Every Regulator Is Drafting the Same AI Letter · Insurance Just Got Theirs First

Insurance already got its AI governance letter from regulators. Every other regulated sector gets one next; here is the program built to absorb them all.
AI Regulations

 

The Letter That Wasn’t About Insurance

Your general counsel forwards you an article during a board meeting, phone angled so you can read it under the table. It is about an insurance carrier, a market conduct exam, and a paragraph regulators have started inserting into their document requests: proof of a written program governing the company’s use of artificial intelligence, a named owner, evidence that someone actually oversees the third-party models embedded in underwriting and claims. Your CFO leans over. “Glad that’s not us.”

It is a reasonable reaction. You are not an insurer. The National Association of Insurance Commissioners does not regulate your industry, and the Model Bulletin it adopted in December 2023, now sitting on the books in close to half the states, has no jurisdiction over whatever you actually do. We have written before about what that bulletin asks of a mid-market carrier: a written program, named accountability, oversight of vendor models, and a testing cadence with dates on it. If you read that piece and felt the particular relief of a problem that belongs to someone else, you read it correctly. It is not your regulator.

But watch what the paragraph is actually made of, not which agency wrote it. A written program. A named owner. Oversight of the AI you did not build yourself. Documentation on a cadence. None of that is insurance-specific. It is a template, and templates get reused. The question this piece answers is not whether your sector will get its own version of that paragraph. It already has, or it is drafting one right now. The question is whether you will be the company that already has the answer taped to the wall when it arrives, or the one searching a shared drive for a policy that does not exist.

The question is whether you will be the company that already has the answer taped to the wall when it arrives, or the one searching a shared drive for a policy that does not exist.

 

The Second Letter Already Arrived

It did not take long. While insurance regulators were still refining market conduct exam questions around the NAIC bulletin, a different set of regulators, in a different set of statehouses, were writing healthcare’s version from scratch. Not as a single federal rule with one effective date, which would at least be easy to track, but as the same kind of rolling, state-by-state accumulation that built the insurance bulletin’s reach: quieter, faster, and arriving on a dozen different clocks at once.

Maine now requires patient consent before a provider uses ambient listening or other AI-powered recording tools in a clinical encounter, a plain acknowledgment that the exam room conversation is being captured by something other than a note-taker. Arizona has written informed-consent documentation into its behavioral health regulations specifically for AI-assisted services, the sector where a misfire carries the least room for error. On the payer and utilization-review side, the language converges almost word for word across states that never coordinated with each other: Washington bars AI from being the sole basis for a medical necessity denial; Colorado requires that any AI-assisted denial undergo review by a qualified professional and that the underlying models pass regular accuracy audits; Utah mandates public disclosure of AI use in adverse determinations; Iowa allows AI to flag a prior authorization request but not to be the sole basis for denying, delaying, or downgrading it. Effective dates run from the middle of this year into 2028, which means the accumulation is not finished. It is a wave still arriving, one legislative session at a time.

Notice what did not happen. No single healthcare AI law passed Congress. No one regulator sat down and wrote healthcare’s version of the NAIC bulletin in one document. Dozens of statehouses independently arrived at nearly the same four requirements insurance regulators had already settled on: disclose the AI, keep a human genuinely in the decision, document the oversight, and do not let a vendor’s model function as an accountability shield. Different regulators, different sectors, the same underlying shape. That is not a coincidence. It is a pattern learning to repeat itself.

It is not stopping at two industries, either. A third wave is already moving through statehouses this year, aimed at a category that has nothing to do with insurance or healthcare underwriting: AI chatbots and companion tools. Tennessee now prohibits an AI system from misrepresenting itself as a licensed mental health professional. Oregon requires clear disclosure that a user is talking to AI, mandates detection protocols for suicidal ideation, and adds heightened protections when the user is a minor. Idaho and Nebraska have written nearly identical disclosure and crisis-protocol requirements, arriving at them independently the same way Colorado and Washington converged on nearly identical language for AI-assisted coverage denials. Three sectors, three separate sets of regulators, three overlapping years of legislative sessions, and the same underlying move each time: name the harm, require disclosure, insert a human or a documented safeguard at the point where the harm would occur. If you were waiting for a fourth data point before taking the pattern seriously, that is three more than most companies bother to collect.

 

The Pattern Underneath the Patchwork

Regulators read each other’s work. A bulletin that survives its first legal challenges and its first two years of exam cycles without producing a public disaster becomes a template other regulators borrow from, tailor to their sector’s vocabulary, and adopt. That is exactly what happened between insurance and healthcare, and there is no structural reason it stops there. Financial services examiners, utility commissions, education regulators, and state bar ethics committees are all reading the same trade publications your general counsel reads. The specific trigger differs by sector. The response, once a regulator decides to act, does not.

We have written elsewhere about why some sectors feel this pressure before others: the cost of being wrong is not evenly distributed, and sectors where an AI error is expensive, hard to reverse, or slow to surface attract regulatory attention faster than sectors where a bad output just gets corrected on the next refresh. Insurance underwriting and healthcare decisions sit near the expensive, hard-to-reverse end of that spectrum, which is why they went first. It does not mean sectors further down the curve are exempt. It means they are earlier in the sequence, not outside it. The governor on adoption speed is real; it is not a permanent shield.

Regulators do not coordinate with each other, and they are converging on the same four requirements anyway.

Regulators do not coordinate with each other, and they are converging on the same four requirements anyway.

