on it, not the vendor.

The practical gap most insurers face is that vendor management programs built for traditional software procurement do not cover these requirements. A service-level agreement governing uptime and response time does not satisfy examination of fairness monitoring or model documentation. Insurers deploying third-party AI need procurement processes, contractual terms, and runtime AI controls that reflect what regulators will actually ask for.

The AI systems evaluation tool: the new examination standard

The Bulletin's governance requirements don't exist in isolation; they connect directly to how state regulators will actually audit insurers, and selecting the right AI governance tools shapes how well an insurer can meet those expectations. The NAIC developed an AI Systems Evaluation Tool to give regulators a structured framework for assessing whether an insurer's AI governance program meets the Bulletin's expectations in practice.

There are four domains the evaluation tool covers:

  • Governance and accountability structures, including whether a designated AI executive owns oversight responsibility and whether board-level reporting on AI risk exists
  • Documented risk assessment processes for each AI system, with evidence that adverse impact testing occurred before deployment
  • Ongoing monitoring programs that track model performance and fairness metrics post-deployment, extending beyond the initial launch
  • Vendor and third-party AI management controls, since many insurers source models externally and remain accountable for their outputs regardless

In practice, documentation gaps become audit findings. An insurer that can describe its AI governance program verbally but cannot produce evaluation records, adverse impact test results, or vendor due diligence files will not pass a regulatory review under this framework. The tool is designed to surface exactly those gaps.

What examiners will actually ask for

When a state examiner opens an AI-related market conduct review, the questions will not be abstract. Examiners will look for documentation trails that prove a carrier's AI systems are governed, tested, and monitored continuously, disclosure at deployment is the starting point, not the finish line.

The specific artifacts examiners are likely to request include:

  • Inventory records listing every AI system used in underwriting, claims, or pricing decisions, including vendor-supplied models, with named model owners and governance leads for each entry.
  • Pre-deployment fairness testing results showing that adverse impact analysis was conducted across protected classes before a model went live, with threshold values documented and approved.
  • Ongoing monitoring logs confirming that performance and fairness metrics are tracked in production, that drift alerts are configured, and that someone is accountable for acting on them.
  • Vendor accountability records confirming that third-party AI providers have supplied documentation sufficient for the carrier to meet its own oversight obligations under the bulletin.
  • Consumer complaint logs tied to AI-influenced decisions, with records showing how complaints were reviewed and whether model behavior was investigated as a contributing factor.

The gap most carriers will face is not absence of good intentions. It is absence of auditable evidence. A model that was tested before launch but never monitored afterward, or a vendor relationship where the insurer accepted outputs without reviewing the supplier's governance documentation, will look identical to an ungoverned system under examination. Examiners assess what can be produced, not what teams intended to maintain.

State-level variation and the multi-state compliance problem

Even among adopting states, the operative document varies. Some enacted the Bulletin verbatim; others modified provisions before passage, producing versions with different documentation thresholds, testing obligations, or vendor oversight requirements.

Three states have layered additional obligations on top of the Bulletin framework:

StateInstrumentAdditional Obligation Beyond the NAIC BulletinKey Area
ColoradoColorado AI ActSpecific testing and transparency mandates for insurance AI systemsPre-deployment testing; transparency disclosures
New YorkDFS Circular LetterIndependent requirements covering model documentation and consumer disclosure, running alongside Bulletin obligationsModel documentation; consumer disclosure
CaliforniaState insurance lawRestricts reliance on automated tools in certain health insurance decisions regardless of Bulletin documentation standardsHealth insurance; automated decision limits

A compliance program calibrated to one home state will leave gaps across a multi-state footprint. Choosing among the best AI governance software platforms can help insurers design an AIS Program against the most demanding requirements across all licensed states, treating the strictest applicable standard as the floor.

How Openlayer supports NAIC Model Bulletin compliance

Insurers building AI governance programs under the NAIC Model Bulletin face a structural problem: the Bulletin's requirements for transparency, fairness documentation, and ongoing oversight are not satisfied by policy documents alone. They require active monitoring, versioned audit trails, and the ability to show -- with evidentiary records -- that controls were in place and functioning at the time a specific decision was made.

Openlayer's unified evaluation, observability, and governance platform connects directly to each of those obligations across the AI lifecycle.

