Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
US-AKMEDIUM coverage

Alaska — Bulletin B 24-01, THE FIRST NAIC AI MODEL ADOPTION IN THE UNITED STATES (1 February 2024): a NINTH model-diff shape — ADOPTION-ANNOTATED AND ONE AUTHORITY LIMB SHORT (model numbers stripped, model-act names kept, all four remaining brackets filled with real AS cites, and the Market Conduct Surveillance bullet deleted outright because Alaska never enacted Model #693) + the Vein's Most Emphatic A&H EXCLUSION (AS 21.39.020(b)(2) excludes health insurance in terms) + a UTPA Penalty Ladder Topping Out at $1,000,000 Per Violation With a Permanent Industry Bar (AS 21.36.910(f)) + Credit/Insurance-Scoring Rules That Name Algorithms and Models (AS 21.36.460) + the Prior-Authorization Act Alaska Enacted Through the SENATE Bill While the Identical HOUSE Bill Died in Committee (SB 133 / Ch. 21 SLA 2025, AS 21.07.100-21.07.180, effective 1 January 2027) + the Vein's Sharpest UR Bar: a PERSONAL-REVIEW ATTESTATION (AS 21.07.120(b)): AI Compliance Requirements

Alaska has no comprehensive private-sector AI statute reaching insurers. What it has is the FIRST adoption of the NAIC AI model bulletin anywhere in the United States, a rating limb that excludes accident and health more emphatically than any other state in this vein, a penalty ladder whose top rung is the largest number recorded across all twenty adopters, and — arriving 1 January 2027 — a prior-authorization statute containing the single hardest bar on automated utilization review found anywhere in the vein. (1) THE INSTRUMENT. Bulletin B 24-01, "The Use of Artificial Intelligence Systems in Insurance", dated 1 February 2024 and signed by Director of Insurance Lori Wing-Heier, issued by the Division of Insurance within the Department of Commerce, Community, and Economic Development on Anchorage-office letterhead, addressed "TO: ALL INSURERS LICENSED TO DO BUSINESS IN THE STATE OF ALASKA AND OTHER INTERESED PARTIES" (the misspelling is the Division's). It is a bulletin, not an order and not a regulation: it creates no penalty of its own, contains no effective-date or sunset clause, and — like the model — expressly preserves alternative routes to compliance. The NAIC's own implementation map lists it first among adopted states. It remains, as of 27 August 2026, the ONLY Alaska insurance bulletin addressing artificial intelligence. (2) THE MODEL DIFF IS A NINTH SHAPE, and the right name for it is ADOPTION-ANNOTATED AND ONE AUTHORITY LIMB SHORT. The shapes recorded in this ledger so far are verbatim (Oklahoma, Arkansas), verbatim-plus-citations (District of Columbia), verbatim-plus-citations-and-broadened (Rhode Island), softened (Kentucky), gutted (West Virginia), bidirectional or tightened-and-thinned (New Hampshire), broadened-but-disclaimed (Delaware) and re-domesticated (Vermont). Alaska fits none. On the OPERATIVE text it is a faithful copy: Section 2's ten definitions, Section 3 with its AIS Program Guidelines 1.1-1.9, 2.0-2.4 and 3.0-3.7, Section 4's Third-Party guidelines 4.0-4.3 and Section 4's itemised production list are the model's, materially word for word. It KEEPS the four-sentence background paragraph on AI risk that New Hampshire deleted; KEEPS "the Insurer's OWN ASSESSMENT of the degree and nature of risk"; KEEPS Guideline 1.3's "senior management accountable to the board or an appropriate committee of the board"; KEEPS "to identify errors AND BIAS" and plain "bias analysis and minimization"; KEEPS "the transparency and EXPLAINABILITY of outcomes"; KEEPS "Third Party" as an "organization"; KEEPS the NIST AI Risk Management Framework reference at Guideline 1.5; and RETAINS Section 4's production list in full, including "or evidencing", "that is the subject of investigation or examination" and "where applicable". It does not re-designate the regulated party — it is "Insurer" throughout, where Delaware substituted "insurance carrier" at some forty places. ALL of Alaska's editing sits in the authority section, and it has three distinct moves. FIRST, Alaska DELETED EVERY NAIC MODEL NUMBER — #880, #900, #305, #1780 and #693 are all gone — but, unlike Vermont, KEPT THE MODEL-ACT NAMES as the bullet headings. SECOND, and found in no other adopter, Alaska ANNOTATED ITS OWN ADOPTION STATUS on the face of the bulletin: two headings read "Corporate Governance Annual Disclosure Model Act ADOPTED" and "Property and Casualty Model Rating Law ADOPTED". The bulletin is telling the reader which NAIC models Alaska actually enacted. THIRD, and this is the structural subtraction that names the shape, ALASKA DELETED THE MARKET CONDUCT SURVEILLANCE MODEL LAW BULLET ENTIRELY. The model has five authority bullets; Alaska has four. Delaware kept that bullet and left its citation bracket empty; Vermont kept it and filled it with 8 V.S.A. §§ 3573-3574; Alaska removed the head and kept only its trailing narrative sentence ("An Insurer's conduct in the state... is subject to investigation, including market conduct actions"), which now stands with no cited authority above it. The reason is checkable and it is not sloppiness: ALASKA HAS NEVER ENACTED MODEL #693. Its market-conduct power comes instead from a general examination statute, AS 21.06.120 ("Examination of insurers, third-party administrators, and pharmacy benefit managers"), which lets the Director examine "as often as the director considers advisable" and which itself incorporates the NAIC Market Regulation Handbook — but only as one of the criteria the Director "may consider" in scheduling. There was no #693-corresponding statute to put in the bracket, so the bullet went. Read against the District of Columbia, which the ledger records as filling every bracket while softening nothing, Alaska is the same fill-the-brackets instinct applied honestly to a state that had only four of the five models to fill them with. (3) ALASKA FILLED EVERY REMAINING BRACKET, INCLUDING THE INLINE ONES. The model leaves bare "[]" placeholders not only in the bullet headings but inside two running sentences. Alaska closed all of them: unfair trade practices "as defined in A.S. 21.36.010 - A.S. 21.36.120 and A.S. 21.36.130 - A.S. 21.36.920", unfair claims settlement practices "as defined in A.S. 21.36.125" (plus regulations at 3 AAC 26.010-3 AAC 26.300), corporate governance at AS 21.09.400-21.09.460 (regulations 3 AAC 21.785-3 AAC 21.790), and rating at AS 21.39.010-21.39.070 (regulations 3 AAC 29.200-3 AAC 29.300). It also collapsed the model's separate CGAD Model Regulation (#306) reference into the same bullet, and de-acronymised the model's follow-on sentence from "The requirements of CGAD and CGAD-R" to "The requirements of Alaska's corporate governance disclosure statutes and regulations". Every one of these citations was verified against the current code this session and every one still lands. (4) THE RATING LIMB EXCLUDES ACCIDENT AND HEALTH, AND ALASKA IS THE STRONGEST FORM OF THAT ANSWER IN THE VEIN. The bulletin's rating sentence is the model's verbatim and reaches "all forms of casualty insurance—including fidelity, surety, and guaranty bond—and to all forms of property insurance—including fire, marine, and inland marine insurance". Accident and health is absent. Unlike the states where A&H is merely unmentioned, in Alaska the exclusion is EXPRESS IN THE STATUTE the bulletin cites: AS 21.39.020(b)(2) provides that the rating chapter "does not apply to... health insurance", alongside carve-outs for reinsurance, ocean marine and surplus lines. So Alaska's bulletin is not under-reaching its own law — it tracks it exactly. A health insurer in Alaska is not outside AI regulation, but it answers under the unfair trade practices and claims-settlement limbs and (from 2027) the prior-authorization act, not under the rate standard. (5) THERE IS A REAL FILING HOOK FOR P&C, AND IT IS GENERIC RATHER THAN AI-SPECIFIC. This is the honest answer to the model-filing question that New Hampshire, Delaware and Vermont each answered with a dedicated scoring-model statute: ALASKA HAS NO STATUTE REQUIRING AN INSURER TO FILE A PREDICTIVE OR SCORING MODEL AS SUCH. What it has instead is AS 21.39.040(a), which requires each insurer to file with the Director "every manual, minimum, class rate, rating schedule, loss cost adjustment, or RATING PLAN and every other RATING RULE, and each modification of any of them that it proposes to use", under the procedures and waiting periods of AS 21.39.041, 21.39.210 or 21.39.220, and AS 21.39.040(d), which lets the Director demand "the information upon which the insurer supports the filing" and restarts the waiting period when that information arrives. An AI-derived rating plan or rating rule for a property or casualty line is therefore inside a prior-filing regime, and the supporting-information power is the practical route by which an Alaska regulator gets at the model behind the numbers. (6) CREDIT AND INSURANCE SCORING — ALASKA NAMED ALGORITHMS AND MODELS IN ITS INSURANCE CODE INDEPENDENTLY OF THE