The five regulatory frames
AI regulation in insurance is layered, not unified. A US carrier writing in multiple states sits under federal-style guidance from the NAIC, state-specific rules from Colorado and New York, and overlapping consumer protection rules. A European carrier sits under Solvency II, GDPR, DORA, and the EU AI Act simultaneously. A UK carrier sits under FCA and PRA guidance plus retained-EU rules.
Most regulators have not written AI-specific statutes from scratch. They have extended existing frameworks — fair-lending, unfair-discrimination, model governance, vendor management, operational risk — to cover AI use. The result is a patchwork that is easier to navigate once you recognize the five recurring frames that appear in nearly every rule.
Every AI regulatory rule in insurance is some combination of these five frames. When you hear a new rule cited, ask: which frame is this? Then map it to the controls Indico's platform already implements. Most of the answer is data lineage, audit logs, role-based access, model documentation, and human-in-the-loop oversight.
NAIC Model Bulletin on AI (US)
The NAIC (National Association of Insurance Commissioners) published its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It is not a statute — the NAIC has no direct enforcement authority — but it provides a template that state insurance departments have been adopting. As of mid-2026, more than 20 states have issued bulletins substantially aligned with the NAIC model.
What it says
- Carriers must adopt a written AI Systems program, approved by senior leadership and the board (or a board committee).
- The AI Systems program must cover governance, risk management, testing, validation, and ongoing monitoring across the full AI lifecycle.
- Carriers must address fairness, transparency, accountability, and security in the program.
- Third-party AI systems (i.e., vendor-supplied) are explicitly in scope. The carrier remains accountable for outcomes.
- State examiners can request documentation of the program, including testing records and incident logs.
What it doesn't say
The bulletin is principles-based. It does not prescribe specific algorithmic tests, specific disparate-impact thresholds, or specific documentation formats. That ambiguity is intentional — the NAIC wants the program to scale to carriers of different sizes and AI use intensities. It also means examiners have wide latitude to interpret.
What this means for an Indico engagement
A US carrier prospect will increasingly ask Indico to provide documentation that supports their AI Systems program — model cards, validation results, monitoring dashboards, incident response procedures. Carriers will incorporate Indico's controls into their own governance framework rather than rely on vendor attestations alone.
"Aligned with the NAIC Model Bulletin" is a phrase that increasingly appears in carrier RFPs. Indico's standard documentation package — SOC 2 report, model documentation, audit logs, human-in-loop attestations — answers most of what the bulletin contemplates, but the wrapper (mapping each control to the bulletin's framework) often needs to be assembled per-prospect.
Colorado SB 21-169 & Reg 10-1-1
Colorado was the first US state to enact substantive AI regulation in insurance. SB 21-169 (signed July 2021) prohibits insurance practices that result in "unfair discrimination" based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression — when those practices are produced by an external consumer data source, algorithm, or predictive model.
The mechanism
Colorado's Division of Insurance issues line-specific regulations under SB 21-169. The first one — Reg 10-1-1, applicable to life insurance — went into effect in 2023. It requires life insurers using algorithms or predictive models to:
- Establish a governance and risk management framework
- Test their algorithms for disparate impact using prescribed quantitative methods
- Remediate any disparate outcomes identified
- Report annually to the Division
- Document third-party (vendor) AI systems including the carrier's due diligence
Subsequent regulations covering auto, P&C, and other lines are in development. Several other states (notably New York, California, Washington, and Maryland) are watching closely and are likely to adopt similar frameworks.
What this means for an Indico engagement
An IDP platform doing extraction and triage does not, on its face, perform pricing or coverage decisioning — which is the use case Colorado most directly targets. But the boundary blurs when the platform's outputs influence downstream decisions. Carriers operating in Colorado will increasingly ask: does this IDP system, by ordering or scoring submissions, contribute to disparate outcomes? A clear answer ("no, the platform extracts data fields without scoring or routing decisions based on protected-class proxies") usually satisfies the concern, but it needs to be documented.
