Nearly three out of four financial institutions cannot say which of their vendors use artificial intelligence; Risk and compliance firm Ncontracts's 2026 State of Third-Party Risk Management Survey found that 72 percent of institutions remained only partially aware of vendor AI use, and 9 percent had not assessed it at all.
That blind spot now poses the sharper third-party risk for insurance carriers than the AI itself, says John Romano (pictured), a principal at Baker Tilly in Philadelphia who leads the accounting and advisory firm's insurance regulatory practice.
A managing general agent (MGA) that uses generative AI to summarize claims files sits at the low end of any risk scale, said Romano. Meanwhile, a partner that runs proprietary models to: select risks, set pricing, triage claims, score severity, or refer fraud, sits far higher.
“If it affects price, if it affects coverage, if it affects claims outcomes, if it affects fraud [or] any customer communications that are regulatory bound, then it deserves heightened oversight,” Romano said.
One commercial insurers AI chatbot approved a claim at the wrong figure, ten-times too large. “It was supposed to be $50,000, but the chatbot said $500,000,” he said. The carrier had disclosed the tool, he noted, but the error still triggered a costly back-and-forth – the kind of regulatory scrutiny and customer-trust damage that turns efficiency into a liability. IBA has tracked the hidden AI liability multiplying as autonomous agents proliferate, and Romano's warning lands in the same territory.

The gap does not stem from missing policy: Grant Thornton's 2026 AI Impact Survey of 950 executives found that over one-in-two insurance leaders reported their boards had set AI governance policies, yet nearly half (44 percent) still traced project failure or underperformance to governance and compliance gaps. The harder task is not writing a policy of one's own, but seeing – and judging – each vendor's own AI and data-governance practices.
Romano starts with an inventory. A carrier should be able to say where a vendor uses AI across its process, he said, what kinds of decisions the system makes, where it runs autonomously, and where people stay in the loop. A polished governance document rarely answers those questions. “It's very important to understand the process connections,” he said – not just to read a vendor's stated guardrails.
When Romano assesses how a vendor uses AI, he pushes past the written policy to the decision itself. “Tell me about the decisioning process. Maybe there's a flowchart. Where exactly is the agent actually performing?” he said. He wants to know how the vendor trained the model, what data it draws on, whether it touches customer data, and how the vendor gets comfortable with accuracy, explainability, and bias.
Bias worries him because the data often carries it from the start, and model drift compounds the problem as a system learns and ingests more data over time. Romano also presses vendors on their own third and fourth parties. A carrier's oversight, in his view, has to reach the subcontractors its vendor relies on, not stop at the first contract.
Romano's central advice reframes governance itself. Too many carriers, he said, assess their vendors through a “toll booth” style of scrutiny: every vendor, whatever its AI does, must clear the same questionnaire, the same legal review, the same documentation. As AI spreads into nearly every tool, a toll booth-approach stalls the business.
“You want to refer to it not as a toll booth, but an ‘express lane’ with specific guardrails,” Romano said; Carriers should define their AI risk appetite up front, he argued, then let low-risk cases move quickly while high-consumer-impact uses draw the deeper review.
That express lane cannot live in procurement alone, Romano stressed. Business owners need to weigh in, and compliance, legal, and technology all belong in the loop.
What sorts a vendor into the fast lane or the slow one, in Romano's framing, is how deeply that provider's own AI and data governance reach into consumer decisions. He tiers by consumer impact and the sensitivity of the data a vendor handles, not by spend. A managing general agent with delegated authority sits at the top of that risk pyramid: “Essentially you're giving the pen to another,” he said. That exposure is not marginal – delegated underwriting authority enterprises wrote $108.7 billion in direct premiums in 2025, up from $92.3 billion in 2024, and carriers granted underwriting authority in more than 75 percent of MGA contracts, according to AM Best data drawn from NAIC filings.

Below the MGAs, Romano ranks third-party administrators, then claims-technology providers that touch part of a claim – handing over a first-cut reserve or payment recommendation, say – and then any outside firm a carrier leans on to build its own proprietary models.
At the other end, uses that stay clear of consumer decisions earn the thinnest review. A vendor that runs AI only to draft marketing copy, or to help analyze geography, distribution, and sales inside the business, belongs in the express lane, Romano said. A claims vendor shows how the lane narrows in practice: a carrier might wave through a provider at first, then owe it harder questions precisely because it has come to rely on that provider for a block of claims. The test he keeps returning to is whether the vendor only advises or actually holds the pen – as decision authority climbs, the guardrails tighten.
Romano expects regulators to sharpen their focus on third-party governance without strangling innovation. He pointed to the National Association of Insurance Commissioners (NAIC), which is field-testing an AI Systems Evaluation Tool through a 12-state pilot running from March to September 2026 – California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. Examiners use the tool during market conduct and financial exams to map where an insurer uses AI, how it governs those systems, which models carry the most risk, and what data feeds them – with third-party use a core focus. The NAIC expects to weigh the tool for adoption at its fall 2026 national meeting.
The tool builds on the NAIC's 2023 model bulletin on the use of AI systems, which roughly 25 states have now adopted and which states plainly that existing insurance laws apply whether a decision comes from a human, an algorithm, or a third-party vendor. A separate model law on third-party data and models, anticipated later in 2026, could go further, potentially carrying licensing requirements for the vendors that sell models into the industry. Regulators “don't want to stifle innovation,” Romano said, and they keep working with the industry as they bring in more subject-matter experts. That trajectory already shapes the NAIC's growing scrutiny of how insurers deploy AI.
The direction of travel, as Romano reads it, runs from documentation toward evidence. Regulators will move past “we have an AI governance policy and an inventory,” and start asking carriers to show support for the specific controls that matter most – above all in underwriting, pricing, and claims, where AI reaches consumers directly. As AI keeps accelerating across insurance, carriers that map their vendors' AI now, and reserve their heaviest scrutiny for the decisions that touch policyholders, will meet that shift already prepared. The ones still treating a signed governance policy as proof may find the pen was never fully in their hands.