If you spent 2024 and 2025 building your first written Information Security Program, completing your first risk assessment, and updating your vendor contracts to satisfy the NAIC Insurance Data Security Model Law, you did the right thing. That work was necessary.
The problem is that it is no longer sufficient.
The NAIC's regulatory agenda for 2026 adds two entirely new compliance obligations that the original Model Law did not address in any meaningful depth: governance of artificial intelligence tools used in insurance operations, and enhanced third-party data management requirements that are significantly more specific than anything your existing program was likely built to satisfy.
This article is for agencies that are past the starting line on NAIC compliance and need to understand what comes next. If you are still building your foundational program, start with our overview of the original law: The Cybersecurity Law Your State Passed Without Telling You.
As of early 2026, at least 28 jurisdictions have enacted some version of the NAIC Insurance Data Security Model Law. For agencies operating across state lines, this means compliance with MDL-668 provisions is functionally mandatory regardless of where your agency is headquartered. You must satisfy the most restrictive requirements in every state where you hold appointments or licenses. If your agency holds appointments or licenses in New York, Texas, and Connecticut, you are operating under three different versions of the same model law simultaneously, and your compliance program must account for all three.
This multi-state complexity alone creates a compliance challenge most small agencies have never formally mapped. Most agency owners build one program for their home state and assume it covers their full footprint. That assumption is nearly always incorrect.
But the more pressing issue in 2026 is not the geographic spread of the existing law. It is the fact that the law itself is actively evolving in two directions that will require agencies to update programs they may have spent the better part of two years building.
The NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers has now been adopted by more than 20 jurisdictions, with broader adoption expected at the 2026 Fall National Meeting. The bulletin requires a written AI Systems Program with senior-management and board accountability, risk controls, model validation and testing for bias and errors, and oversight of third-party AI tools where the insurer or agency remains fully responsible for the AI's behavior.
This is not a future-dated best practice. For agencies operating in states that have already adopted the bulletin, it is a live compliance obligation that will be examined during market conduct reviews.
The practical problem for small and mid-sized insurance agencies is straightforward. Most agencies that adopted AI tools in the past two years, whether for customer communication, quoting support, claims triage, or document processing, did so without building any governance infrastructure around those tools. The pattern of unmonitored AI tools entering business workflows without formal evaluation or oversight is one of the most common compliance gaps our team encounters across regulated industries.
What the NAIC AI Model Bulletin requires is not simply that you stop using unsanctioned AI tools. It requires that you build a documented program that governs every AI system your agency uses, whether that system was developed internally or provided by a third party. The core elements of a compliant AI Systems Program under the bulletin include a written inventory of all AI tools in use across your agency's operations, documented risk controls and testing procedures for each tool, evidence of senior management oversight, and a formal process for evaluating any new AI tool before it is deployed.
For agencies using AI in underwriting support or claims workflows, the governance and cost containment implications of unregulated AI adoption extend well beyond compliance risk. The regulatory obligation and the operational risk are pointing in the same direction: AI tools need to be inventoried, evaluated, and governed before they are used in consequential insurance processes.
The Third-Party Vendor Registry: What Is Coming and Why It Changes Your Program
At the NAIC's 2026 Spring National Meeting in March, the Third-Party Data and Models Working Group advanced a proposal to create a registry for vendors that provide AI models and datasets to insurers. The registry would require vendors to file structured disclosures with regulators about the AI models and data sets they provide. The realistic adoption timeline puts the first state implementations in late 2026 or early 2027.
Two things about this framework deserve particular attention for small agency owners.
First, the registry is not designed as a safe harbor. An insurer or agency that uses a registered vendor is still fully accountable for that vendor's behavior in pricing, underwriting, claims, and fraud detection. A vendor appearing in the registry does not satisfy your due diligence obligation. You must still produce your own evidence that you evaluated the vendor, understood its model, and maintain ongoing oversight of its performance. The registry creates regulatory visibility. It does not transfer your compliance responsibility to the vendor.
Second, the existing MDL-668 already requires third-party vendor oversight. What the 2026 amendments add is specificity. Where the original law mentioned vendor oversight in general terms, the amendment drafts define what adequate oversight looks like in practice: documented vendor inventories, periodic security reviews, mandatory contract language covering incident notification, data handling standards, and exit provisions. Agencies that built vendor oversight programs in 2024 or 2025 will likely need to update both their documentation and their vendor contracts to meet the more prescriptive standards the amendments introduce.
