State DOI, NAIC AI Model Bulletin, and Annuity-Suitability Layer
A dually-licensed advisor who sells annuities under a state insurance department's jurisdiction and uses AI to draft client-facing materials, score suitability, or recommend a specific contract is now operating under three layered regimes: the federal Reg BI / Marketing Rule / FINRA Rule 2210 / 3110 / 4511 stack, the SEC Marketing Rule 206(4)-1 / Compliance Rule 206(4)-7 framework, and the state insurance regime built around the NAIC AI Model Bulletin, NAIC Model #275 (the Suitability and Best Interest in Annuity Transactions Model Regulation), and the state-by-state adoptions that vary materially. This lesson installs the practical 2026 supervisory layer for AI-generated annuity recommendations โ naming what the dually-licensed advisor must do that the IA-only or BD-only advisor does not, where the state DOI requirements diverge from the federal framework, and how the AI Governance Committee's WSPs accommodate the annuity layer without producing duplicate or conflicting policies.
Why the Annuity Layer Is Different โ and Why AI Makes It Harder
An annuity recommendation is not a securities recommendation in the federal sense โ it is regulated by state insurance departments under the McCarran-Ferguson Act's preservation of state insurance authority. The NAIC develops model regulations that individual states then adopt (with variations); NAIC Model #275 โ the Suitability and Best Interest in Annuity Transactions Model Regulation โ sets out the four obligations on the producer (care, disclosure, conflict, documentation) that parallel Reg BI but exist in a separate regulatory channel. As of mid-2026, 48 states have adopted some version of Model #275; the adopting states differ on training hours required, on the precise documentation, on the producer's obligation to consider replacement, and on enforcement intensity. For the dually-licensed advisor (registered with FINRA and SEC, licensed as an insurance producer in one or more states), every annuity recommendation triggers the state framework even when the same client also has a securities account under the federal framework.
AI amplifies three friction points in this layered regime. First, the AI tool that drafts a client-facing annuity comparison may include language that satisfies the federal Marketing Rule 206(4)-1 "clear and prominent" disclosure standard but fails a specific state DOI's required disclosure language for variable annuity surrender charges. Second, an AI tool that scores annuity suitability against a client profile must align with the state's "consumer's insurance needs and financial objectives" framing under Model #275, not just the federal Reg BI Care Obligation under ยง240.15l-1(a)(2)(ii) โ the two overlap heavily but are not identical. Third, the NAIC AI Model Bulletin (the broader insurance-industry AI governance framing the NAIC published and individual states have started adopting through 2025-2026) imposes vendor-oversight, fairness-testing, and disclosure expectations that the federal regime does not necessarily match.
The practical implication: the dually-licensed advisor running AI on annuity workflows must maintain the federal WSP layer (developed in L4 Ch3 and L4 Ch6 L1) and a state-DOI-specific layer that addresses the named state DOI variations, the NAIC AI Model Bulletin expectations, the Model #275 best-interest documentation, and the principal review architecture that produces a single supervisory record satisfying both regimes.
The NAIC AI Model Bulletin and the State Adoption Wave
The NAIC AI Model Bulletin, first published in December 2023 and refined through 2024-2025 with the March 2026 NAIC Artificial Intelligence and State Insurance Regulation Issue Brief providing the most-recent framing, articulates the NAIC's expectations for insurers (and, by extension, producers using AI in insurance transactions) across six domains: governance and risk management, vendor oversight, data quality, fairness and non-discrimination, transparency and disclosure, and post-deployment monitoring. The Bulletin is not itself binding law in any state โ it is a model for state adoption. As of mid-2026, more than 30 states have adopted some version of the AI Model Bulletin through state DOI bulletin or guidance, with material variations.
The advisor's job is not to memorize the 50-state variation but to understand the six domains the Bulletin organizes around โ because every state adoption clusters around these. The L4 Ch6 L1 AI Risk Register's twelve risks map cleanly onto the six Bulletin domains: governance (governance committee + register), vendor oversight (vendor due diligence under L4 Ch2 L2), data quality (training-data poisoning + hallucination risks), fairness (model bias), transparency (client perception + Marketing Rule disclosure), monitoring (dashboard under L4 Ch5 L2). For the dually-licensed advisor, the practice's existing AI Governance Committee and risk register already cover the substantive expectations โ the extra work is the state-specific documentation overlay.
