By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Holistic AIPublished October 30, 2025

TL;DR: U.S. insurance regulators are moving AI governance from guidance to operational expectation, with the NAIC Model Bulletin pressing insurers to inventory AI systems, formalise oversight, and manage third-party risk across the lifecycle, according to Holistic AI. The practical shift is less about model novelty and more about provable accountability, traceability, and control.


At a glance

What this is: This is an analysis of how the NAIC Model Bulletin is shaping AI governance expectations for insurers, especially around inventory, oversight, and lifecycle controls.

Why it matters: It matters because insurance teams now need defensible governance for AI systems that influence underwriting, claims, and third-party decisioning, while aligning AI oversight with broader identity and access controls.

👉 Read Holistic AI's AI governance analysis for U.S. insurance regulators


Context

AI governance in insurance is no longer just a policy discussion. Regulators are increasingly treating AI systems as part of the operational control environment, which means insurers need to prove where AI is used, who owns it, and how it is monitored across its lifecycle.

That matters for identity and access governance because many insurance AI workflows depend on human approvals, service accounts, vendor integrations, and data pipelines. If those inputs are not inventoried and controlled, the organisation cannot reliably govern the decisions the system produces.


Key questions

Q: How should insurers govern AI agents that access policy and claims data?

A: Insurers should govern AI agents as non-human identities with explicit scope, short-lived permissions, and auditable action trails. If an agent can retrieve policy data or trigger downstream work, it needs lifecycle control, transaction-level limits, and separate accountability from the human users it supports. Treat the agent as an identity class, not a hidden automation layer.

Q: Why do AI systems in insurance need lifecycle governance rather than one-time approval?

A: Because AI risk changes after deployment. Data changes, model behaviour drifts, owners move, and vendors update their services, so a single approval cannot prove ongoing control. Lifecycle governance gives insurers a way to show continuous oversight, trace decisions back to accountable owners, and respond to regulatory inquiries with evidence.

Q: What do insurers get wrong about third-party AI risk?

A: They often focus on procurement checks and forget the ongoing governance dependency. Once a vendor AI system influences regulated decisions, the insurer still needs visibility into data use, audit cooperation, access boundaries, and change management. Without that, the organisation inherits regulatory and operational risk it cannot fully observe.

Q: Who is accountable when AI use affects cyber insurance coverage?

A: Accountability usually sits with the security, risk, legal, and business owners who approve how AI is used and what data it can touch. Insurers are looking for documented oversight and defined use cases, not informal adoption. If AI is poorly governed, the organisation may face exclusions or tougher renewal terms.


Technical breakdown

How AI system inventories support regulator-ready governance

An AI inventory is the basic control layer that tells an organisation which systems are making or influencing decisions, who owns them, what data they use, and whether they are first-party or third-party. In regulated settings, the inventory becomes the bridge between model governance, operational accountability, and evidence for auditors. Without it, insurers cannot trace risk, prove testing coverage, or show that oversight is consistent across business units and vendors.

Practical implication: create a living AI inventory that ties each system to a business owner, data source, and governance status.

Why lifecycle controls matter more than deployment-time checks

AI governance fails when it is treated as a one-time approval exercise. The article points to oversight across design, training, deployment, monitoring, and retirement, which reflects the reality that risk changes as models drift, data changes, or business use expands. For insurers, lifecycle control also means the governance model must track changes to access, datasets, and third-party dependencies, not only model performance.

Practical implication: extend approvals, testing, and review evidence to the full AI lifecycle, including retirement and offboarding.

Third-party AI systems create hidden governance dependencies

When insurers adopt external AI tools or datasets, they inherit governance obligations they do not fully control. That creates a familiar identity pattern: the organisation relies on delegated access, opaque processing, and contract terms to constrain behaviour. The risk is not only model error but also weak traceability over data use, audit cooperation, and accountability when the external system influences regulated decisions.

Practical implication: require third-party AI due diligence, contractual audit rights, and documented data-use boundaries before adoption.


Threat narrative

Attacker objective: The objective is not always theft in the classic sense, but ungoverned decision influence that creates regulatory exposure, consumer harm, and loss of accountability.

  1. Entry occurs when insurers adopt AI systems through direct build, procurement, or embedded vendor tooling without a complete inventory of where those systems sit in the business.
  2. Escalation happens when the system is allowed to influence underwriting, claims, or customer decisions without lifecycle controls that track drift, data change, or ownership transfer.
  3. Impact follows when the organisation cannot prove fairness, accountability, or regulatory compliance for decisions that affect consumers and conduct risk.