What Openlayer covers across the Bulletin's core requirements

The Bulletin's expectations map to four concrete execution gaps that documentation frameworks leave open:

  • Governance documentation: Openlayer maintains a versioned record of every model deployed, including the evaluation results, risk classifications, and approval events that authorized deployment. When a regulator asks which model version produced a specific underwriting decision, that record exists and is traceable.
  • Bias and fairness monitoring: Openlayer runs continuous fairness checks across protected classes, with configurable thresholds. For example, teams can set alerts to fire when a demographic parity gap exceeds 5 percentage points across applicant populations, and block promotion if that gap is present at deployment time. (Calibrate thresholds to your institution's risk tolerance and applicable state requirements.)
  • Runtime enforcement, beyond passive observation: Logging a fairness anomaly is observation. Openlayer's deployment gates block model promotion when evaluation criteria are not met. That blocking step separates enforcement from observation, and it is what produces evidence regulators can inspect, structured records they can review, in place of incident reports they have to take on faith.
  • Audit trail generation: Evaluation pass/fail records, metric scores, flagged failure modes, and model version hashes populate a structured audit trail. When a state insurance department reviews an insurer's AI governance program, those records are the evidentiary layer a regulator inspects, not a summary of what the program was supposed to do.

Credo AI and IBM watsonx.governance cover AI governance documentation well, but neither monitors live model outputs, enforces behavioral thresholds at inference time, or flags drift in production. For insurers operating under the Bulletin's ongoing oversight expectations, governance documentation without production monitoring leaves the compliance posture incomplete after deployment day.

Final thoughts on AI governance and the NAIC Model Bulletin

Compliance with the NAIC Model Bulletin comes down to one question: can you show an examiner what your AI systems did, when they did it, and how you caught problems before they affected policyholders? Documentation frameworks get you partway there. Production monitoring and deployment enforcement are what close the gap. Reach out to the Openlayer team to see how that works across underwriting, claims, and pricing systems.

FAQ

How many states have adopted the NAIC AI Model Bulletin as of 2026?

As of July 2026, 25 states have formally adopted the NAIC Model Bulletin on AI, with another 8 working through legislative or regulatory approval processes. Insurers should not treat non-adoption as a safe harbor, several states that have not formally enacted the Bulletin are already applying its expectations informally through market conduct examination activity.

What does the NAIC AI Model Bulletin actually require insurers to produce for a regulatory examination?

Examiners will ask for a documented AI system inventory with named model owners, pre-deployment fairness testing results showing adverse impact analysis across protected classes, ongoing monitoring logs with configured drift alerts, vendor accountability records proving third-party AI providers supplied sufficient governance documentation, and consumer complaint logs tied to AI-influenced decisions. A governance program that exists verbally but cannot produce these specific artifacts will not pass examination under the NAIC's AI Systems Evaluation Tool framework.

NAIC AI Model Bulletin compliance: governance documentation tools like Credo AI vs. a platform with production monitoring, which covers the Bulletin's ongoing oversight requirements?

Credo AI covers governance documentation well but does not monitor live model outputs, enforce behavioral thresholds at inference time, or detect drift in production after deployment. The NAIC Bulletin's ongoing monitoring requirements, continuous fairness checks, post-deployment performance tracking, and auditable evidence that controls were functioning at the time a specific decision was made, are not satisfied by policy documentation alone; they require production monitoring and runtime enforcement that generates records examiners can inspect.

How should insurers set up bias testing for AI underwriting models under the NAIC Model Bulletin's unfair discrimination requirements?

Run adverse impact analysis across three categories: proxy variables embedded in inputs like ZIP code or credit attributes, disparate impact in model outputs measured as a demographic parity gap (flag for review when that gap exceeds 5 percentage points, calculated from the EEOC's four-fifths rule requiring any group's selection rate stay at or above 80% of the highest group's rate), and calibration gaps by subgroup as well as in aggregate, aggregate accuracy alone can mask subgroup failures. Each test run must produce a written record covering the input data used, protected class breakdown, metric values computed, threshold applied, and the reviewer who cleared or escalated the result -- because a fairness test with no audit trail carries no evidentiary weight during examination.

Can insurers use a vendor-supplied AI scoring model and let the vendor handle NAIC Model Bulletin compliance?

No. The Bulletin's look-through rule holds the insurer accountable for a vendor model's outputs, fairness properties, and compliance posture regardless of who built it. Insurers must obtain sufficient documentation from vendors to assess training data sources, known limitations, and performance across protected classes; include audit rights and incident notification clauses in vendor contracts; and monitor third-party models in production so that drift introduced by a vendor-side update is detected and acted on by the insurer, not the vendor.

Work on the future.

2026 Openlayer. All rights reserved.