Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
US-RIMEDIUM coverage

Rhode Island — DBR Insurance Bulletin 2024-03 (NAIC AI Model, Verbatim-Plus-BROADENED) + Vehicle History Score Ban (2024-8) + Aerial Imagery Underwriting Rules (2025-3) + UR Same-Licensure Signature Reservation (§ 27-18.9-5(b)(1)): AI Compliance Requirements

Rhode Island has no comprehensive private-sector AI statute (the "Artificial Intelligence Act", S 0627 of 2025, died in committee — held for further study on May 12, 2025), but it regulates AI in INSURANCE, and the instrument most compliance programmes reach for is the WEAKEST of the four surfaces described here. (1) AI SYSTEMS — DBR Insurance Bulletin Number 2024-03, "Use of Artificial Intelligence Systems by Insurers" (March 15, 2024, Superintendent of Insurance Elizabeth Kelleher Dwyer), adopts the NAIC Model Bulletin. Diffed sentence-by-sentence against the model this session, it is a FIFTH shape in this vein: not verbatim (Oklahoma, Arkansas), not verbatim-plus-citations (District of Columbia), not softened (Kentucky) and not gutted (West Virginia), but verbatim-plus-citations-and-BROADENED. Rhode Island filled every blank citation bracket AND widened the instrument in four places: it generalises the model's single Property and Casualty Model Rating Law bullet into a defined term, "the Rating Laws", spanning §§ 27-6-4, 27-9-4, 27-44-5 and 27-7.1-4.1; it ADDS § 27-29-4(7), an unfair-discrimination hook that appears nowhere in the model; it enlarges Section 3's list of governing standards from the model's "unfair trade practice laws" to "any applicable insurance laws and regulations" plus the Rating Laws by name; and it broadens the definition of "Third Party" from the model's "an organization other than the Insurer" to "an ENTITY other than the Insurer". It preserves the model's "are expected to" normativity — nothing was downgraded to a recommendation — and it keeps Section 4's itemised production list in full. It drops only the model's drafting-note footnote and its model-number references. (2) A CITATION DEFECT IN THE STATE'S OWN BULLETIN, verified against the legislature's chapter indexes rather than assumed: Section 1.B.4 names "R.I. Gen. Laws § 27-72-1 et seq., the Rhode Island Market Conduct Surveillance Act". Chapter 27-72 is the LIFE SETTLEMENTS ACT. The Market Conduct Surveillance Act is chapter 27-71, which the same bulletin cites correctly in Section 4. A reader following the Section 1 pointer lands in the wrong chapter. (3) RATE SCOPE — the rating chapter the bulletin routes to, § 27-44-5, is governed by § 27-44-3(a), which excludes EIGHT classes outright: life insurance, annuities, ACCIDENT AND HEALTH INSURANCE, ocean marine, reinsurance, medical malpractice, workers' compensation and residual market mechanisms; § 27-44-3(b) redirects those classes to chapters 6, 7.1, 9, 19 and 20 of title 27 and chapter 62 of title 42. The bulletin's own rating paragraph closes on a matching property/casualty line list. So an A&H insurer takes nothing from the rating limb. What DOES reach it is the hook Rhode Island added beyond the model: § 27-29-4(7)(ii) bars unfair discrimination between individuals of the same class and essentially the same hazard in the premium, policy fees or rates charged for any policy or contract of ACCIDENT OR HEALTH insurance, or in the benefits payable, or in any of the terms or conditions, "or in any other manner". Rhode Island's broadening is therefore not cosmetic — it is the only path by which the AI bulletin's rating discipline touches health lines. (4) THE HARD RULES ARE THE DATA-SPECIFIC BULLETINS, NOT THE AI ONE. Bulletin 2024-8 (September 9, 2024) addresses third-party VEHICLE HISTORY SCORES in private passenger auto rating and does what 2024-03 never does — it declares a class of model output unlawful on its face: any rating program using a vehicle history score that counts losses which are not Chargeable Accidents or Moving Violations, or that fall outside the three-year lookback, "is deemed to be in violation of the RI Rating statutes and regulations", insurers "should cease using those scores", and any insurer using one "must submit a filing to the Division via SERFF removing the non-compliant elements no later than November 30, 2024", with a continuing bar on future filings. Bulletin 2025-3 (August 18, 2025) governs AERIAL AND SATELLITE IMAGERY in homeowners underwriting and claims, reaching initial risk consideration, tiering, non-renewal and the determination of causes and amounts of loss; it sets testable evidentiary standards (images must be clear, accurate and CURRENT — less than 15 months old; low-resolution, out-of-focus, blurry or stale images "cannot alone justify" cancellation or nonrenewal; cosmetic roof damage such as streaking or discoloration is "not sufficient to independently support" nonrenewal absent functional or structural damage), states that failure "may constitute an unfair trade practice under R.I. Gen Laws Chapter 27-29" and, for claims, a violation of the Unfair Claims Settlement Practices Act, and — decisively for model builders — extends expressly to "any third-party roof scores or similar mechanism that leverage aerial imagery". Neither bulletin uses the word "artificial intelligence"; both bite directly on machine-derived scores. (5) UTILIZATION REVIEW — Rhode Island has no AI-specific UR statute (the Benefit Determination and Utilization Review Act, chapter 27-18.9, contains no occurrence of "artificial intelligence", "algorithm", "automated" or "machine learning"), but § 27-18.9-5(b)(1) imposes a reservation STRONGER than the District of Columbia's: all initial, prospective and concurrent non-administrative ADVERSE benefit determinations of a healthcare service ordered by a physician, dentist or other practitioner "shall be made, documented, and signed by a licensed practitioner with the same licensure status as the ordering provider". DC reserves the making of the adverse determination to a licensed physician of the same or similar specialty; Rhode Island reserves the making, the DOCUMENTING and the SIGNING, and matches to the ordering provider's licensure status. No AI system can make, document or sign such a determination. § 27-18.9-5(b)(3) separately bars retrospective denial of an already-authorized service unless the approval rested on materially inaccurate information. STANDING NEGATIVE, recorded because it is a near-miss that will return: the Transparency and Accountability in Artificial Intelligence Use by Health Insurers to Manage Coverage and Claims Act (S 2010 of 2026) — which would have required disclosure of model types, training datasets, performance metrics and governance policies to DBR and OHIC, five-year retention of AI-influenced decisions, and qualified-professional review of any AI adverse benefit determination — passed the SENATE 38-0 on June 9, 2026 and went no further; the House never took it up and companion H 7190 never left committee. It is NOT law, and secondary summaries describing its requirements in the present tense are describing a bill. Its sponsor has said she will reintroduce it.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

