# How Shadow AI Undermines NAIC Exhibit A

> Shadow AI corrupts the counts reported in NAIC Exhibit A. What ungoverned AI use means for insurers, and a practical plan to close the gap.

- Source: https://insureaiwire.com/shadow-ai-insurance/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-08-01

---
Employees across insurance companies use artificial intelligence to summarize claims notes, draft customer emails, build pricing spreadsheets, and write board materials. Many do so without the knowledge of IT, legal, or compliance. The resulting blind spot now affects security, records, and regulatory answers.

[Shadow AI](/glossary/shadow-ai/) is the use of AI tools, applications, or services that sit outside an organization's approved technology governance framework.[^1] Our [NAIC AI Evaluation Tool guide](/naic-ai-evaluation-tool/) walks the four exhibits this breaks. For insurers, the issue goes beyond data leakage or security risk: the NAIC AI Systems Evaluation Tool begins with [Exhibit A](/glossary/exhibit-a/), which asks carriers to quantify their AI systems by operational area.[^2] A tool no one knows about cannot be inventoried. A model used by a claims team but never reviewed by compliance cannot be documented. That gap turns an operational nuisance into a regulatory failure.

## Why Exhibit A is the right place to start

The NAIC AI Systems Evaluation Tool is built around four exhibits. Exhibit A is the foundation because it asks a simple question: what AI systems do you actually use? Regulators want to know the number of models, where they sit in the organization, what decisions they influence, and whether they have been updated recently [^2]. The purpose is to give regulators a baseline before they move into governance, risk, and high-risk system details.[^2]

The tool itself suggests regulators use Exhibit A first and read the answers to decide whether further inquiry is needed at all.[^2] Counsel advising carriers on pilot requests reads the same signal from the other side: the pilot is positioned as a risk identification exercise, so the answers can influence how a regulator sizes the insurer's inherent risk profile and how far an examination reaches.[^3] If those counts come from an incomplete system inventory, the rest of the evaluation becomes harder to defend. A carrier can have a polished board-level [AI governance](/ai-governance-in-insurance/) policy and a vendor oversight program on paper, but if the actual AI footprint is larger than the inventory shows, regulators will notice the mismatch. The question then becomes whether the company did not know, or did not want to know. Either answer is bad.

Exhibit A asks for counts across operational and program areas. A carrier needs an underlying register to produce those counts; the [AI inventory playbook](/ai-inventory-by-line-of-business/) owns that register's fields and maintenance. The tool's definition of an AI system is broad enough to reach tools embedded in third-party software, AI features inside productivity suites, and locally built scripts [^2]. Those examples are ours, read off the definition rather than listed in the exhibit. A claims adjuster using an AI-enabled browser extension to summarize medical records is using an AI system. An underwriter running pricing scenarios through a spreadsheet with an AI add-in is using an AI system. If compliance does not know those tools exist, they cannot be reflected in the counts.

## How shadow AI creates the gap

Shadow AI appears in insurance organizations in predictable ways. Employees use public AI platforms to draft correspondence or analyze documents. They activate AI features in existing software without a formal review. They build small internal tools or use AI-enabled browser extensions [^1]. In each case, the tool is useful, the data leaves the approved environment, and the activity is invisible to governance.[^1]

The structural problem is that AI risk does not fit neatly into one function. Business owns the value, risk and audit own oversight, IT and cyber own execution and protection, legal and compliance own regulatory alignment, data and privacy own ethical use, and procurement owns vendor accountability.[^1] When no single function owns the whole AI lifecycle, gaps form in the handoffs. A procurement team may vet a vendor contract, but not know the claims department has turned on an AI feature inside that vendor's platform. IT may monitor network traffic, but not notice that a licensed employee is using an AI tool on a personal account.

The consequences are not hypothetical. As advisory firm Cherry Bekaert has documented, a recent SEC cybersecurity disclosure involved an employee's use of an unsanctioned AI tool that triggered a public-company disclosure. The incident did not require a breach or an external attacker. It required only an employee using a tool that governance had not approved or monitored.[^1] For insurers, the same dynamic applies to producer data, claims files, and policyholder information.

