Standard / soft law
Insurers adopting the NAIC model guidance should maintain an AIS Program and AI-use notice
The NAIC AI Model Bulletin recommends that insurers using AI systems that make or support regulated insurance decisions maintain a written AI Systems (AIS) Program covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and accountable leadership, and provide notice to impacted consumers that AI systems are in use. Detect an insurer AI decision path with no AIS Program artifact or consumer AI-use notice. State adoption and enforcement require separate primary-source evidence.
Who it applies to
- Duty falls on: deployer
- Systems covered: automated decision, consequential decision
- Sectors: insurance
- Insurers considering or adopting NAIC Model Bulletin guidance. The bulletin itself is model guidance; a state-specific finding requires a primary-source adoption record and enforcement basis in a jurisdiction variant.
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.
In the code path that calls a model for underwriting, rating, premium quoting, or claims decisions, send or render a consumer notice that AI systems are used (in the quote flow, claim acknowledgement, or decision letter) and record that it was delivered. The model is an entry in the insurer's written AIS Program, covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and an accountable leader, with an owner; keep the inventory entry or a pointer to it in the repository so each decision path is traceable to its program record.
Where it goes: 9 AI output handling, 14 user-facing text, 12 repository artifacts.
Example (Python + OpenAI SDK), before:
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision)After:
AI_USE_NOTICE = ('An AI system helped evaluate your claim. '
'You can ask us how it was used and request review by a claims adjuster.')
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision, ais_program_ref='AIS-012')
send_ai_notice(claimant, text=AI_USE_NOTICE)Control: Insurer AI decision system without a written AIS Program / consumer notice. The same guard addresses 1 item. Engineering guidance, not legal advice.
Rule id naic-ai-bulletin.ais-program · review status: primary source derived