Back to Briefs

Commentary

It's Time To Renew! What Will Your Insurer Ask About AI Governance?

Insurers now have to govern their own AI under a regulator's bulletin. That changes what they expect to see from you when your policy comes up for renewal.

iSinghLabs · September 27, 2026 · 5 min read

Your insurer is now being asked the same questions about its AI that it is about to ask you about yours.

The regulator got there first

In December 2023, the National Association of Insurance Commissioners adopted a model bulletin on how insurers use AI.[1] It tells an insurer to keep a written program for the responsible use of AI systems that make or support decisions about regulated insurance practices. Senior management owns that program. It covers every stage of an AI system's life, from design and validation through monitoring and retirement. It also covers AI the insurer buys from a vendor, not only what it builds itself.[1] The bulletin names the NIST AI Risk Management Framework as one standard for an insurer to build the program on.[1][6]

A model bulletin has no force until a state adopts it. By the NAIC's own count, 24 states and the District of Columbia had adopted it as of April 1, 2026. California, Colorado, New York, and Texas have their own AI rules for insurers instead.[2]

Insurers are buying the tools to comply

You can see the result in who buys AI governance software. Monitaur sells a platform for governing AI models, and the customer logos on its own homepage include Progressive, Unum, and Clearcover Insurance.[5] I name Monitaur as one example of a category, not as a recommendation. The point is that carriers now pay for documented model inventories, validation records, and oversight trails because a regulator can ask to see them.

Why that reaches you at renewal

Here is my read, and it is an inference rather than anything a carrier has published. An underwriter whose own company keeps an AI program for its examiner knows exactly what a good one looks like. That same underwriter now has to price a business whose AI can hurt someone, and there is almost no loss history to price it from. The file YOU can hand over is the most useful evidence they have.

The policy language is moving at the same time, in both directions. Verisk, which drafts standard policy forms used across the industry, released three optional generative AI exclusions for general liability coverage with a January 2026 edition date. One of them, CG 40 47, removes bodily injury, property damage, and personal and advertising injury coverage arising out of generative AI.[3] On the other side, Coalition added an affirmative AI endorsement to its cyber policies in March 2024. Among other things, it extends funds transfer fraud coverage to fraudulent instructions sent through deepfakes.[4] One carrier can take AI risk out of your policy while another writes it in. What decides which way your renewal goes is what you can show.

What to have ready

The NAIC bulletin makes insurers account for vendor AI and puts ownership at the leadership level, so expect the same questions to come to you.[1] Here is what the file looks like at each size of business.

In your renewal file
SMB minimum
Mid-Market expectation
AI system inventory[1]
A spreadsheet of every AI tool you use, including those inside vendor software, and what each one touches
A maintained register with owner, vendor and data per system
A named owner[1]
The owner or ops lead, named in writing
An executive owner who reports to leadership
Testing and monitoring records
A dated note per tool: how you checked it before relying on it
Scheduled validation and monitoring logs per system
Framework mapping[6]
One page against the NIST AI RMF's four functions
A documented control-by-control mapping
Your current policy wording[3]
Your general liability and cyber wording, read for AI exclusions before the renewal conversation
A broker review of every line for AI exclusions and AI grants

The full version of that file, nine documents and the underwriter concern behind each one, is in The Underwriter's File on the AI Liability Insurance Guide.[7]

Building the list is usually the easy part. Harder is knowing whether what you have will satisfy an underwriter or examiner. That is the work iSinghLabs does: an independent read of how your AI is governed, scored against the same controls regulators now expect of insurers.

SMB

Not sure where to start?

Thirty minutes is enough to see which of the five you already have and which one to build first.

Book a 30-minute call
Mid-Market

Have the file, need it to hold up?

We check your file against what underwriters and examiners look for and tell you what to fix before renewal.

AI Readiness Assessment

Works Cited

7 sources5 primaryChecked September 27, 2026
  1. 01
    National Association of Insurance Commissioners
    NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers
    Adopted December 4, 2023content.naic.orgRegulator↩ back to text

    The requirements described above come from sections 1.3, 1.5, 1.7 and 1.8.

  2. 02
    National Association of Insurance Commissioners
    Implementation of NAIC Model Bulletin: state adoption map
    Status as of April 1, 2026content.naic.orgRegulator↩ back to text
  3. 03
    Nancy Germond, Independent Insurance Agents & Brokers of America
    Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures
    October 21, 2025independentagent.comTrade association↩ back to text

    Cited because Verisk's own form text is licensed and not public.

  4. 04
  5. 05
    Monitaur
    Homepage, customer logos
    Accessed September 27, 2026monitaur.aiCompany, own site↩ back to text

    One example of a category, not a recommendation.

  6. 06
    National Institute of Standards and Technology
    Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
    January 26, 2023doi.orgStandards body↩ back to text
  7. 07
    Joel R. Singh, AI Liability Insurance Guide
    The Underwriter's File
    September 12, 2026aicoverageguide.comiSinghLabs↩ back to text

    Our own work, listed here so every source we control is marked as ours.