Categories: The Silent Line
Share:

Welcome to the first issue of The Silent Line, a monthly briefing tracking how artificial intelligence is reshaping insurance regulation, coverage litigation, and market practice on both sides of the Atlantic. Our goal each month is to examine regulatory issues in the U.S. and U.K., the current bad faith exposure picture, and where policy language and market practice stand.

In this issue: Regulatory Radar, a Deep Dive on algorithmic claims denials and bad faith exposure, Docket Watch, Market Signals, The Transatlantic Read, and One to Watch.

REGULATORY RADAR

UNITED STATES — NAIC

NAIC's AI Systems Evaluation Tool enters a 12-state pilot

The NAIC's Big Data and Artificial Intelligence (H) Working Group has moved its AI Systems Evaluation Tool from exposure draft to active pilot phase. Twelve states — California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin — are running the tool from March through September 2026, meeting monthly to test a risk-based examination framework covering AI governance structure, model validation, bias testing, third-party vendor management, and audit-trail adequacy.

The tool builds directly on the 2023 NAIC Model Bulletin's expectations that insurers maintain a written AI program, document model inputs and validation testing, and be able to explain adverse outcomes attributable to AI-assisted decisions. What's new in the pilot is the shift from bulletin-style guidance toward an actual examination protocol: examiners are testing specific document requests and interview questions against real carrier AI governance files. Participation is voluntary for regulators, but the pilot's design will likely become the template non-pilot states borrow from once findings are published this fall.

WHAT THIS MEANS FOR PRODUCERS AND UNDERWRITERS

  • Carriers licensed in any of the 12 pilot states should assume their AI governance documentation could be tested even without a formal exam notice. Accordingly, now would be a good time to review and fine tune written AI policies and model validation records.
  • Third-party vendor and model-provider agreements should be reviewed for audit-trail and explainability provisions before the pilot's fall findings drive broader adoption.

COLORADO

Colorado AI Act repealed, replaced by narrower ADMTA

In May 2026, Colorado repealed its broad Colorado Artificial Intelligence Act before it took effect and replaced it with the Automated Decision-Making Technology Act (ADMTA), effective January 1, 2027 pending the Attorney General's rulemaking. The ADMTA is narrower in scope than its predecessor, reflecting industry pushback on the original Act's broad "high-risk AI system" definition. Importantly, however, insurance is still named among its covered sectors.

Complicating the picture, Colorado's insurance-specific AI regulation (Regulation 10-1-1) is proceeding on its own track, independent of the ADMTA repeal-and-replace. That regulation was amended in 2025 to extend governance and bias-testing requirements beyond life insurance toward private passenger auto and health benefit plans. Carriers licensed in Colorado are therefore navigating two frameworks with different effective dates, different rulemaking timelines, and potentially different substantive requirements. Compliance issues are therefore likely through the transition.

WHAT THIS MEANS FOR UNDERWRITERS AND PRODUCERS

  • Don't assume the ADMTA repeal reduces your Colorado AI compliance burden — Regulation 10-1-1 obligations continue independently and are expanding to new lines.
  • Monitor the AG's forthcoming ADMTA rulemaking as the narrower statutory language leaves substantial detail to be filled in by rule.

CALIFORNIA

AI Transparency Act takes effect

California's AI Transparency Act took effect January 1, 2026, requiring disclosure obligations for covered AI systems. Its scope is broader than insurance, but insurers doing business in California sit within its reach alongside the sector-specific UR/UM software rules already in place under SB 1120, which govern the use of AI and algorithmic tools in utilization review and utilization management functions.
(FEDERAL)

Executive order signals a push toward federal preemption

A December 11, 2025 executive order, "Ensuring a National Policy Framework for Artificial Intelligence," represents the federal government's most aggressive attempt yet to centralize AI governance and potentially preempt state-level regulation. For insurance this creates a genuine tension: NAIC and individual states are actively building out AI-specific regulations at the exact moment the federal government is signaling interest in displacing a state-by-state approach. How (or whether) this order's implementation touches insurance specifically is one of the more consequential open questions for 2027 planning.
(UNITED KINGDOM — FCA / LLOYD'S)

UK financial services moves from pilots to deployment

The FCA's 2026 regulatory outlook describes the UK financial services sector (including the London and Lloyd's markets) as having moved from cautious AI pilots to widespread deployment, prompting regulators to sharpen their supervisory focus. Consistent with the FCA's principles-based approach, expect continued integration of AI governance expectations into the existing Consumer Duty and Senior Managers & Certification Regime (SM&CR) frameworks rather than a standalone AI-specific regime. This represents a materially different regulatory architecture than the U.S.'s emerging model-law/bulletin approach, discussed further in The Transatlantic Read below.

