State DOI Bulletins You Must Know - NY DFS, Colorado Reg 10-1-1, Connecticut, Nevada
If the NAIC Model Bulletin is the framework, the state DOI bulletins are the rebar. By mid-2026 four state regimes - New York DFS Circular Letter 2024-7 (issued July 11, 2024, effective on issuance), Colorado Reg 10-1-1 (expanded effective October 15, 2025, first compliance report due July 1, 2026), Connecticut MC-25-8, and Nevada Bulletin 24-006 - have set the prescriptive bars the NAIC bulletin only principles. California (CDI), Texas (TDI), and Florida (OIR) are watching from adjacent postures. A carrier writing in any of these states is operating to the higher state bar enterprise-wide, because the operational cost of running two AI programs (one for NY, one for the rest of the book) is higher than running one program at the NY bar across the book. This lesson is the working map of those bulletins - what each one says, what triggers an exam, what the algorithm inventory and bias-testing schedule actually look like in the wild, and what the people on the desk produce in response.
New York DFS Circular Letter 2024-7 - The Proxy Test
NY DFS issued Circular Letter 2024-7 on July 11, 2024, with no delayed implementation - the circular has been operationally effective since its issuance date, and DFS has been examining insurers under existing market-conduct authority since then. The circular's scope is broad: every life, accident, health, and P&C insurer authorized in New York that uses External Consumer Data and Information Sources (ECDIS) or AI Systems in underwriting and pricing. The articulated expectations are governance, fairness, proxy testing, and senior-management reporting - and the document is widely treated as the single most operational state bulletin in 2026 because it names the proxy test by name and provides enough specificity to operationalize.
What the Proxy Test Actually Means Operationally
The proxy test is the centerpiece of Circular Letter 2024-7. The articulation: an insurer using AI or ECDIS in underwriting or pricing must affirmatively test whether the model's outcomes correlate with protected classes (race, color, creed, national origin, status as a victim of domestic violence, past lawful travel, or any other characteristic protected by NY Insurance Law §2606, §4224, or §3221). The test is not optional. The test is not a one-time exercise - DFS expects ongoing testing tied to model updates and a defined cadence. The test must be documented, reproducible, and reviewable by DFS examiners.
Operationally, the proxy test methodology that survives DFS scrutiny in 2026 looks like this. Step one - identify candidate proxy variables in the feature set (ZIP code, education attainment, occupation, vehicle make and model in auto, credit-tier where allowed, prescription-drug history in L&H, MVR signals correlated with geography). Step two - construct race-and-ethnicity proxy attributions using Bayesian Improved Surname Geocoding (BISG) or an equivalent statistically defensible technique. Step three - compute the marginal effect of each candidate proxy on the model output, holding other variables constant (the partial-dependence-plot approach or a Shapley-value decomposition). Step four - compute the disparate-impact ratio of model decisions across the BISG-attributed cohorts. Step five - where the marginal effect or DI ratio exceeds the carrier's threshold, justify the variable as actuarially necessary and non-substitutable under NY Insurance Law §4224, or remove or replace it. Step six - document the methodology in the proxy-test memo and store with the model card. Step seven - refresh quarterly for high-risk models. Step eight - reference the methodology in the SERFF rate-filing exhibit.
NY DFS has been clear in its examiner interactions through 2025–2026 that a carrier responding "we don't use protected-class variables" is not a defense. The whole point of the proxy test is that protected-class outcomes can emerge from facially neutral variables - and the test is what surfaces them. A carrier that has not run the test cannot demonstrate the absence of proxy discrimination, which is itself a §4224 exposure.
What Triggers a DFS Exam
DFS market-conduct exams are triggered by (a) consumer complaints flagged through the DFS complaint database with an AI or ECDIS nexus, (b) data calls during DFS's annual examination planning where the carrier's response signals governance gaps, (c) producer or third-party tip-offs, (d) the carrier's own filed rate increase that DFS chooses to question on fairness grounds, and (e) targeted thematic exams DFS publishes in advance. The 2025 thematic was accelerated UW; the 2026 thematic skews toward pricing AI in auto and homeowners, with cyber UW and L&H accelerated UW as secondary focus.
Colorado Reg 10-1-1 - The Most Prescriptive State Regime
Colorado Reg 10-1-1 - formally titled the Governance and Risk Management Framework Regulation - is the most prescriptive state AI regime in the United States. The regulation began with life insurance under Colorado SB 21-169 (the underlying 2021 statute prohibiting unfair discrimination through ECDIS and AI in life insurance). The Colorado Division of Insurance adopted amended Reg 10-1-1 effective October 15, 2025, expanding the regulation's reach to private passenger auto insurance and health benefit plans. The first compliance reports are due July 1, 2026, with annual compliance reports thereafter.
