What does the NAIC Model Bulletin on AI require from insurers deploying AI agents?
The 2023 NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers requires carriers to maintain governance frameworks over all AI systems used in underwriting, claims, and customer interactions. This includes documented policies governing how AI makes or informs decisions, oversight of third-party AI vendors, and mechanisms to detect unfair discrimination. For AI agents that access policyholder data or drive automated decisions, insurers must be able to demonstrate what data the agent consumed, under what authorization, and whether the output was consistent with filed policy guidelines. The Bulletin does not prescribe a specific technical architecture, but the accountability requirements map directly to runtime policy enforcement and audit logging at the retrieval layer.
What are the third-party oversight requirements under the NAIC Insurance Data Security Model Law (#668)?
NAIC Model Law #668 requires licensed insurers to oversee third-party service providers that access, process, or store nonpublic information on the insurer's behalf. Covered companies must include contractual provisions ensuring vendors maintain appropriate security controls and must conduct risk-based due diligence before engagement and periodically thereafter. For AI deployments, any model vendor, data pipeline operator, or agent framework provider that touches customer data falls within scope. Insurers must document what nonpublic information the vendor accesses and verify their controls meet the insurer's information security program requirements. Gaps in this documentation are a common exam finding in states that have adopted Model Law #668, including New York, South Carolina, Ohio, and Michigan.
When does the NAIC Insurance Data Security Model Law apply, and which states have adopted it?
The NAIC Insurance Data Security Model Law (#668) applies to insurance licensees — carriers, agents, and brokers — holding a license in an adopting state. It is not federal law; each state legislature must enact it independently. As of 2026, more than 20 states have adopted versions of Model Law #668, with New York (via NY DFS Part 500), South Carolina, Ohio, and Michigan among the earliest movers. The New York DFS version is the most prescriptive and carries its own examination authority. Insurers operating across multiple states must satisfy the most restrictive adopted version. Organizations expanding AI-driven underwriting or claims workflows need to verify adoption status in each state where they are licensed before assuming a single compliance posture.
How does AutoPIL help insurers meet NAIC data security and AI governance requirements?
AutoPIL addresses three NAIC compliance pressures directly. First, its policy engine enforces access controls before sensitive policyholder data enters an AI agent's context, satisfying the information security program requirements under Model Law #668. Second, the agent registry documents every third-party AI service provider and its authorized data scope — a direct response to vendor oversight obligations. Third, the tamper-evident audit log records every access decision with a cryptographic chain, giving insurers a defensible evidence base for incident notification scope under #668 and for regulatory examinations under the AI Bulletin. AutoPIL policy IDs INS-NAIC-668-001 and INS-NAIC-AIBUL-001 map enforcement rules to these specific obligations.
What are the incident notification requirements under the NAIC Insurance Data Security Model Law?
Under NAIC Model Law #668, a licensee that discovers a cybersecurity event must notify the domiciliary state insurance commissioner within 72 hours if the event meets materiality thresholds — typically affecting 250 or more consumers or meeting a harm standard. Notification must include the nature and scope of the event, the categories of nonpublic information involved, and corrective actions taken. For AI-related incidents, scoping the exposure is often the hardest part: insurers must identify exactly which data the AI system accessed, which agents were involved, and over what timeframe. A runtime audit log that records every agent access decision — indexed by agent, data source, and timestamp — is the most direct mechanism for producing accurate scope documentation within the 72-hour window.