State DOI Variations the Producer Must Track
Three named state DOI variations matter most as of mid-2026. New York DFS โ under 23 NYCRR 500 and its 2024-2025 AI-related cyber guidance, the producer must meet third-party-service-provider expectations on AI tools touching NPI, MFA enforcement, encryption, and 72-hour breach notification, layered with the NY annuity-specific Reg 187 best-interest framework (which predates Model #275 and remains in force). California Department of Insurance โ has published AI-specific guidance on disclosure to consumers, fairness testing for AI-driven underwriting and claims, and CPRA alignment for AI tools touching personal information. Colorado SB 21-169 โ the first state law specifically governing AI use in insurance, requires insurer and producer testing for unfair discrimination, with specific documentation requirements and a state-administered enforcement mechanism. Other states (Connecticut, Illinois, Washington) have produced their own bulletins; the practice operating in multiple states maintains a state-by-state matrix in the WSP appendix.
NAIC Model #275 โ The Suitability and Best Interest Framework
Model #275, originally adopted by the NAIC in 2010 and updated in 2020 to incorporate the best-interest standard, articulates the four producer obligations on every annuity recommendation: (1) Care Obligation โ exercise reasonable diligence, care, and skill; consider the consumer's insurance needs and financial objectives; document the basis for the recommendation. (2) Disclosure Obligation โ provide a written description of the various types of products and services the producer can offer; disclose material conflicts of interest. (3) Conflict of Interest Obligation โ identify and avoid or mitigate material conflicts. (4) Documentation Obligation โ produce a written record demonstrating the basis for the recommendation including the consumer profile information used.
The parallel to Reg BI is intentional but not identical. The dually-licensed advisor in a Model #275 state running a federal Reg BI workflow on a securities recommendation and a Model #275 workflow on an annuity recommendation for the same client must produce two documented files โ they cannot be merged into one. AI tools that pull from a shared client profile (Wealthbox or Salesforce Financial Services Cloud household record, Holistiplan tax extraction, RightCapital plan) populate both files, but the recommendation memos differ: the Reg BI memo cites ยง240.15l-1 and documents the four obligations against a securities recommendation; the Model #275 memo cites the state's adoption of Model #275 and documents the four obligations against an annuity recommendation. The supervisory architecture must produce both.
The New York Reg 187 Overlay
New York's Reg 187 ("Suitability and Best Interests in Life Insurance and Annuity Transactions") was adopted in 2018 and predates Model #275. It applies to both life insurance and annuities and is the most-prescriptive state best-interest regime in the country. For the dually-licensed advisor producing annuity recommendations in New York, Reg 187 applies on top of Model #275 (which New York has also adopted in part). The AI tool that drafts the recommendation memo must produce the documentation Reg 187 specifies โ including the consumer profile data elements the regulation enumerates and the producer's certification that the recommendation is in the consumer's best interest. The NY DFS 23 NYCRR 500 cyber overlay layers on top: the AI tool must satisfy the third-party-service-provider expectations.
AI-Generated Annuity Recommendations โ The Supervisory Pattern
The AI workflow for an annuity recommendation in 2026 looks like this for the dually-licensed advisor. The advisor or paraplanner pulls the client's profile from Wealthbox or Salesforce FSC, the planning context from RightCapital or eMoney, the tax context from Holistiplan, and any relevant estate context from Wealth.com or FP Alpha. The advisor's AI prompt โ drawn from the firm-approved prompt library โ generates a draft annuity-suitability analysis comparing two or three candidate contracts (the carrier-agnostic comparison the practice is obligated to consider under the producer's duty to evaluate reasonably available alternatives). The draft includes the cost analysis (surrender charges, mortality and expense fees, rider costs, sub-account fees for variable annuities), the income projection under realistic assumptions, the surrender-period analysis, the death-benefit feature comparison, and the rider analysis (income riders, long-term-care riders, return-of-premium provisions). The advisor reviews, applies professional judgment, and finalizes the recommendation memo.
The supervisory layer adds three required actions distinct from the IA-only or BD-only flow. State principal review under Model #275 documentation. The principal review queue under FINRA Rule 2210 covers the BD-side, the SEC Marketing Rule 206(4)-1 review covers the IA-side, and a separate principal review under the state's adoption of Model #275 covers the producer-side; in practice these three reviews can be conducted by the same designated principal on the same artifact, but the documentation must show all three reviews completed. State DOI disclosure language verification. The advisor or principal verifies the AI-generated language satisfies the state's specific disclosure requirements โ California's mandatory disclosures, New York's Reg 187 language, Colorado's fairness-testing documentation. State annuity carrier-required forms. Most carriers require their own suitability or best-interest forms; the AI workflow's role is to populate accurately, not to substitute for the carrier's required form.
