The EU classed life and health insurance pricing AI as high-risk, US states are adopting governance bulletins, and Colorado wrote bias testing into regulation. The pattern: regulators are not banning algorithmic underwriting — they are making insurers prove it is fair.
Insurance was discriminating by algorithm long before machine learning gave the practice a new name — actuarial tables are, after all, formalised generalisations about groups of people. What has changed is the raw material. When underwriting models can ingest browsing behaviour, purchase histories and thousands of engineered features, the old settlement — price on risk, but never on protected traits — becomes hard to verify from the outside. Regulators in three major jurisdictions have now answered, and their answers rhyme.
The thesis of this piece: the emerging global rulebook for AI in insurance is not prohibition. It is a burden shift. Insurers may use algorithmic underwriting, but they must govern it, document it, and increasingly test it for discriminatory outcomes — with the proof obligation resting on the insurer, not the regulator.
Three jurisdictions, one direction
Europe went first with the broadest instrument. The EU AI Act's Annex III lists, among its high-risk categories, AI systems intended for risk assessment and pricing of natural persons in life and health insurance. High-risk status triggers the Act's full apparatus: risk management systems, data governance, technical documentation, human oversight, and conformity assessment before deployment. Notably, the EU drew a line around life and health — the covers where algorithmic exclusion can lock a person out of financial protection — rather than sweeping in all insurance pricing.
The United States moved through its state-based machinery. In December 2023 the NAIC adopted a model bulletin on insurers' use of AI, since taken up by a growing list of state regulators. It is guidance rather than statute, but its expectations are concrete: a written AI systems programme, governance proportionate to risk, and — significantly for an industry that buys most of its models — documented oversight of third-party vendors whose algorithms the insurer deploys.
Colorado is the sharpest edge. Its SB21-169, signed in 2021, prohibits insurers' use of external consumer data and algorithms that unfairly discriminate on protected characteristics, and its insurance division has been converting the principle into binding regulation — a governance and risk-management regulation covering life, private passenger auto and health underwriting, with an amended version effective October 2025, and a quantitative bias-testing regime for life insurers that has been through public drafts and industry counter-proposals. Colorado matters beyond its borders because it is the working prototype of outcome testing: not "did you intend to discriminate" but "measure whether your model's outputs differ by protected class, and remediate if they do."
Why regulators converged on governance, not bans
A ban was never realistic — pricing is prediction, and prediction is what these models do better than the tools they replaced. But the alternative of doing nothing collided with a genuinely new problem: proxy discrimination. A model barred from using ethnicity can reconstruct it from postcode, purchasing patterns and a hundred correlated signals, without any human intending it. Intent-based anti-discrimination law struggles here, which is why the regulatory centre of gravity moved to process and outcomes: force insurers to know what their models do, keep evidence, and check the results against protected classes.
The question regulators now ask is not whether your model is fair in design, but whether you can demonstrate it is fair in output.
What this means in practice
For insurers and for the platforms that distribute their products, the converging rules point to a short list of durable obligations. Inventory your models — every jurisdiction's regime starts with knowing what is deployed where. Govern your vendors — the NAIC bulletin and the EU Act both make clear that buying a model does not outsource accountability for it. Keep decision trails — adverse decisions increasingly must be explainable to the customer affected, not just to a data scientist. And expect outcome testing to spread — Colorado's quantitative approach is the direction, not an outlier.
Distribution has its own stake in this. Embedded channels pass rich contextual data to insurers for quoting; the cleaner and more auditable that data pipeline, the easier it is for the insurer to satisfy a data-governance review. A distribution layer that logs what was collected, under what consent, and what the customer was shown is quietly doing fairness compliance work for the whole chain.
Honest caveats
The picture is still forming. The EU Act's insurance provisions await sector practice and guidance to settle what compliance concretely looks like; the NAIC bulletin binds nobody until a state adopts it; Colorado's testing rules for lines beyond life insurance remain in progress. Gulf regulators, including Saudi Arabia's Insurance Authority, have not yet issued insurance-specific AI underwriting rules — though national AI governance frameworks exist, and the international direction described here is the obvious template when sector rules arrive. And there is a real open question the rules have not resolved: perfect fairness across every statistical definition is mathematically unattainable, so regulators will eventually have to say which fairness metric counts. Nobody has, yet.
The safe prediction is the structural one. Wherever you operate, algorithmic underwriting is becoming a licensed activity in all but name: permitted, valuable, and contingent on proof. Building the evidence trail now is cheaper than retrofitting it under supervisory deadline.