As companies have increasingly leveraged AI tools to streamline their business processes and decision-making, state attorneys general have likewise increasingly taken an interest in how those tools are used and whether they violate the law. One industry of particular interest to state attorneys general is the insurance sector. Whether under emerging data privacy statutes or traditional consumer protection and civil rights laws, attorneys general have signaled over the past year a heightened level of scrutiny of insurance companies regarding their AI use.
New data privacy or AI statutes
Numerous states including Alabama, California, Maryland, Minnesota, and Virginia have recently enacted data privacy laws relating to the insurance industry's use of AI. These statutes, many of which have gone into effect within the last year, often focus on consumer and data protection and regulate the ways in which insurance companies can use automated technology in making "significant decisions," including insurance claim determinations.
Notably, some attorneys general have signaled they do not intend to pursue enforcement activity under these new legal schemes, at least immediately. For example, Colorado Attorney General Philip Weiser has stated that he does not intend to investigate or litigate claims under the
Consumer protection enforcement
Beyond enforcement based on specific data privacy or AI laws, attorneys general have pursued enforcement against insurance companies for their AI use under their home state consumer protection statutes.
Earlier this year, Pennsylvania Attorney General Dave Sunday entered into a settlement with Geico following an investigation alleging
Potential enforcement activity under civil rights laws
Many state attorneys generals have also signaled potential future enforcement of AI use in the insurance space on account that such use could constitute a civil rights violation.
States including Connecticut, New Jersey, and California have released guidance over the past year on how existing laws apply to AI use, many of which specifically cite potentially suspect activities in the insurance space. Across the board, these offices flagged the heightened risk of bias and discrimination in decision making made by AI tools, especially where those decisions proceed without human review. Connecticut's guidance, for example, directly discusses potential liability for insurance companies if their use of AI discriminates against consumers in significant decisions. Similarly, New Jersey affirmed that the state law against discrimination applies to algorithmic decision making, and highlighted the risks from such decision making in health insurance claim decisions. California's guidance also highlights the various existing civil rights laws that may be implicated when using AI tools.
Practical implications
With attorneys general's intensifying focus on the use of AI in the insurance industry, it is critical that insurance companies evaluate their use of AI tools in high-risk decision making broadly, under emerging AI-specific statutes as well as existing consumer protection or civil rights law.
One particular focus of attorneys general in the insurance space will likely be companies' use of AI in underwriting. For example, companies should be cognizant of what criteria they represent to consumers is used in their underwriting and whether their AI tools use criteria above and beyond that. To the extent there is any mismatch between the two, attorneys general may consider enforcement activity under existing consumer protection law.
Similarly, companies should also be continuously assessing whether any underwriting or other decision-making they undertake using an AI tool appears to be impacting or treating a specific group of their insureds differently. If so, attorneys general will be interested in whether those disparities could violate civil rights law and, in particular, what if any human involvement there was in final decision-making.











