Third-Party AI

AI systems, models, or components built or operated by an outside vendor. The insurer stays responsible for outcomes even when the algorithm is rented.

Third-party AI refers to artificial intelligence systems, models, data sources, or platforms that an insurer licenses or buys from an outside vendor rather than building internally. In the NAIC’s survey of health insurers, more than half of respondents used third-party components somewhere in their AI stack, and roughly one in seven ran on vendor systems entirely.

Renting the algorithm does not rent out the responsibility. Under the NAIC Model Bulletin, compliance obligations follow the insurance decision rather than the authorship of the model: in an examination, the carrier answers for the documentation, the explainability, and the outcomes of any AI it uses, vendor-built or not.

A strong third-party AI program includes due diligence before signing, contract clauses for audit rights and regulatory cooperation, and ongoing monitoring after deployment. See our AI vendor risk assessment checklist and glossary entry on vendor oversight.

Primary sources

Last reviewed JUL 31, 2026