Around the Track: NAIC’s Technology Regulation Work So Far in 2026
The National Association of Insurance Commissioners (NAIC) Innovation, Cybersecurity, and Technology (H) Committee’s working groups continue training for their regulatory relay, with each group carrying the baton on its own charge while keeping pace with the committee’s broader race to coordinate NAIC efforts regarding innovation, cybersecurity, privacy, and technology.
1. Big Data & Artificial Intelligence (H) Working Group
The Big Data & Artificial Intelligence (H) Working Group maintained its stride in “enabl[ing] regulators to identify and assess AI systems' related risks on an on-going basis with a scope that considers both financial and consumer risks evolving specifically from company's use of AI systems to the extent such risks can be parsed from the comprehensive structure.” Together with 12 states, the working group is piloting the Risk Evaluation Supplement 4.0 (formerly the AI Systems Evaluation Tool).
The pilot is expected to run through September, with each pilot state gathering feedback from participating companies (including through a centralized survey) by the end of that month. The working group expects the next trial to be version 5.0 of the supplement, with two further handoffs for public exposure, and the final lap at the NAIC Fall National Meeting, where the tool would be adopted.
2. Third-Party Data & Models (H) Working Group
The Third-Party Data & Models (H) Working Group got off the block by exposing its third-party regulatory framework for property and casualty pricing and underwriting on July 8. The draft:
- Encourages third-party data and model vendors to register through a shared multistate registry hosted by the NAIC.
- Preserves each state’s existing rate, underwriting, and data/model filing requirements for third-party data and models.
- Requires vendors to annually attest through the multistate registry, via a senior leader, that their governance programs are effective and legally compliant.
- Requires vendors to notify the registry of material changes to, or decommissioning of,
a dataset or model. - Preserves insurers’ full accountability for their own compliance obligations regardless of third-party involvement.
On August 12, the working group met to discuss the draft framework. Commenters generally agreed on a core play — insurers remain ultimately responsible for how vendor tools are used. Some commenters emphasized that vendors need protection for proprietary information and more tailored annual attestation obligations. Further, Nevada regulators drew an important boundary line — maintaining that a model's mathematics, weighting, and methodologies warrant confidential treatment but that consumers should be able to learn when a third-party model affects them, including the insurer’s use of the vendor and what consumer data was used, to be able to correct any errors. A smaller team will evaluate the comments and revise the framework for possible adoption at the NAIC Fall National Meeting.
3. Privacy Protections (H) Working Group
The Privacy Protections (H) Working Group and multiple teams have been maintaining pace in proposing revisions to the Privacy of Consumer Financial and Health Information Regulation (Model #672) article by article after the NAIC scrapped the game plan to create a new Insurance Consumer Privacy Protection Model Law (Model #674). At long last, the working group has rounded the track and sent out its long-awaited exposure draft for a revised Model #672.
At the final heat on August 13, the working group heard comments from interested parties on the exposure draft. The exposure draft, however, may not yet have caught its stride as commenters questioned how to add clear guidance, ensure meaningful consumer rights, align with existing privacy regimes, and avoid creating fraud prevention gaps and imposing disproportionate burdens for smaller licensees. Comments, with specific alternative language, are racing to the finish line on September 22, after which the working group will develop its game plan for next steps.
4. Cybersecurity (H) Working Group
The Cybersecurity (H) Working Group wrapped up its sprint to receive comments on its exposure draft of a Cybersecurity Event Response Coordination Framework by July 24. The working group is racing to develop its Cybersecurity Event Notification Portal project, but the NAIC’s June cybersecurity incident has refreshed focus on an old hurdle: ensuring the security of the sensitive information that insurers would enter into the portal. At the working group’s August 14 meeting, Chair Michael Yaworsky, Florida's Insurance Commissioner, requested that, before the portal’s race continues to the executive committee, a clear and easy-to-read document be created to help everyone understand the security precautions
The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.