AI Insurance Regulation in the United States: Federal vs State Rules
Quick Answer: AI insurance regulation in the United States is primarily state-based, although federal laws and federal agencies can also become relevant depending on the insurance product, data involved, conduct and technology. The National Association of Insurance Commissioners (NAIC) has developed AI-related model guidance and governance frameworks, but state insurance departments remain central to the regulation of insurers.
Artificial intelligence is rapidly becoming part of the insurance business.
Insurers use or explore AI for:
- Underwriting.
- Pricing.
- Claims processing.
- Fraud detection.
- Customer service.
- Risk assessment.
- Document processing.
- Marketing.
But one question appears every time an insurer deploys a new AI system:
Who regulates it?
The answer is more complicated in the United States than in many other jurisdictions.
The United States does not currently operate under one comprehensive federal insurance AI statute governing every insurer and every AI application.
Instead, insurers may have to navigate several layers of law and regulatory oversight.
At the centre is the state insurance regulatory system.
Then there are:
- NAIC model laws and regulatory guidance.
- Federal consumer-protection laws.
- Federal anti-discrimination requirements.
- Privacy and data-protection requirements.
- Sector-specific federal regulation.
- General corporate and contractual law.
This produces a fragmented regulatory landscape.
An AI system used by an insurer in California may face different regulatory considerations from an equivalent system deployed in another state.
That creates a practical problem for national insurers.
One model may operate across fifty regulatory environments.
The central challenge is therefore not simply building an accurate AI model.
It is building an AI system that can be governed across the applicable legal environment.
Legal disclaimer: This article provides general educational information and is not legal, insurance, regulatory, actuarial, privacy or compliance advice. AI and insurance requirements vary according to state, product, insurer activity, data and applicable federal law.
Key Takeaways
- U.S. insurance regulation is predominantly state-based.
- There is no single comprehensive federal AI insurance statute governing every insurance use case.
- State insurance departments remain central regulators.
- The NAIC develops model laws, guidance and regulatory frameworks that can influence state regulation.
- Federal laws can apply to particular insurance activities and technologies.
- AI used in underwriting, pricing and claims can create different regulatory risks.
- Algorithmic discrimination is a major concern.
- Consumer-protection laws can apply even when no AI-specific statute exists.
- Privacy obligations may arise from the data used by AI systems.
- Third-party AI vendors do not automatically eliminate insurer governance responsibilities.
- Insurers should maintain model inventories, validation procedures and governance controls.
- National insurers need a state-by-state regulatory strategy.
How Is Insurance Regulated in the United States?
Quick Answer: Insurance is primarily regulated at the state level in the United States.
State insurance departments supervise insurers operating within their jurisdictions.
This system is different from a model in which one national federal insurance regulator establishes all insurance rules.
Why Is Insurance Primarily State-Regulated?
Quick Answer: The U.S. insurance regulatory system developed around state-level oversight, and federal law recognises an important role for state regulation of insurance.
This has significant consequences for AI.
There is no single state insurance environment.
There are multiple jurisdictions.
Therefore:
AI insurance compliance = federal considerations + state considerations + product-specific requirements.
What Is the Role of State Insurance Departments?
Quick Answer: State insurance departments regulate insurers within their jurisdictions and may oversee matters including licensing, solvency, market conduct, rates, forms, underwriting and claims practices, subject to state law.
For AI systems, regulators may be concerned with:
- How AI is used.
- What data it uses.
- Whether outcomes are discriminatory.
- Whether models are appropriately governed.
- Whether consumers are treated fairly.
What Is the NAIC?
Quick Answer: The National Association of Insurance Commissioners is an organisation through which state insurance regulators coordinate, develop model laws and regulations, and address emerging insurance issues.
The NAIC does not function as a single federal insurance regulator.
Its model laws and guidance can nevertheless have significant influence when adopted or implemented by individual states.
Does the NAIC Regulate AI?
Quick Answer: The NAIC has developed AI-related regulatory guidance and model approaches addressing the governance and use of artificial intelligence by insurers.
However, the legal effect of a particular NAIC model depends on whether and how a state adopts it or otherwise incorporates its principles into regulatory practice.
What Is the NAIC Model Bulletin on AI?
Quick Answer: The NAIC has issued an AI-related model bulletin addressing insurers' use of artificial intelligence systems and the governance controls expected around those systems.
The bulletin reflects a risk-management approach.
It focuses on matters such as:
- Governance.
