The AI your vendor runs is still your responsibility
For years, the rules for using AI in insurance read more like suggestions. That era is over.
The shift has been quiet, but it's real. AI governance in insurance has moved from published principles to active examination, and it's picking up speed toward 2027. Here's the part that catches a lot of carriers off guard: you are, in fact, accountable for how AI is used in your business, even when an outside vendor runs it. The responsibility doesn't transfer with the work.
That one idea changes how vendor diligence should feel. It's no longer a box your procurement team checks on the way to signing. It's the moment you decide what you'll be able to explain later, when someone asks.
In late 2023, the National Association of Insurance Commissioners (NAIC), the body that coordinates every state's insurance regulators, issued a Model Bulletin on the use of AI. Most states have now adopted it. Alongside it sits the NIST AI Risk Management Framework, from the federal standards agency, which has quietly become the shared language examiners use when they talk about AI: govern, map, measure, manage.
The calendar is the part worth circling. The NAIC is piloting a tool to evaluate how insurers use AI, with a formal exam version expected to follow. And in January 2027, new rules covering automated decisions take effect in Colorado and California. Sooner or later, a regulator will ask how one of your AI-assisted decisions was made, usually in a market-conduct exam, the review of how you actually treat policyholders. It's far cheaper to ask the hard questions before you sign than to hunt for the answers under exam pressure.
Where the risk actually lives
Introducing AI into an organization is never a single decision, and expanding it is even less so. Every deployment really sits in three layers:
- The model underneath: shared infrastructure, roughly the same, no matter who you buy from.
- Your data on top: where it lives, how long it's kept, who can delete it.
- The layer in between: where the system is actually assembled, what the AI can see, what it can do, and when a person steps in.
That middle layer is where most of the real risk lives, and where most of your attention should go. One question gets to the heart of it: what actually stops the AI from doing something it shouldn't? "It was told not to" isn't a control. It's a request the model can ignore. A real safeguard is built into the software itself, so the AI can't step outside its task even when it misbehaves. Once you know to listen for that difference, you'll hear it in any answer you get.
The questions worth asking
The full diligence comes down to twelve questions, across four themes: the models and the data, control and judgment, the record and the disclosure, and resilience and the road ahead. The questions we’ve developed are grounded in our experience, and we hope as you think through them, they serve as a jumping-off point as you tailor your search based on your own experience as well.
Could you reconstruct any single decision, in full, two years from now?
Most AI gets judged on how it performs in a demo, but the moment that counts comes later, when a regulator expects a record: what came in, which version of the AI handled it, where a person stepped in, and how it ended. "We keep logs" isn't the same as a record you could hand to an examiner.
When the answer is a roadmap
These standards are young, and almost no one has every box checked yet. So in most reviews, at least one answer will be a plan rather than a finished control, and that's fine. A clear gap with a date attached is actually a good sign. It means the program knows exactly where it stands, and it gives both sides something to build against.
Before you sign
We put AI in production for carriers and TPAs, which means we're usually the ones on the answering side of these reviews. So we wrote down the twelve questions we get asked most, and the ones we wish everyone asked, along with what a good answer actually sounds like. It's not a scorecard. It's a place to start, and it leaves room for the questions only your business knows to ask.