NYDFS Circular Letter 7 (2024)
The New York Department of Financial Services issued Circular Letter No. 7 of 2024 in July 2024, addressing the use of artificial intelligence and external consumer data and information sources (ECDIS) in insurance underwriting and pricing. It is the most operationally prescriptive AI-in-insurance guidance from any US regulator to date.
What it covers
- Disparate impact testing. Insurers must affirmatively test for prohibited unfair discrimination, including testing against protected-class proxies, before deploying AI.
- Governance. Senior leadership accountability, written policies, board reporting, model inventory.
- Documentation. Models, ECDIS sources, vendor relationships — all must be documented and available to examiners.
- Risk-based oversight. The level of governance must scale with the risk of the AI use case.
- Consumer disclosures. Insurers must be able to explain to consumers (and to NYDFS) the basis of AI-informed decisions.
What this means for an Indico engagement
NYDFS is the most aggressive US insurance regulator. Carriers writing in New York treat Circular Letter 7 as the de facto bar for AI vendor relationships across their entire book — because the operational cost of running different controls in different states is too high. An Indico deployment at any carrier with NY-significant business needs to clear this bar.
The EU AI Act
The EU AI Act entered into force in August 2024, with most operational obligations becoming enforceable in stages through August 2026 and beyond. It is the world's first comprehensive AI statute. For insurance, the AI Act takes a risk-based approach: it classifies certain AI uses as "high-risk," subjecting them to a substantial compliance regime.
High-risk classification for insurance
The AI Act explicitly lists, in Annex III, AI systems used in:
- Risk assessment and pricing in life insurance
- Risk assessment and pricing in health insurance
These are high-risk. Other insurance uses (commercial P&C pricing, fraud detection, claims handling, submission triage) are not categorically classified as high-risk but may fall into other Annex III categories depending on use (credit scoring, employment, biometric ID).
Obligations on high-risk AI
Providers and deployers of high-risk AI systems must:
- Implement a risk management system across the AI lifecycle
- Use high-quality, representative training data with documented governance
- Maintain technical documentation and automated event logs
- Provide transparency to users about the AI system's purpose and limitations
- Implement human oversight measures
- Ensure accuracy, robustness, and cybersecurity
- Register the system in the EU AI database
- Conduct a fundamental rights impact assessment (for deployers in certain sectors)
General-purpose AI obligations
Separate from high-risk classification, providers of "general-purpose AI" models (including LLMs) face their own transparency, documentation, and (for systemic-risk models) safety obligations. Carriers using LLM-powered IDP need to confirm their providers comply.
What this means for an Indico engagement
For non-life-and-health commercial IDP use cases, the AI Act is mostly about general-purpose AI compliance from the underlying LLM provider plus carrier-side documentation. For life and health pricing, the carrier needs Indico's outputs to feed into a high-risk AI compliance regime, which raises the documentation bar substantially.
The AI Act's definitions of "provider," "deployer," and "important amendment" are tricky. A vendor that customizes a third-party LLM, deploys it into a carrier's workflow, and influences decisions can be classified differently than it expects. Carriers in scope ask for explicit role mapping early — be ready.
GDPR for insurance AI
The General Data Protection Regulation (in force 2018) is not AI-specific but applies to virtually every IDP deployment in Europe. Two articles bite hardest:
What this means for an Indico engagement
EU carriers will require: a clear legal basis for processing, a DPIA they can co-author, human-in-the-loop confirmation, data residency commitments, breach notification SLAs, and signed standard contractual clauses for any non-EU data flow. None of this is novel — most enterprise SaaS contracts now include it — but it is non-negotiable in EU/UK procurement.
DORA — Digital Operational Resilience Act
DORA, the EU Digital Operational Resilience Act, became enforceable in January 2025. It applies to financial entities — including insurers and reinsurers — and to their "critical ICT third-party service providers." It is essentially a comprehensive operational risk and vendor management regime aimed at making the financial system resilient to ICT failures, cyber attacks, and vendor outages.
