Use-case guide
AI in Insurance
Insurance is one of the few sectors where the EU AI Act explicitly names you as high-risk by default. Life and health pricing using AI sits in Annex III §5(c); credit/property-side coverage often falls in §5(b). Layered on top: US state insurance regulators are issuing AI bulletins (NAIC Model Bulletin on AI 2023; Colorado Reg 10-1-1; NYDFS Circular Letter 7), state UDAP rules on discriminatory pricing, and Solvency II model-risk overlays in the EU. Algorithmic bias in underwriting has been the most-litigated area of insurance discrimination since 2022.
For: P&C and life-and-health insurers, reinsurers, insurtech founders, actuarial leads, insurance regulators, broker compliance
What's at stake
Life & health AI pricing is high-risk under the EU AI Act
Annex III §5(c) explicitly captures AI for 'risk assessment and pricing in relation to natural persons in the case of life and health insurance'. The full Annex III obligation stack applies — risk management, data governance, technical documentation, post-market monitoring, human oversight.
US states have NAIC Model Bulletin in force
Twenty-plus states adopted the NAIC Model Bulletin on AI use by insurers (2023). It requires written AI governance, third-party model risk management, testing for unfair discrimination, and consumer-protection compliance. Enforcement comes via market-conduct exams.
Disparate-impact theory applies to AI pricing
Colorado SB21-169 explicitly prohibits use of external consumer data and information sources (ECDIS) and predictive models that result in unfair discrimination. Other states (NY, CA, CT) are following the model. Even a fully algorithmic decision can trigger disparate-impact claims under McCarran-Ferguson + state law.
Model risk under Solvency II / IFRS 17
EU insurers running AI in pricing, reserving, or claims must integrate the model into their existing Solvency II / ORSA model-risk framework — the AI Act adds on top, it doesn't replace.
Regulations that apply
EU AI Act
LawLife and health insurance AI is high-risk (Annex III §5(c)); credit-related insurance products may also be (§5(b)). Full Annex III obligation stack applies. EIOPA has issued sector-specific guidance.
Where in the text: Annex III §5(b), §5(c); Articles 9-15, 17, 27.
NAIC Model Bulletin on AI
GuidelineAdopted by 20+ US states. Written governance, third-party MRM, unfair-discrimination testing, consumer-protection. Enforced via state market-conduct exams.
Where in the text: NAIC Model Bulletin on the Use of AI Systems by Insurers (2023).
Colorado SB21-169 + Reg 10-1-1
LawBans use of external consumer data and predictive models that result in unfair discrimination in insurance. Triennial bias-testing duty; algorithmic-fairness reports to the Division of Insurance.
Where in the text: Colo. Rev. Stat. § 10-3-1104.9; Colo. Code Regs. 10-1-1.
Colorado AI Act
LawInsurance is a 'consequential decision' category — deployers (insurers) must complete annual impact assessments and notify consumers of AI use in adverse decisions.
Where in the text: Sec. 6-1-1701(3)(g); 6-1-1703.
Do
- ✓Fold AI under your existing model-risk-management framework — auditors and regulators expect this; building parallel governance creates gaps.
- ✓Run rigorous disparate-impact testing across all protected classes BEFORE deployment AND at scheduled intervals afterwards. Keep the methodology documented.
- ✓Engage your state insurance regulator early when adopting AI in pricing or claims — most NAIC-aligned states expect prior consultation, not just reactive disclosure.
- ✓Build adverse-action notices that include AI-specific 'specific reasons' satisfying both Reg B and your state's unfair-trade rules.
- ✓Vet your vendor's model documentation against NAIC Model Bulletin requirements before contracting — your MRM obligation flows down even to vendor-built models.
Don't
- ✗Don't use ZIP code, surname, or other proxy features in pricing — Colorado SB21-169 (and the path-dependent state followers) treat these as per-se unfair discrimination.
- ✗Don't deploy AI in EU insurance pricing without a documented Article 27 Fundamental Rights Impact Assessment.
- ✗Don't outsource the explanation duty — when a consumer asks why their rate went up, 'the model decided' is not an acceptable answer under Reg B or NAIC Model Bulletin.
- ✗Don't bundle generative-AI features into customer service without an Article 50 (EU AI Act) disclosure — chatbots interacting with consumers must self-identify as AI.
- ✗Don't ignore the genetic information rules — using genomic features in pricing is restricted by GINA (US) and Annex III triggers in the EU.
Also worth knowing
For reinsurers and captives: the principal-insurer's AI use is your downstream exposure too — flow MRM expectations through reinsurance contracts. For US health insurers: ACA Section 1557 plus the new HHS Section 1557 final rule on algorithmic discrimination (2024) layers on top of state insurance regulation. For UK insurers: PRA SS1/23 and the FCA's Consumer Duty interact with AI deployment decisions.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.