Independent Research & Regulatory Compliance Monitor
Statutory Benchmarks: NAIC AI Model Bulletin · Cal. Ins. Code § 14021 · Colorado SB 21-169

Statutory Analysis · Algorithmic Discrimination

Colorado SB 21-169 & Algorithm Testing: The Blueprint for State AI Claims Regulation

Colorado is the first state to mandate algorithmic bias audits, quantitative model testing, and data governance for insurance algorithms. Why popular claims AI architectures fail to meet Colorado's standards—and why other state DOIs are rapidly adopting this framework.

Statutory Standard: Colorado Revised Statutes § 10-3-1104.9

Colorado law explicitly prohibits insurers from using external consumer data and predictive models that result in unfair discrimination based on protected characteristics—including race, color, national or ethnic origin, religion, sex, sexual orientation, disability, or gender identity. Crucially, insurers are legally required to quantitatively test and prove that their models do not produce disproportionately negative outcomes.

The First Enforceable AI Statute in American Insurance

While the National Association of Insurance Commissioners (NAIC) released its Model Bulletin on Artificial Intelligence Systems in late 2023, Colorado had already codified binding statutory requirements through Senate Bill 21-169 (C.R.S. § 10-3-1104.9), enforced by the Colorado Division of Insurance.

Unlike aspirational white papers, Colorado Regulation 3 CCR 702-10-1 establishes rigorous, mandatory obligations for any insurer deploying predictive models or algorithms:

  • Mandatory Inventory of Algorithms: Carriers must maintain a complete, updated catalog of every algorithm, predictive model, and AI system used in underwriting, pricing, and claims handling.
  • Quantitative Testing for Unfair Discrimination: Insurers cannot simply accept vendor assurances. They must run statistical disparity tests across protected classes on raw model outputs.
  • Vendor Due Diligence Mandates: Contracts with third-party claims tech vendors must allow carriers to inspect source code, training datasets, and testing methodology.

The Claims AI Vulnerability: How Startups Introduce Proxy Bias

Venture-backed claims automation startups frequently pitch models trained on historical insurance claims records or publicly scraped legal dockets. These startups claim their models are “neutral” because they do not include explicit protected demographic fields like race or religion.

However, Colorado's regulatory framework explicitly targets proxy variables. When applied to claims handling and settlement, algorithmic systems ingest variables that heavily correlate with protected characteristics:

Input Variable Used by AI Underlying Correlated Proxy Disparate Claims Impact Regulatory Violation (SB 21-169)
Claimant Zip Code & Medical Facility Racial and socioeconomic neighborhood demographics. Discounts medical bills from inner-city safety-net hospitals at higher rates than private suburban surgery centers. Unfair discrimination in settlement valuation (C.R.S. § 10-3-1104.9(1)).
Linguistic Sentiment & Tone Analysis English as a second language (ESL) or regional vernacular. Flags ESL claimants or minority dialects as having higher “fraud propensity” during intake calls. Disparate referral to Special Investigation Units (SIU).
Treatment Delay Gaps Uninsured status or lack of paid sick leave. Categorizes necessary treatment gaps as “non-causal delay,” slashing bodily injury reserve calculations. Unjustified indemnity reduction based on socioeconomic factors.

The Vendor Contract Trap: Why Off-the-Shelf Tools Fail Audits

When insurance carriers undergo market conduct examinations by the Colorado Division of Insurance, the California Department of Insurance, or the New York DFS, examiners request quantitative validation reports.

In response, carriers that purchased black-box claims software from venture-backed startups often discover three fatal structural flaws in their vendor agreements:

  1. No Access to Training Data: The vendor refuses to disclose the training dataset, citing trade secrets or proprietary IP. Under Colorado law, this leaves the carrier completely unable to certify compliance.
  2. No Disparity Testing Conducted: Most early-stage insurtech startups have never conducted a single disparate impact test or quantitative bias audit prior to marketing their software at industry conferences like InsurTech NY or ITC Vegas.
  3. Indemnity Carve-Outs: Standard software-as-a-service (SaaS) contracts expressly disclaim any regulatory liability, leaving the insurance carrier 100% exposed to regulatory fines, consent decrees, and bad-faith class action litigation.

The Compliant Roadmap: How Carriers Can Comply

To operate safely in Colorado and states adopting similar algorithmic testing regulations, carriers must discard black-box scoring systems in favor of transparent, examiner-centric architectures:

  • Eliminate Autonomous Valuation: Software must never generate unilateral settlement numbers, offer haircuts, or assign automated fault percentages.
  • Primary Source Document Anchors: Every extraction must be accompanied by a verifiable Bates-stamp or direct visual link to the underlying medical chart or invoice.
  • Human Examiner Sign-Off: Retain licensed human claims examiners as the sole decision-makers on all coverage, causality, and settlement decisions.
Research & Editorial Methodology

This report was authored by the Claims Governance Institute Research Group. CGI is an independent, non-partisan research monitor examining artificial intelligence, algorithmic accountability, and regulatory compliance across the insurance and legal-tech sectors. Learn more at our Editorial Standards & Disclosures.