A patent claim and a state insurance bulletin are written for opposite audiences, but two of them now describe the identical control: a mandatory human confirmation step before an AI output is accepted.

Patra's US Patent 12,639,972, issued May 26, 2026, and Sixfold's US Patent 12,561,746, issued February 2026, each fence a version of that mechanism as private property, just as 24 states and the District of Columbia require insurers to document human oversight under the NAIC Model Bulletin (Quarles, 2026).

Key Takeaways

  • 24 states plus DC have adopted the NAIC Model Bulletin or substantially similar guidance, all of which ask a carrier to evidence what oversees an AI output before it reaches a policyholder.
  • 68% of insurers rely on third-party AI tools while only 18% maintain dedicated tracking of vendor-level AI model risk, which is the gap that decides whether a carrier notices the dependency before renewal.
  • $270 billion of gross written premium now runs Sixfold's patented rule-encoding pipeline across carriers including Zurich North America, Guardian and Skyward Specialty.
  • Patra's claims end in a non-optional human confirmation, the same architectural choice that anchors a Section 101 argument and satisfies a regulator's oversight question.
  • More than 900 AI patents across State Farm, UnitedHealth, Allstate, Cigna and The Hartford sit a layer above this, on functions carriers run themselves rather than license.

Two Patents Claiming the Same Control

Patra Corporation, a privately held insurance business-process outsourcer, was granted Patent 12,639,972, "Systems and Methods for Value Extraction and Guided Review," with a priority date of February 2022 (Patra, July 2026). The claims cover a pipeline that maps word positions on a page, extracts a target value such as a coverage limit, then routes it to a human reviewer who must confirm before the system commits the result.

Named inventor Juan Cristian Martinez Vega described the patent as capturing "the foundation of the AI and human-in-the-loop mechanisms that are still at the core of what Policy Checking AI is today." The eligibility dimension of that grant is examined in Patra's patent as a survival strategy.

Sixfold's Patent 12,561,746, "Extracting Rules and Determining Risk Parameters from an Underwriting Manual," covers a transformer pipeline that ingests a carrier's unstructured underwriting manual and converts it into machine-readable code signals, risk signals and structured question-and-answer pairs encoding the carrier's appetite, traced in underwriting manuals becoming code. The AI Underwriter product layered on top launched June 2026 across carriers representing $270 billion in gross written premium, with Zurich reporting savings of up to two hours per submission across more than 200 underwriters and Skyward Specialty cutting quote response times by 35% (The Insurer, June 2026).

The two protect different technical steps. Both claim a version of the same governance idea: an AI output does not become authoritative until it passes a checkpoint the carrier did not design and, in most deployments, does not own.

The Control Doing Double Duty

The human-confirmation step is not incidental to either claim. Since the Federal Circuit's 2025 Recentive Analytics decision and the USPTO's August 4, 2025 guidance memo pulled examiners back toward a stricter Alice and Mayo framework, a claim that says apply AI to an existing task reads as an abstract idea. A claim specifying a pipeline that ends in a non-optional human or rule-based determination gives an examiner a technical anchor.

That same architecture is the artifact regulators ask carriers to document. The NAIC Model Bulletin, adopted December 4, 2023, directs insurers to maintain a written AI systems program covering governance, risk controls and internal audit for AI used directly or through a vendor, and to show that vendor-supplied AI is governed to the same standard as internally built AI. Colorado has since layered on an annual model-documentation cycle for auto and health carriers.

The practical requirement is identical across every version: what oversees the AI, who confirms its outputs, and how that is evidenced on demand. When the control lives inside a vendor's patented workflow, the carrier's compliance narrative and the vendor's licensing terms become the same document.

Dimension Build in-house License from Patra or Sixfold
Upfront cost Full data science and engineering build, no licensing fee Subscription or per-seat licensing, lower upfront capital
Patent exposure Must design around claims covering document-scan-plus-confirmation or manual-to-rule encoding, or accept infringement risk Licensed use is authorized; risk shifts to contract terms, not litigation
Compliance documentation Carrier controls the full audit trail and can tailor it to any state's exact bulletin language Carrier depends on the vendor's documentation format and cooperation for regulator requests
Switching cost None; the control is owned outright High if the carrier's risk appetite is encoded inside the vendor's proprietary rule set
Time to deployment Months to years, dependent on internal capacity Weeks, since the governed workflow already exists and is field-tested

That distinguishes this from the carrier-side portfolios. State Farm, UnitedHealth Group, Allstate, Cigna and The Hartford hold more than 900 AI patents across claims triage, computer vision and telematics pricing (CB Insights, 2026), on functions those carriers run themselves, where a competitor's patent is a freedom-to-operate question. Patra and Sixfold sit one layer down, in tooling carriers license, claiming the mechanism state guidance treats as a requirement.

The build column's patent exposure is not hypothetical. The Hartford filed a declaratory-judgment suit against Intellectual Ventures in April 2026 over patents targeting off-the-shelf infrastructure embedded in its stack, including Docker, Kubernetes and Apache Spark (Insurance Business, April 2026). That case involved generic infrastructure, and a purpose-built human-confirmation pipeline is a considerably narrower and more clearly infringeable target.

Lock-In on the Compliance Evidence, Not the Model

Standard vendor lock-in concerns center on model dependency: prompts tuned to one provider, fine-tunes that do not transfer, evaluation suites calibrated to specific outputs. A patented governance control adds a stickier layer, because the carrier's compliance evidence moves with the vendor rather than with the software.

Sixfold's pipeline shows the mechanism. Once a carrier's underwriting manual has been converted into Sixfold's machine-readable rule format, and the system has absorbed months of underwriter feedback on top of it, the carrier's own risk appetite is encoded in a structure only that patented pipeline produces and updates. Migrating it is not a data export. It is a re-derivation from the original manuals, minus whatever tacit knowledge the feedback loop captured.

The tracking gap makes that hard to see coming. 68% of insurers rely on third-party AI tools and 18% maintain dedicated vendor-level AI model risk tracking (Insurance Journal, May 2026). A carrier without that discipline is poorly placed to notice, ahead of a renewal, that its regulator-facing oversight control and its underwriting rule base sit inside one vendor's proprietary format. Running dual-vendor AI stacks hedges the model-concentration version of the problem and not this one, since two independently patented compliance workflows are structurally incompatible rather than redundant.

The contract terms that would close the gap are audit access to the control logic and portability of the accumulated rule base in a vendor-neutral format. Those mirror the model-risk practices actuaries already apply to third-party pricing models. What is new is that the counterparty holding the patent has a direct commercial incentive to resist exactly the terms that would make its governance mechanism replaceable.

Further Reading