
Insurance AI governance isn't a subset of general AI compliance. It's its own regulatory track, built on top of a licensing and market-conduct system that already treats underwriting and pricing decisions as things a state insurance department can examine, unwind, or fine an insurer over. An AI employee that reads an application, scores risk, or sets a premium is stepping directly into that examined territory, which is why insurance carries rules that a generic enterprise AI compliance checklist won't surface.
This guide covers the three frameworks that actually govern AI employees in US insurance today: the NAIC's AI Model Bulletin, New York's DFS Circular Letter 2024-7, and Colorado's SB21-169 testing regime, plus where claims-processing AI employees fit and what to check before putting one of these systems into production.
One scope note before we start: this guide is about AI employees, the software agents zamp.ai builds. It isn't about Zamp HR, a payroll and PEO product, or zamp.com, the US sales-tax compliance platform, which happen to share part of the name.
An underwriting or pricing decision determines whether someone gets covered at all, and what they pay for it. A claims decision determines whether a covered loss actually gets paid. Both are the kind of consumer-facing, life-affecting outcomes that insurance regulators have examined for decades under unfair-discrimination and market-conduct rules, long before AI entered the picture. What's changed is that regulators now have to figure out how those existing protections apply when a model, rather than an underwriter, is making or shaping the call.
That's produced a wave of insurance-specific AI rules distinct from the general state AI laws covering employment or consumer protection broadly. An insurer already complying with a state's general AI or hiring law still has a separate, insurance-specific compliance track to satisfy on top of it.
The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023, and state insurance departments have been adopting it individually ever since. As of 2026, 25 states and DC have formally adopted it, with several more moving through their own approval processes. California, Colorado, New York, and Texas didn't adopt the model bulletin as written; each runs its own insurance-specific AI framework instead, which is why a nationally licensed insurer needs a state-by-state map rather than one blanket policy.
Where it's adopted, the bulletin expects an insurer to run a real AI governance program, not just a policy document. That means board- and senior-management-level accountability for AI use, written governance covering the AI system's full lifecycle from development or vendor selection through monitoring and retirement, and documented oversight of any third-party AI vendor whose tools touch underwriting, pricing, claims, or marketing. Examiners can request that documentation directly during a market conduct exam, so "we trust our vendor" isn't an adequate answer on its own.
New York took its own path. The Department of Financial Services adopted Insurance Circular Letter No. 7 in July 2024, covering how authorized insurers use AI systems and external consumer data and information sources, ECDIS in the letter's own shorthand, in underwriting and pricing. It's scoped narrowly on purpose: it governs underwriting and pricing decisions specifically, and doesn't reach claims adjusting, marketing, or fraud detection.
The requirement that shows up most often in practice: when an applicant isn't approved through an accelerated underwriting path, the insurer has to give that applicant a way to review, for accuracy, the data that drove the decision, at the time they're notified of it. DFS frames the whole circular as an application of existing New York insurance law to AI-driven underwriting, not new legislation, which means the underlying fair-underwriting standards New York already enforced still apply in full; the letter just spells out how they apply when a model is doing the assessing.
Colorado passed SB21-169, protecting consumers from unfair discrimination in insurance practices, back in 2021, well before most state AI legislation existed. It requires insurers to test the algorithms, external consumer data sources, and predictive models behind underwriting for discrimination against protected classes, on the basis of race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.
The Colorado Division of Insurance implements SB21-169 through Regulation 10-1-1, which has governed life insurance since November 2023 and was expanded in October 2025 to cover private passenger auto and health benefit plans, with full compliance required by July 1, 2026. Worth being explicit about, since it trips people up: this is a separate regime from Colorado's general AI Act, SB 26-189, which covers high-risk AI systems across industries broadly. An insurer operating in Colorado needs to satisfy both, not one instead of the other, and the general AI Act's disclosure requirements don't substitute for SB21-169's discrimination-testing obligations on underwriting models specifically.
Framework | Scope | What it requires | Status |
|---|---|---|---|
NAIC AI Model Bulletin | 25 states + DC (2026); adopted per-state | Board/senior-management accountability, full-lifecycle governance policy, documented third-party AI vendor oversight | Adopted since Dec 2023, ongoing state rollout |
NY DFS Circular Letter 2024-7 | New York; underwriting and pricing only | Data-accuracy review path for non-accelerated declines; governance over AI and external consumer data used in pricing | Effective July 11, 2024 |
Colorado SB21-169 / Reg 10-1-1 | Colorado; life insurance now, auto and health expanding | Algorithmic-discrimination testing on underwriting models and external data sources against protected classes | Life insurance since Nov 2023; auto/health compliance due July 1, 2026 |
Underwriting and claims are governed differently, as the frameworks above show, but both are common first deployments for insurance AI employees, and both need the same underlying governance discipline even where a specific rule, like NY's circular letter, is scoped to only one of them. An AI employee triaging a claim, verifying coverage, checking documentation completeness, or flagging a suspected discrepancy is still making decisions a market conduct examiner can ask about, even on the days no specific AI bulletin names claims work directly.
For the operational side of what that looks like day to day, see our complete guide to insurance claims automation, which covers the workflow mechanics this guide's regulatory frameworks apply on top of.
An Agent Operating Procedure, or AOP, is a living definition of the job: the underwriting or claims outcome, source data, tolerances, and escalation rules. A compliance or underwriting officer should be able to read and edit that procedure directly, in plain language, when a state adopts a new bulletin or a testing requirement changes, rather than filing an engineering ticket and waiting on a release cycle.
A full decision audit trail, built in. Every underwriting or claims action should carry a record of what the agent saw, what it decided, and why, tied to the specific applicant or case, not just a system log confirming a step ran. That's the exact shape of documentation the NAIC bulletin and NY DFS both expect an insurer to produce on request, so it needs to exist before an examiner asks for it, not after.
A persistent institutional record. Reviewed corrections feed back into the AOP, building what Zamp calls a Company Brain, a shared, reviewable record of how the business actually underwrites or adjudicates claims. A new state's bulletin adoption becomes a documented policy update, not a system rebuilt from scratch.
Deployment flexibility. Zamp can run on-prem, as multi-tenant SaaS, or inside the insurer's own cloud environment (BYOC), which matters for carriers with strict data-residency or vendor-risk requirements layered on top of their state insurance department's expectations.
For the broader definition of what an AI employee is and how the governance model applies across industries, see our complete guide to AI employees. For how this same governance model applies in two other heavily regulated industries, see our guides to AI employees in banking and financial services and AI employees in healthcare and pharma.