What Regulators Test in AI Underwriting

How AI in underwriting works across P&C, life, and health lines, what the NAIC evaluation tool expects, and how to prove your models are fair and traceable.

In this article

For Underwriting leaders, actuaries, and compliance officers at P&C, life, and health carriers.

Read if Your underwriting runs on AI or external data and you want to know what an examiner will ask before they arrive.

By Simon Li · Published JUN 30, 2026 · Updated AUG 2, 2026 · 8 min read

Engraved cover illustration: What Regulators Test in AI Underwriting
Ask AI

AI in insurance underwriting reaches different evidence in every line. Accelerated underwriting platforms can return a life risk class in minutes. P&C carriers ingest telematics, aerial imagery, and weather data before quoting a policy. Health products and programs operate within a different set of eligibility and rating constraints. This guide owns the cross-line workflow and the questions an examiner can ask across it. Life-specific mortality evidence, New York’s testing procedure, homeowners pricing, and proxy analysis remain with the specialist guides linked where each issue arises.

Regulators know this. The NAIC’s AI Systems Evaluation Tool, which twelve states are piloting between March and September 2026,1 lists underwriting and eligibility as one of the fifteen operational or program areas a carrier has to account for.2 The site’s underwriting branch places that decision beside the other business-line routes. The examiner’s practical question is how the carrier knows the AI is fair, traceable, and properly governed.

Why underwriting is the natural test case for AI regulation

Underwriting is where an insurer decides who to cover and what to charge. Colorado’s statute calls that kind of decision a consequential decision.3 The NAIC Model Bulletin never uses the phrase; it reaches the same ground through “Adverse Consumer Outcome,” defined as an insurer decision subject to the standards the department enforces that harms the consumer in a way those standards forbid.4 Either way the decision directly affects consumers’ access to coverage and the price they pay. It also tends to use the richest and most sensitive data: driving behavior, health history, property condition, financial records.

Because underwriting is both high-impact and data-intensive, it attracts attention from three directions at once:

  • State insurance regulators want to know that pricing and selection practices do not produce unfair discrimination.
  • State insurance AI statutes such as Colorado’s SB 21-169, which bars insurers from using models that unfairly discriminate and leaves the testing and reporting duty to rules the commissioner adopts one line of insurance at a time. Only one such rule has been adopted so far, and it covers three personal lines rather than the whole market.3 Colorado’s newer SB 26-189 adds disclosure and human review for automated decisions from January 1, 2027, but section 6-1-1708(1)(a) deems an insurer already subject to SB 21-169 compliant in the practice of insurance, so underwriting stays SB 21-169 work.3
  • Consumer advocates and plaintiffs’ lawyers look for adverse outcomes that appear correlated with protected classes.

The result is that underwriting is no longer just a pricing or risk-selection exercise. It is a compliance exercise with a risk-selection component.

Where underwriting appears in the Evaluation Tool

Underwriting and eligibility is one of Exhibit A’s operational areas. The exhibit asks for counts and use cases, not a second underwriting inventory.2 If the insurer’s own risk method classifies a model as high risk, Exhibit C asks for model identity, purpose, limitations, testing, last test date, and other system details. Exhibit D identifies the data categories and sources behind the models.2

The Evaluation Tool guide owns the full A through D structure. For underwriting, the important seam is whether the same system, version, use, and data source appear consistently in the operational record, high-risk record, and data map.

Three lines, three different underwriting risks

P&C underwriting

Property and casualty underwriting has adopted AI rapidly because the data sources are abundant and relatively structured. Common applications include:

  • Auto insurance: Telematics and usage-based insurance models score driving behavior in real time. Regulators ask whether the scoring correlates with protected classes and whether consumers receive adequate notice.
  • Homeowners insurance: Aerial imagery, roof-age estimates, and catastrophe models influence pricing and eligibility. A run of states has since written age limits on the image itself before it can carry a cancellation or nonrenewal, which is the fight the homeowners pricing guide follows state by state.
  • Commercial insurance: Submission scoring, risk aggregation tools, and natural catastrophe models help underwriters prioritize accounts. The challenge is explaining why a model recommends a declination when the underlying risk is complex.

The dominant risk in P&C is proxy discrimination. A variable that appears neutral, such as roof age or distance to a fire station, can correlate with race or income when mapped across a geographic area.

