NAIC APR 2, 2026 · Updated August 18, 2026 · InsureAI Wire

NAIC Proposes Vendor Registry for AI Models Sold to Insurers

Registration is voluntary in the framework the NAIC’s Third-Party Data and Models (H) Working Group re-exposed on July 8, 2026. Vendors whose data and models feed property and casualty pricing and underwriting “would be encouraged to voluntarily register” through a shared multi-state registry hosted by the NAIC. Comments closed August 5, and the document went on the agenda for the working group’s August 12 session in Columbus. Chair Jason Lapham of Colorado told the working group on July 16 that this is phase one. Claims handling, utilization review, marketing, and fraud detection sat in the broader scope first considered and remain on the table for later phases.

The material for the August 12 session carries an August 3 draft date on its cover and holds the 11 comment letters that came in by the deadline; the copy of the framework in it still bears the July 8 date. What it records therefore runs to the start of the August 12 session and no further, and so does this brief.

What a registrant would file is specified in some detail. Corporate governance documentation covers contact information, legal entity, ownership structure, and responsible officers. Model documentation covers purpose, assumptions, inputs, limitations, performance metrics, and validation processes. Data documentation reaches further, into accuracy, completeness, timeliness, representativeness, auditable data lineage, quality controls, provenance, internal oversight roles, and a defined process for identifying and remediating missing or incomplete data. Vendors would also disclose how they use consumer data and how consumers can access and correct their records, list which insurers have purchased each dataset or model, and commit, as a condition of registering, to answer regulator requests within specified timeframes. Governance programs would have to be consistent with the NAIC’s AI Principles and its Model Bulletin.

The access side is equally specific. On request, a vendor would also hand regulators input and output specifications, any fairness and bias testing results, and change logs and audit trails. Regulators would see which vendors supply models and data for products sold in their state, and which insurers bought them. The NAIC would treat registry submissions as confidential, and it is not subject to open records laws in any state. But once information reaches a state, that state’s open records law governs it, and the draft says states may need to write new statutes covering third-party vendor material or amend existing ones to include it. Information a vendor designates as confidential would go only to states with authority to keep it that way.

The draft’s executive summary states that insurers remain fully responsible for compliance with all applicable insurance laws when using third-party data or models. A closing section itemizes what that leaves with them: model suitability, insurer-level validation and monitoring, the accuracy of vendor data, and contract terms that give insurer and regulator access to model and data information. Registration does not move any of it.

Two obligations sit in the filing section rather than the registry section, and neither is written to depend on whether a vendor registered. An insurer still files rates and underwriting rules under each state’s law. A third-party dataset or model in use would have to be filed too, and the vendor would then supply what an insurer would for its own model. The draft adds that the framework does not change any state’s requirements for the filing of data and models. Where a vendor does not produce what a regulator asks for, the draft says the regulator may prohibit insurers from using that data or model for pricing or underwriting in the state. The ongoing requirements run on two different triggers. A senior leader with relevant technical expertise and formal authority over data and model governance would sign an annual attestation that the governance program is effective and that the vendor’s data and models comply with insurance law in every state where insurers use them. The vendor would separately notify the registry whenever a model or dataset is materially modified or decommissioned.

Lapham described the framework as an exposed draft, still open for comments and revisions, and the questions put to him on July 16 mark where the mechanics are unfinished. Anthony Habayeb of Monitaur said the current draft reads more as a structured repository of information than as an active review process, and Lapham agreed with that characterization. The framework does not explicitly address what happens when a data aggregator holds none of this documentation, a gap Lapham acknowledged after Eric Ellsworth of Consumers’ Checkbook raised it. Erica Eversman of the Automotive Education and Policy Institute asked what would encourage vendors to enroll, and Lapham said incentives would likely come through the carriers vendors contract with. She then asked why, if registration is an advantage for both state insurance regulators and insurers, it is not mandatory. The minutes record no answer and move to the next questioner. For now the registry is a place to look rather than a verdict to rely on, which leaves the first reading of a vendor’s governance file where vendor due diligence already puts it.

Share

InsureAI Wire seal IAW Source

Official document

content.naic.org →

The instrument itself, issued by a government, court, legislature, or standard-setting body.

Information aggregation and analysis, not legal advice. See our disclaimer.