Algorithmic Underwriting
Proxy Discrimination and the Emerging Regulatory Framework for AI in Insurance
In January 2025, the Texas Attorney General commenced proceedings against Allstate Corporation and its data subsidiary Arity International LLC under the Texas Data Privacy and Security Act. The complaint alleged that Arity had collected trillions of miles of location data from approximately 45 million consumers through software trackers embedded in third-party mobile applications, without adequate disclosure or consent. That data was then sold to insurers for use in premium pricing. A parallel class action survived a motion to dismiss in March 2026.1 The proceedings represent the first enforcement action under the TDPSA and a further major regulatory challenge to the telematics data supply chain now used in algorithmic insurance pricing across the United States.
Telematics data is only one input among many. Insurers and their data vendors increasingly draw on credit-based information, postcode-level demographic data, telematics, app-derived behavioural signals and other external consumer data to inform underwriting and pricing. The result is a pricing architecture in which traditional actuarial variables coexist with machine learning models trained on consumer data of a breadth and granularity that existing regulatory frameworks were not designed to address. Regulators, courts and legislatures are responding across multiple jurisdictions, but they are doing so unevenly, with different legal traditions and different conceptions of what constitutes unlawful discrimination in insurance underwriting.
Insurance is becoming both a deployer of AI and a market for the liabilities AI creates. That dual role is producing a regulatory structure in which underwriting, discrimination law, privacy enforcement, product liability and insurance coverage are beginning to converge.
Algorithmic Pricing and Proxy Discrimination
The central risk in algorithmic insurance pricing is proxy discrimination. An insurer may exclude race, ethnicity or disability from its pricing model and still produce discriminatory outcomes if the model relies on variables that correlate with those protected characteristics. Credit-based insurance scores, postcode-level data, telematics records and app-derived behavioural signals can each serve as proxies for characteristics that insurers are prohibited from using directly. The difficulty is that the correlation is often invisible to the insurer itself. A model optimised for predictive accuracy may learn to weight variables that are statistically associated with protected characteristics without any explicit instruction to do so.
The mechanism is well documented in adjacent sectors. In 2024, SafeRent Solutions agreed to a class-action settlement of approximately $2.3 million in Louis v SafeRent Solutions, after plaintiffs alleged that its tenant-screening algorithm disproportionately harmed Black and Hispanic rental applicants using housing vouchers. The Department of Justice was not the claimant, although it had earlier filed a statement of interest on the application of the Fair Housing Act to algorithmic screening.2 In July 2025, the Massachusetts Attorney General secured a $2.5 million settlement from Earnest Operations LLC after an investigation found that the company’s algorithmic student lending model incorporated variables that served as proxies for race, resulting in less favourable terms for borrowers of colour.3
The pattern is now visible. Algorithmic discrimination claims are succeeding where claimants or regulators can show that facially neutral variables produce disparate outcomes along the lines of protected characteristics. The analytical framework is transferable to insurance. The same data sources that created liability in housing and lending are now embedded in insurance pricing models across personal lines. No insurance commissioner has yet imposed a fine specifically for algorithmic pricing discrimination. The enforcement gap is narrowing. The question is when the first action arrives, not whether it will.
The US Regulatory Response
Three regulatory developments define the current US position.
Colorado was the first state to legislate directly on algorithmic discrimination in insurance. Senate Bill 21-169, enacted in 2021, prohibited insurers from using external consumer data sources, algorithms or predictive models in a manner that unfairly discriminates on protected grounds. Regulation 10-1-1 initially focused on life insurers. Amendments adopted in August 2025 extended the governance and risk-management framework to private passenger automobile insurers and health benefit plan insurers, with line-specific compliance timing.4 The compliance obligation is granular. Insurers must identify the external data sources and algorithms used in underwriting, test for disparate impact across protected characteristics and document the results. Separately, Colorado’s broader AI regime has changed again. SB 24-205 was first deferred and then superseded by SB 26-189, signed in May 2026, which recasts the state’s framework around automated decision-making technology and creates obligations beginning on 1 January 2027. That broader regime will intersect with the insurance-specific requirements, but the operative structure is no longer the original SB 24-205 high-risk AI framework.
