NAIC Exposes the AI Risk Evaluation Supplement With Comments Due September 29
The NAIC has put its AI Risk Evaluation Supplement out for comment. The Big Data and Artificial Intelligence (H) Working Group’s page posts version 5.0 as a Word file “for a 30-day comment period ending Tuesday, September 29, 2026,” and directs written comments to Scott Sobel or Miguel Romero at the NAIC by close of business that day. The group’s meeting materials packet for August 31 runs 40 pages, and its second attachment holds three presentation slides, a 23-page draft of the supplement, a summary of changes written by NAIC staff, and a July 21 comment letter from ACLI. Our August 27 report said a summary of changes was circulating about a document the public did not have. The packet carries both, and the summary now posted beside version 5.0 is that same staff document.
The agenda listed the item as an update from Coral Manning of Wisconsin, and the packet’s timeline slide shows why that wording matters. It files the August session under “BDAIWG Mtg. to Introduce v. 5.0” and places “V. 5.0 exposed (30 days)” in September. October brings a working group meeting for comment on 5.0 and a 14-day exposure of version 6.0. November brings revisions from that shorter window, a second comment meeting, and consideration of version 7.0 for adoption at the Fall National Meeting. Neither the agenda nor the slide put exposure in August, and the window that is now open came from a separate posting on the working group’s page, one that calls itself a follow-up to the August 31 meeting. That posting gives no date on which the 30 days began.
A second slide lists the pilot states by name: California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. Earlier dispatches carried the count without the roster. A footnote on the timeline slide adds that timing varies by state, that not every pilot may finish by September 30, and that the pilot experience will inform drafts “through adoption and future iterations.”
The slide summarizing changes from version 4.0 leads with definitions. The draft defines Agentic AI as systems that can “pursue objectives across multiple steps without requiring human input at each stage.” Such a system does “not just respond to a single prompt or instruction, but actively executes a process.” AI Model, Direct Consumer Impact, Materiality, Material Financial Impact, and Third Party are defined. The change slide’s definition list names the first three, not the last two. Generalized linear models get their first definition here too. An AIS Program is “the controls and processes that an insurer adopts and implements to ensure the responsible use of AI Systems.” Staff record the AI Model definition as an addition drawn from “the NIST/WH Executive Order language,” and record one removal, “Degree of Potential Harm to Consumers.”
Exhibit edits are the third bullet on that slide. Requests the previous version only implied are now written out, and in staff’s phrasing, “regulators now ask for a Model Inventory.” Exhibit A’s revised columns gather model type information separately for AI models with Direct Consumer Impact and for those with Material Financial Impact. Exhibit B is now titled for the AIS Program and offered as narrative or checklist; the narrative version gains a question on explainability and transparency at 3d, the checklist version questions on materiality at 3o and third-party model oversight at 3p. Our standing guide to the exhibits describes the version this draft revises.
On generalized linear models the packet holds two documents pointing in opposite directions. The draft’s new machine learning guidance says GLMs, “as with other machine learning techniques,” are “not without risk of causing unfair discrimination or other adverse consumer outcomes.” The same sentence asks for governance across the model’s life cycle, from data quality and development through validation and monitoring to legal compliance. ACLI’s July 21 letter, addressed to working group chair Nathan Houdek and written about version 4.0, recommends “at minimum” excluding “predictive models with transparent structures, such as Generalized Linear Models (GLMs) and Generalized Additive Models (GAMs), from the scope of the exhibits.” The letter cites EIOPA analysis placing the risk in governance and business practices rather than model architecture. The draft names no comment and no commenter, and the packet records no reply to the letter.
The phrase “AI Systems Evaluation Tool” appears twice in the 40 pages, both times inside the ACLI letter, which was written about the version that still carried the old name. The draft body does not use it anywhere. Version numbers live outside the document: 5.0, 6.0, and 7.0 appear only on the slides, and the 23-page draft prints no version number at all.
Nothing in the packet adopts this text. We read the version now out for comment against the packet’s 23-page draft, and it is that draft word for word. Every difference we found comes from pulling text out of a Word file on one side and a PDF on the other, with nothing cut on either side. The largest is an Exhibit A heading row that the Word file stores once and the PDF prints on both pages the table runs across. Version 5.0 as posted still stamps itself a draft, with “DRAFT AI Risk Evaluation Supplement” and a page number in the footers and a DRAFT watermark in the headers. No version number appears in the body, the headers, or the footers. Three asks are legible now regardless: Exhibit A names a Model Inventory outright, Exhibit B is built around the AIS Program rather than a governance framework, and 3p asks how third-party models are overseen. September 29 is a deadline for commenting on those asks, not for answering them. No date in the packet requires a carrier to have those answers ready.
Official document
content.naic.org →The instrument itself, issued by a government, court, legislature, or standard-setting body.