The NAIC's Big Data and Artificial Intelligence Working Group released a Request for Information on May 12, 2025 asking whether it should pursue a binding model law on insurers' use of AI. The 45-day comment period closed on June 30 and drew 33 written submissions from regulators, consumer groups, trade associations, consultants and vendors.
The letters agree on the three pillars and divide on the definitions underneath them. One of those definitions decides whether a conventional rate filing falls inside the law.
Key Takeaways
- 33 comment letters responded to the RFI; the split is not for or against a model law but over scope, vendor liability, size thresholds, the definition of "AI system", and how a law would sit against Colorado's SB 21-169.
- The Model Bulletin, adopted December 4, 2023, carries no independent statutory authority, so the 25 states that have adopted or referenced it have each integrated it into a different existing framework.
- The definitional question is the one with pricing consequences: on a broad reading a Poisson GLM with twelve rating variables is an AI system, and every personal auto filing in the country triggers the governance, transparency and accountability requirements.
- The 12-state AI Systems Evaluation Tool pilot launched March 2, 2026 and runs to September, with adoption targeted for the Fall National Meeting in November 2026.
- Trade groups' December 5, 2025 joint letter objected that participation is voluntary for regulators but compulsory for selected companies, and that firms face potential penalties for negative findings during a pilot.
What the Record Actually Contains
The NAIC's progression runs from the Principles on Artificial Intelligence adopted in August 2020, aspirational and without prescriptive requirements, to the Model Bulletin of December 4, 2023, which directs insurers to maintain written AI governance programs, establish senior oversight, test for unfair discrimination and document AI-driven decisions well enough to explain them.
The bulletin is not a model law or a model regulation, so it carries no independent statutory authority. Each adopting state integrates it into its own framework, which is why 25 states adopting the same text has produced varying interpretation and enforcement rather than a national standard. That variation is itself the principal argument in the record for legislating.
The positions in the letters are stated plainly enough. A joint submission from APCIA, ACLI and NAMIC argued that the bulletin remains the appropriate vehicle, since insurers are already reachable through unfair claims settlement practices law, market conduct examination authority and state unfair trade practices statutes. APCIA's own letter said a model law is unnecessary at this time.
The American Academy of Actuaries went the other way, agreeing that the three-pillar framework of governance, transparency and accountability is appropriate for model legislation. Its letter attached a condition: that "unfair discrimination" and "unethical practices" need precise definition as applied to AI. Consumer advocacy groups, including the Center for Economic Justice and the National Consumer Law Center, pressed for mandatory pre-deployment testing, public disclosure of AI use in consumer-facing decisions and a private right of action.
Wisconsin Commissioner Nathan Houdek, who chairs the Working Group, has described the regulators themselves as split, saying the jury is still out and that some states think more is needed while others hold a very different opinion.
The Definition Decides Whether a Rate Filing Is In Scope
Of the five fault lines, the one that reaches actuarial work directly is what counts as an "AI system." The bulletin's definition is broad, covering machine learning, natural language processing and computer vision, and the breadth is what creates the problem.
Read broadly, a Poisson GLM with twelve rating variables qualifies. On that reading every personal auto rate filing in the country carries the governance, transparency and accountability obligations, and the compliance cost lands on methods that have been reviewed by regulators for decades without producing the consumer harm the law is aimed at.
Read narrowly, as techniques that learn from data without explicit programming, the boundary falls in an equally awkward place. A carrier scoring risk with XGBoost is inside the law; a carrier using a manually specified GLM on the same rating variables is outside it, even where the two produce identical pricing outcomes. The regulated object becomes the fitting procedure rather than the rate.
That is why the Academy's request for definitional precision is the substantive comment in the file rather than a drafting note. Actuaries rely on the line between actuarially justified risk differentiation and unfair discrimination when they build and validate models, and a statute that draws it imprecisely moves the compliance question from what a model does to how it was estimated.
Colorado shows what the prescriptive version costs. SB 21-169, signed in July 2021, requires insurers using external consumer data, algorithms and predictive models to run governance and risk management frameworks, monitor for unfair discrimination, and from July 1, 2026 file annual compliance reports for auto and health lines. Whether a national model law would sit above that as a ceiling or beneath it as a floor is a drafting choice that determines whether it reduces the patchwork or adds a layer to it.
The Enforcement Tool Arrives Whether or Not the Law Does
While the model law is still a question, the mechanism that would enforce it is already in the field. The 12-state AI Systems Evaluation Tool pilot launched on March 2, 2026 and runs through September, covering California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia and Wisconsin.
The tool has four exhibits:
- Exhibit A: quantify AI usage across the organization.
