Insurance · AI rules for insurers
The rules on insurers’ AI, jurisdiction by jurisdiction.
Insurance supervisors now say what they expect when an insurer uses AI: a written program, named people answerable for it, testing, records a supervisor can ask for, and responsibility for a vendor’s models. This page sets out where each rule stands, what it asks of an insurer in plain words, and links to the primary document.
At a glance
Where the rules stand.
The tracker
What each rule asks of an insurer.
| Jurisdiction and instrument | What it asks of an insurer | Status and date | Evidence it asks for |
|---|---|---|---|
| United States | |||
| NAIC model, adopted state by stateNAIC Model Bulletin: Use of Artificial Intelligence Systems by InsurersOn this site: the bulletin, section by section | A written AI Systems Program for every AI system that makes or supports decisions in regulated insurance practices, owned by senior management and reported to the board. It covers risk management and internal controls, testing and validation, and AI systems and data bought from third parties. Section 4 lists what the Department can request in an investigation or market conduct action. | Model adoptedAdopted by the NAIC Executive Committee and Plenary, 4 December 2023. In force in each state that adopts it: see the state table below. | The written program, proof it was adopted and operates, records of validation, testing and audit, and the diligence done on each vendor’s system. |
| ColoradoRegulation 10-1-1, 3 CCR 702-10, risk management framework for external consumer data, algorithms and predictive models, made under SB21-169Related on this site: Colorado SB 26-189, automated decisions | Life, private passenger auto and health benefit plan insurers that use external consumer data, or algorithms and models built on it, keep a risk-based framework overseen by the board, with senior management accountable. It includes documented policies for design, testing, use and monitoring, an inventory with version control, a record of quantitative testing for unfair discrimination, and oversight of third-party vendors. Health insurers keep a provider responsible for prior and concurrent authorization decisions informed by these models. | In forceSB21-169 signed 6 July 2021. Regulation effective 14 November 2023 for life insurers. Amended regulation effective 15 October 2025, extending it to auto and health insurers, whose framework is due on request from 1 July 2026, with an annual report from the same date. | An inventory with version control, test methods and results, the title and qualifications of the person responsible for each requirement, and a report signed by an officer attesting to compliance. |
| New YorkDFS Insurance Circular Letter No. 7 (2024), use of AI systems and external consumer data in underwriting and ratingRelated on this site: NYDFS 23 NYCRR Part 500 | Before using AI systems or external consumer data in underwriting or rating, an insurer shows through a comprehensive assessment that the result is not unfairly or unlawfully discriminatory. The board sets direction, senior management runs it day to day, written policies are reviewed, and the insurer stays responsible for tools supplied by vendors. Applies to underwriting and rating only. | IssuedCircular Letter No. 7, 11 July 2024. | Comprehensive documentation of every AI system and data source, including a vendor’s, ready for the Department on request, and the specific reasons and data sources behind each adverse underwriting or rating decision. |
| CaliforniaInsurance Commissioner Bulletin 2022-5, bias and unfair discrimination in marketing, rating, underwriting and claims | Insurers and licensees avoid conscious and unconscious bias from AI and big data in marketing, rating, underwriting, claims and fraud investigation. When a complex algorithm is used in a declination, limitation, premium increase or other adverse action, the specific reason is given. | IssuedBulletin 2022-5, 30 June 2022. | The specific reason for each adverse action, including one reached with a complex algorithm. |
| CaliforniaSB 1120, AI in utilization review and utilization management | A health plan or disability insurer that uses AI, an algorithm or other software in utilization review, directly or through a contractor, meets set requirements, including fair and equitable application. A determination of medical necessity is made only by a licensed physician or licensed health care professional, and the tool is open to inspection for audit or compliance review by the department. | EnactedChapter 879, Statutes of 2024. Approved by the Governor 28 September 2024. | Who made each medical necessity decision, and a tool that can be audited. |
| TexasCommissioner’s Bulletin B-0036-20, insurers’ use of third-party data | Regulated entities are responsible for the accuracy of the data they use in rating, underwriting and claims handling, including data a third party supplies. TDI encourages insurers to give policyholders a way to review and correct that data. | Issued30 September 2020. | Where each data point came from, and that it was accurate. |
