# Inside the NAIC AI Model Bulletin

> What the NAIC AI Model Bulletin is, how adoption works, what belongs in a written AIS Program, and which implementation guide to use next.

- Source: https://insureaiwire.com/naic-model-bulletin/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-07-31

---
The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023.[^1] The document is easy to misclassify. It is not a model law, and it does not create a new cause of action or penalty. It explains what a commissioner expects from insurers using AI in decisions and actions that can affect consumers, under insurance law that already applies.

That distinction determines how to use it. Read the bulletin as an authority document: what it says, who it addresses, and what kind of program it expects. The broader [governance map](/ai-governance-in-insurance/) shows where it sits. The implementation and vendor owner guides handle operating detail; organization-level exam readiness remains a separately scheduled guide.

## What the bulletin is

The NAIC writes model material for state insurance regulators. A state then chooses whether and how to adopt, adapt, reference, or ignore it. The [state tracker](/states/) records the instrument in each jurisdiction. A “not adopted” entry does not mean AI-assisted decisions fall outside that state's unfair-practices, discrimination, claims, rating, or examination authority. It means the state has not used this model instrument in the recorded form.

The bulletin itself makes its legal position explicit. It does not establish new standards of conduct. It describes expectations for showing that AI-supported decisions comply with applicable insurance law.[^1] That is why adoption status and underlying authority must be checked together.

## Who and what it reaches

The bulletin addresses insurers authorized to conduct business in the issuing state. Its focus is an AI system that makes or supports decisions related to regulated insurance practices. The relevant question is the function the system performs, not whether a vendor calls the product AI or whether the company built it internally.

The document uses a broad definition of AI systems and recognizes different techniques, including predictive and generative systems. It also asks insurers to scale governance to their own circumstances. Controls should be commensurate with the insurer's own assessment of the risk its systems pose to consumers [^1]. Five things go into that assessment: the nature of the decision, the potential harm, how far a human is involved in the final call, how explainable the outcome is to the person affected, and how much the insurer leans on outside data and models.[^1]

The bulletin does not supply a universal list of high-risk systems. It does not say that every claims or underwriting model receives the same controls. The insurer needs a defensible method for deciding what level of oversight fits the use. That method belongs to the [framework implementation guide](/ai-governance-framework-implementation/).

## The written AIS Program

The central expectation is a written Artificial Intelligence Systems Program. The program should be appropriate for the insurer's use of AI and designed to mitigate the risk of adverse consumer outcomes, including outcomes that violate unfair trade-practices or unfair-discrimination law.[^1]

The bulletin organizes its guidance under General Guidelines, Governance, Risk Management and Internal Controls, and Third-Party AI Systems and Data. In practical terms, the program needs to connect:

- accountability and reporting;
- documented policies, standards, and controls;
- risk assessment proportionate to the use;
- validation, testing, and ongoing review;
- consumer notice and access to appropriate information;
- third-party acquisition, use, and oversight;
- records that allow the department to examine the program.

These are subjects, not a prescribed table of contents. The bulletin says it is not intended to prescribe specific practices or documentation. An insurer can organize the program around existing enterprise risk, model risk, product, actuarial, compliance, or internal-audit processes if the result addresses the applicable expectations.

## Governance and accountability

The governance section points toward clear responsibility, senior-management accountability, reporting to the board or an appropriate board committee, and cross-functional participation. It offers business units, product specialists, actuarial, data science, underwriting, claims, compliance, and legal as examples of relevant disciplines.[^1]

The exact organizational chart is the insurer's choice. The supervisory question is whether responsibilities, escalation, and decision rights can be followed when a system changes, performs poorly, or affects consumers. A separately scheduled roles playbook will own the practical assignment of preparers and signers; that working model should not be mistaken for regulator-prescribed staffing.

## Risk controls and testing

The bulletin expects risk management and internal controls that reflect the nature of the system and its possible harm. It discusses validation, testing, performance, accuracy, [unfair discrimination](/glossary/unfair-discrimination/), data, change management, monitoring, and human involvement.[^1]

It does not dictate one fairness test, one threshold, or one revalidation interval. Cross-regime concepts such as proxy variables and outcome differences are explained in the [disparate-impact guide](/how-disparate-impact-shapes-ai-pricing/), and New York's particular testing steps remain in the [Circular Letter 7 guide](/ny-dfs-circular-letter-7/).

Post-deployment thresholds and drift records belong to [model monitoring](/ai-model-monitoring-insurance/).

## Third-party AI

An insurer cannot move its regulatory responsibility to a vendor. The AIS Program should address the acquisition and use of third-party AI and data, including due diligence, contractual terms, audit rights, and cooperation with regulatory inquiries where appropriate and available.[^1]

The qualifiers matter. The bulletin does not guarantee that every vendor will provide every desired right, or declare one contract clause mandatory in all circumstances. The insurer still needs to understand the resulting gap, decide whether the use is acceptable, and document any limitation or compensating control. The [vendor assessment](/ai-vendor-risk-assessment/) carries the detailed questionnaire and decision record.

## How the bulletin is examined

The bulletin tells insurers that a department may request information and documentation about the development, implementation, use, and oversight of AI systems during an investigation or examination.[^1] The separate [AI Systems Evaluation Tool](/naic-ai-evaluation-tool/) shows one optional way a regulator can structure supplemental questions through Exhibits A through D.

Those instruments should not be collapsed into one checklist. The bulletin describes the insurer's program expectations. The Evaluation Tool helps a regulator select and organize inquiry. The insurer's inventory, model files, vendor records, monitoring, notices, and governance evidence are the operational materials underneath both.

## The correct next step

After interpreting the bulletin for the states and business uses in scope, move to the framework implementation guide. It turns Exhibit B and the AIS Program themes into an operating sequence. A narrower gap should go directly to its owner: inventory, vendor review, or model monitoring. The bulletin itself does not become another implementation checklist.

[^1]: National Association of Insurance Commissioners, [Model Bulletin on the Use of Artificial Intelligence Systems by Insurers](https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf), adopted December 4, 2023.