State insurance regulators are using this year’s marquee national gathering to sharpen how they oversee artificial intelligence and cyber risk in the insurance sector. The National Association of Insurance Commissioners opened its 2026 Summer National Meeting in Columbus, Ohio, running from August 11 to August 14, a hybrid event where participants can attend either in person or virtually. Behind the logistics sits a governance agenda years in the making, anchored by a live pilot tool, a standing model bulletin, and cyber-focused working groups that meet twice during the four-day session.
NAIC’s AI Systems Evaluation Tool Goes Live in 12 States
The clearest signal of where NAIC’s AI oversight stands in practice is a review tool now being tested in the field. As of March 2026, the NAIC’s AI Systems Evaluation Tool is being piloted by 12 participating states, which are providing feedback on its effectiveness. The tool is one piece of a broader push described in the association’s own strategic planning: the NAIC says it will support state regulators’ responsible-innovation efforts by advancing cybersecurity frameworks, piloting an AI evaluation tool, and expanding regulator training and expertise. None of that shifts accountability away from carriers themselves. Insurers remain responsible for complying with insurance laws, regulations, insurance standards, and consumer protection rules when they use AI, according to the NAIC. International regulators have reached similar conclusions on their own terms: Germany’s BaFin has taken on a similar role as AI market watchdog for insurers, formalizing supervisory expectations that echo what NAIC’s pilot is testing state by state.
Innovation, Cybersecurity, and Technology Committee Convenes in Columbus
This year’s AI governance push builds on a six-year track record. NAIC’s regulatory principles on artificial intelligence were adopted by the full membership at the 2020 Summer National Meeting. Those principles hardened into operational guidance three years later, when the NAIC’s Model Bulletin on the Use of Artificial Intelligence by Insurance Companies was adopted in December 2023. The Columbus agenda keeps that lineage in the room twice. The Big Data and Artificial Intelligence (H) Working Group is scheduled to meet at the Greater Columbus Convention Center, in the Heart of It All Ballroom B, for a one-hour session, followed a day later by the Innovation, Cybersecurity, and Technology (H) Committee, which holds a one-hour-and-15-minute session in the Battelle Grand Ballroom on Level 3. European supervisors have moved on a comparable timeline of their own: the ESAs have begun demanding documented proof of AI governance from insurers, a parallel push toward evidence-based oversight rather than principles alone.
Cybersecurity Working Group’s 2026 Charges Center on Breach Response
Cyber risk gets its own dedicated track. One of the Cybersecurity (H) Working Group’s 2026 charges is to monitor cybersecurity trends — vulnerabilities, risk management, governance practices, and breaches — that could affect the insurance industry. The working group is also charged with developing and maintaining regulatory guidance to help state insurance regulators investigate national insurance cyber events. A third charge looks at the market side of the equation: the working group is directed to monitor cyber insurance industry trends, including meeting with subject matter experts and assessing regulators’ data needs. The statutory backbone behind those charges predates this year’s meeting. The NAIC adopted the Insurance Data Security Model Law, number 668, which requires insurers and other licensees to develop, implement, and maintain an information security program. Australia’s prudential regulator has separately called for a step change in how insurers govern AI risk, a reminder that pairing AI oversight with cyber-breach protocol is becoming a global pattern rather than a US-only experiment.
Strategic Priorities Frame AI and Cyber as a Single Watch Item
NAIC leadership has folded both threads into one heading for the year. Among its 2026 strategic priorities, the NAIC states that the state-based regulatory system is best equipped to protect policyholders as emerging technology creates new opportunities and risks, under the heading of leading on AI model governance, innovation oversight, and cyber threats. Part of that framing acknowledges how fast the underlying technology is changing: the NAIC describes large language models as a newer form of AI designed to understand and generate human language. The message to insurers is less about any single tool and more about a standing expectation: governance capacity has to keep pace with what the technology can do.
What to Watch Before and After the Columbus Session
For firms tracking the proceedings without traveling to Ohio, the practical details are already public. Reserved hotel room blocks for the meeting expire on July 13, 2026, though rooms could sell out earlier. The NAIC has published a tentative agenda for the meeting on its Meetings and Events page, giving compliance teams a working map of which committees take up AI and cyber items and when. The bigger signal is directional rather than procedural: a pilot tool already running in a dozen states, a data security law already on the books, and committee charges written to keep both topics under active review through the rest of 2026.