Regulatory / NAIC

Meridian and the NAIC AI Model Bulletin — an evidence-backed record of your AI systems

The bulletin asks insurers a question most can't answer quickly: what AI systems are in use, and who's accountable for them? Meridian answers it from your billing and usage data — continuously, with evidence.

What it expects

As of August 2026

  • A documented AI Systems (AIS) Program, commensurate with the insurer's risk
  • Governance, documentation, risk-management, and oversight practices for AI systems
  • Appropriate vendor oversight of relevant third-party AI systems, providers, data, and services
  • Enough information to identify and govern the AI systems within the program's scope

Exact obligations vary by state adoption; quote your state's bulletin for verbatim requirements.

How Meridian supports it

ExpectationMeridian capabilityEvidence artifact
Identification of AI systems in scope, including third-partyAI systems and vendors detected in connected billing and usage sources, with owner, department, workflow, and spendAgent estate report; ledger export
Documentation and accountabilityAttribution provenance — who assigned ownership, when, by what ruleAudit Evidence Export
Ongoing oversightContinuous metering, anomaly and budget alerts, monthly reportingBoard Pack; Risk & Anomaly report
Vendor oversightPer-vendor spend, usage, and drift across providersVendor detail; QBR report

Why billing-derived records hold up

A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use. Unattributed spend is surfaced, not hidden — the systems nobody has claimed yet are the first thing a program should govern.

See it in your environment

Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).

FAQ

Does Meridian replace our AI Systems Program under the bulletin?
No — your program, counsel, and regulator relationship remain yours. Meridian produces records that programs are built on.
Does this require access to policyholder data?
Meridian's spend-metering workflow is designed not to require policyholder data or PHI; connections are read-only to billing and usage sources.
We keep a spreadsheet inventory. Is that enough?
Usage-based AI changes weekly; a self-reported list goes stale. Meridian's record updates from the sources themselves and shows the delta.