What Is the NAIC AI Model Bulletin and Which States Have Adopted It?
The NAIC AI Model Bulletin is a non-binding framework issued by the National Association of Insurance Commissioners in early 2023 that sets baseline expectations for insurers deploying artificial intelligence and algorithmic decision-making systems. Rather than functioning as law itself, the bulletin serves as template language that individual state regulators can adopt through their own legislative or administrative processes. As of August 2026, eleven states have formally adopted the model bulletin's language or substantively equivalent requirements, while a larger group of jurisdictions has issued guidance documents, market conduct bulletins, or examination protocols that track its principles without formal adoption. The bulletin concentrates on the insurance functions where algorithmic decisions carry the greatest consumer consequence: underwriting, rating, claims adjudication, and consumer-facing interactions. Its core demands are governance-oriented rather than technology-specific — insurers must document how models are developed, tested for accuracy and disparate impact, monitored after deployment, and governed by accountable human oversight. For payors and carriers operating across state lines, the practical effect is a compliance patchwork: the same AI system may face pre-deployment validation requirements in one state, post-deployment monitoring expectations in another, and only general unfair trade practices scrutiny in a third. Understanding which states have adopted the bulletin, and how each has modified it, is now a foundational input into any multi-state AI compliance program.
Also worth reading: How does the NAIC model law AI compliance guide work for insurance companies in 2026? · How do I dispute a workers compensation premium audit and win? · What are the best practices for COI compliance tracking in insurance underwriting?
Why the NAIC Issued the Bulletin: The Regulatory Problem It Responds To
The bulletin emerged from a specific regulatory anxiety: that opaque machine learning models could reproduce or amplify discrimination in ways traditional rate filing review cannot detect. Legacy actuarial models used a small number of transparent variables — age, territory, driving record — that regulators could inspect line by line. Modern models ingest hundreds or thousands of features, including credit-based scores, telematics data, purchasing patterns, and in some cases proxy variables that correlate with protected characteristics like race or zip code-level socioeconomic status. A model never explicitly using race can still produce racially disparate outcomes if its inputs correlate with race. Regulators at the NAIC's Innovation, Cybersecurity and Technology (H) Committee concluded that existing unfair trade practices statutes and rate filing regimes were not designed to surface these risks, particularly because many insurers purchase third-party models whose internals they do not fully understand themselves. The bulletin's answer is to shift the regulatory burden toward documentation and governance: an insurer must be able to explain what its model does, demonstrate it was tested before deployment, show it is monitored afterward, and identify who inside the organization is accountable when it fails. This mirrors the "three lines of defense" structure familiar from financial services regulation. The timing also reflected external pressure — high-profile reporting on algorithmic bias in insurance pricing and claims, plus parallel federal activity from the NAIC's counterparts in banking, created momentum for a coordinated state-level response.
The Adoption Landscape: Eleven States and Counting
Formal adoption has proceeded unevenly since 2023. According to tracking by McDermott Will & Schulte, eleven states had adopted the NAIC model bulletin's language through legislative action, regulatory rulemaking, or binding commissioner bulletins by mid-2026. Early adopters tended to be states with active insurance innovation agendas; later adopters often moved after their own market conduct examinations revealed gaps in vendor oversight or model documentation. Beyond the eleven formal adopters, numerous other states have issued guidance that aligns with the bulletin's principles without adopting its text verbatim — some through market conduct exam handbooks, others through advisory opinions clarifying that existing unfair practices laws apply fully to algorithmic decisions.
