The US Just Decided Who Regulates Insurance AI. It’s Not Washington
- Reuben John
- 1 day ago
- 5 min read

By Reuben John, Founder & CEO at True Aim AG
On 1 July 2025, the United States Senate voted 99 to 1 to strip a proposed moratorium on state AI laws out of the budget bill. The House passed the amended bill two days later and it was signed into law on 4 July. Nothing then stopped a single state from writing its own rules on how insurers use artificial intelligence. For anyone trying to read where US insurance AI regulation is heading, that vote is the whole story. There will be no single federal rulebook. There will be fifty conversations, loosely co-ordinated, and they are already underway.
That is a harder environment for which to build than a single statute and most carriers have not yet adjusted to it. The instinct is to wait for one clear national standard before changing how a claims system works. In US insurance, that standard is not coming. The standard is being set state by state, and the body doing the co-ordinating is the one most technology buyers have never had to think about.
The regulator you should actually be reading
The National Association of Insurance Commissioners (NAIC) is not a federal agency. It has no direct power to make law. What it has is the ability to write a model that state insurance departments adopt almost verbatim, which is how a great deal of US insurance regulation has always travelled.
In December 2023, the NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. It is principles-based rather than a checklist. It tells insurers that they are responsible for the outcomes their AI systems produce, that they need a documented governance programme with named senior accountability, that they must be able to explain how an input led to a specific decision, and that buying the system from a vendor does not transfer responsibility. The carrier owns the answer the regulator gets.
By early 2026, roughly half of US states had adopted that bulletin or a close version of it. Alaska went first, in February 2024; Hawaii was the most recent, in December 2025. For a carrier writing across multiple states, that is no longer guidance to monitor. It is the operating reality of the book.
Principles become questions
A principle only matters when someone asks you to demonstrate it. In early 2026, the NAIC went a step further. It finalised a twelve-state group in February, including California, Colorado, Connecticut and Florida. Then, in March, began a pilot of an AI Systems Evaluation Tool: a structured framework that gives market conduct examiners a standard set of questions for reviewing how an insurer governs its AI. The pilot runs through September 2026, and the tool is slated to be considered for adoption at the NAIC's 2026 Fall National Meeting.
The point of the tool is plain. An examiner can now sit down with a carrier and ask, in a consistent format, which decisions are touched by AI, how those models were validated, what data fed them, and who reviewed the output. The questions are no longer abstract. They are a worksheet. A carrier that cannot produce a clean record for each AI-assisted decision is going to have a difficult examination.
Some states have gone further than the bulletin on their own. Colorado's Senate Bill 21-169 framework requires insurers that use external consumer data, algorithms or predictive models to govern those systems against unfair discrimination and to report on compliance. In October 2025, Colorado extended that governance and risk-management regulation to private-passenger auto and health insurers, having previously applied it to life insurers only. Its quantitative bias-testing requirement still applies to life insurers alone, with auto and health in development. That is the harder edge of the same direction of travel. Whether a carrier faces the lighter bulletin or the Colorado regime, the demand underneath is identical. Show your work.
Where probabilistic AI walks into a wall
Here is the problem most current insurance AI has, and it is structural rather than a tuning issue. A large share of the AI sold into claims over the past three years is probabilistic. It produces a score, a likelihood, a recommendation, and it does so through a model whose internal reasoning cannot be reproduced exactly or traced to a specific rule. That is acceptable when the question is "roughly how risky is this." It falls apart when the question is "which clause in this policy produced this denial and would the identical claim produce the identical answer next week."
The NAIC bulletin and the new evaluation tool are both built around that second kind of question. They ask for explainability, reproducibility and a documented chain from input to outcome. A system that returns a confidence score cannot answer that question without a human reconstructing the reasoning after the fact, which defeats the automation and leaves a thin record. The carrier ends up holding a decision it cannot fully account for, made by a tool it does not fully control, in front of an examiner who now has a standard form for asking.
This is the gap that catches buyers by surprise. The accuracy numbers in a vendor demo describe how often the model is right. They say nothing about whether the model can explain itself to a regulator, and that second question is the one around which US insurance regulation is now organised.
Build for the examination, not just the decision
The way out is not less automation. It is automation built so that every decision arrives with its own justification attached. For the large majority of claims, the facts and the policy logic determine the answer. The same inputs should produce the same outcome every time, and that outcome should trace directly back to the contract clause and the rule that produced it. When a system is built that way, the record an examiner wants is not assembled after the fact. It is a by-product of the decision itself. The harder, ambiguous claims still go to a human, with the machine handling the parsing and the routine work and the person owning the judgement.
That design happens to answer the bulletin's questions by construction. You can name the inputs. You can show the rule. You can reproduce the outcome. You can point to the human in the loop. None of that is a compliance bolt-on. It is what the architecture produces when explainability is a requirement rather than an afterthought.
The US has made its choice clear. Regulation of insurance AI will be state-led, NAIC co-ordinated and increasingly examined against a common standard. The carriers that treat an audit trail as the starting point, rather than something to manufacture once a regulator calls, are the ones building for the market that actually exists.
.png)


