Resources

AI Regulation by Jurisdiction

AI regulation varies dramatically by jurisdiction. Know the rules before you deploy.

Showing 15 jurisdictions

North America Pending Last updated: February 2026

United States (Federal)

Legislation

  • No comprehensive federal AI legislation yet
  • Executive Order 14110 on Safe AI (October 2023)
  • FTC enforcement actions on AI deception and discrimination

Regulatory Guidance

  • NAIC Model Bulletin on AI (December 2023) — most significant insurance-specific guidance
  • NAIC Big Data & AI Working Group — ongoing model law development
  • Federal Insurance Office monitoring AI in insurance

Industry Standards

  • NIST AI Risk Management Framework (AI RMF 1.0)
  • ACORD data standards for AI interoperability
  • III guidelines on AI adoption for insurers

Notable Cases

  • State DOI enforcement actions on algorithmic discrimination
  • FTC settlements over AI-powered insurance marketing claims
North America Enacted Last updated: February 2026

Colorado

Legislation

  • SB 21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices (2021)
  • First comprehensive U.S. state law addressing algorithmic bias in insurance
  • Requires testing for unfair discrimination in AI-based insurance decisions

Regulatory Guidance

  • Colorado Division of Insurance AI governance framework requirements
  • Mandatory impact assessments for AI/ML models in underwriting and pricing
  • Annual reporting on algorithmic testing results

Industry Standards

  • Colorado-specific compliance frameworks emerging
  • Industry working groups on SB 21-169 implementation

Notable Cases

  • First state enforcement actions under SB 21-169 expected 2026
  • Industry pushback on testing methodology requirements
North America Enacted Last updated: February 2026

New York

Legislation

  • Circular Letter 2019-1: Use of External Consumer Data in Underwriting
  • NYC Local Law 144: Automated Employment Decision Tools (indirect insurance impact)
  • Proposed AI Bill of Rights implications for insurance

Regulatory Guidance

  • NYDFS guidance on AI in insurance underwriting and pricing
  • Cybersecurity regulation (23 NYCRR 500) applies to AI systems
  • Market conduct examination focus on algorithmic fairness

Industry Standards

  • NY-specific fair lending and pricing standards
  • Insurance industry compliance frameworks for NYDFS expectations

Notable Cases

  • NYDFS enforcement actions on discriminatory pricing algorithms
  • Market conduct findings related to AI-driven underwriting
North America Pending Last updated: February 2026

California

Legislation

  • CCPA/CPRA applies to AI data processing in insurance
  • Multiple AI bills proposed in state legislature
  • Insurance Code provisions on unfair practices extend to AI

Regulatory Guidance

  • CDI attention to algorithmic bias in insurance pricing
  • California Privacy Protection Agency considering AI-specific rules
  • Proposition 103 rate-making constraints apply to AI models

Industry Standards

  • California-specific privacy compliance for AI tools
  • Industry advocacy groups developing best practices

Notable Cases

  • Rate filing challenges involving AI-based pricing models
  • Privacy enforcement actions relevant to insurance AI
North America Pending Last updated: February 2026

Canada

Legislation

  • Artificial Intelligence and Data Act (AIDA) — proposed as part of Bill C-27
  • PIPEDA and provincial privacy laws apply to AI in insurance
  • Quebec's Law 25 strengthens data privacy for AI systems

Regulatory Guidance

  • OSFI guidance on model risk management for insurers
  • Provincial insurance regulators monitoring AI adoption
  • Canadian Centre for Cyber Security AI guidelines

Industry Standards

  • Insurance Bureau of Canada AI adoption guidance
  • CPA Canada guidelines on AI governance

Notable Cases

  • Privacy Commissioner investigations into AI-based insurance decisions
  • Growing regulatory scrutiny of telematics data usage
Europe Enacted Last updated: February 2026

European Union

Legislation

  • EU AI Act (Regulation 2024/1689) — comprehensive risk-based AI regulation
  • Insurance AI classified as high-risk in multiple categories
  • GDPR continues to apply to AI data processing in insurance

Regulatory Guidance

  • EIOPA guidelines on AI governance for insurers
  • European Insurance and Occupational Pensions Authority oversight
  • National competent authorities implementing EU AI Act

Industry Standards

  • Insurance Europe AI principles
  • CRO Forum on AI risk management
  • AMICE guidance for mutual insurers

Notable Cases

  • First EU AI Act enforcement proceedings expected 2026-2027
  • GDPR enforcement actions on automated insurance decisions
Europe Pending Last updated: February 2026

United Kingdom

Legislation

  • No dedicated AI legislation — pro-innovation approach
  • Data Protection Act 2018 / UK GDPR applies to AI
  • Financial Services and Markets Act 2023 — AI oversight authority for FCA/PRA

Regulatory Guidance

  • FCA guidance on AI in financial services including insurance
  • PRA supervisory expectations on AI model risk
  • Lloyd's Market AI governance standards

Industry Standards

  • ABI (Association of British Insurers) AI principles
  • Lloyd's Lab innovation standards
  • UK Finance/insurance cross-sector AI working groups

Notable Cases

  • FCA enforcement related to algorithmic trading (precedent for insurance)
  • ICO investigations into AI-powered insurance profiling
Europe Enacted Last updated: February 2026

Germany

Legislation

  • EU AI Act applies directly
  • BaFin regulatory framework for AI in financial services
  • Sector-specific regulation through existing insurance law (VAG)

