Insurance Regulators Get Schooled on AI Governance

insurance-artificial-intelligence-regulations

Insurance regulators are moving artificial intelligence governance from the policy manual into the examination file.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    On Thursday (Aug. 13) at its Summer National Meeting, the National Association of Insurance Commissioners provided an update on its AI Risk Evaluation Supplement, a structured set of inquiries designed to help state regulators examine how insurers use and oversee AI.

    The working group renamed the document from the “AI Systems Evaluation Tool” to reduce confusion about its purpose. The supplement isn’t a certification program, a rating system or a new insurance law. It gives regulators a common way to gather evidence about AI use during market conduct reviews, financial examinations, financial analysis or stand-alone inquiries.

    The distinction is important, but the practical effect may be more important. The NAIC’s AI principles and 2023 model bulletin established expectations for responsible AI use. The supplement begins translating those principles into specific requests for information.

    In other words, insurers may need to do more than say they govern AI responsibly. They’ll need to show how.

    The pilot includes California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia and Wisconsin. Participating states haven’t followed a single process. Some incorporated the supplement into scheduled examinations while others used it as an ad hoc questionnaire.

    The pilot will continue through September, although the NAIC cautioned that every state may not finish by Sept. 30. State feedback and initial company responses will inform version 5.0, which is expected to receive a 30-day public exposure period in September. Version 6.0 is scheduled for a second, 14-day exposure before regulators consider version 7.0 for adoption at the fall national meeting.

    The supplement’s emerging scope shows where insurers could face the most scrutiny. Regulators want to understand an AI system’s purpose, data sources, training data, validation procedures and risk classification. They are also looking at documentation, performance monitoring, change histories and whether a company can audit and explain an AI-generated outcome.

    Human oversight is part of that review. Regulators are examining who can approve a model, challenge its output, intervene when performance deteriorates and document what happened after a system or vendor changes.

    For insurers, that raises the value of a current AI inventory. A company should be able to identify each system, explain what it does, name the data it uses, and map its internal and external dependencies. It should also be able to produce testing results, monitoring records and proof that controls work in practice.

    The vendor implications are developing on a parallel track. On Wednesday (Aug. 12), the NAIC’s Third-Party Data and Models Working Group reviewed feedback on a proposed framework covering outside data and predictive models used in property and casualty pricing and underwriting.

    The proposal could require vendors to provide documentation covering model purpose, assumptions, inputs, limitations, validation and performance. Regulators could also seek data-lineage records, fairness testing, change logs and audit trails. The meeting materials said insurers would retain responsibility for validating, testing and monitoring third-party products.

    That could create a new commercial dividing line for insurance technology providers. Platforms that can supply audit-ready documentation may become easier for regulated companies to adopt. Vendors that treat model details as off-limits could create compliance friction for their customers.

    The message from regulators is becoming harder to miss. An insurer can outsource an AI model, but it can’t outsource accountability.

    For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.