NAIC's AI Working Group used its Summer Meeting to push toward Tool 5.0 and agentic AI oversightThe NAIC's Big Data and Artificial Intelligence Working Group met August 13th during the Summer National Meeting in Columbus, where AM Best presented on how AI governance expectations differ across predictive, generative, and agentic AI systems, a distinction regulators are now building into their review approach. Materials from the session point to company surveys running through the end of September, a revised Tool 5.0 expected to enter a 30-day public comment period next month, and a further-revised version headed to the Fall National Meeting in November for possible adoption. What insurance leaders should care about: Every prior brief has tracked this pilot from launch through its first progress checkpoint. This is the meeting where the tool's next version starts taking shape based on what regulators actually saw across five months of pilot use. The agentic AI distinction matters specifically: if your claims or underwriting operation has moved toward multi-agent AI workflows, expect the next tool revision to ask about it by name rather than folding it into generic AI system language. Watch for the September comment period and get your governance documentation ready to map against whatever exhibits change.
|
|
|
California's data-deletion platform is now an enforceable operational obligation, not a registration exerciseAs of August 1st, more than 600 data brokers registered in California must begin actively processing consumer deletion requests through DROP, the state's centralized Delete Request and Opt-Out Platform, at least once every 45 days. More than 300,000 Californians had deletion requests queued ahead of the deadline. Brokers now have 90 days to act on each retrieved request. Penalties run $200 per unprocessed request, per day, on top of a doubled $200-per-day fine, up from $100, for failing to register at all. What insurance leaders should care about: This brief has tracked telematics and location-data restrictions since May. DROP is the enforcement mechanism behind that entire thread, not a new one. If your organization, or a marketing, analytics, or telematics vendor you use, meets California's data broker definition, August 1st converted a paperwork obligation into a live operational one with a running clock and a real penalty. Confirm registration and processing status for every vendor in that category, not just your own program, since a vendor's non-compliance can still surface as your problem if their data practices are covered in your own privacy disclosures.
|
|
|
|
|
The FTC put personalized pricing on notice the same week NAIC regulators discussed rate cross-subsidization On August 19th, the FTC proposed an enforcement policy statement warning that businesses using personal data to set individualized prices without adequate disclosure may violate the FTC Act, opening a 30-day public comment period. The statement does not ban personalized pricing outright, and the FTC acknowledged it lacks authority to do so, but it signals aggressive Section 5 enforcement against undisclosed practices and explicitly builds on state-level scrutiny already underway in New Jersey, Maryland, Connecticut, and New York. The same week, NAIC's Casualty Actuarial and Statistical Task Force met at the Summer National Meeting to discuss a white paper on homeowners rate regulation and cross-subsidization. What insurance leaders should care about: Insurance rating is generally governed by state insurance law rather than FTC jurisdiction, but the direction of travel is the same at both levels. Regulators on multiple fronts are scrutinizing how data-driven, individualized pricing gets disclosed and justified. Telematics discounts, credit-based insurance scores, and AI-assisted underwriting all use exactly the kind of personal data the FTC statement describes. Even where the FTC has no direct jurisdiction over your rate filings, expect state regulators to borrow its disclosure framework and plaintiffs' counsel to cite it regardless of jurisdiction. Review whether your current disclosures explain, in plain language, which data inputs affect an individual policyholder's price.
|
|
|
Federal agencies named insurance directly in an updated ransomware advisoryOn August 18th, CISA, the FBI, and HHS jointly updated their #StopRansomware advisory on Medusa ransomware for the first time since March 2025, the most significant revision to date. The update documents more than 500 confirmed victims, up from 300 in the original advisory, adds new tactics observed through FBI investigations as recent as April 2026, and names HHS as a co-sealing agency for the first time to reflect intensified healthcare targeting. The advisory lists medical, education, legal, insurance, technology, and manufacturing among the sectors Medusa actors target, and notes that initial access brokers earn between $100 and $1 million for providing network access into a victim organization. What insurance leaders should care about: This is a federal agency naming your sector directly, in writing, the same week a new group claimed two more insurance-sector victims. Medusa's targeting skews toward small and mid-sized organizations that typically lack a dedicated security team, the same profile as most agencies, MGAs, and RRGs. The advisory includes specific indicators of compromise and mitigations. Pull it and have IT walk through the detection guidance directly rather than relying on a summary. If your organization or a key vendor is closer to a five-person agency than a national carrier in security staffing, the mitigations in this advisory are written for you specifically.
|
|
|
|
|
Marsh's Q2 2026 Global Insurance Market Index shows cyber insurance rates fell 4% globally in the second quarter, the twelfth consecutive quarter of decline, with the U.S. specifically down a more modest 2%, in line with Q1. Marsh notes U.S. cyber rates have now declined every quarter since Q2 2023, a three-year stretch. What insurance leaders should care about: Twelve straight quarters of softening, measured by Marsh, and the eighth consecutive quarter of declines AM Best cited in July's brief, are two different methodologies pointing to the same conclusion: a market pricing this risk lower every quarter for three years running, even as this month alone produced two new claimed ransomware victims in the sector and a federal ransomware advisory naming insurance by name. That gap between price and loss exposure does not close on its own.
|
|
|
Priority Actions for Insurance Leaders (Next 60 Days)Priority 1 — : Confirm your RRG, captive, or pooled-risk arrangement's security posture gets vendor-level scrutiny.
If you participate in a risk retention group, captive, or other pooled-risk structure, do not assume its security program matches what you would require of a standalone vendor. Ask directly: when was the last third-party security assessment, and does the arrangement have incident response capability independent of its members? Priority 2 —Confirm your California data-broker vendors are actually processing DROP requests, not just registered. Registration status alone no longer satisfies the Delete Act. For every marketing, analytics, or telematics vendor that might meet California's data broker definition, confirm they are actively pulling and processing DROP requests on the required 45-day cycle, not just paying the annual registration fee. Priority 3 — Pull the updated Medusa advisory and walk the mitigations with IT directly. Do not rely on a summary. CISA's August 18th update includes specific indicators of compromise and tactics current through April 2026. Have IT or your MSP confirm each mitigation against your own environment this month, particularly if your security staffing looks more like a five-person agency than a national carrier.
|
A new ransomware crew found two insurance targets the same week federal agencies named the sector directly in a ransomware advisory. Regulators moved on AI oversight and data-driven pricing in the same seven-day window. None of it happened because the industry did something wrong this month. It happened because the industry is a target, a data source, and a pricing model regulators are watching all at once. The response is the same as every month before it: know what you can document, and document it before someone asks
|
|
|
→ If you cannot show which vendors in your RRG, captive, or marketing stack are actually meeting their August 1st DROP obligations, or whether your AI governance program accounts for agentic systems specifically, those are two questions worth answering before the Fall National Meeting, not after. FiveM helps insurers build, document, and continuously test regulator-ready governance programs, so the answer to an examiner's question is already on file.
|
|
|
|
|
|
|