Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

Your State Regulator Is About to Ask for Your AI Inventory: What the NAIC's 12-State Pilot Means for Insurance AI Governance

The NAIC's AI Systems Evaluation Tool is live in 12 states through September 2026, with full national adoption expected at the November NAIC Fall Meeting. Regulators are asking for four specific exhibits — AI inventory, governance framework, high-risk system detail, and data quality controls. If you're not in a pilot state yet, you have a narrow window to build these before they come for you.

By Rebecca Leung · July 21, 2026 ·
Table of Contents

An insurance company compliance officer in one of the 12 pilot states received a data request letter from their state Department of Insurance in April 2026. It asked for documentation across four categories: a complete inventory of AI systems used in operations, the company’s governance framework for those systems, detailed information about any AI used in underwriting or claims decisions, and documentation of how AI input data is sourced and validated.

The letter gave them 30 days.

Most insurers weren’t ready.

The NAIC’s AI Systems Evaluation Tool — developed by the Big Data and Artificial Intelligence (H) Working Group and currently in active use across 12 states — is the mechanism state regulators now have to examine AI governance at scale. If you’re not in a pilot state, you have a shrinking window before it comes to you. The NAIC’s planned November 2026 Fall National Meeting adoption will give every member state authority to use this tool in their examination programs.

TL;DR

  • The NAIC AI Systems Evaluation Tool is live in 12 states (CA, CO, CT, FL, IA, LA, MD, PA, RI, VT, VA, WI) through September 2026, with national adoption expected at the November NAIC Fall Meeting
  • The tool asks for four exhibits: AI usage inventory (A), governance framework (B), high-risk AI detail (C), and data sources/quality controls (D)
  • Regulators apply a proportionality principle — AI used in underwriting, pricing, claims, fraud detection, and utilization management faces the most scrutiny
  • Insurers not in the 12 pilot states should treat November 2026 as a soft deadline to have documentation in place
  • The NAIC Model Bulletin adopted in 23+ jurisdictions is the standard; the Evaluation Tool is the examination instrument regulators will use to verify compliance

Why the NAIC Built a Dedicated AI Examination Tool

The NAIC has been tracking AI in insurance since at least 2019, when it adopted its AI principles framework. The 2023 Model Bulletin on the Use of Artificial Intelligence Systems by Insurers raised the stakes by establishing that existing insurance laws — prohibitions on unfair discrimination, rate adequacy requirements, claims handling rules — apply fully to AI-driven decisions. Ignorance of how your model works isn’t a defense when an examiner flags discriminatory pricing patterns.

But the Model Bulletin left an operational gap. Regulators had the authority to examine AI; they didn’t have a standardized framework for doing it. Different states were asking different questions, using different vocabularies, and getting wildly inconsistent documentation from carriers.

The AI Systems Evaluation Tool closes that gap. By standardizing what regulators ask for — across all carriers, in all participating states — it also standardizes what compliance programs need to produce. That’s either a compliance headache or a gift, depending on how prepared you are.

The 12-state pilot running from March through September 2026 is testing the tool in live examination contexts. States are coordinating monthly to avoid duplicating requests to carriers operating across multiple jurisdictions. The feedback from that pilot will be incorporated into the final version before the November adoption vote.


The Four Exhibits: What Regulators Are Actually Asking For

Exhibit A: AI Usage Inventory

This is your complete map of every AI system deployed in business operations. The inventory should include:

  • System name and vendor (or whether the model is built in-house)
  • Business function and use case (underwriting, fraud detection, claims routing, customer service, HR, internal finance)
  • Deployment date
  • Responsible business unit
  • Whether third-party data or models are involved
  • Model version and update frequency

The scope is broader than most compliance teams assume. The NAIC is asking for AI across the enterprise — not just customer-facing underwriting models, but also back-office AI used in billing, document processing, and internal risk assessment. The proportionality principle means examiners will spend most of their time on the high-risk systems in Exhibit C, but they need Exhibit A to see the full picture.

