On August 13, 2026, the National Association of Insurance Commissioners (NAIC) announced the continuation of the AI Risk Evaluation Supplement pilot project — a document designed to unify the approach to auditing the use of artificial intelligence in insurance companies. The pilot will run until September, after which regulators plan to release an updated version of the document for public discussion. This event marks a key stage in forming unified oversight standards for AI in one of the most conservative sectors of the US economy.

Twelve States at the Forefront of Digital Oversight

The current pilot project involves regulators from 12 states: California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. It is important to note that the application of the document varies: some states have integrated it into scheduled audits, while others use it as a one-time questionnaire. This flexible approach allows regulators to adapt the tool to the specifics of the local market and the maturity of insurance companies in the region.

What Exactly Is Being Checked: From Model Registries to Consumer Impact

The current version of the Supplement requires insurers to provide a detailed description of AI application across several key areas. Companies must provide information on model governance systems, validation and testing procedures, and identify models with elevated risk. Special attention is paid to data sources, monitoring methods, and control over third-party AI solution providers. Additionally, regulators request data on the impact of algorithms on consumers and existing protective measures.

The Path to Version 7.0: From Public Discussions to a National Meeting

The pilot phase serves as the basis for developing version 5.0 of the document, which is planned for publication in September for a 30-day public discussion. This will be followed by another 14-day discussion period for version 6.0. The final version 7.0 will be considered at the NAIC's autumn national meeting. However, experts warn that the deadlines for completing audits in different states may vary, and the completion of all pilot audits by September 30 is not guaranteed.

New Requirements for ML System Development Teams

For teams developing machine learning in insurance, this means a significant increase in requirements for the evidence base. Regulators may now require up-to-date model registries, information on ownership and approvals, validation results, data provenance, monitoring history, and full documentation for third-party systems. This creates a need for stricter internal discipline and transparency in development processes.

Contradictory Data

Although the NAIC positions the Supplement as a tool for unifying approaches, in practice, there is inconsistency in its application. While some states include the document in mandatory scheduled audits, others use it only as a recommended questionnaire. This creates a risk of regulatory fragmentation: companies operating in multiple states may face different requirements, complicating their operations and increasing compliance costs.

Why This Matters for the Entire Industry

Although the Supplement remains a project within the framework of a pilot and public discussion, its August update demonstrates how a unified approach by US regulators to auditing AI in insurance may take shape. For the industry, this is a signal that the era of "wild" AI implementation is ending, to be replaced by an era of strict regulation, transparency, and accountability. Companies that can adapt to these requirements earlier than others will gain a competitive advantage in the face of growing regulatory pressure.