Updated October 1, 2026.
Direct answer: AI underwriting remains legal in the U.S. and EU, but 2026 exams expect written governance, quantitative unfair-discrimination testing, explainability, and carrier accountability for vendor models. Twenty-five states plus D.C. have adopted the NAIC insurer AI bulletin; Colorado enforces SB21-169; New York applies Circular Letter No. 7; the NAIC twelve-state AI Systems Evaluation Tool pilot ran March–September 2026. EU Annex III high-risk duties for life and health pricing AI start 2 December 2027; Article 50 transparency already applies.
State insurance commissioners are examining carrier underwriting algorithms with blunt questions: What variables are in the model? How did you test for discrimination? Can you show pricing does not track protected classes? Without exam-ready documentation, carriers face market conduct exams and corrective orders.
Regulators moved from passive oversight to algorithmic scrutiny—driven by disparate-impact methods, proxy-variable evidence, NAIC guidance, and pressure to keep coverage accessible. Carriers that shipped models without documented bias testing are in the reckoning now.
The Regulatory Scrutiny Accelerates
NYDFS, California DOI, and regulators in Texas, Florida, Colorado, and Pennsylvania embed AI reviews in underwriting, pricing, and claims work. They want proof of non-discrimination and human explainability where required.
Impact need not be intentional. Credit attributes, geography, and occupation codes can proxy protected classes and produce disparate outcomes without naming race or gender in code.
Examiners expect variable documentation, quantitative protected-class testing, actuarial justification, and appeal paths— the same discipline as licensing and examination programs, applied to model inventories. In 2026, NAIC pilot states sent Exhibit A–D requests; carriers that skipped retesting after retrains are seeing findings, not informal follow-ups.
The Underwriting Algorithm Governance Gap
Many carriers optimized accuracy and speed without unfair-discrimination protocols or retained evidence. Even internal bias runs rarely produced protocols, sample design, or remediation logs when four-fifths ratios slipped.
Variable justification: Inputs must predict loss, not demographics.
Disparate impact testing: Measure approvals and premiums by protected class where data allows; “we didn’t code bias” is not a defense.
Vendor risk: Third-party engines stay on the carrier’s balance sheet—audit rights and test artifacts required. See AI underwriting compliance and algorithmic accountability.
Drift: Retrain triggers retest.
Claims AI and Algorithmic Disclosure
States ask what share of claims are auto-routed, which payments or denials are algorithm-final, and whether claimants reach a human. AI handlers without escalation draw fair-claims scrutiny.
Disclose AI interaction, log overrides, and document appeals. See claims management and carrier claim evaluation for file standards.
Cyber and E&O Coverage Gaps
Cyber and E&O forms rarely clearly cover algorithmic error or discrimination fines. Specialty coverage talks are active; place cyber with AI-driven cyber market evolution in view.
Accountability Minimums for 2026
Inventory every underwriting and claims model; run documented disparate-impact tests; actuarially sign off inputs; disclose escalation; govern vendors; report inventory and test results to the board annually—aligned with regulatory compliance reporting.
Timeline
March–September 2026: NAIC AI Systems Evaluation Tool pilot (CA, CO, CT, FL, IA, LA, MD, PA, RI, VT, VA, WI).
Fall 2026: Tool updates and possible adoption at the November NAIC meeting.
2026–2027: Mississippi adopted the bulletin July 2026; Colorado auto/health testing rulemaking continues; EU Annex III insurance pricing duties begin 2 December 2027.
Regulatory Landscape at a Glance
| Framework | Jurisdiction | Requires | Status (Oct 2026) |
|---|---|---|---|
| NAIC AI Model Bulletin | U.S. states | AIS program, testing, vendor oversight, documentation | 26 jurisdictions (25 states + D.C.) on NAIC map Aug 31, 2026; MS Bulletin 2026-9 (Jul 22, 2026) latest adopter. |
| SB21-169 / Reg 10-1-1 | Colorado | Governance + quantitative unfair-discrimination testing | Binding; life since 2023; auto/health extensions effective Oct 15, 2025; testing rules in rulemaking. |
| Circular Letter No. 7 | New York | Discrimination analysis, actuarial validity, vendor oversight | Final Jul 11, 2024. |
| EU AI Act Annex III 5(c) | EU | High-risk risk management, oversight, FRIA | Annex III standalone duties from 2 Dec 2027 (Digital Omnibus); Art. 50 transparency from 2 Aug 2026. |
| NAIC Evaluation Tool pilot | 12 pilot states | Exhibits A–D on usage, governance, high-risk AI, data | Pilot closed Sep 2026; feeds Fall 2026 tool revision. |
Core pillars
- Testing for disparate impact and documented remediation.
- Explainability for underwriting and pricing outcomes.
- Vendor oversight with audit rights and monitoring.
- Written governance and inventory—see also regulatory convergence in 2026.
Frequently Asked Questions
Is AI underwriting legal?
Yes. Using AI in insurance underwriting and pricing is legal in the United States and the European Union. It is increasingly regulated: insurers must test for unfair discrimination, maintain documented governance, explain material decisions, and remain accountable for vendor-built models. Colorado’s requirements are binding law; most NAIC bulletin states enforce expectations through market conduct exams.
What is the NAIC AI Model Bulletin?
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers sets expectations for written AI Systems programs, senior accountability, unfair-discrimination testing, vendor oversight, and examinable documentation. As of the NAIC adoption map dated August 31, 2026, 25 states and the District of Columbia have adopted it—26 jurisdictions total—making it the de facto U.S. baseline for insurer AI governance.
Does the EU AI Act cover insurance?
Yes. Annex III point 5(c) classifies AI used for risk assessment and pricing of natural persons in life and health insurance as high-risk. Annex III standalone obligations apply from 2 December 2027 after the Digital Omnibus delay. Article 50 transparency duties and broader governance rules already apply from 2 August 2026.
How do insurers test AI for bias?
Insurers run quantitative disparate-impact testing on models affecting eligibility or price. A common benchmark is the four-fifths rule: a ratio below 0.8 between a protected class and a reference group signals potential unfair discrimination. Testing focuses on proxy variables—ZIP code, occupation, education, vehicle type, credit-based attributes—and documents ratios, data, proxies, remediation, and retest cadence.
What does Colorado’s SB21-169 require?
SB21-169 and Regulation 10-1-1 require a risk-based governance framework and quantitative testing of external data, algorithms, and predictive models for unfair discrimination across listed protected classes, with progress and annual compliance reporting. Life insurers were first in scope; amended rules extended the framework toward private passenger auto and health benefit plans effective October 15, 2025, with further testing rules in rulemaking in 2026.
Who is accountable when a vendor AI model discriminates?
The insurer. Under the NAIC bulletin, NYDFS Circular Letter No. 7, and Colorado rules, the carrier remains accountable for vendor models used in regulated underwriting or pricing. Insurers need due diligence records, audit rights, use-case validation, and ongoing monitoring. “The vendor built it” is not a defense in examination.
Related: More in Regulatory Compliance. Back to Risk Coverage Hub.