
Nobody signed up for this, exactly. There was no announcement, no single policy change you could point to and say “that’s when it happened.” Instead, the way insurance works quietly rewired itself over about five years, one integration at a time — a credit score folded into a pricing formula, a claims model rolled out in a back office, a telematics app offered at renewal because it made the quote a little cheaper. Each change was small enough to wave through. Add them up, though, and you get something that deserves to be called what it is: an algorithmic insurance economy, where software — not an underwriter, not a claims adjuster — is usually the thing deciding what you pay and whether you get paid.
That’s not a hypothetical for 2030. It’s already how the industry runs. McKinsey’s research on AI in insurance describes carriers moving well past pilot projects into what it calls domain-level rewiring — underwriting, claims, and distribution redesigned around AI rather than AI bolted onto the old process. The upside of that shift is genuinely large: faster quotes, claims settled in hours instead of weeks, fraud caught before it drains the risk pool. The part that gets less airtime is what happens to the person on the other end of the algorithm when it gets something wrong, and how little recourse they usually have.
The Quote You Get Isn’t Really About You Anymore — It’s About People Like You
Ask most people what determines their car insurance premium and they’ll say something like driving record, age, the car itself. All true, but incomplete. Modern underwriting models weigh hundreds of variables simultaneously — some directly about you, many that are proxies for you: your ZIP code, your credit tier, your education level, sometimes the device you used to request the quote. None of that shows up on the declarations page. You just see a number.
The trouble is that proxy variables have a habit of reconstructing exactly the discrimination insurers aren’t supposed to price on. The Consumer Federation of America has documented for years that drivers in predominantly Black ZIP codes are quoted significantly higher auto premiums than similarly situated drivers elsewhere, even after controlling for driving record and population density — a gap the industry has never been able to fully explain through risk alone. When a model is trained on decades of pricing data shaped by redlining and unequal access to credit, it doesn’t need to “know” a customer’s race to reproduce racial disparity. It just needs a few correlated inputs, and it has plenty. Regulators have started treating that as exactly the compliance problem it is. Colorado moved first: under SB 21-169, the state’s Division of Insurance now requires carriers to inventory every algorithm and external data source touching a pricing decision, test it for discriminatory outcomes, and file annual attestations confirming they’ve done so. It’s the first law in the country to put teeth behind the idea that a model’s outputs matter more than its intentions.
What Happens When the Algorithm Says No
Pricing bias is the slow-motion version of this problem. Claims denial is the acute one. When an AI system rejects a claim, the consumer usually gets a letter with a code, not an explanation — and the appeal process, where one exists, was rarely designed with algorithmic decision-making in mind. This is where the regulatory response has moved fastest, because the harm is immediate and easy to point to. California’s SB 1120 is the clearest example: it bars health insurers from denying a claim based solely on an AI-generated determination, requiring a licensed clinician to be involved in any adverse decision. New York took a governance-first approach instead. The state’s Department of Financial Services issued Circular Letter No. 7 (2024), which doesn’t ban algorithmic underwriting but requires insurers to prove — through documented adverse-effects testing — that any AI system or external data source they use isn’t producing disproportionate outcomes for protected classes. It’s guidance rather than a new statute, but DFS can and does examine insurers against it using its existing market conduct authority. At the national level, the National Association of Insurance Commissioners has been tracking adoption for years through its AI/ML surveys, and the most recent health insurance results are worth sitting with: the overwhelming majority of health insurers now use AI in some capacity, yet close to a third still don’t regularly test their own models for bias. That gap — high adoption, inconsistent oversight — is precisely what state examiners are now being trained to look for, and it’s precisely what’s showing up in litigation. Several federal lawsuits against major health insurers, alleging claims denials generated at scale with minimal individualized review, have already cleared motions to dismiss, which means discovery: insurers being compelled to open up the model architecture and training data that produced the denials in question.
