Feature AI Risk
Your State Regulator Is About to Ask for Your AI Inventory: What the NAIC's 12-State Pilot Means for Insurance AI Governance
The NAIC's AI Systems Evaluation Tool is live in 12 states through September 2026, with full national adoption expected at the November NAIC Fall Meeting. Regulators are asking for four specific exhibits — AI inventory, governance framework, high-risk system detail, and data quality controls. If you're not in a pilot state yet, you have a narrow window to build these before they come for you.
Table of Contents
An insurance company compliance officer in one of the 12 pilot states received a data request letter from their state Department of Insurance in April 2026. It asked for documentation across four categories: a complete inventory of AI systems used in operations, the company’s governance framework for those systems, detailed information about any AI used in underwriting or claims decisions, and documentation of how AI input data is sourced and validated.
The letter gave them 30 days.
Most insurers weren’t ready.
The NAIC’s AI Systems Evaluation Tool — developed by the Big Data and Artificial Intelligence (H) Working Group and currently in active use across 12 states — is the mechanism state regulators now have to examine AI governance at scale. If you’re not in a pilot state, you have a shrinking window before it comes to you. The NAIC’s planned November 2026 Fall National Meeting adoption will give every member state authority to use this tool in their examination programs.
TL;DR
- The NAIC AI Systems Evaluation Tool is live in 12 states (CA, CO, CT, FL, IA, LA, MD, PA, RI, VT, VA, WI) through September 2026, with national adoption expected at the November NAIC Fall Meeting
- The tool asks for four exhibits: AI usage inventory (A), governance framework (B), high-risk AI detail (C), and data sources/quality controls (D)
- Regulators apply a proportionality principle — AI used in underwriting, pricing, claims, fraud detection, and utilization management faces the most scrutiny
- Insurers not in the 12 pilot states should treat November 2026 as a soft deadline to have documentation in place
- The NAIC Model Bulletin adopted in 23+ jurisdictions is the standard; the Evaluation Tool is the examination instrument regulators will use to verify compliance
Why the NAIC Built a Dedicated AI Examination Tool
The NAIC has been tracking AI in insurance since at least 2019, when it adopted its AI principles framework. The 2023 Model Bulletin on the Use of Artificial Intelligence Systems by Insurers raised the stakes by establishing that existing insurance laws — prohibitions on unfair discrimination, rate adequacy requirements, claims handling rules — apply fully to AI-driven decisions. Ignorance of how your model works isn’t a defense when an examiner flags discriminatory pricing patterns.
But the Model Bulletin left an operational gap. Regulators had the authority to examine AI; they didn’t have a standardized framework for doing it. Different states were asking different questions, using different vocabularies, and getting wildly inconsistent documentation from carriers.
The AI Systems Evaluation Tool closes that gap. By standardizing what regulators ask for — across all carriers, in all participating states — it also standardizes what compliance programs need to produce. That’s either a compliance headache or a gift, depending on how prepared you are.
The 12-state pilot running from March through September 2026 is testing the tool in live examination contexts. States are coordinating monthly to avoid duplicating requests to carriers operating across multiple jurisdictions. The feedback from that pilot will be incorporated into the final version before the November adoption vote.
The Four Exhibits: What Regulators Are Actually Asking For
Exhibit A: AI Usage Inventory
This is your complete map of every AI system deployed in business operations. The inventory should include:
- System name and vendor (or whether the model is built in-house)
- Business function and use case (underwriting, fraud detection, claims routing, customer service, HR, internal finance)
- Deployment date
- Responsible business unit
- Whether third-party data or models are involved
- Model version and update frequency
The scope is broader than most compliance teams assume. The NAIC is asking for AI across the enterprise — not just customer-facing underwriting models, but also back-office AI used in billing, document processing, and internal risk assessment. The proportionality principle means examiners will spend most of their time on the high-risk systems in Exhibit C, but they need Exhibit A to see the full picture.
The most common gap in Exhibit A preparation: no one owns the inventory. Underwriting has its models, claims has different tools, fraud uses a vendor platform, and IT built something for document routing. When the DOI letter arrives, no one has a list of all of them.