Several states have launched, or are expected to launch, pilot programs using the NAIC's AI Systems Evaluation Tool, which regulators can use to assess how agencies and insurers deploy artificial intelligence across business functions. The tool focuses on AI governance, risk management, and transparency, and is expected to be formally adopted at the 2026 Fall National Meeting.
For agencies operating across multiple states, this creates an emerging compliance matrix that is more complex than anything the original Model Law introduced. Colorado's Artificial Intelligence Act applies to insurers operating in that state and imposes governance and testing requirements with a specific focus on preventing algorithmic discrimination in underwriting and pricing. Illinois has both adopted the NAIC AI Model Bulletin and passed independent legislation. New York's existing NYDFS Part 500 framework creates parallel obligations for agencies licensed under the New York Department of Financial Services.
The practical implication for multi-state agencies is the same as it has always been, but with higher stakes: you cannot build one program for your home state and assume it satisfies your full regulatory footprint. Each state's adoption of the NAIC model bulletin, the AI Systems Evaluation Tool, and any independent state AI legislation needs to be mapped against your agency's specific state appointments or licenses. The floor is rising in every jurisdiction, and it is rising unevenly.
Agencies that completed their foundational NAIC compliance work in 2024 or 2025 should audit their programs against the following six areas before the end of 2026.
AI tool inventory. Your existing risk assessment almost certainly did not include an inventory of AI tools because most agencies were not using AI in meaningful ways when the original compliance work was completed. A current AI tool inventory should identify every AI system in use across your agency, the data it accesses, the processes it supports, and the governance documentation that exists for each tool.
Third-party vendor documentation. Review your existing vendor list against the more specific requirements the 2026 amendment drafts introduce. Your vendor contracts should include incident notification obligations, data handling standards, access controls, and exit provisions. If your contracts were drafted to satisfy the general vendor oversight language in the original Model Law, they will likely need updates.
Multi-state compliance map. If your agency holds appointments or licenses in states that have adopted the NAIC AI Model Bulletin, you need a written AI Systems Program that align with individual state AI laws.
For example, if you hold appointments in Colorado, your program also needs to account for the Colorado Artificial Intelligence Act's specific testing and transparency requirements.
Annual risk assessment update. Your risk assessment needs to reflect your current operational environment, including any AI tools adopted since the previous assessment and any new vendor relationships. A risk assessment that was accurate in 2024 may no longer reflect the risks your agency actually faces in 2026.
Incident response plan notification workflows. With a centralized cybersecurity event notification portal under development at the NAIC level, the mechanics of reporting a cybersecurity event to state insurance commissioners are likely to change. Your incident response plan should be updated to account for the portal once it becomes operational in your states of appointment or licenses.
Staff training records. The AI governance requirements being embedded across NAIC frameworks include expectations around employee awareness of AI risks. Training your staff to recognize the risks associated with AI tools, including the compliance implications of using unsanctioned AI tools in insurance workflows, is a component of a defensible AI governance program.
The agencies that invested time and resources in building foundational NAIC compliance programs in 2024 and 2025 are in a materially better position than agencies that have not started. The risk assessment discipline, the vendor oversight infrastructure, and the incident response planning that the original Model Law required are not wasted work. They are the foundation on which the new requirements build.
The point is not to replace your existing program. The point is to recognize that the regulatory environment governing insurance cybersecurity has moved significantly since your program was built, and that standing still is no longer the same as staying compliant.
Compliance with the NAIC Insurance Data Security Model Law was never a one-time task. The working group that drafted it said exactly that from the beginning. In 2026, that statement has moved from a philosophical principle to a practical reality with specific new requirements attached to it.
CompassMSP's compliance team works with insurance agencies and licensed entities on NAIC MDL-668 compliance, AI governance program development, and the multi-state compliance mapping that multi-appointment agencies require.
Learn about our insurance compliance services at compassmsp.com/industries/insurance
If AI governance is your immediate gap, our Shadow AI Playbook walks through exactly how to build a governed AI program for a regulated business environment.