The NAIC's Third-Party Data and Models (H) Working Group advanced a draft framework at the Spring 2026 National Meeting in San Diego that would require AI model vendors to register with state insurance departments before carriers can deploy their products in consumer-facing functions.
That is a new regulatory surface rather than a refinement of the 2023 Model Bulletin, which reached insurer conduct only. It runs upstream, into the vendors supplying underwriting, pricing, claims automation and fraud detection to many carriers at once.
Key Takeaways
- Six covered functions sit in scope where a third-party model has direct consumer impact: pricing, underwriting, claims, utilization review, marketing and fraud detection. That is close to every production use of vendor AI at a carrier.
- Registration, not licensure. Vendors submit entity information and model documentation and file an annual governance attestation. There are no capital requirements, examinations or revocation proceedings in the draft.
- A 60-day comment period ran from the December 9, 2025 exposure through February 6, 2026, drawing dozens of letters. The Working Group reviewed them on February 26, 2026 and kept the registration requirement in the draft.
- Direct regulator access is the structural change: for the first time regulators would see vendor documentation without the insurer as intermediary.
- 50 or more separate registrations would face a national vendor absent reciprocity, which several commenters argue would concentrate the vendor market rather than open it.
What the Framework Requires
The draft rests on three components, and the distinction between the first two and existing tools is what makes it new.
Vendors whose products are used in insurer functions with direct consumer impact must register with state departments before carriers deploy them, submitting entity information and model documentation. As Carlton Fields noted, the Working Group sees registration as the way to identify, track and set minimum governance expectations for third-party providers. Registration is a transparency mechanism; licensure, with its examinations and revocation proceedings, is not on the table.
Registered vendors must then maintain a documented governance program and attest annually that they adhere to it. The framework sets minimum expectations for documentation, model testing and data governance without prescribing the program's structure. Third-party filings get the same confidentiality treatment as insurer proprietary information and trade secrets, a provision added after early vendor concern about intellectual property.
Three NAIC initiatives now run in parallel, and they differ mainly in who they reach:
| Dimension | Model Bulletin (Dec 2023) | AI Evaluation Tool Pilot (Mar-Sep 2026) | Vendor Registry Framework (Proposed) |
|---|---|---|---|
| Primary target | Insurers | Insurers | Third-party vendors |
| Regulatory mechanism | Guidance bulletin adopted by states | Examination tool used within existing exam authority | Registration-based framework with governance requirements |
| Adoption status | ~24 states plus D.C. have adopted | 12-state pilot running through September 2026 | Exposure draft; comments reviewed; refinement ongoing |
| Third-party visibility | Indirect (through insurer vendor management) | Indirect (Exhibit D asks about data sources) | Direct (vendors register and attest to governance) |
| Enforcement basis | State regulatory authority over insurers | Existing financial and market conduct exam authority | New registration requirement (authority still debated) |
The Second Source Changes What Validation Has to Be
The mechanism worth understanding is not registration itself but the channel it opens, because it gives a regulator two accounts of the same model.
Under the Model Bulletin and the AI Evaluation Tool pilot, the insurer is the intermediary. A regulator asking about a third-party model receives whatever the carrier obtained during procurement. Where a vendor treats architecture, training data composition or validation methodology as proprietary, that documentation can amount to model summaries rather than the technical detail a validation team would need.
The registry gives the regulator a direct account from the vendor. What the vendor tells the department and what it told the carrier become comparable documents, and any gap between them surfaces during an examination of the carrier. A validation function resting on vendor-supplied documentation as a proxy for its own testing is exposed by that comparison, not by any new validation standard.
The consequence reaches rate filings specifically. Where a filing relies on a vendor-supplied loss cost model or classification system, registry information about that vendor's governance program is available to the reviewer, so questions about testing methodology, data composition and validation results become part of routine review rather than something raised only when a filing is contested.
Banking supervision reached this point first and stopped short of the structural step. The Federal Reserve's SR 11-7, issued in April 2011, requires banks to validate vendor models with the same rigour as internal ones, acknowledging that modelling expertise may sit outside the bank and some components may be proprietary. It expects outcomes testing, sensitivity analysis and benchmarking, and it scales validation intensity to model materiality.
The NAIC draft carries none of those: no quantitative validation requirements, no model tiering, and no ongoing monitoring between annual attestations. What it adds instead is the centralized registry, which banking regulation never built, because insurance regulators oversee thousands of carriers across 56 jurisdictions and many state departments could not construct that map alone.
The Registry May Concentrate What It Is Mapping
The strongest objection is not that the registry asks too much of vendors, but that the burden falls unevenly in a direction that works against the framework's own rationale.
The rationale is concentration risk. When one vendor's catastrophe model sits inside dozens of carriers' reinsurance decisions, or one underwriting algorithm drives selection at several companies writing the same lines, the vendor becomes a source of correlated exposure no single-carrier examination detects. The registry is the first attempt to see that.
Yet without reciprocity or portable registration, a national vendor faces 50 or more separate processes with potentially different filing requirements, timelines and governance standards. Large providers with existing compliance infrastructure absorb that as administrative overhead, and registration may function as a credential smaller competitors cannot match. An early-stage company would have to build governance documentation, register across multiple states and maintain annual attestation before a single carrier could put its model into production. Commenters flagged the result directly: a barrier to entry that protects incumbents in a market whose concentration is the stated concern.