BULLETIN. AS 21.36.460 governs "uses of and restrictions on credit history or insurance scoring applicable to personal insurance" and defines an "insurance score" at subsection (i)(6) as "a number or rating that is derived from an ALGORITHM, COMPUTER APPLICATION, MODEL, or other process that is based in whole or in part on credit history". Its substantive rules bite an automated underwriting pipeline directly. Subsection (d)(3) BANS a set of inputs outright: an insurer may not use an insurance score calculated using "the income, age, sex, address, ZIP CODE, CENSUS BLOCK, ethnic group, religion, marital status, or nationality of the consumer as a factor" — a proxy-variable prohibition that reaches exactly the geographic and demographic features a model would otherwise learn. Subsection (d)(4) forbids relying on credit history obtained more than 90 days before the decision, and (d)(5) forbids using a score to set eligibility for a payment plan. Subsection (b) imposes an explainability duty on the output: an adverse-action notice must "clearly and specifically state the SIGNIFICANT FACTORS of the credit history or insurance score that resulted in the adverse action, in a manner that allows the consumer to identify the basis", must tell the consumer how to request reconsideration, must advise on ways to improve the score, and must point to the extraordinary-life-circumstances exceptions at AS 21.36.461 with a 60-day request window. Subsection (e) requires retroactive reissue or re-rating and a refund of overpayment for up to 12 months where incorrect credit history was used, and subsection (f) gives the consumer a right to have the coverage REUNDERWRITTEN WITHOUT CREDIT INFORMATION AS A FACTOR on a reconsideration certification filed within 10 days — a form which is itself "subject to filing and approval by the director under AS 21.42.120". (7) UTILIZATION REVIEW — the standing sweep, and Alaska produces the sharpest bar recorded anywhere in this vein: a PERSONAL-REVIEW ATTESTATION. Alaska enacted a prior-authorization act at AS 21.07.100-21.07.180, and it is real enacted law carrying a deferred effective date of 1 JANUARY 2027 (the code prints each section under "<Text of section effective January 1, 2027.>"). AS 21.07.120(b) provides that a peer reviewer "must have relevant clinical expertise in the specialty area or be of an equivalent specialty as the health care provider submitting the prior authorization request", and then adds the sentence that no other state in this vein contains: "A peer reviewer SHALL ATTEST, IN WRITING OR ELECTRONICALLY, THAT THE REVIEWER HAS PERSONALLY REVIEWED AND CONSIDERED ALL MEDICAL NOTES AND RELEVANT CLINICAL INFORMATION submitted as part of the prior authorization request." Every other bar in this vein is a species-of-decider rule — the District of Columbia bars the adverse determination itself, Rhode Island requires it made, documented and signed, New Hampshire requires named credentials, Delaware requires same-or-similar specialty first with compensation independence, Vermont requires a state review-agent licence and comparable-provider concurrence. Alaska is the first to convert automation into an AFFIRMATIVE FALSE STATEMENT: a model cannot personally review anything, and a human who signs the attestation over a model's output while not having read the notes has made a false written attestation to a regulated fact. AS 21.07.120(c) reinforces it by entitling the provider, on request, to "the qualifications of a peer reviewer issuing an adverse decision... including the specialty and relevant board certifications". THREE FURTHER LIMBS BITE AN AUTOMATED PIPELINE. AS 21.07.100(b) sets determination clocks of 72 hours for a standard request and 24 hours for an expedited one, and AS 21.07.100(f) makes the request "CONSIDERED APPROVED if the health care insurer fails to provide a written denial, approval, or request for additional information within the time specified" — a deemed-grant consequence for a stalled queue. AS 21.07.140 requires an adverse determination to give "a clear explanation of the reasons... including the SPECIFIC EVIDENCE-BASED REASONS AND CRITERIA USED to make the determination" plus a description of any missing information. AS 21.07.110(b) requires prior-authorization requirements to be "based on peer-reviewed, evidence-based clinical review criteria and be CONSISTENTLY APPLIED BY ALL SOURCES, including utilization review organizations, to avoid discrepancies or conflicts", reviewed and updated at least annually — which reaches a vendor's model as squarely as the insurer's own. AS 21.07.130 fixes prior-authorization validity at not less than 12 months with automatic renewal for chronic conditions and 90 days or a clinically appropriate duration otherwise, with 60 days' advance notice of any new or amended requirement and a bar on implementing it until BOTH the insurer's and the utilization review organization's websites are updated. HONEST NEGATIVE, with method: AS 21.07.100 through 21.07.180 were each read in full this session and NONE of them contains the words "artificial intelligence", "algorithm", "machine learning", "automated" or "predictive". Alaska's utilization-review reservations are clinician and attestation rules, not AI rules — which is precisely why they bite an AI system. (8) A SECOND, EARLIER UR BAR THAT IS LIVE TODAY AND WHOSE RELIEF HAS EXPIRED. Alaska's grievance regulation 3 AAC 28.936(o) requires a grievance decision to include "the NAME, TITLE, AND QUALIFYING CREDENTIALS of each person participating as a reviewer in the review process", and 3 AAC 28.936(b) requires the name, address and telephone number of the person or organizational unit coordinating the review. Bulletin B 25-05 (24 January 2025) granted a TEMPORARY forbearance from the naming duty, on employee-safety grounds, permitting a first name plus last initial or an alpha-numeric identifier "as long as the actual reviewer is able to be tracked internally", with full names still producible to the Division on request under AS 21.09.320(c) (the bulletin misprints this as "AS 2109.320(c)") and held confidential under AS 21.06.060(f)-(g). That bulletin states on its face: "This bulletin expires on January 24, 2026." IT HAS EXPIRED. Absent a replacement rule, the full 3 AAC 28.936(o) duty to name, title and credential every human reviewer is back in force — and it presupposes a person participating as a reviewer. (9) NO AI-UTILIZATION-REVIEW BILL PASSED IN ALASKA, AND THE ENACTING VEHICLE FOR THE PRIOR-AUTHORIZATION ACT IS NOT THE BILL THE TRACKERS NAME. This is the correction this round produced and it matters to anyone citing Alaska law. Secondary sources point at HB 144 of the 34th Legislature ("INSURANCE; PRIOR AUTHORIZATIONS"). Per the Legislature's OWN bill record, HB 144 NEVER PASSED: its current status is "(H) L&C" with a status date of 9 April 2025 — it died in the House Labor & Commerce Committee. The identically-titled Senate companion, SB 133, is the law: the Legislature's record shows CSSB 133(L&C) enrolled 18 May 2025 and its current status as "CHAPTER 21 SLA 25", status date 16 July 2025. Cite SB 133 / Chapter 21, SLA 2025 — not HB 144. Separately, SB 2 of the 34th Legislature (election deepfakes, state-agency AI and inter-agency data transfers) never moved past its first referral — status "(S) STA / Then JUD", 22 January 2025 — and it was not a utilization-review bill in any event. Alaska has NO enacted or pending AI-specific utilization-review statute. (10) THE DIVISION BULLETIN SHELF, SWEPT, WITH THE NEGATIVE BOUNDED. The Division's HTML bulletin index refuses automated access, so the shelf was swept by direct enumeration of its own PDF portal (commerce.alaska.gov/web/Portals/11/Pub/): all thirty candidate slots from B 24-01 to B 26-10 were probed, twenty-three exist and seven return 404 (B 24-08, B 25-10, B 26-02 and B 26-05 through B 26-10). Every one of the twenty-two bulletins after B 24-01 was downloaded and its subject line read. NONE of them addresses artificial intelligence, algorithms, predictive models, insurance scoring, external consumer data, accelerated underwriting, telematics or aerial imagery. The shelf is: recurring eligible-surplus-lines lists (B 24-03, B 24-09, B 25-01, B 25-06, B 26-01, B 26-04), annual health-insurance surveys under AS 21.06.110 (B 24-02, B 25-04, B 26-03), the Change Healthcare cyber-attack response and its extension (B 24-04, B 24-06), a title-insurance closing protection letter (B 24-05), depreciation of labor (B 24-07, subsequently WITHDRAWN by B 25-03 — do not cite B 24-07 as current), storm fair-treatment bulletins (B 24-10 for Ketchikan 2024, B 25-07 and B 25-08 for the 2025 west-coast storm), independent-adjuster licence exemptions (B 25-02), the grievance reviewer-identification forbearance (B 25-05, expired), and SB 132 licensing guidance (B 25-09). So B 24-01 stands alone and unrevised: Alaska issued the country's first AI insurance bulletin and has issued nothing on the subject since.

