The National Council of Insurance Legislators shelved its AI model act in March 2026 after its own sponsor concluded the votes were not there. The body best positioned to give states one adoptable legislative template will not produce one this year.
Carriers are left signing against four mismatched regimes at once, and the documentation that satisfies one does not automatically satisfy the next.
Key Takeaways
- 24 states plus D.C. have adopted the NAIC Model Bulletin, and four have layered their own insurance-specific AI regulation on top of it rather than in place of it.
- Colorado changed shape mid-year. SB 26-189, signed May 14, 2026, replaced the algorithmic-discrimination duty with a 30-day post-decision explanation, so bias-testing infrastructure built for the prior law answered a question the statute no longer asks.
- Exhibit C is a different bar than the bulletin. It requires per-model design detail, training-data description, validation procedures and bias-testing results, where a Model Bulletin attestation describes a program.
- Executive Order 14365 asserts federal authority broadly enough to reach routine analytical tools, and McCarran-Ferguson's reverse-preemption doctrine, in force since 1945, is not addressed in it.
- The pilot runs regardless. Twelve states began March 2, 2026, running through September, with adoption expected at the Fall National Meeting in November.
Why NCOIL Could Not Get to Yes
Sponsor Erik Dilan introduced a model act on insurers' use of AI to the Financial Services and Multi-Lines Issues Committee, built around a core requirement: a "qualified human professional" makes final claims and underwriting decisions, insurers maintain action records, and consumers are told when AI touched their outcome. At the March 2026 meeting Dilan told the committee that reaching consensus was unlikely, and the group paused development rather than force a vote it would lose.
The split was structural. Insurers argued the human-final-decision requirement would slow straight-through claims processing built over two years. Consumer advocates argued the disclosure language was too easy to satisfy with boilerplate. Legislators from states that had already adopted the NAIC Model Bulletin questioned whether a separate NCOIL model would add a layer to reconcile against rather than one to adopt in place of existing guidance.
What advanced instead was a resolution favoring state-based AI oversight over federal preemption, a narrower ask that could clear the room. States are left to write their own.
| Regime | Legal Basis | Core Requirement | Enforcement Path |
|---|---|---|---|
| NAIC Model Bulletin adopters | State regulatory bulletin, 24 states + D.C. | Written AI governance program: risk management, documentation, third-party oversight | Market conduct exam, financial exam |
| Non-adopter states | No AI-specific guidance | General unfair trade practices and rating statutes only | Case-by-case, existing rate/claims review |
| Independent state statutes | Colorado SB 26-189; Illinois AI Systems Use in Health Insurance Act | Consumer notice and disclosure when AI drives a consequential decision | State AG (Colorado) or Dept. of Insurance (Illinois), private right of action varies |
| EU AI Act exposure | EU Regulation 2024/1689, Annex III high-risk systems | Conformity assessment, technical documentation, human oversight design | EU market surveillance authorities, fines up to 7% of global turnover |
What the Actuary Signs Against
The four regimes do not nest inside one another, which is the whole problem.
Twenty-four states plus D.C. have adopted the Model Bulletin, and four states have layered their own insurance-specific AI regulation on top. Colorado is one of them, and Colorado itself changed shape mid-year: Governor Polis signed SB 26-189 on May 14, 2026, replacing the original algorithmic-discrimination duty, which would have required insurers to actively test for and prevent unfair bias, with a narrower notice regime giving consumers 30 days of explanation after an adverse automated decision. A carrier that spent 18 months building bias-testing infrastructure for the prior version built for a requirement that no longer exists.
Illinois runs a parallel but different statute. The Artificial Intelligence Systems Use in Health Insurance Act puts the Department of Insurance in charge of reviewing how carriers use AI in adverse determinations and bars denying, reducing or terminating benefits based solely on an AI system's output. That "solely" standard has no direct analog in the bulletin or in Colorado's disclosure rule. For carriers with any European book, Annex III of the EU AI Act adds conformity-assessment and technical-documentation duties on its own clock.
The evaluation tool is where the four converge on the actuary's own file. Unlike the bulletin, which asks for a governance narrative, it is a structured examiner questionnaire built to be scored and fed into market conduct and financial examinations:
- Exhibit A inventories every AI system in production, complaint volume tied to each, and forward deployment plans, giving examiners a baseline count before a single governance question.
- Exhibit B scores the governance framework in narrative and checklist form, testing whether the program described in a bulletin attestation actually operates as documented.
