Compliance Guide
State AI Insurance Regulation Tracker 2026: Adoption by State
State insurance regulators are adopting AI governance requirements largely modeled on the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, issued December 2023. Adoption pace and exact requirements vary by state, and Colorado maintains a separate statutory regime under SB21-169. Insurers operating across multiple jurisdictions should verify current adoption status against NAIC's official tracking resources, since bulletin issuance dates and effective dates change frequently.
AI Insurance Regulation at a Glance
NAIC Model Bulletin
Adopted December 2023 as a template for state insurance departments to set AI governance expectations.
Multi-State Adoption
Several state insurance departments have issued bulletins substantially based on the NAIC template.
Colorado SB21-169
A distinct statutory regime requiring life insurers to test for unfair discrimination and submit governance documentation.
Vendor Oversight
Insurers remain accountable for third-party AI systems used in underwriting, claims, and pricing.
The NAIC's Innovation, Cybersecurity, and Technology (H) Committee coordinates AI-related model bulletin development for state insurance regulators. Rather than a single national rule, individual state insurance departments choose whether and how to adopt bulletin language, which produces overlapping but non-identical obligations for carriers and MGAs operating across multiple states. Because adoption timing, exact wording, and enforcement posture differ by jurisdiction, compliance teams should treat this as a moving landscape rather than a fixed checklist. Colorado is the clearest example of divergence: its AI-related obligations for life insurers are grounded in statute (SB21-169) rather than a bulletin, which changes both the legal basis and the specific documentation insurers must produce. Enterprises should confirm current state-by-state adoption status directly against NAIC's official tracking resources before finalizing internal compliance mappings, since bulletin issuance and effective dates change frequently and are not fully enumerated in this guide.
NAIC Model Bulletin vs. Colorado SB21-169
| Aspect | NAIC Model Bulletin (State-Adopted) | Colorado SB21-169 |
|---|---|---|
| Legal basis | Regulatory bulletin, adopted individually by each state insurance department | State statute, separate from bulletin adoption |
| Origin | NAIC template issued December 2023 | Existing Colorado statutory requirement |
| Scope | General AI governance expectations for insurers using AI in underwriting, claims, and pricing | Applies specifically to life insurers |
| Core requirement | Written AI governance program, bias testing, retrievable documentation | Testing for unfair discrimination and submission of governance documentation |
| Adoption status | Adopted by multiple states; wording and effective dates vary | Applies in Colorado only, independent of bulletin adoption |
Common Compliance Themes Across Adopting States
Despite variation in exact language, states adopting NAIC-derived bulletins tend to converge on a consistent set of expectations. Insurers are generally expected to maintain a written AI governance program that addresses risk management and internal controls across the full AI system lifecycle, not just at deployment. Bias or unfair discrimination testing is a recurring technical expectation, though states do not uniformly prescribe a specific statistical methodology, leaving insurers to select and justify their own testing approach. Documentation requirements extend beyond internal recordkeeping: insurers must be able to produce evidence in a form suitable for regulatory examination, which implies formal, retrievable records rather than informal notes. Third-party AI vendor oversight is treated as a direct insurer responsibility. Bulletins generally expect insurers to obtain documentation or attestations from vendors covering model design, training data, and testing results, even when the underlying tool is licensed rather than built in-house.
Operationalizing Compliance Across Multiple States
Technical Controls Insurers Need to Demonstrate Compliance
- Centralized audit logging capable of reconstructing AI decision history across underwriting, claims, and pricing systems
- Version control for AI/ML models used in regulated decisions, supporting change-history requests from governance programs
- Repeatable bias testing pipelines that produce retained evidence, rather than one-time assessments
- Documented data lineage and testing evidence for third-party AI vendor systems, retrievable on demand
- A governance data model mapping internal controls to multiple overlapping state bulletin or statute requirements
- Model risk management processes covering validation, versioning, and periodic reassessment
Where Runtime Governance Infrastructure Fits
The requirements described above are principle-based rather than prescriptive of specific software architecture, which leaves implementation approach to the insurer. In practice, satisfying multiple overlapping state regimes depends on infrastructure that can produce consistent, retrievable evidence rather than manual, one-off documentation. This is where runtime governance capabilities become relevant: audit logging that captures AI decision activity as it occurs, policy enforcement that applies consistent controls across underwriting, claims, and pricing systems, and permission and tool approval workflows that govern how AI systems and third-party vendor tools interact with insurance data.
Trussed AI provides runtime governance and security infrastructure for enterprise AI agents, including audit logging, runtime policy enforcement, and agent permission controls, which map directly to the documentation and vendor oversight expectations described in state AI bulletins and statutes.
Not Legal Advice
This guide does not represent legal advice. Insurers should validate specific control requirements against the applicable state bulletin or statute text.
Frequently Asked Questions
Does complying with the NAIC Model Bulletin satisfy Colorado's SB21-169?
No. Colorado's SB21-169 is a separate statutory regime with its own testing and documentation requirements for life insurers. Insurers operating in Colorado need to address both frameworks separately rather than assuming bulletin compliance covers statutory obligations.
How often should a multi-state compliance mapping be updated?
Since bulletin issuance and effective dates vary by state and change over time, compliance and legal teams should review the mapping on a recurring basis and whenever a new state issues or amends AI-related guidance, rather than treating it as a one-time exercise.
Are insurers responsible for AI tools they license from third-party vendors?
Yes. State bulletins generally extend insurer accountability to third-party AI systems and data vendors, requiring due diligence and ongoing oversight even when the tool is developed or hosted externally.
Operationalize AI Compliance Across Jurisdictions
Multi-state AI insurance regulation requires consistent audit trails, vendor oversight, and governance controls. See how runtime governance infrastructure supports these requirements in practice.
Explore Runtime Governance