Does AI Insurance Regulation Apply to You? A Plain-Language Self-Check
Five questions that flag when the AI regulations for insurance companies may reach your business, and what to review before treating the answer as settled.
For Small carriers, MGAs, agencies, and anyone unsure whether insurance AI rules reach them.
Read if You are not sure whether the NAIC and state AI rules are meant for a business your size, or only for the big national carriers.
A lot of the writing about insurance AI regulation is aimed at large carriers with compliance departments. If you run a smaller carrier, an MGA (managing general agent), or an agency, it is fair to wonder whether any of it reaches you at all, or whether it is a concern for firms several sizes up.
The five checks below identify uses that deserve a closer compliance review. They do not replace the entity, license, jurisdiction, and line-of-business analysis that determines which rule applies.
The question that finds the likely exposure
Does software help you make or shape a decision about a consumer?
Not “do you use AI” in the abstract. Ask whether a model, score, or algorithm influences who gets covered, what they pay, how a claim is handled, or who sees an offer. A yes puts the use on the review list. The legal answer still depends on who deployed it, where the insurance transaction occurs, which line is involved, and what the system does. Internal drafting and scheduling tools usually present less insurance-conduct exposure, although privacy, cybersecurity, employment, and professional-responsibility rules can still matter.
Regulators wrote these rules around consumer decisions, which is why the type of software matters less than what it touches. Whether a particular rule attaches, and to whom, is the review the next section sets up.
Five checks
Run the first four as plain yes/no. A single yes is enough to require a closer review. The fifth tells you how many jurisdictions may shape the answer.
1. Do you use a model or score to help decide who to insure or what to charge? Accelerated underwriting, a third-party risk score, a pricing algorithm, a telematics program. If a number from a model moves a coverage or price decision, this is a yes.
2. Do you use AI to help handle claims? Fraud flags, damage estimates from photos, a bot that triages or closes claims, an automated adjudication step. Claims decisions are consumer decisions.
3. Do you use external consumer data or a predictive tool in marketing? Lead scoring, offer personalization, a model that decides who sees which product. This one surprises people, because it does not feel like underwriting, but steering which prospects see which product can raise the same fairness questions.
4. Do you rely on a vendor or third-party tool for any of the above? If a licensed platform does the scoring, the pricing, or the claims triage, this is still a yes. The tool being someone else’s does not make the decision someone else’s.
5. If any of the first four is a yes, do you write business in more than one state? This one puts nobody in scope on its own. It tells you how many versions of the answer you need: several states have layered their own AI rules on the baseline, and a few run regimes of their own.
What a “yes” means
A yes identifies a regulated insurance decision or activity that may be affected by software. It does not establish that every document described in the NAIC Model Bulletin applies to every agency, MGA, vendor, or other participant in the same way.
The distinction matters. The Model Bulletin is addressed to insurers licensed in the issuing jurisdiction. Producers, MGAs, TPAs, and vendors may be reached through their own licenses and contracts, unfair-practices law, privacy or security duties, or a carrier’s oversight obligations. The correct next question is “which rule reaches this entity and use?” rather than “does AI regulation apply at all?”
Two points clear up most of the confusion.
The adoption question is the one that misleads people most. The NAIC Model Bulletin on the use of AI systems by insurers creates no new statute. It opens by reminding insurers that decisions affecting consumers must comply with all applicable insurance laws, “including those laws that address unfair trade practices and unfair discrimination.”1 Its legislative-authority section then rests the whole document on two acts every state already has: the Unfair Trade Practices Act and the Unfair Claims Settlement Practices Act. Actions taken by insurers, it says, “must not violate the UTPA or the UCSPA, regardless of the methods the Insurer used to determine or support its actions.”1 A model is a method. Methods do not get their own exemption.
About half the states have issued the bulletin formally.2 In the rest, a department can still ask what your AI did, under law it has enforced for decades.
The vendor question is the other one. The bulletin asks insurers to run due diligence on third-party AI so that decisions it supports “will meet the legal standards imposed on the Insurer itself,” and to seek audit rights in the contract where they are available.1 Diligence, audit rights, and monitoring stay with whoever put the tool in front of consumers, which is why “the vendor built it” gets a regulator’s attention rather than ending the conversation. What that diligence has to contain is the subject of the AI vendor risk assessment checklist.
