A patent claim and a state insurance bulletin are written for opposite audiences, but in 2026 two of them describe the identical control: a mandatory human confirmation step before an AI output is accepted. Patra's US Patent 12,639,972 (issued May 26, 2026) and Sixfold's US Patent 12,561,746 (issued February 2026) each fence a version of that mechanism as private property, just as 24 states and the District of Columbia require insurers to document human oversight under the NAIC Model Bulletin (Quarles Law Firm, 2026).
Two Patents, One Control Mechanism
Patra Corporation, a privately held insurance business-process outsourcer, was granted US Patent 12,639,972, "Systems and Methods for Value Extraction and Guided Review," on May 26, 2026, with a priority date of February 2022 (USPTO, May 2026; Patra, July 2026). The claims cover a document-scanning pipeline that maps word positions on a page, extracts a target value such as a coverage limit, and then routes that value to a human reviewer who must confirm it before the system commits the result to the record. Patra Chief Technology Officer Tony Li's team built the product, Policy Checking AI, around that sequence, and named inventor Juan Cristian Martinez Vega described the patent as capturing "the foundation of the AI and human-in-the-loop mechanisms that are still at the core of what Policy Checking AI is today" (Patra, July 2026). The site covered the Section 101 dimension of that grant in depth in its analysis of Patra's patent as a survival strategy; this piece works a different question: what the grant does to a carrier's build-versus-buy math.
Sixfold AI's US Patent 12,561,746, "Extracting Rules and Determining Risk Parameters from an Underwriting Manual," issued in February 2026 and covers a transformer-based pipeline that ingests a carrier's unstructured underwriting manual and converts it into machine-readable rules: code signals, risk signals, and structured question-and-answer pairs that encode the carrier's risk appetite. The site examined the switching-cost implications of that specific patent in its coverage of underwriting manuals becoming code. Sixfold has since layered a live decision-capture loop on top of that patented ingestion pipeline in its AI Underwriter product, launched in June 2026 and now running across carriers representing $270 billion in gross written premium, including Zurich North America, Guardian, Generali Global Corporate & Commercial, and Skyward Specialty (The Insurer, June 2026). Zurich reports saving up to two hours per submission across more than 200 underwriters, and Skyward Specialty has cut quote response times by 35% (The Insurer, June 2026).
The two patents protect different technical steps, extraction-plus-confirmation in Patra's case, manual-to-rule encoding in Sixfold's, but both claim a version of the same governance idea: an AI system's output does not become authoritative until it passes through a defined human or rule-based checkpoint that the carrier did not design and, in most deployments, does not own.
Human-in-the-Loop as a Double-Duty Claim Element
The reason both patents lean on a human-confirmation step is not incidental. Since the Federal Circuit's 2025 Recentive Analytics decision and the USPTO's August 4, 2025 guidance memo pulled examiners back toward a stricter Alice/Mayo framework, a claim that merely says "apply AI to an existing task" reads as an abstract idea with no inventive concession (USPTO, August 2025). A claim that instead specifies a concrete pipeline ending in a non-optional human or rule-based determination gives an examiner a technical, non-abstract anchor to point to. The same architectural choice that survives Section 101 scrutiny is, separately, the exact control artifact regulators are now asking carriers to document: a documented point where a person or a validated rule set, not an unsupervised model, finalizes the output.
That double duty is what makes 2026's patent activity different from the carrier-side portfolios this site has tracked elsewhere. State Farm, UnitedHealth Group, Allstate, Cigna, and The Hartford collectively hold more than 900 AI patents covering claims triage, computer vision, and telematics pricing (CB Insights, 2026), functions those carriers run themselves and where a competitor's patent mostly matters for freedom-to-operate risk. Patra's and Sixfold's patents sit one layer down, in the vendor tooling carriers license rather than build, and they claim the specific mechanism a growing body of state guidance treats as a compliance requirement rather than an engineering nicety. A carrier does not merely risk infringing a competitor's pricing algorithm; it risks discovering that the control it needs to show a regulator is itself somebody else's intellectual property.
