There is no single federal law governing how artificial intelligence may be used in insurance underwriting, claims, pricing, or sales. Instead, the United States regulates AI in insurance through a patchwork of state-level rules, model laws adopted by the National Association of Insurance Commissioners (NAIC), and sector-specific enforcement by state insurance departments. As of August 2026, the differences between states are substantial enough that a carrier, MGU, or broker operating nationally must effectively build a compliance matrix rather than follow one rulebook. This article compares how the major regulatory approaches differ, what they require in practice, and where the gaps and contradictions sit.
The Direct Answer: Three Regulatory Models Dominate
Also worth reading: What are the key AI insurance fairness regulations coming into effect in 2026 and how should insurers prepare? · What are the e-bike insurance discount requirements for 2026 and how do new regulations affect premiums? · How does algorithmic auditing ensure insurance compliance with emerging AI regulations?
State approaches to AI in insurance fall into three broad camps as of mid-2026. The first camp is adoption of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, which was issued in December 2023 and has since been adopted, in full or modified form, by more than half the states. States in this camp — including Colorado, Connecticut, Illinois, Ohio, Pennsylvania, Texas, and others — require insurers to maintain an AI governance program covering risk management, internal controls, and third-party vendor oversight when AI is used in any regulated activity.
The second camp consists of states that have gone beyond the NAIC bulletin with their own statutes or regulations. Colorado is the clearest example: its Division of Insurance finalized life insurance-specific rules (Regulation 3-6-1) requiring insurers to test external consumer data and information sources (ECDIS) and algorithms for unfair discrimination, with documented testing evidence available on request. New York's Department of Financial Services issued Circular Letter No. 7 (2024) on AI in underwriting and pricing for life insurance, emphasizing that use of AI does not change existing prohibitions on unfair discrimination under Insurance Law Article 26. California, meanwhile, has pursued both regulatory action and political attention — the 2026 race for insurance commissioner featured multiple candidates campaigning explicitly on AI oversight of pricing models, signaling likely new rulemaking after the election.
The third camp comprises states with little or no AI-specific insurance regulation, relying instead on general unfair trade practices statutes and rate filing review. In those states, an insurer using an algorithmic pricing model faces essentially the same scrutiny it would have faced in 2015, which critics argue leaves consumers exposed to proxy discrimination embedded in data sources such as credit-based scores, telematics, and social media-derived variables.
Why State Regulation Diverged From Federal Action
The reason for the state patchwork is structural. Insurance is regulated primarily at the state level under the McCarran-Ferguson Act of 1945, which delegates ratemaking, solvency, and market conduct authority to state insurance departments. When Congress failed to pass comprehensive AI legislation — proposals like the Algorithmic Accountability Act stalled repeatedly between 2022 and 2025 — the NAIC filled the vacuum with its Model Bulletin, and individual states moved at different speeds based on their political composition and market characteristics.
The result is timing divergence that matters operationally. Colorado's ECDIS rules took effect in phases beginning November 2023 and were fully applicable to life insurers by 2024. The NAIC bulletin adoptions rolled out from late 2023 through 2026, each with slightly different definitions of "artificial intelligence system" and different documentation thresholds. Separately, broader AI statutes are arriving that touch insurance indirectly: Illinois' AI Safety Measures Act (SB 315), signed into law with compliance obligations for frontier AI developers phasing in before January 2028, imposes transparency and safety-testing duties that will reach insurers indirectly through their vendors. Any national carrier therefore faces overlapping obligations from insurance regulators, general AI statutes, and consumer protection enforcement — often with conflicting documentation demands.
