meilynx

Framework · Insurance AI

Examination evidence for the AI your insurer actually runs.

The NAIC Model Bulletin is in effect in 24 states and DC, Colorado's Reg 10-1-1 reached auto and health insurers in July 2026, and New York, Texas, and Connecticut add their own layers. Meilynx evidences the LLM and agent slice of an AIS Program; your rating models, testing, and written program stay yours.

What the bulletin expects

Program, inventory, controls, production.

Section 3 sets the AIS Program expectations. Section 4 lists what a market-conduct examination will request, and it names Generative AI explicitly.

  • A written AIS Program proportionate to the insurer's use of AI and the Degree of Potential Harm, with senior management accountable to the board (§3 1.1-1.4).
  • Inventories, traceability, and record retention for the AI Systems and Predictive Models that make or support regulated decisions (§3 3.3, 3.6).
  • Third-party AI and data diligence with audit rights and regulator cooperation in contracts; an LLM provider is a Third Party (§3 4.0).
  • Examination production: the program, its adoption, per-system documentation, validation and drift testing, and third-party contracts on request (§4); Colorado and Connecticut add annual attestations.
How Meilynx maps

Runtime expectations, to runtime evidence.

A specific Meilynx control for each expectation the proxy can substantiate, and the artifact it produces. The written program, testing, notices, third-party contracts, and state filings stay attested in your own program.

NAIC bulletin and state layers → Meilynx controls (LLM / agent slice)

Inventory the AI Systems that make or support regulated decisions

NAIC AI Bulletin · §3 3.3(a) · CO Reg 10-1-1 · §5.A.9

Maps to · The inventory of LLM and agent systems and the third-party providers behind them is derived from live traffic and enforced by runtime model allow-listing. The population an insurer tiers by Degree of Potential Harm starts from what actually runs.

Examination artifact · AI System inventory and third-party provider list, generated from traffic

Keep a record of AI-supported decisions that survives a market-conduct examination

NAIC AI Bulletin · §3 3.6 · §4 1.3(c)

Maps to · Each AI request, response, and governance decision is captured inline at the proxy and sealed into a tamper-evident, hash-chained record with write-once retention. That is the per-system documentation Section 4 asks for, for the routed slice.

Examination artifact · Hash-chained decision audit trail with WORM retention

Protect non-public consumer information reaching an AI System

NAIC AI Bulletin · §3 3.5 · Model #668 · §4.A

Maps to · Detection of consumer personal data and of credentials in prompts and outputs evidences what nonpublic information actually reaches each provider.

Examination artifact · Nonpublic-information findings by system and provider

Detect unapproved changes to the deployed system and prove the approved controls were in force

NAIC AI Bulletin · §3 3.3(c) · §3 2.1 · CO Reg 10-1-1 · §5.A.10

Maps to · Prompt-drift and tool-grant-drift detection flag configuration changes against approved baselines, the data plane's acknowledged governance bundle is compared with the approved one, and enforcement fails closed at startup. This is configuration drift, not statistical model drift, which stays with your validation function.

Examination artifact · Drift findings, configuration-integrity verdict, enforcement-continuity evidence

Show a person reviewed consequential AI-supported decisions before action

TX B-0003-26 · CO Reg 10-1-1 · §5.A.5

Maps to · Two-party approval gates and their review record are supporting evidence that a human stood between the AI output and a consequential decision. The review itself is a human act, and this control never auto-verifies.

Examination artifact · Approval-grant lifecycle and human-review attestation

Answer Section 4: the written program, testing, third-party diligence, state filings

NAIC AI Bulletin · §4 1.1-2.4 · CT MC-25 · CO Reg 10-1-1 · §6

Maps to · The written AIS Program, unfair-discrimination testing, data practices, notices, third-party contracts, internal audit, and the Connecticut certification and Colorado annual report are insurer acts, attested in the package with statute-shaped evidence fields and never performed by Meilynx. A Section 4 crosswalk maps each request item to where it is answered and its evidence scope.

Examination artifact · NAIC Section 4 examination crosswalk and attested program evidence

The evidence

What you hand a market-conduct examiner.

The audit trail renders into a governance package scoped to the LLM and agent slice. Each control is classified as proxy-verified runtime evidence or attested in your program, and the Section 4 crosswalk ties each regulator request to where it is answered.

In the package

  • AI System inventory and third-party provider list, auto-populated from traffic.
  • NAIC Section 4 examination crosswalk: request item, where addressed, evidence scope.
  • Change monitoring, configuration integrity, and enforcement-continuity evidence.
  • Tamper-evident decision audit trail with write-once retention.
  • Obligation timeline: NAIC, Colorado, New York, Texas, Connecticut in effect; the evaluation tool as a pilot; NYDFS 500 and EU AI Act pointers.
FAQ

Insurance AI and the proxy.

Which insurance AI requirements does the preset cover?

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023 and in effect in 24 states and the District of Columbia as of the NAIC's Spring 2026 meeting) is the primary citation on every control: the AIS Program expectations in Section 3 and the examination requests in Section 4. The state layers are secondary citations: Colorado Reg 10-1-1 (amended October 2025; life, private passenger auto, and health benefit plans using external consumer data), New York DFS Circular Letter 7 (2024; underwriting and pricing), Texas Bulletin B-0003-26 (June 2026; a person reviews consequential AI decisions), and Connecticut Bulletin MC-25 (annual AI certification). NYDFS 500 and the EU AI Act's Annex III insurance-pricing entry stay with their own presets.

Does this cover our rating and underwriting models?

Only where they call an LLM. Meilynx sits on the generative-AI, LLM, and agent traffic: the claims assistant, the underwriting summarizer, the servicing chatbot, the agent calling tools. Classical predictive models (rating GLMs, underwriting scores, ECDIS-derived risk scores) run outside the proxy path and are not evidenced here. Their validation and unfair-discrimination testing remain with your actuarial and data-science functions; the package records that testing as attested evidence and never performs it.

Does the preset make us compliant with the NAIC bulletin or Reg 10-1-1?

No runtime product could. The written AIS Program, board accountability, risk tiering, consumer notices, third-party contracts, quantitative testing, and the state filings all happen outside the proxy. What the proxy substantiates from live traffic (the AI System and provider inventory, nonpublic-information findings, configuration drift and enforcement continuity, and the tamper-evident decision record) carries proxy-verified evidence. Everything else is marked as attested, and the Section 4 crosswalk says which is which for every request item.

What about the NAIC AI Systems Evaluation Tool?

It is a pilot. Twelve state regulators are testing the tool in examinations through September 2026, with adoption targeted for later in the year. The preset claims no coverage of it. The Section 4 crosswalk tracks the request categories the tool draws on, so the package is organized the way an examiner using it would ask.

Examination package

See exactly what an examiner receives

Download a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.