DEEP DIVE: ALGORITHMIC DENIALS AND THE NEW FRONTIER OF BAD FAITH

An emerging trend in coverage litigation has been summarized by some with the colloquialism, "when algorithms deny". The concept is easy to state and harder to litigate cleanly. The question which flows from the concept is as follows: when a carrier uses an AI or algorithmic tool to evaluate, prioritize, or deny a claim, does the automation itself create or heighten bad faith exposure, separate from whatever exposure existed under a manual claims-handling process?

The doctrinal starting point in Texas is unchanged by the presence of AI. Chapter 541 of the Texas Insurance Code prohibits unfair claims settlement practices, and Chapter 542 imposes prompt-payment obligations with statutory penalties for noncompliance. Stowers and its progeny establish the duty owed in third-party contexts, while Menchaca and its extra-contractual damages framework govern first-party bad faith. None of this doctrine was written with AI in mind — which is precisely the interpretive gap now being tested.

Three fact patterns are emerging as the likely proving grounds for this theory. First, denial-rate disparities: plaintiffs' counsel are seeking discovery into whether an algorithmic claims tool produces statistically different denial or reduction rates than manual review of comparable claims — the Colossus litigation history from the 2000s-2010s is the closest analogue, and expect renewed citation to that body of case law as a template for discovery scope and expert methodology. Second, explainability gaps: when an insured challenges a denial and the carrier's own claims file cannot explain why the algorithm produced the result it did, that gap itself becomes evidence in a bad faith case — arguably strengthening the insured's position beyond what a manual denial with a paper trail would present. Third, human-review theater: carriers that route claims through an algorithm and then have an adjuster nominally "review" the output without meaningful independent judgment face argument that the human review step is pretextual, undermining any defense that a person actually exercised the discretion required to negate bad faith.

From a litigation perspective, the practical implication is that AI-driven claims handling doesn't change the elements of a bad faith claim, but it does change the evidentiary landscape, particularly around discovery of model documentation, training data, and validation testing, all of which are now squarely within the scope of what a plaintiff will seek to obtain and what a defending carrier needs to be prepared to produce or protect. This will also present new areas of deposition preparation for witnesses and counsel.

WHAT THIS MEANS FOR UNDERWRITERS AND PRODUCERS

  • Audit whether your claims files can affirmatively document the reasoning behind AI-assisted denials. Failure to adequately explain a denial is quickly becoming a bad faith vulnerability in its own right.
  • Scrutinize "human-in-the-loop" review processes for whether they reflect genuine independent judgment or are effectively rubber-stamping algorithmic output; the latter undermines a key bad faith defense.
  • Anticipate broader discovery demands modeled on Colossus-era requests — model documentation, training data, and validation testing should be treated as discoverable and litigation-ready, not just a compliance file.
  • Prepare accordingly for these new topics to be covered in corporate representative depositions

AUTHORITIES REFERENCED
Tex. Ins. Code §§ 541.051 et seq. (unfair claims settlement practices)
Tex. Ins. Code §§ 542.051 et seq. (prompt payment of claims)
Stowers Furniture Co. v. American Indem. Co., 15 S.W.2d 544 (Tex. Comm'n App. 1929) — duty owed in third-party context
USAA Tex. Lloyds Co. v. Menchaca, 545 S.W.3d 479 (Tex. 2018) — first-party bad faith / extra-contractual damages framework
Note: verify current status and pull additional pending matters before circulation — this list reflects doctrine and background authority, not a comprehensive docket survey.

DOCKET WATCH

Duty-to-defend disputes involving algorithmic decision-making

Several duty-to-defend disputes moving through state and federal courts this year turn on whether allegations involving automated or algorithmic decision-making trigger coverage under existing CGL and E&O forms drafted before insurers contemplated AI-specific exposures. Because the eight-corners rule in Texas looks to the allegations in the petition rather than the underlying facts, plaintiffs' pleading choices about how they characterize an AI system's role in causing harm — as a tool the insured used negligently versus an autonomous actor whose conduct falls outside traditional negligence framing — may end up mattering more than the underlying technology itself.

Colossus-adjacent claims-automation disputes continue

Litigation activity referencing algorithmic claims-evaluation tools continues to surface in coverage disputes, generally following the discovery and expert-methodology patterns established in the Colossus litigation of the 2000s and 2010s. Expect this litigation strategy to be used with increasing frequency as a blueprint even in disputes involving newer generative or agentic AI tools. The underlying discovery questions, i.e., access to the algorithm, its inputs, and its validation are structurally similar regardless of the specific technology.

MARKET SIGNALS

AI exclusions gain traction on commercial liability forms

Carrier interest in AI-specific exclusions is accelerating on two fronts at once. On the general liability side, three ISO exclusions — CG 40 47, CG 40 48, and CG 40 35 — are drawing increased underwriting attention as a way to carve AI-related risk out of standard commercial liability policies, closely mirroring the earlier emergence of silent cyber exclusions after cyber-related losses began surfacing under traditional property and casualty forms.

On the management liability side, Berkley has published its own “Artificial Intelligence Exclusion (Absolute)” (form PC 51380 00 (06-24)), amending its D&O, EPL, and Fiduciary Liability coverage parts. The form is broad by design: it bars coverage not only for claims arising from AI-generated content or a company’s AI products and services, but also for claims arising from inadequate AI governance policies or training, from a company’s own public statements and disclosures about its AI plans, risks, or capabilities, and from regulatory demands to investigate or respond to AI-related risk. It also specifically excludes claims arising from representations made by a chatbot or virtual customer service agent and defines “Artificial Intelligence” broadly enough to reach ordinary automated decision systems, not just generative tools.

Together, the ISO and Berkley forms show carriers hedging AI exposure on both the liability and the management liability side of the ledger, establishing a broader and faster-moving trend than a single-line reading would suggest. As with silent cyber, expect an initial period of inconsistent adoption with some carriers excluding broadly, others experimenting with narrower, use-case-specific carve-outs, before market practice and court rulings converge.

The parallel to silent cyber is worth taking seriously as a predictive framework: silent cyber exposure went from an afterthought to a market-wide underwriting priority within a few underwriting cycles once large losses crystallized the exposure. If AI-related claims volume follows a similar trajectory, the current patchwork of exclusionary language will likely tighten and standardize faster than carriers currently expect.

Consolidation continues around AI-native platforms

Munich Re's 2025 acquisition of Next Insurance — a technology-first commercial P&C insurer built around AI and digitization — remains a bellwether for continued M&A activity at the intersection of traditional carriers and AI-native platforms. Analysts tracking deal volume in this space reported triple-digit growth in both value and volume of AI-related insurance M&A through 2025, a pace worth watching for signs of continuation or cooling through the back half of 2026.

THE TRANSATLANTIC READ

THE TRANSATLANTIC READ | Two Regulatory Philosophies, One Underlying Risk

The U.S. and U.K. are converging on substantively similar concerns — governance, explainability, bias, accountability for automated decisions — through structurally opposite regulatory architectures. NAIC's approach is bulletin-and-model-law driven: states adopt discrete, insurance-specific instruments (the Model Bulletin, state AI Acts, Regulation 10-1-1-style rules) that accumulate into a patchwork requiring line-by-line, state-by-state compliance mapping. The FCA's approach folds AI expectations into pre-existing, principles-based frameworks — Consumer Duty and SM&CR — treating AI governance as an application of duties firms already owe rather than a freestanding new regime. For carriers and syndicates operating across both markets, the practical consequence is that U.S. compliance work product (governance documentation built to satisfy a specific state bulletin) doesn't translate cleanly to U.K. expectations (a demonstrated culture of accountability under Consumer Duty), and vice versa. Firms building AI governance programs for one market should resist the temptation to treat the other market's compliance file as a template rather than a starting point.

ONE TO WATCH

NAIC's third-party data and models workstream is expected to produce a model law later in 2026 — a meaningful step up from the current bulletin-based framework toward binding legislative language states could adopt directly. Given how much of the current AI-in-insurance landscape rests on the non-binding 2023 Model Bulletin, a codified model law would be the single biggest structural shift since regulators started paying attention to this issue. We'll track the exposure draft closely and cover it in depth as soon as language is public.

Sign Up for Updates

Contributors

View Archives

Jump to Page

By using this site, you agree to our updated Privacy Policy and our Terms of Use.