The ECDIS Inventory and Algorithm Registry
Colorado requires regulated carriers (now: life, private passenger auto, and health benefit plan insurers) to maintain a comprehensive inventory of every External Consumer Data and Information Source they use in underwriting, pricing, claims, or marketing - and every AI system or predictive model that ingests those sources. The ECDIS inventory for a life carrier includes, at minimum: tobacco-flag data sources, prescription-drug-history vendors (Milliman IntelliScript, ExamOne ScriptCheck, LexisNexis MedAdvisor), MIB code data, MVR data, public records (criminal, civil, bankruptcy), behavioral data (web-scraped social-media signals, wearable device data, location/telemetry), credit attributes where allowed, and any other consumer attribute purchased from a third party. For auto carriers, the ECDIS inventory adds telematics data, credit-based insurance scoring inputs (where allowed in CO), MVR, and vehicle attributes. For health benefit plans, the inventory adds clinical attributes ingested under HIPAA.
For each ECDIS, the carrier documents: the source vendor, the data elements ingested, the purpose of use, the data refresh cadence, the consent and notice posture, the contractual sub-processor schedule, the data-quality controls, and any known proxy-class correlation. The algorithm registry then maps each AI model to its ECDIS feeds - so a Munich Re accelerated-UW knockout model gets a registry entry that references the underlying ECDIS sources, and a §4-style examiner can trace a knockout decision through the model back to the data feeds back to the consent posture.
The July 1, 2026 Compliance Report
The first compliance report is due July 1, 2026 - and for many Colorado-writing carriers this is the most consequential single deliverable of the 2026 calendar year. The report's structure follows the regulation: a governance section (describing the AI program structure under the bulletin's §4.1 equivalent), an ECDIS inventory section (the data feeds and their controls), an algorithm registry section (every AI model in scope), a testing-and-validation section (the §4.3 equivalent - quantitative bias testing under Colorado SB 21-169's framework), a documentation section (the §4.4 equivalent), and a consumer-facing transparency narrative.
The quantitative bias testing under SB 21-169 is operationally specific. Carriers run disparate-impact ratio analyses across protected classes (race, color, national origin, age, sex, sexual orientation, gender identity, disability), use BISG-style proxy attribution where direct race data is unavailable, run marginal-effects analyses, and document the actuarial necessity of any variable producing meaningful disparate impact. The Colorado DOI publishes guidance on acceptable methodologies; the methodology must be reproducible and the underlying data must be retainable for examiner review. Carriers that miss the July 1 deadline or file an incomplete report face market-conduct exam exposure and potential cease-and-desist authority.
What Triggers a Colorado DOI Exam
Triggers include (a) a non-filing or late filing of the annual compliance report, (b) a complaint flagged through the Colorado DOI's complaint database with an AI nexus, (c) an audit selection from the DOI's annual examination plan (Colorado has been signaling AI as a thematic focus through 2025–2026), (d) a SERFF rate filing that includes AI-model output and triggers actuarial-staff questions, and (e) industry-wide thematic exams the DOI announces in advance. The Colorado Division of Insurance is one of the most resourced state DOIs on the AI front, and 2026 enforcement activity is expected to rise materially after the July 1 first-report deadline.
Connecticut Insurance Department Bulletin MC-25-8
Connecticut issued MC-25-8 in 2025 - a market-conduct bulletin that operationalizes the NAIC Model Bulletin framework for Connecticut-licensed insurers. The Connecticut bulletin follows the four-pillar NAIC structure (governance, third-party AI, testing, documentation) and adds Connecticut-specific transparency and complaint-handling expectations. Connecticut is one of the 12 pilot states for the NAIC AI Systems Evaluation Tool, so carriers writing in CT are likely to receive coordinated Exhibit A/B/C/D requests through the pilot in addition to Connecticut's own examination activity.
The operational differences between Connecticut and Colorado are useful to know. Colorado's framework is prescriptive and report-driven (the annual compliance report). Connecticut's framework is bulletin-style - expectations are articulated, but the examination is the enforcement mechanism rather than a periodic filed report. Carriers operating in both states often produce the Colorado compliance report as the artifact and treat the Connecticut MC-25-8 expectations as ongoing examination readiness.
