Is your AI governed ? Get your maturity score and roadmap. Request Access to the AI Governance Advisor →

AI in Insurance Underwriting and Pricing: Governing Unfair Discrimination Under the New Rules

Table of Contents

Summarize and analyze this article with
ChatGPT

Chat GPT

ChatGPT

Perplexity

 
ChatGPT

Grok

 
ChatGPT

Google AI

ChatGPT

Claude

 

Where insurance regulators focus hardest

Of all the ways insurers use AI, underwriting and pricing draw the sharpest regulatory attention, because those decisions determine who gets covered and at what price, and because a model can produce unfairly discriminatory outcomes even when race, and other protected characteristics are left out of the inputs. Proxies in the data reproduce the disparity. Regulators have responded: the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted since December 2023 by 24 states and the District of Columbia as of the 2026 Spring National Meeting with several more states issuing AI-specific regulation, sets governance expectations, and states such as Colorado have gone further with testing and governance requirements for life insurers. For insurers, defensible underwriting and pricing AI is now a documented, tested discipline.
This guide explains what a defensible AI underwriting and pricing program requires. It is educational and not legal advice.

What a defensible program needs

Element What it requires Evidence
Unfair-discrimination testing Test outcomes for proxy and disparate-impact effects across protected classes Documented testing and mitigations
External-data governance Control the provenance and use of external consumer data and its outputs Data lineage and permitted-use records
Governance framework An AI systems program with accountability, policies, and inventory Written program mapped to NIST AI RMF and ISO 42001
Documentation and filings Records and any filings the state expects Reviewable documentation
Monitoring Ongoing testing as models and data drift Monitoring logs and remediation records
Human accountability A person accountable for the underwriting or pricing decision Clear ownership and review records

The NAIC Model Bulletin and state rules

The NAIC Model Bulletin does not ban any AI use or hand insurers a control checklist; it sets a principle-based expectation that insurers govern AI through a documented program, remain accountable, and avoid unfair discrimination, and it references the NIST AI Risk Management Framework and related frameworks. Because two dozen states and DC have adopted it, most of a nationally writing carrier’s premium now sits in bulletin jurisdictions, and market-conduct examinations increasingly include structured questions about AI governance. States such as Colorado have added specific governance and quantitative-testing requirements for certain lines. Separately, the NAIC’s AI Risk Evaluation Supplement, in pilot and exposed for comment in 2026, signals where examination is heading, including a focus on inherent risk. Confirm the rules applicable to your lines and states at implementation.

Where PiTech fits

PiTech Solutions builds the data, testing, and governance behind defensible AI underwriting and pricing: unfair-discrimination and proxy testing pipelines, external-data lineage and permitted-use controls, an AI governance program mapped to the NIST AI RMF and ISO 42001, and the documentation an examination expects. It works alongside the insurer’s actuarial, underwriting, and compliance teams, owning the data and testing that turn a fairness policy into evidence. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See the insurance practice, AI, GenAI and ML, and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.

The bottom line

AI underwriting and pricing is defensible when it is tested for proxy discrimination, governs the external data it relies on, sits inside a documented AI program, and keeps human accountability. Excluding protected fields is not a defense; tested outcomes and governed data are.

Frequently Asked Questions (FAQs)

How is AI regulated in insurance underwriting and pricing?

Through a combination of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by two dozen states and DC, state-specific rules such as Colorado’s, and longstanding unfair-trade-practices and anti-discrimination laws that apply regardless of the technology. The expectation is that insurers govern AI through a documented program, avoid unfair discrimination, and remain accountable for decisions. Underwriting and pricing draw particular scrutiny because they determine coverage and cost. There is no single federal AI insurance law; the framework is state-based and principle-driven, hardening into examinable expectations through market-conduct exams and tools such as the NAIC’s AI Risk Evaluation Supplement. Insurers should confirm the rules applicable to their specific lines and states.

Yes. Removing race, and other protected characteristics from the inputs does not make a model fair, because other variables can act as proxies and reproduce the same disparate outcomes. This is why regulators focus on testing outcomes for unfair discrimination rather than accepting input exclusion as sufficient. A model can be facially neutral and still produce results that disadvantage a protected class, which requires detection and mitigation. The defensible approach tests model outcomes across protected classes for proxy and disparate-impact effects, documents what is found, and addresses it. Treating the omission of sensitive fields as compliance is one of the most common and consequential mistakes in AI underwriting and pricing.