The New York Department of Financial Services issued Circular Letter No. 7 in 2024, setting out supervisory expectations for insurers using external consumer data and information sources, algorithms and predictive models in underwriting and pricing. The Circular Letter requires multi-step proxy-discrimination testing using a disproportionate-impact, justification and less-discriminatory-alternative methodology, documented governance, contractual controls over vendors and detailed adverse-decision explanations. It also creates a specific 15-day notice obligation where an applicant cannot be underwritten through an External Consumer Data and Information Sources/Algorithmic and Innovative Systems (ECDIS/AIS) process and must instead proceed through a non-ECDIS/AIS process.5 The DFS approach is notable for its specificity. It prescribes the testing methodology by which compliance is to be demonstrated and extends the governance obligation to the insurer’s supply chain. A carrier that purchases pricing data from a vendor such as Arity is expected to hold contractual rights sufficient to audit the vendor’s data collection and modelling practices.
Through the state-regulatory coordination process, the National Association of Insurance Commissioners published a Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on 4 December 2023. The Model Bulletin sets supervisory expectations that insurers maintain a written AI programme, conduct impact assessments and ensure human oversight of algorithmic decisions. More than 24 states have adopted or issued guidance based on the Model Bulletin.6 A 12-state pilot examination tool, designed to standardise supervisory review of insurer AI systems, commenced in March 2026 and is expected to run until September 2026, with formal adoption anticipated in the autumn. Once adopted, the examination tool is likely to become the baseline standard against which state regulators assess insurer AI compliance.
The US regulatory framework is therefore layered. State-level legislation, supervisory circulars and model standards adopted through the National Association of Insurance Commissioners (NAIC) process operate concurrently, with varying degrees of enforcement rigour and different definitions of key terms. An insurer writing business across multiple states faces a patchwork of obligations that differ in scope, in the specificity of testing requirements and in the consequences of non-compliance.
The EU Framework
The European Union has taken a different approach, embedding insurance AI within a horizontal regulatory architecture rather than addressing it through sector-specific legislation.
The EU AI Act classifies AI systems used for risk assessment and pricing in relation to natural persons in life and health insurance as high-risk under Annex III, point 5(c).7 High-risk classification triggers conformity assessments, risk management systems, data governance requirements, transparency obligations and human oversight. Under Regulation (EU) 2026/1744, the Digital Omnibus on AI, stand-alone Annex III high-risk AI obligations will apply from 2 December 2027, while obligations for high-risk AI systems embedded in regulated products will apply from 2 August 2028. Insurers operating in the EU therefore have a defined implementation window, but the obligations themselves remain substantial and require significant investment in documentation, testing and governance infrastructure. An insurer that uses a third-party AI model for pricing will need to satisfy itself that the model meets the conformity requirements, even if the insurer did not develop the model.
The AI Liability Directive, which would have established a harmonised framework for civil liability arising from AI systems, was withdrawn in October 2025. Its withdrawal leaves the liability position fragmented across national tort regimes. The revised Product Liability Directive (2024/2853) partially fills the gap. The Directive extends the definition of “product” to include software and AI systems, and it introduces a concept of defect that applies to self-learning systems whose behaviour changes after placing on the market.8 The revised Product Liability Directive is relevant where an AI system causes damage falling within the Directive’s scope, including defects in software or self-learning systems. It is less likely to serve as the principal civil-liability route for discriminatory insurance pricing, which will more naturally arise through the AI Act, sectoral insurance supervision, equality law, consumer protection, data protection and national tort regimes. Member states must transpose the Directive by December 2026.
The European Insurance and Occupational Pensions Authority published an Opinion on AI Governance in August 2025, setting out supervisory expectations for national competent authorities.9 The EIOPA Opinion adopts a risk-based and proportionate approach, emphasising that the intensity of supervisory scrutiny should reflect the materiality of the AI system’s impact on policyholders. It does not create directly binding obligations on insurers but signals the direction of supervisory engagement across the single market.
The EU position therefore combines ex ante classification under the AI Act, product liability exposure under the revised Directive and supervisory expectations through EIOPA. The withdrawal of the AI Liability Directive creates a gap in the harmonised civil liability framework that national courts and legislatures may address differently across member states.
The UK Position
The United Kingdom has no AI-specific insurance regulation. The Financial Conduct Authority has relied on existing conduct rules, principally the General Insurance Pricing Practices rules (PS21/5), which require insurers to offer renewal prices no higher than equivalent new business prices, and the Consumer Duty (introduced in July 2023), which imposes a general obligation to deliver good outcomes for retail customers.10
The Consumer Duty is broad enough in principle to capture algorithmic pricing discrimination. If an insurer’s pricing model produces systematically worse outcomes for customers who share a protected characteristic, there is a credible argument that the insurer has failed to deliver the good outcomes the Duty requires. The FCA has acknowledged that bias in algorithmic decision-making is a “live issue” for the insurance sector. The Treasury Committee has called on the FCA to produce specific guidance on AI in financial services by the end of 2026.
