AI Governance

Adoption without control maturity: tracking AI regulation across insurance

Adoption of AI across insurance is near-universal while bias testing and vendor oversight lag. Where enforcement and litigation risk is concentrating, and what closes the gap.

By Jonas Osman AbdelghafourPublished December 11, 2025

Summary A wide-angle survey of artificial intelligence regulation across insurance shows the defining feature of the current period: adoption is near-universal, control maturity is not, and enforcement risk concentrates precisely in that gap.

Source: Fenwick · 11 December 2025 · read the original article

The numbers that define the gap Between 58% and 92% of insurers across sectors report current or planned AI use. The NAIC's 2023 Model Bulletin has been adopted by 23 states plus the District of Columbia. Yet nearly a third of health insurers do not regularly test models for bias, litigation alleging discriminatory AI in claims processing is emerging, and a model law on third-party AI vendors is anticipated.

Read together: the obligation exists in most markets, the deployment exists in most firms, and the testing evidence does not.

Bias testing as an evidentiary requirement Testing for unfair discrimination is not primarily a statistical exercise; it is an evidentiary one. The questions that matter in an examination or a claim are which protected characteristics were considered, what proxy analysis was performed, what disparity threshold triggered action, who reviewed the result, and what changed as a consequence.

A firm that tests but does not retain that chain is in a weaker position than one that tests less often and documents completely. Cadence should be set by decision impact — pricing and claims decisioning at least annually and after any material model change.

Third-party models are the weakest link An anticipated model law on third-party AI vendors reflects a practical reality: much insurance AI is bought rather than built, and the buyer carries the regulatory obligation regardless. Contractual rights are therefore controls. The minimum set is disclosure of intended use and training data characteristics, notification of material model change, access to evaluation results or the ability to test independently, audit and regulator access, and exit terms that survive a supervisory finding.

Methodology and limitations This summarises a law firm survey as at the date shown and links to the original. Adoption ranges are drawn from the cited surveys with differing methodologies and sector definitions, and adoption counts of the model bulletin change as further states act.

Related reading See [Insurance Risk](/expertise/insurance-risk), [Model Risk](/expertise/model-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).

Frequently asked questions

What should risk leaders know about the numbers that define the gap?

Between 58% and 92% of insurers across sectors report current or planned AI use. The NAIC's 2023 Model Bulletin has been adopted by 23 states plus the District of Columbia. Yet nearly a third of health insurers do not regularly test models for bias, litigation alleging discriminatory AI in claims processing is emerging, and a model law on third-party AI vendors is anticipated.

What should risk leaders know about bias testing as an evidentiary requirement?

Testing for unfair discrimination is not primarily a statistical exercise; it is an evidentiary one. The questions that matter in an examination or a claim are which protected characteristics were considered, what proxy analysis was performed, what disparity threshold triggered action, who reviewed the result, and what changed as a consequence.

What should risk leaders know about third-party models are the weakest link?

An anticipated model law on third-party AI vendors reflects a practical reality: much insurance AI is bought rather than built, and the buyer carries the regulatory obligation regardless. Contractual rights are therefore controls. The minimum set is disclosure of intended use and training data characteristics, notification of material model change, access to evaluation results or the ability to test independently, audit and regulator access, and exit terms that survive a supervisory finding.

What should risk leaders know about methodology and limitations?

This summarises a law firm survey as at the date shown and links to the original. Adoption ranges are drawn from the cited surveys with differing methodologies and sector definitions, and adoption counts of the model bulletin change as further states act.

What should risk leaders know about related reading?

See [Insurance Risk](/expertise/insurance-risk), [Model Risk](/expertise/model-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).