
The NAIC's AI Risk Evaluation Supplement moves from principles to exam questions. Twelve states are piloting the framework. Version 5.0 gets a 30-day public exposure in September.
Insurance regulators are turning artificial intelligence principles into examination questions. At its Summer National Meeting on Thursday, the National Association of Insurance Commissioners updated its AI Risk Evaluation Supplement, a set of inquiries that state examiners can use during market conduct reviews, financial examinations or stand-alone AI inquiries.
The working group renamed the document from "AI Systems Evaluation Tool" to avoid confusion. It is not a certification, a rating or a new law. The supplement gives regulators a common structure to collect evidence on how an insurer builds, validates, monitors and governs AI systems.
The timeline has concrete milestones. The pilot includes California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia and Wisconsin. Participating states have used the supplement in different ways: some embedded it in scheduled exams, others treated it as an ad hoc questionnaire. The NAIC cautioned that every state may not finish by Sept. 30. Feedback from the pilot will feed version 5.0, which gets a 30-day public exposure period in September. Version 6.0 will have a 14-day public exposure afterward. Regulators expect to consider version 7.0 for adoption at the fall national meeting.
The supplement's scope shows where insurers will face the most scrutiny. Regulators want to know a system's purpose, data sources, training data, validation procedures and risk classification. They are also asking for documentation, performance monitoring, change histories and evidence that a company can audit and explain an AI-generated outcome.
Human oversight is a central piece. Examiners are looking at who can approve a model, challenge its output, intervene when performance deteriorates and document what happened after a system or vendor changed.
For insurers, that raises the value of a current AI inventory. A company needs to identify each system, explain its purpose, name the data it uses and map internal and external dependencies. It should have testing results, monitoring records and proof that controls work in practice.
The vendor side is developing on a parallel track. On Wednesday, the NAIC's Third-Party Data and Models Working Group reviewed feedback on a proposed framework covering outside data and predictive models in property and casualty pricing and underwriting. The proposal could require vendors to supply documentation on model purpose, assumptions, inputs, limitations, validation and performance. Regulators could also seek data-lineage records, fairness testing, change logs and audit trails. Meeting materials said insurers would retain responsibility for validating, testing and monitoring third-party products.
That could create a new commercial dividing line for insurance technology providers. Platforms that can supply audit-ready documentation may become easier for regulated companies to adopt. Vendors that treat model details as off-limits could create compliance friction for their customers.
"An insurer can outsource an AI model," the meeting materials said. "It can't outsource accountability."
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.