Nevada Insurance Division Bulletin 24-006
Nevada issued Bulletin 24-006 in 2024 - pre-dating the NAIC Model Bulletin's adoption but operationally aligned. The Nevada bulletin imposes governance, fairness, and documentation expectations on insurers using AI in underwriting, pricing, claims, and marketing, with a Nevada-specific emphasis on consumer-facing transparency for adverse decisions. Nevada is not a 12-state pilot state, but its bulletin posture is consistent with NAIC framework expectations and Nevada examiners are tracking the pilot for adoption signals.
California - CDI Emerging Posture
The California Department of Insurance has not published a single comprehensive AI bulletin equivalent to NY DFS 2024-7 or Colorado Reg 10-1-1, but California is a 12-state pilot state and is operationally one of the most active AI examination jurisdictions through 2025–2026. California Insurance Code prohibits unfair discrimination on protected classes (Cal. Ins. Code §679.71 and related), and CDI has been applying the existing statutory framework to AI through targeted exams and the Bulletin 2022-5 anti-discrimination framework. California-specific overlays include (a) the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) data-rights obligations for personal information in AI training and operation, (b) the credit-based insurance scoring ban for personal auto in California (Proposition 103 framework), and (c) the gender-pricing prohibition for auto rates under the 2018 SB 1245 reforms. A carrier writing in California operates to California's existing statutory framework plus the NAIC pilot - and California's contribution to the pilot is itself a strong signal of forthcoming formal CDI guidance.
Texas - TDI Posture
Texas Department of Insurance has not issued a comprehensive AI bulletin and is not a 12-state pilot state, but TDI operates under Texas Insurance Code §544 (unfair discrimination) and §541 (unfair claims-settlement practices). Texas's posture in 2026 is observational - TDI is monitoring the NAIC pilot and California/Colorado/NY enforcement trajectories. A carrier writing primarily in Texas can operate to NAIC bulletin §4 expectations as a working baseline, but Texas adjuster license-board posture (Texas adjusters licensed under Tex. Ins. Code §4101) is increasingly focused on AI-use disclosure in claims handling - meaning the adjuster on the desk has license-board exposure for "AI did it" claim positions even where the carrier has no specific AI regulation. Lesson 6 of this chapter walks through the adjuster license-board posture in detail.
Florida - OIR Posture and FSLSO Surplus Lines Interface
Florida Office of Insurance Regulation (OIR) is a 12-state pilot state and is engaged in the NAIC AI Systems Evaluation Tool work. Florida has not issued a standalone comprehensive AI bulletin equivalent to NY DFS 2024-7, but Florida Statutes Chapter 626 (Insurance Field Representatives), Chapter 627 (Insurance Rates and Contracts), and Chapter 624 (Insurance Code) provide the regulatory authority for AI-related actions. Florida has been particularly active on the cat-modeling AI front given the state's hurricane exposure and the post-2023 reform environment. The Florida Surplus Lines Service Office (FSLSO) and the surplus-lines stamping process intersect with AI-driven submission triage and AI-generated diligent-effort declination affidavits - meaning a producer using AI to clear a surplus-lines submission in Florida needs the AI involvement to be documented in the stamping-office filing packet.
The Algorithm Inventory and Bias-Testing Schedule in the Wild
The operational artifact that carries the weight across NY DFS, Colorado, Connecticut, Nevada, California's existing framework, and the NAIC pilot is the algorithm inventory plus the testing schedule. A practical 2026 inventory at a mid-size carrier writing in three or more of these states looks like a registry tool entry per model with: model name, vendor or in-house build, version number, internal owner, function (UW, claims, pricing, fraud, distribution, customer service), line of business, deployment scope (which states), risk tier (low/medium/high), last-tested date, last bias-test result (the disparate-impact ratio across protected classes plus the marginal-effects narrative), drift status (PSI trailing 30 or 90 days, KS, AUC), Colorado Reg 10-1-1 compliance-report inclusion flag, NY DFS proxy-test memo storage location, NAIC Exhibit A scope flag, BAA chain status if HIPAA-eligible, FCRA adverse-action workflow link if consumer-report data is involved, and decommission criteria.
The testing schedule is calendar-driven. High-risk models (UW knockout, pricing GLMs, fraud SIU referral, accelerated-UW life knockout, claims-denial AI) get quarterly bias tests, monthly drift checks, semiannual calibration reviews. Medium-risk models (triage scoring, photo damage assessment, document IDP) get semiannual bias tests, monthly drift checks. Low-risk models (administrative IDP, customer-comms summarization) get annual reviews. Missed-deadline events on the schedule are themselves §4.3 exposures and Reg 10-1-1 compliance failures.