Exhibit B: Governance Framework
This is your documented policies, procedures, and accountability structure for AI. Examiners are looking for:
- A written AI governance policy that addresses model development, validation, deployment, and monitoring
- Documented accountability — who is responsible for AI decisions and outcomes
- Evidence of pre-deployment testing, including fairness and bias testing
- Oversight of third-party AI vendors and models (this matters enormously — see below)
- Incident and error handling procedures for when AI systems produce problematic outputs
- Board and senior management involvement in AI governance
Most insurers have pieces of this. Few have assembled them into a coherent framework that a regulator can review in 30 days.
The third-party vendor gap is particularly acute. The NAIC Model Bulletin makes explicit that insurers are responsible for the AI systems they use, even when those systems are built and maintained by vendors. Your governance framework needs to show how you oversee those vendors, what representations you require in contracts, and how you validate that their models are performing as expected. If your fraud detection platform is a black box from a vendor, “we rely on the vendor for governance” is not a compliant answer.
Exhibit C: High-Risk AI System Detail
For AI systems used in underwriting, pricing, claims adjudication, fraud detection, and health insurance utilization management, regulators want significantly more detail:
- Model inputs and feature variables
- Model outputs and how they feed into final decisions
- Validation and testing methodology, including out-of-time testing and stress testing
- Bias and fairness testing results, including disparate impact analysis by protected class characteristics
- Human override procedures — when and how human judgment can supersede a model output
- Performance monitoring — how ongoing model accuracy is tracked and what thresholds trigger remediation
- Explainability — whether and how the model’s outputs can be explained to affected consumers
This is where the difference between a prepared and unprepared insurer becomes stark. Carriers that have formal model risk management programs — with documented model inventories, validation reports, and ongoing monitoring — can produce this documentation in days. Carriers that have been running AI in underwriting for five years without formal governance documentation face a major remediation exercise.
Exhibit D: Data Sources and Quality Controls
The fourth exhibit covers AI input data — specifically, what data feeds your models and how you ensure its quality:
- Sources of training and operational data (first-party, third-party data vendors, government sources)
- Data validation and quality assurance procedures
- How data bias is detected and addressed in training data
- Procedures for handling data from third-party vendors, including what contractual protections exist
- Documentation of data governance policies
The NAIC is particularly focused on whether carriers are using third-party data sources that introduce bias or violate state insurance regulations. Credit-scoring data, consumer purchasing behavior, and geographic proxies for protected characteristics are all areas of examiner attention.
What the Proportionality Principle Actually Means
The pilot guidance specifies that participating state regulators will “prioritize examining high-risk AI systems that could cause serious consumer or financial issues, while paying less attention to low-risk back-office systems.” This is a meaningful commitment — it signals that regulators aren’t trying to audit your billing automation software. They care about decisions that affect consumers.
In practice, proportionality means:
| AI Use Case | Examination Priority |
|---|---|
| Personal lines underwriting decisions | High |
| Commercial pricing models | High |
| Claims approval / denial automation | High |
| Fraud detection used to deny or delay claims | High |
| Health insurance utilization management (prior auth) | High |
| Customer service chatbots (informational) | Low-Medium |
| Document classification and routing | Low |
| Internal billing automation | Low |
| HR recruiting tools | Low-Medium |
The principle doesn’t mean you can skip Exhibit A entries for low-risk systems. But it does mean your preparation energy should concentrate on the Exhibit C systems in the high-priority column.
If You’re Not in the Pilot States, You’re Not Off the Hook
Eleven of the twelve pilot states include some of the largest insurance markets in the country — California, Florida, and Pennsylvania alone represent enormous premium volume. But the strategic significance of the pilot isn’t its geographic footprint right now; it’s what happens in November.
The NAIC’s timeline is:
- September 2026: Pilot concludes; feedback collected from participating states
- September–October 2026: Tool is revised based on pilot findings
- October 2026: Revised tool released for public review and comment
- November 2026: Submission for adoption at the NAIC Fall National Meeting in Seattle
NAIC Full National Meeting adoption doesn’t automatically bind all states — insurance regulation is still state-level — but it does equip any member state’s DOI to implement the tool in their examination programs without waiting for state legislation or separate rulemaking. States with active AI oversight agendas (most of them, at this point) are likely to move quickly.