The 50-State Matrix in the WSP Appendix
A practice operating in multiple states maintains a state-by-state matrix in its WSP appendix. The matrix columns: state, Model #275 adoption status, state DOI bulletin or guidance referencing AI, NY-style overlay or other state-specific best-interest framework, mandatory disclosure language elements, fairness-testing requirements, training requirements for the producer, NY DFS-style cyber overlay if any, enforcement-intensity assessment based on prior actions. The matrix is updated quarterly by the CCO or designated principal during the L4 Ch6 L1 regulatory scan and reviewed annually by outside counsel.
The matrix is load-bearing because the state-by-state variation is real and changes. As of mid-2026, the practice operating in 12 states will track approximately 12 distinct disclosure-language requirements, 6-8 distinct training-hour requirements (the NAIC suggested 4 hours; some states require more), and 3-5 state-specific AI-related bulletins or guidance documents. The matrix is the operational source-of-truth for the AI-generated annuity-recommendation prompt library โ the prompt must produce language that satisfies the most-restrictive applicable state, and the principal review verifies the state-specific elements before signoff.
Model #275 Training and the Advisor License
NAIC Model #275 requires producers to complete training (typically 4 hours) on the model regulation before selling annuities, plus 1-4 hours of carrier-product-specific training before selling a specific contract. Many adopting states have added additional CE requirements. The AI training overlay โ required by some state DOI bulletins that adopt the NAIC AI Model Bulletin โ adds AI-specific CE on top: the producer must demonstrate understanding of how the AI tool the practice uses operates, what it produces, what verification the producer applies, and what disclosures the consumer receives.
The practical operational workflow: the practice's L4 Ch5 L1 90-day adoption training program includes an annuity-AI-specific module for the dually-licensed advisors, mapped to the relevant state CE requirements. The L5 Ch4 L2 AI-literate workforce lesson develops the full continuing education curriculum. The annual ADV Part 2A amendment (L4 Ch7 L2) reflects the AI tool's annuity-specific role; the producer-license-specific filings (state-by-state) reflect the carrier and product training. The dashboard (L4 Ch5 L2) tracks completion of state-required training as an operational health item alongside the other supervisory signals.
The Marketing Rule Overlap and the "Clear and Prominent" Standard
An AI-generated annuity comparison or AI-summarized illustration shown to a client is simultaneously a marketing communication under SEC Marketing Rule 206(4)-1 (if the advisor is also IA-registered, which the dually-licensed advisor is by definition), a recordable communication under FINRA Rule 2210 (the BD-side), and a producer communication under the state DOI framework. The "clear and prominent" disclosure standard of Rule 206(4)-1 applies. The Marketing Rule's hypothetical-performance rule (under 206(4)-1) applies to any AI-generated illustration showing projected income or account values under future scenarios. The 2024-2025 AI-washing settlements (Delphia and Global Predictions) and the January 2026 SEC staff FAQs anchor the federal framing; the state DOI framework adds a parallel obligation that the AI-generated content not mislead about the contract's features, costs, or guarantees.
The practical disciplines: (1) the firm-approved prompt library encodes the disclosure language in every AI-generated annuity artifact; (2) the L4 Ch7 L1 AI-washing audit specifically covers annuity-related claims; (3) the L4 Ch7 L2 testimonial / third-party-rating / ADV / performance disclosure framework operationalizes the Marketing Rule mechanics; (4) the state DOI overlay adds the state-specific disclosure language verification in the principal review step. The CCO's supervisory architecture must produce a single coherent review that satisfies all three regimes; bifurcating the review across regimes creates exception clusters that surface as supervisory gaps.
Incident Response When an AI Annuity Recommendation Goes Wrong
The L4 Ch3 L4 AI incident response playbook applies, with three state-DOI-specific extensions. First, the state DOI complaint reporting threshold (varies by state) โ a client complaint relating to an annuity recommendation may require state DOI notification. Second, the state-specific replacement-of-existing-coverage scrutiny โ if the AI-generated recommendation involved replacing an existing annuity or life policy, state regulations on replacement transactions (most states require additional disclosure forms and a cooling-off period) apply. Third, the NY DFS 72-hour breach notification rule under 23 NYCRR 500 applies if NPI involved in the incident.