Summary of publicly-available regulatory text as of 2026-08-27. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

February 1, 2024

Maximum Penalty

Alaska's ceiling is the highest recorded anywhere in this vein, and it is reached by disobedience rather than by the underlying AI failure. THE LADDER IS AT AS 21.36.910 AND IT HAS FOUR RUNGS. (1) A cease and desist order is MANDATORY, not discretionary: under § 21.36.910(c), if the Director determines a person violated the chapter, the Director "SHALL serve upon the person charged an order requiring that person to cease and desist". (2) Under § 21.36.910(d) the Director may, after a hearing, order restitution and assess "not more than $2,500 for each violation or $25,000 for engaging in a GENERAL BUSINESS PRACTICE in violation of this chapter", and may add interest calculated under AS 09.30.070 to any restitution order. (3) Under § 21.36.910(e), where the Director finds after a hearing that the person "KNEW OR SHOULD HAVE KNOWN" it was in violation, the exposure multiplies tenfold and licence action becomes available: suspension or revocation plus "not more than $25,000 for each violation or $250,000 for engaging in the general business practice". The knew-or-should-have-known standard is a low bar for a documented AI governance failure — an insurer that ran an unvalidated model after its own AIS Program flagged drift is squarely inside it. (4) The top rung is for defying the order, and it is the largest number in the vein: under § 21.36.910(f), if a cease and desist order is violated the Director may certify the facts to the superior court under AS 44.62.590, and the court on finding a breach "may order the violator to comply with the order, pay an additional penalty of NOT MORE THAN $1,000,000 FOR EACH VIOLATION, may revoke or suspend the violator's license, and MAY BAR THE VIOLATOR FROM TRANSACTING THE BUSINESS OF INSURANCE IN THE FUTURE" — a permanent industry bar that no other state in this vein carries in its UTPA. TWO STRUCTURAL FEATURES CUT THE OTHER WAY AND MUST TRAVEL WITH THE HEADLINE. First, § 21.36.910(g) makes mitigation mandatory rather than optional: in setting the (d) and (e) penalties the Director "SHALL consider the amount of loss or harm caused by the violation and the amount of benefit derived", and may weigh seriousness, "the promptness and completeness of remedial action", whether the conduct was a single act or a trade practice, and deterrence — so a documented, promptly-remediated model defect is a statutory mitigating factor, and the AIS Program is the evidence of it. Second, § 21.36.910(h) is a SINGLE-ACT SAFE HARBOUR found nowhere else in this vein: where the violation is a single act prohibited under AS 21.36.125 (unfair claim settlement practices) that results in loss or harm, the Director "may require restitution or issue a cease and desist order but MAY NOT IMPOSE A PENALTY that includes a fine or require other remedial action, unless the violation results in loss or harm AND IS INTENTIONAL". It expressly does not shelter multiple acts — which is exactly the exposure profile of a systematic AI claims pipeline, where a defective model produces the pattern the safe harbour withholds. OTHER ROUTES, EACH WITH ITS OWN NUMBER. Corporate governance: AS 21.09.460 prices a late corporate governance annual disclosure at "$1,000" for each day of failure without just cause, "not to exceed $365,000", reducible at the Director's discretion. Prior authorization from 1 January 2027: AS 21.07.180(d) directs the Director to adopt regulations establishing penalties and caps the civil penalty for a single instance of noncompliance at "$25,000"; § 21.07.180(b) requires examinations under AS 21.06.120-21.06.230 at least once every two years directed at response times, published-requirement accuracy and consistency of practice across vendors and utilization review organizations; and AS 21.07.170 requires an annual compliance report to the Director including records of denials and associated appeals. Injunctive relief is separately available under AS 21.36.920. Bulletin B 24-01 itself creates NO penalty and is not an enforcement hook — it is neither a statute nor a regulation, and its closing paragraph expressly preserves compliance "through alternative means, including through practices that differ from those described in this bulletin"; every sanction above arrives through the statutes underneath it.

