The Carrier Lens Chapter 58 24 min read

AI in insurance — the regulatory landscape.

Selling AI into a regulated industry means the conversation always reaches a compliance review. Carriers do not adopt AI systems that cannot survive their state insurance department, their FCA examiner, or their internal model risk team. This chapter is the regulatory map across the US, EU, and UK — what each rule actually says, who enforces it, and what it means for an IDP deployment.

5
Regulatory frames to know cold
High-risk
EU AI Act classification for insurance pricing
Aug 2026
EU AI Act primary obligations live
Jan 2025
DORA enforceable for EU financial entities
§ 01

The five regulatory frames

AI regulation in insurance is layered, not unified. A US carrier writing in multiple states sits under federal-style guidance from the NAIC, state-specific rules from Colorado and New York, and overlapping consumer protection rules. A European carrier sits under Solvency II, GDPR, DORA, and the EU AI Act simultaneously. A UK carrier sits under FCA and PRA guidance plus retained-EU rules.

Most regulators have not written AI-specific statutes from scratch. They have extended existing frameworks — fair-lending, unfair-discrimination, model governance, vendor management, operational risk — to cover AI use. The result is a patchwork that is easier to navigate once you recognize the five recurring frames that appear in nearly every rule.

Frame 1 · Anti-discrimination
Rules that prohibit AI systems from producing disparate impact on protected classes. Colorado SB 21-169 is the most explicit; NAIC bulletin echoes it; EU AI Act and FCA pick up the same theme.
Frame 2 · Model governance
Requirements that the carrier (not the vendor) own and document model risk, validation, monitoring, and human oversight. Closest analogy: existing model risk management frameworks like SR 11-7 from US banking.
Frame 3 · Vendor & third-party risk
Carriers cannot outsource accountability. The carrier remains responsible for AI outcomes even when the model is from a vendor. Drives heavy InfoSec, SOC 2, and due-diligence requirements.
Frame 4 · Transparency & explainability
Insureds, agents, and regulators must be able to understand and challenge AI-influenced decisions. Drives audit-log, decision-rationale, and reason-code requirements.
Frame 5 · Operational resilience & data protection
DORA and GDPR in Europe, NYDFS cybersecurity rules in the US. Treat AI systems as financial infrastructure with strict uptime, incident response, and data-handling requirements.
Anchor concept

Every AI regulatory rule in insurance is some combination of these five frames. When you hear a new rule cited, ask: which frame is this? Then map it to the controls Indico's platform already implements. Most of the answer is data lineage, audit logs, role-based access, model documentation, and human-in-the-loop oversight.

§ 02

NAIC Model Bulletin on AI (US)

The NAIC (National Association of Insurance Commissioners) published its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It is not a statute — the NAIC has no direct enforcement authority — but it provides a template that state insurance departments have been adopting. As of mid-2026, more than 20 states have issued bulletins substantially aligned with the NAIC model.

What it says

  • Carriers must adopt a written AI Systems program, approved by senior leadership and the board (or a board committee).
  • The AI Systems program must cover governance, risk management, testing, validation, and ongoing monitoring across the full AI lifecycle.
  • Carriers must address fairness, transparency, accountability, and security in the program.
  • Third-party AI systems (i.e., vendor-supplied) are explicitly in scope. The carrier remains accountable for outcomes.
  • State examiners can request documentation of the program, including testing records and incident logs.

What it doesn't say

The bulletin is principles-based. It does not prescribe specific algorithmic tests, specific disparate-impact thresholds, or specific documentation formats. That ambiguity is intentional — the NAIC wants the program to scale to carriers of different sizes and AI use intensities. It also means examiners have wide latitude to interpret.

What this means for an Indico engagement

A US carrier prospect will increasingly ask Indico to provide documentation that supports their AI Systems program — model cards, validation results, monitoring dashboards, incident response procedures. Carriers will incorporate Indico's controls into their own governance framework rather than rely on vendor attestations alone.

