Leadership1 distinct publisher3 min readPublished
Twenty-nine US jurisdictions now supervise insurer AI in some form, and the record that satisfies them describes how a system is deployed and on whose contract terms. Model choice is the smaller variable.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The reach into third-party arrangements is the part that reorganizes the work. The NAIC bulletin obliges insurers to govern the AI they procure as well as the AI they build [3], and Holland & Knight's May 2025 analysis reads that as a requirement to design the program so it prevents violations in systems the insurer buys rather than builds [6]. A vendor contract stops being a procurement document and becomes part of the compliance record, which means the operative terms are drafted by people who do not currently sit in the model evaluation meeting.
The footprint arithmetic is simple and incomplete. Twenty-five jurisdictions have adopted the bulletin [1] and four more regulate insurer AI under their own frameworks [2], which is twenty-nine places where a carrier's AI faces a named supervisory expectation [5]. The article does not identify them [24], so no carrier can read its own exposure off that figure; it can only read the direction.
The privacy question resolves along the same line. Nowak argues the constraint is not that personal data must never reach a public model but that consumer accounts generally lack the contractual protections enterprise offerings carry [7], among them commitments that customer data will not be used to train foundation models, that the customer retains ownership, and, depending on product and region, controls over residency and processing [8]. Self-hosting answers the question differently, by putting the runtime and the access list inside the insurer [9]. Either path can satisfy the standard; they differ in how much of the evidence the carrier holds in its own hands.
The trade is worth naming plainly. Self-hosting is available only where weights are licensed for it, and frontier weights are not [10], while frontier models are the ones with a real edge on open-ended work [11]. Nowak's case for accepting that trade rests on the shape of insurance work, where intake, document extraction, coverage checks and claims correspondence recur in recognizable patterns [12]. The harness, the software layer that decides which questions get asked, in what order, with what data and under what rules [13], is what allows a smaller, more precisely defined task to go to a smaller model [14], with a golden set per task type measuring performance on the carrier's own work instead of a public benchmark [15]. He reports having seen the harness matter more than the model it wraps [25], and says a well-designed one makes cheaper models viable for workflows that would otherwise call for a frontier system [26].
A skeptic in underwriting would say that rules around a weaker model still leave you with a weaker model. The design answer in the article is that low confidence is treated as a routing decision: answers are checked against rules and confidence thresholds, and anything below the bar goes to a human adjuster [16]. That is one practitioner's account rather than a measured result, and Nowak is a board member at Decerto, a software supplier to the industry [21], which belongs in the read.
The board-deck version of this quarter is a model selection with evaluation scores attached, and it is incomplete because those scores are calibrated to a version the provider controls. Public services can update model versions, change serving infrastructure or retire older versions, so a model that behaved well on Tuesday can behave differently on Thursday [17], and prompts, decomposition and validation thresholds tuned to one model have to be redone when it moves [19]. Deloitte's 2026 Global Insurance Outlook puts the advantage with insurers that act on their models, tools and strategies rather than those that adopt the newest technology fastest [20]. The decision taken this quarter is which model to license; the invoice that arrives next quarter is recalibration, and it lands on the same engineers who built the harness.
Ranked by verification strength, evidence, and original report placement.
The NAIC's AI Model Bulletin has been adopted by 25 U.S. jurisdictions.
Four further jurisdictions regulate insurer AI under their own frameworks rather than the NAIC bulletin.
Consumer accounts for LLM services generally do not provide the same contractual protections as enterprise offerings.
Enterprise agreements can include commitments that customer data will not be used to train foundation models, that the customer retains ownership of its data, and, depending on product and region, controls over data residency and processing.
The article does not identify which 25 jurisdictions adopted the NAIC bulletin or which four regulate insurer AI under their own frameworks.
The NAIC AI Model Bulletin requires insurers to govern not only their own AI systems but also their third-party AI arrangements.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Verisk files three endorsements that let carriers exclude generative AI from general liability1 distinct publisher
product
Deloitte counts one orchestrated agent deployment for every three expanding ones1 distinct publisher
build
Google's legal AI bundle lands a day after a $40M model, and the connector list tells you why2 distinct publishers
invest
FASB would let stablecoins sit in cash equivalents, but the issuer has to earn it1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One contributor, no external checks
Everything in this story arrives through a single Forbes Tech Council column. The two verifiable facts — the bulletin's third-party governance duty and Holland & Knight's reading of it — are the strongest material present, while the jurisdiction counts come with no list or link and the architectural argument comes with an explicit admission that no benchmark data backs it.
The rule is widely adopted; the practice barely is
Two very different adoption pictures sit in one story. Supervision is broad — 29 jurisdictions, on the author's count — while the architecture he recommends shows up as exactly one unnamed claims project with daily canary tests. Regulatory reach is real; the harness pattern is a practitioner's habit, not a documented industry move.
Deflationary on models, unproven on harnesses
Most of this column pushes against hype: don't buy the frontier model, don't trust the roadmap volume, price the division on last quarter's real traffic. The overreach is narrower and sits at the centre — a smaller model plus good scaffolding is said to cover work that would otherwise need a frontier model, and the author tells you outright he has no benchmark data for it. The dek's framing that model choice is 'the smaller variable' inherits that gap.
A vendor board member on his own product surface
Nowak sits on the board of Decerto, an insurance software firm, and the argument he makes is that the software layer around the model — the thing such firms build and integrate — is where success is decided, while the model is a commodity you should be able to swap in days. Forbes discloses the affiliation in the byline and then lets the conclusion stand unexamined. The Councils format is a paid contributor channel, not a reported beat.
Enough to judge the sourcing, not the substance
We can be quite sure who is speaking, what he sells, and which of his claims carry outside support — the disclosure and the citations are on the page. What we cannot settle from this material is whether the advice works: no second publisher, no named jurisdictions, no numbers on cost or accuracy, and one anonymous deployment.