| TexasCommissioner’s Bulletin B-0003-26, use of artificial intelligence | Addressed to all regulated entities and their agents and representatives. Where AI is used to make a consequential decision, TDI expects a person to review and agree with all decisions before action is taken. Entities can furnish their procedures and protections on request, and the expectations extend to any third party working with a regulated entity. | Issued12 June 2026. | The person who reviewed and agreed to each consequential decision, before action was taken. |
| NAIC, work in progressBig Data and Artificial Intelligence (H) Working Group, AI Risk Evaluation Supplement (AI Systems Evaluation Tool) | A common supplement state regulators use when they examine an insurer’s AI. The updated draft asks for a model inventory, defines agentic AI, and adds questions on explainability and transparency, materiality, and how the insurer oversees third-party models. | Under discussionUpdated draft after a multi-state pilot. Public call 8 October 2026. | A model inventory, the documents of the insurer’s AI program, and how third-party models are overseen. |
| NAIC, work in progressThird-Party Data and Models (H) Working Group, framework for third-party data and model vendors in property and casualty rating and underwriting | A proposed framework for regulatory oversight of third-party data and predictive models, so that regulators have timely access to vendors’ data and models. | ProposedExposed for public comment. Comment period closed 5 August 2026. | Regulator access to the data and models a vendor supplies to an insurer. |
| European Union | |||
| EU AI ActRegulation (EU) 2024/1689, Annex III point 5(c), with Article 26 and Article 27On this site: Articles 9, 13, 14 and 15 · Article 12, event logging | AI used for risk assessment and price setting for natural persons in life and health insurance is high-risk. An insurer deploying it assigns human oversight to people with the competence, training and authority to exercise it, keeps the logs the system generates, and carries out a fundamental rights impact assessment before deploying it. | Adopted, applies laterHigh-risk rules for Annex III systems apply from 2 December 2027, under Article 113 as amended by the AI Omnibus, in force 27 July 2026. | Automatically generated logs kept for at least six months, the named people assigned to oversight, and the impact assessment. |
| EIOPAEIOPA Opinion on AI risk management and oversight, EIOPA-BoS-25-360Related on this site: DORA, Regulation 2022/2554 | Addressed to national supervisors, it reads Solvency II, the Insurance Distribution Directive and DORA for AI used by insurers and intermediaries. It asks for risk-based, proportionate controls covering fairness and ethics, data quality, documentation and record keeping, transparency and explainability, human oversight, and accuracy, robustness and cybersecurity. The management body is responsible for the overall use of AI, with roles and escalation set out in policy. | Published6 August 2025. | Records of training and testing data and modelling methods, enough to reproduce and trace results, and defined roles and escalation routes for oversight. |
| United Kingdom | |||
| FCAFCA AI Update, further to the Government’s response to the AI White Paper | The FCA applies its existing rules to AI. The Consumer Duty asks firms to deliver good outcomes for retail customers, and the FCA says AI that embeds or amplifies bias, leading to worse outcomes for some groups, can fall short of acting in good faith. For dual-regulated insurers and Enhanced firms under the Senior Managers and Certification Regime, any use of AI in an activity, business area or function falls within a senior manager’s responsibilities. SYSC covers systems, controls and outsourcing, with SYSC 13 for insurers. | Published22 April 2024. | A named senior manager answerable for each use of AI, and evidence of the outcomes customers receive. |
| Bank of England and PRALetter on the Bank and PRA approach to AI, to the Secretary of State for Science, Innovation and Technology and the Economic Secretary to the Treasury | Material use of AI in an activity or business area sits within a senior manager’s responsibilities, set out for Solvency II firms in the PRA Rulebook. Insurers keep processes for the completeness, accuracy and appropriateness of data used in technical provisions and internal models. The PRA’s model risk statement, SS1/23, is written for banks. | Published22 April 2024. | The senior manager accountable for each material use of AI, and data controls an examiner can test. |
| International and other jurisdictions | |||
| IAISApplication Paper on the supervision of artificial intelligence | Sets out how the Insurance Core Principles apply to AI across five topics: risk-based supervision and proportionality; accountability; robustness, safety and security; transparency and explainability; fairness, ethics and redress. The board’s oversight extends to risk management and internal controls for AI. | FinalPublished 2 July 2025. | Event logs recording all meaningful activity of an AI system, made available to supervisors and auditors so they can assess and challenge its decisions, and an inventory of deployed models for high-risk uses. |
