NAIC Advances AI Risk Governance for the Insurance Industry

NAIC Advances AI Risk Governance for the Insurance Industry

Effective risk assessment now depends on factors such as the importance of the decision, the level of system autonomy, and the explainability of the resulting output for consumers. At the NAIC 2026 Summer National Meeting in Columbus, Ohio, the Big Data and Artificial Intelligence Working Group addressed the rapid integration of advanced technology into the insurance sector. This session marked a turning point as regulators, industry leaders, and rating agencies moved beyond theoretical discussions to focus on practical, evidence-based governance. The primary objective was to establish a framework that balances innovation with financial stability and consumer protection. By centering the discussion on tangible diagnostic tools, the group signaled that the era of speculative oversight has ended, replaced by a rigorous commitment to operational transparency. The goal is to ensure that as insurers adopt more complex machine learning models, the mechanisms for safeguarding the public and maintaining solvency remain equally advanced and reliable across all jurisdictions.

Establishing a Unified Framework for Technological Oversight

The Transition to Diagnostic Evaluation Models

The evolution of the project title from a tool to a supplement underscores the philosophy that AI governance is an ongoing diagnostic process rather than a one-time approval. This shift in nomenclature reflects a deeper understanding of the technological lifecycle, where software is not static but constantly adapting to new data streams. By framing the regulatory approach as a supplement, the NAIC allows for the integration of AI oversight into existing examination frameworks, ensuring that technology does not exist in a regulatory vacuum. This maturation of oversight ensures that as technology evolves, the regulatory response remains both relevant and rigorous. The framework prioritizes the examination of how companies validate their models and manage the risks associated with automated decision-making. Instead of a rigid certification, the industry is moving toward a more nuanced method of evaluation that can keep pace with the high velocity of innovation seen in the current insurance market.

The supplement allows state regulators to ask targeted questions about how insurers manage their AI systems, moving away from a traditional check-the-box mentality. This diagnostic approach is designed to reveal the internal mechanics of corporate governance, focusing on whether an organization has the necessary talent and infrastructure to monitor complex algorithms. By asking specific questions about data provenance and model performance, regulators can identify potential vulnerabilities before they manifest as market-wide failures. This flexibility ensures that oversight can be tailored to the specific needs of different jurisdictions, allowing for a decentralized yet cohesive strategy across the United States. As the supplement nears formal adoption, it signals a shift toward a standardized regulatory toolkit for the entire industry. It provides a common language for both insurers and examiners, facilitating clearer communication and more effective risk management across various lines of business and operational departments.

Implementation of the Multi-State Pilot Program

Currently being tested through a multi-state pilot program, the AI Risk Evaluation Supplement is undergoing a trial by fire to ensure its practical utility in the field. This pilot phase is essential for identifying any logistical hurdles or ambiguities in the questioning process, allowing for real-time adjustments based on examiner feedback. State regulators participating in the program are gaining firsthand experience in applying the diagnostic criteria to a diverse range of insurance providers. This empirical approach ensures that when the supplement is officially rolled out, it will be a proven instrument capable of handling the complexities of modern digital underwriting. The pilot program also fosters collaboration between states, encouraging the sharing of best practices and specialized knowledge regarding algorithmic auditing. This collective effort strengthens the overall regulatory environment, making it more difficult for opaque or poorly managed systems to operate without sufficient oversight.

Flexibility remains a hallmark of this new diagnostic tool, as it allows state insurance departments to integrate AI inquiries into existing market conduct exams or treat them as separate, targeted investigations. This modularity is crucial because it accounts for the varying levels of technological adoption among different insurers and the differing priorities of state jurisdictions. A large national carrier using agentic AI for claims processing requires a different level of scrutiny than a small regional player using basic predictive models for marketing. By allowing regulators to scale their inquiries based on the risk profile of the specific entity, the NAIC ensures that resources are allocated efficiently. This risk-based methodology prevents unnecessary administrative burdens on smaller companies while ensuring that high-impact systems at larger organizations are thoroughly vetted. This balanced approach is vital for maintaining a competitive insurance market while providing consumers with the necessary protections they deserve.

Aligning Financial Ratings with Technological Complexity

The Role of Credit Agencies and Risk Management Frameworks

Rating agencies like AM Best are increasingly evaluating AI through the lens of innovation and Enterprise Risk Management (ERM) rather than treating it as a standalone metric. Analysts are no longer looking at technology in isolation but are instead asking whether a company’s leadership and resources are effectively turning AI deployment into durable financial results. The focus has shifted toward the sustainability of the technological advantage and whether the organization possesses the governance maturity to manage the associated risks. From this perspective, AI is viewed as a catalyst that can either improve operational efficiency or amplify traditional risks such as cyber threats and third-party vulnerabilities. Because AI influences creditworthiness, insurers must demonstrate that their internal controls are expanding at the same rate as the technical risks they are introducing. This holistic view ensures that financial ratings accurately reflect the long-term stability and resilience of the firm.

To manage oversight effectively, the industry has categorized AI into three functional classes: predictive, generative, and agentic. Predictive AI is largely used for scoring and fraud detection, where the primary regulatory concerns involve data drift and model fairness. However, the introduction of generative AI, which creates content like claims summaries, introduces new risks related to hallucinations and the security of sensitive data shared with outside providers. Agentic AI represents the most complex frontier, as these systems can perform autonomous tasks across multiple steps without constant human intervention. Governance for these systems must focus on guardrails, including clear task boundaries and the ability for a human to roll back actions via a kill switch. By classifying technology into these tiers, regulators can apply specific sets of controls that correspond to the unique hazards presented by each type of machine learning application, ensuring safety without stifling development.

Moving from Policy Documentation to Operational Evidence

A major theme of recent discussions is the need for insurers to move beyond written policies and provide operational evidence of their governance. Regulators are looking for proof that human-in-the-loop processes are meaningful rather than just a procedural formality. If human oversight never results in a flagged error or a changed decision, it may be viewed as ineffective or merely a rubber stamp by auditing bodies. To avoid the fragile layering of new tools onto old processes, insurers are encouraged to holistically redesign their workflows to accommodate the unique requirements of automated systems. This involves clearly defining who owns the outcome of an AI decision and ensuring that accountability is built into the system from the start. True governance requires a transparent audit trail that can reconstruct an AI decision-making path, proving that the technology is being managed with active and thoughtful supervision rather than being left to run on autopilot.

Insurers successfully transitioned toward a model of accountability that prioritized actionable results over abstract compliance statements. They established clear protocols for internal auditing and ensured that every autonomous action could be traced back to a specific human authority. Organizations also invested in cross-functional teams that brought together legal, technical, and actuarial expertise to monitor the long-term performance of machine learning models. This holistic approach reduced the frequency of algorithmic bias and improved the overall accuracy of automated claims processing. By focusing on operational evidence, companies demonstrated to regulators that their systems were under control and aligned with the interests of policyholders. Moving forward, the industry adopted a culture of continuous improvement, where technological updates were met with corresponding enhancements in risk governance. These efforts paved the way for a more stable insurance market where innovation and consumer protection coexisted.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later