If your domestic state isn’t in the pilot, the question isn’t whether this tool is coming. It’s whether you’ll have four organized exhibits when it does.
The post about shadow AI governance in financial services covers an adjacent risk: AI use that compliance programs don’t know about. That’s exactly the gap that makes Exhibit A so difficult — you can’t inventory what you can’t see.
What Colorado and New York Are Already Doing
Two states have binding rules, not just model bulletin adoptions: Colorado and New York.
Colorado’s SB 21-169 (the Artificial Intelligence in Insurance Practices Act, effective November 2023) requires insurers to maintain governance programs, test for unfair discrimination, and document their AI systems. Colorado is one of the 12 pilot states, which means carriers there are now facing both binding state requirements and the NAIC evaluation tool framework simultaneously.
New York’s NYDFS Part 500 cybersecurity regulation has AI implications on the security and vendor governance side. NYDFS has also issued broader AI guidance — not limited to cybersecurity — for NYDFS-regulated entities including licensed insurers. The EU AI Act transparency code of practice deadline covered the international dimension of AI governance deadlines; what’s happening at NAIC is the domestic equivalent playing out on an accelerated state-by-state timeline.
How to Prepare Before the Tool Reaches Your State
The preparation sequence that makes the most sense given the November timeline:
Step 1: Run an AI inventory exercise now. Talk to every business unit. Ask: what software are you using that makes predictions, recommendations, or automated decisions? Get legal and procurement involved to pull the vendor contracts. You will find AI systems you didn’t know existed. That’s normal. Better to find them now than when a data request letter shows up.
Step 2: Assign governance accountability. Every AI system in your inventory needs an owner — a business unit lead who is responsible for its performance, oversight, and documentation. Without assigned accountability, governance documents are fiction.
Step 3: Build or formalize your governance policy. A written AI governance policy doesn’t need to be 200 pages. It needs to answer: how are new AI systems approved? How are existing ones monitored? Who reviews model performance and how often? What happens when a model produces discriminatory outputs? What do you require from AI vendors contractually?
Step 4: Commission bias testing for high-risk models. If you use AI in underwriting or claims and haven’t run disparate impact analysis by race, gender, age, and other protected characteristics, that gap needs to close before an examiner asks for your Exhibit C documentation. This isn’t a speculative requirement — it’s what the Model Bulletin established in 2023.
Step 5: Map your third-party AI vendors. Your vendor risk management program needs AI-specific provisions: what governance documentation do they provide? What testing do they conduct? What contractual representations do you have about model accuracy, bias, and data handling? Your third-party risk management controls apply to AI vendors too, and regulators will look at whether your contracts give you enough visibility into models you’re relying on.
So What?
The NAIC AI Systems Evaluation Tool is the most concrete thing that’s happened in insurance AI regulation since the Model Bulletin in 2023. It converts high-level principles into a specific documentation request — four exhibits with defined scope.
The 12-state pilot is working. States are coordinating, carriers are being examined, and the tool is generating examination data that will make the final version more precise. When November comes and the NAIC votes on national adoption, the tool that gets adopted will have been tested in real market conduct and financial examination contexts.
If you’re an insurer operating in the 12 pilot states, the risk is immediate. If you’re not, the risk is a few months out. Either way, the documentation you need to produce — AI inventory, governance framework, high-risk model detail, data quality controls — takes months to build properly if you’re starting from scratch.
The best time to start was before the NAIC announced the pilot. The second-best time is now.
The NAIC’s AI Systems Evaluation Tool documentation is publicly available, including the four-exhibit structure. The Fenwick analysis of the 12-state pilot expansion provides detail on what AI vendors supporting insurers need to know. Monitaur has published a practical guide for insurers receiving the Tool. Foley & Lardner has guidance on what to do if you receive a data request under the pilot. The NAIC’s March 2026 AI Issue Brief outlines the broader regulatory context.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the NAIC AI Systems Evaluation Tool?
Which 12 states are participating in the NAIC AI Systems Evaluation Tool pilot?
What are the four exhibits insurers need to prepare?
What qualifies as a 'high-risk AI system' under the NAIC tool?
If my state isn't in the pilot, do I still need to prepare now?
What does the NAIC Model Bulletin on AI require, and how does it relate to the Evaluation Tool?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026