What Your Business Must Do

12 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Bulletin B 24-01 Section 4 — the Production List That Applies Whether or Not an AIS Program Exists, and the Examination Power Behind It

Critical

This is the operative teeth of the bulletin and the reason a written AIS Program is worth building even though the bulletin is non-binding. Section 4 states that "REGARDLESS OF THE EXISTENCE OR SCOPE OF A WRITTEN AIS PROGRAM, in the context of an investigation or market conduct action, an Insurer can expect to be asked about its development, deployment, and use of AI Systems, or any specific Predictive Model, AI System or application and its outcomes (including Adverse Consumer Outcomes)". The itemised list is the model's in full. Item 1 (governance, risk management and use protocols) reaches information "related to OR EVIDENCING" the AIS Program: the written program itself; documentation evidencing its ADOPTION; "the scope of the Insurer's AIS Program, including any AI Systems and technologies NOT INCLUDED IN OR ADDRESSED BY the AIS Program" — so deliberately excluding a model from the program does not put it beyond production; how the program is tailored to the risk of Adverse Consumer Outcomes and the Degree of Potential Harm; and the policies, procedures, guidance and TRAINING MATERIALS, including processes for development, adoption or acquisition, identification of constraints and controls on automation and design, data governance covering lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, model management measurements, standards or thresholds, and protection of non-public information including unauthorized access to the models themselves. Item 1.3 reaches documentation "relating to or evidencing the Insurer's implementation and compliance with its AIS Program", including the formation and ongoing operation of coordinating bodies; data practices; inventories and descriptions of Predictive Models and AI Systems "used by the Insurer to make or support decisions that can result in Adverse Consumer Outcomes"; and, "as to any specific predictive model or AI System THAT IS THE SUBJECT OF INVESTIGATION OR EXAMINATION", documentation of compliance with all applicable AI Program policies, information about the data used including source, provenance and lineage, and the techniques, measurements and thresholds used. Item 1.3(d) requires documentation of validation, testing and auditing "including evaluation of MODEL DRIFT to assess the reliability of outputs", reflective of whether the system is based on Predictive Models or GENERATIVE AI. Item 2 adds third-party material: due diligence conducted on third parties; contracts with third-party AI System, model or data vendors "including terms relating to representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and/or cooperation with regulators"; audits and confirmation processes; and documentation of validation, testing and auditing including Model Drift evaluation. The power behind the list is AS 21.06.120, under which the Director may examine an authorized insurer "as often as the director considers advisable", weighing among other things consumer complaint volume, prior examination results and the criteria in the NAIC's Financial Condition Examiners Handbook and MARKET REGULATION HANDBOOK. The bulletin's closing paragraph preserves that power in terms: "Nothing in this bulletin limits the authority of the DOI to conduct any regulatory investigation, examination, or enforcement action relative to any act or omission of any Insurer the DOI is authorized to perform."

Deadline: February 1, 2024

Bulletin B 24-01 (1 February 2024), Section 4 (Regulatory Oversight and Examination Considerations), items 1.1-1.3 and 2.1-2.4, and closing paragraphs; examination authority at AS 21.06.120-21.06.230.

AS 21.36 — Unfair Trade Practices and Unfair Claim Settlement Practices Bind AI Decisions Regardless of Method

Critical

This is the binding law under the non-binding bulletin, and it is the limb that reaches HEALTH insurers in Alaska (who sit outside the rating chapter). Bulletin B 24-01 states the principle in the model's words: "Actions taken by Insurers in the state must not violate the UTPA or the UCSPA, REGARDLESS OF THE METHODS THE INSURER USED TO DETERMINE OR SUPPORT ITS ACTIONS", and expects insurers to adopt governance frameworks and risk management protocols designed to ensure that the use of AI Systems does not result in unfair trade practices as defined in AS 21.36.010-21.36.120 and 21.36.130-21.36.920, or unfair claims settlement practices as defined in AS 21.36.125 (with regulations at 3 AAC 26.010-3 AAC 26.300). Section 3 supplies the substantive standard an AI-supported decision must meet: decisions subject to regulatory oversight "must comply with the legal and regulatory standards that apply to those decisions, including unfair trade practice laws", and those standards require "at a minimum, decisions made by Insurers are NOT INACCURATE, ARBITRARY, CAPRICIOUS, OR UNFAIRLY DISCRIMINATORY". The four adjectives are the test: an AI system that is merely accurate on average but arbitrary in an individual case fails it. AS 21.36.125 lists the specific claim-handling acts — misrepresenting facts or policy provisions relating to coverage among them — and an automated claims pipeline commits them through its outputs just as a human adjuster does through statements. Note the enforcement asymmetry that AS 21.36.910(h) creates and that matters specifically to automation: a SINGLE act prohibited under AS 21.36.125 causing loss or harm attracts restitution or a cease and desist order but NO FINE unless intentional — but that shelter expressly does not extend to multiple acts, which is precisely the shape of harm a systematically defective model produces.

Deadline: February 1, 2024

AS 21.36.010-21.36.120 and AS 21.36.130-21.36.920 (Unfair Trade Practices); AS 21.36.125 (Unfair claim settlement practices) with 3 AAC 26.010-3 AAC 26.300; standard applied to AI at Bulletin B 24-01 Sections 1 and 3.

AS 21.07.100-21.07.180 (SB 133 / Ch. 21 SLA 2025, effective 1 JANUARY 2027) — Prior-Authorization Clocks, Deemed Approval on Timeout, and Evidence-Based Reasons on Every Denial

Critical

Alaska enacted a prior-authorization act in 2025 with a deferred effective date: every section of AS 21.07.100-21.07.180 prints under "<Text of section effective January 1, 2027.>", and AS 21.07.100(a) binds a health care insurer "offering a health plan issued or renewed on or after January 1, 2027". CITE THE RIGHT BILL. The enacting vehicle is SB 133 of the 34th Legislature — CSSB 133(L&C), enrolled 18 May 2025, recorded by the Legislature as "CHAPTER 21 SLA 25" with a status date of 16 July 2025. Its identically-titled House companion, HB 144, DIED IN COMMITTEE: the Legislature's own record shows its status as "(H) L&C" with a status date of 9 April 2025. Secondary trackers that attribute the law to HB 144 are wrong. THE DUTIES THAT CONSTRAIN AN AUTOMATED QUEUE. Under AS 21.07.100(a) the insurer must designate a prior authorization process that is "reasonable and efficient and minimize[s] administrative burdens on health care providers and facilities". Under (b), where the request contains the information necessary to decide, the insurer must determine and notify within 72 HOURS of a standard request (72 hours excluding weekends if submitted by facsimile) or 24 HOURS of an expedited request. Under (c), where it does not, the insurer must request specific additional information within one calendar day (expedited) or three calendar days (standard), and under (d) may set a due date of not less than five nor more than 14 working days for that information, notifying both provider and covered person. Under (e) the insurer must confirm receipt showing the date and time. And under (f) — the provision that prices a stalled model — a request "IS CONSIDERED APPROVED if the health care insurer fails to provide a written denial, approval, or request for additional information within the time specified under this section". AS 21.07.140 governs the denial itself: an adverse determination requires notice to both the covered person and the provider giving "a clear explanation of the reasons for the adverse determination, including the SPECIFIC EVIDENCE-BASED REASONS AND CRITERIA USED to make the determination and a description of any specific missing or insufficient information that contributed to" it, plus a statement of appeal rights and instructions including the appeal timeline and direct contact details. AS 21.07.110 requires the insurer to publish its current prior-authorization standards on its website "in detailed, easily understood language", requires those standards to be "based on peer-reviewed, evidence-based clinical review criteria and be CONSISTENTLY APPLIED BY ALL SOURCES, INCLUDING UTILIZATION REVIEW ORGANIZATIONS, to avoid discrepancies or conflicts", reviewed and updated at least annually, and provides at (c) that where the insurer's published standards differ from its utilization review organization's, "the health care insurer shall use the prior authorization standard MOST FAVORABLE TO THE COVERED PERSON". AS 21.07.130 fixes validity: not less than 12 months for a chronic condition with automatic renewal on certification of compliance with an unchanged treatment plan, and otherwise 90 calendar days or a clinically appropriate duration, whichever is longer; new or amended requirements need 60 days' written notice to participating providers and 60 days' website notice, and may not be implemented until BOTH the insurer's and the utilization review organization's websites are updated. AS 21.07.150 requires a prior authorization application programming interface automating provider determination of requirements. HONEST NEGATIVE, with method: every section from AS 21.07.100 to AS 21.07.180 was read in full this session and none contains "artificial intelligence", "algorithm", "machine learning", "automated" or "predictive". These are technology-neutral rules, which is exactly why they constrain an AI pipeline — the clocks, the deemed-grant and the evidence-based-reasons duty do not care what produced the answer.