- Risk management.
- Internal controls.
- Documentation.
- Testing.
- Monitoring.
What Is the NAIC AI Systems Evaluation Approach?
Quick Answer: NAIC's broader AI-related work emphasises responsible governance of AI systems, including risk identification, controls and regulatory oversight.
The important point for insurers is that AI governance should not be treated as a purely technical function.
It is increasingly part of enterprise risk management.
Does Every State Have the Same AI Insurance Rules?
Quick Answer: No.
States can differ in:
- AI-specific legislation.
- Insurance regulations.
- Privacy requirements.
- Consumer-protection rules.
- Regulatory guidance.
- Disclosure requirements.
This creates a significant compliance challenge for national insurers.
Why Is State-by-State AI Compliance Difficult?
Quick Answer: A single AI model can operate across multiple jurisdictions with different legal requirements.
For example:
One underwriting model β 20 states β potentially 20 regulatory analyses.
Even if the underlying technology is identical, the legal environment may differ.
What Federal Laws Can Affect AI Insurance?
Quick Answer: Federal laws can become relevant where an insurance AI system implicates areas such as consumer protection, discrimination, privacy, financial activity or other federally regulated conduct.
The exact laws depend on the activity.
Potentially relevant federal frameworks can include:
- Consumer-protection law.
- Federal fair-lending or financial-discrimination requirements where applicable.
- Federal anti-discrimination law.
- Privacy-related federal statutes applicable to particular data or sectors.
- Federal laws governing specific insurance products or markets.
Federal and state analysis should therefore be conducted together rather than treating insurance AI as exclusively a state issue.
Does the FTC Regulate AI Used by Insurers?
Quick Answer: The Federal Trade Commission has broad authority over certain unfair or deceptive acts or practices and has taken an active interest in AI-related consumer-protection issues. However, the extent of FTC jurisdiction in a particular insurance context must be analysed carefully, including applicable statutory limitations and the regulatory status of the entity.
The key principle is:
βAIβ does not create a regulatory exemption.
Can Consumer-Protection Law Apply to Insurance AI?
Quick Answer: Potentially.
AI-related conduct can raise consumer-protection issues where representations, practices or automated systems cause consumers to be treated unfairly or misled.
Examples may include:
- Misleading explanations.
- Inaccurate AI-generated communications.
- Improper use of consumer data.
- Deceptive claims practices.
Can Anti-Discrimination Law Apply to Insurance AI?
Quick Answer: Potentially, depending on the insurance product, protected characteristic, jurisdiction and applicable legal framework.
AI can create discrimination risks through:
- Explicit variables.
- Proxy variables.
- Historical data.
- Model interactions.
The fact that a model does not explicitly contain a protected characteristic does not automatically eliminate discrimination concerns.
What Is Proxy Discrimination in Insurance?
Quick Answer: Proxy discrimination occurs when a variable indirectly captures information associated with a protected characteristic and contributes to a discriminatory outcome.
For example:
Protected characteristic β Correlated variable β AI model β Outcome.
Insurers should therefore examine not only the variables they intentionally select but also the relationships produced by the model.
Does Insurance AI Need to Be Explainable?
Quick Answer: Explainability requirements depend on the use case and applicable law. Regardless of whether a specific disclosure is legally mandated, insurers should maintain sufficient documentation to understand, validate and govern material AI systems.
For consequential decisions, explainability can be particularly important.
Is AI Underwriting Regulated?
Quick Answer: AI underwriting is subject to the legal and regulatory requirements applicable to insurance underwriting in the relevant jurisdiction and product.
AI does not create a separate regulatory category in which ordinary underwriting rules disappear.
Is AI Insurance Pricing Regulated?
Quick Answer: AI-supported insurance pricing can be subject to applicable state rating laws, filing requirements, actuarial requirements and anti-discrimination rules.
Insurers should assess:
- Rating variables.
- Model methodology.
- Actuarial support.
- Data sources.
- Consumer impact.
Is AI Claims Processing Regulated?
Quick Answer: Yes, AI-supported claims handling remains subject to applicable insurance and claims-handling requirements.
An insurer cannot necessarily avoid claims obligations simply because an automated system made the recommendation.
Can AI Fraud Detection Be Regulated?
Quick Answer: AI fraud detection can create regulatory concerns when automated systems influence claims investigations, delays, payment decisions or consumer treatment.
A key distinction is:
Fraud flag β proof of fraud.
