AI Governance in Insurance

States Continue Enacting Laws Restricting AI in Health Insurance Coverage and Utilization Review Decisions

By Arnold D. Lee · August 18, 2026

The legislative campaign to rein in artificial intelligence in health insurance coverage decisions, which began in earnest in California in 2024 and Texas in 2025, shows no sign of slowing. Between March and July 2026, at least seven states enacted new statutes governing how health insurers, pharmacy benefit managers, and utilization review organizations may use AI when deciding whether to authorize or pay for medical care, while several other bills stalled or were defeated. For health insurers, third-party administrators, and the AI vendors that build the utilization-review and claims-adjudication tools those companies rely on, the result is not a single national standard but an expanding, state-by-state patchwork, each statute with its own effective date, disclosure obligations, and definition of impermissible reliance on AI. Understanding that patchwork has become a compliance necessity for anyone doing business in the health insurance market across multiple states.

Why Legislatures Are Acting

The legislative wave did not emerge in the abstract. It tracks a well-publicized controversy over predictive algorithms in Medicare Advantage utilization review. In November 2023, the estates of two deceased Medicare Advantage enrollees sued UnitedHealth Group and its subsidiary NaviHealth in federal court in Minnesota, alleging that the companies used a proprietary algorithm, nH Predict, to estimate a fixed length of post-acute care and then pressured claims staff to terminate coverage once a patient’s stay approached that estimate, regardless of the treating physician’s assessment of medical necessity.1 The complaint drew on investigative reporting alleging that the algorithm’s projected lengths of stay carried an extremely high reversal rate on appeal, and that internal pressure to hold length-of-stay outcomes within a narrow band of the algorithm’s prediction effectively substituted a statistical model for individualized clinical judgment.2 UnitedHealth has maintained that nH Predict is a planning tool rather than a coverage-determination engine, and that its actual coverage decisions are governed by members’ plan terms and CMS criteria; the litigation remains ongoing. Whatever its ultimate outcome, the case crystallized the precise risk that this round of state legislation targets: an algorithm trained on population-level data authorizing or denying an individual patient’s care without a licensed clinician meaningfully reviewing whether that patient’s specific circumstances fit the model’s assumptions.

A Sparse Federal Backdrop

Congress has not enacted comprehensive legislation governing AI in health insurance, and pending bills remain limited to directing further study rather than imposing substantive restrictions. The one significant federal guardrail comes from the Centers for Medicare & Medicaid Services, which clarified in a February 2024 guidance memorandum that Medicare Advantage organizations may use AI and other algorithms to assist in coverage determinations, but only if the algorithm’s output is based on the specific beneficiary’s medical history, the treating physician’s recommendations, and the beneficiary’s individual clinical circumstances, rather than on a larger dataset that does not account for that individual’s situation, and only in a manner consistent with the plan’s existing, publicly posted coverage criteria.3 That guidance applies only to Medicare Advantage plans, however, and even there it takes the form of sub-regulatory guidance rather than a statute or formal rule specific to AI. States have stepped into that gap, and because their statutes generally reach commercial, Medicaid managed care, and in some cases Medicare Advantage business alike, they are now the primary source of enforceable, AI-specific restrictions on coverage decisions nationally.

Two Early Movers: California and Texas

California moved first. Senate Bill 1120, enacted in 2024 and effective January 1, 2025, prohibits health care service plans and disability insurers regulated under the state’s Health and Safety Code and Insurance Code from denying, delaying, or modifying requested health care services based, in whole or in part, on medical necessity, using AI or an algorithm, without that determination being reviewed and made by a licensed physician or other qualified health care provider with expertise in the relevant clinical area. The law also requires that any AI or algorithm used in the process weigh the individual enrollee’s medical history and clinical circumstances rather than relying solely on group data, and it applies the state’s existing nondiscrimination principles to algorithmic decision-making.4 Texas followed in 2025 with a dedicated AI statute of its own. Senate Bill 815, enacted in the 89th Legislature’s regular session and effective September 1, 2025, added Section 4201.156 to the Insurance Code, which provides that a utilization review agent may not use an automated decision system to make, wholly or partly, an adverse determination. The same act defined algorithm, artificial intelligence system, and automated decision system, preserved those tools for administrative support and fraud detection, and authorized the insurance commissioner to audit an agent’s use of them at any time; the prohibition reaches utilization review for plans delivered, issued, or renewed on or after January 1, 2026. The Texas Department of Insurance issued implementing guidance in Bulletin B-0003-26 on June 12, 2026, restating that prohibition and reminding regulated entities that any AI-assisted decision must still satisfy the state’s unfair trade practice, unfair discrimination, and claims-settlement statutes, and that a person must review and agree with any AI-influenced consequential decision before it is acted upon.5 Between them they framed the two approaches the 2026 legislation elaborates: require a qualified human to make the call, or forbid the machine from making it at all.