The legal foundation is also untested. Insurance regulatory authority derives from state codes written around insurers and their contractual counterparts, and whether it extends to technology vendors supplying analytical tools rather than insurance products is an open question no state has litigated. Framing registration as transparency rather than regulation narrows the exposure without resolving it, and the question is likely to be answered only when a vendor declines to register. Scope compounds that: with "data," "model" and "direct consumer impact" defined broadly in the current draft, a vendor supplying one data feed into a carrier's own pricing model sits alongside one supplying a packaged underwriting decision engine.
Further Reading
- Duck Creek Buys Send: The Build-vs-Buy Shift in Agentic Underwriting – A concrete test case for this registry: an orchestration vendor whose triage rules now function as underwriting guidelines the carrier must be able to produce on demand.
- NAIC Third-Party Vendor Registry for Insurance AI: What the Model Law Draft Means for Actuaries -- The March 23, 2026 Spring National Meeting proceedings in detail: registry versus licensure enforcement gaps, the alien insurer analogy that reveals the registry's intended market function, the state authority constitutional question, and the three unresolved questions heading into the Summer 2026 Columbus meeting.
- NAIC Third-Party AI Framework Keeps Carrier Accountability: What Actuaries Must Build Before State Adoption – The operational compliance question the registry creates for actuarial teams: how to independently validate and audit vendor models when carrier accountability does not transfer to a registered vendor.
- NAIC AI Pilot Moves Insurer Reviews Into Market Exams – How model inventories, consumer harm scoring, and third-party controls become reviewable evidence in examination workflows, and where vendor documentation is the weakest link in most carrier evidence chains.
- NAIC AI Evaluation Pilot Launches Amid Industry Pushback – The 12-state pilot running through September 2026, including the four-exhibit structure and the joint industry letter.
- Why the NAIC Singled Out Claims AI for Additional Regulatory Review – How the vendor registry's initial exclusion of claims creates a documentation gap that carriers must close through contractual audit rights with claims AI vendors.
- The AI Governance Gap in Actuarial Practice – How ASOP No. 56 applies to AI systems and where the standards fall short of current deployment realities.
- CCC's Top-Five Subrogation Win Puts an AI Score Inside the Net Loss Pick – A concentrated-reliance case study one step closer to the registry's core concern: a single vendor's subrogation model now driving recovery decisions across one of the largest US auto books.
- AI Regulation and NAIC 2026 – Broader regulatory context, including the Model Bulletin, state adoption, and the trajectory toward a possible AI model law.
- EXL's 10 AI Patents: Building Insurance's AI Infrastructure – How one major third-party vendor is building a patented AI stack for carrier deployment.
- The AI Patent Race in Insurance: Complete Guide – AIG, Quantiphi, and EXL patent strategies across underwriting, claims, and data infrastructure.
- NAIC Model Law Deliberation: How 33 RFI Responses Are Shaping Insurance AI Regulation – The vendor liability fault line, company-size thresholds, and the path from bulletin to statute.
- NAIC Risk Taxonomy and Compliance Reports: Where Third-Party Vendor Documentation Fits – The four-tier framework and model card requirements that will shape vendor governance expectations.
- How the NAIC Cybersecurity Notification Portal Addresses Multi-State Compliance – The parallel H Committee project building centralized reporting infrastructure for Model Law 668 breach notifications.
Sources
- Alston & Bird, "Key AI, Cybersecurity, and Privacy Takeaways from the NAIC 2026 Spring Meeting" (April 2026)
- Mondaq / Eversheds Sutherland, "NAIC Spring 2026 Meeting: Third-Party Data and Models (H) Working Group" (April 2026)
- Mondaq / Eversheds Sutherland, "NAIC Fall Meeting Update: Third-Party Data and Models (H) Working Group Exposes Risk-Based Regulatory Framework" (January 2026)
- NAIC, Third-Party Data and Models (H) Working Group
- NAIC, Big Data and Artificial Intelligence (H) Working Group
- NAIC, Third-Party Data and Models Working Group Materials, Spring 2026 National Meeting (March 23, 2026)
- NAIC, Big Data and AI Working Group Materials, Spring 2026 National Meeting (March 24, 2026)
- NAIC, Model Bulletin: Use of Artificial Intelligence Systems by Insurers (December 2023)
- NAIC, Model Bulletin State Adoption Tracker (updated April 2025)
- NAIC, Insurance Topics: Artificial Intelligence
- Carlton Fields, "NAIC Working Group Begins Sculpting a Framework to Assess Third-Party Data and Models" (2025)
- Holland & Knight, "The Implications and Scope of the NAIC Model Bulletin on the Use of AI by Insurers" (May 2025)
- McDermott Will & Emery, "State Regulators Address Insurers' Use of AI: State Adoption Tracker"
- Federal Reserve, Supervisory Letter SR 11-7: Guidance on Model Risk Management (April 2011)
- Fenwick, "NAIC Expands AI Systems Evaluation Tool Pilot Program to 12 States" (2026)
- Actuarial Standards Board, ASOP No. 56: Modeling
- Fenwick, "Tracking the Evolution of AI Insurance Regulation"