The NAIC Model Bulletin on the Use of AI Systems by Insurers is adopted in some form in more than 25 states and the District of Columbia. None of those adoptions carries a penalty provision.
Colorado's algorithmic discrimination regulation under C.R.S. Section 10-3-1104.9 does, with a July 2026 compliance deadline, and Texas TRAIGA sets penalties of up to $200,000 per violation from January 1, 2026. The distance between advisory guidance and enacted law is the distance between an examination finding and an enforcement action.
Key Takeaways
- The NAIC bulletin is adopted in more than 25 states with no penalty provision, while Texas TRAIGA carries $200,000 per violation enforced through the Attorney General rather than the Department of Insurance.
- Colorado expanded Section 10-3-1104.9 from life to private passenger auto and health benefit plans in October 2025, roughly tripling the number of in-scope models at a carrier writing the state.
- The July 2026 deadline requires a documented bias testing methodology operational, not planned, including an actuarial sign-off on whether observed disparity has an actuarially sound defense.
- 23 comment letters landed on the NAIC Third-Party Data and Model Vendor Framework, which would push the same documentation duty into vendor and MGA relationships.
- Colorado's SB 26-189 grants carriers that satisfy Section 10-3-1104.9 a deemed-compliant safe harbor under the broader automated decision-making framework taking effect January 1, 2027.
Two Statutes, Two Enforcement Routes
The obligations that now bite are statutory, and they run on different triggers from the bulletin regime actuarial teams built for.
Colorado's Section 10-3-1104.9 prohibits carriers from using external consumer data sources, algorithms, or predictive models that unfairly discriminate on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression. It has been on the books in some form since 2021. What changed in October 2025 was scope: the Division of Insurance extended it from life to private passenger auto and health benefit plans.
The implementing regulation's bias testing methodology has four parts: a statistical test for disparate impact across protected characteristics; a causal analysis of whether external data sources carry proxies for those characteristics; documentation of training data provenance and preprocessing decisions; and an assessment of whether any identified disparate impact is defensible on actuarially sound principles. Governance sits at named senior officer level, and annual reporting to the Division runs on a calendar cycle whether or not an examination is scheduled.
Texas TRAIGA, effective January 1, 2026, covers high-impact AI systems used in consequential decisions across eight named domains including insurance. Its insurance carve-out is narrower than it reads. It does not cover the carrier as an employer, and asserting it requires demonstrated compliance with the Texas Insurance Code's unfair discrimination statutes, which is the same documentation the exemption is meant to spare. Enforcement runs through the Attorney General, so a gap in the exemption's support is exposure even where TDI has raised nothing.
The Attribution Chain the Notice Requires
The fourth element of Colorado's bias test is an actuarial conclusion, and the notice obligation behind it is where most model documentation stops short.
Whether an observed disparity has an actuarially sound justification is not a legal finding. It is an actuarial one, and under the DOI's rules it appears in the documented methodology under a named officer. That signature is the compliance artifact, and it has to rest on the same testing evidence the annual report carries.
The consumer-facing half is harder. Colorado requires disclosure of which external consumer data sources contributed to a decision, with enough specificity for the consumer to identify what to contest. TRAIGA requires notice that an AI system contributed to a consequential decision, with reasoning sufficient to support appeal or a request for human review. Both point at the same technical layer: a transaction-level record of which inputs, in terms a consumer can read, produced that consumer's outcome.
SHAP values and partial dependence plots are actuarially meaningful explanations. They are not adverse action notices. Where consumer report data is among the inputs, the Fair Credit Reporting Act's Section 615(a) notice overlays the state duty and requires the credit component's contribution to be identified separately from the other model inputs. Colorado extends that attribution logic to any external consumer data source in an in-scope model.