Human investigation may be necessary before consequential action.
What Is an AI Insurance Model Governance Programme?
Quick Answer: An AI model governance programme establishes processes for identifying, evaluating, approving, monitoring and retiring AI systems.
A robust programme should address:
- Model inventory.
- Risk classification.
- Data governance.
- Validation.
- Fairness testing.
- Documentation.
- Human oversight.
- Change management.
- Monitoring.
Should Insurers Maintain an AI Inventory?
Quick Answer: Yes.
An AI inventory should identify:
- System name.
- Business function.
- Vendor.
- Data used.
- Risk level.
- Decision impact.
- Model owner.
- Validation status.
Without an inventory, an insurer may not even know where AI is being used.
What Is AI Model Validation?
Quick Answer: Model validation evaluates whether an AI system performs as intended and remains appropriate for its purpose.
Validation can examine:
- Accuracy.
- Stability.
- Data quality.
- Bias.
- Performance.
- Limitations.
What Is Model Drift?
Quick Answer: Model drift occurs when the environment or data changes such that the model no longer performs as expected.
Insurance risks change.
Consumer behaviour changes.
Claims patterns change.
Technology changes.
A model therefore requires continuing monitoring rather than one-time approval.
Are Third-Party AI Vendors Regulated?
Quick Answer: AI vendors may be subject to laws applicable to their activities, but an insurer must also manage the risks associated with outsourcing material functions to technology providers.
Vendor governance should include:
- Due diligence.
- Contractual controls.
- Performance requirements.
- Audit rights.
- Security requirements.
- Incident reporting.
- Model-change notifications.
Can an Insurer Outsource AI Compliance?
Quick Answer: Outsourcing technology does not automatically mean outsourcing the insurer's governance responsibilities.
The insurer should understand:
What does the vendor do?
What data does the vendor use?
How does the model affect consumers?
Can the insurer audit the system?
What Is Regulatory Examination of AI?
Quick Answer: Regulatory examination involves regulators reviewing an insurer's practices, controls, records and compliance with applicable requirements.
For AI, regulators may want to understand:
- What systems are deployed.
- How they are governed.
- How models are validated.
- How discrimination is assessed.
- How complaints are handled.
What Records Should an Insurer Maintain?
Quick Answer: Insurers should maintain appropriate documentation concerning material AI systems and their governance.
Depending on the system, this can include:
- Model documentation.
- Training-data information.
- Validation reports.
- Approval records.
- Monitoring reports.
- Change logs.
- Vendor documentation.
- Incident records.
What Is the Difference Between AI Governance and AI Regulation?
Quick Answer: Regulation consists of external legal requirements, while governance is the insurer's internal system for managing AI risks and compliance.
The relationship is:
Law β Regulatory expectations β Internal governance β Operational controls.
AI Insurance Regulation Risk Matrix
| Area | AI Risk | Governance Response |
|---|---|---|
| Underwriting | Unfair risk classification | Variable and outcome testing |
| Pricing | Improper differentiation | Actuarial and regulatory review |
| Claims | Incorrect denial | Human review and auditability |
| Fraud | False positives | Investigator review |
| Data | Improper use | Data governance |
| Privacy | Excessive collection | Privacy assessment |
| Vendor | Opaque third-party model | Vendor due diligence |
| Explainability | Unclear decision basis | Documentation and explanation framework |
| Model drift | Declining performance | Continuous monitoring |
AI Insurance Regulation Compliance Checklist
- Identify every AI system used by the insurer.
- Classify each system according to risk and consumer impact.
- Identify the states in which the system operates.
- Identify the insurance product affected.
- Map applicable state requirements.
- Map applicable federal requirements.
- Review relevant NAIC guidance and model approaches.
- Document AI governance procedures.
- Establish model validation.
- Conduct appropriate discrimination testing.
- Review data sources.
- Review privacy implications.
- Establish human oversight.
- Maintain audit trails.
- Monitor model performance.
- Monitor model drift.
- Review third-party vendors.
- Document material model changes.
- Maintain regulatory records.
- Periodically reassess the regulatory framework.
Frequently Asked Questions
How is AI regulated in insurance in the United States?
Insurance is primarily regulated at the state level, supplemented by NAIC guidance and applicable federal laws.
Does the United States have one AI insurance law?
No. The U.S. regulatory framework consists of multiple federal and state legal requirements rather than one comprehensive federal AI insurance statute.
