At the Spring 2026 National Meeting in San Diego on March 24, the NAIC's Big Data and Artificial Intelligence (H) Working Group gave a full panel to agentic AI. Three risk categories came out of it: cascading errors across autonomous decision chains, accountability gaps where no single person oversees the workflow, and failure modes that model validation does not test for.
The reason this is a break rather than an extension is in the existing text. The December 2023 Model Bulletin requires insurers to designate "a person or persons who are responsible for the AI system," a sentence drafted for one model with one owner.
Key Takeaways
- The Model Bulletin is adopted by 24 states and the District of Columbia as of the Spring meeting, with four states layering additional insurance-specific AI rules on top, all of it built around defined inputs, identifiable training data and single-model ownership.
- The 12-state evaluation tool pilot launched March 2, 2026 and its Exhibit C, covering high-risk models with automated decision-making, was designed before agentic AI was named as a distinct category.
- AIG's Lloyd's Syndicate 2479 went live January 1, 2026 with LLM agents on a delegated authority portfolio managing $300 million of premium, while Lexington processed over 370,000 E&S submissions in 2025 against a 500,000 target by 2030.
- Travelers launched an agentic voice claim assistant in February 2026, three years and two months after the NAIC adopted the AI Principles that preceded the bulletin now being outgrown.
- August 2020 to December 2023 was the NAIC's own interval from AI Principles to Model Bulletin, which puts specific agentic guidance no earlier than 2028 on the same cadence.
What the Panel Named
The three categories the working group set out are each a failure the existing framework was not built to catch, rather than a harder version of one it was.
Cascading errors come first. A predictive model produces one output that a human evaluates. An agent chains reasoning steps, calls tools and takes actions, so an error in an early step propagates through everything downstream before any human sees a result.
Accountability is the second, and it is the one with existing text pointing at it. The bulletin's designated-person requirement assumes one model, one owner, one chain. An underwriting agent drawing on a claims model, a pricing algorithm and external data in a single workflow produces a composite output, and the panel noted that no current guidance says which designated person owns it.
Performance limitations are the third. Validation against holdout data, discrimination metrics and stability testing will not surface an agent that performs well on routine work and fails unpredictably at the edge of its training distribution, or one optimizing a proxy rather than the business objective. The panel's word was redesign, not extension.
NAIC staff also presented a four-level risk taxonomy that mirrors the EU AI Act's tiered structure.
| Risk Level | Description | Examples in Insurance |
|---|---|---|
| Unacceptable | Subliminal manipulation, social scoring | Systems that exploit behavioral biases to increase premium acceptance |
| High | Potential for significant harm if failure occurs | Automated claims denial, underwriting triage with coverage impact |
| Medium | Requires transparency; chatbots, emotion recognition | Customer service AI, sentiment analysis in claims calls |
| Low | Minimal restrictions | Spam filters, internal document search, scheduling tools |
The Gap Between the Exhibit and the Deployment
The concrete version of the problem is that the instrument regulators are piloting right now assumes the architecture the panel said no longer holds.
The AI Systems Evaluation Tool pilot launched March 2, 2026 across California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia and Wisconsin, and runs to September. Exhibit A quantifies AI usage, Exhibit B assesses governance, Exhibit C gathers detail on high-risk models with automated decision-making, and Exhibit D documents data sources and vendor relationships. Exhibit C is the closest fit for an agentic system and still asks for one model, one decision, one documented input set. A workflow chaining three or four models with tool-calling and branching logic does not resolve into a single response.
What sits on the other side of that gap is already in production. Through Lloyd's Syndicate 2479, launched January 1, 2026, AIG deployed LLM agents against a delegated authority portfolio managing $300 million in premium, using Palantir Foundry ontologies that map entities, risks and relationships, coordinated by an orchestration layer across the enterprise. Lexington processed over 370,000 E&S submissions in 2025 against a 500,000 target by 2030. Travelers, having committed to AI assistants for nearly 10,000 staff, launched an agentic voice claim assistant in February 2026 that consults policies, guides filing decisions and escalates to live agents.
Both carriers name human escalation as the safeguard, and neither has disclosed how the triggers are calibrated or what false-negative rate on escalation they accept. That figure is the whole safeguard. Escalate too rarely and harmful decisions pass unchecked; escalate too often and the system is a conventional workflow with suggestions attached. For anyone signing off on a rate indication or reserve estimate downstream of one of these chains, the escalation false-negative rate is the number that determines whether the human oversight in the governance document exists in the running system, and it is not currently in any exhibit.
The proposed vendor registry, narrowed at the same meeting to pricing and underwriting, has the same shape of limitation. AIG's stack spans Palantir, multiple LLM providers and its own ontology construction; Travelers' spans Anthropic, OpenAI and internal engineering. Cataloging which vendor supplied which model does not capture how they are orchestrated or where autonomy sits, and the NAIC was explicit that the registry "is not intended to relieve insurers of their existing vendor diligence and management obligations."
The Clock Runs at Two Speeds
The constraint is that the interval between recognizing a gap and writing guidance for it is fixed by process, and deployment is not.
The NAIC adopted its AI Principles in August 2020. The Model Bulletin followed in December 2023, more than three years later. The evaluation tool was developed through 2024 and 2025 and reached pilot in March 2026. On that cadence, specific agentic guidance arrives no earlier than 2028, by which point the question is not whether carriers have deployed agentic systems but how deeply embedded they are.
