NAIC Commissioners Press a Consultant on Agentic AI Governance
At the NAIC’s Spring 2026 National Meeting in San Diego, the Innovation, Cybersecurity, and Technology (H) Committee gave its AI slot to a presentation from PwC on insurance AI trends, including agentic applications. Scott Froseth of PwC told the Committee that most carriers remain in a transitional phase, constrained by legacy architecture and data readiness, and are deploying AI as incremental point solutions rather than reworking operating models. He described agentic systems as differing from generative AI in that agents execute tasks and orchestrate workflows by combining language models with automation and process management tools, and said current implementations generally preserve human-in-the-loop controls for higher-risk decisions in underwriting and claims.
The record here is the Committee’s own minutes, still marked draft pending adoption, and its useful part is not the presentation but the questions. The questioning went at the parts of AI governance that are still unsettled, and the answers came from a consultancy rather than from the NAIC, which is worth keeping straight when this meeting gets cited later as though it produced a position.
Colton Schulz, appearing for North Dakota Commissioner Jon Godfread, asked how data governance for agentic systems differs from traditional AI. Ilana Golbin Blumenfeld of PwC answered that the principles do not change but the complexity does, because agents access, combine, and pass information across multiple data sources; she pointed to access permissions, source validation, and the risk that agent orchestration inadvertently circumvents existing controls. Commissioner Michael Yaworsky of Florida, who chairs the Committee, asked about governance under pressure to deploy quickly, and observed that legislative discussion tends to center on outcomes in a way that does not capture the full scope of a governance framework. Commissioner Hershman of Connecticut asked whether AI governance should be principles-based or prescriptive, with specific deviation thresholds when performance drifts.
Two of the answers cut against where state rules have been heading. Blumenfeld cautioned against relying on humans in the loop, on the grounds that people carry their own imperfections, at a point when a growing number of states have made human review the central control in AI-assisted insurance decisions. On thresholds, she argued that rigid uniform numbers are difficult to apply across diverse use cases and that most systems need use-case-specific evaluation rather than a single quantitative benchmark. Hershman pushed back far enough to ask whether a deviation standard becomes necessary at some point, which is the question a prescriptive regime eventually has to answer.
No framework came out of the session, and none was proposed. What a carrier can take from it is a read on where commissioners are unsure: the principles-versus-prescriptive line, and what a performance deviation has to look like before it triggers anything. Those are the same seams the evaluation tool’s exhibits probe, and agentic deployments will meet them first.
Official document
content.naic.org →The instrument itself, issued by a government, court, legislature, or standard-setting body.