Carriers rely on automated systems to shape consumer outcomes, but with AI governance regimes converging, those without integrated, enterprise-wide controls are accumulating regulatory debt that regulators are about to collect.
AI capability evolution: Upskilling has shifted from conversational prompting to strategic context engineering
Insurance has become the most AI-intensive industry in the United States by the measure that matters most: the density of automated decisions that touch individual consumers.
Every underwriting workflow, pricing engine, claim-routing model and fraud detection system runs at scale, producing outcomes that determine whether consumers get covered, at what price and on what terms. But the risk management programs governing those decisions have not kept pace, and as a result, carriers are increasingly facing major enterprise-wide implications, with regulatory deadlines for AI compliance fast approaching.
Until recently, AI governance in insurance was a risk management conversation between compliance teams and legal departments, but that’s no longer the case.
Three separate regulatory frameworks are now answering the governance question on carriers’ behalf, and most are not ready for any of them.
Three regulatory clocks govern AI compliance
The first clock is ticking down.
California’s Automated Decisionmaking Technology regulations (ADMT), part of the state’s omnibus privacy framework, go into effect on Jan. 1, 2027. Under ADMT, organizations, including insurance companies, must provide consumers with opt-out rights, meaningful human review and documented risk assessments for any automated system that materially influences significant consumer decisions.
For insurers, the rules apply across all segments of personal and commercial lines. They also apply to rules engines and scoring models, not just machine learning systems. Importantly, they carry enforcement obligations with real regulatory consequence. The California Privacy Protection Agency (CalPrivacy), which holds enforcement authority, can issue fines of up to $7,500 per violation, assessed per consumer. CalPrivacy has already demonstrated it will impose penalties rather than issue warnings with a growing roster of enforcement actions starting in the hundreds of thousands and reaching into tens of millions of dollars.
The second clock strikes sooner. The National Association of Insurance Commissioners’ AI Model Bulletin, now adopted by 25 states, requires carriers to establish a written AI governance program covering the development, acquisition, testing, monitoring and oversight of AI systems. The first live examination cycle begins in the fourth quarter, before ADMT enforcement even opens.
The third clock has already struck. The New York Department of Financial Services (NYDFS) Circular Letter No. 7, issued in 2024, requires carriers operating in New York to maintain a written AI governance program with board-level accountability. Carriers operating in New York without a written AI governance program are already out of compliance.
These compliance programs share common infrastructure requirements: a documented automated-decision footprint, model and data mapping, consumer rights mechanisms, risk assessment evidence, vendor oversight programs and written governance policies. Carriers treating each framework as an isolated compliance mandate are building redundant cost into their operations and structural gaps into their governance, with a strong probability of costly rework as additional states join the movement.
The scope is broader than most carriers have mapped
The most dangerous misconception in insurance AI governance is that these frameworks target AI and machine learning only. They do not.
Any automated system that materially influences a significant consumer decision falls under ADMT. This would include, for example, a rules engine built 15 years ago if it influences pricing, eligibility or coverage outcomes. Also included are fraud-scoring models and claim-routing workflows along with a myriad of essential decision making across the enterprise. What matters isn’t the technology, but whether the decision significantly affects consumers’ lives.
The NAIC framework extends the requirement further, covering not just the systems but the vendors and data relationships behind them. NYDFS goes further still: Carriers must govern both their internal models and the external data used to feed those models. For P&C carriers running usage-based insurance programs on telematics and third-party behavioral data, this is significant. The framework applies to the data supply chain, not just the decision system.
Carriers that have done this work consistently find more compliance exposure than they expected: legacy rules engines that predate any formal AI program, third-party models embedded in core platforms, workflows routing consumer outcomes for years without ever being formally classified as decision systems.
Most have not done this exercise and it’s what examiners are coming to find.
The state law pattern is not slowing down
Colorado’s SB 21-169, in force since 2023, requires that life insurance carriers document algorithmic fairness protections and file annual attestations with the state insurance commissioner. At the time, the insurance industry considered it a Colorado-specific compliance event. It was not. It was the pattern.
California’s ADMT framework has extended the same logic to automated decisions across all lines of insurance, covering consumer rights, explainability and accountability. New York has had comparable requirements in force since early 2024. Illinois, Maryland and Connecticut are advancing analogous frameworks. The NAIC bulletin has reached 25 states and continues to expand.
The most dangerous misconception in insurance AI governance is that these frameworks target AI and machine learning only. Carriers that have treated each development as an isolated event have been building stateby-state patch programs. Carriers that recognize the pattern are building integrated programs designed to accommodate new requirements as additional states move, without rebuilds each time. The difference is not just cost, it is competitive speed. When the next state acts, one carrier configures while others must start over.
The difference is not just cost, it is competitive speed.
What deployement-ready requires
The goal of insurance AI governance is not compliance for its own sake. It is the ability to deploy automated-decision capabilities at scale, with confidence that those capabilities can be explained, defended and adjusted when regulators, consumers or business conditions require it. Carriers that build this infrastructure now are not just managing regulatory exposure. They are building the operational foundation for competitive advantage in an AI-intensive market.
Here’s what that infrastructure requires:
- A documented register of every automated decision classified against ADMT, NAIC and NYDFS scope criteria. Not just AI systems, but rules engines, scoring models and profiling tools.
- A complete map of the data flowing into those decisions, including external sources and third-party vendor inputs.
- Consumer notice and opt-out pathways that function operationally, not as policy statements but as mechanisms that alter decision outcomes.
- Human review processes where reviewers hold genuine override authority and document their rationale in ways that are retrievable for regulators.
- Formal risk assessments for each material decision system: documented evidence that the carrier has evaluated, understood and controls the risks its automated systems create.
None of this is novel governance theory. Regulators across multiple jurisdictions have already written it into law. Carriers will be measured against it when examiners arrive.
The window to build is closing
The NAIC examination cycle opens this fall.
ADMT enforcement begins Jan. 1. Both are not far off and demand cross-functional coordination across data, technology, legal, underwriting and claims. Carriers entering the second half of 2026 without a written AIS Program, without an ADMT readiness assessment, and without a NYDFS-compliant AI gov- ernance framework are not preparing for an exam, they are already in the examination room.
The good news is that the infrastructure required across all three frameworks share common elements. An integrated program, built once and designed to address ADMT, NAIC and NYDFS simultaneously, costs less and produces more defensible governance than three parallel compliance workstreams. Carriers building it now will have structural advantages in examination readiness, deployment speed and regulatory relationship management that their later-moving competitors will not be able to replicate quickly.
Carriers waiting for a more convenient moment to start are misreading their calendar.
The automated decisions are running. The frameworks are in force. Every month without an AI governance program is regulatory debt, and the collection schedule is set.

BLOG







