How Shadow AI Undermines NAIC Exhibit A
Shadow AI corrupts the counts reported in NAIC Exhibit A. What ungoverned AI use means for insurers, and a practical plan to close the gap.
In this article
For Whoever owns the AI inventory, compliance, risk, or legal, and will have to defend it in an exam.
Read if You have an AI governance policy on paper but aren't sure the AI actually in use across the company is all on the books.
Employees across insurance companies use artificial intelligence to summarize claims notes, draft customer emails, build pricing spreadsheets, and write board materials. Many do so without the knowledge of IT, legal, or compliance. The resulting blind spot now affects security, records, and regulatory answers.
Shadow AI is the use of AI tools, applications, or services that sit outside an organization’s approved technology governance framework.1 Our NAIC AI Evaluation Tool guide walks the four exhibits this breaks. For insurers, the issue goes beyond data leakage or security risk: the NAIC AI Systems Evaluation Tool begins with Exhibit A, which asks carriers to quantify their AI systems by operational area.2 A tool no one knows about cannot be inventoried. A model used by a claims team but never reviewed by compliance cannot be documented. That gap turns an operational nuisance into a regulatory failure.
Why Exhibit A is the right place to start
The NAIC AI Systems Evaluation Tool is built around four exhibits. Exhibit A is the foundation because it asks a simple question: what AI systems do you actually use? Regulators want to know the number of models, where they sit in the organization, what decisions they influence, and whether they have been updated recently 2. The purpose is to give regulators a baseline before they move into governance, risk, and high-risk system details.2
The tool itself suggests regulators use Exhibit A first and read the answers to decide whether further inquiry is needed at all.2 Counsel advising carriers on pilot requests reads the same signal from the other side: the pilot is positioned as a risk identification exercise, so the answers can influence how a regulator sizes the insurer’s inherent risk profile and how far an examination reaches.3 If those counts come from an incomplete system inventory, the rest of the evaluation becomes harder to defend. A carrier can have a polished board-level AI governance policy and a vendor oversight program on paper, but if the actual AI footprint is larger than the inventory shows, regulators will notice the mismatch. The question then becomes whether the company did not know, or did not want to know. Either answer is bad.
Exhibit A asks for counts across operational and program areas. A carrier needs an underlying register to produce those counts; the AI inventory playbook owns that register’s fields and maintenance. The tool’s definition of an AI system is broad enough to reach tools embedded in third-party software, AI features inside productivity suites, and locally built scripts 2. Those examples are ours, read off the definition rather than listed in the exhibit. A claims adjuster using an AI-enabled browser extension to summarize medical records is using an AI system. An underwriter running pricing scenarios through a spreadsheet with an AI add-in is using an AI system. If compliance does not know those tools exist, they cannot be reflected in the counts.
How shadow AI creates the gap
Shadow AI appears in insurance organizations in predictable ways. Employees use public AI platforms to draft correspondence or analyze documents. They activate AI features in existing software without a formal review. They build small internal tools or use AI-enabled browser extensions 1. In each case, the tool is useful, the data leaves the approved environment, and the activity is invisible to governance.1
The structural problem is that AI risk does not fit neatly into one function. Business owns the value, risk and audit own oversight, IT and cyber own execution and protection, legal and compliance own regulatory alignment, data and privacy own ethical use, and procurement owns vendor accountability.1 When no single function owns the whole AI lifecycle, gaps form in the handoffs. A procurement team may vet a vendor contract, but not know the claims department has turned on an AI feature inside that vendor’s platform. IT may monitor network traffic, but not notice that a licensed employee is using an AI tool on a personal account.
The consequences are not hypothetical. As advisory firm Cherry Bekaert has documented, a recent SEC cybersecurity disclosure involved an employee’s use of an unsanctioned AI tool that triggered a public-company disclosure. The incident did not require a breach or an external attacker. It required only an employee using a tool that governance had not approved or monitored.1 For insurers, the same dynamic applies to producer data, claims files, and policyholder information.
Why insurance is especially vulnerable
Insurance companies face a specific shadow AI risk because of how decisions are made. Pricing, underwriting, claims, and customer service are distributed across business units, regions, and third-party partners. Each group may adopt AI tools to speed up its own work. The central compliance team may not have visibility into what each group is using until an exam notice arrives.
Third-party relationships make the problem worse. Agents, brokers, managing general agents, and claims administrators may use AI tools that the carrier does not control. The NAIC Model Bulletin on the Use of AI Systems by Insurers reaches part of this. An AIS Program should address the data and AI systems an insurer acquires from a third party, with due diligence and the exercise of audit rights among the things that program may include, as appropriate.4 It does not speak to a distribution partner’s own tooling, which is where visibility usually runs out first.
Formal adoption is already broad enough that discovery cannot stop at the tools compliance approved. An adjuster may use an AI service to summarize notes, while a customer service representative may use another to draft responses. Each use looks small in isolation. Together they can produce an AI footprint materially different from the one on file. The health insurance map owns the NAIC survey numbers for that line of business.
What compliance officers can do in one month
A directionally complete and defensible inventory is a realistic first goal; eliminating every unauthorized tool on day one is not. The following steps can be completed in roughly one month, after which the organization can close remaining gaps over time.