What the NAIC Bulletin Actually Asks For
The NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023 and now in force through state adoption in 24 states plus DC (Quarles Law Firm, 2026), directs insurers to maintain a written AI systems program that includes governance, risk management controls, and internal audit processes covering AI systems the insurer uses directly or through a third-party vendor. The bulletin does not name "human-in-the-loop" as a specific technical requirement, but it does require insurers to be able to demonstrate that outputs affecting consumers are subject to appropriate oversight and that vendor-supplied AI is governed to the same standard as internally built AI. Several states have since layered on their own documentation regimes, including a Colorado auto and health carrier rule that pulled insurers into an annual model-documentation cycle for the first time, detailed in the site's coverage of that filing requirement, and the NAIC's own compliance report form that formalizes what a carrier's AI governance program must show, covered separately in the site's analysis of that form.
The practical requirement, across every version of this guidance, is documentation of a specific control: what oversees the AI, who or what confirms its outputs before they reach a policyholder, and how that oversight is evidenced on demand. When that control lives inside a vendor's patented workflow, the carrier's compliance narrative and the vendor's licensing terms become the same document. A carrier cannot describe its human-in-the-loop control to a regulator in terms different from how the vendor's patent describes it, because the control is the patent.
The Build-Versus-Buy Calculus, Reworked
Build-versus-buy in insurance technology has historically weighed development cost, time to deployment, and long-run total cost of ownership against a vendor's subscription price and integration effort, the framing this site applied to Roots Automation's Bevaya launch in its analysis of insurance-native AI platforms. A patented governance primitive adds a variable that does not show up in either side's price sheet: freedom-to-operate risk on the control itself.
| Dimension | Build in-house | License from Patra or Sixfold |
|---|---|---|
| Upfront cost | Full data science and engineering build, no licensing fee | Subscription or per-seat licensing, lower upfront capital |
| Patent exposure | Must design around claims covering document-scan-plus-confirmation or manual-to-rule encoding, or accept infringement risk | Licensed use is authorized; risk shifts to contract terms, not litigation |
| Compliance documentation | Carrier controls the full audit trail and can tailor it to any state's exact bulletin language | Carrier depends on the vendor's documentation format and cooperation for regulator requests |
| Switching cost | None; the control is owned outright | High if the carrier's risk appetite is encoded inside the vendor's proprietary rule set |
| Time to deployment | Months to years, dependent on internal capacity | Weeks, since the governed workflow already exists and is field-tested |
The freedom-to-operate risk in the "build" column is not hypothetical. The Hartford filed a declaratory-judgment suit against Intellectual Ventures in April 2026 over patents targeting off-the-shelf infrastructure, Docker, Kubernetes, and Apache Spark among them, embedded in its own technology stack rather than anything the carrier built or customized (Insurance Business, April 2026). That case involved generic infrastructure, not a purpose-built governance workflow, but it establishes the pattern: a carrier that assumes a category of tooling is unpatented generic infrastructure can be wrong, and a patented human-confirmation pipeline is a considerably narrower, more clearly infringeable target than a Kubernetes deployment.
Vendor Lock-In on the Control Primitive, Not Just the Model
Standard AI vendor lock-in concerns center on model dependency: prompts tuned to one provider's quirks, fine-tunes that do not transfer, evaluation suites calibrated against a specific model's outputs. A patented governance control adds a second, stickier layer, because the carrier's compliance evidence, not just its technology stack, is now tied to the vendor. Sixfold's rule-encoding pipeline illustrates the mechanism directly: once a carrier's underwriting manual has been converted into Sixfold's machine-readable rule format and the system has learned from months or years of underwriter feedback on top of it, the carrier's own risk appetite is encoded inside a structure only Sixfold's patented pipeline produces and updates. Migrating that institutional memory to a competing platform is not a data export; it is a re-derivation of the rule set from the original manuals, minus whatever tacit knowledge the feedback loop had already captured.
That risk is compounded by a documented governance gap: 68% of insurers rely on third-party AI tools, but only 18% maintain dedicated tracking of vendor-level AI model risk (Insurance Journal, May 2026). A carrier that has not built that tracking discipline is poorly positioned to notice, before a contract renewal forces the question, that its regulatory-facing human-in-the-loop control and its underwriting rule base both live inside a single vendor's patented, proprietary format. Some carriers are already hedging the model-concentration version of this risk by running dual-vendor AI stacks, a pattern the site documented in its analysis of Travelers' and AIG's parallel deployments, but a dual-vendor model layer does not solve dual-vendor governance-control redundancy if both vendors' compliance workflows are independently patented and structurally incompatible.