Deadline: January 1, 2027

AS 21.07.100-21.07.180, added by SB 133 (34th Legislature), Chapter 21, SLA 2025, effective 1 January 2027 — in particular AS 21.07.100(b)-(f), AS 21.07.110(b)-(c), AS 21.07.130, AS 21.07.140 and AS 21.07.150.

AS 21.07.120(b) — THE PERSONAL-REVIEW ATTESTATION: the Sharpest Bar on Automated Utilization Review in the Vein

Critical

This is the single provision that most constrains AI in Alaska utilization review, and it works by a mechanism no other state in this vein uses. AS 21.07.120 (effective 1 January 2027) requires a health care insurer to establish a process for a provider to request a CLINICAL PEER REVIEW of a prior authorization request, and then imposes two conditions on the reviewer. First, a species-of-decider rule familiar from Delaware: "A peer reviewer MUST HAVE RELEVANT CLINICAL EXPERTISE IN THE SPECIALTY AREA OR BE OF AN EQUIVALENT SPECIALTY as the health care provider submitting the prior authorization request." Second, and found nowhere else: "A peer reviewer SHALL ATTEST, IN WRITING OR ELECTRONICALLY, THAT THE REVIEWER HAS PERSONALLY REVIEWED AND CONSIDERED ALL MEDICAL NOTES AND RELEVANT CLINICAL INFORMATION SUBMITTED AS PART OF THE PRIOR AUTHORIZATION REQUEST." Every other reservation recorded in this vein tells you WHO may decide; Alaska additionally requires the decider to certify WHAT THEY PERSONALLY DID. An AI system cannot personally review anything and cannot attest. More importantly, a human who signs the attestation over a model's recommendation without having read the notes has not merely fallen short of a governance expectation — they have made a false written or electronic attestation to a regulated fact, which converts an automation shortcut into an affirmative misstatement. The practical design consequence is precise: a compliant Alaska peer-review workflow may use a model to triage, summarise, retrieve or prepare, but the attesting clinician must actually read the submitted notes, and the system must not be built to make that attestation a formality or a default checkbox. AS 21.07.120(c) supplies the audit trail: "A health care insurer shall provide to a health care provider AT THE PROVIDER'S REQUEST the qualifications of a peer reviewer issuing an adverse decision on a prior authorization request, including the SPECIALTY AND RELEVANT BOARD CERTIFICATIONS of the peer reviewer" — so the reviewer's identity-in-substance is discoverable by the very provider whose request was refused. Read this together with the second, already-live Alaska bar recorded separately in this entry: the grievance regulation 3 AAC 28.936(o), whose reviewer-naming duty is back in force since Bulletin B 25-05's forbearance expired on 24 January 2026.

Deadline: January 1, 2027

AS 21.07.120 (Peer review of prior authorization request), subsections (a)-(c), added by SB 133 (34th Legislature), Chapter 21, SLA 2025, effective 1 January 2027.

Bulletin B 24-01 — Written AI Systems (AIS) Program, on the Model's Text Unaltered

High Priority

All Insurers authorized to do business in Alaska are EXPECTED to develop, implement and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make, or support decisions related to, regulated insurance practices. The AIS Program should be designed to mitigate the risk of Adverse Consumer Outcomes, "including, at a minimum, the statutory provisions set forth in Section 1 of this bulletin" — which in Alaska means the UTPA, the UCSPA, the corporate governance disclosure statutes and, for property and casualty only, the rating chapter. Alaska preserved the model's self-assessment discretion in full: controls "should be reflective of, and commensurate with, the INSURER'S OWN ASSESSMENT of the degree and nature of risk posed to consumers", weighing the nature of the decision, the type and Degree of Potential Harm to Consumers, "the extent to which humans are involved in the final decision-making process", the transparency and EXPLAINABILITY of outcomes to the impacted consumer, and the extent of reliance on third-party data, Predictive Models and AI Systems. The Program must span the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, fraud detection), all phases of an AI System's own life cycle from design through validation, implementation, monitoring, updating and retirement, and systems "whether developed by the Insurer or a third-party vendor". Guideline 1.9 requires processes providing NOTICE TO IMPACTED CONSUMERS that AI Systems are in use, with access to appropriate levels of information for the life-cycle phase. The Program may sit inside or outside the Insurer's ERM programme and may adopt a third-party standard framework such as the NIST AI Risk Management Framework. Because the bulletin was issued on 1 February 2024 with no transition period and no phase-in, the expectation has run from that date.

Deadline: February 1, 2024

Alaska Division of Insurance Bulletin B 24-01, "The Use of Artificial Intelligence Systems in Insurance" (1 February 2024, Director Lori Wing-Heier), Section 3 (Regulatory Guidance and Expectations) and AIS Program Guidelines 1.1-1.9.

Bulletin B 24-01 — Governance Framework, and the Corporate Governance Annual Disclosure Hook Alaska Annotated as ADOPTED

High Priority

Vest responsibility for the development, implementation, monitoring and oversight of the AIS Program — and for setting the Insurer's strategy for AI Systems — with "senior management accountable to the board or an appropriate committee of the board" (Guideline 1.3, kept in full where New Hampshire cut the board tie). The governance framework must "prioritize transparency, fairness, and accountability in the design and implementation of the AI Systems, recognizing that proprietary and trade secret information must be protected", and should address: policies, processes and procedures at each stage of the AI System life cycle from proposed development to retirement (2.1); documentation requirements "developed WITH SECTION 4 IN MIND" (2.2); and an internal AI System governance accountability structure (2.3) covering centralized, federated or otherwise constituted committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of responsibility, chains of command and decisional hierarchies; "the INDEPENDENCE OF DECISION-MAKERS and lines of defense at successive stages of the AI System life cycle"; monitoring, auditing, escalation and reporting protocols; and ongoing training and supervision of personnel. Guideline 2.4 adds a Predictive-Model-specific duty: documented processes for designing, developing, verifying, deploying, using, updating and monitoring models, "including a description of methods used to detect and address errors, performance issues, outliers, or unfair discrimination in the insurance practices resulting from the use of the Predictive Model". The separate statutory limb is Alaska's Corporate Governance Annual Disclosure, which the bulletin heads "Corporate Governance Annual Disclosure Model Act ADOPTED" and cites at AS 21.09.400-21.09.460 with regulations at 3 AAC 21.785-3 AAC 21.790; the bulletin states that those requirements "apply to elements of the Insurer's corporate governance framework that address the Insurer's use of AI Systems to support actions and decisions that impact consumers". Unlike the AIS Program expectation, the CGAD filing is a genuine statutory obligation with its own per-day penalty, and AI governance is now expressly within its subject matter.