What the People on the Desk Produce
For the underwriter writing in NY, the proxy-test memo on each high-risk pricing variable is part of the rate-filing package. For the underwriter writing in Colorado, the algorithm-inventory entry for every Akur8 or Earnix model is reviewed quarterly and included in the July 1 compliance report. For the adjuster, the AI involvement in any adverse claim decision (denial, ROR, SIU referral, reserve impact) is documented in the file note with the model name, version, prompt log location if generative, and the human-reviewable reason code that does not reduce to the AI's score. For the producer, any AI-generated client communication is reviewed under the agency's written supervisory procedure before send, and any AI-driven adverse decision touching the consumer (such as a Coalition cyber decline) triggers the FCRA pre-notice and adverse-action letter where consumer-report data is involved. For the actuary, the SERFF rate-filing memo cites the bias-test methodology by name (BISG attribution, disparate-impact ratio calculation, marginal-effects analysis) and references the NAIC §4, NY DFS proxy test, and Colorado SB 21-169 frameworks explicitly.
Why Running to the Highest State Bar Is the Strategic Choice
A carrier writing in 30+ states could theoretically operate three or four parallel AI programs - a NY program, a Colorado program, a Connecticut program, and a baseline program for the rest. In practice, this is operationally impossible at scale, and most carriers in 2026 have decided to run the highest state bar across the book. The reason is not just cost: it is risk asymmetry. The downside of underrun (operating a baseline program in NY) is a §4224 violation, a DFS enforcement action, market-conduct exam findings, potential restitution to affected consumers, and reputational damage. The downside of overrun (running NY's proxy test for an Iowa-only book) is incremental compliance cost that scales sub-linearly with each additional state. The asymmetry favors running to the top.
The strategic posture in 2026 is therefore: build the enterprise AI program to the highest state bar (Colorado Reg 10-1-1's prescriptive framework plus NY DFS proxy test plus NAIC bulletin §4 pillars), produce the Colorado compliance report as the working annual artifact, produce the NY proxy-test memo per high-risk pricing variable, respond to the NAIC pilot through the lead-state framework, and treat Connecticut, Nevada, California, Texas, and Florida as additional examination readiness rather than additional program builds. The carrier's enterprise GRC tool unifies the inventory; the testing schedule unifies the cadence; the policy stack unifies the governance posture.
Key Takeaways
- NY DFS Circular Letter 2024-7 (July 11, 2024; effective on issuance) is the single most operational state bulletin in 2026. The proxy test - identify candidate proxies, BISG attribution, marginal effects, disparate-impact ratio, justify or remove - is the de facto national §4.3 testing methodology, and is referenced in SERFF filings, model cards, and Exhibit C responses across states.
- Colorado Reg 10-1-1 expanded to private-passenger auto and health benefit plans effective October 15, 2025. First annual compliance report due July 1, 2026; ECDIS inventory plus algorithm registry plus quantitative bias testing under SB 21-169. Colorado is the most prescriptive state regime in the country.
- Connecticut MC-25-8 operationalizes NAIC framework for CT-licensed insurers. Connecticut is a 12-state pilot state - carriers receive coordinated Exhibit A/B/C/D requests through the NAIC pilot plus CT-specific examination activity.
- Nevada Bulletin 24-006 (2024) pre-dates the NAIC bulletin but is operationally aligned. Nevada-specific transparency for consumer-facing adverse decisions; consistent with NAIC framework expectations.
- California is a 12-state pilot state without a single comprehensive AI bulletin. CDI applies Cal. Ins. Code §679.71, Bulletin 2022-5, the credit-based insurance scoring ban for personal auto (Proposition 103), the gender-pricing prohibition (SB 1245), CCPA/CPRA data-rights, and pilot participation as the enforcement framework.
- Texas and Florida are not pilot states (Florida is - correction: Florida is) but operate under existing unfair-discrimination authority. Florida is a pilot state with strong cat-modeling AI focus and FSLSO surplus-lines interface implications. Texas TDI is observational, but Texas adjuster license-board posture under Tex. Ins. Code §4101 is increasingly focused on AI-use disclosure in claims.
- The algorithm inventory and the testing schedule are the two artifacts that carry the cross-state load. Mid-size carriers in 2026 maintain one enterprise inventory in a GRC tool with model name, version, owner, risk tier, last-tested date, bias-test result, drift status, deployment-scope flags by state, and Reg 10-1-1 / NY DFS / NAIC Exhibit references.
- The strategic choice is to build to the highest state bar enterprise-wide. The downside asymmetry favors overrun (incremental compliance cost) over underrun (regulatory exposure plus reputational damage). Most carriers in 2026 operate to a unified program at the Colorado plus NY DFS bar across the entire book.
Skill.re