TwinEthosRequest access

Standard or framework

NAIC AI Model Bulletin

National Association of Insurance Commissioners / state Departments of Insurance · United States (federal) (US) · 3 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: content.naic.org.

Standard / soft law

Insurers adopting the NAIC model guidance should maintain an AIS Program and AI-use notice

NAIC Model Bulletin, AIS Program Guidelines 1.1-1.9 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

The NAIC AI Model Bulletin recommends that insurers using AI systems that make or support regulated insurance decisions maintain a written AI Systems (AIS) Program covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and accountable leadership, and provide notice to impacted consumers that AI systems are in use. Detect an insurer AI decision path with no AIS Program artifact or consumer AI-use notice. State adoption and enforcement require separate primary-source evidence.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision, consequential decision
  • Sectors: insurance
  • Insurers considering or adopting NAIC Model Bulletin guidance. The bulletin itself is model guidance; a state-specific finding requires a primary-source adoption record and enforcement basis in a jurisdiction variant.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.

In the code path that calls a model for underwriting, rating, premium quoting, or claims decisions, send or render a consumer notice that AI systems are used (in the quote flow, claim acknowledgement, or decision letter) and record that it was delivered. The model is an entry in the insurer's written AIS Program, covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and an accountable leader, with an owner; keep the inventory entry or a pointer to it in the repository so each decision path is traceable to its program record.

Where it goes: 9 AI output handling, 14 user-facing text, 12 repository artifacts.

Example (Python + OpenAI SDK), before:

resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision)

After:

AI_USE_NOTICE = ('An AI system helped evaluate your claim. '
                 'You can ask us how it was used and request review by a claims adjuster.')
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision, ais_program_ref='AIS-012')
send_ai_notice(claimant, text=AI_USE_NOTICE)

Control: Insurer AI decision system without a written AIS Program / consumer notice. The same guard addresses 1 item. Engineering guidance, not legal advice.

Rule id naic-ai-bulletin.ais-program · review status: primary source derived

Standard / soft law

Insurers adopting the NAIC model guidance should validate and bias-test AI and predictive models

NAIC Model Bulletin, Governance 2.4 + Risk Management 3.4 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

The NAIC AI Model Bulletin recommends processes to detect and address errors, performance issues, outliers, and unfair discrimination in predictive models, and to validate, test, and retest AI outputs including data suitability and model drift. Detect an insurance AI or predictive-model decision path with no documented validation or bias and unfair-discrimination testing. State adoption and enforcement require separate primary-source evidence.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision
  • Sectors: insurance
  • Insurers considering or adopting NAIC Model Bulletin guidance. The bulletin itself is model guidance; a state-specific finding requires a primary-source adoption record and enforcement basis in a jurisdiction variant.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.

A validation stage that runs whenever a decision model is trained, fine-tuned, or retrained (the same module or pipeline step as fit(), Trainer, xgb.train, or fine_tuning.jobs.create) and again on a recurring schedule against recent decisions: accuracy and error rates per group, selection rates and disparity metrics (fairlearn MetricFrame, demographic_parity_difference, AIF360 disparate impact), and drift. Results go to a versioned validation report alongside a datasheet or data card for the training data, and a threshold gate blocks promotion of a model version whose metrics regress until a named owner reviews and records a decision. The validation cadence and owner are written in the model's validation record.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.

What this provision adds:

  • Cover errors, performance issues, outliers, unfair discrimination, data suitability, and model drift, and retest AI outputs over time.

Example (scikit-learn + fairlearn), before:

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
joblib.dump(clf, 'models/credit_v4.joblib')

After:

from fairlearn.metrics import MetricFrame, selection_rate, demographic_parity_difference
from sklearn.metrics import accuracy_score

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
y_pred = clf.predict(X_test)
mf = MetricFrame(metrics={'accuracy': accuracy_score, 'selection_rate': selection_rate},
                 y_true=y_test, y_pred=y_pred, sensitive_features=A_test)
dpd = demographic_parity_difference(y_test, y_pred, sensitive_features=A_test)
write_validation_report('credit_v4', mf.by_group, dpd)
if dpd > MAX_DPD:
    raise SystemExit('bias gate failed: owner review required before release')
joblib.dump(clf, 'models/credit_v4.joblib')

Control: AI decision system without regular accuracy/bias validation. The same guard addresses 4 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id naic-ai-bulletin.model-validation-bias-testing · review status: primary source derived

Standard / soft law

Insurers adopting the NAIC model guidance should oversee third-party AI systems

NAIC Model Bulletin, Third-Party AI Systems and Data 4.1-4.3 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

The NAIC AI Model Bulletin recommends that insurers relying on third-party data or AI systems conduct due diligence, use appropriate audit-right and regulator-cooperation contract terms, and ensure third-party systems meet the legal standards imposed on the insurer. Detect an insurance AI decision path using third-party models or data with no vendor due-diligence or oversight artifact. State adoption and enforcement require separate primary-source evidence.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision
  • Sectors: insurance
  • Insurers considering or adopting NAIC Model Bulletin guidance. The bulletin itself is model guidance; a state-specific finding requires a primary-source adoption record and enforcement basis in a jurisdiction variant.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.

An AI bill of materials in the repository (aibom.yaml or a third-party AI component registry) lists each component: publisher and source, pinned version or digest, license, a link to the reviewed model or system card or the vendor due-diligence record, the approving owner, and a re-review date. The code matches it: AI SDK and agent-framework dependencies pinned exactly with a committed lockfile, MCP servers launched from pinned versions (pkg@1.2.3, uvx pkg==1.2.3) or vendored, and skills or plugins taken only from vetted sources. A CI step fails when a dependency, model id, or tool server appears that the inventory does not list, and updates trigger re-review.

Where it goes: 12 repository artifacts, 5 dependencies, 11 CI/CD pipeline, 15 agent action surface.

What this provision adds:

  • The vendor oversight record covers due diligence, audit-right and regulator-cooperation contract terms, and whether the third-party system meets the legal standards imposed on the insurer.

Example (requirements.txt), before:

openai>=1.0
anthropic
langchain

After:

openai==1.109.1
anthropic==0.69.0
langchain==0.3.27
# installed in CI with: pip install --require-hashes -r requirements.lock

Control: GenAI with untracked third-party components (value chain). The same guard addresses 3 items. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

Rule id naic-ai-bulletin.third-party-ai-oversight · review status: primary source derived