| Category | Approach | Examples of Mechanism | Compliance Burden |
|---|---|---|---|
| Formal adopters (11 states) | Adopted bulletin language via statute, rule, or binding bulletin | Commissioner orders, regulatory rulemaking | Highest — enforceable documentation and governance duties |
| Guidance-aligned states | Issued advisories referencing bulletin principles | Market conduct bulletins, exam protocols | Moderate — enforceable through existing UTP authority |
| Observing states | Monitoring pilot programs and peer outcomes | Participation in NAIC evaluation tool pilots | Lower today, rising as tools mature |
| Divergent states | Crafting bespoke AI requirements | State-specific model laws under debate | Unpredictable — watch legislative sessions |
What the Bulletin Actually Requires of Insurers
Stripped of legal formatting, the bulletin imposes four clusters of obligations. First, governance: insurers must maintain a written AI governance framework identifying accountable executives, defining risk tolerance for model error, and establishing escalation paths when models misbehave. Second, documentation: firms must retain records of model development, including training data provenance, feature selection rationale, validation results, and any disparate impact testing performed across demographic groups. Third, third-party oversight: because most carriers license models from vendors, the bulletin makes clear that outsourcing does not outsource accountability — insurers must perform due diligence on vendor models and cannot claim ignorance of how a purchased scoring engine works. Fourth, ongoing monitoring: deployment is not the end of the obligation; insurers must monitor model performance drift, re-test periodically, and remediate when outcomes diverge from validated expectations. The NAIC has supplemented these principles with a standardized evaluation tool piloted to help examiners assess insurer AI programs consistently across jurisdictions, a development covered by Repairer Driven News and discussed at the Spring 2026 National Meeting. Notably, the bulletin does not ban any particular technique, does not require explainability by algorithmic method, and does not create a private right of action — enforcement flows through existing market conduct and unfair practices authority. That restraint was deliberate: the NAIC wanted a floor, not a ceiling, and explicitly left room for states to go further.
How State Adoption Differs From a Federal Approach
The bulletin-versus-federal-law distinction shapes everything about compliance strategy. Because the United States has no comprehensive federal insurance AI statute, the NAIC model operates as coordinated soft law: it harmonizes expectations without preempting state autonomy. This produces both benefits and friction. On the benefit side, a carrier that builds one governance program meeting the bulletin's requirements can generally satisfy most state regulators, since the model language gives examiners a common reference point. On the friction side, states remain free to modify, exceed, or delay adoption, so multistate carriers still maintain state-by-state matrices tracking which obligations apply where. Compare this to sectors like consumer lending, where federal agencies issue binding rules with uniform effect. Insurance regulation is historically state-based under the McCarran-Ferguson framework, and the NAIC's model law approach preserves that structure. There is also a live debate inside the NAIC about whether the bulletin should evolve into a true model law with mandatory force — S&P Global reported membership division on this question, with some commissioners favoring a binding model act and disclosure standard, and others preferring continued reliance on guidance. Meanwhile, some states are pursuing entirely independent legislation on algorithmic discrimination, raising the possibility that the eventual landscape will be less uniform than the bulletin intended. Carriers should therefore treat bulletin compliance as necessary but not sufficient, and monitor state legislative sessions for divergent proposals.
Practical Steps for Payors and Carriers Preparing for Multi-State Compliance
A workable compliance program starts with inventory. Most insurers discover they cannot enumerate every algorithmic system touching consumers — underwriting scorecards, claims triage engines, fraud detection models, chatbots, and third-party data enrichment tools all count. Build a registry capturing each system's purpose, data inputs, vendor origin, decision impact, and affected lines of business. Next, assign ownership: the bulletin's governance expectations fail without a named executive accountable for AI risk, typically within the chief risk officer or chief compliance officer function. Third, close the documentation gap for legacy models, which were often built without the records the bulletin now expects; retrospective validation and disparate impact testing may be needed. Fourth, renegotiate vendor contracts to secure the access rights needed for due diligence — model cards, performance metrics, and change notifications. Fifth, align internal testing with the NAIC evaluation tool pilot methodology so examiner requests can be answered efficiently. Faegre Drinker's launch of algorithmic discrimination testing services for insurers illustrates how quickly an advisory ecosystem has formed around these obligations; outside counsel and specialized consultants can stress-test a program, but the underlying governance must live inside the carrier. Finally, integrate AI oversight into board reporting. As commentary in Insurance Business has argued, boards need enough visibility to govern AI risk without micromanaging model development — a calibrated reporting cadence covering incidents, testing results, and regulatory developments strikes that balance.
