
Research question
What does the National Association of Insurance Commissioners Model Bulletin on the Use of Artificial Intelligence by Insurance Companies expect of insurers, and what does that guidance mean for an insurance agency that adopts AI tools in its own operations or works alongside carriers that use them?
The question is timely because AI tools have moved quickly into writing assistance, call summarization, document classification, and customer response drafting, which are exactly the kinds of tasks an agency may delegate to staff or a virtual assistant. This paper reviews the NAIC guidance and the NAIC's current AI work program. It is not legal advice and does not describe the law of any particular state.
Method
This is a desk review of two NAIC sources:
- The NAIC's public topic page on artificial intelligence, last updated April 3, 2026, which describes the regulatory context, the model bulletin, and the ongoing work of the Big Data and Artificial Intelligence Working Group.
- The NAIC Model Bulletin on the Use of Artificial Intelligence by Insurance Companies, adopted December 4, 2023.
The topic page was read in full. The bulletin is referenced through the NAIC's published adoption document and the NAIC's own description of it. No insurer, agency, or vendor AI system was examined, and no model was tested. Evidence checked September 18, 2026.
Evidence
The regulatory context
The NAIC's topic page states that AI is used across the insurance industry in underwriting, pricing, customer service, claims handling, marketing, and fraud detection. It describes AI as increasingly capable of handling tasks that were once difficult for computers, including recognizing images, understanding written and spoken language, and analyzing large amounts of unstructured data.
The page also states the governing principle plainly: when insurers use AI, they remain responsible for complying with insurance laws, regulations, insurance standards, and consumer protection rules, including requirements related to fairness, accuracy, and avoiding unfair discrimination. It adds that state insurance regulators oversee insurers' use of AI and may require companies to explain how the tools are used in underwriting, pricing, marketing, or claims decisions, and that human oversight remains an important part of insurance decision-making.
Source fact: The NAIC's stated position is that using AI does not change the underlying compliance obligations. Responsibility stays with the regulated entity.
The model bulletin
The NAIC states that it developed the Model Bulletin on the Use of Artificial Intelligence by Insurance Companies, which was adopted in December 2023. According to the NAIC's description, the bulletin establishes guidelines and expectations to ensure responsible use of AI by insurance companies, aligned with the NAIC Principles of Artificial Intelligence adopted in 2020. The NAIC states that the bulletin reminds insurers that decisions or actions made or supported by AI must comply with all applicable insurance laws and regulations, sets expectations for how insurers will govern the use of AI, and advises insurers of the type of information the department may request during an investigation or examination.
Source fact: The bulletin is a governance and examination-expectation document. It is aimed at insurers, and its core message is that AI-supported decisions are the insurer's decisions.
The NAIC's AI work is continuing
The NAIC page describes an active work program rather than a finished rulebook. It states that the Big Data and Artificial Intelligence Working Group surveyed insurers by line of business beginning in 2021, with reports on private passenger auto, homeowners, life, and health companies. It reports that large shares of responding insurers said they use, plan to use, or plan to explore AI or machine learning. Among the responses it summarizes, 88 percent of responding auto insurers and 70 percent of responding home insurers reported that posture, compared with 58 percent of responding life companies and 92 percent of responding health insurers.
The page also describes newer work. It states that a Third-Party Data and Models Working Group was formed in 2024 to evaluate and develop a regulatory framework for third-party AI data and models, and that the working group is developing a framework to streamline how regulators gather information about those tools. It states that in 2025 and 2026 the Big Data and Artificial Intelligence Working Group has been developing an AI Systems Evaluation Tool as a guide for regulators in market conduct, financial analysis, or financial examination contexts, and that as of March 2026 the tool is being piloted by 12 participating states, with adoption anticipated at the 2026 Fall National Meeting.
Source fact: Even where a state has not enacted a specific AI statute, the supervisory toolkit is expanding. Regulators are building the questions they will ask.
What the guidance expects in substance
The NAIC's description and the model bulletin's stated purpose point to a consistent set of expectations: an AI governance framework with board and senior management oversight, a written policy or program, risk management that is proportionate to the use case, attention to third-party AI tools and data, testing and monitoring, and the ability to explain to a regulator how AI is used and how risks are managed. The NAIC's emphasis on human oversight reinforces that a person remains accountable for decisions that affect consumers.
Source fact: The expected controls are governance, documentation, risk management, oversight of third parties, and explainability, not a specific technology.
