Six days to produce your AI inventory
As sent to subscribers on July 22, 2026. Get the next one in your inbox →
Three of the country’s largest health insurers have until Tuesday to hand Congress a list of every predictive tool they use in coverage decisions. Whatever they produce sets the format the rest of the industry gets asked for next.
This week’s story: what UnitedHealth, Humana, and CVS have to hand over by Tuesday
Two senators, one from each party, want to see the machinery. Richard Blumenthal and Josh Hawley wrote to UnitedHealthcare, Humana, and CVS Health on July 14, asking how each decides post-acute care coverage and specifically what software touches determinations of medical necessity, payment, and authorization. Each company was asked to restate in writing that no final Medicare Advantage denial is issued by technology alone, and to hand over a list of the predictive tools it runs. Answers are due July 28.
None of this carries subpoena power. Blumenthal writes from the minority as the investigations subcommittee’s ranking member, which on its own would make a slow-walk cheap. Hawley’s signature is what raises the price. Between them the letters move AI-assisted prior authorization off the vendor-management agenda and onto an oversight docket, where the test is not whether a model performs but whether a denial it shaped holds up when read aloud.
The document itself is the part to watch. Three of the largest carriers in the country have two weeks to produce a predictive-tool inventory, and whatever they settle on becomes the reference point when an examiner or a plaintiff’s counsel asks for yours. Courts got there first: a federal magistrate has already ordered UnitedHealth to open its files on nH Predict, down to the minutes of its AI review board. July 28 tests whether Congress can pull the same records by asking.
Set that beside the vote two days later. On July 16 the Senate declined, 46 to 50, even to take up a resolution that would have ended CMS’s WISeR Model, leaving AI-assisted prior authorization running in traditional Medicare across six states. Private plans are being told to show their work. The public program is scaling up with less disclosure attached. A carrier in both markets does not get to average the two.
Full breakdown of the inquiry, including what a defensible file looks like: Senators Press UnitedHealth, Humana, CVS on AI-Driven Medicare Advantage Care Denials. On the WISeR vote and what closes next: Senate Blocks Effort to End AI Prior Authorization in Traditional Medicare.
What to do this week
- Build the predictive-tool inventory before anyone asks for it: every AI touchpoint in prior authorization and utilization management, named, with an owner
- For each one, make sure the file names a reviewer, the criteria they worked from, and the reason the decision landed where it did. Missing any of the three, the file answers “the model recommended it” by default, and that does not survive being read into a hearing record
- Line that inventory up against the disclosures you have already filed with state regulators. Where the two describe different systems, the difference is the exposure
- If you write both traditional Medicare and Medicare Advantage, hold the whole book to the Medicare Advantage standard. Two standards running at once is not a reason to document to the looser one
On the Docket
- July 22, 2026, 12:00 PM ET: The NAIC’s Big Data and Artificial Intelligence Working Group takes up governance trends with an actuarial panel, plus where the AI Systems Evaluation Tool pilot now stands. Relevant to anyone tracking the model framework. NAIC committee page
- July 28, 2026: UnitedHealthcare, Humana, and CVS Health responses due to Senators Blumenthal and Hawley. Health insurers using algorithms anywhere in utilization management.
- Fall 2026: the AI Systems Evaluation Tool is set for a September and October update on pilot feedback, and it is that later draft the fall meeting is scheduled to weigh for adoption. Carriers preparing for a standardized evaluation regime.
- Jan 1, 2027: Illinois’s frontier AI statute begins operating, with the audit requirement it is best known for held back to January 2028. Matters to any insurer whose stack sits on a frontier vendor.
- Jan 1, 2027: Minnesota’s prohibition kicks in, signed May 27: no adverse determination reached on automation alone, and the sign-off has to come from an appropriate health professional.
This week in brief
Governance
The White House launched Gold Eagle, a clearinghouse that brings AI developers together with critical-infrastructure operators. It takes in vulnerabilities already identified across industries and sectors and coordinates the scanning for more, which is where the frontier AI comes in. Treasury leads it, which puts the department at the center of financial-sector policy in charge of forming the clearinghouse; that lead comes from the June executive order behind the launch rather than from the announcement itself, which names four parties jointly. Cyber underwriters should expect historical loss patterns to get less stable. White House announcement
Britain brought the UK cloud arms of Amazon, Microsoft, Google, and Oracle inside the financial regulators’ perimeter on July 13, with the Bank of England, the PRA, and the FCA overseeing the resilience of the critical services they supply rather than reaching them through the firms that depend on them. A vendor oversight program that stops at the model now has a layer underneath it to account for. Bank of England
Texas issued Commissioner’s Bulletin B-0003-26, and it reaches further than the headline does: every regulated entity, and every “advanced analytical and computational” technology standing behind a decision that touches a consumer, not AI alone. Those decisions have to comply with existing insurance law, a person should review the consequential ones before action is taken, and the same expectations “extend to any third party working with a regulated entity.” The bulletin prescribes no documentation of its own, so what an inquiry reaches is the record a company already keeps. Texas Department of Insurance
Business Lines
ISO’s generative AI exclusions carry a 01 26 edition date and are reported effective from January 2026, and the seam is the definition rather than the title. The forms define generative AI as a system that creates content, which describes producing text and images and does not obviously describe taking actions. The Insurer reported on July 10 that ISO is weighing exclusions aimed specifically at agentic systems. Pull the endorsement schedule and read the wording, not the form name. Verisk
Sysdig published its analysis of JADEPUFFER, an intrusion its researchers believe a language model drove from first scan to extortion demand with no operator present. The way in was mundane: an internet-facing Langflow instance left unpatched against a published CVE. That is the part an underwriter can put a number on. Sysdig
NHTSA wants measurable standards for how a self-driving car behaves, competencies a manufacturer can pass or fail. They would sit on top of the crash-by-crash recall and enforcement work the agency says it will carry on, not in place of it. Those competencies get settled in the public comment NHTSA plans to seek first, not in the final rule, and they are what an AV fleet account will be asked to evidence later. That round has not opened yet; anyone underwriting commercial auto for AV operators wants to be ready to file the day it does. Insurance Journal
One data point
31 seconds. That is how long JADEPUFFER took to correct its own failure mid-campaign, according to Sysdig’s reconstruction. Response plans assume a human on the other side: a lull between stages, a mistake that gives away intent, a window in which to negotiate. Thirty-one seconds is faster than a pager.
That’s the week. Reply to the email this issue arrived in if you want us to dig into any of these further, we read every reply.
Correction, August 16, 2026: nine entries here were rewritten after a read against the primary sources behind them, and the July 22 email stands as delivered.
– The Editor, InsureAI Wire