Regulatory Guidance

  • BaFin Big Data/AI principles for financial sector
  • GDV (German Insurance Association) AI guidance
  • Federal data protection authority AI oversight

Industry Standards

  • GDV code of conduct for AI in insurance
  • German actuarial standards for AI models

Notable Cases

  • BaFin enforcement on AI-driven credit scoring (precedent for insurance)
  • GDPR enforcement on automated insurance decisions
Latin America Pending Last updated: February 2026

Brazil

Legislation

  • AI Regulatory Framework (PL 2338/2023) — pending Senate approval
  • LGPD (data protection) applies to AI in insurance
  • SUSEP (Insurance Superintendency) monitoring AI adoption

Regulatory Guidance

  • SUSEP Sandbox for insurtech innovation
  • Central Bank AI governance principles (cross-sector)
  • National AI Strategy emphasizes responsible adoption

Industry Standards

  • CNseg (Insurance Confederation) AI working group
  • FenSeg (Federation of Insurers) digital transformation guidelines

Notable Cases

  • LGPD enforcement actions on automated insurance decisions
  • SUSEP sandbox projects involving AI underwriting
Latin America Proposed Last updated: February 2026

Mexico

Legislation

  • Multiple AI bills proposed in Congress
  • Federal Law on Data Protection applies to AI
  • CNSF (Insurance Commission) monitoring AI adoption

Regulatory Guidance

  • CNSF regulatory sandbox for insurtech
  • Limited formal AI guidance for insurance sector
  • Digital transformation strategy for financial services

Industry Standards

  • AMIS (Mexican Insurance Association) technology initiatives
  • Limited formal industry AI standards

Notable Cases

  • Early-stage regulatory discussions on AI in insurance
  • Insurtech licensing developments
Asia-Pacific Enacted Last updated: February 2026

China

Legislation

  • Interim Measures for Management of Generative AI (2023)
  • Algorithm Recommendation Regulations (2022)
  • CBIRC regulations on technology risk in insurance

Regulatory Guidance

  • CBIRC (banking/insurance regulator) AI governance requirements
  • Mandatory algorithm filing and disclosure
  • AI ethics guidelines for financial services

Industry Standards

  • Insurance Association of China AI standards
  • InsurTech standardization working groups

Notable Cases

  • Regulatory enforcement on algorithmic insurance pricing
  • Ping An AI governance as industry benchmark
Asia-Pacific Proposed Last updated: February 2026

Japan

Legislation

  • AI Guidelines for Business (2024)
  • No dedicated AI law — agile governance approach
  • Insurance Business Act applies to AI-driven decisions

Regulatory Guidance

  • FSA (Financial Services Agency) AI guidance for insurers
  • JFSA supervisory expectations on AI model risk
  • Ministry of Economy AI governance framework

Industry Standards

  • GIAJ (General Insurance Association) AI principles
  • LIAJ (Life Insurance Association) technology guidelines

Notable Cases

  • FSA supervisory actions on AI in insurance pricing
  • AI governance sandbox initiatives
Asia-Pacific Enacted Last updated: February 2026

Singapore

Legislation

  • Model AI Governance Framework (2019, updated 2024)
  • AI Verify testing framework for trustworthy AI
  • PDPA applies to AI data processing in insurance

Regulatory Guidance

  • MAS (Monetary Authority) FEAT principles for AI in financial services
  • MAS guidelines on fair dealing with AI in insurance
  • Technology risk management guidelines for insurers

Industry Standards

  • GIA (General Insurance Association) digital transformation standards
  • LIA (Life Insurance Association) AI adoption guidelines
  • Singapore Actuarial Society AI working group

Notable Cases

  • MAS regulatory sandbox AI projects in insurance
  • AI governance certification pilots
Asia-Pacific Proposed Last updated: February 2026

Australia

Legislation

  • Proposed mandatory guardrails for high-risk AI (2024)
  • Privacy Act reform with AI implications for insurance
  • Insurance Contracts Act applies to AI-driven decisions

Regulatory Guidance

  • APRA guidance on AI model risk for insurers
  • ASIC enforcement focus on AI in financial services
  • OAIC AI and privacy guidance

Industry Standards

  • Insurance Council of Australia AI principles
  • Actuaries Institute AI working group standards

Notable Cases

  • ASIC enforcement on automated financial advice (precedent for insurance)
  • Privacy investigations into AI-based risk scoring
Asia-Pacific No Specific Regulation Last updated: February 2026

India

Legislation

  • No dedicated AI legislation
  • Digital Personal Data Protection Act (2023) — AI implications
  • Insurance Act amendments being considered for AI

Regulatory Guidance

  • IRDAI (Insurance Regulatory Authority) monitoring AI adoption
  • IRDAI sandbox for insurtech innovation
  • National AI Strategy (NITI Aayog) — cross-sector

Industry Standards

  • GIC (General Insurance Council) technology guidelines
  • LIC modernization initiatives

Notable Cases

  • IRDAI sandbox projects involving AI underwriting
  • Growing insurtech ecosystem driving regulatory attention

How to Use This Guide

This guide provides an overview of AI regulation relevant to insurance. It is not legal advice. Always consult qualified legal counsel for jurisdiction-specific compliance questions.

Need Deeper Guidance?

Understanding regulations is just the first step. Our Learning Program includes compliance-focused modules for insurance professionals.

Ready for structured learning? Explore the Learning Program →