Start Free Trial
Home/Regulations/AI Fairness / Algorithmic Bias Rules (State DOI) — Regulatory Reference
Regulatory Reference
Insurance State high

AI Fairness / Algorithmic Bias Rules (State DOI) — Regulatory Reference

CO/CA DOI guidance on AI in underwriting — model risk management, adverse action notice, and agent audit trail directly required.

Key Provisions
  • Colorado Reg 10-1-1 — governance framework for AI in life insurance
  • California Department of Insurance Bulletin 2022-5 — bias and discrimination in AI underwriting
  • Quantitative testing for disparate impact in protected classes
  • Documentation of model risk management framework
How AutoPIL Enforces It
  • Agent registry + policy YAML constitutes the documented governance framework
  • Audit chain provides per-decision evidence for disparate impact testing
  • Adverse action notice generation supported by access history
Audit LogPolicy EngineAgent RegistryAlert RulesLineage
AutoPIL Policy IDs
INS-AIFAIR-CO-001Colorado Algorithm Governance Framework
INS-AIFAIR-CA-001California Underwriting AI Audit
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What do Colorado and California DOI AI fairness rules require for insurers using AI agents in underwriting?
Colorado Regulation 10-1-1 requires life insurers to maintain a documented algorithm and predictive model governance framework, including model risk management procedures and bias testing. California DOI Bulletin 2022-5 requires insurers to demonstrate that AI systems used in underwriting do not result in unfair discrimination or disparate impact against protected classes. Both frameworks demand that each AI-driven decision be traceable and that the insurer can produce evidence of ongoing bias monitoring. Insurers using AI agents — whether for data retrieval, scoring, or decision support — must capture per-decision audit records sufficient to support quantitative disparate impact analysis on demand.
When do Colorado Reg 10-1-1 and California Bulletin 2022-5 apply to AI agent deployments?
Colorado Reg 10-1-1 applies to any life insurer licensed in Colorado that uses an algorithm or predictive model in a decision that could affect policyholder outcomes — including underwriting, rating, and claims. California Bulletin 2022-5 applies broadly to insurers using AI or ML in California for rating, underwriting, or claims handling. Both frameworks are triggered when an AI agent accesses data that informs any such decision. If an agent queries customer records, medical data, credit proxies, or external data sources as part of an underwriting workflow, the governance and audit obligations apply to that agent's behavior.
What is the adverse action notice requirement under state DOI AI fairness rules?
Under state fair lending and insurance non-discrimination principles — reinforced by the California and Colorado guidance — insurers must be able to explain adverse decisions to applicants. When AI is involved, this means the insurer must reconstruct which data the agent accessed, which model scored the request, and what policy governed the decision at the moment it was made. A generic log that captures only the final outcome is not sufficient. The adverse action notice must be supportable by a complete decision trail, which requires that every agent access event be recorded with the data source, sensitivity level, governing policy version, and outcome classification at the time of the decision.
How does AutoPIL support compliance with state DOI AI fairness and algorithmic bias requirements?
AutoPIL maps directly to the three compliance obligations these frameworks impose. The agent registry and policy YAML provide the documented governance framework Colorado and California require — each agent is registered, bound to a named policy, and the policy is version-controlled so no decision is retroactively reinterpreted. The tamper-evident audit chain records every data access event before sensitive data enters the agent's context window, with the governing policy version stamped on each record — this is the per-decision evidence needed for quantitative disparate impact testing. Access history by source and agent supports adverse action notice reconstruction. AutoPIL ships pre-built policies `INS-AIFAIR-CO-001` and `INS-AIFAIR-CA-001` for these frameworks.
What are the enforcement risks for insurers that cannot produce an AI audit trail under state DOI guidance?
Regulators in Colorado and California have signaled examination readiness on AI fairness. An insurer that cannot produce a documented governance framework, bias testing results, or per-decision audit records for AI-assisted underwriting faces examination findings, market conduct action, and potential cease-and-desist orders on affected products. California's DOI has authority to require rate or form withdrawals where unfair discrimination is alleged and the insurer cannot refute it with data. Beyond direct regulatory action, failure to document adverse action notice support exposes insurers to civil claims under state unfair insurance practices statutes. The evidentiary bar is: can you show, for any specific decision, exactly what data the AI accessed and which policy governed it?
Covered Industries

These state DOI frameworks apply to any insurer licensed in Colorado or California that uses AI agents in underwriting, rating, or claims decisions. Compliance requires documented model governance, quantitative bias testing, and a complete audit trail for every AI-driven access to applicant or policyholder data.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries