Home
/
Blog
/
Insights
/
NAIC AI Pilot Update and What Comes Next for Insurers

NAIC AI Pilot Update and What Comes Next for Insurers

Subscribe to updates

Receive the latest content and invites to your inbox, unsubscribe anytime.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share

The NAIC AI pilot launched across twelve states back in March and regulators have been using it to ask insurance companies how they use AI and how they govern it responsibly.  

In June, I wrote my first post on the topic: five reasons I thought this pilot was a meaningful signal for the industry, even for carriers, MGAs, and brokers outside the twelve pilot states. This is the second, now that the pilot is further along, has changed its name, and has been through a round of public comment.

Since June, the pilot's current draft has been renamed to the AI Risk Evaluation Supplement v5.0 from AI Systems Evaluation Tool. It went out for public comment on August 31, and that window closed September 29, the same week 9,000+ people were with us on the ITC Vegas floor talking about agentic AI. It’s interesting how a regulator was writing about agentic AI the same week the industry was on a show floor hyping it up. 

My reasons in June were that AI decisions will need to be traceable, human-in-the-loop (or AI TPAs) won’t be enough on their own, auditability will become core infrastructure, the trust layer around a model will matter as much as the model itself, and early movers will gain an advantage. Version 5.0 gives two of those predictions real specifics, and starts to confirm a third.

Traceability and Auditability Aren’t Aspirational Anymore

Exhibit B, the section of the Supplement that evaluates a company's AI governance program, used to ask companies to describe their oversight plans in a checklist. Version 5.0 asks for the document name and page number behind each answer.

"We handle that in our model risk committee" stops being an answer. Either the control is written down somewhere a regulator can locate or it isn't a control yet. My reasons from June hold up and now there's a specific requirement written into an exhibit with its own dedicated field for it.

Human-in-the-Loop Won’t Be the Only Checkpoint 

Version 5.0 defines agentic AI for the first time as systems that "pursue objectives across multiple steps without requiring human input at each stage." It doesn't yet define what an agent is permitted to access or what happens when it operates outside its boundaries. However, that level of detail is almost certainly coming. 

Human-in-the-loop as a single checkpoint was never going to be the whole answer for something that takes multiple steps on its own and regulators are already writing toward something more specific.

The Trust Layer of AI Matters as Much as the Model

Version 5.0 adds guidance folding generalized linear models (GLMs), the actuarial technique insurers have used in pricing and underwriting for decades, into the same governance conversation as newer machine learning. 

Its language treats GLMs the same as any other model, "not without risk of causing unfair discrimination or other adverse consumer outcomes". That's the trust-layer point exactly. The regulator isn't grading how sophisticated your model is. They're asking whether the governance wrapped around it holds up, and a twenty-year-old GLM with no audit trail fails that question just as easily as a black-box model would.

Why Insurers Shouldn’t Wait 

Most AI in insurance today was built to clear operational bars like speed and containment. None of that is what a regulator is going to ask about.

They'll ask whether insurers can demonstrate that their AI follows defined policies, produces traceable decisions, and operates within a documented governance structure.  

State regulators in twelve pilot states have been using this guidance since March. Version 6.0 is now going through a shorter comment window and Version 7.0 is expected to be considered at the NAIC Fall National Meeting in November. 

While adoption there won’t create a new nationwide mandate by itself, the Supplement will be made available to every state as a standard resource, on top of a pilot twelve states are already running under authority they’ve had all along.

Most systems weren’t designed to answer to it — Notch was. We built Notch's governance layer around the same bar, with rules that can be set per jurisdiction, audit trails that aren't a reporting feature added after the fact, and guardrails that are built in by default, not bolted on later. See how that maps to the Supplement's exhibits.

Early movers aren't waiting for an adoption vote to decide it's time to get their AI governance in order. That gap is the advantage.

I'll keep tracking this as it moves toward November. If you're evaluating AI right now, the question worth asking before "what can it automate" is simpler: can you prove it, on demand, in writing?

Key Takeaways

  • Undocumented controls don't count. Exhibit B now asks for the document name and page number behind every governance answer. If a regulator can't find it in writing, it isn't a control yet.
  • Agentic AI is officially on the regulator's radar. Version 5.0 defines agentic AI for the first time. A single human-in-the-loop checkpoint won't cover systems that act across multiple steps on their own, and rules on access and boundaries are likely next.
  • Every model is in scope, old or new. GLMs that have powered pricing and underwriting for decades now sit in the same governance conversation as machine learning. Regulators are grading the governance wrapped around the model.
  • The timeline is moving fast. Twelve states have used this guidance since March. Version 6.0 is in a shorter comment window, and Version 7.0 goes to the NAIC Fall National Meeting in November, where adoption would make it a standard resource for every state.
  • Early movers set the bar. Speed and containment won't satisfy a regulator. Before asking what your AI can automate, ask whether you can prove what it did, on demand, in writing.

See how Notch can help you scale

We don’t win until your operation runs without us.

General insights
Return purchase
Policy name
Policy guidelines

AUTONOMOUS ORGANIZATION
Autonomous AI for operations leaders ready to turn complexity into advantage.

Deployed in weeks. Autonomous in months. Compounding for years.

Deliver better outcomes across every metric that matters
Get more done across every channel, system, and workflow.
Decouple revenue growth from operational cost.
Every action governed, traceable, and audit-ready.