## Why insurance is especially vulnerable

Insurance companies face a specific shadow AI risk because of how decisions are made. Pricing, underwriting, claims, and customer service are distributed across business units, regions, and third-party partners. Each group may adopt AI tools to speed up its own work. The central compliance team may not have visibility into what each group is using until an exam notice arrives.

Third-party relationships make the problem worse. Agents, brokers, managing general agents, and claims administrators may use AI tools that the carrier does not control. The [NAIC Model Bulletin on the Use of AI Systems by Insurers](/naic-model-bulletin/) reaches part of this. An AIS Program should address the data and AI systems an insurer acquires from a third party, with due diligence and the exercise of audit rights among the things that program may include, as appropriate.[^4] It does not speak to a distribution partner's own tooling, which is where visibility usually runs out first.

Formal adoption is already broad enough that discovery cannot stop at the tools compliance approved. An adjuster may use an AI service to summarize notes, while a customer service representative may use another to draft responses. Each use looks small in isolation. Together they can produce an AI footprint materially different from the one on file. The [health insurance map](/ai-in-health-insurance/) owns the NAIC survey numbers for that line of business.

## What compliance officers can do in one month

A directionally complete and defensible inventory is a realistic first goal; eliminating every unauthorized tool on day one is not. The following steps can be completed in roughly one month, after which the organization can close remaining gaps over time.

First, map the known AI systems. Start with the obvious sources: approved vendor contracts, IT procurement records, model risk management files, and the legal team's AI use policy acknowledgments. This is the inventory the company already thinks it has. It is the baseline.

Second, ask the business units directly. A company cannot assess its exposure without knowing which platforms its people use and what data gets submitted to them.[^1] Send a short questionnaire to each line of business and function, asking three questions: what AI tools are you using, what decisions do they influence, and what data do they process. Explain that the exercise completes the inventory and closes control gaps. The answers will surface tools that central records missed.

Third, check network and SaaS spending data. Shadow AI tools often leave a financial footprint before they leave a security footprint. Look for new software purchases, browser extension deployments, or API calls to AI services. IT and finance can run this together. The results will identify tools that employees may not have reported.

Fourth, document the gaps honestly. When a tool is discovered that is not in the approved inventory, record what it does, who uses it, what data it touches, and whether it can be brought into governance or retired. Do not hide shadow AI findings from the official inventory. Neither the Model Bulletin nor the evaluation tool says anything about how to present a gap, so treat what follows as our judgment: a disclosed gap with a named owner and a remediation date is easier to defend than an implausibly clean inventory that one follow-up question can puncture.

## How to keep the inventory current

New AI features appear inside existing software every quarter, so the initial inventory sprint needs a repeatable follow-up process [^1]. Assign an owner for the AI inventory. That owner should be accountable for updating the inventory when new AI systems are deployed, when vendors release AI features, or when business units report new use cases. The owner should also be responsible for escalating high-risk findings to legal, compliance, and risk committees.[^1]

Integrate the inventory into the existing AI governance program. The NAIC Model Bulletin expects a written AI Systems Program covering governance, risk management, internal controls, consumer notice, and [vendor oversight](/glossary/vendor-oversight/).[^4] The inventory should be the first document referenced in that program and the first document updated when something changes.

Finally, train employees on what shadow AI is and how to report it. Many employees do not know that an AI-enabled browser extension or a personal AI account is a governance issue. Clear guidance and a simple reporting channel can turn employees into sensors rather than liabilities. Training should be specific: give examples of tools that are allowed, tools that require approval, and tools that are prohibited.

## The link to Exhibits B, C, and D

A complete system inventory makes Exhibit A's counts reliable and the rest of the NAIC evaluation tool easier. Exhibit B asks about governance and risk management [^2]. If the underlying register is wrong, the governance structure is governing the wrong set of systems. Exhibit C asks about high-risk AI systems. If the register is incomplete, high-risk systems may be missed entirely. Exhibit D asks about data and model details. Regulators cannot review data lineage for a model that was never identified.[^2]

