CLIENT ALERT
AI regulation in insurance: A crossroads
September 28, 2026
Read time: 10 min
The United States approaches a “fork in the road” on AI development, while state insurance regulators continue enhancing their examination powers.
In a summer full of headlines, discussion regarding an elevated concern over safety and regulation of artificial intelligence (AI) may be what we remember most. Reported AI safety incidents followed growing public concern, fueled by discussion among experts and commentators, that AI development may be outpacing safety efforts, particularly around self-improving systems (recursive self-improvement, or RSI). Reactions from the AI industry, government, and media reignited debate over federal regulation versus industry self-regulation, with some calling for a pause in AI development and others pushing to move full speed ahead in pursuit of US dominance.
With competing proposals in Congress unlikely to advance in the near term, the question of how to manage liability for frontier AI development remains unresolved. Some in the government and the industry oppose a liability shield for AI developers, arguing that exposure to liability is precisely what compels them to adopt robust risk management practices. At the same time, the insurance industry continues to weigh how far it is willing to go in covering AI-related risks.
Against this backdrop, state insurance regulators are forging ahead with plans to apply their existing statutory and examination authority to insurers’ use of AI. We summarize a few recent developments below.
NAIC governance framework – AI risk evaluation supplement
We detailed in prior reports the work, since 2019, of state insurance regulators to regulate AI, primarily through the National Association of Insurance Commissioners (NAIC). Regulators have expressed concern over various safety and related risks, including the potential for AI systems to produce biased or discriminatory outcomes for consumers, limited transparency into automated decision-making, insufficient human review of generative AI, and data privacy.
To date, roughly half the states have adopted the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (Model Bulletin), which outlines a comprehensive governance framework for insurers’ use of AI and machine learning (ML). In addition to New York, other states have expanded on these principles, with examples summarized below. Colorado remains the only state imposing new requirements via legislation, though implementing rules have yet to be adopted, and there seems to be uncertainty around overall AI regulation in the state.
The NAIC is nearing completion of its AI Risk Evaluation Supplement (Supplement) (renamed from the AI Systems Evaluation Tool) as a practical examination-level framework for state regulators to assess AI governance practices of insurers. On August 31, 2026, the NAIC’s Big Data Working Group exposed version 5.0 of the Supplement for a 30-day public comment period ending September 29, 2026. This version of the Supplement reflects feedback from a 12-state1 pilot that began in March 2026. A final version is targeted for adoption at the NAIC Fall National Meeting in November. Insurers (including those domiciled outside the pilot states) should anticipate that the Supplement will serve as the standard framework for AI-related regulatory inquiries going forward.
The Supplement is designed to complement existing market conduct, financial analysis, and financial examination procedures. It includes optional exhibits for regulators to assess an insurer’s AI usage, governance practices, high-risk models, and data inputs. The 12 pilot states have been using the Supplement for market conduct exams, financial exams, financial analyses, and general regulatory inquiries for companies across property/casualty, life, and health lines.
The Supplement has the potential for indirect regulation of managing general agents, third-party administrators, and other third parties. Exhibit B of the Supplement, which evaluates an insurer’s AI Systems Program of controls for managing AI risk, asks insurers to explain oversight of third-party models and identify models operating inside the insurer’s system, including any AI embedded in third-party products. Third parties should expect their insurer partners to flow down documentation, audit, and disclosure requirements to support the insurer’s response to such regulatory inquiries.
Version 5.0 expands the Supplement’s scope to ML and general language models, meaning insurers deploying these technologies can now expect regulators to ask specifically about those systems and the governance surrounding them. Other key changes include clarified definitions aligned with the NAIC Financial Condition Examiners Handbook, a clearer distinction between AI “systems” and AI “models,” tightened materiality language, and additional questions on third-party oversight.
Following the close of written comments, the Big Data Working Group has tentatively scheduled a public meeting on October 8, 2026, to hear verbal comments. A subsequent version will then be exposed for a 14-day comment period in October, with a final version targeted for adoption at the NAIC Fall National Meeting in November 2026.
The NAIC’s Third-Party Data and Models Working Group continues to develop its Risk-Based Regulatory Framework for Third-Party Data and Model Vendors (Third-Party Framework), which is intended to provide regulatory oversight of third-party data and predictive models. The Third-Party Framework includes a broad definition of “third party,” which covers organizations providing data, models, or model outputs to insurers for use in pricing, underwriting, claims, marketing, or fraud detection, such as insurtech vendors, data aggregators, and AI platform providers.
The Working Group may produce a model law on this topic in 2026/2027. If ultimately adopted by the NAIC and implemented in a given state, the Third-Party Framework may result in the indirect regulation of third-party models as insurers remain accountable under state insurance laws for their use of such models. Insurers may seek to flow down compliance obligations.
