NAIC Model Bulletin
The NAIC's non-binding guidance for state insurance regulators on how insurers should govern, document, and test their use of AI systems.
The NAIC Model Bulletin on the Use of AI Systems by Insurers is the closest thing U.S. insurance has to a national AI governance standard. It was adopted by the NAIC in December 2023 and recommended to the states for adoption, with or without modification.
Its AIS Program Guidelines run in four numbered sections:
- General guidelines (1.0): the program should be proportionate to how much the insurer relies on AI, should cover the whole insurance life cycle and the whole model life cycle, and should provide notice to affected consumers that AI systems are in use.
- Governance (2.0): a governance framework covering AI risk, accountability, and board or senior-management oversight.
- Risk management and internal controls (3.0): identifying and assessing the risk of adverse consumer outcomes, including unfair discrimination, from AI used in insurance practices.
- Third-party AI systems and data (4.0): due diligence on vendors, contract terms covering audit rights and regulatory cooperation where appropriate and available, and confirmation that the vendor is complying.
It is not a model law or regulation, so it does not create enforceable obligations on its own. State adoption determines whether any part of it becomes binding. On the NAIC’s own adoption map, the instrument varies: formal bulletins in most adopting states, but also insurance notices, administrative letters, technical assistance advisories, and staff-level guidance documents, and four states (California, Colorado, New York, and Texas) skipped the model and wrote their own insurance-AI rules instead. See our guide to the NAIC Model Bulletin and how it fits into AI governance in insurance.