Life underwriting

Life insurance accelerated underwriting uses predictive models and electronic health records to bypass traditional fluid testing. The benefits are faster issuance and lower friction. The risks are different:

  • Health data sensitivity: The data used, including prescription history, medical claims, and electronic health records, is highly sensitive and tightly regulated under state and federal privacy laws.
  • Mortality scoring opacity: Models that predict mortality are difficult to explain to consumers and regulators.
  • Historical bias: Training data from decades of manual underwriting may embed the biases of earlier underwriting practices.

That last risk has no settled name. A 2021 paper on AI-enabled life underwriting in the NAIC’s own Journal of Insurance Regulation found no standard definition of proxy discrimination in insurance underwriting.5 It also found no consensus on whether the issue turns on discriminatory intent or discriminatory impact.5

Health underwriting

Health underwriting in the United States operates under tighter constraints than P&C or life. The Affordable Care Act largely prohibits medical underwriting in individual health insurance.6 But AI is still used in several related areas:

  • Risk adjustment: Models predict the expected cost of enrolled populations to set risk-adjustment payments. Bias here can shift dollars between plans.
  • Medicaid eligibility: States use automated systems to determine eligibility, which can affect coverage access.
  • Supplemental health and short-term plans: These products may still use health-related underwriting, where AI models face scrutiny under both insurance law and consumer protection law.

Health underwriting AI sits at the intersection of insurance regulation and health equity law, making it one of the most regulated areas. For a deeper look, see our analysis of AI in health insurance governance.

The fairness question changes with the line

A neutral-looking variable can correlate with protected-class status, and a model can produce different outcomes even when protected-class data is absent. Those are related but separate questions. The proxy and disparate-impact guide owns the concepts; the NYDFS AI guidance, Circular Letter No. 7 owns that state’s testing sequence and notice boundary.

The underwriting team’s job in this article is to identify where the question enters the workflow. In P&C it may be a location, property, credit, or driving feature tied to selection or price. In life it may be an external data source used to replace traditional evidence, and the life underwriting guide works that substitution through accelerated underwriting and the tests it now has to pass. In health it may be a product or program decision whose permissible inputs are constrained before model testing begins.

Build the line-specific evidence seam

For each underwriting use, record the decision, the product and jurisdiction, the source evidence, the system output, the underwriter’s action, and the consumer-facing result. Then add what is unique to the line.

Line-specific underwriting evidence that a generic checklist can miss
LineEvidence that should not be flattened into a generic checklist
P&CProperty or driving observation, rating treatment, filing or rule reference, inspection or correction path
LifeTraditional evidence replaced, mortality rationale, external-data source, accelerated-program exception and manual path
HealthProduct and plan type, permissible eligibility or rating treatment, program rule, handoff to utilization or risk-adjustment operations

Use the inventory playbook for the company register and the decision evidence pack for one completed transaction. The table above tells those tools what underwriting-specific facts they must point to.

Vendor models add an interface, not a second framework

Underwriting teams need to identify which vendor release, score, data source, and limitation reached the decision. Procurement and legal own the detailed diligence and contract process in the vendor risk assessment. The underwriting owner remains responsible for deciding whether the vendor’s evidence is adequate for this product and use.

What an exam asks underwriting

AI in underwriting insurance has already stopped being a future risk and become a current exam topic. The NAIC’s twelve-state pilot, Colorado’s SB 21-169, and New York’s Circular Letter No. 7 all point to the same expectation: explain what the underwriting models do, name the data that feeds them, and show how the outcomes were tested.

The exam will put the same basic questions to every carrier: what the model does, what data feeds it, and how the outcomes were tested. Preparing now means walking in with those answers already written down. The practical next step is to select one completed underwriting decision and trace its product, jurisdiction, data, model output, what the underwriter did, any consumer notice, and the retained evidence.

Underwriting is the hard case for a reason that has nothing to do with model complexity. The decision is adverse, it names a person, and it carries a date. That combination is the one shape a regulator can pull a file on and follow all the way back to the variable that produced it.

FAQ

Does the NAIC Model Bulletin cover underwriting models? Yes. Underwriting is one of the core areas where AI systems can produce or support adverse consumer outcomes. The NAIC Model Bulletin expects insurers to have governance, testing, and documentation programs that apply to these models.4

What is the difference between Exhibit A and Exhibit D in the NAIC Evaluation Tool? Exhibit A is a count: how many AI models each operational area runs, how many of them reach consumers directly, and what the use cases are. Exhibit D is the data inventory, covering which of twenty-five data-element categories feed the systems and whether each one is internal or bought, with the vendor named.2 Neither asks about proxy testing in those words; that question sits in Exhibit C.2

Is AI underwriting banned? No. Existing insurance laws continue to govern AI-assisted underwriting, including prohibitions on unfair discrimination and unfair trade practices. Insurers need evidence that their systems comply with those rules.

