16.2 NAIC AIS, NYC AEDT, CA/CO ADMT, Colorado Insurance

Key Takeaways

  • The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted 4 December 2023) is the BoK-named AIS governance guideline: a written AIS Program covering governance, risk management, and documentation; it is not a model statute and binds an insurer only after a state insurance department adopts it
  • NYC Local Law 144 bars employers and employment agencies from using an automated employment decision tool unless an independent bias audit was completed within the prior year, a summary of results is publicly posted, and required notices go to candidates or employees
  • CPPA ADMT regulations were approved 22 September 2025 and became effective 1 January 2026; businesses that use automated decisionmaking technology to make significant decisions must comply with the ADMT article beginning 1 January 2027 — do not collapse those two dates
  • The Colorado Privacy Act gives consumers a right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects; that is a general consumer-privacy right, not an insurance-examination rule
  • Colorado Division of Insurance 3 CCR 702-10 / Regulation 10-1-1, issued under SB 21-169, is a separate unfair-discrimination governance regime for life insurers that use external consumer data, algorithms, and predictive models
Last updated: August 2026

NAIC Artificial Intelligence Systems Model Bulletin

Body of Knowledge 2.6.1 names the National Association of Insurance Commissioners (NAIC) Artificial Intelligence Systems (AIS) materials as the insurance-governance guideline candidates must be able to place. On 4 December 2023, NAIC membership adopted the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. Official NAIC page: https://content.naic.org/insurance-topics/artificial-intelligence. Official adopted bulletin: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf.

The bulletin is not a model law and is not self-executing. It becomes an examination expectation when a state insurance department issues it (or a substantively similar bulletin) to its domestic and licensed insurers. It reminds insurers that decisions or actions made or supported by AI must still comply with unfair-trade-practice laws and every other applicable insurance statute. It then tells insurers to develop, implement, and maintain a written AIS Program commensurate with the risk, aligned with the NAIC’s 2020 Principles of Artificial Intelligence (fair and ethical, accountable, compliant, transparent, and secure / safe / robust).

A written AIS Program is the artifact the exam is hunting. It documents governance (board or senior-management accountability and a cross-discipline structure that includes business units, actuarial, data science, underwriting, claims, legal, and compliance), risk management (inventory of AIS in use, including vendor systems used on the insurer’s behalf), development and acquisition controls, testing for inaccuracy and unfair bias, documentation, and the records a department may request in an investigation or financial examination. Third-party models do not leave the program. If a vendor’s credit or marketing score supports an underwriting or claims decision, the insurer still owns the outcome.

Scenario. A Midwestern life insurer buys a third-party “longevity propensity” score trained on credit-header, shopping, and social-media features. The NAIC bulletin, in a state that has adopted it, does not ask whether the marketing deck said “AI.” It asks whether the AIS Program inventoried that score, assigned an owner, tested it for unfair discrimination, and documented the result for the next examination. A privacy notice that mentions “automated processing” is not an AIS Program.

NYC Local Law 144: AEDT Bias Audits

New York City Local Law 144 of 2021 is the municipal hiring-tool statute. Official Department of Consumer and Worker Protection (DCWP) page: https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page. Enforcement of the law and its rules began 5 July 2023. It is unlawful for an employer or employment agency to use an automated employment decision tool (AEDT) in New York City unless three conditions are met.

First, the tool must have been subject to a bias audit by an independent auditor no more than one year before the use. The rules define an AEDT as computational process derived from machine learning, statistical modeling, data analytics, or artificial intelligence that issues a simplified output (score, classification, recommendation) and that is used to substantially assist or replace discretionary decision-making to screen candidates for employment or employees for promotion. Second, the employer or agency must make a summary of the most recent bias-audit results publicly available on its website before using the tool. Third, it must give required notices to candidates or employees: that an AEDT will be used, the job qualifications and characteristics the tool will assess, and (if available) information about the data collected and its source — in time for the person to request an alternative process. DCWP’s rules treat at least 10 business days before use as the notice window.

DCWP enforces. Civil penalties run not more than $500 for a first violation and not more than $1,500 for each subsequent violation, and each day a violation continues is a separate violation. Local Law 144 is not a general New York AI code, not a substitute for Title VII or the New York City Human Rights Law, and not a California ADMT regulation. It is a city hiring-audit and notice ordinance.

Scenario. A bank uses a résumé-ranking model as a required first screen for every New York City analyst posting. No independent bias audit has been completed in the last year, and candidates learn about the model only when a rejection email arrives. Local Law 144 is already failed on the audit, the published summary, and the advance notice — before anyone reaches a disparate-impact analysis under federal employment law.

California CPPA ADMT Regulations: Two Dates, Not One

The California Privacy Protection Agency (CPPA) automated decisionmaking technology (ADMT) regulations sit inside the broader CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT, and Insurance package. Official rulemaking page: https://cppa.ca.gov/regulations/ccpa_updates.html. The Office of Administrative Law approved the package on 22 September 2025. The regulations are effective 1 January 2026. That effective date is not the date every business must already be running a full ADMT compliance program for significant decisions.

The Agency’s 23 September 2025 announcement is the sentence to memorize: https://cppa.ca.gov/announcements/2025/20250923.html. Businesses that use ADMT to make significant decisions must comply with the ADMT requirements beginning 1 January 2027. Pre-2027 ADMT use for a significant decision must be brought into compliance by that date; ADMT first used after 1 January 2027 must comply before it is implemented. Do not collapse “regulations effective” with “businesses must fully comply.”

