Seven states passed laws in 2026 setting rules for how health insurers use artificial intelligence (AI) in coverage decisions. Alabama, Colorado, Georgia, Illinois, Iowa, Utah, and Washington all enacted statutes this year, and each lands on the same principle: an algorithm does not get the final word on a denial.
The effective dates arrive in waves. Washington's law took effect June 11 and Iowa's on July 1. Alabama's begins Oct. 1. Colorado, Georgia, and Utah start Jan. 1, 2027, and Illinois' law waits until Jan. 1, 2028. The new statutes join earlier laws in California, Texas, Arizona, Nebraska, Connecticut, and Maryland, putting more than a dozen states on the books with rules for AI in coverage or utilization decisions.
Which states passed AI health insurance laws in 2026?
Alabama, SB 63 (effective Oct. 1, 2026): Insurers must disclose AI use in their review processes and ground determinations in the member's medical history and individual clinical circumstances rather than group data alone. The law adds an annual certification covering discrimination safeguards and accuracy monitoring.
Colorado, HB 1139 (effective Jan. 1, 2027): The broadest of the group. It reaches insurers, pharmacy benefit managers, utilization review organizations, behavioral health administrative services organizations, and managed care entities. AI-based utilization review must weigh individual clinical history, undergo periodic accuracy audits, and avoid discriminatory application. A qualified professional must review a medical necessity denial before it goes out, and the law bars coverage of AI-delivered psychotherapy.
Georgia, SB 444 (effective Jan. 1, 2027): Coverage decisions based solely on AI systems or other software tools are prohibited. Adverse determinations require review and approval by a licensed health care provider, and AI output never supersedes clinical peer judgment.
Illinois, SB 3114, the Transparency in Downcoding Act (effective Jan. 1, 2028): Illinois aimed at claims rather than prior authorization. Payers are barred from using algorithms to bypass submitted billing information when downcoding a claim, and every downcoding determination requires human review against current American Medical Association CPT guidelines. Self-insured ERISA and workers’ compensation plans sit outside the law.
Iowa, HF 2635 (effective July 1, 2026): AI is permitted for initial prior authorization review and prohibited as the sole basis for a decision to deny, delay, or downgrade a request. A qualified reviewer or clinical peer makes the final call, and denials require written explanations naming the criteria relied upon.
Utah, SB 319 (effective Jan. 1, 2027): The transparency approach. Insurers must publicly post prior authorization requirements along with approval and denial statistics, disclose AI use to the state, providers, and enrollees, and base adverse determinations on a reviewer's independent medical judgment.
Washington, SB 5395 (effective June 11, 2026): Only licensed physicians or health professionals deny requests on medical necessity grounds. AI serves as a tool, never the sole means to deny, delay, or modify care. Systems must incorporate individual patient data, apply fairly and equitably, and feed annual reporting on AI-aided denials.
Two more 2026 laws sit beside this group. Indiana's HB 1271 (effective July 1, 2026) prohibits AI as the sole basis for downcoding a claim without a health care professional's review. Maryland's HB 1563 (effective June 1, 2026) requires quarterly reporting of adverse decisions to the state insurance commissioner and gives the commissioner authority to investigate significant increases in denials.
What do the new laws have in common?
Strip away the bill numbers and four requirements repeat across the map. A human with clinical credentials holds final authority over adverse determinations. Decisions reflect the individual patient, not a population data set. AI use gets disclosed to regulators, providers, or members. And the tools face ongoing scrutiny through audits, accuracy monitoring, or denial reporting.
The pattern matters more than any single statute. Legislators in different states, working from different bill drafts, keep arriving at the same guardrails. A health plan building AI governance around those four principles is building toward where the whole map is heading.
Why are states writing these laws now?
CMS wrote the template. Federal rules effective in 2024 require Medicare Advantage (MA) organizations to ground medical necessity determinations in each individual's circumstances rather than an algorithm's population-level output, with clinician review of denials. The CY2026 MA final rule declined to finalize additional AI guardrails and pointed to future rulemaking instead. States read the pause as an opening.
Public attention pushed in the same direction. Litigation over algorithmic denial tools and research linking AI-aided prior authorization to higher denial rates put the issue on legislative agendas nationwide. Lawmakers in both parties found an easy consensus: patients want a person, not a model, deciding whether care gets covered.
The trend has room to run. Pennsylvania and Oklahoma bills remain pending, and the National Association of Insurance Commissioners' model bulletin on AI use by insurers, already adopted in some form by a majority of states, gives regulators a ready framework even where no statute exists.
Where does Medicare Advantage fit?
State insurance statutes generally reach state-regulated commercial and Medicaid managed care business. MA answers to federal rules, which already impose parallel requirements. For a multi-line organization, the distinction offers little comfort. One AI governance program now has to satisfy CMS requirements and a growing patchwork of state ones, each with its own disclosure formats, audit expectations, and reporting calendars.
The staggered effective dates work in plans' favor. With the biggest wave landing Jan. 1, 2027, and Illinois holding until 2028, compliance teams have runway to inventory every algorithmic tool touching utilization management, map each tool to the states where it operates, and document the human review sitting on top of it. Plans doing this work now are building the record regulators will ask for later.
Questions to consider
- Do you have a current inventory of every AI and algorithmic tool touching utilization management, prior authorization, and claims across your lines of business?
- Which of your markets sit in the seven new states, and which effective dates hit your compliance calendar first?
- If a regulator asked tomorrow, would your team show how a human reviewer shaped each adverse determination an algorithm touched?
- How do your vendor contracts handle disclosure, audit rights, and accuracy monitoring for AI tools built by third parties?
See how your AI strategy compares to the rest of the industry at RISE West 2026, September 2-4, in San Diego. The exclusive general session, Winning with AI in Medicare Advantage: Benchmarking Results and Leader Insights, debuts first-ever MA AI benchmarking data, and the program dives deep on operationalizing AI and data at scale.