The exam-ready toolkit for everyone building, operating, and answering for AI in insurance

The exam is coming for your AI. Be ready to answer with your evidence.

If you build, run, or answer for AI anywhere in insurance, an exam is coming for it. State examiners now work from a common set of questions, the NAIC AI Risk Evaluation Supplement, and the answers have to be yours to produce. The reach is wide: it is addressed to carriers, but Exhibit B, question 4 asks them to describe the AI their MGAs, programs, and vendors run. So whether you build the model, sell it, or answer for it, the same test applies: can you prove it, with evidence you own and can export? Renting the AI is fine. This toolkit is the working answer: a scoring methodology, the engineering build behind it, a state-by-state tracker, and a changelog that moves when the regulation moves.

Builders and operators

Where you put the probabilistic components decides your tier, your cost, and your exam. The map and the controls are for you.

Carriers and fronting partners

The exhibits are addressed to you. Q3 and Q4 ask you to describe the AI your vendors and delegated operators run. You need one schema for the whole book.

MGAs, programs, TPAs, claims admins

You are the service provider in Q4. Your carrier answers with your evidence, or restricts what you can do.

AI and data vendors

Exhibit C and D name you. Q3b asks how you were validated. A separate vendor framework is in draft; your buyers will send you the contract schedule.

Brokers and embedded distributors

If a model touches quote, bind, or servicing on your side, you are in the chain, at whatever tier your systems occupy.

Latest release Supplement version 5.0 (Aug 31, 2026)Comment on it in writing by ~Sep 30; verbal meeting Oct 8, 2026 (tentative)Adoption target version 7.0, Fall National Meeting, Nov 2026

The Supplement in 60 seconds

Exhibit AHow much AI you use, by function: counts of models, which touch consumers, which touch money, which are new.
Exhibit BHow you govern it. Two versions: a narrative (numbered questions Q1 to Q5) and a checklist (items 1 to 3n). Q4 asks about AI used by MGAs and other service providers.
Exhibit CDetail on each high-risk model: version, vendor, testing, last test date, legal review, any regulatory action. Thirteen numbered items.
Exhibit DWhat data feeds the models: 25 categories from aerial imagery to telematics, with the source and vendor for each.

The references throughout this guide ("Exh C 8", "checklist 3m") link to those items on the reference page. The Supplement is a set of questions examiners may ask. It is not a law, a certification, or a score.

The guide

Six parts, each anchored to the Supplement, each with its verified-versus-Nolte's-read ledger.

State tracker

Every jurisdiction, three facts: has it adopted the NAIC model bulletin, does it run its own AI rule, and is it in the Supplement pilot.

25Adopted the NAIC model bulletin
4Own insurance-specific AI rule
12Supplement pilot states
22No action recorded

Open the interactive tracker →

Check your readiness

25 questions in five sections, about four minutes. You get a live score, the pillars you are weakest on, and the control that closes each gap. Answers stay in your browser; only an anonymous score is logged.

Check your readinessRead the methodology

Changelog

The part that makes this documentation living rather than published. Full changelog.

Self-assessment and orientation only. Nothing here is legal advice, a certification, or a compliance determination. Nolte is not affiliated with or endorsed by the NAIC. Exhibit references are paraphrased from Supplement draft 4.0; the wording that counts is the NAIC's. Corrections: j@nolte.io.