Comparison Table: Key State Approaches to AI in Insurance
| Feature | Colorado | New York | Illinois | Texas / Ohio (NAIC adopters) |
|---|---|---|---|---|
| Primary instrument | Reg. 3-6-1 (ECDIS testing) | DFS Circular Letter No. 7 (2024) | SB 315 + NAIC-style bulletin | NAIC Model Bulletin adoption |
| Scope | Life insurance ECDIS and algorithms | Underwriting and pricing, all lines via existing anti-discrimination law | Frontier AI developer duties; insurance governance bulletin | Governance programs for any AI in regulated activities |
| Testing requirement | Documented bias testing of external data sources before and during use | No new test mandate; existing unfair discrimination standards apply | Vendor-side safety testing phased in before Jan 2028 | Risk-based governance; testing expected but not prescribed |
| Documentation | Evidence retained and producible on regulator request | Explanations owed to consumers on adverse action | Developer transparency reports | Internal controls records per bulletin language |
| Effective dates | Phased from Nov 2023; fully operative 2024–2025 | Guidance effective upon issuance (2024); enforced via exams | Compliance milestones through Jan 2028 | Varies by state, mostly 2024–2026 |
| Enforcement posture | Active exam focus on life carriers | Market conduct exams using existing law | Emerging; penalties tied to general AI statute | Bulletin-based; exam-driven |
What the Rules Actually Require in Practice
Strip away the legal language and most state requirements converge on four operational duties. First, governance: an insurer must designate who owns AI risk, typically a committee spanning actuarial, compliance, IT, and legal functions, and document that structure. Second, inventory: every AI system used in underwriting, rating, claims triage, fraud detection, or marketing must be catalogued, including third-party tools and vendor models, because regulators have made clear that outsourcing does not outsource accountability.
Third, testing and validation: carriers must show that models do not produce unfairly discriminatory outcomes against protected classes, whether directly or through proxies. Colorado's framework is the most prescriptive here, requiring pre-use testing of ECDIS and ongoing monitoring, but even bulletin-only states expect validation evidence during market conduct exams. Fourth, explainability and adverse action: when AI contributes to an adverse underwriting decision, the carrier must be able to explain the basis in terms a consumer and a regulator can understand. New York's circular letter stresses that complexity of a model is not an acceptable defense for an unexplainable discriminatory outcome.
For brokers and agencies, the obligations are lighter but real. Several state bulletins extend expectations to producers who use AI tools for lead scoring, quote generation, or client communication. An agency deploying an AI chatbot that gives policy advice can be held to suitability and licensing standards, and misrepresentation by an automated tool is treated as misrepresentation by the licensee.
Where the Approaches Conflict or Fall Short
The comparison reveals genuine friction points. Definitions diverge: some states define AI narrowly around machine learning, while others include rule-based automation and predictive analytics, meaning a simple GLM rating model may be "AI" in one jurisdiction and not another. Documentation thresholds conflict: Colorado wants granular testing artifacts, while some bulletin states accept high-level governance summaries, forcing multi-state carriers to produce two tiers of evidence for the same model.
Enforcement capacity is uneven. State insurance departments vary enormously in staffing and technical expertise; a department with two analytics staff cannot audit the same way as one with a dedicated innovation unit. This creates de facto unevenness where identical conduct draws scrutiny in one state and passes unnoticed in another. There is also a coverage gap: health insurance AI used in utilization management and claim denials has drawn federal attention from CMS and congressional hearings — including joint state legislative hearings such as the Illinois House and Senate committees' examination of AI in healthcare licensing and insurance — but state insurance AI frameworks largely target life and P&C underwriting, leaving utilization-review algorithms governed mainly by ERISA and Medicare Advantage rules rather than the new state AI regimes.
Finally, rate regulation creates tension. Carriers argue that aggressive disclosure and testing mandates slow filings and delay competitive pricing; consumer advocates counter that without them, proxy discrimination persists. Both points have merit, and the honest assessment is that no state has yet found a calibration that satisfies carriers, regulators, and consumer groups simultaneously.
Practical Steps for Insurers and Brokers Operating Multi-State
A workable compliance approach starts with a state-by-state applicability matrix. Map every AI system in your stack — including vendor-provided scoring, telematics analytics, document processing, and chatbots — against each state's definition and scope. Systems touching life underwriting should be tested to the Colorado standard regardless of where they operate, because building to the strictest regime is cheaper than maintaining parallel versions.