Deadline: February 1, 2024

Bulletin B 24-01 (1 February 2024), AIS Program Guidelines 1.2, 1.3 and 2.0-2.4, read with Section 1 (Corporate Governance Annual Disclosure Model Act Adopted) citing AS 21.09.400-21.09.460 and 3 AAC 21.785-3 AAC 21.790.

Bulletin B 24-01 — Risk Management and Internal Controls, With Validation on Unseen Data and Model Drift Named

High Priority

The AIS Program should document the Insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each stage of the AI System life cycle (Guideline 3.0). The itemised expectations are the model's unaltered. 3.1: the oversight and approval process for developing, adopting or acquiring AI Systems, and "the identification of constraints and controls on automation and design to align and balance function with risk". 3.2: data practices and accountability procedures "including data currency, lineage, quality, integrity, BIAS ANALYSIS AND MINIMIZATION, and suitability" — Alaska kept the model's plain "bias", where New Hampshire narrowed it to "unfair" bias. 3.3: management and oversight of predictive models including the algorithms used therein, requiring (a) inventories and descriptions of the Predictive Models, (b) detailed documentation of their development and use, and (c) assessments "such as interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, MODEL DRIFT, and the auditability of these measurements where appropriate". 3.4: "validating, testing, and retesting as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model", where validation "can take the form of comparing model performance on UNSEEN DATA AVAILABLE AT THE TIME OF MODEL DEVELOPMENT to the performance observed on data post-implementation, measuring performance against expert review, or other methods". 3.5: protection of non-public information, "particularly consumer information, including unauthorized access to the predictive models themselves". 3.6: data and record retention. 3.7: for Predictive Models specifically, "a narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure that the AI Systems that rely on such models correctly and efficiently predict or implement those goals and objectives". Note that "Model Drift" is a defined term in Section 2 — "the decay of a model's performance over time arising from underlying changes such as the definitions, distributions, and/or statistical properties between the data used to train the model and the data on which it is deployed" — so drift monitoring is not a discretionary nicety but a named expectation with a defined meaning.

Deadline: February 1, 2024

Bulletin B 24-01 (1 February 2024), AIS Program Guidelines 3.0-3.7, read with the Section 2 definitions of "Model Drift", "Predictive Model", "Algorithm" and "Machine Learning (ML)".

Bulletin B 24-01 — Third-Party AI Systems and Data: Diligence, Audit Rights and a Regulator-Cooperation Clause

High Priority

Each AIS Program should address the Insurer's process for acquiring, using or relying on (i) third-party data to develop AI Systems and (ii) AI Systems developed by a third party, which may include establishing standards, policies, procedures and protocols on three matters. Guideline 4.1: "due diligence and the methods employed by the Insurer to assess the third party and its data or AI Systems acquired from the third party to ensure that decisions made or supported from such AI Systems that could lead to Adverse Consumer Outcomes WILL MEET THE LEGAL STANDARDS IMPOSED ON THE INSURER ITSELF" — the vendor is held to the insurer's own standard, not to a lesser one. Guideline 4.2: "where appropriate and available, the inclusion of terms in contracts with third parties that (a) provide AUDIT RIGHTS and/or entitle the Insurer to receive audit reports by qualified auditing entities, and (b) REQUIRE THE THIRD PARTY TO COOPERATE WITH THE INSURER WITH REGARD TO REGULATORY INQUIRIES AND INVESTIGATIONS related to the Insurer's use of the third-party's product or services". Guideline 4.3: "the performance of audits and/or other activities to confirm the third-party's compliance with contractual and, WHERE APPLICABLE, regulatory requirements" — Alaska retained the model's "where applicable" qualifier, which New Hampshire and Delaware each handled differently. Guideline 1.8 reinforces the whole limb by requiring the AIS Program to address AI Systems used with respect to regulated insurance practices "whether developed by the Insurer or a third-party vendor". The practical consequence is contractual: an Alaska insurer buying a scoring, triage or claims-estimation model needs AI-scoped audit rights and a regulator-cooperation covenant in the vendor agreement, because Section 4 of the bulletin makes the insurer answerable for third-party models it cannot itself explain.

Deadline: February 1, 2024

Bulletin B 24-01 (1 February 2024), AIS Program Guidelines 4.0-4.3 and 1.8, read with the Section 2 definition of "Third Party" ("an organization other than the Insurer who provides services, data, or other resources related to AI").

AS 21.39 — AI-Derived Rates, Rating Plans and Rating Rules Must Be Filed and Must Not Be Excessive, Inadequate or Unfairly Discriminatory (PROPERTY AND CASUALTY ONLY — Health Expressly Excluded)

High Priority

Bulletin B 24-01 heads this bullet "Property and Casualty Model Rating Law ADOPTED" and cites AS 21.39.010-21.39.070 with regulations at 3 AAC 29.200-3 AAC 29.300. The operative sentence is the NAIC model's verbatim: the requirements apply "regardless of the methodology the Insurer used to develop rates, rating rules, and rating plans", and "Insurers are responsible for assuring rates, rating rules, and rating plans are developed using AI techniques and Predictive Models that rely on data and Machine Learning do not result in excessive, inadequate, or unfairly discriminatory insurance rates with respect to all forms of casualty insurance—including fidelity, surety, and guaranty bond—and to all forms of property insurance—including fire, marine, and inland marine insurance, and any combination of the foregoing." READ THE SCOPE LIMIT AS A HARD ONE. Accident and health is not merely unmentioned: AS 21.39.020(a) applies the chapter to casualty (including fidelity, surety and guaranty bonds) and to fire, marine and inland marine, and AS 21.39.020(b) then provides that the chapter "does not apply to... (2) HEALTH INSURANCE", alongside carve-outs for reinsurance, ocean marine and AS 21.34 surplus lines. Alaska's bulletin therefore tracks its own statute exactly rather than over-reaching. THE FILING DUTY IS THE PRACTICAL HOOK. Under AS 21.39.040(a) each insurer "shall file with the director... every manual, minimum, class rate, rating schedule, loss cost adjustment, or RATING PLAN and every other RATING RULE, and each modification of any of them that it proposes to use", stating the proposed effective date and indicating the character and extent of coverage contemplated, under the filing procedures of AS 21.39.041, 21.39.210 or 21.39.220 — with an informational-filing route available for some commercial lines under § 21.39.040(k) and an exception for inland marine risks not written to manual rates. Under AS 21.39.040(d), where a filing is unsupported the Director "shall require the insurer to furnish the information upon which the insurer supports the filing" and the statutory waiting period restarts when that information arrives; the supporting information may include "the experience or judgment of the insurer", its interpretation of the statistical data relied on, other insurers' experience and "any other relevant factors". An insurer may discharge the duty through a licensed rating organization under § 21.39.040(b). So while Alaska has NO statute requiring a predictive or scoring model to be filed as such, an AI-derived rating plan or rating rule for a P&C line is inside a prior-filing regime, and § 21.39.040(d) is the lever by which the Director reaches the model behind the numbers.

AS 21.39.010 (Purpose), AS 21.39.020 (Applicability — (b)(2) excludes health insurance), AS 21.39.040 (Rate filings) and AS 21.39.041/21.39.210/21.39.220; 3 AAC 29.200-3 AAC 29.300; applied to AI at Bulletin B 24-01 Section 1.