Practical note

"Aligned with the NAIC Model Bulletin" is a phrase that increasingly appears in carrier RFPs. Indico's standard documentation package — SOC 2 report, model documentation, audit logs, human-in-loop attestations — answers most of what the bulletin contemplates, but the wrapper (mapping each control to the bulletin's framework) often needs to be assembled per-prospect.

§ 03

Colorado SB 21-169 & Reg 10-1-1

Colorado was the first US state to enact substantive AI regulation in insurance. SB 21-169 (signed July 2021) prohibits insurance practices that result in "unfair discrimination" based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression — when those practices are produced by an external consumer data source, algorithm, or predictive model.

The mechanism

Colorado's Division of Insurance issues line-specific regulations under SB 21-169. The first one — Reg 10-1-1, applicable to life insurance — went into effect in 2023. It requires life insurers using algorithms or predictive models to:

  • Establish a governance and risk management framework
  • Test their algorithms for disparate impact using prescribed quantitative methods
  • Remediate any disparate outcomes identified
  • Report annually to the Division
  • Document third-party (vendor) AI systems including the carrier's due diligence

Subsequent regulations covering auto, P&C, and other lines are in development. Several other states (notably New York, California, Washington, and Maryland) are watching closely and are likely to adopt similar frameworks.

What this means for an Indico engagement

An IDP platform doing extraction and triage does not, on its face, perform pricing or coverage decisioning — which is the use case Colorado most directly targets. But the boundary blurs when the platform's outputs influence downstream decisions. Carriers operating in Colorado will increasingly ask: does this IDP system, by ordering or scoring submissions, contribute to disparate outcomes? A clear answer ("no, the platform extracts data fields without scoring or routing decisions based on protected-class proxies") usually satisfies the concern, but it needs to be documented.

§ 04

NYDFS Circular Letter 7 (2024)

The New York Department of Financial Services issued Circular Letter No. 7 of 2024 in July 2024, addressing the use of artificial intelligence and external consumer data and information sources (ECDIS) in insurance underwriting and pricing. It is the most operationally prescriptive AI-in-insurance guidance from any US regulator to date.

What it covers

  • Disparate impact testing. Insurers must affirmatively test for prohibited unfair discrimination, including testing against protected-class proxies, before deploying AI.
  • Governance. Senior leadership accountability, written policies, board reporting, model inventory.
  • Documentation. Models, ECDIS sources, vendor relationships — all must be documented and available to examiners.
  • Risk-based oversight. The level of governance must scale with the risk of the AI use case.
  • Consumer disclosures. Insurers must be able to explain to consumers (and to NYDFS) the basis of AI-informed decisions.

What this means for an Indico engagement

NYDFS is the most aggressive US insurance regulator. Carriers writing in New York treat Circular Letter 7 as the de facto bar for AI vendor relationships across their entire book — because the operational cost of running different controls in different states is too high. An Indico deployment at any carrier with NY-significant business needs to clear this bar.

§ 05

The EU AI Act

The EU AI Act entered into force in August 2024, with most operational obligations becoming enforceable in stages through August 2026 and beyond. It is the world's first comprehensive AI statute. For insurance, the AI Act takes a risk-based approach: it classifies certain AI uses as "high-risk," subjecting them to a substantial compliance regime.

High-risk classification for insurance

The AI Act explicitly lists, in Annex III, AI systems used in:

  • Risk assessment and pricing in life insurance
  • Risk assessment and pricing in health insurance

These are high-risk. Other insurance uses (commercial P&C pricing, fraud detection, claims handling, submission triage) are not categorically classified as high-risk but may fall into other Annex III categories depending on use (credit scoring, employment, biometric ID).