| Canada · OSFIGuideline E-23, Model Risk Management (2027)Related on this site: US bank model risk, SR 26-2 | Federally regulated institutions, including life, fraternal and property and casualty insurers, manage model risk across the model lifecycle, with AI and machine learning models in scope. Senior management defines roles and accountability, models are reviewed independently and monitored, and third-party models are covered. | Final, effective laterPublished 11 September 2025. Effective 1 May 2027. | An inventory of models with owner and risk rating, documentation across the lifecycle, and records of independent review and monitoring. |
| Singapore · MASProposed Guidelines on AI Risk Management, alongside the FEAT principles | For all financial institutions: board and senior management oversight of AI risk, AI inventories and materiality assessments, and life cycle controls including data management, fairness, explainability, human oversight, third-party risk, testing and monitoring. | ConsultationIssued 13 November 2025. Comment period closed 31 January 2026. | An up-to-date AI inventory, materiality assessments, and records of the life cycle controls applied. |
| Bermuda · BMAConsultation Paper: The Responsible Use of Artificial Intelligence in Financial Services in Bermuda, with a proposed Guidance Note | Covers traditional AI, generative AI and agentic AI, including AI embedded in a third party’s product. Accountability stays with the regulated entity, its board and senior management. Human oversight is meaningful and matched to the risk, autonomy and reversibility of each use case. Where an agent can call tools, payment functions or other systems, controls cover permitted tools, purposes, approval thresholds and access, and for higher-impact actions they do not rely solely on prompts or model instructions (paragraph 74). | ConsultationPublished 14 August 2026. Comments to be received by 30 October 2026. | For material agentic use, records of actions, tool calls, access decisions, approvals, exceptions and outcomes (paragraph 75). For material uses, records enough to reconstruct a decision: material inputs and outputs, human review, overrides, reliance, and the basis for the final decision or action. |
| Australia · APRAAPRA letter to industry on artificial intelligence | Addressed to all APRA-regulated entities, insurers included. Boards hold enough AI literacy to challenge management. Entities keep an inventory of AI tools and use cases, assign ownership and accountability across the AI lifecycle, map third-party and fourth-party dependencies, and apply security controls and oversight to agentic and autonomous workflows. | Issued30 April 2026. | An inventory of AI tools and use cases, named ownership across the lifecycle, and human involvement in high-risk decisions. |
United States · NAIC Model Bulletin
Where the NAIC bulletin is adopted.
25 states and the District of Columbia, as listed on the NAIC’s implementation map, status as of 31 August 2026. Colorado, New York, California and Texas appear on the same map under their own insurance rules, set out in the tracker above.
| State | Adopting document | Date |
|---|---|---|
| Alaska | Bulletin B 24-01 | 1 February 2024 |
| Arkansas | Bulletin 13-2024 | 31 July 2024 |
| Connecticut | Bulletin No. MC-25 | 26 February 2024 |
| Delaware | Domestic and Foreign Bulletin No. 148 | 5 February 2025 |
| District of Columbia | Bulletin 24-IB-002-05/21 | 21 May 2024 |
| Hawaii | Insurance Commissioner Memorandum No. 2025-13A | 10 December 2025 |
| Illinois | Company Bulletin 2024-08 | 13 March 2024 |
| Iowa | Insurance Division Bulletin 24-04 | 7 November 2024 |
| Kentucky | Bulletin No. 2024-02 | 16 April 2024 |
| Maryland | Bulletin No. 24-11 | 22 April 2024 |
| Massachusetts | Bulletin No. 2024-10 | 9 December 2024 |
| Michigan | Bulletin 2024-20-INS | 7 August 2024 |
| Mississippi | Bulletin 2026-9 | 22 July 2026 |
| Nebraska | Insurance Guidance Document No. IGD-H1 | Issued 11 June 2024 |
| Nevada | Bulletin 24-001 | 23 February 2024 |
| New Hampshire | Bulletin Docket #INS 24-011-AB | 20 February 2024 |
| New Jersey | Insurance Bulletin No. 25-03 | 11 February 2025 |
| North Carolina | Bulletin No. 24-B-19 | 18 December 2024 |
| Oklahoma | Bulletin No. 2024-11 | 14 November 2024 |
| Pennsylvania | Insurance Notice 2024-04, 54 Pa.B. 1910 | 6 April 2024 |
| Rhode Island | Insurance Bulletin No. 2024-03 | 15 March 2024 |
| Vermont | Insurance Bulletin No. 229 | 12 March 2024 |
| Virginia | Administrative Letter 2024-01 | 22 July 2024 |
| Washington | Technical Assistance Advisory 2024-02 | 22 April 2024 |
| West Virginia | Insurance Bulletin No. 24-06 | 9 August 2024 |
| Wisconsin | Insurance Bulletin | 18 March 2025 |
What they share
What the rules have in common.
Two sides of one market
For carriers using AI, and for underwriters of AI risk.
A carrier deploying AI reads these rules for what it must be able to show. An underwriter of AI risk reads the same rules for what a well-run insured can show: who authorized each action, what was checked, and a record an outside party can check.
Regulayer™ checks an AI agent’s action against a named person’s current authority before the action takes effect, and seals a tamper-evident record anyone can verify offline. Regulayer™ for insurers · Technical overview
Regulayer™ supplies the evidence. The insurer, the regulator or the court makes the determination.
On this site
