The NAIC Model Bulletin on the Use of AI Systems by Insurers is adopted in some form in more than 25 states and the District of Columbia. None of those adoptions carries a penalty provision.

Colorado's algorithmic discrimination regulation under C.R.S. Section 10-3-1104.9 does, with a July 2026 compliance deadline, and Texas TRAIGA sets penalties of up to $200,000 per violation from January 1, 2026. The distance between advisory guidance and enacted law is the distance between an examination finding and an enforcement action.

Key Takeaways

  • The NAIC bulletin is adopted in more than 25 states with no penalty provision, while Texas TRAIGA carries $200,000 per violation enforced through the Attorney General rather than the Department of Insurance.
  • Colorado expanded Section 10-3-1104.9 from life to private passenger auto and health benefit plans in October 2025, roughly tripling the number of in-scope models at a carrier writing the state.
  • The July 2026 deadline requires a documented bias testing methodology operational, not planned, including an actuarial sign-off on whether observed disparity has an actuarially sound defense.
  • 23 comment letters landed on the NAIC Third-Party Data and Model Vendor Framework, which would push the same documentation duty into vendor and MGA relationships.
  • Colorado's SB 26-189 grants carriers that satisfy Section 10-3-1104.9 a deemed-compliant safe harbor under the broader automated decision-making framework taking effect January 1, 2027.

Two Statutes, Two Enforcement Routes

The obligations that now bite are statutory, and they run on different triggers from the bulletin regime actuarial teams built for.

Colorado's Section 10-3-1104.9 prohibits carriers from using external consumer data sources, algorithms, or predictive models that unfairly discriminate on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression. It has been on the books in some form since 2021. What changed in October 2025 was scope: the Division of Insurance extended it from life to private passenger auto and health benefit plans.

The implementing regulation's bias testing methodology has four parts: a statistical test for disparate impact across protected characteristics; a causal analysis of whether external data sources carry proxies for those characteristics; documentation of training data provenance and preprocessing decisions; and an assessment of whether any identified disparate impact is defensible on actuarially sound principles. Governance sits at named senior officer level, and annual reporting to the Division runs on a calendar cycle whether or not an examination is scheduled.

Texas TRAIGA, effective January 1, 2026, covers high-impact AI systems used in consequential decisions across eight named domains including insurance. Its insurance carve-out is narrower than it reads. It does not cover the carrier as an employer, and asserting it requires demonstrated compliance with the Texas Insurance Code's unfair discrimination statutes, which is the same documentation the exemption is meant to spare. Enforcement runs through the Attorney General, so a gap in the exemption's support is exposure even where TDI has raised nothing.

The Attribution Chain the Notice Requires

The fourth element of Colorado's bias test is an actuarial conclusion, and the notice obligation behind it is where most model documentation stops short.

Whether an observed disparity has an actuarially sound justification is not a legal finding. It is an actuarial one, and under the DOI's rules it appears in the documented methodology under a named officer. That signature is the compliance artifact, and it has to rest on the same testing evidence the annual report carries.

The consumer-facing half is harder. Colorado requires disclosure of which external consumer data sources contributed to a decision, with enough specificity for the consumer to identify what to contest. TRAIGA requires notice that an AI system contributed to a consequential decision, with reasoning sufficient to support appeal or a request for human review. Both point at the same technical layer: a transaction-level record of which inputs, in terms a consumer can read, produced that consumer's outcome.

SHAP values and partial dependence plots are actuarially meaningful explanations. They are not adverse action notices. Where consumer report data is among the inputs, the Fair Credit Reporting Act's Section 615(a) notice overlays the state duty and requires the credit component's contribution to be identified separately from the other model inputs. Colorado extends that attribution logic to any external consumer data source in an in-scope model.

That is an infrastructure requirement, not a documentation one. The serving layer has to capture feature values and the decision rule mapping for every scored transaction, retain them for the statutory period, typically three years under Colorado's framework, and expose them queryable by transaction rather than by model version. The EU AI Act sets the same bar higher still, classifying underwriting, life and health risk assessment, and claims assessment as Annex III high-risk systems requiring an immutable audit log and on-demand per-decision retrieval. A program built to Annex III clears every current U.S. state requirement, which is why multinational cedants and capacity providers increasingly ask for it.

The Obligation Can Arrive Through a Model the Carrier Never Built

The chain does not stop at the carrier's own models, and that is where the statutory design has the least settled answer.

The NAIC Third-Party Data and Model Vendor Framework drew 23 comment letters after its spring 2026 exposure and is expected to advance toward adoption at the Fall National Meeting in November 2026. It would extend the documentation duty into vendor relationships directly. A carrier licensing a third-party predictive model holds the same obligations as one that built its own, but cannot independently generate the training data provenance, validation methodology, or attribution capability behind it. Vendor documentation capacity becomes a procurement term rather than a diligence footnote.

Delegated authority compounds it. An MGA underwriting on a carrier's paper with a licensed model holds some share of the obligation, but the allocation depends on how binding authority is written and which entity made the consequential decision. A carrier can end up holding the statutory duty for a model it did not build, did not validate, and cannot document, because the adverse decision reached the consumer on its policy.

Colorado's SB 26-189 sharpens rather than softens this. It replaces high-risk artificial intelligence systems with automated decision-making technology as the operative term, moves the general effective date to January 1, 2027, and deems carriers that satisfy Section 10-3-1104.9 compliant with the broader framework. The safe harbor is real relief for a carrier that meets the insurance standard. A carrier that misses the July 2026 deadline does not simply fail one regulation. It loses the harbor and stands exposed under both frameworks at once, on models that may have entered its book through a vendor contract or a binding authority it did not write.

Further Reading

Sources