Why January 2027 Is Already a Problem
Three separate regulatory deadlines land on January 1, 2027, and every insurer using AI in underwriting, claims, or customer decisions is in scope for at least one of them. Colorado’s rewritten automated decision-making law. California’s CCPA ADMT rules. The NAIC’s examination tool going live in state after state. If your organization treated AI governance as an innovation issue rather than a compliance function, the window to fix that is this year.
What NYDFS Is Actually Signaling
On May 21, 2026, the New York Department of Financial Services issued an advisory warning DFS-regulated entities — including insurers — that frontier AI models will soon allow threat actors to find and exploit system vulnerabilities “at unprecedented speed and scale.” The advisory was paired with detailed guidance on defensive measures entities should consider in a heightened cybersecurity environment.
The NYDFS was explicit: this creates no new legal requirements under 23 NYCRR Part 500. But that’s almost beside the point. The agency also said it will treat the advisory as a reference point during examinations. Insurers that haven’t updated their Part 500 risk assessments to address frontier AI risks — and can’t document why they didn’t — face real examination exposure, even without new rules on the books.
This is the NYDFS pattern: guidance that isn’t technically binding but shapes what examiners expect to see. An April 2026 cybersecurity settlement reinforced the message — regulators are checking whether policies are operationalized, not just written.
Colorado’s Narrower Rewrite: What SB26-189 Does
Colorado’s original AI Act (SB 24-205) was broadly written and faced intense industry opposition. On May 14, 2026, the state replaced it with SB26-189, which takes a more targeted approach — but it still bites hard for insurers, and it takes effect January 1, 2027.
The new law covers automated decision-making technology (ADMT) used in “consequential decisions,” a category that explicitly includes insurance. Where the old law focused on “high-risk” AI systems and required extensive developer obligations, SB26-189 distinguishes more carefully between developer and deployer responsibilities.
For developers, the main obligation is transparency to deployers: a general statement of the ADMT’s intended use, training data, known limitations, instructions on human review, and mandatory notification of material updates. For deployers — which most insurers are — the obligations are consumer-facing: clear notice when ADMT influences a consequential decision, additional disclosures when an adverse decision is reached, a mechanism for consumers to access and correct their data, and an option to request meaningful human review. Both parties must retain compliance documentation for at least three years.
The law explicitly exempts insurers who are already complying with Colorado’s pre-existing insurance-specific AI regulation from the broader ADMT framework — but you have to actually be complying with that regulation, not just claiming you are.
California Adds Its Own January 2027 Deadline
California’s finalized CCPA regulations also split across two dates. Risk assessment obligations under those rules began January 1, 2026. ADMT compliance — covering automated profiling, scoring, and decision-making — begins January 1, 2027. Cybersecurity audit certifications for larger businesses are phased in starting 2028. For insurers doing business in California (which is most major carriers), this is a parallel compliance track running alongside the Colorado deadline.
The NAIC Is Building the Infrastructure to Examine You
The practical shift that gets undercut in most coverage of insurance AI regulation is that the NAIC now has the machinery to actually examine insurer AI programs, not just publish principles. The NAIC’s AI Systems Evaluation Tool — a structured framework for assessing AI governance during market conduct examinations — is being piloted in 2026 by 12 states, including California, Colorado, Connecticut, Florida, Iowa, Maryland, Pennsylvania, and Wisconsin.
The tool covers AI governance structure and board oversight, model development and validation, data quality and bias testing, third-party vendor management, consumer impact assessment, and documentation. Expected to be considered for formal adoption at the 2026 Fall National Meeting, this framework gives state regulators a common, rigorous basis for AI-related examinations — something they’ve never had before.
At least 24 states and the District of Columbia have already adopted the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. The bulletin requires insurers to build a written AI governance program covering the full insurance lifecycle. That includes not just underwriting and pricing, but claims, fraud detection, marketing, and customer service. Third-party vendor relationships don’t provide a compliance shield: the bulletin explicitly holds insurers responsible for AI systems developed or provided by vendors, and regulators have signaled they will “look through” those relationships during examinations.
A NAIC model law on third-party data and models — potentially including licensing requirements for AI vendors serving the insurance industry — is anticipated later in 2026. This would extend scrutiny beyond insurers to the vendors providing the algorithms and data underlying insurance decisions. That’s a significant escalation.
Health Insurance AI: The Highest-Scrutiny Use Case
Regulators, plaintiffs, and policymakers have continued to focus intensely on AI in prior authorization, utilization review, claims administration, and fraud detection. The common thread in enforcement and litigation is the same: algorithms making or influencing denial decisions, without adequate human oversight or individualized assessment.
The key themes regulators are looking for in health insurance AI: human review mechanisms, individualized assessment (not just population-level model outputs), transparency to consumers about when AI is in use, auditability of decisions, privacy restrictions on patient data used for AI training, and anti-discrimination controls. If your health plan’s AI system can’t answer those questions for an examiner, it won’t survive the new examination infrastructure.
What to Have Ready Before December 31
The practical question isn’t whether to comply — it’s whether you can demonstrate compliance when an examiner shows up in Q1 2027 with the NAIC evaluation tool in hand. The minimum viable governance program for a US insurer heading into 2027 includes an inventory of every AI and ADMT system in use across underwriting, pricing, claims, fraud, marketing, and customer service; documented bias testing results with a clear methodology; third-party vendor contracts that include audit rights, model documentation requirements, and cooperation with regulatory inquiries; consumer-facing notice processes for any AI-influenced consequential decision; and an adverse action disclosure workflow that enables human review where required.
The NYDFS advisory adds one more item to that list: update your Part 500 risk assessment to specifically address frontier AI cybersecurity risks. If your assessment doesn’t mention frontier AI threat vectors, document why — and be prepared to explain that reasoning to an examiner.
Insurers that have been treating AI governance as a technology project run by the data science team will need to restructure that ownership. The NAIC bulletin requires cross-functional oversight with defined authority across actuarial, data science, underwriting, claims, compliance, and legal. That governance structure is now the thing regulators will assess first.
The Illinois AI Safety Act — signed last month — shows where this is heading: mandatory audits, not just examinations. And Colorado’s earlier AI Act already established that states are willing to move faster than federal frameworks. The January 2027 deadline isn’t a soft target.
Further Reading
- AI Governance Expectations on the Rise for Insurers Amid New Regulatory Activity (Hinshaw) — The most thorough legal breakdown of NYDFS, Colorado SB26-189, NAIC examination tool, and California CCPA ADMT, with concrete steps for compliance teams.
- AI Regulation in Insurance 2026: The NAIC Model Bulletin and Federal Preemption Battle (actuary.info) — State-by-state adoption tracker, the federal executive order challenge, and a line-of-business breakdown of where AI scrutiny is highest.
- NAIC Model Bulletin on the Use of AI Systems by Insurers (NAIC) — The source document. If you haven’t read the actual bulletin, do it before your next board presentation on AI governance.