What to Put in the Vendor Contract
The IP fence around a governance primitive does not make licensing the wrong choice; it changes what the contract needs to cover, because the standard SaaS terms most carriers negotiate were not written with a patented compliance control in mind. Four terms matter more than they did before a governance mechanism itself carried patent protection. License scope should extend explicitly to regulatory use, meaning the carrier's right to describe and evidence the vendor's human-confirmation or rule-encoding step in its own NAIC-facing compliance documentation, not merely its right to run the software. Audit rights should guarantee the carrier's internal audit and compliance functions access to the underlying control logic on demand, not just aggregate output reports, since a regulator's request under a state's model-bulletin adoption will name the carrier, not the vendor. Documentation portability should require the vendor to supply the carrier's accumulated rule base, feedback history, and audit trail in a vendor-neutral format on contract termination, closing the re-derivation gap Sixfold's pipeline otherwise creates. Continuity provisions should address what happens to the carrier's compliance evidence, not just its software access, if the vendor is acquired, sunsets the product, or is itself found to infringe a third party's patent, the scenario The Hartford's Intellectual Ventures suit shows is not theoretical for insurance technology vendors.
None of those four terms are exotic asks; they mirror model-risk-management practices actuaries already apply to third-party pricing and reserving models under frameworks like the Federal Reserve's SR 11-7. What is new is that the counterparty holding the patent has direct commercial incentive to resist audit access and portability terms that would make its governance mechanism easier to replace.
Where Building In-House Still Wins
The build case has not disappeared, and for a specific class of carrier it strengthens. A large carrier with an established internal AI engineering team, a data science group already comfortable with document-extraction and human-review-queue architectures, and enough submission volume to amortize the build cost can design around both patents' specific claim language, scan-plus-word-position-mapping-plus-confirmation in Patra's case, transformer-based manual ingestion in Sixfold's, without replicating the patented sequence exactly. A carrier that builds in-house also owns its compliance narrative outright: the audit trail, the confirmation logs, and the underwriting rule base all live in formats the carrier controls, with no vendor contract standing between the carrier and a regulator's document request. For carriers below the scale where that internal build is realistic, and Sixfold's and Patra's client rosters suggest that threshold is higher than most mid-sized carriers clear alone, licensing remains the faster and often the only practical path to a documented human-in-the-loop control, provided the contract terms above are in place before the carrier's regulatory exposure, not after.
Further Reading
- Patra's AI Patent Signals a New Tier of Insurance IP Players – The Section 101 mechanics behind Patra's human-confirmation claim.
- Sixfold's Patent Shows How Underwriting Manuals Are Becoming Code – The switching-cost case built around the rule-encoding patent alone.
- How Insurance-Native AI Platforms Reframe the Carrier Build-vs-Buy Decision – The data-moat version of the same build-versus-buy question.
- Dual-Vendor AI Stacks Become the Carrier Playbook for Model Risk – How Travelers and AIG hedge model concentration, and why it does not solve governance-control redundancy.
- Colorado's Quiet Statute Pulls Carriers Into Annual AI Documentation – A state-level documentation regime the vendor contract terms above are built to satisfy.
- NAIC AI Model Bulletin Gets a Compliance Report Form – The formal reporting structure carriers now file against.
Sources
- Patra Corporation, "Patra Awarded U.S. Patent for AI Value Extraction," GlobeNewswire, July 7, 2026
- USPTO, Patent No. 12,639,972, "Systems and Methods for Value Extraction and Guided Review," issued May 26, 2026
- USPTO, Patent No. 12,561,746, "Extracting Rules and Determining Risk Parameters from an Underwriting Manual," issued February 2026
- The Insurer, "Sixfold Launches AI Underwriting Agent With Straight-Through Quote and Bind Capability," June 12, 2026
- Quarles Law Firm, "Nearly Half of States Have Now Adopted NAIC Model Bulletin on Insurers' Use of AI," 2026
- NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023
- USPTO, Subject Matter Eligibility Memo, August 4, 2025
- Insurance Journal, third-party AI vendor risk tracking survey coverage, May 21, 2026
- Insurance Business, "The Hartford Sues Intellectual Ventures Over Patents Targeting Major Insurers," April 2026
- CB Insights, AI Readiness Index for insurance carriers, 2026
- Fintech Global, "What Actuaries Need to Know About Agentic AI," July 10, 2026