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the NAIC in December 2023, sets a principle-based expectation that insurers using AI maintain a documented governance program, remain accountable for AI-driven decisions, avoid unfair discrimination, and manage AI risk across the lifecycle, referencing frameworks such as the NIST AI Risk Management Framework. It does not ban AI uses or provide a control checklist. As of the 2026 Spring National Meeting, 24 states and the District of Columbia had adopted it, with additional states issuing AI-specific regulation, so it governs most of a nationally writing carrier’s business. Market-conduct examinations in bulletin states increasingly include structured questions about AI governance.
Colorado has gone beyond the model bulletin with requirements stemming from its legislation addressing insurers’ use of external consumer data and algorithms, including a governance-and-risk-management framework and, for certain lines such as life insurance, quantitative testing expectations aimed at detecting and addressing unfairly discriminatory outcomes. The specifics, including which lines and practices are covered and the testing methodology expected, are detailed and have evolved through rulemaking, so insurers operating in Colorado should confirm the current regulations applicable to their products. Colorado is significant as an early, prescriptive state model that others watch, which is why its governance-and-testing approach is often treated as a preview of where broader expectations may head.
It is a standardized tool, formerly called the AI Systems Evaluation Tool, that gives state regulators a consistent way to interrogate an insurer’s AI use and governance, organized around exhibits covering the extent of AI use, the governance program, high-risk models, and data. As of 2026 it is in a multistate pilot and its version 5.0 was exposed for comment following the 31 August 2026 working-group meeting, with adoption anticipated at the Fall National Meeting; it is not yet in force. Its direction, including an explicit focus on inherent risk, signals where examination is heading. Insurers should treat the pilot period as a chance to build toward the standard and confirm the tool’s current status.
Test model outcomes across protected classes for proxy and disparate-impact effects, rather than relying on the exclusion of protected characteristics from inputs. Where testing reveals disadvantage to a protected class, investigate the drivers, consider and document less-discriminatory alternatives that still meet legitimate underwriting objectives, and mitigate. This testing belongs in development and in ongoing monitoring, because models and the external data feeding them drift over time. The output is documented evidence: the testing performed, the results, alternatives considered, and the rationale for the model in use. Some states, such as Colorado for certain lines, specify testing expectations, so confirm the methodology your jurisdictions expect and align the program to the strictest applicable standard.
It is the control an insurer maintains over the third-party data, and the algorithms and models built on it, used in underwriting and pricing. Regulators are concerned that external data sources can introduce bias or unfair discrimination into decisions, so insurers are expected to understand the provenance, permitted uses, and effects of the external data they rely on, not treat it as a black box. Governance includes recording data lineage, validating that external data is appropriate and permitted for the use, and testing its effect on outcomes. This is a specific focus of state rules such as Colorado’s and of the broader unfair-discrimination expectation, because external data is a common route through which proxy discrimination enters a model.
Underwriting and pricing models are among the highest-inherent-risk entries in an insurer’s AI inventory, because of what they decide and about whom, so the inventory is where they are identified, tiered, and tracked. A defensible program starts from an inventory that scores inherent risk from the decision and records the controls, including discrimination testing and external-data governance, credited for reducing residual risk. The NAIC’s exposed AI Risk Evaluation Supplement reflects this by focusing on inherent risk and the extent of AI use. In short, the inventory catalogues and tiers the models, and the underwriting-and-pricing governance described here is how the highest-risk entries are tested, documented, and defended. The two work together.
Yes. PiTech Solutions builds the data, testing, and governance behind defensible AI underwriting and pricing: unfair-discrimination and proxy testing pipelines, external-data lineage and permitted-use controls, an AI governance program mapped to the NIST AI RMF and ISO 42001, and the documentation an examination expects. It works alongside the insurer’s actuarial, underwriting, and compliance teams, owning the data and testing that turn a fairness policy into evidence. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. PiTech is positioned as a specialist partner for insurance AI governance at a mid-market price, complementing actuarial and legal expertise rather than replacing it.