Second, centralize governance documentation so it can be sliced per jurisdiction. One model inventory, one testing repository, and one incident log, tagged by state requirement, avoids duplicative work. Third, contractually flow down obligations to vendors: require model cards, training-data summaries, and cooperation with your testing. Regulators increasingly ask not just what you did but what your vendor refused to tell you. Fourth, prepare for exam requests now — several departments have begun asking for AI inventories during routine market conduct exams rather than waiting for dedicated AI exams.
Brokers should add two items: verify that any AI-assisted recommendation tool preserves agent accountability and produces auditable logs, and check whether your errors-and-omissions policy contemplates algorithmic errors. The emerging AI agent liability insurance market — projected by analysts such as Fact.MR to grow substantially through 2036 — offers standalone coverage, but terms vary widely and exclusions for "model drift" or "training data defects" are common enough to read carefully.
Common Mistakes That Draw Regulatory Attention
The most frequent error is treating the NAIC bulletin as a one-time attestation exercise. Departments that adopted it expect living governance programs; a binder produced in 2024 and untouched since will read poorly in a 2026 exam. The second mistake is ignoring third-party systems. Several enforcement actions and exam findings have centered on vendor-supplied scores the carrier never validated, on the theory that reliance without diligence is itself a control failure.
The third mistake is conflating explainability with accuracy. A model can be highly predictive and still unexplainable at the level required for adverse action notices, and regulators care about the latter in consumer disputes. The fourth is assuming health-line AI is covered by these frameworks — much of it is not, and carriers deploying utilization-management AI have been surprised by scrutiny arriving through Medicaid and Medicare channels instead. Fifth, smaller carriers sometimes assume scale exemptions exist; most state instruments contain none, though proportionality in documentation depth is generally accepted.
Timing: What Changes Between Now and 2028
Between August 2026 and January 2028, three developments are reasonably predictable. More states will adopt or amend the NAIC bulletin, continuing the trend that brought adoption past the majority mark. California's post-election insurance commissioner is likely to advance AI-related rulemaking given how prominently it featured in the campaign among the leading candidates. And Illinois' SB 315 milestones will begin binding frontier AI developers whose tools feed insurance workflows, pushing vendor transparency obligations upstream into carrier contracts.
Carriers and brokers with national footprints should treat 2026–2027 as the window to build durable governance infrastructure, because retrofitting documentation after an exam notice arrives is far more expensive than maintaining it continuously. Firms operating in only one or two states can calibrate narrowly, but should monitor neighboring jurisdictions if expansion is planned within three years.
Cost Considerations
Compliance costs scale with model count and state footprint. For a mid-size regional carrier, industry estimates place initial AI governance build-out — inventory, testing protocols, documentation, and staff or consultant time — in the low hundreds of thousands of dollars, with annual maintenance typically a fraction of that. Large national carriers report multi-million-dollar programs spanning dozens of models and all fifty states plus DC. For independent agencies and small brokers, costs are modest: most obligations involve vendor due diligence, logging, and procedure updates achievable for under $25,000 annually, often absorbed into existing compliance budgets. Standalone AI liability coverage for technology errors adds premium cost, with pricing driven by revenue, model exposure, and claims history rather than fixed rates.
Bottom Line
Comparing state AI insurance regulations in 2026 means comparing degrees of the same idea: every serious framework demands governance, testing, documentation, and explainability, but they differ in specificity, scope, and enforcement muscle. Colorado sets the testing benchmark, New York anchors enforcement in existing anti-discrimination law, Illinois extends obligations upstream to developers, and NAIC-bulletin states provide a flexible middle ground. No federal backstop exists, so multi-state operators must build to the strictest standard and tag documentation by jurisdiction. The firms that treat this as continuous operational discipline rather than periodic paperwork will spend less, fail fewer exams, and face fewer surprises as the remaining states legislate through 2028.