First, map the known AI systems. Start with the obvious sources: approved vendor contracts, IT procurement records, model risk management files, and the legal team’s AI use policy acknowledgments. This is the inventory the company already thinks it has. It is the baseline.
Second, ask the business units directly. A company cannot assess its exposure without knowing which platforms its people use and what data gets submitted to them.1 Send a short questionnaire to each line of business and function, asking three questions: what AI tools are you using, what decisions do they influence, and what data do they process. Explain that the exercise completes the inventory and closes control gaps. The answers will surface tools that central records missed.
Third, check network and SaaS spending data. Shadow AI tools often leave a financial footprint before they leave a security footprint. Look for new software purchases, browser extension deployments, or API calls to AI services. IT and finance can run this together. The results will identify tools that employees may not have reported.
Fourth, document the gaps honestly. When a tool is discovered that is not in the approved inventory, record what it does, who uses it, what data it touches, and whether it can be brought into governance or retired. Do not hide shadow AI findings from the official inventory. Neither the Model Bulletin nor the evaluation tool says anything about how to present a gap, so treat what follows as our judgment: a disclosed gap with a named owner and a remediation date is easier to defend than an implausibly clean inventory that one follow-up question can puncture.
How to keep the inventory current
New AI features appear inside existing software every quarter, so the initial inventory sprint needs a repeatable follow-up process 1. Assign an owner for the AI inventory. That owner should be accountable for updating the inventory when new AI systems are deployed, when vendors release AI features, or when business units report new use cases. The owner should also be responsible for escalating high-risk findings to legal, compliance, and risk committees.1
Integrate the inventory into the existing AI governance program. The NAIC Model Bulletin expects a written AI Systems Program covering governance, risk management, internal controls, consumer notice, and vendor oversight.4 The inventory should be the first document referenced in that program and the first document updated when something changes.
Finally, train employees on what shadow AI is and how to report it. Many employees do not know that an AI-enabled browser extension or a personal AI account is a governance issue. Clear guidance and a simple reporting channel can turn employees into sensors rather than liabilities. Training should be specific: give examples of tools that are allowed, tools that require approval, and tools that are prohibited.
The link to Exhibits B, C, and D
A complete system inventory makes Exhibit A’s counts reliable and the rest of the NAIC evaluation tool easier. Exhibit B asks about governance and risk management 2. If the underlying register is wrong, the governance structure is governing the wrong set of systems. Exhibit C asks about high-risk AI systems. If the register is incomplete, high-risk systems may be missed entirely. Exhibit D asks about data and model details. Regulators cannot review data lineage for a model that was never identified.2
For insurers preparing for the NAIC evaluation tool, inventory is the prerequisite for every other answer. Shadow AI leaves that inventory incomplete and casts doubt on the governance framework built over it. Fixing the register is the fastest way to reduce regulatory risk across the program.
Leaving it alone costs far more than the shadow tool is worth. Every downstream answer inherits the error: governance documented over the wrong population, high-risk models never flagged as high-risk, data lineage traced for systems that were never the problem. Every one of those tasks can be executed correctly and still be executed against the wrong list.
Footnotes
-
Cherry Bekaert, “What Is Shadow AI and How Can This Governance Blind Spot Trigger an SEC Disclosure?,” July 2, 2026: https://www.cbh.com/insights/articles/what-is-shadow-ai-its-sec-disclosure-risk-cherry-bekaert/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
NAIC, “AI Systems Evaluation Tool 4.0,” Exhibit A: Quantify Regulated Entity’s Use of AI Systems: https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Foley & Lardner, “What To Do If You Receive an NAIC AI Systems Evaluation Tool Pilot Request,” 2026: https://www.foley.com/p/102mmre/what-to-do-if-you-receive-an-naic-ai-systems-evaluation-tool-pilot-request/ ↩
-
NAIC Model Bulletin, “Use of Artificial Intelligence Systems by Insurers,” adopted December 4, 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf ↩ ↩2
The Bottom Line
- Shadow AI creates an Exhibit A gap as well as a security risk. The NAIC evaluation tool opens with system counts, and a tool no one logged cannot be counted.
- Vendor contracts and procurement records provide the inventory floor. Productivity suites, browser extensions, and business-unit workarounds often reveal the rest.
- You can build a directionally complete inventory in roughly one month: map known systems, ask each business unit directly, cross-check SaaS and spend data, then disclose the gaps instead of presenting an implausibly clean list.
- Wrong Exhibit A counts make Exhibits B through D suspect. They signal governance over the wrong systems, missed high-risk models, and undocumented data lineage. Fixing the underlying inventory is the fastest way to cut program-wide regulatory risk.
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
How to Identify the High-Risk AI Systems Exhibit C Asks About
Five screening lines that turn an existing AI inventory into a defensible list of the high-risk systems NAIC Exhibit C asks about, and the record behind it.
Who Owns the Evidence in Insurance AI Governance
Insurance AI governance roles as an ownership matrix: which function prepares each piece of NAIC evidence, which one signs it, and who answers for it in an exam.
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
AI Model Monitoring After the Model Goes Live
A playbook for insurers on AI model monitoring, validation, drift detection, and retesting records that satisfy NAIC Model Bulletin and Exhibit C expectations.
Information aggregation and analysis, not legal advice. See our disclaimer.