Mandating Human Clinical Review

The largest group of 2026 statutes regulates the pressure point California identified, the moment an algorithmic output becomes an adverse determination, and differs mainly in how tightly each defines the human who must intervene. Colorado drew the requirement most generally. House Bill 26-1139, signed June 2, 2026 and effective January 1, 2027, adds insurance-specific language to the state’s earlier cross-industry algorithmic discrimination statute: a denial based in whole or in part on medical necessity may not issue solely on an AI system’s output, and the system must account for the enrollee’s individual medical and clinical history rather than group data alone.6 Georgia is more specific. Senate Bill 444, effective January 1, 2027, amends the state’s private review agent statute to permit AI to automate tasks and participate in decision-making, but bars any AI system from issuing an adverse determination until a natural person qualified as a private review agent conducts a utilization review in which a clinical peer participates, and specifies that the AI system must not supersede that peer’s judgment.7 Washington is more specific still. Senate Bill 5395, effective June 11, 2026, limits the authority to deny a prior authorization request based on medical necessity to a licensed physician or other licensed health professional, prohibits carriers from relying solely on AI for that denial, and requires the human reviewer to evaluate the treating provider’s recommendation, the enrollee’s medical history, and the enrollee’s individual clinical circumstances; where AI is used, the system must be subject to audit by the insurance commissioner, reviewed periodically for accuracy and outcomes, operated nondiscriminatorily, and limited in its use of patient data to purposes consistent with HIPAA.8 Utah reached a comparable result by indirection. Senate Bill 319, enacted March 19, 2026 and effective January 1, 2027, requires anyone making an adverse preauthorization determination on medical or clinical necessity grounds to exercise independent medical judgment and bars reliance solely on recommendations from any other source, a phrase broad enough to capture AI-generated recommendations.9 Two states narrowed the mandate rather than broadening it. Iowa’s House File 2635, effective July 1, 2026, permits AI to conduct the initial review of a prior authorization request but provides that, for any request involving medical necessity, AI may not be the sole basis for a decision to deny, delay, or downgrade it, and it requires utilization review organizations to furnish the requesting provider with a written attestation of the reviewing clinical peer’s qualifications.10 Alabama’s Senate Bill 63, effective October 1, 2026, borrows the CMS Medicare Advantage guardrails rather than the California model, requiring that AI-assisted prior authorization determinations rest on the beneficiary’s medical history and individual clinical circumstances.11

Layering On Disclosure and Reporting

A second and partly overlapping mechanism regulates not the decision but the record of it. Maryland relies on it almost exclusively. House Bill 1563, effective June 1, 2026 and building on 2025’s HB 820, requires quarterly reporting to the Insurance Commissioner of the number of adverse coverage decisions issued, the type of service involved, and whether AI or another software tool played a role, and it gives the commissioner express authority to investigate an insurer if adverse determinations, particularly denials of emergency department claims, spike significantly.12 Several of the human-review states bolt similar obligations onto their substantive mandates. Washington requires a carrier that denies a request to disclose the reviewing clinician’s credentials to the enrollee and the referring provider, and to report annually what percentage of prior authorization denials were AI-aided. Utah requires insurers to disclose their use of AI to the Utah Insurance Department and to post their preauthorization and AI-use practices conspicuously on their websites. Alabama requires annual certification to its Department of Insurance that the insurer’s AI does not rely on group datasets, does not discriminate against groups of subscribers, and is periodically monitored for accuracy.

Restricting Automated Claims Downcoding

A third mechanism operates on claims payment rather than coverage or prior authorization, specifically the practice of downcoding, in which an insurer’s system automatically reduces the billing code, and therefore the reimbursement, that a provider submitted. Indiana’s House Bill 1271, effective July 1, 2026, prohibits insurers from using AI as the sole basis for downcoding a claim without a healthcare professional first reviewing the beneficiary’s medical record, and separately bars providers from submitting claims through an automated process without human review.13 Illinois went further. The Transparency in Downcoding Act, enacted as Senate Bill 3114 and signed July 10, 2026 as Public Act 104-0568, bars health care payors from using any algorithm or automated process that bypasses the information a billing provider submitted in order to downcode a claim, requires that a natural person applying current CPT coding guidelines make or review every downcoding determination, and requires notice to the billing professional of the downcoding and its clinical rationale, along with a process for disputing it; the law takes effect January 1, 2028, and exempts self-insured ERISA plans and workers’ compensation coverage.14 California is weighing a comparable measure in Assembly Bill 2431, which cleared its policy committee in April 2026 before being held under submission in appropriations.15 Claims-payment automation is emerging as its own area of legislative interest, distinct from the prior-authorization requirements described above.

Where the Legislation Stalled

The trend, while broad, has not swept every statehouse. Pennsylvania’s House Bill 1925, which would impose clinical-peer-review requirements similar to Georgia’s, was reported from committee and laid on the table on May 5, 2026, removed from the table on June 25, 2026, and sits on first consideration in the House. Oklahoma’s House Bill 3675 was referred to the House Rules Committee in February 2026 and has not moved since. New Hampshire’s House Bill 1406 cleared its House committee unanimously and was adopted by the full House in March 2026, but the Senate killed it on the floor on May 7, 2026. Louisiana’s Senate Bill 246 was withdrawn from the files of the Senate in late May 2026.16 The uneven survival rate is a useful reminder for compliance planning: the direction of travel is unmistakable, but insurers operating in a given state should confirm the current status of that state’s legislation rather than assuming enactment is inevitable, or that a bill’s substantive terms will survive the legislative process unchanged.