The UK approach is reactive rather than prescriptive. The legal tools to challenge algorithmic discrimination in insurance pricing exist within the current framework. What is absent is the specific regulatory guidance that would tell insurers how to test for proxy discrimination, what governance structures to maintain and what disclosures to make to affected consumers. The contrast with the New York DFS Circular Letter is instructive. An insurer operating in New York has a prescribed testing methodology, defined vendor audit obligations and a specific 15-day notice obligation where an applicant cannot be underwritten through an ECDIS/AIS process. An insurer operating in the United Kingdom has a general duty to produce good outcomes and an acknowledgement from the regulator that bias is a live issue. The gap between the two positions is one that regulated firms and their advisers must manage without regulatory guidance.
AI in Healthcare Coverage Decisions
The application of AI to coverage determinations in health insurance raises distinct concerns that go beyond pricing.
In Estate of Lokken v UnitedHealth Group Inc., proceedings before the United States District Court for the District of Minnesota, the plaintiffs alleged that UnitedHealth used an algorithm called nH Predict to deny post-acute care benefits to Medicare Advantage members. The plaintiffs allege that internal data showed the algorithm’s denial recommendations were overturned on appeal at a rate of approximately 90 per cent, and that UnitedHealth continued to use the system despite knowledge of this error rate. UnitedHealth disputes the allegations. The Court ordered discovery in March 2026, permitting the plaintiffs to obtain documents concerning the development, design, creation, approval, implementation, use and oversight of nH Predict, while not requiring production of the data, rules, source code or medical guidelines on which the system was based.11
The case is significant for two reasons. First, it moves the algorithmic accountability inquiry from pricing to coverage, an area where the consequences of an erroneous decision are immediate and potentially irreversible for the policyholder denied treatment. Second, the discovery order opens the development, deployment and oversight of the algorithm to judicial scrutiny in a way that ordinary regulatory examination has not yet achieved. If the litigation proceeds to trial, it is likely to produce the most detailed judicial analysis of an insurer’s AI system to date.
California enacted SB 1120 in 2024, effective from January 2025, requiring health plans and insurers using AI, algorithms or software tools in utilisation review to preserve human clinical decision-making, use patient-specific clinical information and prevent discriminatory application. The statute also requires disclosure of AI use in utilisation-review policies and procedures. It goes beyond transparency: it imposes substantive constraints on how AI may be used in coverage determinations, including a prohibition on denying care based solely on algorithmic output.
Insuring AI
As insurers adopt AI in their own operations, a parallel market is developing to insure the liabilities that AI systems create for their deployers across all sectors.
Armilla AI, in partnership with Chaucer, launched an AI liability insurance product in April 2025. Munich Re markets aiSure, a suite of AI performance insurance products. The Artificial Intelligence Underwriting Company (AIUC) was reported in 2026 to offer up to $50 million of product-liability coverage for AI agent failures, backed by Beazley paper. Testudo, a managing general agent specialising in AI liability, launched in January 2026.12 These new entrants are building products for a risk category that the traditional insurance market has been slow to address.
Standard commercial general liability and professional indemnity policies were not drafted with algorithmic decision-making in mind. Exclusions for technology errors, data processing failures and software performance are common and may operate to deny coverage for losses caused by AI systems. The traditional market response has been twofold. First, absolute AI exclusions are appearing in professional indemnity and technology errors and omissions policies, removing any ambiguity about whether existing wordings respond to AI-related claims. Second, insurers are eliminating “silent AI” exposure by expressly addressing AI in policy wordings, ensuring that coverage is either affirmatively granted and priced or explicitly excluded.
The market is splitting. Specialist providers are writing affirmative AI liability coverage at rates that reflect the novelty and uncertainty of the risk. Traditional insurers are restricting or excluding coverage for the same risk. Organisations that identify the gap and purchase specialist cover will have protection. Those that assume their existing policies respond to AI-related claims may discover at the point of loss that they do not. The timing is acute. Regulatory obligations are increasing, litigation risk is rising and the insurance market that would ordinarily absorb those risks is simultaneously repricing and restricting.
Strategic Outlook
The regulatory framework for AI in insurance is fragmented across jurisdictions, between sectoral and horizontal regulation and between legislative rules and supervisory expectations. That fragmentation creates compliance cost for multinational insurers and uncertainty for consumers whose rights depend on the jurisdiction in which their policy is written.
Three consequences follow.
First, proxy discrimination is likely to be the primary litigation vector for the next several years. The analytical framework is established. Enforcement precedents from housing and lending are accumulating. The data sources that create proxy discrimination risk are becoming more central to insurance pricing models. The absence of an insurance-specific enforcement action to date reflects regulatory caution and the difficulty of demonstrating algorithmic causation, not regulatory acceptance of discriminatory outcomes.