March 15, 2024

Maximum Penalty

Rhode Island's insurance penalties are shaped so that the first instance of an AI-driven unfair practice draws an ORDER, not a fine — the money arrives only on defiance, and it arrives through a court. Under R.I. Gen. Laws § 27-29-9(a) a person who violates a cease and desist order of the insurance commissioner issued under § 27-29-6, after it has become final and while it is in effect, "shall, upon proof of the violation to the satisfaction of the court, forfeit and pay to the state" a sum not to exceed $25,000, recoverable in a CIVIL ACTION — rising to not more than $250,000 where the violation is found to be willful. § 27-29-9(b) adds discretionary suspension or revocation of the insurer's licence after notice and hearing. There is no first-instance per-violation fine attached to the underlying unfair method of competition itself. The rating chapter is the opposite shape and is the more dangerous one for a model deployed at scale: § 27-44-18(a) lets the director impose up to $1,000 for EACH violation of the chapter, or up to $50,000 for each violation found to be willful, expressly "in addition to any other penalty provided by law"; § 27-44-18(b) provides that an insurer using a rate for which it failed to file the rate, supplementary rate information or supporting information "has committed a separate violation for each day that failure continues", so an unfiled model-derived rating element accrues daily; § 27-44-18(c) permits suspension or revocation of the licence of any rating organization or insurer that fails to comply with an order; and § 27-44-18(e) requires that no penalty be imposed and no licence suspended or revoked except upon a written order stating the director's findings, made after a hearing. Utilization review carries no bespoke figure: § 27-18.9-14 routes healthcare entities and review agents to "the penalty and enforcement provisions of title 27 and chapters 14 and 14.5 of title 42", in the same manner as a licensee. Bulletin 2024-03 imposes no penalty of its own — it is guidance whose sanctions arrive through the Unfair Competition and Practices Act (chapter 27-29), the Unfair Claims Settlement Practices Act (chapter 27-9.1), the Rating Laws, examination authority under chapter 27-13.1 and market conduct actions under chapter 27-71.