The ADMT article is a notice, opt-out, and access regime for significant decisions — decisions that result in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or health-care services. By the 2027 compliance date, a covered business generally must give a pre-use notice at or before the point of collection that states the specific purpose, how the ADMT makes the significant decision, and what happens if the consumer opts out; honor the right to opt out of that ADMT use, subject to limited exceptions; and respond to access (and appeal) requests about how the ADMT works. Risk-assessment and cybersecurity-audit clocks in the same package are different: risk-assessment work is prospective as of 1 January 2026, with first submissions due 1 April 2028; cybersecurity-audit certifications stagger 2028–2030 by revenue. Those clocks belong in Chapter 14’s assessment discussion. This section’s trap is treating 1 January 2026 as the day every hiring or lending model in California must already display an ADMT opt-out.

Colorado: CPA Profiling Versus Insurance ECDIS

Colorado has two AI-adjacent regimes. Mixing them is an easy miss.

The Colorado Privacy Act (CPA) is a comprehensive consumer-privacy statute. It gives a consumer the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer — provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services. Colorado’s implementing rules (4 CCR 904-3) then tier the processing. Consumers may opt out of solely automated profiling and human-reviewed automated profiling in furtherance of those decisions. Human-involved automated processing — where a human meaningfully considers and can change the output — is treated differently. The CPA right is a controller-facing consumer right, enforced as part of the comprehensive statute, not a Division of Insurance market-conduct exam.

The insurance rule is Senate Bill 21-169, Protecting Consumers from Unfair Discrimination in Insurance Practices, implemented for life insurers in 3 CCR 702-10, Regulation 10-1-1. Official Division of Insurance materials live on the Colorado Department of Regulatory Agencies site (https://doi.colorado.gov/). The regulation requires a life insurer that uses external consumer data and information sources (ECDIS), or algorithms and predictive models that use ECDIS, to maintain a governance and risk-management framework designed to detect and control unfair discrimination. The insurer must inventory the ECDIS and models, document testing for unfair discrimination, assign senior-management accountability, and be prepared to produce that file to the Division. Later amendments expanded the same family of rules beyond the original life-only core; the exam still treats 3 CCR 702-10 / life-insurer ECDIS governance as the named prototype. Unfair-discrimination testing is not a consumer click-to-opt-out. A life applicant does not “CPA-opt-out” of a mortality model the way a shopper opts out of profiling. The Division examines whether the model produces unfairly discriminatory outcomes and whether the governance file exists.

RegimeWhat it isWho it bindsSignature dutyWhen / who enforces
NAIC AIS Model Bulletin (4 Dec 2023)Principles-based insurance guidanceInsurers in states that adopt the bulletinWritten AIS Program: governance, risk, testing, vendor modelsState insurance department examinations
NYC Local Law 144City hiring ordinanceEmployers / agencies using an AEDT on NYC candidates or employeesAnnual independent bias audit, published summary, advance noticeDCWP; up to $500 / $1,500 per day
CPPA ADMT regulationsCCPA article on automated significant decisionsCCPA businesses using ADMT for significant decisionsPre-use notice, opt-out, ADMT accessCPPA / California AG; article effective 1 Jan 2026, significant-decision compliance 1 Jan 2027
Colorado CPA profilingComprehensive-privacy consumer rightCPA controllersOpt out of profiling for legal / similarly significant effectsColorado AG / CPA rules
3 CCR 702-10 (SB 21-169)Insurance unfair-discrimination regulationLife insurers using ECDIS / modelsGovernance framework and testing for unfair discriminationColorado Division of Insurance

Scenario. A Colorado life insurer uses a third-party spending-pattern score in underwriting and uses a website chatbot that ranks incoming term-life leads. The score is an ECDIS/model problem under 3 CCR 702-10: inventory, test, document, produce to the Division. The chatbot that decides whether a consumer is offered a live agent is closer to CPA profiling if it produces a similarly significant effect and is solely automated or only human-reviewed. One company, two statutes, two files. A single “we follow the NAIC bulletin” binder does not answer either question unless the department has adopted the bulletin and the binder actually covers that model.

Exam traps

  • The NAIC AIS bulletin is guidance a department adopts. It is not a federal AI statute and not a private right of action.
  • Local Law 144 is an annual independent audit plus publication and notice, not a California ADMT opt-out and not Title VII.
  • 1 January 2026 is when the CPPA ADMT regulations became effective. 1 January 2027 is when businesses using ADMT for significant decisions must comply with that article.
  • Colorado CPA profiling and 3 CCR 702-10 are not interchangeable. One is a consumer opt-out; the other is insurance-unfair-discrimination governance.
Loading diagram...
Insurance AIS, NYC AEDT, California ADMT, and Colorado Split
Test Your Knowledge

A New York City employer uses a machine-learning résumé screener as a required first cut for every open role. Which Local Law 144 package must be in place before that automated employment decision tool is used?

A
B
C
D
Test Your Knowledge

On a 2026 CIPP/US item, a national lender uses automated decisionmaking technology to approve or deny California auto-loan applications. The CPPA ADMT regulations are already on the books. Which dating statement is correct?

A
B
C
D
Test Your Knowledge

A Colorado life insurer uses an external consumer spending score inside a predictive underwriting model. Separately, its website uses solely automated profiling to decide whether a visitor is offered a live agent for a term-life quote. Which statement correctly distinguishes the two Colorado regimes?

A
B
C
D