The NAIC's AI exam questions get a comment window
As sent to subscribers on July 29, 2026. Get the next one in your inbox →
The NAIC’s evaluation tool pilot has had a September end date since it opened. What surfaced this week is what happens after it, in enough detail to put on a calendar.
This week’s story: the NAIC’s AI exam questions get a comment window
The Big Data and Artificial Intelligence Working Group has been piloting its evaluation tool in 12 states since March, inside a window the NAIC published at the start: March 2026 to September 2026, with adoption considered at the Fall National Meeting in November. Materials posted for the group’s most recent public meeting fill in what sits between those two ends. Company surveys run through September 30, and Tool 5.0 is expected to enter a 30-day comment period that month.
Those two middle steps are the new part, and they surfaced in a Coverager opinion piece by the chief executive of an AI vendor that sells into claims, reading off the working group’s posted materials rather than an NAIC announcement. Worth knowing, and not a reason to wait: none of the homework below depends on the dates holding exactly.
The Exhibit A-D structure is not going to change fundamentally between now and any adoption vote, which is what makes the work below knowable today. A comment period is also the last point at which the questions are still editable; after it closes, a carrier is reading a finished draft. Our guide to what each exhibit actually asks, and in what order is built for that week of work.
None of this is a filing obligation. The tool is an optional supplemental exhibit a regulator can pick up during a market conduct exam, a financial condition exam, or financial analysis, and each one is told to ask only what the inquiry needs. Optional is the regulator’s option, not yours. Twelve states are making that call this summer, each on its own terms, with the authority to adapt the questions to its own jurisdiction.
The federal layer moved on the same file from underneath. The AI Kill Switch Act, introduced July 23, would let Homeland Security order a covered system throttled or shut down outright. Its two thresholds, $100 million of compute cost to build the system and $500 million in revenue from it, miss the claims-triage and underwriting vendors most carriers actually sign with. What they catch is the model tier underneath those vendors. Exhibit D asks you to name the third party behind each data element; the bill is a reminder that the name you write down has a supplier of its own.
Full breakdown of the bill, including where the two coverage tests actually land: AI ‘Kill Switch’ Bill Reaches the Labs Under Insurers’ AI Vendors. Source for the NAIC dates: The NAIC is building an AI evaluation playbook. Claims leaders should know what it will ask (opinion, Coverager).
What to do this week
- Put the September comment window on the calendar now. Tool 5.0 is the version carriers and vendors still get to argue with; the NAIC has not published an opening date, and the working group meets August 13 at the Summer National Meeting.
- Count the AI models you would report under Exhibit A. The exhibit has fifteen operational rows, so the misses are the ones outside pricing and claims: reserves, reinsurance, catastrophe triage, utilization management. Exhibit A wants four counts per area and the use cases in prose, so the answer either already exists or gets assembled under a deadline.
- Walk the 14 governance elements in Exhibit B (3a through 3n) and split them into two columns, evidenced and not. Put a name and a date against everything in the second column. That two-column sheet is what you hand over.
- Decide which of your models the company would call high-risk, and write down why. Nobody hands you that definition. Your tiering scheme is what decides which of your models Exhibit C reaches.
- Start the Exhibit D data map. For each model, list the data elements used in training or testing, whether they are internal or third-party, and if third-party, the vendor’s name.
On the Docket
- August 2, 2026: EU AI Act Article 50 transparency obligations apply. The high-risk obligations that were due the same day now run to December 2027. Any carrier with EU life or health operations, or a consumer-facing AI system reaching the EU. Regulation (EU) 2026/1744
- August 13, 2026: NAIC Big Data and AI (H) Working Group meets at the Summer National Meeting, 1:00 to 2:00 PM ET; no agenda posted yet. Any carrier that could face a pilot or exam request. NAIC committee page
- September 2026: Company surveys in the 12-state evaluation tool pilot run through September 30, and Tool 5.0 is expected to open a 30-day comment period during the month. Pilot participants, plus carriers and vendors that want input before adoption consideration. Coverager
- November 2026: A later version of the tool could reach the NAIC for adoption consideration. Every carrier, because adoption moves the exhibits into the 2027 examiner toolkit.