What Your Business Must Do

11 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

The Rating Laws — AI-Derived Rates Must Not Be Excessive, Inadequate or Unfairly Discriminatory (and A&H Is Excluded)

Critical

The bulletin defines "the Rating Laws" as all Rhode Island insurance laws and regulations regarding rates, rating plans, rating rules, practices and standards, and states that their requirements apply REGARDLESS of the methodology used to develop rates, rating rules and rating plans — so an insurer is responsible for assuring that rates developed using AI techniques and Predictive Models that rely on data and Machine Learning do not produce excessive, inadequate or unfairly discriminatory rates. The operative standards under R.I. Gen. Laws § 27-44-5 are specific enough to test a model against: a rate is EXCESSIVE if it is likely to produce an underwriting profit that is unreasonably high for the class of business, or if expenses are unreasonably high in relation to services rendered, with evidence of a reasonable degree of competition in the relevant classification treated as material evidence that a rate is not excessive; a rate is INADEQUATE only if clearly insufficient to sustain projected losses and expenses in the class and its use has or would have the effect of substantially lessening competition or tending to create monopoly; and UNFAIR DISCRIMINATION exists if, after allowing for practical limitations, price differentials fail to reflect equitably the differences in expected losses and expenses — rates are not unfairly discriminatory merely because different premiums result for policyholders with like loss exposures but different expense factors, or like expense factors but different loss exposures, so long as the rates reflect those differences with reasonable accuracy. That last formulation is the one a model must satisfy: the differential has to be explainable as expected loss or expense, which is precisely what an unexplainable feature interaction cannot supply. SCOPE, AND THE POINT MOST PROGRAMMES GET WRONG: § 27-44-3(a) excludes eight classes from the chapter outright — life insurance, annuities, ACCIDENT AND HEALTH INSURANCE, ocean marine insurance, reinsurance, medical malpractice insurance, workers' compensation insurance, and insurance through residual market mechanisms — and § 27-44-3(b) redirects those classes to chapters 6, 7.1, 9, 19 and 20 of title 27 and chapter 62 of title 42. The bulletin's own rating paragraph closes on a matching property/casualty line list, extending to all forms of casualty insurance including fidelity, surety and guaranty bond, and all forms of property insurance including fire, marine and inland marine. An accident and health insurer therefore takes nothing from this limb and must look to § 27-29-4(7)(ii) instead. The bulletin also cites §§ 27-6-4 (fire and marine) and 27-9-4 (casualty), and § 27-7.1-4.1 for workers' compensation.

Deadline: March 15, 2024

R.I. Gen. Laws § 27-44-5 (rate standards), § 27-44-3 (scope of application and exclusions), § 27-44-18 (penalties), §§ 27-6-4, 27-9-4 and 27-7.1-4.1; applied to AI-derived rates by DBR Insurance Bulletin Number 2024-03, Section 1.B.3

§ 27-29-4(7) — Unfair Discrimination, and the Only Limb That Reaches Accident and Health

