Insurers face AI oversight squeeze as states tighten rules

The gist
With states racing to tighten the screws on AI oversight, insurers now face a regulatory minefield demanding unprecedented transparency, accountability, and control over both in-house and third-party AI systems.
What to know
- By early 2026, 24 states plus D.C. require insurers to implement written AI governance, comply with insurance law, and notify consumers when AI shapes decisions.
- Florida ups the ante by forcing insurers to disclose how their AI works and naming licensed professionals liable for AI-driven outcomes—no more blaming the algorithm.
- Over 90% of AI-related risks lurk in legacy policies, while insurers struggle to track third-party AI actions and face mounting pressure to expose the black box.
State Patchwork, Global Pressure
Insurers must navigate a maze of state-by-state AI rules while global frameworks like the EU AI Act push for enterprise-wide transparency, forcing companies to rethink how they document and control AI decisions.
The NAIC continues to anchor AI governance in the insurance sector within the framework of state-based regulation, as reaffirmed at the 2026 Summer National Meeting in Columbus. This approach, rooted in the McCarran-Ferguson Act of 1945, allows states to tailor AI oversight to local market conditions but also creates a complex regulatory patchwork for national insurers. By early 2026, 24 states plus the District of Columbia had adopted the NAIC's model bulletin requiring insurers to implement written AI governance programs, comply with existing insurance laws, and notify consumers when AI systems influence decisions, reflecting a growing consensus on transparency and accountability in AI use.
Transparency and human accountability have emerged as non-negotiable pillars in AI governance, particularly exemplified by Florida’s regulatory stance. Rather than banning AI, Florida mandates insurers to clearly disclose how their AI models function and holds named, licensed professionals legally responsible for AI-driven outcomes, emphasizing that accountability cannot be delegated to software. This insistence on explainability is underscored by regulatory friction arising when carriers fail to articulate the role of AI in rate filings, highlighting the critical need for insurers to document and communicate AI’s impact on underwriting and pricing decisions.
Efforts to enhance AI governance extend beyond U.S. borders, with the EU AI Act influencing American insurers to develop a 'reusable evidence spine'—a comprehensive operational record linking AI decisions to the people, systems, content, and controls involved. This holistic approach moves past mere model documentation to integrate enterprise content, permissions, metadata, and human review, ensuring transparency and traceability. By embedding AI tools within existing content repositories and workflows while preserving role-based access and operational controls, insurers can reduce compliance risks and better manage the complexity of AI oversight.
State-level mandates reveal a patchwork of consumer protections in AI-driven insurance, with significant variation in rights such as appealing automated decisions or requiring human review. For example, Maryland’s law prohibits insurers from mandating telematics participation as a condition of coverage, safeguarding consumer choice amid increasing AI integration. Meanwhile, regulators are piloting evaluation tools across 12 states to scrutinize insurers’ AI governance, data practices, and higher-risk models, signaling a proactive stance toward risk management and oversight in an evolving technological landscape.
Human Accountability Takes Center Stage
With only a fraction of staff trained on AI policies, regulators now demand that real people—not algorithms—stand behind every AI-driven insurance decision, making explainability and oversight non-negotiable.
Despite AI adoption in businesses soaring from 13% to 53%, a glaring governance gap persists, with only 8% of employees having clear KPIs to measure AI benefits and a quarter lacking any AI policy training. Jack Jorgensen stresses that formal policies, approval processes, and continuous training are vital to bridge this gap, ensuring organizations maintain operational accountability and transparency in AI deployment.
The insurance industry faces mounting pressure to dismantle the 'black box' nature of AI models, as Florida regulator Mike Yaworsky underscores the critical need for insurers to provide plain-language explanations of AI-driven pricing and underwriting decisions. This regulatory stance prioritizes human accountability, holding named, licensed professionals legally responsible for AI outcomes rather than the software itself, thereby reinforcing trust and operational transparency.
Transparency about AI methodologies, limitations, and responsibilities throughout the data lifecycle is emerging as a cornerstone of responsible AI innovation, according to Arundati Dandapani. She emphasizes that human judgment, ongoing oversight, and continual reassessment of potential harms and value are indispensable to building trust and ensuring explainable, monitored AI decisions in line with evolving global governance expectations.
Operational accountability extends beyond transparency to include safeguarding traditional controls such as protecting personally identifiable information and defending against prompt injection attacks, which can manipulate AI outputs or access restricted data. Jack Jorgensen highlights these risks as critical vulnerabilities that organizations must address to uphold the integrity and trustworthiness of AI systems.
Third-Party AI: Hidden Hazards
Legacy policies and fragmented oversight leave insurers dangerously exposed to third-party AI risks, as new agentic threats outpace traditional controls and underwriters overestimate policyholder readiness.
Insurers face profound challenges in managing risks from AI deployed by third-party vendors due to limited visibility and fragmented data trails. As John Romano of Baker Tilly warns, insurers remain largely 'blind to vendor AI risks,' struggling to reconstruct AI agent actions across multiple disconnected systems that were never designed to provide cohesive operational records. This opacity hampers effective claims investigation and risk assessment, especially since regulators are beginning to demand enhanced oversight and traceability of AI versions, instructions, and data inputs involved in incidents.
The insurance industry’s current frameworks inadequately address the unique complexities introduced by AI agents, with over 90% of AI-related exposures hidden within 'silent coverage' embedded in legacy policies like cyber and D&O. This disconnect is compounded by underwriters’ overconfidence in policyholders’ AI governance—nearly half believe risks are well-managed, yet Deloitte’s January survey found only 20% of enterprises have mature autonomous agent governance. Consequently, there is a pressing need for better transparency, documentation, and specialized insurance products tailored to the agentic AI layer.
Third-party AI agents dramatically expand insurers’ attack surface through what security experts call a 'lethal trifecta': access to private data, untrusted inputs, and the ability to execute cross-system actions. This dynamic enables adversarial text inputs to trigger trusted actions without traditional code execution, as demonstrated by real-world vulnerabilities like the CVE against Microsoft 365 Copilot uncovered by AIM Security. Such inherent risks underscore the urgent necessity for insurers to develop novel oversight mechanisms and contractual frameworks that address these agentic security challenges.
To mitigate these risks, industry leaders advocate for streamlined regulatory approaches such as an 'express lane' oversight mechanism that enhances transparency and control over third-party AI deployments. Maintaining detailed operational records akin to practices in nuclear and cyber insurance could empower insurers to more accurately price AI risks and manage claims. As one analyst notes, an AI agent capable of producing its own operating record would be significantly more insurable, highlighting the critical role of comprehensive logging in evolving AI risk governance.

