Does the NAIC AI Bulletin Apply to AI Agents?
Try it live
Watch Agentshield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
Yes, the NAIC Model Bulletin applies to AI agents. It governs any AI system that makes or supports decisions related to regulated insurance practices, and an agent that triages a claim, prices a quote, or services a policy is doing exactly that. The bulletin was adopted in December 2023, before agentic AI was a common production pattern, so it never uses the word agent. But its scope is defined by what a system does to a regulated decision, not by the system's architecture, and on that test an agent is squarely inside.
As of the NAIC implementation map dated April 1, 2026, 24 states and the District of Columbia have adopted the bulletin. Four more, California, Colorado, New York, and Texas, regulate insurer use of AI through their own separate guidance. So more than half of US jurisdictions now have insurance-specific AI expectations in force, and none of them carve out agents.
What the bulletin actually expects
The core obligation is that insurers develop, implement, and maintain a written program, which the bulletin calls an AIS Program, for the responsible use of AI systems affecting regulated insurance practices. The program has to be proportionate to risk, scaled to how consequential the decision is, how much a person is involved, and how much the insurer relies on third-party data and models.
Read the language carefully, because it is easy to over-read. The bulletin says should, not shall, and it states plainly that its goal is not to prescribe specific practices or documentation. It is an expectations document. What makes it useful for engineering is Section 4, which lists what a regulator will ask to see. That list is effectively a controls checklist.
| What the bulletin expects | Why an agent raises the stakes |
|---|---|
| Inventories and descriptions of AI systems in use | Agents get built quickly and often go unregistered, so the inventory drifts unless it is observed |
| Constraints and controls on automation | An agent acts rather than just scoring, so the limits on what it may do without a person carry real weight |
| Protection of non-public information | An agent reads across records and can leak one insured's data into another interaction |
| Monitoring, auditing, and escalation protocols | Actions happen in real time, so after-the-fact review is not enough on its own |
| Third-party due diligence and audit rights | Much agent tooling is vendor supplied, and liability does not transfer to the vendor |
Does the bulletin require specific security controls?
No, and any vendor telling you it mandates a particular product is misreading it. The bulletin describes outcomes, not tools. It expects you to control access to non-public information, including unauthorized access to the models themselves, and to be able to document what your systems did. It leaves the how to you, and even nods at the NIST AI Risk Management Framework as an acceptable structure.
That freedom is a trap if you treat compliance as a writing project. The efficient path is to run the controls the agent needs for safety anyway, then let the documentation fall out of them. An agent scoped to the claim in front of it, with injection inspection on ingested documents, approval gates on payments, and an immutable trail, produces the inventory, the automation limits, the data protection, and the audit records the bulletin asks about, as a byproduct of operating.
What New York and Colorado add
If you write business in New York or Colorado, they set a higher bar than the model bulletin. New York DFS Circular Letter No. 7, issued July 2024, covers AI in underwriting and pricing and expects a three-step discrimination analysis plus testing before deployment, annually, and on any material change. Colorado Regulation 10-1-1 requires a governance framework with board oversight and an annual officer-signed report, extended in October 2025 to auto and health insurers using external consumer data, with compliance for those lines due July 1, 2026. Building that framework is ordinary AI agent governance work, just with a filing deadline attached.
One fact worth getting right, because it circulates wrong constantly: Colorado's quantitative bias-testing regulation for life underwriting was never adopted. It was drafted in 2023, drew actuarial objections over its methodology, and stalled, and the Division waived the quantitative testing requirement for both the 2024 and 2025 annual reports. The governance framework is in force. The quantitative testing mandate is not.
How to bring an insurance agent into compliance
Carriers that clear their own model risk review tend to follow the same order, because each step generates a document the reviewer wanted.
- Inventory the agents. List each one, the regulated decision it touches, the data it reads, and its owner. This answers the bulletin's question about systems in use, including the ones not yet in your program.
- Scope to the minimum book. A triage agent should reach the claim it is working, not the claims table, which is what per-agent tool permissions enforce at runtime.
- Inspect untrusted input. Claim narratives, broker submissions, and insured emails are attacker-controllable text. Check them for injection before the model acts.
- Gate consequential actions. Hold anything that moves money or changes coverage above your threshold for a licensed person.
- Test on cadence and export the trail. Before deployment, annually, and on material change, then hand examiners the record rather than the intent.
The same evidence-first pattern serves premium billing too, where an agent that chases overdue balances still needs scoping and a trail, much like any automated receivables workflow that touches customer accounts. For the full control-to-evidence mapping, see our AI agent security for insurance page, and AI agent audit requirements for what a defensible trail contains.
The bottom line
The NAIC bulletin applies to your agents whether or not you have mapped them, and in New York and Colorado the expectations are firmer. None of it prescribes a product, but all of it asks for evidence, and evidence is a lot easier to produce when it is a side effect of the controls that keep the agent safe, which is the case we make on AI compliance software for AI agents. Build the controls, and the compliance artifact writes itself.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put Agentshield in front of your own agents.
Keep reading