US insurance regulation is famously a patchwork, but on artificial intelligence the patches are starting to align. The NAIC's December 2023 Model Bulletin on the use of AI systems has now been adopted by roughly half the states, and in 2026 the NAIC moved from principles to practice: a pilot of its AI Systems Evaluation Tool, with a dozen states participating and a group of insurers whose AI programs will be examined against a standardized template for the first time.
Industry trade groups have objected, with some justification, that the pilot is voluntary for regulators while compulsory for the companies selected, and that its duration and success criteria are vague. Those complaints may improve the process. They will not stop it. When the pilot concludes, its lessons will flow into ordinary market-conduct and financial examinations — which means the evaluation tool is, functionally, a preview of the questions every insurer will eventually face.
What the tool asks, in plain terms Strip away the framework language and the evaluation tool asks four things. Where do you use AI, including AI embedded in vendor systems you did not build? Who is accountable for each system, from the board's written AI program down to the analyst who overrides an output? What testing exists — for accuracy, for drift, and above all for unfair discrimination across protected classes? And what happens when a consumer is adversely affected: can you explain the decision, and could a human have changed it?
The gap analysis writes itself. Surveys cited across the industry suggest a majority of insurers now use or plan to use AI in underwriting, claims, or fraud detection, while as many as a third of health insurers do not regularly test models for bias. That distance — near-universal adoption, patchy testing — is precisely where examinations, enforcement, and private litigation will concentrate.
Preparing without waiting The preparation sequence is unglamorous. Build the inventory first; every subsequent control depends on it. Map each system to the Model Bulletin's governance expectations and record where reality falls short, because a documented gap with a remediation date reads far better in an exam than an undocumented one discovered by the examiner. Extend oversight to third-party models now — an NAIC model law on AI vendors is anticipated, and the direction of travel is unmistakable. And rehearse: run one internal mock examination using the evaluation tool's own categories before a regulator does it for you.
There is also a larger political current to watch. Federal efforts to centralize AI regulation have set up a genuine preemption contest with 150 years of state insurance authority. However that resolves, the operational work — inventory, testing, accountability — is identical under every plausible regime. Preparing for the pilot is preparing for all of them.
Related reading - [From principle to proof: bias testing in AI underwriting and claims](/insights/ai-bias-testing-underwriting-claims-jonas-osman-abdelghafour) - [You didn't build it, but you own it: third-party AI risk comes of age](/insights/third-party-ai-vendor-risk-financial-services-jonas-osman-abdelghafour) - [Data governance before AI governance: the foundation insurers keep skipping](/insights/data-governance-before-ai-governance-insurance-jonas-osman-abdelghafour)
See also Insurance Risk, Regulatory Compliance and Governance, Risk and Compliance.
About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.
Frequently asked questions
What the tool asks, in plain terms?
Strip away the framework language and the evaluation tool asks four things. Where do you use AI, including AI embedded in vendor systems you did not build? Who is accountable for each system, from the board's written AI program down to the analyst who overrides an output? What testing exists — for accuracy, for drift, and above all for unfair discrimination across protected classes? And what happens when a consumer is adversely affected: can you explain the decision, and could a human have ch...
What should risk leaders know about preparing without waiting?
The preparation sequence is unglamorous. Build the inventory first; every subsequent control depends on it. Map each system to the Model Bulletin's governance expectations and record where reality falls short, because a documented gap with a remediation date reads far better in an exam than an undocumented one discovered by the examiner. Extend oversight to third-party models now — an NAIC model law on AI vendors is anticipated, and the direction of travel is unmistakable. And rehearse: run o...
What should risk leaders know about related reading?
See also [Insurance Risk](/expertise/insurance-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and [Governance, Risk and Compliance](/expertise/grc).
What should risk leaders know about about the author?
Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.