Alston & Bird·INSURANCE / REINSURANCE

NAIC Signals Shift to AI, Data, and Tech Examinations

US insurance regulators are moving from principles-based guidance to concrete supervisory tools and examination-readiness efforts for insurer governance of AI, third-party data, cybersecurity, and privacy.

The US National Association of Insurance Commissioners (NAIC) is signaling a significant shift from principles-based guidance to direct supervisory tools and examinations for technology governance. Recent initiatives show regulators focusing on how insurers' controls for AI, third-party data, and cybersecurity work in practice. Insurers can no longer just maintain policies; they must be prepared to produce evidence of effective governance.

Sophisticated counsel should note that this shift heightens compliance and operational risk. Regulators are now piloting an AI Risk Evaluation Supplement for use in examinations and developing a regulatory framework for third-party data and models used in underwriting. Other proposals include a centralized portal for cybersecurity event reporting and a comprehensive modernization of consumer privacy rules. These initiatives underscore that insurers retain full accountability for the technologies they deploy, including those from third-party vendors. Firms should advise insurance clients to review their technology governance programs to ensure they can withstand this new level of scrutiny, with key proposals potentially advancing at the NAIC's Fall National Meeting.

naicinsurance-regulationartificial-intelligenceinsurtechcyber-securitydata-privacyvendor-management
Read the original firm alert → Wednesday, September 23, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.