Skip to Content

Around the Track: NAIC’s Technology Regulation Work So Far in 2026

The National Association of Insurance Commissioners (NAIC) Innovation, Cybersecurity, and Technology (H) Committee’s working groups continue training for their regulatory relay, with each group carrying the baton on its own charge while keeping pace with the committee’s broader race to coordinate NAIC efforts regarding innovation, cybersecurity, privacy, and technology.

1. Big Data & Artificial Intelligence (H) Working Group

The Big Data & Artificial Intelligence (H) Working Group maintained its stride in “enabl[ing] regulators to identify and assess AI systems' related risks on an on-going basis with a scope that considers both financial and consumer risks evolving specifically from company's use of AI systems to the extent such risks can be parsed from the comprehensive structure.” Together with 12 states, the working group is piloting the Risk Evaluation Supplement 4.0 (formerly the AI Systems Evaluation Tool).

The pilot is expected to run through September, with each pilot state gathering feedback from participating companies (including through a centralized survey) by the end of that month. The working group expects the next trial to be version 5.0 of the supplement, with two further handoffs for public exposure, and the final lap at the NAIC Fall National Meeting, where the tool would be adopted.

2. Third-Party Data & Models (H) Working Group

The Third-Party Data & Models (H) Working Group got off the block by exposing its third-party regulatory framework for property and casualty pricing and underwriting on July 8. The draft:

  • Encourages third-party data and model vendors to register through a shared multistate registry hosted by the NAIC.
  • Preserves each state’s existing rate, underwriting, and data/model filing requirements for third-party data and models.
  • Requires vendors to annually attest through the multistate registry, via a senior leader, that their governance programs are effective and legally compliant.
  • Requires vendors to notify the registry of material changes to, or decommissioning of,
    a dataset or model.
  • Preserves insurers’ full accountability for their own compliance obligations regardless of third-party involvement.

On August 12, the working group met to discuss the draft framework. Commenters generally agreed on a core play — insurers remain ultimately responsible for how vendor tools are used. Some commenters emphasized that vendors need protection for proprietary information and more tailored annual attestation obligations. Further, Nevada regulators drew an important boundary line — maintaining that a model's mathematics, weighting, and methodologies warrant confidential treatment but that consumers should be able to learn when a third-party model affects them, including the insurer’s use of the vendor and what consumer data was used, to be able to correct any errors. A smaller team will evaluate the comments and revise the framework for possible adoption at the NAIC Fall National Meeting.

3. Privacy Protections (H) Working Group

The Privacy Protections (H) Working Group and multiple teams have been maintaining pace in proposing revisions to the Privacy of Consumer Financial and Health Information Regulation (Model #672) article by article after the NAIC scrapped the game plan to create a new Insurance Consumer Privacy Protection Model Law (Model #674). At long last, the working group has rounded the track and sent out its long-awaited exposure draft for a revised Model #672.

At the final heat on August 13, the working group heard comments from interested parties on the exposure draft. The exposure draft, however, may not yet have caught its stride as commenters questioned how to add clear guidance, ensure meaningful consumer rights, align with existing privacy regimes, and avoid creating fraud prevention gaps and imposing disproportionate burdens for smaller licensees. Comments, with specific alternative language, are racing to the finish line on September 22, after which the working group will develop its game plan for next steps.

4. Cybersecurity (H) Working Group

The Cybersecurity (H) Working Group wrapped up its sprint to receive comments on its exposure draft of a Cybersecurity Event Response Coordination Framework by July 24. The working group is racing to develop its Cybersecurity Event Notification Portal project, but the NAIC’s June cybersecurity incident has refreshed focus on an old hurdle: ensuring the security of the sensitive information that insurers would enter into the portal. At the working group’s August 14 meeting, Chair Michael Yaworsky, Florida's Insurance Commissioner, requested that, before the portal’s race continues to the executive committee, a clear and easy-to-read document be created to help everyone understand the security precautions

©2026 Carlton Fields, P.A. Carlton Fields practices law in California through Carlton Fields, LLP. Carlton Fields publications should not be construed as legal advice on any specific facts or circumstances. The contents are intended for general information and educational purposes only, and should not be relied on as if it were advice about a particular fact situation. The distribution of this publication is not intended to create, and receipt of it does not constitute, an attorney-client relationship with Carlton Fields. This publication may not be quoted or referred to in any other publication or proceeding without the prior written consent of the firm, to be given or withheld at our discretion. To request reprint permission for any of our publications, please use our Contact Us form via the link below. The views set forth herein are the personal views of the author and do not necessarily reflect those of the firm. This site may contain hypertext links to information created and maintained by other entities. Carlton Fields does not control or guarantee the accuracy or completeness of this outside information, nor is the inclusion of a link to be intended as an endorsement of those outside sites.

Disclaimer

The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.