Critical

Rhode Island added this citation to the NAIC model on its own initiative — it appears nowhere in the model bulletin — and it matters more than its brevity suggests, because it is the route by which AI rating discipline reaches health lines that § 27-44-3(a) excludes from the rating chapter. § 27-29-4(7)(i) makes it an unfair method of competition or unfair or deceptive act to make or permit any unfair discrimination between individuals of the same class and equal expectation of life in the rates charged for any policy of life insurance or life annuity, in the dividends or other benefits payable, or in any other of the terms and conditions of the policy. § 27-29-4(7)(ii) does the same for individuals of the same class and of essentially the same hazard in the amount of premium, policy fees or rates charged for any policy or contract of ACCIDENT OR HEALTH insurance, or in the benefits payable under any policy or contract, or in any of its terms or conditions, "or in any other manner" — a catch-all that reaches practices which are not literally pricing. Applied to AI, the test is the same one that defeats an unexplainable model elsewhere: two insureds of the same class and essentially the same hazard must not be treated differently, and a model output is not a justification for the difference unless it maps onto the hazard. The bulletin's Section 1.B.1 pairs this with the two acts it names in full — the Unfair Competition and Practices Act, § 27-29-1 et seq., which defines and prohibits unfair methods of competition and unfair or deceptive acts and practices, and the Unfair Claims Settlement Practices Act, § 27-9.1-1 et seq., which sets standards for the investigation and disposition of claims arising under policies or certificates issued to Rhode Island residents — and states that actions taken by insurers in the state "must avoid violating" both, regardless of the methods the insurer used to determine or support its actions. Note the enforcement shape, because it is unusual and it changes how exposure should be modelled: nothing in chapter 27-29 attaches a first-instance per-violation fine to the underlying unfair practice. The commissioner proceeds by cease and desist order under § 27-29-6, and the money in § 27-29-9 attaches only to violating that order once final — and is recovered by the state in a civil action rather than assessed administratively.

Deadline: March 15, 2024

R.I. Gen. Laws § 27-29-4(7)(i)-(ii) (unfair discrimination in life, annuity and accident or health insurance), § 27-29-1 et seq. (Unfair Competition and Practices Act), § 27-9.1-1 et seq. (Unfair Claims Settlement Practices Act), §§ 27-29-6 and 27-29-9; cited by DBR Insurance Bulletin Number 2024-03, Sections 1.B.1 and 1.B.3

Bulletin 2024-8 — Third-Party Vehicle History SCORES Deemed Unlawful Where They Count Non-Chargeable or Stale Losses

Critical

This is the harder-edged sibling of the AI bulletin and it is easy to miss, because it never uses the words "artificial intelligence" while doing precisely what an AI bulletin would do: declaring a class of third-party model output unlawful on its face. The Department states that it is aware some insurers are using various types of vehicle history SCORES in rating private passenger automobile policies, and reminds them of 230-RICR-20-05-3 (Automobile Insurance Rating) § 3.7, which provides that no insurer shall charge a higher premium as a result of any loss for which a surcharge is prohibited by R.I. Gen. Laws §§ 27-9-4 and 27-9-53 or by § 3.8 of that Part; that no insurer shall use a prior carrier type (standard, non-standard or preferred) for placing an insured into a tier or company or for discount and surcharge programs; and that no insurer may establish a premium surcharge or penalty, remove a discount, decline an award of credits, tier or re-tier, place an insured with a member insurer, or otherwise alter premium for any loss other than a Chargeable Accident or Moving Violation — including that insurers may not establish "loss free discounts" or tiers taking into account losses which are not Chargeable Accidents or Moving Violations, or which occurred more than THREE YEARS prior to the policy effective date. The Department then states that some vehicle history scores in use include losses failing those criteria, and that "any rating program that utilizes such a factor is deemed to be in violation of the RI Rating statutes and regulations and insurers should cease using those scores". The remedial obligation was mandatory and dated: any insurer using a non-compliant score "must submit a filing to the Division via SERFF removing the non-compliant elements no later than November 30, 2024", and "these non-compliant rating elements shall not be included in future filings". The transition date has passed; the forward-looking bar on future filings is continuing and is what binds a model built today. Practical consequence for an AI rating programme: a bought vehicle-history or claims-history score cannot be used as a rating, tiering or discount feature for Rhode Island private passenger auto risks unless the insurer can demonstrate that every loss contributing to the score is a Chargeable Accident or Moving Violation within the three-year lookback — and because the score is supplied by a vendor, that demonstration requires the vendor to expose the score's constituent events, which is exactly the diligence and audit-rights posture Bulletin 2024-03 Guideline D asks for.