The nearer deadline is tighter still. The pilot closes in September 2026, the tool is updated on pilot feedback through September and October and re-exposed for comment, with formal adoption expected at the Fall 2026 National Meeting. Anything the Spring panel surfaced has to reach the permanent instrument through that window, and the carriers best placed to document where Exhibit C falls short are the pilot participants running agentic systems.
The burden of documenting it is not evenly distributed. Panelists raised scope definition difficulties and the resource disparity between large and small insurers: a carrier with a dedicated AI governance team can assemble full Exhibit B and C responses, while a regional mutual running one vendor-supplied tool may not have the staff, and orchestration documentation widens that difference rather than narrowing it.
The state layer does not close the gap either. Colorado's SB 21-169 tests for algorithmic discrimination, with auto and health insurers facing July 1, 2026 reporting deadlines and life insurers in scope since 2023. The NCOIL model act would require qualified human professionals to make final claims decisions. Neither reaches the intermediate steps of a chain, which is precisely where the panel located the cascading-error risk.
Further Reading
- When 80% of AI Agents Run on Three Model Providers, Accumulation Becomes the Actuarial Problem - The capital-modeling side of the governance gap this article maps: only 1 in 5 businesses have a mature agent governance model, against 50% of Lloyd's underwriters who assume otherwise.
- NCOIL Stalls, NAIC Expands: Mapping the 2026 Insurer AI Compliance Maze - Why NCOIL's AI model act failed in March 2026 and the four overlapping compliance regimes (NAIC bulletin, non-adopters, state statutes, EU AI Act) carrier actuaries now certify against.
- How Agentic AI Compounds Errors Across a Pricing Pipeline - The three distinct agentic risk surfaces (ingestion, orchestration, output formatting) and why node-by-node model validation misses errors that only appear at the pipeline level.
- Agentic AI Faces Its First Real Test at the July 2026 Reinsurance Renewal
- NAIC AI Evaluation Pilot 2026: The 12-State Test and Industry Pushback
- NAIC Third-Party AI Vendor Registry: What Carriers Need to Know
- NAIC Vendor Registry Model Law: March 2026 Meeting Proceedings and Actuarial Accountability Analysis
- AIG Deploys LLM Agents at Lloyd’s via Palantir Foundry
- Travelers Deploys Anthropic AI Assistants to 10,000 Staff
- The AI Governance Gap in Actuarial Practice
- Colorado AI Act: June 30, 2026 Insurance Compliance Deadline
- AIG-McGill $1.6B Deal: Agentic AI Enters the Subscription Market - The governance questions raised when autonomous AI agents commit $1.6 billion in follow capacity across the specialty market.
- Duck Creek Embeds Agentic AI With Built-In Governance for P&C Carriers - The first core-system vendor to build AI Assurance directly into the agentic execution path, with traceability and auditability addressing the governance gaps identified by the NAIC.
- EU AI Act Compliance and the Emerging Compliance Actuary Role - How the August 2026 Annex III enforcement deadline creates a new actuarial specialty bridging model validation and AI governance.
- Why Agentic AI Deploys in E&S Lines First - The regulatory asymmetry between E&S and admitted markets, including the 373-day Colorado filing average, that explains why carriers test AI in surplus lines before facing the governance frameworks the NAIC is building.
- AIG's 30-Hour Autonomous Agents and the Oversight Gap - How the 30-hour agent cycle disclosed on AIG's Q1 2026 call maps against the NAIC's four-tier risk taxonomy, EU AI Act Article 14, and banking model risk guidance.
- Hartford Publishes the First Carrier Algorithmic Impact Assessment - The voluntary bias audit disclosure covering ZIP code, age, and property type that operationalizes the governance principles the NAIC discussed at the same Spring 2026 meeting.
- Measuring AI-Human Agreement as a Governance KPI - How carriers can quantify whether agentic AI outputs match expert judgment, with AIG's 88% fraud concordance metric as the first public benchmark.
- Agent Charters: Defining Per-Agent Decision Authority - The operational governance instrument that bridges the gap this article identifies, with measurable approval thresholds, authority creep controls, and SR 26-2 agentic AI exclusion analysis.
- NIST AI Agent Standards and the Insurance Compliance Baseline - How the federal AI Agent Standards Initiative launched in February 2026 maps against carrier agentic AI deployments, with the NCCoE identity framework and the 12-month path from voluntary standard to procurement requirement.
Sources
- NAIC Big Data and Artificial Intelligence (H) Working Group
- NAIC Big Data and AI Working Group Meeting Materials, March 24, 2026
- Alston & Bird: Key AI, Cybersecurity, and Privacy Takeaways from the NAIC 2026 Spring Meeting
- Mayer Brown: NAIC Spring 2026 National Meeting Highlights, H Committee Update
- Carlton Fields / JD Supra: NAIC Big Data and AI Working Group Analysis
- NAIC Issue Brief: Artificial Intelligence and State Insurance Regulation, March 2026
- NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, December 2023
- Fenwick: NAIC Expands AI Systems Evaluation Tool Pilot Program to 12 States
- Fenwick: Tracking the Evolution of AI Insurance Regulation
- InsuranceNewsNet: NAIC 2026 AI Evaluation Pilot Moves Ahead as Industry Balks
- AI News: Insurance Giant AIG Deploys Agentic AI with Orchestration Layer
- Travelers: Partnership with Anthropic to Expand AI-Enabled Engineering and Analytics Capabilities
- Travelers: Launches Industry-Leading Agentic AI Claim Assistant Developed with OpenAI
- Plante Moran: How the NAIC AI Model Bulletin Is Evolving and Why Insurers Should Prepare Now