How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment

    Colorado SB26-189 introduces automated decision-making technology (ADMT) obligations for entities that use automated or AI-assisted systems in decisions with legal or similarly significant effects on consumers. For insurers and MGAs, this raises immediate questions about underwriting scores, pricing engines, claims triage, and fraud detection models. Because the statute's precise definitions, effective dates, and any insurance-specific carve-outs must be confirmed against the enacted bill text and Colorado Division of Insurance guidance, this guide focuses on the readiness work compliance teams can begin now: inventorying candidate ADMT systems, building governance documentation, and establishing auditable controls that hold up regardless of how specific thresholds are ultimately interpreted.

    Insurance AI Governance

    Colorado SB26-189 ADMT Framework: Insurance Compliance Guide

    Colorado SB26-189 introduces automated decision-making technology (ADMT) obligations for entities that use automated or AI-assisted systems in decisions with legal or similarly significant effects on consumers. For insurers and MGAs, this raises immediate questions about underwriting scores, pricing engines, claims triage, and fraud detection models. Because the statute's precise definitions, effective dates, and any insurance-specific carve-outs must be confirmed against the enacted bill text and Colorado Division of Insurance guidance, this guide focuses on the readiness work compliance teams can begin now: inventorying candidate ADMT systems, building governance documentation, and establishing auditable controls that hold up regardless of how specific thresholds are ultimately interpreted.

    At a Glance

    ADMT Readiness Snapshot

    Three workstreams summarize the readiness effort covered in this guide, independent of how Colorado's final statutory thresholds are interpreted.

    Scope Review

    Inventory underwriting, pricing, claims, and fraud systems against ADMT criteria.

    Governance Build

    Impact assessments, consumer notice, and human review documentation.

    Audit Readiness

    Decision-level logging and retained records for regulatory review.

    Governance Program Components to Establish

    Compliance teams can begin building these program components now, ahead of final regulatory interpretation.

    • A documented inventory of internal and vendor systems used in underwriting, pricing, claims, and fraud decisioning
    • An impact assessment process applied before deploying or materially changing a covered system
    • A consumer notice mechanism describing when automated decisioning is used and how it affects the outcome
    • A human review workflow with documented authority to override or reverse an automated output
    • An audit log capturing model version, inputs, output, and any human intervention for each covered decision
    • A defined record retention period aligned to applicable statutory or regulatory requirements

    Defining ADMT Scope for Insurance Operations

    Statutes structured around automated decision-making technology typically target systems that materially influence or determine an outcome affecting a consumer without meaningful human involvement in the final decision. Applied to insurance, that framing raises questions about algorithmic underwriting scores, automated pricing and rating engines, claims triage and adjudication tools, and fraud detection scoring models. Colorado's specific statutory language, its thresholds for what counts as a covered decision, and any exemptions applicable to licensed insurers require direct confirmation against the enacted bill text and any interpretive guidance issued by the Colorado Division of Insurance. Compliance leaders should treat internal scoping work as provisional until legal counsel confirms those specifics, but the absence of final regulatory interpretation is not a reason to delay the underlying inventory and documentation work described below.

    Insurance Systems Likely to Warrant ADMT Review

    Four categories of insurance decisioning commonly draw scrutiny under ADMT-style frameworks and should be catalogued regardless of final statutory scope. Underwriting models that generate risk scores or accept/decline recommendations sit at the center of this review, since they directly shape whether and on what terms a consumer obtains coverage. Pricing and rating engines that adjust premiums based on modeled risk factors raise similar questions, particularly where inputs are derived from third-party data or machine learning models rather than filed rating manuals alone. Claims adjudication and triage tools, including systems that route, prioritize, or recommend settlement outcomes, warrant review because they affect the timing and value of a benefit a consumer receives. Fraud detection scoring models round out the list, since a flag generated by an automated system can materially affect how a claim is handled even when a human ultimately signs off. Vendor-supplied tools used in any of these functions should be included in the inventory, not just internally built models.

    Human Review and Contestability

    ADMT-style requirements generally distinguish between decisions that are fully automated and decisions where a human reviewer has genuine authority and sufficient information to change the outcome. Insurance operations often already include human touchpoints, such as underwriter sign-off or claims adjuster review, but compliance teams need to document whether that review is substantive or functions as a pass-through of an automated recommendation. This distinction typically determines whether a workflow is treated as automated for regulatory purposes. Contestability obligations, where applicable, generally require that a consumer be able to request an explanation of an automated decision and seek reconsideration. Insurers should map existing appeal and reconsideration processes for underwriting declines, pricing disputes, and claims denials against this expectation to identify where current procedures fall short of a documented, timely review pathway.

    Auditability: What Regulators Will Expect to See

    Regardless of the final procedural detail in SB26-189 or its implementing guidance, auditable AI governance generally requires the ability to reconstruct a specific decision after the fact: which model or ruleset produced it, what inputs it considered, what score or recommendation it generated, and whether a human reviewer intervened. For insurers running AI-assisted underwriting, pricing, or claims models in production, building this record manually across multiple systems and vendors is difficult to sustain at scale. Runtime governance tooling, such as Trussed AI's runtime monitoring and audit logging capabilities, can capture this decision-level trail automatically for AI agents and models operating in these pipelines, providing a consistent record without requiring changes to the underlying underwriting or claims logic. This is one implementation mechanism among several, and it does not substitute for the underlying documentation and human review processes described above.

    Closing Common Compliance Gaps

    • Begin the system inventory now rather than waiting for final statutory interpretation, since the underlying documentation work is unlikely to change materially
    • Precisely distinguish automated decisions from genuinely human-reviewed ones, documenting reviewer authority rather than assuming existing sign-off satisfies the distinction
    • Centralize impact assessment and audit documentation in one system of record rather than distributing it across underwriting, claims, and vendor management teams
    • Test the contestability and appeal workflow end to end to confirm it produces a documented, timely response
    • Engage legal counsel early to confirm SB26-189's specific thresholds, effective dates, and any insurance-specific exemptions before finalizing internal policy language
    • Monitor Colorado Division of Insurance guidance for interpretive bulletins that may clarify how existing insurance regulatory frameworks intersect with ADMT obligations

    Build Auditable Controls Before Enforcement Begins

    Insurance compliance teams need decision-level visibility into the AI and automated systems driving underwriting, pricing, and claims outcomes. See how runtime governance can support that record.

    Request a Demo