- Exhibit C drills into specific high-risk systems, requiring model design detail, training data description, validation procedures and bias-testing results for each one individually.
- Exhibit D examines data provenance and quality controls, with attention to whether rating variables function as proxies for race or ethnicity.
Exhibit C is the gap between a governance checklist and an actuarial validation file. A carrier can hold a bulletin-compliant program on paper, with a designated AI officer and a documented risk framework, and still fail Exhibit C if the pricing model's validation file lacks per-model bias-testing results and training-data lineage. "Does a governance program exist" and "can this specific model be evidenced" are different tests, and only the second decides whether a market conduct exam produces a corrective action plan.
The Preemption Fight Makes the Investment Undecidable
The federal layer is where the money question sits, and it is more tangled than a single bill.
Senator Cruz's proposed 10-year moratorium on state AI enforcement was stripped from the reconciliation package in a 99-1 Senate vote in July 2025, killing that vehicle. The push survived it. On December 11, 2025 the administration signed Executive Order 14365, asserting federal authority over AI regulation broadly enough that, per legal analysis, it could reach "routine analytical tools insurers use every day" rather than generative AI alone.
The NAIC opposed the order within days, asking the administration to "reconsider this Executive Order and, at a minimum, affirm state regulation of AI in the business of insurance", and warning that it "introduces legal uncertainty, which may weaken the insurance market by delaying business decisions, deterring investment, and postponing essential consumer protections".
Congress has produced competing attempts to codify some version of it. The bipartisan Great American AI Act would preempt state regulation targeting AI model development, but only for three years and only for development-stage rules, leaving general-applicability laws including most insurance rating and claims statutes untouched. A broader TRUMP AMERICA AI Act seeks a wider sweep. Neither has passed, and McCarran-Ferguson's reverse-preemption doctrine, shielding state insurance regulation from generally applicable federal statutes since 1945, is not addressed in EO 14365.
That leaves the compliance budget in an undecidable position. Carriers spent 2024 through 2026 building state-specific infrastructure: bias-testing pipelines for Colorado's original duty, adverse-determination workflows for Illinois, Exhibit B and C narratives for the bulletin. A narrow preemption bill makes part of that legally unnecessary in the states it reaches, while non-compliance today cannot be risked on a bill that has not cleared committee. Meanwhile the pilot runs on its own schedule: twelve states from March 2, 2026 through September, tool updates in September and October, adoption expected at the Fall National Meeting in November. None of the federal uncertainty moves that date.
Further Reading
- AI Regulation in Insurance 2026: The NAIC Model Bulletin, State Adoption, and the Federal Preemption Battle
- Three Months to the EU AI Act: Insurers Need Compliance Actuaries
- Article 50 Still Lands August 2: What Carriers Owe on EU AI Act Transparency: how the EU's chatbot and synthetic-content disclosure regime compares to the fragmented US state chatbot laws this piece tracks
- NAIC's AI Evaluation Tool Turns Bulletins Into a Scored Exam
- NAIC's 2026 AI Evaluation Pilot Moves Ahead as Industry Balks
- NAIC Flags Agentic AI as Insurance’s Next Governance Gap
- NAIC's AI Risk Taxonomy and the Compliance Framework Behind It
- The August 2026 credit-scoring letters to six carriers – federal pressure arriving alongside the state regimes.
Sources
- Repairer Driven News: NCOIL Resolution Encourages State-Level Regulation of AI Use in Insurance, March 2026
- NAIC Big Data and Artificial Intelligence (H) Working Group
- NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, December 2023
- Fenwick: NAIC Expands AI Systems Evaluation Tool Pilot Program to 12 States
- Mayer Brown: US NAIC Spring 2026 National Meeting Highlights, H Committee Update
- NAIC: Statement on AI Executive Order, December 2025
- Swept AI: Executive Order 14365 vs. NAIC, 2026 Insurance AI Compliance
- Washington Legal Foundation: Compromise Necessary but Not Sufficient for AI Preemption, June 2026
- Mintz: Colorado's Not Finished Regulating AI, Reenacted AI Law, June 2026
- National Law Review: Artificial Intelligence Infiltrating Healthcare in Illinois and Its Effects on Insurers
- WaterStreet Company: What Comes Next for Insurance AI
- InsuranceNewsNet: NAIC's 2026 AI Evaluation Pilot Moves Ahead as Industry Balks