The most common gap in Exhibit A preparation: no one owns the inventory. Underwriting has its models, claims has different tools, fraud uses a vendor platform, and IT built something for document routing. When the DOI letter arrives, no one has a list of all of them.

Exhibit B: Governance Framework

This is your documented policies, procedures, and accountability structure for AI. Examiners are looking for:

  • A written AI governance policy that addresses model development, validation, deployment, and monitoring
  • Documented accountability — who is responsible for AI decisions and outcomes
  • Evidence of pre-deployment testing, including fairness and bias testing
  • Oversight of third-party AI vendors and models (this matters enormously — see below)
  • Incident and error handling procedures for when AI systems produce problematic outputs
  • Board and senior management involvement in AI governance

Most insurers have pieces of this. Few have assembled them into a coherent framework that a regulator can review in 30 days.

The third-party vendor gap is particularly acute. The NAIC Model Bulletin makes explicit that insurers are responsible for the AI systems they use, even when those systems are built and maintained by vendors. Your governance framework needs to show how you oversee those vendors, what representations you require in contracts, and how you validate that their models are performing as expected. If your fraud detection platform is a black box from a vendor, “we rely on the vendor for governance” is not a compliant answer.

Exhibit C: High-Risk AI System Detail

For AI systems used in underwriting, pricing, claims adjudication, fraud detection, and health insurance utilization management, regulators want significantly more detail:

  • Model inputs and feature variables
  • Model outputs and how they feed into final decisions
  • Validation and testing methodology, including out-of-time testing and stress testing
  • Bias and fairness testing results, including disparate impact analysis by protected class characteristics
  • Human override procedures — when and how human judgment can supersede a model output
  • Performance monitoring — how ongoing model accuracy is tracked and what thresholds trigger remediation
  • Explainability — whether and how the model’s outputs can be explained to affected consumers

This is where the difference between a prepared and unprepared insurer becomes stark. Carriers that have formal model risk management programs — with documented model inventories, validation reports, and ongoing monitoring — can produce this documentation in days. Carriers that have been running AI in underwriting for five years without formal governance documentation face a major remediation exercise.

Exhibit D: Data Sources and Quality Controls

The fourth exhibit covers AI input data — specifically, what data feeds your models and how you ensure its quality:

  • Sources of training and operational data (first-party, third-party data vendors, government sources)
  • Data validation and quality assurance procedures
  • How data bias is detected and addressed in training data
  • Procedures for handling data from third-party vendors, including what contractual protections exist
  • Documentation of data governance policies

The NAIC is particularly focused on whether carriers are using third-party data sources that introduce bias or violate state insurance regulations. Credit-scoring data, consumer purchasing behavior, and geographic proxies for protected characteristics are all areas of examiner attention.


What the Proportionality Principle Actually Means

The pilot guidance specifies that participating state regulators will “prioritize examining high-risk AI systems that could cause serious consumer or financial issues, while paying less attention to low-risk back-office systems.” This is a meaningful commitment — it signals that regulators aren’t trying to audit your billing automation software. They care about decisions that affect consumers.

In practice, proportionality means:

AI Use CaseExamination Priority
Personal lines underwriting decisionsHigh
Commercial pricing modelsHigh
Claims approval / denial automationHigh
Fraud detection used to deny or delay claimsHigh
Health insurance utilization management (prior auth)High
Customer service chatbots (informational)Low-Medium
Document classification and routingLow
Internal billing automationLow
HR recruiting toolsLow-Medium

The principle doesn’t mean you can skip Exhibit A entries for low-risk systems. But it does mean your preparation energy should concentrate on the Exhibit C systems in the high-priority column.


If You’re Not in the Pilot States, You’re Not Off the Hook

Eleven of the twelve pilot states include some of the largest insurance markets in the country — California, Florida, and Pennsylvania alone represent enormous premium volume. But the strategic significance of the pilot isn’t its geographic footprint right now; it’s what happens in November.