AS 21.36.460 — Insurance Scoring: an Algorithm Named in Statute, a Proxy-Variable Ban, an Explainability Duty and a Right to Be Reunderwritten Without It

High Priority

Alaska regulated algorithmic scoring in personal insurance years before the AI bulletin, and because AS 21.36.460 sits INSIDE the unfair trade practices chapter, a scoring failure is itself an unfair trade practice priced by the AS 21.36.910 ladder. The statute names the technology: AS 21.36.460(i)(6) defines an "insurance score" as "a number or rating that is derived from an ALGORITHM, COMPUTER APPLICATION, MODEL, or other process that is based in whole or in part on credit history". FOUR DUTIES BITE AN AUTOMATED PIPELINE. (1) DISCLOSURE UP FRONT — under (a), an insurer using credit information in underwriting or rating must disclose, on the application or when it is taken and again at renewal, that it will obtain credit information, and if a third party calculates the score the disclosure must also say so; the statute supplies safe-harbour wording. (2) A PROXY-VARIABLE BAN — under (d)(3) an insurer may not use an insurance score "that is calculated using the income, age, sex, address, ZIP CODE, CENSUS BLOCK, ethnic group, religion, marital status, or nationality of the consumer as a factor". This is the provision that reaches feature engineering directly: geographic granularity down to census block is prohibited as a scoring input, whatever its measured predictive power. Under (d)(4) credit history obtained more than 90 days before the decision may not be used, and under (d)(5) a score may not determine eligibility for a payment plan. (3) AN EXPLAINABILITY DUTY ON THE OUTPUT — under (b), an adverse action based in whole or in part on credit history or an insurance score requires written notice that "clearly and specifically state[s] the SIGNIFICANT FACTORS of the credit history or insurance score that resulted in the adverse action, IN A MANNER THAT ALLOWS THE CONSUMER TO IDENTIFY THE BASIS", tells the consumer of the right to request reconsideration and to a free credit report, explains the right to correct errors, "advise[s] the consumer on ways to improve the consumer's insurance score", and points to the extraordinary-life-circumstances exceptions at AS 21.36.461 with a 60-day window to request one. "Model output" or "score too low" does not discharge this. (4) TWO CONSUMER REMEDIES WITH TEETH — under (e), where incorrect credit history was used and the consumer was charged more or given worse terms, the insurer "shall reissue or rerate the policy RETROACTIVE to the effective date of the current policy term" and refund overpayment calculated back over the last 12 months of coverage or the actual policy period, whichever is shorter, provided the consumer discovers the error within 12 months, resolves the dispute and notifies the insurer in writing. Under (f), where disputed credit history results in denial or cancellation, the insurer "shall REUNDERWRITE THE COVERAGE WITHOUT THE USE OF CREDIT INFORMATION AS A FACTOR" if the consumer supplies a reconsideration certification within 10 days — and that certification form "is subject to filing and approval by the director under AS 21.42.120". Note the boundaries honestly: (g) provides the section "does not require an insurer to use credit history for any purpose", (h) requires the insurer to indemnify and defend its producers who follow its instructions, and the section is confined to PERSONAL insurance — private passenger automobile or motorcycle, and homeowner coverage including mobile homeowner's, manufactured homeowner's and condominium — so commercial lines are outside it.

AS 21.36.460 (Uses of and restrictions on credit history or insurance scoring applicable to personal insurance), subsections (a)-(i), with AS 21.36.461 (extraordinary life circumstances) and AS 21.42.120 (form filing and approval).

3 AAC 28.936 — Every Grievance Reviewer Must Be Named, Titled and Credentialed, and the Bulletin That Relaxed It EXPIRED on 24 January 2026

High Priority

This is Alaska's second utilization-review reservation, it is already in force, and it is date-sensitive in a way an insurer can easily get wrong. Alaska's grievance regulations require, at 3 AAC 28.936(b), that the insurer give the covered person or their representative "the name, address, and telephone number of the person or organizational unit designated" to coordinate a grievance review; and at 3 AAC 28.936(o), that a grievance decision include "the NAME, TITLE, AND QUALIFYING CREDENTIALS OF EACH PERSON PARTICIPATING AS A REVIEWER in the review process". The duty presupposes a person participating as a reviewer, and it makes an anonymous or purely automated review path non-compliant on its face. THE RELIEF HAS LAPSED. Bulletin B 25-05 (24 January 2025, Director Lori Wing-Heier), issued to all insurers authorized to transact health insurance business, recorded that "due to heightened concerns related to the personal safety of insurance company employees" several health insurers wished to remove identifying details from consumer-facing communications. The Director agreed to FORBEAR from administrative action against an insurer that does not provide reviewer names under 3 AAC 28.936(b) and (o), provided it otherwise adheres to the grievance regulations, and permitted "the first name and first initial of the last name of such employees or... an alpha-numeric identifier AS LONG AS THE ACTUAL REVIEWER IS ABLE TO BE TRACKED INTERNALLY", with alternative identifiers submittable to the Director. Insurers, their contractors and Independent Review Organizations remained obliged to produce full reviewer names to the Division on request under AS 21.09.320(c) (the bulletin misprints this citation as "AS 2109.320(c)"), held confidential under AS 21.06.060(f) and (g). The forbearance was expressly temporary "until such time as a long-term solution may be completed through rulemaking", and the bulletin states on its face: "This bulletin EXPIRES ON JANUARY 24, 2026." That date has passed. Absent a replacement bulletin or completed rulemaking — and the Division's bulletin shelf, swept in full to B 26-10 this session, contains no successor — the unmodified 3 AAC 28.936(b) and (o) naming duty governs. Two consequences for an AI-assisted grievance function: the internal-traceability condition the forbearance imposed is a good design requirement to keep regardless, and any workflow built during 2025 around alpha-numeric reviewer identifiers should be re-examined against the regulation as written.

Deadline: January 24, 2026

3 AAC 28.936(b) and (o) (grievance procedures — reviewer identification); temporary forbearance in Alaska Bulletin B 25-05 (24 January 2025), which by its own terms expired 24 January 2026; reviewer-name production to the Division under AS 21.09.320(c), confidentiality under AS 21.06.060(f)-(g).

Monitor Alaska Insurance AI Developments

Lower Priority

Track four things. (1) The Division of Insurance bulletin shelf at commerce.alaska.gov — B 24-01 has stood alone and unrevised since 1 February 2024, and any successor or revision would be the first movement in two and a half years. (2) Completion of the rulemaking that Bulletin B 25-05 anticipated for reviewer identification in grievance communications; the forbearance expired 24 January 2026 with no successor. (3) The 1 January 2027 commencement of AS 21.07.100-21.07.180, and the regulations AS 21.07.180(d) directs the Director to adopt establishing penalties for noncompliance — those regulations do not yet exist and will set the real price of a prior-authorization failure. (4) The Alaska Legislature at akleg.gov for any AI-specific insurance or utilization-review bill; none has been enacted, and the two AI bills of the 34th Legislature that touched adjacent ground either died in committee (SB 2 — election deepfakes, state-agency AI, inter-agency data transfers, status "(S) STA / Then JUD", 22 January 2025) or were not insurance measures at all. Note the drafting trap this round exposed: Alaska passed its prior-authorization act through the SENATE bill (SB 133 / Ch. 21 SLA 2025) while the identical HOUSE bill (HB 144) died in committee — check the Legislature's own bill record before citing a vehicle.