That is an infrastructure requirement, not a documentation one. The serving layer has to capture feature values and the decision rule mapping for every scored transaction, retain them for the statutory period, typically three years under Colorado's framework, and expose them queryable by transaction rather than by model version. The EU AI Act sets the same bar higher still, classifying underwriting, life and health risk assessment, and claims assessment as Annex III high-risk systems requiring an immutable audit log and on-demand per-decision retrieval. A program built to Annex III clears every current U.S. state requirement, which is why multinational cedants and capacity providers increasingly ask for it.
The Obligation Can Arrive Through a Model the Carrier Never Built
The chain does not stop at the carrier's own models, and that is where the statutory design has the least settled answer.
The NAIC Third-Party Data and Model Vendor Framework drew 23 comment letters after its spring 2026 exposure and is expected to advance toward adoption at the Fall National Meeting in November 2026. It would extend the documentation duty into vendor relationships directly. A carrier licensing a third-party predictive model holds the same obligations as one that built its own, but cannot independently generate the training data provenance, validation methodology, or attribution capability behind it. Vendor documentation capacity becomes a procurement term rather than a diligence footnote.
Delegated authority compounds it. An MGA underwriting on a carrier's paper with a licensed model holds some share of the obligation, but the allocation depends on how binding authority is written and which entity made the consequential decision. A carrier can end up holding the statutory duty for a model it did not build, did not validate, and cannot document, because the adverse decision reached the consumer on its policy.
Colorado's SB 26-189 sharpens rather than softens this. It replaces high-risk artificial intelligence systems with automated decision-making technology as the operative term, moves the general effective date to January 1, 2027, and deems carriers that satisfy Section 10-3-1104.9 compliant with the broader framework. The safe harbor is real relief for a carrier that meets the insurance standard. A carrier that misses the July 2026 deadline does not simply fail one regulation. It loses the harbor and stands exposed under both frameworks at once, on models that may have entered its book through a vendor contract or a binding authority it did not write.
Further Reading
- State AI Law Patchwork Forces Multi-State Carriers Into Four Distinct Compliance Regimes: How Connecticut SB 5, Colorado SB 26-189, the NAIC 12-state pilot, and Texas TRAIGA create four structurally different compliance frameworks with overlapping but non-identical obligations, and what annual compliance costs look like across jurisdictional footprints.
- NAIC AI Pilot Moves Insurer Reviews Into Market Exams: The four-exhibit evaluation tool that 12 states are deploying in market conduct and financial exams through September 2026, including what Exhibit C requires on high-risk AI system design, training data, and bias testing.
- Actuarial AI Model Validation in State Rate Filings: How state rate filing requirements for predictive models interact with the statutory AI compliance tier, and what documentation regulators are requesting at the filing stage.
- Aerial Imagery AI: Regulatory Bulletins in 13 States: An example of how a specific AI application in underwriting generated a wave of state regulatory bulletins before statutory law arrived, illustrating the bulletin-to-statute escalation pattern.
- Insurer AI Vendor Risk: The 68/18 Accountability Gap: The documentation accountability gap when carriers rely on third-party models, and how the anticipated NAIC third-party vendor framework would shift that accountability.
Sources
- Colorado Revised Statutes Section 10-3-1104.9: Unfair Discrimination, External Consumer Data and Information Sources (FindLaw)
- CO-AIMS: Colorado AI Act SB 24-205 Complete Compliance Guide 2026
- Alston & Bird: New Final AI Regulation from Colorado Department of Insurance (October 2023)
- Latham & Watkins: Texas Signs Responsible AI Governance Act Into Law (2025)
- Baker Botts: Texas Enacts Responsible AI Governance Act: What Companies Need to Know (July 2025)
- Norton Rose Fulbright: The Texas Responsible AI Governance Act: What Your Company Needs to Know
- NAIC: Artificial Intelligence and State Insurance Regulation Issue Brief (March 2026)
- Fenwick: Tracking the Evolution of AI Insurance Regulation (2026)
- EU Artificial Intelligence Act: Annex III High-Risk AI Systems (Official Text)
- WaterStreet Company: Colorado SB 205 Rules on Insurance AI
- IAPP: Texas Responsible AI Governance Act Compliance: A Sample Policy Framework