Inside the NAIC AI Model Bulletin
What the NAIC AI Model Bulletin is, how adoption works, what belongs in a written AIS Program, and which implementation guide to use next.
In this article
For Compliance officers, CROs, and GCs interpreting the Model Bulletin for an insurer's footprint.
Read if You want to understand the bulletin's status, scope, and AIS Program expectations before designing the implementation.
The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023.1 The document is easy to misclassify. It is not a model law, and it does not create a new cause of action or penalty. It explains what a commissioner expects from insurers using AI in decisions and actions that can affect consumers, under insurance law that already applies.
That distinction determines how to use it. Read the bulletin as an authority document: what it says, who it addresses, and what kind of program it expects. The broader governance map shows where it sits. The implementation and vendor owner guides handle operating detail; organization-level exam readiness remains a separately scheduled guide.
What the bulletin is
The NAIC writes model material for state insurance regulators. A state then chooses whether and how to adopt, adapt, reference, or ignore it. The state tracker records the instrument in each jurisdiction. A “not adopted” entry does not mean AI-assisted decisions fall outside that state’s unfair-practices, discrimination, claims, rating, or examination authority. It means the state has not used this model instrument in the recorded form.
The bulletin itself makes its legal position explicit. It does not establish new standards of conduct. It describes expectations for showing that AI-supported decisions comply with applicable insurance law.1 That is why adoption status and underlying authority must be checked together.
Who and what it reaches
The bulletin addresses insurers authorized to conduct business in the issuing state. Its focus is an AI system that makes or supports decisions related to regulated insurance practices. The relevant question is the function the system performs, not whether a vendor calls the product AI or whether the company built it internally.
The document uses a broad definition of AI systems and recognizes different techniques, including predictive and generative systems. It also asks insurers to scale governance to their own circumstances. Controls should be commensurate with the insurer’s own assessment of the risk its systems pose to consumers 1. Five things go into that assessment: the nature of the decision, the potential harm, how far a human is involved in the final call, how explainable the outcome is to the person affected, and how much the insurer leans on outside data and models.1
The bulletin does not supply a universal list of high-risk systems. It does not say that every claims or underwriting model receives the same controls. The insurer needs a defensible method for deciding what level of oversight fits the use. That method belongs to the framework implementation guide.
The written AIS Program
The central expectation is a written Artificial Intelligence Systems Program. The program should be appropriate for the insurer’s use of AI and designed to mitigate the risk of adverse consumer outcomes, including outcomes that violate unfair trade-practices or unfair-discrimination law.1
The bulletin organizes its guidance under General Guidelines, Governance, Risk Management and Internal Controls, and Third-Party AI Systems and Data. In practical terms, the program needs to connect:
- accountability and reporting;
- documented policies, standards, and controls;
- risk assessment proportionate to the use;
- validation, testing, and ongoing review;
- consumer notice and access to appropriate information;
- third-party acquisition, use, and oversight;
- records that allow the department to examine the program.
These are subjects, not a prescribed table of contents. The bulletin says it is not intended to prescribe specific practices or documentation. An insurer can organize the program around existing enterprise risk, model risk, product, actuarial, compliance, or internal-audit processes if the result addresses the applicable expectations.
Governance and accountability
The governance section points toward clear responsibility, senior-management accountability, reporting to the board or an appropriate board committee, and cross-functional participation. It offers business units, product specialists, actuarial, data science, underwriting, claims, compliance, and legal as examples of relevant disciplines.1
The exact organizational chart is the insurer’s choice. The supervisory question is whether responsibilities, escalation, and decision rights can be followed when a system changes, performs poorly, or affects consumers. A separately scheduled roles playbook will own the practical assignment of preparers and signers; that working model should not be mistaken for regulator-prescribed staffing.
Risk controls and testing
The bulletin expects risk management and internal controls that reflect the nature of the system and its possible harm. It discusses validation, testing, performance, accuracy, unfair discrimination, data, change management, monitoring, and human involvement.1
It does not dictate one fairness test, one threshold, or one revalidation interval. Cross-regime concepts such as proxy variables and outcome differences are explained in the disparate-impact guide, and New York’s particular testing steps remain in the Circular Letter 7 guide.
Post-deployment thresholds and drift records belong to model monitoring.
Third-party AI
An insurer cannot move its regulatory responsibility to a vendor. The AIS Program should address the acquisition and use of third-party AI and data, including due diligence, contractual terms, audit rights, and cooperation with regulatory inquiries where appropriate and available.1
The qualifiers matter. The bulletin does not guarantee that every vendor will provide every desired right, or declare one contract clause mandatory in all circumstances. The insurer still needs to understand the resulting gap, decide whether the use is acceptable, and document any limitation or compensating control. The vendor assessment carries the detailed questionnaire and decision record.
How the bulletin is examined
The bulletin tells insurers that a department may request information and documentation about the development, implementation, use, and oversight of AI systems during an investigation or examination.1 The separate AI Systems Evaluation Tool shows one optional way a regulator can structure supplemental questions through Exhibits A through D.
Those instruments should not be collapsed into one checklist. The bulletin describes the insurer’s program expectations. The Evaluation Tool helps a regulator select and organize inquiry. The insurer’s inventory, model files, vendor records, monitoring, notices, and governance evidence are the operational materials underneath both.
The correct next step
After interpreting the bulletin for the states and business uses in scope, move to the framework implementation guide. It turns Exhibit B and the AIS Program themes into an operating sequence. A narrower gap should go directly to its owner: inventory, vendor review, or model monitoring. The bulletin itself does not become another implementation checklist.
Footnotes
The Bottom Line
- The bulletin does not create a new statute; it explains supervisory expectations under existing insurance law when AI supports regulated decisions.
- Its core deliverable is a written AIS Program scaled to the insurer's systems, risks, and consumer impact.
- Third-party AI stays inside the insurer's responsibility, but the bulletin qualifies several vendor practices with terms such as appropriate and available.
- Implementation sequence, vendor worksheets, and examination files belong to separate owner articles.
How Insurers Can Implement an AI Governance Framework for NAIC Exhibit B
A practical guide to implementing an AI governance framework for NAIC Exhibit B, from AIS programs to vendor oversight and consumer evidence.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
Who Owns the Evidence in Insurance AI Governance
Insurance AI governance roles as an ownership matrix: which function prepares each piece of NAIC evidence, which one signs it, and who answers for it in an exam.
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
How to Identify the High-Risk AI Systems Exhibit C Asks About
Five screening lines that turn an existing AI inventory into a defensible list of the high-risk systems NAIC Exhibit C asks about, and the record behind it.
AI Model Monitoring After the Model Goes Live
A playbook for insurers on AI model monitoring, validation, drift detection, and retesting records that satisfy NAIC Model Bulletin and Exhibit C expectations.
Information aggregation and analysis, not legal advice. See our disclaimer.