Do I need to stop using third-party underwriting models? Use can continue when the insurer has enough evidence to support the model in the product and jurisdiction at issue. The insurer still owns the outcome.4 Detailed diligence, audit rights, and change-notification controls belong in the vendor risk assessment.

How often should underwriting models be tested for bias? The cadence depends on the applicable rule, the decision, and the system’s material changes. New York specifies its own testing steps and timing; the NYDFS Circular Letter guide explains them. In other contexts, the insurer should document why its chosen cadence can detect a harmful change before too many decisions accumulate.

Footnotes

  1. National Association of Insurance Commissioners, “AI Systems Evaluation Tool Pilot: Pilot Project Background” (naming the twelve participating states and the March–September 2026 window): https://content.naic.org/sites/default/files/call_materials/Pilot%20Project%20Summary.pdf

  2. National Association of Insurance Commissioners, “Draft AI Systems Evaluation Tool 4.0,” used in the 2026 state pilot (Exhibit A: AI Usage Inventory; Exhibit C: High-Risk AI Systems; Exhibit D: AI Systems Data Details): https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf 2 3 4 5

  3. Colorado Division of Insurance, “SB21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices” (indexing Regulation 10-1-1, 3 CCR 702-10, the only rule adopted under the statute, whose scope as amended effective October 15, 2025 reaches individually issued life, private passenger automobile, and health benefit plan insurers): https://doi.colorado.gov/for-consumers/sb21-169-protecting-consumers-from-unfair-discrimination-in-insurance-practices. On the later disclosure statute, see Colorado General Assembly, “SB26-189 Automated Decision-Making Technology,” effective January 1, 2027: https://leg.colorado.gov/bills/sb26-189 2 3

  4. National Association of Insurance Commissioners, “Model Bulletin on the Use of Artificial Intelligence Systems by Insurers,” December 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf 2 3

  5. Azish Filabi and Sophia Duffy (The American College of Financial Services), “AI-Enabled Underwriting Brings New Challenges for Life Insurance: Policy and Regulatory Considerations,” Journal of Insurance Regulation 40, no. 8 (2021), published by the National Association of Insurance Commissioners: https://content.naic.org/sites/default/files/JIR-ZA-40-08-EL.pdf 2

  6. Public Health Service Act §2702, “Guaranteed availability of coverage,” 42 U.S.C. §300gg-1 (issuers “must accept every employer and individual in the State that applies for such coverage”): https://www.law.cornell.edu/uscode/text/42/300gg-1. See also Public Health Service Act §2705, “Prohibiting discrimination against individual participants and beneficiaries based on health status,” 42 U.S.C. §300gg-4 (barring eligibility rules and premium differences based on health status, medical condition, claims experience, medical history, genetic information, or disability): https://www.law.cornell.edu/uscode/text/42/300gg-4. “Largely” carries the carve-outs: grandfathered plans, short-term limited-duration insurance, and excepted benefits sit outside this scope.

The Bottom Line

  • Underwriting is one workflow with different evidence seams in P&C, life, and health.
  • The Evaluation Tool locates underwriting systems. The insurer supplies its risk classification, and applicable state law supplies the fairness test.
  • P&C centers on property, driving, and filed-rating evidence; life centers on mortality and external data; health is constrained by product and program rules.
  • Detailed proxy analysis, New York testing steps, inventory fields, and vendor controls each belong to their owner article.

Recommended next

How to Build an AI Inventory by Line of Business for NAIC Exhibit A

Map your insurance AI systems by line of business for NAIC Exhibit A. Use this template to capture underwriting, pricing, claims, fraud, and customer service AI.

Continue →
Engraved portrait of Simon Li

Written by

Simon Li · Founding Editor

I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.

Contact or report a correction →

Related reading

AI in Insurance Claims

Business Lines · Understand

AI in Insurance Claims

AI in insurance claims, step by step from intake to appeal: what each system decides, where it can go wrong, and what record makes the step reviewable.

JUL 31, 2026 · 9 min read

Information aggregation and analysis, not legal advice. See our disclaimer.