#ai#insurance#insurtech#underwriting#claims processing#risk management

AI in Insurance Underwriting and Claims: Pricing Math, Regulation, and Risks

How AI changes insurance pricing and claims, with a worked telematics example, the NAIC bulletin, NY DFS Circular Letter 7, Colorado rules, and EU AI Act dates.

๐Ÿ“… January 9, 2026โœ๏ธ Updated: September 27, 2026โฑ 7 min readโœ Web3 Listicle Editorial Team

Insurance and underwriting professionals reviewing AI-driven risk modeling dashboards and automated claims triage metrics.

Insurance has always been a prediction business. Actuaries estimate how often claims will happen (frequency) and how much they will cost (severity), and the premium follows. What AI changes is how finely that prediction can be made and how quickly claims can be handled. It also changes who can be treated unfairly, which is why regulators have moved faster on insurance AI than on almost any other industry.

This guide covers the pricing math, where AI is used in underwriting and claims, and the rules that now apply in the US and EU.

How better prediction changes a premium

A simplified auto example, with illustrative numbers.

Before telematics. A rating class has a claim frequency of 0.05 claims per driver per year and an average severity of $8,000. The pure premium (expected claim cost) is 0.05 ร— $8,000 = $400. If expenses take 25% of premium and the target profit margin is 5%, the charged premium is $400 รท (1 โˆ’ 0.25 โˆ’ 0.05) = about $571.

With telematics. Driving data splits the same class into two groups of equal size. Careful drivers have a frequency of 0.035; the rest have 0.065. The average is still 0.05.

Group Frequency Pure premium Charged premium
Careful drivers 0.035 $280 $400
Other drivers 0.065 $520 $743
Whole class (unchanged) 0.05 $400 $571

Total premium collected across the class is the same. What changes is who pays it. And this is where competition bites: if a rival insurer offers the careful drivers $400 and you keep charging everyone $571, the careful drivers leave. You are left with the riskier half at a price that does not cover their $520 expected cost. That is adverse selection, and it is why better risk prediction spreads through insurance markets once one large player adopts it.

Usage-based insurance can also change behavior. Drivers who know braking and phone use are measured tend to drive more carefully, which lowers actual claims.

Where AI is used in underwriting

  • Property. Aerial and satellite imagery analyzed by computer vision to assess roof condition, overhanging vegetation, pools, and wildfire defensible space, often replacing a physical inspection for renewals.
  • Auto. Telematics from apps or devices; driving-behavior scores feeding usage-based pricing.
  • Life. Accelerated underwriting using prescription histories, medical claims data, and lab databases to skip medical exams for many applicants.
  • Commercial. Extracting information from submissions, loss runs, and inspection reports so underwriters spend time on judgment rather than data entry. Language models are well suited to this.

Operational dashboard displaying real-time vehicle telematics, drone property scans, and AI risk scores.

Where AI is used in claims

  • First notice of loss and triage. Classifying claims by complexity, coverage questions, and fraud risk, and routing them accordingly.
  • Damage estimation. Photo-based estimates for auto and some property claims.
  • Fast-track payment. Simple, low-value, low-risk claims paid quickly, often the most visible customer benefit.
  • Fraud detection. Network analysis linking claimants, repair shops, medical providers, and addresses; checks for reused or edited photos. Our AI fraud detection guide covers the modeling.
  • Subrogation. Identifying claims where another party is liable and recovery is possible.

The asymmetry matters. Using AI to approve and pay claims faster carries little legal risk. Using it to deny or reduce claims carries a lot. Lawsuits filed against several US health insurers since 2023, including cases against UnitedHealth and Cigna, allege that algorithms were used to deny care or cut coverage without adequate individual review. Those allegations are contested, but they show where regulators and courts will look first. Keep a qualified person responsible for every adverse claim decision, with the model as input, not as the decision.

The regulation that now applies

United States

Insurance is regulated by the states, and they have moved on AI:

  • NAIC Model Bulletin on the Use of AI Systems by Insurers (December 2023). Adopted by 24 states and the District of Columbia as of the NAIC's April 2026 implementation map; California, Colorado, New York, and Texas regulate insurer AI under their own frameworks. It expects a written AI systems program covering governance, risk management, internal controls, testing for unfair discrimination, and oversight of third-party data and model vendors. Regulators can ask for it during market conduct exams.
  • New York DFS Circular Letter No. 7 (July 11, 2024). Insurers using AI systems or external consumer data in underwriting or pricing must be able to show the data is not a proxy for protected classes and does not produce unfair discrimination, using quantitative testing, and must keep documentation and governance to back it up.
  • Colorado SB21-169. Restricts insurers' use of external consumer data and algorithms that unfairly discriminate. The Division of Insurance's Regulation 10-1-1 requires a governance and risk management framework; it took effect in November 2023 for life insurers and was amended effective October 15, 2025 to add private passenger auto and health benefit plan insurers. A separate quantitative testing rule for life underwriting, which would have insurers estimate race from name and geography (the BIFSG method), was still a draft in the reports available as of mid-2026, so check the Division's site for its current status.