The practice's IR plan under Reg S-P 17 CFR Part 248 May 2024 amendments includes a state-DOI annex: state-by-state notification timelines, state regulator contact information, state-specific incident-report forms, and the legal hold protocol for state DOI investigations. The AI Governance Committee (L4 Ch6 L1) reviews state-DOI-related incidents as a category at its monthly meeting; standing register entries track ongoing state DOI compliance items.
How This Integrates With the L4 Strategic Plan
The dually-licensed advisor's L4 capstone (30-page strategic AI plan) explicitly includes the state DOI / NAIC AI Model Bulletin / Model #275 layer. The 10 capstone artifacts have annuity-specific additions: the readiness audit covers state DOI exposure; the three-year roadmap reflects state-specific CE; the vendor selection rationale documents the AI tool's compliance with state DOI expectations for AI use in insurance; the WSPs include the state-by-state matrix; the training plan reflects Model #275 hours; the ROI dashboard includes state-CE-completion as an operational health item; the risk register has standing entries for state DOI regulatory drift, NAIC AI Model Bulletin adoption monitoring, and Reg 187 / Colorado SB 21-169 compliance; the Marketing Rule audit covers annuity-related claims; the cybersecurity playbook reflects the NY DFS 23 NYCRR 500 overlay; the M&A-defensibility memo covers state DOI license transferability and post-close state-by-state harmonization.
The L5 Ch3 enterprise AI policy lesson develops the network-level analog for OSJs and aggregators with dually-licensed advisor populations. The L5 Ch5 L2 pricing and service tiers lesson handles the annuity-fee disclosure intersection with AI cost-to-serve changes. The L4 Ch6 L1 register and committee, plus this L4 Ch6 L2 state DOI layer, together close the L4 Ch6 chapter on risk and governance for the dually-licensed advisor practice.
Key Takeaways
- Annuity recommendations are state-regulated (insurance), not federal-securities-regulated. The dually-licensed advisor operates under three layered regimes: federal Reg BI / Marketing Rule / FINRA 2210/3110/4511 + SEC Marketing Rule 206(4)-1 + state DOI under NAIC Model #275 + NAIC AI Model Bulletin + state-specific overlays (Reg 187, Colorado SB 21-169, California DOI, NY DFS 23 NYCRR 500).
- NAIC Model #275 imposes four obligations on every annuity recommendation: Care, Disclosure, Conflict of Interest, Documentation. 48+ states have adopted some version. Parallels Reg BI but exists in a separate channel โ the dually-licensed advisor produces two recommendation memos (Reg BI for securities + Model #275 for annuities), not one merged file.
- NAIC AI Model Bulletin organizes around six domains: governance / risk management, vendor oversight, data quality, fairness and non-discrimination, transparency / disclosure, post-deployment monitoring. 30+ states have adopted variants. The L4 Ch6 L1 register's twelve risks map onto these six domains.
- Three named state variations matter most: New York DFS / Reg 187 (most prescriptive best-interest regime + 23 NYCRR 500 cyber overlay), California DOI (CPRA alignment + fairness testing), Colorado SB 21-169 (first AI-in-insurance state law with testing for unfair discrimination).
- The AI annuity workflow adds three required supervisory actions: state principal review under Model #275 documentation, state DOI disclosure language verification, state annuity carrier-required forms. All three can be done by the same designated principal on the same artifact but documentation must show all three reviews.
- 50-state matrix lives in the WSP appendix. Columns: state, Model #275 status, state DOI bulletin, overlay (NY Reg 187, Colorado SB 21-169), mandatory disclosure language, fairness testing, training hours, NY DFS cyber overlay, enforcement intensity. Updated quarterly by CCO during the L4 Ch6 L1 regulatory scan; annual outside counsel review.
- Model #275 producer training is typically 4 hours + carrier-product-specific. AI-specific CE adds an overlay in adopting states. The L4 Ch5 L1 90-day adoption program includes an annuity-AI-specific module; the L5 Ch4 L2 curriculum framework integrates with state CE.
- Incident response under Reg S-P 17 CFR Part 248 + state DOI annex. State complaint reporting thresholds vary; state replacement-of-existing-coverage rules apply if AI-recommendation replaces existing annuity / life policy; NY DFS 72-hour rule applies if NPI involved.
- The L4 capstone explicitly accommodates the dually-licensed advisor. All 10 capstone artifacts have annuity-specific additions; L5 Ch3 enterprise policy and L5 Ch5 L2 pricing lessons extend the framework forward.
Skill.re