Strip the sector-specific vocabulary out of both waves and you are left with the same four asks, twice. A written program, proportionate to how you actually use the technology. Named accountability, not a values statement in the employee handbook. Oversight of third-party and vendor models, because the AI making the decision that matters was very likely bought, not built. And testing and documentation on a cadence, with dates on it, not a binder assembled the week the exam letter or the compliance audit arrives. Three regulators, three industries, zero coordination between any of them, and they converged on the same architecture independently. That convergence is the actual news here, more than any single bulletin.

 

Why Chasing Each Letter Individually Fails

The natural response to a new compliance requirement is to build a response to that requirement. A policy document for the insurance bulletin, if you are an insurer. A consent workflow for the ambient listening rule, if you are a hospital. A denial-review process for the utilization management law, if you are a payer. Each response gets built under deadline pressure, scoped narrowly to the letter of that specific law, and filed away until the next exam or the next legislative session produces the next letter.

This works, in the narrow sense that it satisfies the specific request in front of you. It fails in every sense that matters over a three-year horizon. Each one-off response duplicates work the last one already did: identifying which systems use AI, deciding who is accountable, negotiating audit rights with vendors, setting a testing cadence. None of that infrastructure carries forward, because it was built to answer one letter rather than to answer the next one too. You end up maintaining as many separate, thin governance efforts as you have regulators who have gotten around to writing to you, each one built just well enough to pass its own exam and no better.

The freeway principle applies here as directly as it applies anywhere: properly designed guardrails enable speed, and a roadblock rebuilt from scratch at every exit slows you down at every single one. A governance program built once, broadly enough to answer “who is accountable, what is documented, how do we oversee vendors, what is the testing cadence” regardless of which regulator is asking, absorbs a new state law as a data point rather than a fire drill. The insurance carriers and health systems that treated their first letter as an opportunity to build real infrastructure, rather than the minimum viable response, are the ones who will read their sector’s next law as a checklist rather than a crisis.

 

What Building It Once Actually Looks Like

None of this requires a compliance department you do not have the headcount for. It requires four artifacts, built once and maintained on a cadence, that answer any regulator’s version of the same paragraph. First, an inventory: every AI system in active use across the company, including the ones bought inside a vendor platform rather than built in-house, because that is where most of the exposure actually lives. Second, a name. One person, even if the role is fractional or virtual rather than a full-time hire, formally accountable for the program, with the authority to answer for it in an exam or a board meeting. Third, a vendor oversight protocol: contract language that preserves audit and information access rights, and a due-diligence step before any new AI-enabled tool goes into production, so you are not discovering your exposure to a vendor’s model for the first time when a regulator asks about it. Fourth, a testing and documentation rhythm, calendared rather than improvised, so the record a regulator or a board member asks for already exists instead of needing to be assembled under deadline.

Treat these four artifacts as infrastructure, revisited quarterly, not as a project that gets marked complete and shelved. A program built this way does not need to be rewritten when your sector’s letter arrives. It needs a light adaptation: mapping the existing inventory, owner, and vendor protocol onto the specific disclosure language a new state law happens to use. That is a week of work instead of a quarter, and it is the difference between a company that treats each new law as evidence its existing program works and a company that treats each one as proof it needs to start over.

Picture the difference concretely, using illustrative numbers. A mid-market company that builds its first governance response only after a law names it might spend six to eight weeks assembling the inventory, naming an owner, and drafting vendor language under deadline pressure, then repeat something close to that timeline for every subsequent law that touches a different part of the business. A company that built the four artifacts once, ahead of any specific mandate, spends that same six to eight weeks a single time; every law after that is a mapping exercise measured in days, not a build measured in weeks. The total hours converge eventually, law by law, but the company with the freeway already built is never the one an examiner catches flat-footed, and it is never the one whose board is hearing about the gap for the first time from outside counsel.

 

The Question to Bring to Your Next Board Meeting

The relief your CFO felt reading about the insurance bulletin was not wrong; it was early. Somewhere between the statehouse and the exam letter, your sector’s version of that paragraph is being drafted by regulators who have already watched three other industries absorb it and will borrow freely from all of them. The company that has an answer ready is not the one that guessed correctly which regulator would move first. It is the one that stopped waiting to find out and built the program before the letter named it.

The company that has an answer ready is not the one that guessed correctly which regulator would move first. It is the one that stopped waiting to find out and built the program before the letter named it.

Bring one question into your next board meeting, before anyone asks it for you: if a regulator sent your sector’s version of this letter next quarter, could you produce the inventory, the named owner, the vendor oversight record, and the testing documentation today, or would someone need to start searching a shared drive that does not have what the letter is asking for? The honest answer is worth knowing now, while it is still a planning exercise and not an exam response.

More from our blog

Every Regulator Is Drafting the Same AI Letter · Insurance Just Got Theirs First

Every Regulator Is Drafting the Same AI Letter · Insurance Just Got Theirs First

Insurance already got its AI governance letter from regulators. Every other regulated sector gets one next; here is the program…
The 2026 AI Dividend Map · 25 Industries, 4 Shapes

The 2026 AI Dividend Map · 25 Industries, 4 Shapes

This is the first edition of a map we will publish every year. It takes the four shapes of the…
Technology Can’t Transform the Business Alone

Technology Can’t Transform the Business Alone

Why complex technology initiatives require leadership, not just project management by Jose Solera, CIO Consultant   In many organizations, technology…