Common Threads Across the Patchwork

Despite the variation in mechanics and effective dates, the enacted statutes converge on a small number of shared principles. Every one of them prohibits AI from serving as the sole basis for an adverse determination tied to medical necessity. Every one requires that the human who makes or approves that determination be a licensed or otherwise qualified clinician, not merely any available employee. Most require that the AI system, where used, weigh the individual patient’s medical history and clinical circumstances rather than population-level data alone. None of the enacted laws prohibits the use of AI in utilization review or claims administration outright; all of them are aimed at the point where an algorithm’s output becomes an adverse decision affecting a patient’s access to care.

Practical Compliance Considerations

First, health insurers, third-party administrators, and AI vendors operating across multiple states should map each state against the applicable statute’s effective date, since several 2026 laws, including Georgia’s, Utah’s, and Colorado’s, do not take effect until January 1, 2027, providing a compliance runway that should be used rather than allowed to lapse.

Second, organizations should audit and, where necessary, rebuild their utilization review and prior authorization workflows to insert a documented human clinical review before any adverse determination tied to medical necessity is finalized, structured to demonstrate in writing that the reviewer actually considered the treating provider’s recommendation and the patient’s clinical history rather than ratifying the algorithm’s output.

Third, contracts with AI vendors should be revisited to require meaningful transparency into model inputs, training data, and validation methodology, and to allocate state-specific compliance responsibility clearly, since regulators are directing enforcement at the licensed insurer, not the vendor, regardless of which party built or trained the model.

Fourth, insurers should begin building the disclosure and reporting infrastructure these statutes increasingly require well before the deadlines, including Washington’s percentage-of-AI-aided-denials reporting, Maryland’s quarterly adverse-decision reporting, and Utah’s website posting obligations, since that infrastructure cannot be assembled quickly once a deadline is imminent.

Fifth, organizations should track downcoding obligations, as reflected in the Indiana and Illinois statutes, as a compliance stream distinct from utilization review and prior authorization, since the two areas turn on different statutory frameworks, different effective dates, and, in Illinois’s case, an enforcement mechanism built around provider notice and dispute rights rather than insurance department reporting.

Sixth, insurers offering Medicare Advantage products should treat the CMS guardrails and state-law requirements as cumulative rather than substitutable, confirming that AI-assisted coverage determinations satisfy both, since the documentation, certification, and audit expectations differ even where the underlying principle, individualized rather than group-based determinations, is the same.

Looking Ahead

The legislative activity of the past several months confirms that the trend California and Texas began has not slowed. If anything, it has accelerated and diversified, extending beyond prior authorization and utilization review into claims coding and reimbursement, and drawing in a broader and more geographically dispersed set of states. Absent a comprehensive federal framework, health insurers, third-party administrators, and the AI vendors that serve them should expect to keep building compliance programs state by state, with one constant across virtually every enacted law: whatever role artificial intelligence plays in evaluating a claim, a licensed clinician, not an algorithm, must remain the one who ultimately says no.

This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.

The views expressed are those of the author alone and do not represent the views of Spencer Fane LLP or its clients. This article is for general informational purposes only and is not legal advice.

  1. Estate of Gene B. Lokken v. UnitedHealth Group, Inc., No. 0:23-cv-03514 (D. Minn., filed Nov. 14, 2023); CourtListener docket.
  2. CBS News (Nov. 2023); STAT (Nov. 14, 2023).
  3. CMS, HPMS Memo (Feb. 6, 2024); memo text.
  4. Cal. S.B. 1120 (2024), eff. Jan. 1, 2025; bill text.
  5. Tex. S.B. 815, 89th Leg., R.S. (2025), adding Tex. Ins. Code § 4201.156, eff. Sept. 1, 2025; enrolled text; Tex. Dep’t of Ins. Bulletin B-0003-26 (June 12, 2026); TDI bulletin.
  6. Colo. H.B. 26-1139 (2026), eff. Jan. 1, 2027; bill text.
  7. Ga. S.B. 444 (2026), eff. Jan. 1, 2027; bill text.
  8. Wash. S.B. 5395 (2026), eff. June 11, 2026; bill text.
  9. Utah S.B. 319 (2026), eff. Jan. 1, 2027; bill text.
  10. Iowa H.F. 2635 (2026), eff. July 1, 2026; bill text.
  11. Ala. S.B. 63 (2026), eff. Oct. 1, 2026; bill text.
  12. Md. H.B. 1563 (2026), eff. June 1, 2026; bill text.
  13. Ind. H.B. 1271 (2026), eff. July 1, 2026; bill text.
  14. Ill. S.B. 3114, Transparency in Downcoding Act, P.A. 104-0568 (2026), eff. Jan. 1, 2028; bill text.
  15. Cal. A.B. 2431 (2026); bill status.
  16. Pa. H.B. 1925 (2025–26), bill status; Okla. H.B. 3675 (2026), bill status; N.H. H.B. 1406 (2026), bill status; La. S.B. 246 (2026), bill status.