- January 1, 2027: Illinois’s frontier AI act takes effect, though its independent third-party audit and framework duties do not start for another year. The same day, Minnesota bars an adverse determination reached on automated processing alone, and the reviewer it requires is an appropriate health professional, not a physician in every case. Carriers on frontier-vendor stacks and health writers.
This week in brief
Governance
The NAIC is close to a single front door for breach reporting. Its Cybersecurity (H) Working Group adopted the project document for a centralized portal on March 13, and a first draft of the standard form rides along with it; the portal would let a licensee file one cybersecurity event notification instead of one per adopting state. The 72-hour clock under Model Law #668 still runs only where the state-by-state gates open, but a single filing would surface to all of those regulators at the same moment, which would put the weight on when an event is formally determined internally rather than on the filing mechanics. NAIC intake request
Chubb, Westfield and WTW distribution leaders landed on one sequencing rule in remarks Digital Insurance gathered: nothing ships until it has been tested, because a launch is not reversible. Chubb’s Nicholas Davis put it plainly, “You can’t go back.” Exhibit C question 8 asks how a model was validated prior to deployment, which is that rule written for an examiner. Digital Insurance
The EU moved its high-risk AI deadline out by 16 months, six days before it would have landed. Regulation (EU) 2026/1744 entered into force July 27 and pushes the Annex III obligations to December 2, 2027, with product-embedded Annex I systems going to August 2028; Annex III point 5(c) is AI used for risk assessment and pricing in life and health insurance. What still arrives on August 2 is the Article 50 transparency layer, telling people they are dealing with an AI system and marking generated content, though generative systems already on the market have until December 2, 2026 to meet the marking rule. Regulation (EU) 2026/1744
Business Lines
Aon launched an AI Risk Diagnostic, an enterprise assessment it says aligns with ISO standards, the EU AI Act, and the NIST AI Risk Management Framework. The commercial context comes from elsewhere in the same Insurance Business write-up: Willis research finding that firms without documented AI governance now face coverage denials at renewal, with professional liability carriers moving to affirmative warranties or absolute exclusions instead of staying silent on AI. Carriers buying professional liability should expect the AI-governance question on a renewal application before they ever see it on an exam. Insurance Business America
A Delaware judge let Robby Starbuck’s defamation claims against Google proceed, denying the company’s motion to dismiss a suit over statements Starbuck alleges its Bard model made about him. Nothing has been decided on the merits and Google is defending the case. Judge Meghan Adams described the dispute as “a new frontier for defamation law” while resolving the early stages on ordinary defamation precedent. Anyone writing AI liability now has a live case on whether a model’s output is the operator’s own speech. Insurance Journal
The US National Vulnerability Database recorded 45,207 software flaws between January and late July, approaching the whole of 2025 and putting discovery on pace to roughly double year over year; Oracle patched 1,449 in its July update against 309 a year ago. Google attributes its own share to AI tooling, and much of the new volume is vendors’ internal teams reporting on their own products: 401 of Chrome’s 433 July bugs were found by Google itself. Exploitation has not moved with discovery, though, and the government’s Known Exploited Vulnerabilities catalog shows no rise this year. For cyber underwriters the number that has changed is patching volume; loss frequency has not followed it. Insurance Journal
From the Guides
Exhibit D is 25 rows and one column that decides how long the whole exercise takes: for every data element in use, the name of the outside company that supplied it. Our Exhibit D checklist lays the categories out as a worksheet, routes each row to the team that would actually know the answer, and names the three problems carriers hit on the first pass.
That’s the week. If you want us to dig into any of these further, reply to the email this issue arrived in. We read every reply.
– The Editor, InsureAI Wire