Twenty-four states plus the District of Columbia have adopted the NAIC's Model Bulletin on insurers' use of AI, requiring a written AI governance program, documented testing, bias assessment, and consumer notice before an algorithm touches underwriting or claims. AxiSentinel evaluates insurance AI against whichever state's adopted version actually applies.
The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It isn't self-executing, each state's insurance commissioner has to adopt it before it binds insurers licensed there. Twenty-four states already have, and more are expected as 2026 legislative sessions continue.
A bias-testing report is a point-in-time exhibit for one regulator. AxiSentinel is built for what happens between filings: continuous evidence that an underwriting or claims model still behaves the way its last test said it would.
Adoption is state-by-state, not federal. AxiSentinel tracks the growing list the same way it tracks every other state-law patchwork.
In force since February 1, 2024, the first state to bind insurers to the NAIC's governance, testing, and documentation requirements.
One of the largest insurance markets to adopt the Bulletin, in force since March 13, 2024.
Adopted December 9, 2024 and March 18, 2025 respectively, extending Bulletin coverage into two more major markets.
24 states total have adopted the Bulletin as of this writing, each through its own insurance department bulletin or regulation.
A federal push to preempt state AI law has not invalidated any state insurance bulletin as of this writing; the Bulletin's state-by-state adoption model remains the operative rule.
Classifies AI used for risk assessment and pricing in life and health insurance as high-risk (property/casualty insurance is not covered). Compliance deadline for standalone Annex III systems was pushed from 2 August 2026 to 2 December 2027 under the EU's Digital Omnibus simplification package.
Finalized 11 September 2025 by the Office of the Superintendent of Financial Institutions. Explicitly covers federally regulated life and P&C insurers, extending model-risk governance to AI/ML systems and third-party vendor models.
General-purpose AI risk-management frameworks that already apply to any underwriting or claims model an insurer deploys.
From a single underwriting model to a national book of business, AxiSentinel evaluates the software and evidence continuously, not just at filing time.
Nothing about AxiSentinel's core architecture changes for insurance. What changes is which RegDef packages are switched on and what telemetry the agents capture from an underwriting or claims system.
Agents capture underwriting and claims-model telemetry on the cadence you configure, always-on or scheduled, in full rather than sampled, and never limited to a quarterly cycle.
Every telemetry event evaluated against the applicable state's adopted bulletin text, per decision.
Every audit record is linked to the one before it in a signed, tamper-evident evidence chain, verifiable from the first event.
A compliance state change on one model or an entire book of business propagates network-wide as it happens.
Nothing becomes a compliance finding until a qualified auditor reviews and signs it.
AXI-Node agents deploy across underwriting, claims, and fraud-detection systems, with the .axibatch format available for carriers running fully on-prem policy systems.
Tracks human involvement in underwriting and claims decisions, feeding into AxiSentinel's oversight-gap scoring model.
The same agents generating compliance evidence watch for adversarial manipulation of pricing inputs, unauthorized model retraining, and undisclosed proxy variables before a re-certified release reaches production.
New state bulletin adoption, rule, or jurisdiction is added by encoding new RegDef packages. Deployed agents are never rebuilt.
Scoped to your organization during onboarding, not hard-coded into the platform.
A threshold breach becomes a flagged, timestamped, evidence-linked Provisional Alert, reviewed by a certified human auditor before anything counts as a finding.
The same architecture monitoring an underwriting model monitors a trading desk's model or a hospital's diagnostic AI. What changes is which RegDef packages are switched on.
24 states already require the governance program the NAIC Bulletin describes, and more are expected to adopt in 2026. AxiSentinel's evidence-chain architecture already generates continuous proof for regulated AI; insurance-specific evidence is a new RegDef surface on the same platform, not a new product.
Whether it's a single underwriting model or a national book of business across 24 adopting states, AxiSentinel evaluates it the same way it evaluates any AI system: on the cadence you configure, always-on or scheduled, with full evidence, and with a human signature before anything counts as a finding.