Regulators · United States
The United States Framework.
Insurance is regulated state by state. There is no federal insurance regulator, and the closest thing to a national rulebook is a set of models that states adopt in varying forms.
The United States also has the most developed body of insurance-specific supervision of artificial intelligence anywhere in the world.
Structure
Who Actually Regulates
State Departments And Divisions of Insurance
Each state, plus the District of Columbia and the territories, licenses insurers and supervises their market conduct through its own insurance department, led by a commissioner, superintendent or director. Market conduct examinations are the principal supervisory tool for claims handling.
National Association of Insurance Commissioners
A standard-setting and coordinating body of the state regulators. It is not itself a regulator and cannot bind anyone. Its model laws, regulations and bulletins become binding only when a state adopts them, often with amendments.
Federal Insurance Office, US Department of the Treasury
Monitors the insurance sector and advises on federal policy and international insurance matters. It does not license or supervise insurers.
New York State Department of Financial Services
One of several large-state regulators that sets its own direction. DFS issued Circular Letter No. 7 (2024) on the use of artificial intelligence systems and external consumer data in insurance underwriting and pricing, setting expectations on governance, fairness testing and accountability.
Instruments
The Rules That Bear On Claims And On Suppliers
- Unfair Claims Settlement Practices. Adopted from the NAIC model in varying forms by the states, these statutes set standards for the timeliness and fairness of claims handling and are the backbone of market conduct examination in this area.
- NAIC Insurance Data Security Model Law. Widely adopted, it requires an information security programme, incident response planning, notification, and oversight of third-party service providers. Supplier obligations flow through by contract.
- NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 2023. It sets expectations for a written AI systems programme, board and senior management accountability, testing for unfair discrimination, documentation, and oversight of third-party AI vendors and the data they supply. Alaska was the first state to adopt, on 1 February 2024; 24 states had adopted by August 2025. (Adoption tracking as reported by Quarles & Brady and by Locke Lord's InsureReinsure, 2025.)
- Colorado Senate Bill 21-169. Requires insurers to test their use of external consumer data and information sources, algorithms and predictive models for unfair discrimination. The Colorado Division of Insurance has implemented it line of business by line of business, beginning with life insurance.
- Gramm-Leach-Bliley Act. Continues to apply to financial institutions including insurers, with its own privacy and safeguards expectations.
- State comprehensive privacy statutes. Apply in parallel, with varying definitions, thresholds and consumer rights.
What this means for a supplier. The insurer's AI governance obligations extend to its vendors and to the data those vendors supply. A supplier that cannot support a customer's AI systems programme with documentation, logging and testing support becomes a compliance problem for that customer. Kempron's position is here.
On Accuracy. These pages name real bodies and real instruments. They are summaries for orientation, not legal advice, and not a substitute for the instruments themselves. Regulators and supervised firms who find an error here are invited to write to info@kempron.io; it will be corrected.
Jurisdictions that could not be sourced to this standard are not listed.