- Exhibit B: assess the governance and risk assessment framework.
- Exhibit C: detail high-risk AI systems, including those used in underwriting, claims and pricing.
- Exhibit D: cover AI data inputs and sources, with Version 4.0 adding a section on reasonable accommodations and policy modifications.
Trade groups representing life, health, P&C, mutual and reinsurance insurers objected in a joint letter on December 5, 2025, raising five points: that participation is voluntary for regulators but compulsory for selected companies, that the duration was initially undefined, that applicability to financial versus market conduct exams was unclear, that companies face potential penalties for negative findings during the pilot, and that the pilot launched before the final version had full public comment. They asked that participation be voluntary and that the information gathered be used only to develop the tool.
Iowa Commissioner Doug Ommen said the group would hear from participants at the conclusion of the pilot and consider refinements. The tool is expected to be updated on pilot feedback in September and October 2026, re-exposed, and adopted at the Fall National Meeting in November.
That sequencing is the complication. A standardized examination instrument covering underwriting, claims and pricing models becomes adoptable in November whether or not a model law is ever drafted, and market conduct examination authority already exists to use it. NCOIL is separately advancing its own Model Act on the same subject, so a second template may arrive from the body whose members actually pass insurance legislation. The definitional question the Academy raised does not get resolved by any of this; it gets asked one carrier at a time, by examiners working from Exhibit C.
Further Reading
- Allstate Patents a Pricing Engine That Auto-Rejects Risks: A newly granted patent claims a fully automated underwriting rejection engine, the exact kind of consumer-impacting AI decision the model bulletin's documentation expectations are built around.
- NAIC AI Model Bulletin Gets a Compliance Report Form: How the BDAI Working Group's nine-component compliance report structure converts the bulletin's principles into specific documentation fields, with the July 22 meeting advancing the framework toward 2027 implementation.
- NAIC AI Evaluation Pilot Launches Amid Industry Pushback
- NAIC Proposes Third-Party AI Vendor Registry for Insurers
- The AI Governance Gap in Actuarial Practice
- AI Regulation and NAIC 2026
- Predictive Analytics in Insurance Underwriting 2026
- NAIC Four-Tier AI Risk Taxonomy: How It Shapes the Model Law Framework
- Colorado's SB 26-189 Retreats From Mandatory AI Audits: How the first state to require algorithmic bias audits rewrote its law in under two years, and what the pivot signals for the NAIC's model law trajectory.
- State AI Law Patchwork Creates Four Distinct Carrier Compliance Regimes: How Connecticut SB 5, Colorado's revised framework, Texas TRAIGA, and the NAIC evaluation pilot interact to create overlapping but non-identical obligations for multi-state insurers.
- NAIC Market Conduct Modernization Group Takes on Exam Process Overhaul: the new working group tasked with updating examination frameworks, data standards, and interstate coordination for AI-driven insurers, with Fall 2026 recommendations expected.
- Congress probes credit-based insurance scores – the oldest rating variable meets the bulletin's governance vocabulary.
Sources
- NAIC, Request for Information: AI Model Law (May 2025)
- NAIC, Big Data and Artificial Intelligence (H) Working Group
- NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (December 2023)
- NAIC, Insurance Topics: Artificial Intelligence
- NAIC, Implementation Map: AI Model Bulletin State Adoption
- NAIC, AI Systems Evaluation Tool Pilot Project Summary
- NAIC, BDAIWG July 16, 2025 Meeting Minutes
- NAIC, BDAIWG September 29, 2025 Meeting Minutes
- American Academy of Actuaries, Comment Letter on AI Model Law RFI (June 2025)
- McDermott Will & Emery, Update on NAIC's Consideration of AI Model Law for Insurers
- Plante Moran, How the NAIC AI Model Bulletin Is Evolving (March 2026)
- InsuranceNewsNet, NAIC's 2026 AI Evaluation Pilot Moves Ahead as Industry Balks
- Fenwick, NAIC Expands AI Systems Evaluation Tool Pilot Program to 12 States
- Alston & Bird, Key AI Takeaways from the NAIC 2026 Spring Meeting
- Quarles & Brady, Nearly Half of States Have Adopted NAIC Model Bulletin on AI
- S&P Global Market Intelligence, NAIC Membership Divided on Developing AI Model Law (October 2025)
- Colorado Division of Insurance, SB 21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices
- Fenwick, Tracking the Evolution of AI Insurance Regulation
- NCOIL, Committee Working Drafts: Model Act Regarding Insurers' Use of Artificial Intelligence
- Crowell & Moring, NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know