Frequently Asked Questions

Does Alaska — Bulletin B 24-01, THE FIRST NAIC AI MODEL ADOPTION IN THE UNITED STATES (1 February 2024): a NINTH model-diff shape — ADOPTION-ANNOTATED AND ONE AUTHORITY LIMB SHORT (model numbers stripped, model-act names kept, all four remaining brackets filled with real AS cites, and the Market Conduct Surveillance bullet deleted outright because Alaska never enacted Model #693) + the Vein's Most Emphatic A&H EXCLUSION (AS 21.39.020(b)(2) excludes health insurance in terms) + a UTPA Penalty Ladder Topping Out at $1,000,000 Per Violation With a Permanent Industry Bar (AS 21.36.910(f)) + Credit/Insurance-Scoring Rules That Name Algorithms and Models (AS 21.36.460) + the Prior-Authorization Act Alaska Enacted Through the SENATE Bill While the Identical HOUSE Bill Died in Committee (SB 133 / Ch. 21 SLA 2025, AS 21.07.100-21.07.180, effective 1 January 2027) + the Vein's Sharpest UR Bar: a PERSONAL-REVIEW ATTESTATION (AS 21.07.120(b)) apply to my business?

Alaska has no comprehensive private-sector AI statute reaching insurers. What it has is the FIRST adoption of the NAIC AI model bulletin anywhere in the United States, a rating limb that excludes accident and health more emphatically than any other… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Alaska — Bulletin B 24-01, THE FIRST NAIC AI MODEL ADOPTION IN THE UNITED STATES (1 February 2024): a NINTH model-diff shape — ADOPTION-ANNOTATED AND ONE AUTHORITY LIMB SHORT (model numbers stripped, model-act names kept, all four remaining brackets filled with real AS cites, and the Market Conduct Surveillance bullet deleted outright because Alaska never enacted Model #693) + the Vein's Most Emphatic A&H EXCLUSION (AS 21.39.020(b)(2) excludes health insurance in terms) + a UTPA Penalty Ladder Topping Out at $1,000,000 Per Violation With a Permanent Industry Bar (AS 21.36.910(f)) + Credit/Insurance-Scoring Rules That Name Algorithms and Models (AS 21.36.460) + the Prior-Authorization Act Alaska Enacted Through the SENATE Bill While the Identical HOUSE Bill Died in Committee (SB 133 / Ch. 21 SLA 2025, AS 21.07.100-21.07.180, effective 1 January 2027) + the Vein's Sharpest UR Bar: a PERSONAL-REVIEW ATTESTATION (AS 21.07.120(b)) is: Alaska's ceiling is the highest recorded anywhere in this vein, and it is reached by disobedience rather than by the underlying AI failure. THE LADDER IS AT AS 21.36.910 AND IT HAS FOUR RUNGS. (1) A cease and desist order is MANDATORY, not discretionary: under § 21.36.910(c), if the Director determines a person violated the chapter, the Director "SHALL serve upon the person charged an order requiring that person to cease and desist". (2) Under § 21.36.910(d) the Director may, after a hearing, order restitution and assess "not more than $2,500 for each violation or $25,000 for engaging in a GENERAL BUSINESS PRACTICE in violation of this chapter", and may add interest calculated under AS 09.30.070 to any restitution order. (3) Under § 21.36.910(e), where the Director finds after a hearing that the person "KNEW OR SHOULD HAVE KNOWN" it was in violation, the exposure multiplies tenfold and licence action becomes available: suspension or revocation plus "not more than $25,000 for each violation or $250,000 for engaging in the general business practice". The knew-or-should-have-known standard is a low bar for a documented AI governance failure — an insurer that ran an unvalidated model after its own AIS Program flagged drift is squarely inside it. (4) The top rung is for defying the order, and it is the largest number in the vein: under § 21.36.910(f), if a cease and desist order is violated the Director may certify the facts to the superior court under AS 44.62.590, and the court on finding a breach "may order the violator to comply with the order, pay an additional penalty of NOT MORE THAN $1,000,000 FOR EACH VIOLATION, may revoke or suspend the violator's license, and MAY BAR THE VIOLATOR FROM TRANSACTING THE BUSINESS OF INSURANCE IN THE FUTURE" — a permanent industry bar that no other state in this vein carries in its UTPA. TWO STRUCTURAL FEATURES CUT THE OTHER WAY AND MUST TRAVEL WITH THE HEADLINE. First, § 21.36.910(g) makes mitigation mandatory rather than optional: in setting the (d) and (e) penalties the Director "SHALL consider the amount of loss or harm caused by the violation and the amount of benefit derived", and may weigh seriousness, "the promptness and completeness of remedial action", whether the conduct was a single act or a trade practice, and deterrence — so a documented, promptly-remediated model defect is a statutory mitigating factor, and the AIS Program is the evidence of it. Second, § 21.36.910(h) is a SINGLE-ACT SAFE HARBOUR found nowhere else in this vein: where the violation is a single act prohibited under AS 21.36.125 (unfair claim settlement practices) that results in loss or harm, the Director "may require restitution or issue a cease and desist order but MAY NOT IMPOSE A PENALTY that includes a fine or require other remedial action, unless the violation results in loss or harm AND IS INTENTIONAL". It expressly does not shelter multiple acts — which is exactly the exposure profile of a systematic AI claims pipeline, where a defective model produces the pattern the safe harbour withholds. OTHER ROUTES, EACH WITH ITS OWN NUMBER. Corporate governance: AS 21.09.460 prices a late corporate governance annual disclosure at "$1,000" for each day of failure without just cause, "not to exceed $365,000", reducible at the Director's discretion. Prior authorization from 1 January 2027: AS 21.07.180(d) directs the Director to adopt regulations establishing penalties and caps the civil penalty for a single instance of noncompliance at "$25,000"; § 21.07.180(b) requires examinations under AS 21.06.120-21.06.230 at least once every two years directed at response times, published-requirement accuracy and consistency of practice across vendors and utilization review organizations; and AS 21.07.170 requires an annual compliance report to the Director including records of denials and associated appeals. Injunctive relief is separately available under AS 21.36.920. Bulletin B 24-01 itself creates NO penalty and is not an enforcement hook — it is neither a statute nor a regulation, and its closing paragraph expressly preserves compliance "through alternative means, including through practices that differ from those described in this bulletin"; every sanction above arrives through the statutes underneath it.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Alaska — Bulletin B 24-01, THE FIRST NAIC AI MODEL ADOPTION IN THE UNITED STATES (1 February 2024): a NINTH model-diff shape — ADOPTION-ANNOTATED AND ONE AUTHORITY LIMB SHORT (model numbers stripped, model-act names kept, all four remaining brackets filled with real AS cites, and the Market Conduct Surveillance bullet deleted outright because Alaska never enacted Model #693) + the Vein's Most Emphatic A&H EXCLUSION (AS 21.39.020(b)(2) excludes health insurance in terms) + a UTPA Penalty Ladder Topping Out at $1,000,000 Per Violation With a Permanent Industry Bar (AS 21.36.910(f)) + Credit/Insurance-Scoring Rules That Name Algorithms and Models (AS 21.36.460) + the Prior-Authorization Act Alaska Enacted Through the SENATE Bill While the Identical HOUSE Bill Died in Committee (SB 133 / Ch. 21 SLA 2025, AS 21.07.100-21.07.180, effective 1 January 2027) + the Vein's Sharpest UR Bar: a PERSONAL-REVIEW ATTESTATION (AS 21.07.120(b))?

The 12 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.commerce.alaska.gov/web/Portals/11/Pub/B24-01.pdf

Last updated: 2026-08-27 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan