Industry guide
Insurance
Underwriting, pricing, claims triage and fraud models decide who gets cover and at what price. The EU AI Act treats risk assessment and pricing in life and health insurance as high-risk; Colorado's ADMT Act names insurance as a consequential-decision sector from 2027; Quebec's Law 25 gives policyholders rights over fully automated decisions; and state insurance regulators increasingly expect governance programmes for AI models. Proxy discrimination through postcode, credit or occupation data is the central risk.
Regulated uses
- Underwriting and eligibility decisions for individuals
- Risk-based pricing and premium personalisation
- Claims triage, automated settlement and fraud flags
- Use of external data (credit, social media, telematics) in models
- Chatbots giving coverage or claims advice
Laws by region
| Region | Law | Status |
|---|---|---|
| EU | EU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689) | In force |
| EU | EU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) | In force |
| US | Colorado ADMT ActColorado Automated Decision-Making Technology Act (SB 26-189, replacing SB 24-205) | Upcoming |
| US | Texas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149) | In force |
| US | Utah AI Policy ActUtah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025) | In force |
| US | EO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence | In force |
| Canada | Quebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions) | In force |
| Canada | PIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA) | In force |
| Standards | NIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) | Voluntary |
| Standards | ISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management system | Voluntary |
Obligations checklist
- Maintain an inventory of models used in underwriting, pricing and claims with an owner for each.
- Test for unfair discrimination and proxy effects on protected classes before use and on a schedule.
- Give clear notice before an automated tool influences a coverage or claims decision, and explain adverse outcomes.
- Provide a human-review route for denied or reduced claims and for declined applications.
- Document the source and justification of every external data feed.
- Disclose when customers are talking to AI in high-risk interactions (Utah) and label AI-generated communications where required.
- Map life/health underwriting models to EU high-risk duties ahead of 2 December 2027.
Real cases
- Settlement2024 · US-federalLouis v. SafeRent — $2.275 million settlement over algorithmic tenant scoring
Settlement approved by the court on 20 November 2024: SafeRent pays $2.275 million (up to $1.175 million to class members) and, for five years, will not produce a SafeRent Score or accept/deny recommendation for applicants using housing vouchers unless a fair-housing expert validates a new model. The court awarded $1.1 million in attorneys' fees.
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
Where do you stand in insurance?
The screener is pre-filled for this sector — ten minutes to your level and gaps.
Sources
- Colorado Replaces Its Landmark AI Act With New Framework — ArentFox Schiff ↗
- Article 99: Penalties — artificialintelligenceact.eu ↗
Last reviewed Sep 25, 2026.