AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Industries/
  3. Insurance

AI Compliance for Insurance

Insurance carriers and insurtech firms using AI in underwriting, claims processing, fraud detection, and pricing decisions.

Insurance is the most heavily AI-regulated sector in US financial services: as of 2026 more than 20 states plus the District of Columbia have adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023), and Colorado enforces the first binding, insurance-specific AI governance rule — Regulation 10-1-1 — layered on top of the cross-sector state AI acts.

Sector-specific AI regulations

  • NAIC Model Bulletin on the Use of Artificial Intelligence Systems by InsurersModel guidance

    NAIC (adopted 2023 Fall National Meeting) • Effective: Adopted Dec 4, 2023; binding once a state issues it

    Directs insurers to develop, implement, and maintain a written Artificial Intelligence Systems (AIS) Program governing AI that makes or supports decisions in regulated insurance practices, with controls for governance, risk management, and third-party AI oversight. It is guidance until a state adopts it as a bulletin; more than 20 states plus DC had done so by 2026.

    Source: NAIC — Artificial Intelligence (Model Bulletin + implementation map) — retrieved 2026-07-05

  • Colorado Regulation 10-1-1 — Governance and Risk Management Framework for ECDIS, Algorithms, and Predictive ModelsBinding

    3 CCR 702-10; authorized by SB 21-169 (2021) • Effective: Nov 14, 2023 (life insurers); amended reg effective Oct 15, 2025 (life, private-passenger auto, health)

    Requires covered insurers that use external consumer data and information sources (ECDIS) and the algorithms or predictive models built on them to establish a documented governance and risk-management framework, test for unfair discrimination, and report to the Colorado Division of Insurance. It is the first binding US insurance-specific AI governance regulation and derives from SB 21-169, signed July 6, 2021.

    Source: Colorado Division of Insurance — Amended Regulation 10-1-1 adoption notice — retrieved 2026-07-05

Last verified: 2026-07-05

Applicable laws

  • Colorado Artificial Intelligence Act for InsuranceEffective soon
    Colorado•Effective January 1, 2027•Max penalty: $20Kfull detail
  • Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions) for InsuranceEffective soon
    Connecticut•Effective October 1, 2026•Max penalty: Not specifiedfull detail
  • California AI Transparency Act for InsuranceEffective soon
    California•Effective August 2, 2026•Max penalty: $5Kfull detail
  • California Generative AI: Training Data Transparency for InsuranceIn effect
    California•Effective January 1, 2026•Max penalty: Not specifiedfull detail
  • Transparency in Frontier Artificial Intelligence Act (TFAIA) for InsuranceIn effect
    California•Effective January 1, 2026•Max penalty: $1.0Mfull detail
  • Texas Responsible Artificial Intelligence Governance Act (TRAIGA) for InsuranceIn effect
    Texas•Effective January 1, 2026•Max penalty: $200Kfull detail
  • Washington State Artificial Intelligence Task Force / AI Regulation for InsuranceIn effect
    Washington•Effective March 18, 2024•Max penalty: Not specifiedfull detail
  • Virginia High-Risk Artificial Intelligence Developer and Deployer Act for InsuranceDefeated
    Virginia•Effective Not yet set•Max penalty: $10Kfull detail

Interactive tools

  • Vendor AI due diligence questionnaire

    Generate a source-linked questionnaire and evidence-request checklist for an AI vendor, including the NAIC AI Systems Program and Colorado Regulation 10-1-1 ECDIS testing questions that apply to carriers.

Recommended frameworks

  • NIST AI RMF 1.0

    Voluntary US framework. Adopt to demonstrate due care across most state AI laws.

  • ISO/IEC 42001:2023

    Certifiable AI management-system standard. Strong fit for insurance organizations subject to multiple jurisdictions.

Frequently asked questions

What AI compliance rules apply to insurance carriers in the US?

Insurers face three overlapping layers: (1) the NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted by more than 20 states plus DC, which requires a written AI Systems Program; (2) binding state insurance regulations such as Colorado Regulation 10-1-1 (unfair-discrimination testing for ECDIS and predictive models); and (3) cross-sector state AI acts — for example the Colorado AI Act (SB 24-205) — that treat insurance underwriting as a consequential decision. Carriers should map each AI use case against all three layers rather than only the general state AI acts.

How is AI regulated in insurance claims handling and underwriting?

Underwriting and claims decisions that rely on external consumer data and predictive models fall squarely inside the NAIC Model Bulletin’s AI Systems Program expectations and, in Colorado, inside Regulation 10-1-1’s governance, documentation, and unfair-discrimination-testing duties. State insurance regulators increasingly expect explainability and bias testing for AI used in rate-setting, eligibility, and claims triage, coordinated with the department of insurance rather than only a general attorney-general AI regime.

Which framework should insurers adopt for AI risk compliance?

The NAIC Model Bulletin points insurers toward recognized AI risk-management frameworks. The NIST AI Risk Management Framework (AI RMF 1.0) and ISO/IEC 42001:2023 are the two most widely referenced: NIST AI RMF supplies the govern-map-measure-manage functions that satisfy the bulletin’s written-program expectation, and ISO/IEC 42001 offers a certifiable AI management system for carriers operating across multiple states.

Automate AI governance with OneTrust

partner link

Manage AI inventory, risk assessments, and policy enforcement across your organization. Used by hundreds of regulated enterprises.

See OneTrust AI Governance →

Last reviewed 2026-07-05. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.