What it requires
- An ICT risk management framework owned by the financial entity's management body
- ICT-related incident reporting to regulators within tight timelines
- Digital operational resilience testing including threat-led penetration testing for significant entities
- Third-party ICT risk management including contractual provisions, monitoring, and exit strategies
- Information and intelligence sharing about cyber threats
What "critical ICT third-party provider" means
The European Supervisory Authorities (ESMA, EBA, EIOPA) jointly designate certain ICT providers as "critical." Critical providers face direct oversight from the supervisors — beyond what their carrier clients impose. Most IDP vendors do not yet meet the critical-provider threshold, but the bar for being treated like one in carrier contracts has risen substantially.
What this means for an Indico engagement
European carrier contracts now routinely include DORA-mandated clauses on incident reporting timelines, security testing, audit rights, and exit provisions. These are no longer negotiable line items — they are statutory. Indico engagements with EU carriers need a DORA-aware contracting playbook.
UK FCA approach
The UK has not adopted the EU AI Act post-Brexit. The FCA and PRA have taken a principles-based "pro-innovation" stance, building on existing rules rather than enacting new AI-specific statutes.
The key statements
- FCA / Bank of England Discussion Paper DP5/22 (2022). "Artificial Intelligence and Machine Learning" — a joint discussion paper from the FCA, PRA, and Bank of England on regulatory approaches to AI/ML in financial services.
- FCA AI Update (April 2024). Confirms the regulator's approach: extending existing rules (Senior Managers Regime, Consumer Duty, operational resilience) rather than creating a new AI statute.
- Consumer Duty (July 2023). Already requires firms to act in good faith, avoid foreseeable harm, and support consumer understanding. AI deployments that fail consumer outcomes breach the Duty regardless of any AI-specific rule.
- Senior Managers & Certification Regime (SMCR). Holds named senior managers personally accountable for the firm's regulated activities — including AI use. A specific Senior Manager Function holder usually owns AI governance.
What this means for an Indico engagement
UK carriers (and London Market entities) buy AI vendors against the same five frames as elsewhere, but the framing is "how does this support our Consumer Duty obligations" and "who is the SMF holder accountable for this system." Documentation that maps Indico's controls to Consumer Duty outcomes and SMCR accountability lines lands cleanly with UK procurement.
What this means for IDP engagements
Five practical conclusions for an Indico deployment in any region.
1 · Most IDP use cases are lower-risk than they sound
Pure extraction and classification — turning a PDF into structured fields — is not a pricing decision, a coverage decision, or a claim-denial decision. It is a data preparation step. Most regulators distinguish between AI that prepares data for a human decision and AI that makes the decision. The former carries materially less regulatory weight.
2 · The carrier owns accountability; the vendor supports it
Every framework reaches the same conclusion: the carrier remains accountable. The vendor's job is to make it as easy as possible for the carrier to satisfy regulators. This means producing documentation, audit logs, and validation results in formats the carrier can hand directly to an examiner.
3 · Human-in-the-loop is the highest-leverage control
Across NAIC, NYDFS, Colorado, EU AI Act, GDPR, and FCA — every framework treats "meaningful human review" as a mitigating control. IDP deployments designed with explicit underwriter or adjuster oversight at decision points have a materially easier compliance path than deployments that bypass human review.
4 · Documentation is the audit-bridge
Model cards, training-data summaries, validation reports, monitoring dashboards, incident response procedures. These are the artifacts examiners ask for. Producing them on demand is a competitive advantage; producing them only after a regulatory inquiry is a failed engagement.
5 · Region-specific bars exist but cluster around the same controls
An IDP control framework that satisfies NYDFS Circular Letter 7 will substantially satisfy the NAIC bulletin in any other US state. A framework that satisfies the EU AI Act and DORA will substantially satisfy the FCA's Consumer Duty framing. The marginal cost of multi-jurisdiction compliance, once the base framework is sound, is documentation overhead rather than fundamental redesign.
The right frame in a carrier compliance conversation is not "we comply." It is "we make your compliance program easier." The carrier's risk team is staffed for a wave of AI vendor reviews; a vendor that arrives with a mapped control library, a ready-to-share documentation package, and a clean SMCR / NAIC / DORA / EU AI Act crosswalk reduces their workload by weeks. That alone closes deals.