Findings
Finding 1: The bulletin is a model, not self-executing federal law. Its legal effect depends on adoption or implementation by state insurance regulators. Agencies should confirm the position in the states where they operate.
Finding 2: The core principle is accountability, not prohibition. The NAIC does not ask insurers to avoid AI. It asks them to govern it and to keep complying with existing law.
Finding 3: The guidance is directly relevant to third-party tools. The NAIC explicitly created a working group on third-party AI data and models, which is the category most agency tools and virtual assistant platforms fall into.
Finding 4: Supervision is becoming procedural. The AI Systems Evaluation Tool and the examination expectations signal that regulators will ask structured questions about AI inventory, governance, risk, and data.
Finding 5: Human oversight is a stated expectation. The NAIC's own summary places human review inside the acceptable use of AI in insurance decisions.
Interpretation: what this means for an insurance agency using a virtual assistant
The following is the author's interpretation, not NAIC text.
- The bulletin speaks to insurers, but agencies feel it through carrier requirements, producer agreements, and market conduct reviews. An agency that adopts AI tools for letters, notes, summaries, or customer replies should expect to answer questions about those tools.
- The most defensible posture for an agency is the same one the bulletin describes for insurers, scaled down: a written list of AI tools in use, a stated purpose for each, a named owner, limits on what the tool may produce without human review, and a record of who reviews the output.
- A virtual assistant who uses an AI writing tool to draft a client communication is the practical point where these expectations collide with daily work. The agency should decide in advance which outputs require licensed or management review before they leave the office.
- Third-party tools deserve specific attention. If a tool processes client data, the agency should understand what the vendor does with that data and how the arrangement fits the agency's other obligations, including its data security duties.
Operational implications
These are proposed steps derived from the guidance, not a regulatory checklist.
- Inventory AI tools used in agency operations, including features embedded in existing platforms, and name an owner for each.
- State the purpose and the limits of each tool in writing, including what it may not do, such as issuing coverage advice or binding authority decisions.
- Keep human review in the loop for anything that reaches a client or affects a coverage, pricing, or claims outcome.
- Document third-party arrangements for AI tools that process client data, including the vendor's data handling and the agency's oversight.
- Review vendor terms and confirm that the agency can describe how the tool is used, consistent with regulatory expectations.
- Train staff and virtual assistants on the difference between drafting and deciding, and on where an output must be escalated.
- Confirm state adoption. Check the guidance in each state where the agency operates, because the model bulletin is implemented state by state.
- Revisit the program periodically. The NAIC's work is still developing, and the expectations are likely to become more specific.
Limitations
- Not legal advice. This paper summarizes public NAIC sources. It does not determine whether any AI use complies with applicable law.
- The bulletin is a model. Its provisions matter through state adoption and carrier requirements, which were not surveyed exhaustively.
- The page is a summary. The NAIC topic page is a plain-language overview. The adopted bulletin text controls, and this review does not reproduce it in full.
- The work program is moving. Tool pilots, working group outputs, and state adoptions are changing. Confirm the current status before relying on any specific expectation.
- No facts. No agency tool, vendor contract, or AI use case was examined.
Practical conclusion
The NAIC's guidance does not tell insurers to stop using AI. It tells them that AI-supported decisions remain their decisions and must be governed, documented, and explained. For an insurance agency, the practical translation is a short, honest program: know which AI tools are in use, say what each is for, keep a person accountable for anything that reaches a client or affects coverage, oversee the vendors that process client data, and check what each operating state expects. The same discipline that makes an agency defensible for its human workflows applies to the tools layered on top of them. Because the guidance is implemented state by state and continues to develop, an agency should confirm its obligations with qualified counsel and with the carriers whose products it sells.
Sources
- National Association of Insurance Commissioners, Artificial Intelligence (topic page, last updated April 3, 2026). https://content.naic.org/insurance-topics/artificial-intelligence
- National Association of Insurance Commissioners, Model Bulletin on the Use of Artificial Intelligence by Insurance Companies, adopted December 4, 2023. https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf
- National Association of Insurance Commissioners, Principles on Artificial Intelligence, adopted 2020. https://content.naic.org/sites/default/files/inline-files/AI%20principles%20as%20Adopted%20by%20the%20TF_0807.pdf
- National Association of Insurance Commissioners, Big Data and Artificial Intelligence (H) Working Group. https://content.naic.org/committees/h/big-data-artificial-intelligence-wg