The NAIC’s timeline is:

  • September 2026: Pilot concludes; feedback collected from participating states
  • September–October 2026: Tool is revised based on pilot findings
  • October 2026: Revised tool released for public review and comment
  • November 2026: Submission for adoption at the NAIC Fall National Meeting in Seattle

NAIC Full National Meeting adoption doesn’t automatically bind all states — insurance regulation is still state-level — but it does equip any member state’s DOI to implement the tool in their examination programs without waiting for state legislation or separate rulemaking. States with active AI oversight agendas (most of them, at this point) are likely to move quickly.

If your domestic state isn’t in the pilot, the question isn’t whether this tool is coming. It’s whether you’ll have four organized exhibits when it does.

The post about shadow AI governance in financial services covers an adjacent risk: AI use that compliance programs don’t know about. That’s exactly the gap that makes Exhibit A so difficult — you can’t inventory what you can’t see.


What Colorado and New York Are Already Doing

Two states have binding rules, not just model bulletin adoptions: Colorado and New York.

Colorado’s SB 21-169 (the Artificial Intelligence in Insurance Practices Act, effective November 2023) requires insurers to maintain governance programs, test for unfair discrimination, and document their AI systems. Colorado is one of the 12 pilot states, which means carriers there are now facing both binding state requirements and the NAIC evaluation tool framework simultaneously.

New York’s NYDFS Part 500 cybersecurity regulation has AI implications on the security and vendor governance side. NYDFS has also issued broader AI guidance — not limited to cybersecurity — for NYDFS-regulated entities including licensed insurers. The EU AI Act transparency code of practice deadline covered the international dimension of AI governance deadlines; what’s happening at NAIC is the domestic equivalent playing out on an accelerated state-by-state timeline.


How to Prepare Before the Tool Reaches Your State

The preparation sequence that makes the most sense given the November timeline:

Step 1: Run an AI inventory exercise now. Talk to every business unit. Ask: what software are you using that makes predictions, recommendations, or automated decisions? Get legal and procurement involved to pull the vendor contracts. You will find AI systems you didn’t know existed. That’s normal. Better to find them now than when a data request letter shows up.

Step 2: Assign governance accountability. Every AI system in your inventory needs an owner — a business unit lead who is responsible for its performance, oversight, and documentation. Without assigned accountability, governance documents are fiction.

Step 3: Build or formalize your governance policy. A written AI governance policy doesn’t need to be 200 pages. It needs to answer: how are new AI systems approved? How are existing ones monitored? Who reviews model performance and how often? What happens when a model produces discriminatory outputs? What do you require from AI vendors contractually?

Step 4: Commission bias testing for high-risk models. If you use AI in underwriting or claims and haven’t run disparate impact analysis by race, gender, age, and other protected characteristics, that gap needs to close before an examiner asks for your Exhibit C documentation. This isn’t a speculative requirement — it’s what the Model Bulletin established in 2023.

Step 5: Map your third-party AI vendors. Your vendor risk management program needs AI-specific provisions: what governance documentation do they provide? What testing do they conduct? What contractual representations do you have about model accuracy, bias, and data handling? Your third-party risk management controls apply to AI vendors too, and regulators will look at whether your contracts give you enough visibility into models you’re relying on.


So What?

The NAIC AI Systems Evaluation Tool is the most concrete thing that’s happened in insurance AI regulation since the Model Bulletin in 2023. It converts high-level principles into a specific documentation request — four exhibits with defined scope.

The 12-state pilot is working. States are coordinating, carriers are being examined, and the tool is generating examination data that will make the final version more precise. When November comes and the NAIC votes on national adoption, the tool that gets adopted will have been tested in real market conduct and financial examination contexts.

If you’re an insurer operating in the 12 pilot states, the risk is immediate. If you’re not, the risk is a few months out. Either way, the documentation you need to produce — AI inventory, governance framework, high-risk model detail, data quality controls — takes months to build properly if you’re starting from scratch.