NHI Mgmt Group analysis

AI governance in insurance is becoming a control problem, not a policy document problem. The NAIC direction signals that regulators expect insurers to evidence ownership, oversight, and lifecycle control rather than simply publish principles. That changes the governance burden from statements of intent to demonstrable operating controls, which is the point at which auditability becomes central. Practitioners should treat AI governance as a control framework with evidence, not a communications exercise.

The real failure mode is shadow AI decisioning inside otherwise mature insurance workflows. Many insurers already govern underwriting and claims processes, but AI tools can be embedded in vendor platforms, analytics layers, and workflow automation without clear visibility. That creates governance debt because the organisation may know the business process but not the AI system making part of the decision. Practitioners should insist on inventories that expose hidden AI dependencies before they become regulatory gaps.

AI oversight in regulated industries now intersects directly with identity governance. AI systems do not operate alone. They depend on human approvers, service accounts, data pipelines, and third-party access paths, which means IAM and lifecycle controls are part of AI governance whether teams model them that way or not. If those access paths are not owned and reviewed, the organisation cannot credibly claim control over AI behaviour. Practitioners should map AI governance to the identity plane as part of compliance design.

Third-party AI oversight is becoming a contract and lifecycle issue, not just a vendor-risk issue. The bulletin’s emphasis on due diligence and cooperation with regulatory inquiries reflects a wider market shift toward enforceable accountability for external AI systems. That means procurement, legal, GRC, and identity teams need a shared view of who can change data, model behaviour, or access audit evidence. Practitioners should treat vendor AI as a governed dependency, not a black box.

Named concept: AI governance debt. This is the accumulation of undocumented systems, weak ownership, and incomplete lifecycle controls that makes AI harder to assure over time. In insurance, governance debt shows up when the business can describe the use case but cannot prove monitoring, testing, or accountability. Practitioners should reduce it by linking AI inventory, access governance, and regulatory evidence in one operating model.

What this signals

Insurance AI programmes are moving into the same governance pattern seen in identity security: inventory first, then ownership, then evidence. The teams that can connect AI usage, access paths, and regulatory controls will be better placed to respond when regulators ask who approved what, when, and on what data.

AI governance debt: once undocumented AI systems and access paths accumulate, compliance becomes an evidentiary problem rather than a policy problem. That should push insurers to align governance with identity review, procurement gates, and operational monitoring before the control gap becomes visible in an exam or incident.


For practitioners

  • Build a complete AI inventory Record every AI system in use across underwriting, claims, customer service, analytics, and third-party platforms. Include owner, purpose, data sources, approval status, and whether the system influences regulated decisions.
  • Map governance to the AI lifecycle Assign controls at design, training, deployment, monitoring, and retirement so that drift, ownership change, and decommissioning are all covered by evidence.
  • Tie AI oversight to identity controls Review the human approvers, service accounts, and vendor access paths that let AI systems operate. Use access review and least privilege to reduce hidden decision pathways.
  • Document third-party AI due diligence Require audit rights, data-use boundaries, incident cooperation terms, and validation evidence before external AI tools influence insurance outcomes.

Key takeaways

  • AI governance in insurance is shifting from principles to provable control evidence.
  • The biggest risk is hidden AI decisioning that sits outside the organisation’s inventory and ownership model.
  • Insurers need lifecycle controls and identity governance together if they want defensible compliance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article is about governance accountability for regulated AI use.
NIST AI 600-1The bulletin aligns with GenAI governance and lifecycle assurance needs.
GDPRArt.22Insurance AI can affect individuals through automated decisioning and profiling.
NIST CSF 2.0GV.RM-01The topic is a governance and risk management problem across the AI lifecycle.
ISO/IEC 27001:2022A.5.15Access control matters because AI systems depend on human and service account access.

Define AI ownership, oversight, and evidence collection under GOVERN before scaling insurance use cases.


Key terms

  • AIS Program: A written artificial intelligence governance program that defines how an organisation approves, monitors, and controls AI use. In regulated environments, it binds ownership, testing, third-party oversight, and evidence so the business can show accountability rather than simply state it.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Model Drift: Model drift is the gradual change in a model’s behaviour or performance after deployment. It happens when the operating environment, user patterns, or inputs no longer match the conditions used to validate the system. Drift matters because a model can appear functional while no longer meeting approved standards.

What's in the full article

Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:

  • The article expands the NAIC Model Bulletin expectations into implementation-oriented AI governance steps for insurers.
  • It outlines how insurers should inventory AI systems across business units and third-party tools.
  • It summarises state-level adoption signals and the regulatory direction of travel.
  • It connects governance expectations to practical compliance readiness actions.

👉 The full Holistic AI post covers the NAIC bulletin, state adoption, and practical insurer actions in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps security and identity practitioners build the control discipline that regulated AI programmes also depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org