Regulation — insurance-specific

NAIC AI Model Bulletin — independent validation of insurance AI

Adopted December 4, 2023 by the National Association of Insurance Commissioners. Endorsed by 39+ state DOIs 2024-2026. The Bulletin does not create new law — it tells insurers how the existing state unfair-trade-practice statutes apply to AI-driven decisions, and expects an independent-validation layer sitting outside the model.

What the regulation actually says

"Insurers should adopt, implement, and maintain a written program … for the responsible use of AI Systems that make or support decisions related to regulated insurance practices … [including] mechanisms that provide independent review of their AI systems' compliance with legal and internal standards." NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, Section 4.2 (adopted December 4, 2023) — independent-validation language
"The Department expects Insurers to test AI Systems for unfairly discriminatory outcomes … and to remediate any such outcomes identified through such testing." NAIC Model Bulletin, Section 4.3 — unfair-discrimination testing expectation

What this means in plain English

Three obligations for any insurer using AI in a regulated decision:

  1. Written AI program. Board-level ownership. Named roles. Documented processes for design, development, testing, deployment, monitoring.
  2. Independent validation. A review layer outside the model team + outside the vendor. Vendor self-attestation and the modeling team's own validation are not enough.
  3. Ongoing testing for unfair discrimination. Not a one-time exercise. Ongoing, with a documented remediation path when a finding lands.

The Bulletin does not name a specific test method. It names an adequacy standard: is your testing able to detect the harms the underlying state unfair-trade-practice law prohibits?

What triggers the exposure in the sample

I3 (age 25-45, mid credit, mixed urban/lower-income zip) decline / refer-SIU lane rate rose from 11% to 62%. Zip and credit are common proxies for protected classes. A 51 percentage-point group-differential in the wrong direction that occurred silently is precisely the "unfairly discriminatory outcome" trigger the Bulletin expects insurers to detect + remediate through independent testing.

The finding does not require intent. It requires only the operator to be able to demonstrate the outcome pattern has been tested for + acted on. Aggregate-metric monitoring does not satisfy that expectation.

What the $499 Snapshot shows against this rule

See the lane-shift chart that produces the finding →

How does this help me?

The Bulletin is the framing. The consequence of NOT having independent-verifier evidence when the state DOI's market-conduct exam letter lands is a very different exposure profile.

Read: NAIC Bulletin -- what it saves you at market-conduct exam →

$499 Snapshot. 3 business days.

Independent-verifier determination scoped to your carrier's AI surface + 3 fix-first items + signed declaration.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.