Common Mistakes Insurers Make With Bulletin Compliance
Several recurring errors deserve attention. The first is treating the bulletin as a one-time project: firms that produced a governance document for the initial filing but never operationalized monitoring find themselves exposed when examiners ask for evidence of ongoing oversight. The second is the vendor blind spot — assuming that because a model came from a reputable analytics firm, its fairness and performance are someone else's problem. Regulators have been explicit that the regulated entity bears responsibility regardless of who built the model. The third is narrow scoping: carriers sometimes apply AI governance only to underwriting while ignoring claims automation, where denial decisions generate the highest volume of consumer complaints and litigation risk. The fourth is confusing correlation testing with causation analysis in disparate impact reviews; simply measuring outcome differences across demographic groups without investigating driver variables leaves both the bias and the regulator's questions unanswered. The fifth is poor version control — updating a model in production without re-running validation creates an undocumented system that no longer matches its own filings. The sixth is treating explainability as purely technical; a model can be statistically interpretable yet unexplainable to a regulator or consumer in plain terms, and the bulletin's transparency emphasis requires communication, not just mathematics. Avoiding these mistakes costs far less than remediating them after a market conduct examination identifies them.
When to Act: Timing Considerations Through 2026 and Beyond
The window for proactive compliance is narrowing. Eleven states have already adopted the bulletin, and the trajectory points toward broader uptake as the NAIC's evaluation tool matures and peer-state pressure accumulates. Carriers should assume additional adoptions in upcoming legislative and regulatory cycles rather than waiting for certainty. Three timing triggers warrant attention. First, new model deployments: any AI system entering production should meet bulletin-grade documentation standards from day one, because retrofitting is expensive and incomplete. Second, renewal cycles for vendor contracts: embedding due diligence and audit rights now avoids painful renegotiations later. Third, examination notices: several states have begun incorporating AI questions into routine market conduct exams, meaning even non-adopter states may probe bulletin-aligned topics. Health payors face a distinct urgency given heightened scrutiny of utilization management algorithms and prior authorization automation, areas where Crowell & Moring and other observers note intensifying regulatory focus. The strategic calculation favors acting ahead of mandates: building governance incrementally over twelve to eighteen months spreads cost, surfaces problems while they are fixable, and positions the organization to respond quickly when additional states adopt. Waiting until enforcement arrives converts a manageable compliance investment into a defensive scramble conducted under examiner deadlines.
The Road Ahead: From Bulletin to Binding Law?
The central open question is whether the bulletin remains the ceiling or becomes the floor. NAIC membership remains divided on converting the framework into a model law with mandatory adoption targets and a standardized consumer disclosure requirement, and debates at recent national meetings show no consensus on scope — some commissioners want guardrails limited to underwriting and rating, while others argue claims and marketing personalization demand equal attention. Meanwhile, state legislatures are not waiting: independent algorithmic discrimination bills, AI disclosure statutes, and insurance-specific AI acts are advancing in multiple capitals, threatening the very uniformity the bulletin was designed to promote. For insurers, the sensible posture is to build to the strictest plausible standard rather than the loosest current one. A governance program capable of satisfying pre-deployment validation, documented disparate impact testing, vendor accountability, and consumer-facing explanation will survive nearly any foreseeable regulatory configuration. Organizations that invest in that capability now will treat future adoptions as administrative updates; those that wait will keep paying a compliance tax in the form of emergency remediation, examiner findings, and reputational exposure. The bulletin's real lesson is that algorithmic accountability in insurance has moved permanently from optional to expected — the only variable left is how fast each state says so formally.