Your insurer is now being asked the same questions about its AI that it is about to ask you about yours.
The regulator got there first
In December 2023, the National Association of Insurance Commissioners adopted a model bulletin on how insurers use AI.[1] It tells an insurer to keep a written program for the responsible use of AI systems that make or support decisions about regulated insurance practices. Senior management owns that program. It covers every stage of an AI system's life, from design and validation through monitoring and retirement. It also covers AI the insurer buys from a vendor, not only what it builds itself.[1] The bulletin names the NIST AI Risk Management Framework as one standard for an insurer to build the program on.[1][6]
A model bulletin has no force until a state adopts it. By the NAIC's own count, 24 states and the District of Columbia had adopted it as of April 1, 2026. California, Colorado, New York, and Texas have their own AI rules for insurers instead.[2]
You can see the result in who buys AI governance software. Monitaur sells a platform for governing AI models, and the customer logos on its own homepage include Progressive, Unum, and Clearcover Insurance.[5] I name Monitaur as one example of a category, not as a recommendation. The point is that carriers now pay for documented model inventories, validation records, and oversight trails because a regulator can ask to see them.
Why that reaches you at renewal
Here is my read, and it is an inference rather than anything a carrier has published. An underwriter whose own company keeps an AI program for its examiner knows exactly what a good one looks like. That same underwriter now has to price a business whose AI can hurt someone, and there is almost no loss history to price it from. The file YOU can hand over is the most useful evidence they have.
The policy language is moving at the same time, in both directions. Verisk, which drafts standard policy forms used across the industry, released three optional generative AI exclusions for general liability coverage with a January 2026 edition date. One of them, CG 40 47, removes bodily injury, property damage, and personal and advertising injury coverage arising out of generative AI.[3] On the other side, Coalition added an affirmative AI endorsement to its cyber policies in March 2024. Among other things, it extends funds transfer fraud coverage to fraudulent instructions sent through deepfakes.[4] One carrier can take AI risk out of your policy while another writes it in. What decides which way your renewal goes is what you can show.
What to have ready
The NAIC bulletin makes insurers account for vendor AI and puts ownership at the leadership level, so expect the same questions to come to you.[1] Here is what the file looks like at each size of business.
In your renewal file
SMB minimum
Mid-Market expectation
A spreadsheet of every AI tool you use, including those inside vendor software, and what each one touches
A maintained register with owner, vendor and data per system
The owner or ops lead, named in writing
An executive owner who reports to leadership
Testing and monitoring records
A dated note per tool: how you checked it before relying on it
Scheduled validation and monitoring logs per system
One page against the NIST AI RMF's four functions
A documented control-by-control mapping
Your current policy wording[3] Your general liability and cyber wording, read for AI exclusions before the renewal conversation
A broker review of every line for AI exclusions and AI grants
The full version of that file, nine documents and the underwriter concern behind each one, is in The Underwriter's File on the AI Liability Insurance Guide.[7]
Building the list is usually the easy part. Harder is knowing whether what you have will satisfy an underwriter or examiner. That is the work iSinghLabs does: an independent read of how your AI is governed, scored against the same controls regulators now expect of insurers.
SMB
Not sure where to start?
Thirty minutes is enough to see which of the five you already have and which one to build first.
Book a 30-minute call
Mid-Market
Have the file, need it to hold up?
We check your file against what underwriters and examiners look for and tell you what to fix before renewal.
AI Readiness Assessment
Works Cited
7 sources5 primaryChecked September 27, 2026
- 01
National Association of Insurance Commissioners
NAIC Model Bulletin: Use of Artificial Intelligence Systems by InsurersThe requirements described above come from sections 1.3, 1.5, 1.7 and 1.8.
- 02
- 03
Nancy Germond, Independent Insurance Agents & Brokers of America
Verisk to Roll Out New General Liability Exclusions for Generative AI ExposuresCited because Verisk's own form text is licensed and not public.
- 04
- 05
Monitaur
Homepage, customer logosOne example of a category, not a recommendation.
- 06
- 07
Joel R. Singh, AI Liability Insurance Guide
The Underwriter's FileOur own work, listed here so every source we control is marked as ours.