Obligations on high-risk AI

Providers and deployers of high-risk AI systems must:

  • Implement a risk management system across the AI lifecycle
  • Use high-quality, representative training data with documented governance
  • Maintain technical documentation and automated event logs
  • Provide transparency to users about the AI system's purpose and limitations
  • Implement human oversight measures
  • Ensure accuracy, robustness, and cybersecurity
  • Register the system in the EU AI database
  • Conduct a fundamental rights impact assessment (for deployers in certain sectors)

General-purpose AI obligations

Separate from high-risk classification, providers of "general-purpose AI" models (including LLMs) face their own transparency, documentation, and (for systemic-risk models) safety obligations. Carriers using LLM-powered IDP need to confirm their providers comply.

What this means for an Indico engagement

For non-life-and-health commercial IDP use cases, the AI Act is mostly about general-purpose AI compliance from the underlying LLM provider plus carrier-side documentation. For life and health pricing, the carrier needs Indico's outputs to feed into a high-risk AI compliance regime, which raises the documentation bar substantially.

Watch out

The AI Act's definitions of "provider," "deployer," and "important amendment" are tricky. A vendor that customizes a third-party LLM, deploys it into a carrier's workflow, and influences decisions can be classified differently than it expects. Carriers in scope ask for explicit role mapping early — be ready.

§ 06

GDPR for insurance AI

The General Data Protection Regulation (in force 2018) is not AI-specific but applies to virtually every IDP deployment in Europe. Two articles bite hardest:

Article 22 — automated decisions
Data subjects have the right not to be subject to decisions based solely on automated processing that produce legal effects. Pure automated pricing and pure automated claims denial run into this. Human-in-the-loop usually satisfies it.
Article 9 — special categories
Processing of health data, racial origin, and other special categories is prohibited except under narrow exceptions. Health insurance, accident, life, and some general lines that touch medical records all need to navigate this.
Article 35 — DPIA
High-risk processing requires a Data Protection Impact Assessment. AI systems handling personal data typically trigger this.
Cross-border transfer
Carriers in the EU sending data to non-EU vendors need Standard Contractual Clauses or Adequacy Decisions. Data residency is a routine procurement question.

What this means for an Indico engagement

EU carriers will require: a clear legal basis for processing, a DPIA they can co-author, human-in-the-loop confirmation, data residency commitments, breach notification SLAs, and signed standard contractual clauses for any non-EU data flow. None of this is novel — most enterprise SaaS contracts now include it — but it is non-negotiable in EU/UK procurement.

§ 07

DORA — Digital Operational Resilience Act

DORA, the EU Digital Operational Resilience Act, became enforceable in January 2025. It applies to financial entities — including insurers and reinsurers — and to their "critical ICT third-party service providers." It is essentially a comprehensive operational risk and vendor management regime aimed at making the financial system resilient to ICT failures, cyber attacks, and vendor outages.

What it requires

  • An ICT risk management framework owned by the financial entity's management body
  • ICT-related incident reporting to regulators within tight timelines
  • Digital operational resilience testing including threat-led penetration testing for significant entities
  • Third-party ICT risk management including contractual provisions, monitoring, and exit strategies
  • Information and intelligence sharing about cyber threats

What "critical ICT third-party provider" means

The European Supervisory Authorities (ESMA, EBA, EIOPA) jointly designate certain ICT providers as "critical." Critical providers face direct oversight from the supervisors — beyond what their carrier clients impose. Most IDP vendors do not yet meet the critical-provider threshold, but the bar for being treated like one in carrier contracts has risen substantially.

What this means for an Indico engagement

European carrier contracts now routinely include DORA-mandated clauses on incident reporting timelines, security testing, audit rights, and exit provisions. These are no longer negotiable line items — they are statutory. Indico engagements with EU carriers need a DORA-aware contracting playbook.

§ 08

UK FCA approach

The UK has not adopted the EU AI Act post-Brexit. The FCA and PRA have taken a principles-based "pro-innovation" stance, building on existing rules rather than enacting new AI-specific statutes.

The key statements

  • FCA / Bank of England Discussion Paper DP5/22 (2022). "Artificial Intelligence and Machine Learning" — a joint discussion paper from the FCA, PRA, and Bank of England on regulatory approaches to AI/ML in financial services.
  • FCA AI Update (April 2024). Confirms the regulator's approach: extending existing rules (Senior Managers Regime, Consumer Duty, operational resilience) rather than creating a new AI statute.
  • Consumer Duty (July 2023). Already requires firms to act in good faith, avoid foreseeable harm, and support consumer understanding. AI deployments that fail consumer outcomes breach the Duty regardless of any AI-specific rule.
  • Senior Managers & Certification Regime (SMCR). Holds named senior managers personally accountable for the firm's regulated activities — including AI use. A specific Senior Manager Function holder usually owns AI governance.

What this means for an Indico engagement

UK carriers (and London Market entities) buy AI vendors against the same five frames as elsewhere, but the framing is "how does this support our Consumer Duty obligations" and "who is the SMF holder accountable for this system." Documentation that maps Indico's controls to Consumer Duty outcomes and SMCR accountability lines lands cleanly with UK procurement.

§ 09

What this means for IDP engagements

Five practical conclusions for an Indico deployment in any region.

1 · Most IDP use cases are lower-risk than they sound

Pure extraction and classification — turning a PDF into structured fields — is not a pricing decision, a coverage decision, or a claim-denial decision. It is a data preparation step. Most regulators distinguish between AI that prepares data for a human decision and AI that makes the decision. The former carries materially less regulatory weight.

2 · The carrier owns accountability; the vendor supports it

Every framework reaches the same conclusion: the carrier remains accountable. The vendor's job is to make it as easy as possible for the carrier to satisfy regulators. This means producing documentation, audit logs, and validation results in formats the carrier can hand directly to an examiner.

3 · Human-in-the-loop is the highest-leverage control

Across NAIC, NYDFS, Colorado, EU AI Act, GDPR, and FCA — every framework treats "meaningful human review" as a mitigating control. IDP deployments designed with explicit underwriter or adjuster oversight at decision points have a materially easier compliance path than deployments that bypass human review.

4 · Documentation is the audit-bridge

Model cards, training-data summaries, validation reports, monitoring dashboards, incident response procedures. These are the artifacts examiners ask for. Producing them on demand is a competitive advantage; producing them only after a regulatory inquiry is a failed engagement.

5 · Region-specific bars exist but cluster around the same controls

An IDP control framework that satisfies NYDFS Circular Letter 7 will substantially satisfy the NAIC bulletin in any other US state. A framework that satisfies the EU AI Act and DORA will substantially satisfy the FCA's Consumer Duty framing. The marginal cost of multi-jurisdiction compliance, once the base framework is sound, is documentation overhead rather than fundamental redesign.

The compliance value proposition

The right frame in a carrier compliance conversation is not "we comply." It is "we make your compliance program easier." The carrier's risk team is staffed for a wave of AI vendor reviews; a vendor that arrives with a mapped control library, a ready-to-share documentation package, and a clean SMCR / NAIC / DORA / EU AI Act crosswalk reduces their workload by weeks. That alone closes deals.

Chapter 58 · The Carrier Lens · 24 min read

AI in Insurance — Regulation — Cheat Sheet

Selling AI into a regulated industry means the conversation always reaches a compliance review. Carriers do not adopt AI systems that cannot survive their state insurance department, their FCA examiner, or their internal model risk team. This chapter is the regulatory map across the US, EU, and UK — what each rule actually says, who enforces it, and what it means for an IDP deployment.

The mental model: Every AI regulatory rule in insurance is some combination of these five frames. When you hear a new rule cited, ask: which frame is this? Then map it to the controls Indico's platform already implements. Most of the answer is data lineage, audit logs, role-based access, model documentation, and human-in-the-loop oversight.

Watch for

Patterns worth knowing

If you remember three things

Five frames recur across every rule. The carrier remains accountable; the vendor's job is to make compliance easier. Human-in-the-loop is the highest-leverage control.