Does the NAIC regulate insurance companies?
The NAIC coordinates among state insurance regulators and develops model laws and regulatory guidance. State insurance departments exercise regulatory authority.
What is the NAIC's role in AI insurance?
The NAIC develops guidance and model regulatory approaches addressing responsible insurer use and governance of artificial intelligence.
Are AI insurance underwriting systems regulated?
AI underwriting remains subject to applicable insurance underwriting rules, including requirements concerning permissible practices and discrimination.
Are AI insurance pricing models regulated?
They can be subject to state rating laws, filing requirements, actuarial requirements and other applicable rules.
Are AI insurance claims systems regulated?
Yes. AI-supported claims handling remains subject to applicable claims-handling and consumer-protection requirements.
Can AI insurance systems discriminate?
Yes. Discrimination risks can arise from explicit variables, proxy variables, historical data and model design.
Does AI need to be explainable for insurance regulators?
The specific requirements depend on the system and applicable law, but insurers should maintain sufficient documentation and controls to understand and govern material AI systems.
Can insurance companies outsource AI to vendors?
Yes, but insurers should conduct appropriate vendor due diligence and maintain governance over material outsourced systems.
Who regulates insurance companies in the United States?
State insurance departments are the primary regulators of insurance, with federal laws and agencies playing additional roles depending on the activity.
Do state AI insurance laws differ?
Yes. State approaches can differ significantly, making state-by-state compliance important for national insurers.
What is AI model governance in insurance?
It is the internal framework used to identify, validate, approve, monitor and control AI systems.
Why is AI insurance regulation important?
AI can influence financially significant decisions involving underwriting, premiums, claims and fraud investigations, making appropriate regulatory oversight important.
Conclusion
AI insurance regulation in the United States is best understood as a regulatory mosaic rather than a single statute.
There is no universal federal insurance AI code that answers every question.
Instead, insurers must navigate:
State insurance regulation + NAIC frameworks + applicable federal law + product-specific requirements.
This structure creates both opportunities and challenges.
For regulators, AI creates a new generation of questions.
For insurers, it creates a new generation of compliance responsibilities.
For consumers, it creates a new generation of concerns about fairness, transparency and accountability.
The most important mistake would be to assume that AI creates a legal vacuum.
It does not.
When an insurer uses AI to price a policy, existing insurance pricing rules remain relevant.
When AI participates in underwriting, underwriting requirements remain relevant.
When AI processes claims, claims-handling obligations remain relevant.
When AI identifies fraud, consumer and claims protections remain relevant.
The technology changes.
The regulatory question remains.
Is the insurer complying with the law?
This is why AI governance should begin before deployment.
An insurer should first identify:
Where is AI being used?
Then:
What does the AI system do?
Then:
What data does it use?
Then:
What decisions can it influence?
Then:
What laws and regulatory expectations apply?
This should lead to a governance framework covering:
- Model inventory.
- Risk classification.
- Data governance.
- Validation.
- Fairness testing.
- Explainability.
- Human oversight.
- Vendor management.
- Monitoring.
- Documentation.
National insurers face an additional challenge.
A model deployed across the country may interact with different state regulatory environments.
The compliance solution therefore cannot simply be:
βThe model was approved once.β
Instead, insurers need continuing governance.
Models change.
Data changes.
Claims patterns change.
Regulatory expectations change.
State laws change.
Technology changes.
AI governance must therefore be dynamic.
The most important conceptual distinction is:
AI regulation is external.
AI governance is internal.
Regulation tells an insurer what the law requires.
Governance determines how the insurer operationalises those requirements.
A sophisticated AI model without governance can therefore create greater risk than a simpler model with strong controls.
The future of U.S. insurance regulation is unlikely to be about banning AI.
It is more likely to focus on responsible deployment.
That means asking whether AI systems are:
- Accurate.
- Fair.
- Appropriately governed.
- Auditable.
- Explainable where necessary.
- Consistent with applicable law.
The central principle is therefore:
AI does not replace insurance regulation. It creates a new technology layer through which existing regulatory obligations must be implemented and monitored.
Legal Disclaimer
This article is provided for general educational and informational purposes only. It is not legal, insurance, actuarial, financial, privacy or regulatory advice and does not create an attorney-client relationship. U.S. insurance regulation varies by state, insurance product, insurer activity and applicable federal law. Readers should consult the current statutes, regulations, regulatory guidance and professional advice applicable to their circumstances.