Where all of this gets enforced is the market conduct exam. The examiner’s job is to see whether you can produce your inventory, your testing, and your reasoning on demand, which makes it a documentation question before it is a modelling one. States work from a common NAIC handbook when they scope, sample, and document an exam, which is why the request list travels well across state lines even though the standards behind it are your state’s own.3
What to do first
If you came out of the checklist with a yes, the first move is smaller than it sounds. Three things, in order.
List the AI systems that touch a consumer decision. A spreadsheet is fine. For each, note what it does, where it touches a consumer, and whether it is yours or a vendor’s.
Name an owner. One person accountable for the list, even if that person wears three other hats. Governance without a name is a document nobody maintains.
Write down your state exposure. Which states you write in, and whether any of them have rules beyond the baseline. The full map of who governs insurance AI is the AI governance in insurance guide, and the state-by-state view lives in the state tracker.
That is the whole first move: an inventory, an owner, and a map.
The check stops at triage. It can identify the systems, decisions, entities, and states that need attention. It cannot decide whether a rating variable is defensible, whether a department will accept a testing method, or which disclosure duty applies to a particular license. Those answers turn on the actual book, jurisdiction, contract, and use. The useful output here is a review list and the name of the person responsible for resolving it.
Footnotes
-
National Association of Insurance Commissioners, “Model Bulletin: Use of Artificial Intelligence Systems by Insurers,” adopted December 4, 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf ↩ ↩2 ↩3
-
NAIC, “State Adoption Map for the AI Model Bulletin,” Big Data and Artificial Intelligence (H) Working Group. Status as of April 1, 2026: the Reference List on page 2 carries 24 states plus the District of Columbia, each with its own document number and adoption date. This site’s per-state record is at /states/. https://content.naic.org/sites/default/files/cmte-h-big-data-artificial-intelligence-wg-map-ai-model-bulletin.pdf ↩
-
NAIC, Market Regulation Handbook, Examination Standards Summary 2025: “a compilation of the market conduct examination standards found in the 2025 edition of the Market Regulation Handbook,” carrying its own caveat that it “does not represent all examination standards, methodologies and areas of review that may be utilized by a department of insurance.” https://content.naic.org/sites/default/files/publication-mes-hb-market-handbook-examination.pdf ↩
The Bottom Line
- If software influences coverage, price, a claim, or an offer, the use deserves a jurisdiction-specific compliance review. That is a screening result, not a final legal conclusion.
- The unfair-practices and unfair-discrimination authority behind the NAIC bulletin is already law in every state, which makes 'has my state adopted it' a weaker signal than most people assume.
- Buying the model from a vendor leaves the obligation where it was. Whoever deployed it answers for what it does to a consumer.
- A yes here is an exposure reading. The first work is an inventory, an owner, and a map of the states and entities involved.
Inside the NAIC AI Model Bulletin
What the NAIC AI Model Bulletin is, how adoption works, what belongs in a written AIS Program, and which implementation guide to use next.
Continue →
Simon Li · Founding Editor
Much of his time goes into reading NAIC meeting papers, state bulletins, bills, court filings, and public comments. He also keeps the site's 51-jurisdiction tracker up to date.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
How U.S. Insurance Regulation Actually Works
U.S. insurance is regulated state by state, not federally. Why that is, what regulators control across the policy lifecycle, and how the pieces fit together.
What the NAIC Is, and What It Cannot Do
The NAIC is the nonprofit standard-setting organization run by state insurance commissioners. States supply the regulatory power and decide whether its documents bind.
Market Conduct Examinations, Explained
A market conduct exam is how state regulators inspect how insurers treat consumers: what triggers one, what examiners ask for, and how it differs from a financial exam.
How Insurers Assess AI Vendor Risk
A practical NAIC-aligned checklist for AI vendor risk assessment: due-diligence questions, contract clauses, and the ongoing monitoring that stays with the insurer.
Information aggregation and analysis, not legal advice. See our disclaimer.