Marcin Nowak, board member at Decerto, has 20+ years in insurance, focusing on automation, technology impact and software solutions.
If a regulator asked your organization to produce a complete decision audit trail within five business days for every AI-supported decision your systems made in the last quarter, how confident would you be that you could meet the deadline?
For most enterprises deploying AI in 2026, the honest answer is “not very.”
That’s what executives told us when my team surveyed 20 U.S. insurance leaders earlier this year about their AI deployments and their readiness for state insurance department examinations. Of the 14 respondents whose organizations had AI in production, only three said they could produce a complete audit trail with high confidence. Two more said they would hit the deadline but with significant manual reconstruction. The remaining nine either anticipated significant manual work or struggling.
That gap between the AI in production today and the AI ready for regulatory exams is the most underrated executive risk in current enterprise AI strategy.
Why The Gap Exists
Based on my experience working with carriers and other enterprises over the past two decades, I believe the gap exists because three things converged in the past 24 months that almost no organization is structured to address.
First, regulatory frameworks demanding documentation of AI decisioning are now in force across multiple jurisdictions. As of early 2026, 24 U.S. states and the District of Columbia have adopted the National Association of Insurance Commissioners (NAIC) Model Bulletin on the Use of Artificial Intelligence Systems by Insurers or substantively similar guidance. The NAIC’s AI Systems Evaluation Tool, designed to standardize how state examiners assess a carrier’s AI compliance during market conduct examinations, entered exam pilots in March 2026. The bulletin requires carriers to maintain documentation of how AI systems make or support decisions related to regulated insurance practices, and to produce that documentation on request.
The European Union AI Act, which entered force in 2024 and takes full effect in August 2026, requires what it calls high-risk AI systems to maintain logs of operation throughout their life cycle, with documentation of decisioning logic available for regulator inspection.
The National Institute of Standards and Technology (NIST) AI Risk Management Framework, which has become the “de facto standard” for U.S. federal contractors and is increasingly referenced by state agencies, requires similar documentation discipline. Healthcare AI faces requirements from the U.S. Food and Drug Administration and Department of Health and Human Services, and U.S. bank regulators are increasing scrutiny of AI use in the financial sector.
The specific rules differ, but the underlying expectation is the same. If an AI system supports or makes a decision affecting a regulated outcome, you need to be able to show your work.
Second, most enterprises deployed their first production AI systems before these frameworks were finalized. The deployments were scoped for business value. Documentation was either an afterthought or a manual process. Logs were kept in formats that made sense to engineers but not to auditors. Model versions were tracked inconsistently. Input features were not always preserved.
Third, the auditors asking these questions are increasingly not your internal compliance team. They are state insurance department examiners, federal banking regulators, healthcare oversight bodies and EU national competent authorities. They are reading from external rule books, not your internal risk register. They have legally backed authority to compel documentation production within tight timelines, and the consequences for non-production are real.
What Executives Should Do
First, recognize that audit trail capability is not an engineering question. It is a board-level question with material risk consequences. The cost of building auditability into AI systems from day one is small. The cost of retrofitting it after a regulatory finding is large, in some cases multiples of the original deployment cost.
Second, run a one-day audit-readiness assessment on every AI system currently in production. For each system, answer six questions:
1. Can you produce, for a given decision, the model version that was active at that time?
2. Can you produce the input features that fed that decision?
3. Can you produce the model’s output and any thresholds or business rules that influenced the final decision?
4. Can you produce the human reviewer’s identity if one was involved?
5. Can you produce all of this in a format an external auditor can read without your engineering team translating it?
6. Can you produce all of it within the timeline a regulator might give you, which is rarely longer than five to 10 business days?
If the answer to any of those is no, your system is at risk.
Third, set audit-trail capability as a nonnegotiable requirement for any new AI deployment from this quarter forward. The capability is now cheap to build in. Logging frameworks, model version control and explainability tooling have all developed substantially over the past 18 months. The capability is also expensive to add later. In my opinion, the deployments most at risk are the ones that went into production in 2023 and 2024 and have been scaled since.
Fourth, prepare for the auditor question that most boards have not heard yet. Regulators are starting to ask if you can show why a decision was different from a comparable decision your system made for a different customer. That comparison capability requires logging input features and model outputs in a way that supports cross-decision analysis. Few systems currently support it.
The cost asymmetry is clear.
The audit trail gap is not a future regulatory problem. It is a present operational gap that current regulatory frameworks have already made consequential. In my experience, the executives who address this in 2026 will spend a fraction of what their peers who address it in 2027 will spend. The cost asymmetry is unusually clear. Acting now is the cheaper option.
If you have AI in production today, the question is not whether your first regulatory exam is coming, but what state your system will be in when it arrives.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


