Hartford published a voluntary Algorithmic Impact Assessment in February 2026, the first bias-transparency commitment on production models from a top-20 carrier. It landed nine months before the NAIC's AI Systems Evaluation Tool pilot reports and more than a year before Colorado's SB 205 enforcement date.

The document matters less as a disclosure than as a template. It answers, in a form a regulator can request, the question that market conduct examinations and discovery requests are both converging on: how does the carrier know its models are not discriminating?

Key Takeaways

What the Assessment Actually Covers

The bias audit scope is narrow and specific. Three dimensions: ZIP code, a documented proxy for race and income; policyholder age; and property type, where the rural and urban split can correlate with protected class membership. For each, the assessment documents the statistical method used to test disparate impact, the threshold that triggers remediation, and who the breach escalates to.

Validation runs on three lines. First line sits in the business unit that owns the model, typically pricing or underwriting. Second line is an independent model risk function reporting to the Chief Risk Officer. Third line is internal audit, testing whether the first two follow their own documented procedures. The structure is the one banking regulators have required since OCC Bulletin 2011-12.

Escalation is the design choice worth noting. Any output flagged in bias testing goes to a credentialed actuary or a senior underwriter before it can influence a policyholder-facing decision. That is a structured exception path for results outside documented tolerance bands, not review of every transaction, which is the distinction the NAIC's own Spring 2026 agentic AI discussion kept circling.

Vendor systems are inside the perimeter. Hartford's deployment of mea Platform's generative AI for underwriting document processing is subject to the same testing and validation as internally built models, which closes the gap the NAIC's Third-Party Data and Models Working Group was debating at the same meeting.

Why the Documentation Set Is the Regulatory Asset

The Evaluation Tool is the reason this is worth building before anyone asks. The NAIC's Big Data and Artificial Intelligence Working Group launched the pilot on March 2, 2026 across 12 states, running through September 2026, with adoption expected in November. It is organised around four exhibits.

Exhibit Purpose Hartford AIA Alignment
Exhibit A Quantify AI usage across insurance operations Hartford's enterprise AI inventory covers claims, underwriting, operations, and contact center functions
Exhibit B Governance risk assessment framework Three-lines-of-defense validation, CRO-level risk management reporting
Exhibit C Details on high-risk AI systems AIA's bias audit scope (ZIP code, age, property type) directly addresses high-risk use cases in pricing and underwriting
Exhibit D AI data specifics, including reasonable accommodations Data source documentation and vendor audit coverage for third-party inputs

Exhibit C is where the cost sits, because the four-tier risk taxonomy NAIC staff presented at Spring 2026 puts pricing models, underwriting algorithms, and claims triage tools in the high-risk band. Hartford's audit scope covers exactly those functions, so an Evaluation Tool data request is a retrieval exercise rather than a construction project.

The New York DFS Circular Letter No. 7 forecloses the obvious workaround. It requires insurers to show that external consumer data sources are not proxies for protected classes, using data that is available or "reasonably imputed using statistical methodologies." A carrier cannot decline the test on the grounds that it does not collect protected class data directly, so the imputation methodology itself becomes a documented actuarial judgment subject to review.

The counterfactual is running in parallel. State Farm is facing a class action in the Northern District of Illinois alleging its claims algorithms disproportionately flagged Black policyholders for heightened scrutiny, and a federal judge denied the motion to dismiss in early 2026. Discovery will produce algorithmic governance documentation either way. The variable is whether the carrier wrote it in advance or reconstructs it under an adversarial framing.

One Assessment, Four Regimes That Do Not Line Up

The constraint on the template is that the requirements it satisfies are not converging on a single standard.

The NAIC Model Bulletin had been adopted in some form by 23 states and Washington, D.C. as of late 2025. It requires a written AIS Program but does not mandate public disclosure of bias audit results, so it sets an evidentiary expectation without specifying the evidence.

Colorado SB 205 works differently. It creates a duty of reasonable care against algorithmic discrimination from June 30, 2026, penalties reach $20,000 per violation, and enforcement sits with the Attorney General rather than the insurance commissioner. The carve-out for insurers exists only where they meet the commissioner's standards for external data governance, which makes insurance-side compliance a precondition rather than an exemption.

New York's Circular Letter demands quantitative proxy assessment and vendor audits. Connecticut's SB 2, stalled by a veto threat in 2025 but repeatedly reintroduced, would require the assessment before deployment plus a published summary statement. Four regimes, four different artefacts.

That is the real cost of moving early rather than the reason not to. NAIC surveys found 88% of responding auto insurers and 92% of responding health insurers using, planning to use, or exploring machine learning models, so the population facing this is close to the whole market. A carrier that builds one assessment gets a base document and four adaptation projects. A carrier that builds nothing gets four simultaneous construction projects on statutory deadlines it does not control.

Further Reading

Sources