Puerto Rico data call
The Office of the Commissioner of Insurance of Puerto Rico issued Information Requirement No. IE-0719-2026 (Data Call) to authorized insurers in early September 2026 to gather information regarding the degree and scope of their AI use. Insurers must identify AI systems they currently use, have used, or are in the process of implementing or testing, including systems developed internally or acquired or licensed from third parties, and AI embedded into other systems or platforms that it uses. The Data Call covers a broad range of AI uses across the organization, including
- underwriting, claims, customer service, fraud detection and prevention, marketing, sales, compliance, risk analysis, document processing, human resources, operations, investments, and data analysis;
- AI interactions with consumers and other individuals; the purpose, technology type, and provider or developer of each AI system;
- whether AI supports or influences insurance-related decisions;
- human oversight of AI-generated recommendations or decisions; AI policies, procedures, and controls;
- implementation dates and general categories of data used; and
- AI-related incidents, complaints, disputes, or corrective actions during the past three years; and other significant AI uses.
The Data Call also expects insurers to explain how consumers, insureds, claimants, applicants, producers, or other individuals are informed when they interact directly with an AI tool, system, or agent, including the timing and means of disclosure. Responses to the Data Call, using a prescribed form, were due within five calendar days of notification, though we understand the regulator has granted extensions.
Colorado
Insurers and, indirectly, their agents writing in Colorado face a unique regulatory framework with insurance-specific and generally applicable legislation. 2021 legislation requires prescribed testing by insurers before using AI/ML (broadly defined as external consumer data information sources) to prevent unfair discrimination on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression. The legislation applies to insurers writing personal lines (auto, homeowners, life, health) and/or small commercial insurance. The Colorado Division of Insurance has been working for several years on regulations to implement the legislation for each separate insurance line.
The Automated Decision-Making Technology (ADMT) Act (SB 26-189) repealed and replaced the 2024 Colorado AI Act (SB 24-205). The ADMT Act, enforced by the state’s attorney general, regulates ADMT, used in business generally, that materially influences “consequential decisions” concerning a consumer, including decisions relating to a consumer’s access to or eligibility for a “covered domain,” or the pricing or other material terms on which it is provided. Insurance is expressly a “covered domain” under the Act, and includes “underwriting, pricing, coverage, claims adjudication or other determinations that materially affect access to benefits.”
SB 26-189 replaces the heavy administrative burdens of SB 24-205 with certain requirements for transparency, notice, and consumer recourse for the use of automated decision-making technology in consequential decisions. ADMT developers must provide deployers with technical documentation covering intended uses, training data, known limitations, and instructions for human review, while deployers must provide consumers with notice and plain-language disclosures following adverse outcomes.
Similar to other states, Colorado also enacted the Conversational Artificial Intelligence Services Act (HB 26-1263) (Chatbot Safety Act) on May 29, 2026. The Chatbot Safety Act subjects any operators of conversational AI services to AI disclosure, self-harm response protocols, and restrictions on representing chatbot outputs as equivalent to licensed professional services. Conversational AI services include answering frequently asked questions (FAQs), helping with website navigation, and facilitating account set-up.
Both the ADMT Act and the Chatbot Safety Act take effect January 1, 2027. The Colorado Department of Law filed proposed draft regulations on August 11, 2026, with comments due October 26, 2026.
Arizona: Draft AI Bulletin
The Arizona Department of Insurance and Financial Institutions (DIFI) issued earlier in September a notice of an opportunity to comment on a draft AI Bulletin outlining the DIFI’s expectations regarding AI use and advise insurers on information the DIFI may request (Proposed DIFI Bulletin). The Proposed DIFI Bulletin targets insurer AI use but its stated scope “applies to all DIFI-regulated entities that engage in the business of insurance in Arizona.” The Proposed DIFI Bulletin adopts the NAIC Model Bulletin’s core principles (but omits certain elements), while most notably proposing to require a human to approve any consequential decision made by AI. (A Texas Department of Insurance Bulletin issued in June purports to impose a similar requirement.) Comments on the Proposed DIFI Bulletin are due October 9, 2026.
New York: RAISE Act
On September 21, 2026, Governor Hochul announced steps to implement New York’s Responsible AI Safety and Education (RAISE) Act, which establishes safety, transparency, and reporting requirements for “frontier developers.” A frontier developer is generally a person that has trained, or initiated the training of, a frontier model using, or intending to use, at least the amount of computing power specified under the RAISE Act. “Frontier models” are generally defined as foundation models trained using more than 10^26 integer or floating-point operations.
The RAISE Act imposes heightened obligations on “large frontier developers,” meaning those that, together with their affiliates, had annual gross revenues exceeding $500 million in the preceding calendar year. Beginning in November 2026, large frontier developers will be directed to register with New York State. Once the RAISE Act takes effect on January 1, 2027, they will also be subject to requirements relating to safety and transparency frameworks, critical safety incident reporting, and catastrophic-risk assessments.
The RAISE Act will be administered by the new Office of Digital Innovation, Governance, Integrity and Trust within NYDFS, giving NYDFS an administrative role extending beyond its traditional oversight of insurers and financial institutions. The RAISE Act is not insurance-specific and will not generally apply to insurers or producers merely because they use third-party AI tools for underwriting, claims, or other functions.
Takeaways
More headlines and debate over the evolution and safety of AI/ML are a certainty, as is the impact of state insurance regulation on AI/ML use in the industry. Coupled with generally applicable state and federal regulation of model builders and deployers, we expect no pause in the number of developments to follow (with AI’s help) that could impact the insurance industry. And don’t be surprised if the AI liability insurance market has a major influence.