<figure class="figure">
<svg viewBox="0 0 460 340" width="460" role="img">
<title>Exhibit A's AI system counts have a gap caused by undocumented shadow AI. A red line shows that gap propagating upward, making Exhibit B on governance, Exhibit C on high-risk systems, and Exhibit D on data lineage all suspect.</title>
<defs>
<pattern id="hatch-gap" width="8" height="8" patternUnits="userSpaceOnUse"><path d="M-1 1 L1 -1 M0 8 L8 0 M7 9 L9 7" class="s-red" stroke-width="1.1"/></pattern>
</defs>
<rect x="20" y="30" width="130" height="70" fill="none" class="s-ink" stroke-width="2"/>
<rect x="165" y="30" width="130" height="70" fill="none" class="s-ink" stroke-width="2"/>
<rect x="310" y="30" width="130" height="70" fill="none" class="s-ink" stroke-width="2"/>
<text x="85" y="58" text-anchor="middle" class="t-label f-ink" font-size="14">EXHIBIT B</text>
<text x="85" y="76" text-anchor="middle" class="t-label f-soft" font-size="14">GOV. &amp; RISK</text>
<text x="230" y="58" text-anchor="middle" class="t-label f-ink" font-size="14">EXHIBIT C</text>
<text x="230" y="76" text-anchor="middle" class="t-label f-soft" font-size="14">HIGH-RISK AI</text>
<text x="375" y="58" text-anchor="middle" class="t-label f-ink" font-size="14">EXHIBIT D</text>
<text x="375" y="76" text-anchor="middle" class="t-label f-soft" font-size="14">DATA &amp; MODELS</text>
<rect x="81.5" y="96.5" width="7" height="7" class="f-red"/>
<rect x="226.5" y="96.5" width="7" height="7" class="f-red"/>
<rect x="371.5" y="96.5" width="7" height="7" class="f-red"/>
<line x1="85" y1="170" x2="375" y2="170" class="s-red" stroke-width="2"/>
<line x1="85" y1="100" x2="85" y2="170" class="s-red" stroke-width="2"/>
<line x1="230" y1="100" x2="230" y2="170" class="s-red" stroke-width="2"/>
<line x1="375" y1="100" x2="375" y2="170" class="s-red" stroke-width="2"/>
<line x1="230" y1="170" x2="230" y2="234" class="s-red" stroke-width="2"/>
<polygon points="230,240 224,228 236,228" class="f-red"/>
<text x="230" y="212" text-anchor="middle" class="t-label t-halo f-red" font-size="14">UNDOCUMENTED AI</text>
<rect x="20" y="240" width="140" height="60" fill="none" class="s-ink" stroke-width="2"/>
<rect x="160" y="240" width="140" height="60" fill="url(#hatch-gap)" class="s-ink" stroke-width="2"/>
<rect x="300" y="240" width="140" height="60" fill="none" class="s-ink" stroke-width="2"/>
<text x="230" y="326" text-anchor="middle" class="t-label f-ink" font-size="16">EXHIBIT A: AI SYSTEM COUNTS</text>
</svg>
<figcaption>FIG. 1: WHY A GAP IN EXHIBIT A BREAKS B, C, AND D</figcaption>
</figure>

For insurers preparing for the NAIC evaluation tool, inventory is the prerequisite for every other answer. Shadow AI leaves that inventory incomplete and casts doubt on the governance framework built over it. Fixing the register is the fastest way to reduce regulatory risk across the program.

Leaving it alone costs far more than the shadow tool is worth. Every downstream answer inherits the error: governance documented over the wrong population, high-risk models never flagged as high-risk, data lineage traced for systems that were never the problem. Every one of those tasks can be executed correctly and still be executed against the wrong list.

[^1]: Cherry Bekaert, "What Is Shadow AI and How Can This Governance Blind Spot Trigger an SEC Disclosure?," July 2, 2026: https://www.cbh.com/insights/articles/what-is-shadow-ai-its-sec-disclosure-risk-cherry-bekaert/
[^2]: NAIC, "AI Systems Evaluation Tool 4.0," Exhibit A: Quantify Regulated Entity's Use of AI Systems: https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf
[^3]: Foley & Lardner, "What To Do If You Receive an NAIC AI Systems Evaluation Tool Pilot Request," 2026: https://www.foley.com/p/102mmre/what-to-do-if-you-receive-an-naic-ai-systems-evaluation-tool-pilot-request/
[^4]: NAIC Model Bulletin, "Use of Artificial Intelligence Systems by Insurers," adopted December 4, 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf