Washington SB 5395 creates the first state-level disclosure regime in the country requiring health carriers to report, annually to the insurance commissioner, the percentage of prior-authorization denials aided by AI tools and algorithms (Washington Legislature, March 2026). The reporting section anchors a six-state patchwork of 2026 laws restricting AI in adverse coverage determinations, with Iowa HF 2635 and Indiana HB 1271 both effective July 1, 2026.
The Six-State Slate
Six US states enacted AI-restrictive health insurance statutes taking effect across 2026 and January 2027: Alabama, Georgia, Indiana, Iowa, Utah, and Washington (National Law Review, July 2026). Maryland HB 1563, effective June 1, 2026, adds a seventh statute with quarterly reporting requirements to the state insurance commissioner (Holland & Knight, May 2026). Each law addresses the same underlying concern from a different structural angle: whether algorithmic systems can serve as the terminal decision-maker on coverage denials, delays, or downcoding.
Washington SB 5395 was signed by the governor on March 25, 2026 and takes effect June 11, 2026 (Washington Senate Democrats, March 2026). It prohibits health carriers, healthcare benefit managers, and public employee health plans from relying exclusively on AI to deny prior authorization, and it requires that a licensed physician or other licensed professional acting within scope make the adverse determination. Section 6 of the bill layers an annual data-reporting obligation on top of that substantive rule.
Iowa HF 2635, effective July 1, 2026, permits utilization review organizations to use an AI-based algorithm or system for the initial review of a prior authorization request, but forbids AI from serving as the sole basis for a decision to deny, delay, or downgrade a request based on medical necessity (Iowa Legislature, April 2026). Denials or downgrades must be made by a qualified reviewer or clinical peer meeting Iowa's specialty and experience requirements. The URO framing is important: Iowa is regulating the vendors that many carriers outsource prior-authorization workflows to, not only the carriers themselves.
Indiana HB 1271, now Public Law 88, also took effect July 1, 2026 (Indiana General Assembly, March 2026). Its distinguishing feature is the downcoding restriction: AI may not be the sole basis for downgrading a submitted claim without healthcare professional review, and adverse determinations must disclose the use of AI. The Indiana bill also caps overpayment recoupments at 180 days from the date the claim was initially paid, a companion provision that tightens the operational envelope in which retrospective claims review, algorithmic or otherwise, must occur.
Alabama SB 63, effective October 1, 2026, requires insurers to base AI-assisted prior authorization decisions on individual beneficiaries' medical histories and circumstances, and mandates annual certification that AI systems do not discriminate and undergo accuracy monitoring (Holland & Knight, May 2026). Utah SB 319 and Georgia SB 544 both take effect January 1, 2027, and both bar sole reliance on AI for adverse determinations while adding disclosure obligations to enrollees and providers.
Washington's Reporting Section: The First Benchmark Dataset
The Washington reporting requirement is the analytically significant piece for actuaries. Carriers writing at least one percent of total accident and health insurance premiums in Washington must report the total number of prior-authorization requests, approvals, and denials; the breakdown by health plan and each delegated healthcare benefit manager; response-time metrics across authorization categories; and, in the operative clause, "the percentage of total denials that were aided by artificial intelligence tools and algorithms" (Washington Legislature, March 2026). The commissioner is directed to aggregate the data into a standard public report without identifying specific carriers, with annual AI-transparency reporting beginning January 2027.
Once the January 2027 report cycle completes, actuaries will have, for the first time, a state-level dataset pairing denial volumes with an AI-assisted-percentage variable. That structure permits comparison across carriers in the same state and same regulatory environment of a variable that has previously been either aggregated at the national level or inferred through litigation discovery. The prior-authorization denial rate on Medicare Advantage post-acute care at one large national carrier rose from 10.0% in 2020 to 22.7% in 2022 across the period when that carrier was implementing automation initiatives (Nature Digital Medicine, June 2026). The Washington report will make cross-carrier variance of the same kind observable at the state level, in the ordinary course of regulatory filings, rather than only through class-action discovery.
Sen. Tina Orwall, the SB 5395 sponsor, framed the reporting section's intent plainly: "Washingtonians can now have confidence that only licensed providers are ultimately making these critical insurance decisions, not AI" (Washington Senate Democrats, March 2026). The confidence is enforceable only if the data underneath the disclosure regime is credible; the section's requirement to disaggregate denials to health plan and delegated healthcare benefit manager level makes it hard for a carrier to obscure the AI-assisted share by aggregation.
The Actuarial Read on the July 1 Effective Dates
The Iowa and Indiana statutes taking effect the same day generate parallel but distinct pricing implications for 2027 rate filings. Indiana's downcoding restriction shifts loss adjustment expense from algorithm-only pipelines back to case-manager review for the subset of claims where downcoding is contemplated. A carrier that previously ran automated downcoding at high throughput and low incremental LAE now needs a healthcare professional in the workflow to sustain the same practice. The unit cost of downcoding review rises; the volume of downcoded claims may fall as the higher unit cost prices some marginal cases out of the workflow. Both effects flow into loss ratios and administrative expense loads that inform 2027 rate filings.
Iowa's URO framing shifts risk further upstream. A carrier that contracts with a third-party utilization review vendor for prior-authorization services in Iowa needs to confirm that the vendor's AI workflow satisfies HF 2635's requirement that AI not serve as the sole basis for denial, delay, or downgrade (Iowa Legislature, 2026). If the vendor's product does not, either the vendor reworks its process or the carrier absorbs the change through renegotiated terms. Either way, the vendor economics that supported low-cost outsourced prior-authorization review under prior Iowa law shift materially (Iowa Legislature, April 2026).
Beyond the direct expense-side implications, the actuarial memoranda supporting 2027 rate filings in the affected states now need to document two parallel exposure paths. The federal path is the CMS prior-authorization interoperability rule, which required payers to publish annual prior-authorization metrics including approval rates, denial rates, and average decision times with first reports due by March 31, 2026 (CMS, March 2026). The state path is the AI-specific statutory framework applicable in each of Alabama, Georgia, Indiana, Iowa, Utah, Washington, and Maryland, each with different disclosure, human-in-the-loop, and reporting particulars. Actuarial memoranda that reference only the federal path miss half the compliance surface for multistate carriers.
Dual-Track Compliance With the NAIC Model Bulletin
The state statutory patchwork sits alongside the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the NAIC in December 2023 and now adopted or referenced in twenty-five states plus the District of Columbia as of mid-2026 (NAIC, June 2026). Four additional jurisdictions, including California, Colorado, New York, and Texas, operate under their own AI insurance frameworks, bringing the total number of jurisdictions with a formal AI insurance regime to twenty-nine (actuary.info, June 2026).
The Model Bulletin operates at a different layer than the six state statutes. It requires a written AI Systems Program with senior-management and board accountability, risk controls, model validation and testing for bias and errors, and oversight of third-party AI tools. It applies across insurance lines and across use cases, not only to health insurance prior authorization. The state statutes at issue are line-specific and use-case-specific: they regulate the terminal decision-maker on adverse coverage determinations, not the governance architecture around AI generally.
For a multistate health carrier, the compliance surface is now dual-track. The AI governance framework satisfying the NAIC Model Bulletin in the twenty-five bulletin-adoption states must be extended, in the six-plus statute states, with substantive rules about which decisions the AI can make and which reporting outputs must reach the state insurance commissioner. Colorado's insurance-specific AI regime, which took a further step in June 2026, adds another regulatory dimension for carriers licensed there (actuary.info, 2026). The state patchwork discussed here overlays a preexisting patchwork of AI-in-insurance regimes that carriers already had to navigate (actuary.info, 2026).
Reading the Numerator Against the Denominator
The most valuable analytical property of the Washington reporting section is that it produces a numerator (AI-assisted denials) against a denominator (total denials) at the carrier level. Once released in aggregate form by the Office of the Insurance Commissioner, the report allows external observers, whether actuaries, regulators, providers, or plaintiff's counsel, to compute the AI-assisted denial share by carrier and by benefit manager. That share, benchmarked against the observed denial rate, becomes a rough proxy for whether AI-assisted denials cluster at higher or lower denial rates than human-only decisions within the same carrier.
The interpretive complications are significant. Confounders include case-mix differences between AI-triaged and human-only queues, the routing rules a carrier uses to send a request to one queue versus the other, and appeal-overturn dynamics that may differ across the two paths. Nationally, 80.7 percent of appealed Medicare Advantage prior-authorization denials are overturned (KFF, February 2026), which suggests substantial noise in the initial denial signal regardless of AI involvement. But even a noisy first dataset is a step-change from the current information environment, where the AI-assisted percentage has been either unreported or accessible only through discovery in individual litigation.
For a health actuary preparing an experience study or a benchmark denial-rate analysis in 2027, Washington's report will provide a distribution rather than a point estimate. That distribution matters. It permits statements about how a specific carrier's AI-assisted denial rate compares to other carriers writing in the same market, and it makes it possible to hold constant the state-level regulatory environment when comparing carriers. In credibility-weighted analyses of denial patterns for population health projections or medical management pricing loads, the Washington data provides an external anchor that has not existed until now.
Enforcement and Documentation for Rate Filings
The seven-state statutory framework changes what documentation regulators can be expected to request in rate filing review. State DOI actuaries reviewing 2027 individual and small-group filings in Washington, Indiana, Iowa, Alabama, and Maryland now have statutory hooks for questions about how AI is used in the underlying claim and prior-authorization operations that inform the filing's projected loss ratios. Filings that project reductions in medical-management expense loads from AI adoption should anticipate follow-up questions about whether the operational model satisfies the applicable state statute.
Explainability requirements from the federal side reinforce the state-level trend. CMS has been signaling for the past year that explainable AI approaches to claims and fraud detection are the direction of travel for Medicare and Medicare Advantage (actuary.info, 2026). The convergence between state statutes requiring licensed human decision-makers and federal explainability guidance means that black-box scoring models applied to adverse determinations face pressure from both regulatory tracks simultaneously.
Rep. Alicia Rule, the House companion sponsor for SB 5395, framed the shared premise: "When people need medical care, the prior authorization process often slows access to treatment and is a barrier to care. When a prior authorization is needed, those decisions should be made by qualified medical professionals, not AI" (Washington Senate Democrats, March 2026). The statutory language backing that intent creates enforceable documentation obligations that flow into every actuarial memorandum touching prior-authorization economics in the states involved.
Table: 2026 State AI Health Insurance Statutes at a Glance
| State | Bill | Effective | Central Provision |
|---|---|---|---|
| Maryland | HB 1563 | Jun 1, 2026 | Quarterly reporting of adverse decisions and AI involvement |
| Washington | SB 5395 | Jun 11, 2026 | Licensed physician for denials; annual AI-share reporting |
| Iowa | HF 2635 | Jul 1, 2026 | URO framing; AI not sole basis for deny/delay/downgrade |
| Indiana | HB 1271 (PL 88) | Jul 1, 2026 | No AI as sole basis for claim downcoding; 180-day recoupment cap |
| Alabama | SB 63 | Oct 1, 2026 | Individual-basis PA decisions; annual anti-discrimination certification |
| Utah | SB 319 | Jan 1, 2027 | Disclosure to DOI, providers, enrollees; no sole AI reliance |
| Georgia | SB 544 | Jan 1, 2027 | Licensed provider review before adverse determination |
The Second-Order Signal
The six-state slate does more than restrict AI in a specific operational context. It creates the data infrastructure to observe whether AI-assisted decision pipelines produce systematically different denial rates than human-only pipelines within otherwise comparable carrier populations. That observation, once available in 2027 through the Washington report and in different form through Maryland's quarterly filings, will inform actuarial pricing assumptions, regulatory rate review, and provider-carrier contract negotiations for years.
A health actuary building loss-ratio projections for a 2027 filing in any of the affected states should treat the statutory changes as a case-mix event affecting the denominator of the medical-management economics. Prior-authorization workflows built around low-touch algorithmic decisioning will carry higher unit costs; the volume of denials sustained through appeal may shift as the mix between AI-assisted and human-only decisions rebalances; the LAE loads embedded in rating factors need to reflect the new operational envelope. None of these effects will be captured in prior-year experience data; all of them will show up in prospective filings that regulators will now have explicit statutory backing to interrogate.
The July 1, 2026 effective dates for Iowa and Indiana are the visible calendar event. The larger structural change is that adverse-determination decisions in health insurance now exist in a compliance environment where the terminal decision-maker's identity, human or algorithmic, is a regulated feature of the product, subject to disclosure and, in Washington and Maryland, subject to periodic reporting to the state insurance commissioner. Actuarial work touching prior-authorization economics in these states is now downstream of that regulatory feature, not upstream of it.
Further Reading
- Colorado AI Act: June 30, 2026 Insurance Compliance Deadline: Colorado's insurance-specific AI regime is the fourth of the standalone jurisdictional frameworks that sit alongside the NAIC Model Bulletin and the six-state health statutes discussed here.
- The State AI Law Patchwork: Four Regimes and What They Mean for Insurance Compliance: Broader map of the AI-in-insurance state regulatory environment into which the July 1, 2026 health-specific statutes now dock.
- NAIC AI Claims Handling Regulatory Focus 2026: Background on the NAIC Model Bulletin's operational reach and the twenty-five-state adoption profile as of mid-2026.
- CMS Prior Auth Metrics Go Public: Denial Rates, Processing Times, and Actuarial Pricing Impact: The federal-side prior-authorization disclosure regime that the state AI statutes now sit alongside.
- CMS and Milliman on Explainable AI in Medicare Fraud Detection: The federal signal on explainability that reinforces state statutory pressure against black-box scoring in adverse determinations.
Sources
- National Law Review: Additional States Continue Legislative Trend, New Laws Limiting Use of Artificial Intelligence (July 2026)
- Holland & Knight: States Continue Efforts to Regulate AI in Healthcare (May 2026)
- Washington Legislature: SB 5395 Bill Text (March 2026)
- Washington Senate Democrats: Orwall Bill to Improve Prior Authorization Transparency Signed Into Law (March 2026)
- Iowa Legislature: HF 2635 Enrolled Text (April 2026)
- Indiana General Assembly: HB 1271 (Public Law 88) Engrossed Text (March 2026)
- NAIC: Implementation Map of the AI Model Bulletin (June 2026)
- Nature Digital Medicine: Medicare Advantage Becoming a Disadvantage With Use of AI in Prior Authorization Review (February 2026)