# How AI Governance Works in Insurance

> A plain-language map of AI governance in insurance: the regulatory stack, the program it expects, and where to go for rules, implementation, and evidence.

- Source: https://insureaiwire.com/ai-governance-in-insurance/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-07-31

---
AI governance in insurance is the work of keeping an AI-assisted decision inside the same legal and operational boundaries that apply when a person makes it. The technology changes how the decision is produced. It does not remove the carrier's responsibility for underwriting, pricing, claims, sales, privacy, or consumer communication.

That definition is deliberately practical. A useful program must answer four questions: where AI is used, which rules reach each use, who owns the resulting risk, and what evidence shows the controls operated. This page maps those questions to the articles that own them.

## The regulatory stack

There is no single national insurance AI code. The stack begins with state insurance law, including unfair trade practices, unfair discrimination, claims handling, rating, privacy, and market conduct authority. AI-specific instruments explain how regulators expect those existing duties to apply to AI-assisted work.

The NAIC Model Bulletin is the closest thing to a shared supervisory baseline. It does not create a new statute. A state decides whether and how to adopt or use it, and the underlying state law supplies the authority.[^1] The bulletin's central subject is a written AI Systems Program, usually called an AIS Program.

The NAIC AI Systems Evaluation Tool has a different job. Its optional Exhibits A through D help regulators ask about AI counts, governance, selected high-risk systems, and data categories.[^2] It does not replace the NAIC's examination handbooks, and it does not declare which systems are high risk for an insurer.

Several states use their own instruments. [New York Circular Letter 7](/ny-dfs-circular-letter-7/) owns the state's underwriting and pricing expectations for AIS and external consumer data. [Colorado's current insurance regime](/colorado-sb-26-189/) must be read alongside the state's insurance-specific rules rather than treated as a copy of New York. The [state tracker](/states/) is the right place to check the instrument and effective status for a footprint.

Federal policy can change the pressure around that system without instantly replacing it. The [federal-state preemption analysis](/ai-executive-order-insurance-preemption/) explains why an executive action alone does not settle how state insurance regulation is displaced.

## What the program must connect

A governance program is more than a policy document. It connects the systems the company uses, the decisions they shape, the controls applied to them, and the evidence retained. The details have separate owners:

**Table [row-headers]:** Governance questions and the article responsible for answering each one

| Question | Owner article |
|---|---|
| What does the Model Bulletin say? | [NAIC Model Bulletin](/naic-model-bulletin/) |
| How do Exhibits A through D fit together? | [AI Systems Evaluation Tool](/naic-ai-evaluation-tool/) |
| How do we turn the framework into work? | [Framework implementation](/ai-governance-framework-implementation/) |
| What AI systems do we actually have? | [AI inventory by business line](/ai-inventory-by-line-of-business/) |
| Which of those systems are high risk? | [High-risk screening](/identify-high-risk-ai-systems/) |
| Who prepares and signs each artifact? | AI governance roles (available after its scheduled publication) |
| How do we review a vendor? | [Vendor risk assessment](/ai-vendor-risk-assessment/) |
| How do we monitor a deployed model? | [Model monitoring](/ai-model-monitoring-insurance/) |
| What should we assemble for an examination? | Market conduct readiness (available after its scheduled publication) |

The table matters because these are different jobs. An inventory lists systems. It does not perform vendor diligence. A monitoring plan measures a live model. It does not establish the organization's examination response. An exam file assembles existing evidence. It should not become the first place that evidence is created.

New readers should not enter through the most technical article.

The guide map above is a reading path, not a maturity score. A company may be advanced in model monitoring and still discover an unrecorded vendor feature. Move to the page that owns the current gap.

## One program, with documented state differences

Multi-state carriers often ask whether to build to the strictest state. The useful distinction is portability. A sound inventory, approval record, validation method, vendor review, and monitoring process can usually support several jurisdictions. A filing, officer attestation, state portal, prescribed notice, or product-specific deadline usually cannot.

Use a shared baseline for controls that travel. Keep a state appendix for obligations that do not. Where two states genuinely conflict, document separate treatment instead of pretending one national ceiling exists. This approach reduces duplicate programs without erasing local law.

## Where the map becomes concrete

Governance is tested in business decisions. The [business-line hub](/ai-by-business-line/) routes claims, underwriting, life, health, homeowners, fraud, reinsurance, and distribution to separate owners. The [UnitedHealth case study](/unitedhealth-ai-governance/) then shows how public facts, litigation allegations, company responses, and regulatory evidence can expose control questions without turning one company's experience into a universal rule.

The end state is simple to describe and hard to fake. The organization can name the system, explain why its controls fit the decision, show what happened after deployment, and reproduce the evidence without building it during the examination. Every deeper guide on this site is responsible for one part of that result.

[^1]: National Association of Insurance Commissioners, [Model Bulletin on the Use of Artificial Intelligence Systems by Insurers](https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf), adopted December 4, 2023.
[^2]: National Association of Insurance Commissioners, [AI Systems Evaluation Tool 4.0](https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf), 2026.