At its March 23, 2026 Spring National Meeting, the NAIC's Third-Party Data and Models (H) Working Group held one provision unchanged against objections from 23 comment-letter authors: insurer accountability for AI-driven consumer decisions does not transfer to a registered vendor. A carrier using a vendor pricing model that produces biased outcomes is still the responsible party. That clause turns a vendor registration scheme into a carrier-side actuarial validation obligation.
Key Takeaways
- 23 comment letters, one unchanged clause. The Working Group narrowed scope in response to industry objections but left accountability nontransfer intact, which tells carriers which half of the framework is negotiable.
- Scope cut from six covered functions to two. Pricing and underwriting are in; claims handling, utilization review, marketing and fraud detection are deferred to a later phase.
- More than 25 states had adopted the 2023 NAIC AI Model Bulletin by early 2026, which already requires the same governance rigor for third-party models as for internally built ones.
- Examiners routinely review two to three years of lookback documentation, and will cross-reference the vendor's registry filing against the carrier's own validation record.
- First state implementations are expected in late 2026 or early 2027, roughly six to twelve months after the November 2026 Fall Meeting.
Registration Buys Transparency, Not Liability Transfer
The proposal, first exposed in December 2025 with a 60-day comment period closing February 6, 2026, would require third-party data and model vendors to register with state insurance departments before carriers can use their products in consumer-facing pricing and underwriting. The registry structure and the industry opposition are covered in the earlier vendor registry piece.
"Registration is intended to provide regulators with information they need from third parties without requiring each party to undergo an extensive licensure process," the Working Group stated. The registry answers who is selling models and what governance those vendors maintain. Whether a carrier's deployment produces fair, accurate outcomes for its own policyholders stays with the carrier.
The scope narrowing came in response to objections that the December definitions of data, model, third-party vendor and direct consumer impact were too broad (Eversheds Sutherland). It also captures the highest-concentration part of the vendor market. ISO loss cost and classification systems underpin rate filings at hundreds of carriers at once, so a single vendor update to an ISO loss cost model propagates across dozens of carrier rate plans in the same filing cycle, which is exactly the systemic exposure an individual carrier examination cannot see and a registry can.
Five Vendor Disclosures, Five Carrier Assessments
The framework requires vendors to file five documentation categories at registration. Each defines what the vendor discloses, and by implication what an actuarial team has to assess against its own book.
- Purpose and intended use. A vendor writes the purpose statement for a general market. A model documented for standard auto risk stratification, deployed in a nonstandard segment or on a regionally skewed portfolio, carries an intended-use mismatch the registry filing does not resolve.
- Training data sources and vintage. A disclosure reading "personal auto loss data from member companies, 2015 through 2023" is real information and raises three questions the registry does not answer: how the training distribution compares to the carrier's book, whether a vintage ending in 2023 captures post-pandemic frequency and severity, and whether a multi-state multi-company cohort generalizes to a state-specific book.
- Bias testing methodology. The vendor attests that testing was performed against protected class proxies. It does not establish outcomes in the carrier's deployment.
- Known limitations. A limitation such as reduced accuracy in high-theft ZIP codes is material for an urban personal auto writer and immaterial for a rural specialty carrier. The assessment, not the vendor's list, is the carrier's file.
- Change management practices. The requirement signals that regulators expect carriers to stay current on vendor changes, not just to have made a defensible initial deployment decision.
Bias testing is where the accountability clause actually bites, because disparate impact depends on the population being scored. A model that clears national-cohort testing can fail at a carrier whose geographic or demographic concentration produces materially different input distributions. Passing the vendor's test is evidence about the vendor's cohort, not about the carrier's rating universe, and the carrier is the party the framework holds responsible for the difference.
That is a validation burden with an actuarial shape: a structured comparison of vendor-disclosed data characteristics against the carrier's own portfolio characteristics, documented conclusions on the gaps, and independent testing on the carrier's policyholder data where the concentration is material.
The Carrier Cannot Validate What It Has No Right to See
The obligation runs ahead of the contracts. A carrier cannot maintain an independent validation record for a vendor model without contractual rights to the technical documentation that validation requires, and examiners will not accept that the vendor declined to share it.
The minimum set is specific: training data provenance covering source institutions, vintage, geographic scope and line-of-business composition; bias testing results by protected class proxy rather than a certification that testing occurred; performance metrics on hold-out samples comparable to the carrier's book; version history for the current deployment and the prior two versions; and a notification commitment with defined lead time before future updates reach production.
Some of that already exists inside the vendors. Verisk's Synergy Studio is built to let carriers combine their own data with Verisk datasets and produce auditable carrier-specific performance records, and EXL's governance architecture includes a Governance Hub component for compliance workflows. Documentation held in a vendor's internal systems is not the same as a carrier holding contractual access to it on demand, and that provision is what most standard agreements currently lack.
The gap that keeps opening on its own is the sub-major update. When a vendor pushes a recalibration below the thresholds that trigger annual review or major-version review, the carrier's rating plan changes with no internal action taken and no validation performed. Examiners running a two-to-three-year lookback will line the vendor's version history up against the carrier's validation dates, and every unexplained gap between them is a finding written against a model the carrier did not build and cannot fully see.
Further Reading
- NAIC Proposes Third-Party AI Vendor Registry for Insurers: Supply-Chain Oversight Comes to Insurance AI
- The AI Governance Gap in Actuarial Practice
- NAIC Market Conduct Modernization and the AI Working Group
- NAIC Model Bulletin Compliance Report Form 2026
- NAIC Life AI Accelerated Underwriting and Market Conduct
- How the February letters reshaped the framework before Columbus
- FTC's AI Accuracy Policy Statement Pulls Insurer Models Under Section 5
Sources
- NAIC, Third-Party Data and Models (H) Working Group (accessed June 2026)
- NAIC, Third-Party Data and Models Working Group Materials, Spring 2026 National Meeting (March 23, 2026)
- Mondaq / Eversheds Sutherland, "NAIC Spring 2026 Meeting: Third-Party Data And Models (H) Working Group" (April 2026)
- Foley Hoag, "NAIC Spring 2026 Meeting: Third-Party Data and Models (H) Working Group" (April 2026)
- swept.ai, "The 2026 NAIC Third-Party Model Law: A Vendor Registry Is Coming for Insurance AI" (2026)
- Mayer Brown, "US NAIC Spring 2026 National Meeting Highlights: Innovation, Cybersecurity and Technology (H) Committee Update" (April 2026)
- Mondaq / Eversheds Sutherland, "NAIC Fall Meeting Update: Third-Party Data And Models (H) Working Group Exposes Risk-Based Regulatory Framework" (January 2026)
- NAIC, Model Bulletin: Use of Artificial Intelligence Systems by Insurers (December 2023)
- Plante Moran, "How the NAIC AI Model Bulletin Is Evolving and Why Insurers Should Prepare Now" (March 2026)