European Union

Annex III of the AI Act lists AI used for risk assessment and pricing of individuals in life and health insurance as high-risk. After the Digital Omnibus adopted in 2026, those obligations (risk management, data governance, logging, human oversight, documentation) apply from 2 December 2027. Property and casualty pricing is outside that category, although GDPR still applies to any personal data used.

Proxy discrimination: why dropping variables is not enough

Removing race, religion, or national origin from a model does not stop it from discriminating. Other variables can stand in for them: ZIP code, certain credit attributes, even some purchasing data. A model can learn the proxy on its own.

Regulators now expect outcome testing:

  1. Estimate the protected characteristic for the tested population where it is not collected (Colorado's draft life-insurance testing rule uses a statistical method based on name and geography).
  2. Compare outcomes, such as approval rates and premium levels, across groups.
  3. Where disparities appear, test whether specific variables drive them and whether they have a sound actuarial justification.
  4. Document the analysis and the decision.

This needs to happen before a new variable or model goes live, and again periodically.

Vendors are your responsibility

Much insurance AI comes from vendors: imagery scores, fraud scores, prescription-history scores, claims estimating tools. The NAIC bulletin and NY DFS both make clear that the insurer stays responsible. Contracts should give you enough documentation, testing results, and audit rights to answer a regulator's questions about a vendor model as if you had built it. The SaaS vendor management guide covers contract terms.

Getting started

  1. Inventory every model and external data source used in underwriting, pricing, claims, and fraud, including vendor tools.
  2. Write the AI program the NAIC bulletin describes, even if your state has not adopted it; exam questions will follow it.
  3. Start with low-risk, high-volume uses: submission intake, claims triage, fast-track payment.
  4. Test for unfair discrimination before launching any new pricing variable or model.
  5. Keep people accountable for adverse decisions on applications and claims.

For governance structures that work across the business, see AI governance frameworks. For the business side of cyber coverage specifically, see cybersecurity insurance.


This guide is for informational purposes only and is not legal or actuarial advice. Insurance regulation varies by state and country; consult qualified advisors.

Frequently Asked Questions

To estimate claim frequency and severity more precisely from more data: telematics for auto, aerial and satellite imagery for property roofs and vegetation, prescription and lab data for life insurance, and text from applications and inspection reports. The models feed rating plans that regulators still review, and underwriters handle exceptions.
The NAIC's [Model Bulletin on the Use of AI Systems by Insurers](https://content.naic.org/insurance-topics/artificial-intelligence), adopted in December 2023 and since adopted by [24 states and the District of Columbia](https://techsavvyinsurance.com/answers/which-states-adopted-naic-ai-model-bulletin/) as of the NAIC's April 2026 implementation map, expects a written AI program with governance, risk controls, and oversight of third-party vendors. New York's [DFS Circular Letter No. 7](https://www.dfs.ny.gov/industry-guidance/circular-letters/cl2024-07) (July 2024) expects insurers using AI or external data in underwriting and pricing to show it does not cause unfair discrimination. Colorado's SB21-169 governance regulation applies to life, private passenger auto, and health benefit plan insurers.
AI used for risk assessment and pricing of individuals in life and health insurance is [listed as high-risk in Annex III](https://artificialintelligenceact.eu/annex/3/). After the 2026 Digital Omnibus, those obligations [apply from 2 December 2027](https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/). Property and casualty pricing is not in that category.
When a rating variable that looks neutral, such as a ZIP code or certain consumer data, stands in for a protected characteristic like race. Removing protected attributes from the model does not prevent it. Regulators increasingly expect insurers to test outcomes across groups, sometimes using statistical methods to estimate race where it is not collected.
Automating claim denials is where the legal risk is highest. US lawsuits filed since 2023 allege that health insurers used algorithms to deny claims or cut coverage without adequate individual review; the allegations are contested. The safer pattern is to use AI to fast-track approvals and flag claims for review, with a qualified person deciding any denial.