Published: September 5, 2026 | Category: Insurance | By Mahesh
The Real Fight Isn't Over the Technology
A federal executive order is now attempting to preempt state authority over insurance AI regulation at precisely the moment more than 24 states have already adopted their own binding rules governing exactly that.[1] This is not a minor jurisdictional footnote, it is the actual center of the 2026 story about AI and insurance, and it matters more to an ordinary policyholder than any individual chatbot or claims-processing algorithm an insurer might deploy. The technology itself, AI estimating repair costs from photos or flagging fraudulent claims, is genuinely useful and largely uncontroversial. What is genuinely contested, and what will determine whether that technology helps or harms consumers, is which government, federal or state, gets to set the rules for how it is used, and whether an insurer's AI-driven decision can be challenged the same way a human underwriter's decision always could. Depth Grid's coverage this week of business interruption insurance and professional versus general liability coverage both examined specific policy mechanics. This piece steps back to the regulatory battle actually shaping how every one of those policies gets priced, underwritten, and adjudicated going forward.
Where AI Already Runs Inside a Policy, Quietly
Before getting to the regulatory fight, it helps to establish exactly where AI already operates inside the insurance process today, since the technology's actual footprint is broader and less visible than most policyholders realize. The National Association of Insurance Commissioners' own public guidance states plainly that AI is used across underwriting, pricing, customer service, claims handling, marketing, and fraud detection, with concrete examples including AI-powered chatbots answering routine customer questions and assisting with simple transactions at any hour, and AI systems used in claims processing to estimate repair costs or assess damage directly from submitted photos combined with historical claims data.[2] The NAIC's own framing of the underlying technical capability is direct: AI has improved substantially at tasks that were historically difficult for computers, recognizing images, understanding written and spoken language, and analyzing large volumes of unstructured data like text, photos, and video, which is precisely why claims photo assessment and chatbot-driven customer service have become two of the most visible early applications.[2]
The pace of adoption accelerated further with the emergence of agentic AI, systems capable of taking multi-step actions rather than simply answering a single query. Industry tracking shows agentic AI began appearing in insurance processes in early 2025 through pilot projects run by insurers and technology vendors, and by mid-2025 industry publications and consulting firms were documenting real-world production use specifically in claims processing, fraud detection, and underwriting.[3] That shift from pilot to production use within roughly a year is a meaningfully faster adoption curve than most prior insurance technology cycles, and it is precisely this acceleration that regulators cite as the reason oversight needed to intensify starting in 2026 rather than waiting for a slower, more gradual rollout the way earlier predictive-modeling technologies had been allowed to mature under lighter scrutiny.
The NAIC's Own Rule, and Why It Doesn't Change Your Legal Rights
The foundational regulatory document shaping how insurers deploy AI is the NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, which established the expectation that any insurer using AI in a regulated insurance practice maintain a written governance program, formally called an AIS Program, covering oversight structures, risk management, bias testing, and third-party vendor accountability.[4] As of 2026, more than 24 states have formally adopted this bulletin, and the NAIC's own position on what that adoption actually changes is worth stating precisely, because it is easy to misread: AI is a tool used in underwriting, pricing, claims, fraud detection, and utilization management, and using it does not alter insurers' legal obligations, since existing state insurance laws apply regardless of whether a decision is made by a human, an algorithm, or a third-party vendor.[1]
That last point deserves emphasis because it directly answers a question many policyholders have without realizing it: an insurer cannot use "the AI decided" as a legal shield against a claim it would otherwise be required to pay or a rate it would otherwise be prohibited from charging under existing law. The NAIC has also moved from guidance toward active examination capability, launching a multistate pilot of an AI Systems Evaluation Tool running from January through September 2026, with 12 participating states providing feedback on the tool's effectiveness, and current expectations pointing toward formal adoption at the 2026 Fall National Meeting.[1] This tool is specifically designed to let regulators gather structured information during a market conduct, financial analysis, or financial examination about the extent of an insurer's AI use, its governance and risk mitigation practices, and the types of data feeding into its AI systems, converting what has so far been largely a documentation and disclosure requirement into an active, standardized examination capability regulators can deploy directly against a specific insurer.[2]
The Federal-State Collision Reshaping Compliance in Real Time
The most consequential near-term development in this entire regulatory landscape is a direct jurisdictional collision that emerged in December 2025, when President Trump signed an executive order specifically aimed at preempting state AI laws, a move that directly challenges the state-based regulatory authority the NAIC and individual state insurance departments have spent the past two years building.[5] This is not an abstract legal dispute playing out only in courtrooms and law firm memos, it has immediate practical consequences for how insurers operating across multiple states must currently plan their compliance programs, since a carrier cannot simply wait for the jurisdictional question to resolve before making underwriting and claims decisions that regulators, state or federal, will eventually scrutinize. The White House followed its executive order with a broader AI legislative framework published in March 2026, adding another layer to an already contested regulatory landscape that insurers must navigate without clear resolution of which government's rules will ultimately prevail.[6]