The Data Feeding All of This Didn’t Come From a Form You Filled Out
None of this pricing and claims machinery runs on what you disclosed in an application. It runs on continuous data collection that mostly happens without a moment you’d recognize as consent. Your car’s telematics system tracks braking, speed, and time of day; that data can move from the manufacturer to a broker and on to an insurer well before you’ve thought about switching carriers, a pipeline we mapped in detail in our piece on telematics privacy risks. The checkout-page insurance products that have exploded across travel, gig work, and e-commerce apps run on a similar logic — convenient, contextual coverage that also happens to be a fresh data collection layer, which we unpack in our guide to embedded insurance. The deeper question underneath all of it — who actually owns the information determining your premium, and whether you have any say in how it moves between companies — is one we went after directly in The Data Rights Economy. Short version: in most U.S. states, the answer is that you have far less control over that data than you’d assume.
Europe Drew a Bright Line. The U.S. Drew a Patchwork.
The regulatory contrast between jurisdictions in 2026 is genuinely stark. The EU AI Act’s Annex III explicitly classifies AI systems used for risk assessment and pricing in life and health insurance as high-risk, which triggers a substantial compliance burden — documented human oversight, bias testing, and a fundamental rights impact assessment — with full obligations applying from August 2026. There’s no ambiguity about whether it applies; the text names insurance directly. In the U.S., there is no federal equivalent. What exists instead is a state-by-state patchwork: Colorado’s testing mandate, New York’s governance letter, California’s clinician-review rule for health claims, and dozens of states that have adopted the NAIC’s principles-based model bulletin with no binding testing requirement attached. If you’re a consumer, your practical protection against algorithmic unfairness currently depends heavily on your ZIP code — which, given everything above, is a genuinely uncomfortable irony. For anyone trying to understand how these systems reach the decisions they do — and why “the algorithm said so” isn’t actually an explanation — our earlier deep dive into AI bias in insurance walks through the mechanics in more detail, and our look at how AI Overviews are changing what consumers can even find out about their coverage rounds out the picture of where visibility is being lost.
Frequently Asked Questions
Is AI making insurance more fair, or more discriminatory?
Both, depending on where you sit. AI has extended coverage to populations traditional distribution never reached and made claims dramatically faster. It has also been shown to reproduce pricing discrimination through proxy variables like ZIP code and credit score — well documented by the Consumer Federation of America and now regulated directly under laws like Colorado’s SB 21-169.
What are my rights if an AI denies my insurance claim?
In most states you can request a written explanation and appeal to a human reviewer. California’s SB 1120 bars health insurers from denying a claim based solely on an algorithm. New York’s DFS Circular Letter 2024-7 requires insurers to prove their AI systems don’t produce disproportionate outcomes for protected classes. In the EU, the AI Act’s high-risk classification gives consumers a right to explanation for consequential automated decisions.
How does AI actually set my insurance premium?
Models weigh a large set of variables simultaneously — driving or claims history, credit tier, ZIP code, property data, and increasingly telematics or device signals — to generate a price without a person reviewing the individual case. Most of those inputs are never shown to the customer.
Is insurance regulation keeping pace with AI adoption?
Unevenly. The EU AI Act, applying to insurance underwriting AI from August 2026, is currently the most comprehensive framework. The U.S. has no federal equivalent — protection depends on which state you’re in, with Colorado, New York, and California furthest ahead and many states still relying on non-binding NAIC guidance.
The Bottom Line
The algorithmic insurance economy isn’t coming — it’s the operating reality for hundreds of millions of policyholders right now, priced, approved, and sometimes denied by systems that are faster and more opaque than anything the industry has run before. That’s not automatically bad news. The efficiency gains are real, the fraud detection genuinely works, and embedded products are reaching people traditional distribution never bothered with. But the accountability gap is just as real, the bias data is well-documented rather than speculative, and protection still depends heavily on which state or country you happen to live in.
Speed and fairness are not the same design goal, and 2026 is the year the industry can no longer treat them as interchangeable. Getting this right will take informed consumers who ask for the reason behind a denial, regulators willing to actually test the models rather than just requesting a governance memo, and — for what it’s worth — publishers willing to sit with how complicated this actually is instead of flattening it into either blind enthusiasm or blanket alarm.




