NAIC Model Bulletin on AI: What Your Insurance AI Policy Must Include
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted by the National Association of Insurance Commissioners on December 4, 2023. It is not itself law; it is a template that each state insurance department can issue to the insurers it regulates. As of the NAIC's Spring 2026 meeting, twenty-four states and the District of Columbia had adopted it, and several others had issued their own AI rules. If you are licensed in one of those states, your regulator has told you in writing what it expects. This guide explains what that is and what an AI policy has to contain to satisfy it.
What the bulletin requires: a written AIS Program
The core requirement is that each insurer adopt, implement, and maintain a written program for the responsible use of AI systems, which the bulletin calls an AIS Program. The program should be proportionate to the risk of the insurer's actual AI use, with particular attention to AI that makes or supports decisions affecting consumers: underwriting, rating, marketing, claims handling, and fraud detection. The bulletin grounds itself in existing law: the Unfair Trade Practices Act, the Unfair Claims Settlement Practices Act, corporate governance disclosure requirements, and market conduct examination authority. Using AI does not create new obligations so much as it creates new ways to breach old ones, and the regulator wants to see that you have controlled for that.
The four areas an AIS Program must cover
- Governance: accountability at senior management and, where appropriate, board level; a cross-functional structure that includes actuarial, data science, underwriting, claims, compliance, and legal; written policies and procedures; and defined roles for approving, monitoring, and retiring AI systems.
- Risk management and internal controls: identifying where AI is used, assessing each use for the risk of inaccurate or unfairly discriminatory outcomes, validating and testing models before and after deployment, documenting data sources and their suitability, and keeping records that show the controls operated.
- Third-party AI systems and data: due diligence on vendors and external data, contractual rights to information and cooperation, and an explicit acknowledgment that the insurer remains responsible for outcomes produced by third-party tools.
- Documentation for regulators: the bulletin tells insurers that in an examination or investigation they may be asked to produce their governance framework, risk controls, testing records, vendor oversight, and records of adverse consumer outcomes connected to AI use.
Adverse consumer outcomes
The bulletin's key concept is the adverse consumer outcome: a decision or action produced with AI that harms a consumer in a way the insurance laws prohibit, most importantly unfair discrimination and unfair trade or claims practices. The whole program exists to prevent these, detect them when they happen, and be able to explain them. That is why testing for bias and unfair discrimination is not optional, and why every consequential AI-assisted decision needs a documented human review path.
Agencies, brokers, and MGAs
The bulletin is addressed to insurers, but it reaches everyone in the distribution chain through its third-party provisions. A carrier that must oversee third-party AI will ask its agencies and managing general agents what AI they use in quoting, underwriting submissions, and claims intake, and what controls sit around it. Having your own AI policy, even a short one, is what lets you answer that question with a document rather than a shrug.
What to put in your AI policy
- Scope and inventory: every AI system in use, including AI features inside policy administration, claims, and marketing platforms, and which regulated decisions each one touches.
- Governance: a named owner of the AIS Program, an approval process for new AI uses, and reporting to senior management.
- Data rules: which categories of data may be used with which tools, with nonpublic personal information under GLBA restricted to approved systems, and prohibited inputs such as protected-class proxies where the law forbids them.
- Human review: AI may inform underwriting, rating, and claims decisions, but a documented human review is required before any adverse decision, and consumers retain their rights to explanation and appeal.
- Testing and monitoring: models used in regulated decisions are validated for accuracy and tested for unfair discrimination before use and on a schedule afterward, with results kept.
- Third parties: vendor due diligence, contract terms that secure audit and information rights, and the principle that outsourcing the tool never outsources the responsibility.
- Records: what is documented, where, and for how long, so an examiner's request can be met.
- Incident handling: how an adverse consumer outcome or a model failure is reported internally, remediated, and where required reported to the regulator.
The fast path
Our generator produces an insurance AI policy that includes the state insurance regulation clause referencing the NAIC Model Bulletin, GLBA data rules for nonpublic personal information, mandatory human review of consequential decisions, and a vendor assessment checklist in the full pack. It is a workplace AI use policy, the foundation of an AIS Program rather than the whole of one; larger carriers will layer model risk management on top of it. Preview the full document free before paying. It is a self-help template, not legal or regulatory advice.
Generate your AI policy in 3 minutes
Customized to your industry, jurisdictions, and tools. Free preview, $ 49 one-time to download, delivered instantly.
Generate an insurance AI policy