Individual states have not waited for this federal question to resolve, and several have moved well beyond simply adopting the NAIC's voluntary bulletin into binding, enforceable law. Colorado's SB 24-205, the Colorado Artificial Intelligence Act, took effect June 30, 2026 and explicitly covers AI systems used to make or substantially contribute to consequential decisions, a category that includes insurance underwriting, pricing, and claims determinations, requiring insurers deploying high-risk AI to conduct formal impact assessments, implement risk management programs, and provide direct consumer notice when AI contributes to a decision affecting them.[7] New York has taken a notably different path from the NAIC's own model, with the Department of Financial Services' Circular Letter 2024-7, finalized in July 2024, establishing detailed fairness principles and proxy-variable assessment requirements for insurers using AI or external consumer data in underwriting and pricing, without formally adopting the NAIC bulletin at all, illustrating how even states broadly aligned on the goal of AI oversight have chosen materially different regulatory mechanisms to achieve it.[8] Comprehensive tracking of this legislative activity counts 71 separate AI bills across 27 states directly affecting insurance as of 2026, a volume that itself signals how unsettled and fast-moving this compliance landscape remains for any insurer operating nationally.[9]
The Human-Review Laws Responding to AI Claims Denials
Perhaps the most consumer-facing regulatory response to AI in insurance has emerged specifically around claims denials, where multiple states have moved to guarantee that a human being, not an algorithm alone, makes or reviews the final decision to deny coverage. Alabama's SB 63 prohibits insurers from denying a health insurance claim based solely on AI without physician review, a direct legislative response to concern that an algorithmic denial could occur without any licensed medical professional ever examining the underlying clinical facts of a specific case.[9] Florida moved in a similar direction in December 2025, with a state House panel passing a bill specifically requiring human involvement in claims denial decisions, reflecting a legislative pattern emerging independently across multiple states rather than coordinated through the NAIC's own model bulletin process.[10]
The NAIC's own compliance guidance to insurers reflects this same human-oversight expectation as a structural governance requirement rather than a case-by-case courtesy. The NAIC explicitly expects insurers to establish cross-functional AI governance committees with actuarial, data science, underwriting, claims, compliance, and legal representation, and current guidance to compliance professionals frames 2026 as the critical year to establish this structure before an insurer's specific state examination tool deployment arrives, since regulatory examinations are expected to focus heavily on documentation: model development methodology, data sources used, bias testing results, consumer impact assessments, and evidence of ongoing monitoring after a model goes into production.[11] For a policyholder, the practical upshot of this entire regulatory push, spanning the NAIC's model bulletin, Colorado's binding law, New York's separate fairness framework, and state-specific human-review mandates like Alabama's and Florida's, is a genuine and growing legal expectation that an AI-driven denial or adverse decision remains challengeable through the same channels a human-made decision always was, provided the policyholder actually knows to invoke them.
What This Means for a Policyholder Right Now
Ask directly whether AI contributed to any adverse decision on your policy or claim. Given that Colorado's binding law requires direct consumer notice when AI contributes to a consequential decision, and that the NAIC's own position confirms existing insurance law applies regardless of whether a human or algorithm made the call, a policyholder facing a denial or unfavorable rate has a legitimate basis to ask their insurer specifically whether AI was involved in that determination, and to request the same explanation and appeal process that would apply to a purely human decision.
Know that "the algorithm decided" is not a valid final answer to a denied claim. The NAIC's own guidance is explicit that using AI does not alter an insurer's legal obligations under existing state law. If a claim is denied and the explanation offered amounts only to an automated determination without a clear, specific factual basis, a policyholder retains the same right to challenge that denial through their state insurance department's complaint process that has always existed for a purely human underwriting or claims decision.
Watch your own state's specific regulatory posture, since it genuinely varies. With Colorado enforcing a binding law, New York running its own separate fairness framework independent of the NAIC bulletin, and other states still relying solely on the voluntary bulletin without additional legislation, the actual protections available to a policyholder in a claims dispute differ meaningfully depending on which state issued the policy, making it worth checking your own state insurance department's specific AI guidance rather than assuming a uniform national standard applies.
Common Questions
This analysis is editorial commentary based on publicly available sources cited above. It is not financial, legal, or insurance advice. AI regulation in insurance varies significantly by state and is evolving rapidly; confirm your specific state's current requirements and your policy's own terms with a licensed insurance professional or your state insurance department.
Sources
- Crowell & Moring LLP, "NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know," March 25, 2026. Link
- National Association of Insurance Commissioners (NAIC), "Insurance Topics: Artificial Intelligence," accessed September 2026. Link
- Fenwick, "Tracking the Evolution of AI Insurance Regulation," December 11, 2025. Link
- WaterStreet Company, "AI in Insurance: AI Compliance and the Defining Challenge of 2026," April 1, 2026, citing NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (December 2023). Link
- WaterStreet Company, "AI in Insurance: AI Compliance and the Defining Challenge of 2026," April 1, 2026, citing Seyfarth Shaw, "President Trump Signs Executive Order Preempting State AI Laws" (December 2025). Link
- WaterStreet Company, "AI in Insurance: AI Compliance and the Defining Challenge of 2026," April 1, 2026, citing Freshfields, "White House Publishes AI Legislative Framework" (March 2026). Link
- AI Laws by State, "Insurance AI Compliance Laws by State (2026 Guide)," citing Colorado SB 24-205. Link
- WaterStreet Company, "AI in Insurance: AI Compliance and the Defining Challenge of 2026," April 1, 2026, citing NY DFS Insurance Circular Letter No. 7 (July 2024). Link
- AI Laws by State, "Insurance AI Compliance Laws by State (2026 Guide)," citing Alabama SB 63. Link
- WaterStreet Company, "AI in Insurance: AI Compliance and the Defining Challenge of 2026," April 1, 2026, citing Insurance Journal, "Florida House Panel Passes Bill Requiring Human Touch on Claims Denials" (December 2025). Link
- actuary.info, "AI Regulation in Insurance 2026: The NAIC Model Bulletin, State Adoption, and the Federal Preemption Battle," March 27, 2026. Link
Read More on Depth Grid
- Business Insurance for Small Businesses: Types, Coverage, Costs and How to Choose in 2026
- Cyber Insurance for Small Businesses: Coverage, Cost and Requirements in 2026
- Business Interruption Insurance: What Does It Cover?
- What Is an AI Native Company? Complete Definition, Examples and Guide
Article by Mahesh | Depth Grid