Second, the structural gap between the US and EU approaches is unlikely to close. The EU has opted for ex ante classification and conformity assessment under the AI Act. The US is developing a mixture of state-level legislation, supervisory guidance and enforcement actions through litigation. The UK has adopted neither approach in a meaningful form. Each has limitations. Ex ante classification imposes compliance cost regardless of whether a particular system creates risk. State-level variation creates regulatory arbitrage opportunities. Reliance on existing conduct rules leaves regulated firms without clear standards and exposes them to enforcement actions based on rules that were drafted before the technology they are applied to existed.
Third, the AI liability insurance market is developing faster than the regulatory framework it is responding to. If coverage contraction in the traditional market accelerates, organisations deploying AI in insurance and adjacent sectors may face a period in which meaningful coverage is available only from specialist providers at premium rates that reflect the absence of actuarial data on AI-related losses. The convergence of rising regulatory obligations, increasing litigation risk and tightening insurance coverage creates a compounding exposure that boards and risk committees should be addressing now.
The period between mid-2026 and the end of 2027, when the NAIC examination tool is expected to reach formal adoption and stand-alone Annex III obligations under the EU AI Act begin to apply under the Digital Omnibus timetable, is likely to define the structural terms on which AI in insurance operates for the following decade. The regulatory choices made in that window will determine whether algorithmic underwriting remains a competitive advantage available to insurers with robust governance or becomes a source of systemic liability for those without it.
Notes
1 Texas v Allstate Corp. and Arity International LLC, proceedings commenced January 2025 in the State of Texas. The complaint alleged violations of the Texas Data Privacy and Security Act (TDPSA). A parallel class action survived a motion to dismiss in March 2026.
2 Louis v SafeRent Solutions LLC, class-action settlement 2024, approximately $2.3 million. The plaintiffs alleged that SafeRent’s tenant-screening algorithm disproportionately harmed Black and Hispanic rental applicants using housing vouchers. The Department of Justice filed a statement of interest on the application of the Fair Housing Act to algorithmic screening but was not the claimant.
3 Massachusetts AG v Earnest Operations LLC, settlement July 2025, $2.5 million. The Massachusetts Attorney General’s investigation found that Earnest’s algorithmic student lending model used variables that served as proxies for race.
4 Colorado SB 21-169 (2021); Regulation 10-1-1 amended August 2025 to extend the governance and risk-management framework to private passenger automobile insurers and health benefit plan insurers, with line-specific compliance timing. Colorado SB 26-189, signed May 2026, superseded the earlier SB 24-205 framework and creates broader automated decision-making technology obligations from 1 January 2027.
5 New York Department of Financial Services, Circular Letter No. 7 (2024), on the use of artificial intelligence systems and external consumer data and information sources in insurance underwriting and pricing.
6 National Association of Insurance Commissioners, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, 4 December 2023. A 12-state pilot examination tool commenced March 2026, with formal adoption expected autumn 2026.
7 Regulation (EU) 2024/1689 (the AI Act), Annex III, point 5(c). Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and provides that stand-alone high-risk AI obligations apply from 2 December 2027, while high-risk AI systems embedded in regulated products apply from 2 August 2028. The AI Liability Directive was formally withdrawn in October 2025.
8 Directive 2024/2853 on liability for defective products (revised Product Liability Directive). Member state transposition deadline December 2026. The Directive extends the definition of “product” to include software and AI systems and introduces a concept of self-learning defect extending beyond placing on the market.
9 European Insurance and Occupational Pensions Authority, Opinion on AI Governance, August 2025.
10 FCA, PS21/5, General Insurance Pricing Practices (2021). The Consumer Duty was introduced in July 2023. The FCA has acknowledged algorithmic bias as a “live issue”. The Treasury Committee has called for AI-specific guidance by the end of 2026.
11 Estate of Lokken v UnitedHealth Group Inc. (D. Minn.). The complaint alleged that UnitedHealth’s nH Predict algorithm denied post-acute care to Medicare Advantage members with an approximately 90 per cent error rate on appeal. Discovery was ordered in March 2026.
12 Armilla AI, in partnership with Chaucer, launched an AI liability insurance product in April 2025. Munich Re markets aiSure as an AI performance insurance suite. The Artificial Intelligence Underwriting Company (AIUC) was reported in 2026 to offer up to $50 million of product-liability coverage for AI agent failures, backed by Beazley paper. Testudo, a specialist AI liability MGA, launched in January 2026.