The best time to start was before the NAIC announced the pilot. The second-best time is now.


The NAIC’s AI Systems Evaluation Tool documentation is publicly available, including the four-exhibit structure. The Fenwick analysis of the 12-state pilot expansion provides detail on what AI vendors supporting insurers need to know. Monitaur has published a practical guide for insurers receiving the Tool. Foley & Lardner has guidance on what to do if you receive a data request under the pilot. The NAIC’s March 2026 AI Issue Brief outlines the broader regulatory context.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the NAIC AI Systems Evaluation Tool?
The NAIC AI Systems Evaluation Tool is a structured regulatory assessment framework developed by the NAIC's Big Data and Artificial Intelligence (H) Working Group. It gives state insurance regulators a standardized way to examine how insurers use AI — what systems exist, how they're governed, which ones pose consumer or financial risk, and what data feeds them. It's structured as four exhibits: Exhibit A (AI usage inventory), Exhibit B (governance framework), Exhibit C (high-risk AI system detail), and Exhibit D (data sources and quality controls). The tool is currently in a 12-state pilot running from March through September 2026, with adoption expected at the NAIC's November 2026 Fall National Meeting.
Which 12 states are participating in the NAIC AI Systems Evaluation Tool pilot?
The 12 participating states are California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. Participating states are focusing on domestic insurers and applying a principle of proportionality — regulators will prioritize examining high-risk AI systems that could cause serious consumer or financial harm, while paying less attention to low-risk back-office systems. Regulators from these states participate in monthly coordination calls to avoid duplicative requests across carriers operating in multiple pilot jurisdictions.
What are the four exhibits insurers need to prepare?
Exhibit A is an AI usage inventory — a comprehensive list of every AI system the insurer uses in operations, including use case, responsible business unit, vendor or build-vs-buy status, and deployment date. Exhibit B is the governance framework — documented policies, procedures, oversight structure, testing practices, and accountability chains for AI. Exhibit C provides detail on potentially high-risk AI models — those used in underwriting, pricing, claims adjudication, fraud detection, and utilization management — including model inputs, outputs, testing methodology, and bias auditing. Exhibit D covers data sources and quality controls for AI inputs, including third-party data usage, data validation practices, and data governance procedures.
What qualifies as a 'high-risk AI system' under the NAIC tool?
The NAIC pilot focuses examiner attention on AI systems used in areas with direct consumer and financial impact: underwriting decisions (policy issuance or denial), premium pricing and rating, claims approval or denial, fraud detection, and health insurance utilization management (prior authorizations). AI systems used in these areas require the detailed documentation in Exhibit C. Low-risk back-office systems — billing administration, document routing, internal HR tools — receive less scrutiny under the proportionality principle, though they still appear in Exhibit A.
If my state isn't in the pilot, do I still need to prepare now?
Yes. The NAIC will update the tool based on September-October 2026 pilot feedback, release it for public review, and submit it for adoption at the November 2026 Fall National Meeting. Once adopted at the national meeting, all member states can implement the tool in their examination programs — meaning your domestic state regulator can use it without any additional legislative or regulatory action in most jurisdictions. The 12-state pilot is also building examiner expertise that will transfer directly to non-pilot states. If you're a mid-sized or large insurer, the prudent assumption is that your domestic state will start using this tool in 2027.
What does the NAIC Model Bulletin on AI require, and how does it relate to the Evaluation Tool?
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, originally adopted in 2023, establishes high-level governance and accountability expectations — that insurers maintain governance programs, test AI systems for accuracy and bias, and oversee third-party AI vendors. Over 20 jurisdictions have adopted it, with Colorado and New York having binding rules based on it. The AI Systems Evaluation Tool is the operational instrument that state regulators will use to verify compliance with those principles. Think of the Model Bulletin as the 'what' and the Evaluation Tool as the 'how examiners will check.'
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.