The regulator already arrived
The NAIC Model Bulletin on the use of AI has now been adopted by roughly half the states, and the NAIC publishes a map of exactly which ones. If you write in more than a couple of jurisdictions, you are already inside it, whether or not your program has caught up. Transparency, explainability, and non-discrimination are no longer positions a carrier takes. They are things a carrier gets asked to demonstrate.
Most claims organizations I talk to treat that as the brake. Legal is the reason the pilot has not shipped, the vendor's model is a black box, and the program is waiting on a governance review that keeps getting rescheduled.
I think that reads your situation exactly backwards. Every carrier faces the same bulletin. The ones moving fastest right now are the ones who can answer the question when it arrives, without pausing the program to go find out.
Explainability is the thing that lets you deploy at all.
Why I can make that argument
At Yembo I built computer vision that assesses property from video and put it into production claims and inspection workflows in more than 20 countries. I also took that platform through ISO 27001, SOC 2 Type II, GDPR, and NIST 800-171, so I have been on the receiving end of the questions your compliance team is about to ask, and I know which of them are real.
That is the useful half of the talk. Not that AI can read a photo of a damaged roof, which your team already believes and your competitors already do, but which controls a claims model genuinely needs, which ones are theater, and what it costs to retrofit the difference after a program has already shipped.
When your leadership wants to work rather than listen, the 60-Minute Security Audit takes them through the data-handling questions directly, my work on AI for customer service covers the claims contact center, and AI for fine art logistics covers the documentation side of a contested high-value claim.