Trustible — US Insurance AI Compliance
US Insurance

Insurance AI Compliance

Trustible separately covers Colorado insurance guidance (Reg 10-1-1), NYDFS guidance, and the NAIC Model Bulletin.

What Each Framework Requires

Framework
What It Requires
NAIC Model Bulletin
The national baseline for US insurer AI governance — adopted by state regulators across jurisdictions. Requires written governance programs, board accountability, fairness testing, and vendor oversight.
NYDFS AI Guidance
New York's examination-ready governance expectations, including consumer transparency and senior management accountability for AI systems involving cybersecurity-relevant data.
Colorado Regulation 10-1-1
Annual compliance certification, bias testing requirements, and written governance programs for Colorado-regulated entities.

How Trustible Supports Insurance AI Governance

Compliance
Trustible Capability
Insurance AI Inventory
Pre-populated templates for underwriting, pricing, claims, fraud, and customer service AI capturing insurance-specific governance context.
Sector-Specific Risk Taxonomies
Insights Taxonomies include insurance-specific risks — unfair discrimination, explainability gaps, adverse action obligations.
Vendor Governance
Structured evaluations for third-party AI vendors — insurance scoring models, algorithmic underwriting tools — with AI-assisted documentation analysis.
Multi-Framework Mapping
Insurance framework governance activities map alongside NIST AI RMF, ISO 42001, EU AI Act, and applicable state requirements simultaneously.

US Insurance FAQs

As of mid-2026, 25 states plus the District of Columbia have formally adopted the NAIC Model Bulletin, with several more actively moving through legislative or regulatory approval. California, Colorado, New York, and Texas have taken a different route, operating under their own insurance-specific AI frameworks rather than adopting the Bulletin directly. States that haven't formally adopted it are increasingly applying its principles through market conduct examinations regardless, so the practical reach extends further than the formal adoption count suggests. For a multi-state carrier, most of the country now has some form of AI governance expectation on the books, and building to NAIC standards positions you well ahead of where the remaining states are heading.

No, they're two separate laws with different scope. SB 21-169 (implemented through Regulation 10-1-1) is insurance-specific, governing how insurers use external consumer data, algorithms, and predictive models in regulated decisions like underwriting and pricing. The Colorado AI Act (SB 26-189) is the broader law, extending high-risk AI consumer protections across sectors including employment, education, healthcare, and financial services, not just insurance. An insurer operating in Colorado is likely subject to both: SB 21-169 for insurance-specific obligations and annual certification, and the Colorado AI Act for any high-risk AI use that falls outside insurance-specific activity, like an internal hiring tool. Organizations that have built governance programs for SB 21-169 will find significant overlap with the AI Act's requirements, since both share the same underlying activities of risk assessment, bias testing, and documentation.

See How Trustible Operationalizes Industry AI Compliance in a Unified Governance Program.

© 2026 Trustible