Deadline: November 30, 2024

Rhode Island DBR Insurance Bulletin Number 2024-8, "Vehicle History Used in Private Passenger Automobile Insurance Rating" (September 9, 2024, Superintendent Elizabeth Kelleher Dwyer), quoting 230-RICR-20-05-3 § 3.7 and citing R.I. Gen. Laws §§ 27-9-4 and 27-9-53

Bulletin 2025-3 — Aerial and Satellite Imagery in Homeowners Underwriting and Claims, Extended to Third-Party Roof Scores

Critical

The Department's most recent and most concretely testable constraint on machine-derived underwriting evidence, issued seventeen months after the AI bulletin and considerably harder in voice. It applies to the use of aerial imagery, including satellite imagery, in the underwriting of homeowners policies and the settlement of claims, and expressly reaches the initial consideration of risks, the TIERING of risks, the NON-RENEWAL of policies, and the determination of causes and amounts of loss. The Department states it is aware that some insurers are non-renewing or refusing to write Rhode Island homeowners policies based on property characteristics identified through aerial imaging. While it does not seek to restrict aerial imagery as part of an underwriting toolkit, it must be used responsibly, and the standards are specific: images used to evaluate a property risk "must provide a clear, accurate, and current (less than 15 months old) view of the property"; images that are low-resolution, out-of-focus, blurry or not current do not provide an accurate and clear representation and thus "cannot alone justify a cancellation or nonrenewal based on the condition of the property without further investigation"; aerial images of a roof showing only COSMETIC damage such as streaking or discoloration, without functional or structural damage, "are not sufficient to independently support cancellation or nonrenewal based on roof degradation"; and to justify underwriting action "there must be clear evidence of significant material degradation or damage that increases the risk of loss". Where inconclusive imagery creates concerns, the insurer should obtain recent, clear information through a physical inspection or otherwise. The Department states its position that failure to follow these guidelines "may constitute an unfair trade practice under R.I. Gen Laws Chapter 27-29". Where imagery is used in CLAIM SETTLEMENT the same currency and clarity standards apply, and images failing them "cannot alone be used to determine a claim settlement or denial", with failure potentially constituting a violation of the Unfair Claims Settlement Practices Act. A consumer-facing layer is stated as best practice rather than obligation: notify the homeowner before initiating nonrenewal, provide copies of any aerial images used, allow the homeowner to provide updated information or dispute the accuracy of the imagery, and issue loss control recommendations with reasonable time to make repairs before taking other action. THE CLAUSE THAT MATTERS MOST FOR AI: the Department closes by reminding insurers that the bulletin applies "not only to their direct use of aerial imagery, but also the use of any third-party roof scores or similar mechanism that leverage aerial imagery to generate the information provided to the insurer". A purchased roof score derived from imagery inherits every one of these standards, including the 15-month currency limit and the cosmetic-damage exclusion.

Deadline: August 18, 2025

Rhode Island DBR Insurance Bulletin Number 2025-3, "Aerial Imagery Used by Homeowners Insurers" (August 18, 2025, Superintendent Elizabeth Kelleher Dwyer); enforcement hooks stated in the bulletin at R.I. Gen. Laws chapter 27-29 (Unfair Competition and Practices) and chapter 27-9.1 (Unfair Claims Settlement Practices Act)

§ 27-18.9-5(b)(1) — Adverse Benefit Determinations Must Be Made, DOCUMENTED and SIGNED by a Same-Licensure Practitioner

Critical

Rhode Island has no AI-specific utilization review statute — a term sweep of the Benefit Determination and Utilization Review Act, chapter 27-18.9, returns no occurrence of "artificial intelligence", "algorithm", "automated" or "machine learning" — but § 27-18.9-5(b)(1) imposes a reservation that is functionally stronger than the District of Columbia's and that no automated system can satisfy. All initial, prospective and concurrent non-administrative ADVERSE benefit determinations of a healthcare service that had been ordered by a physician, dentist or other practitioner "shall be made, documented, and signed by a licensed practitioner with the same licensure status as the ordering provider". Three elements each independently exclude an AI system from the decision: the determination must be MADE by the licensed practitioner, it must be DOCUMENTED by that practitioner, and it must be SIGNED by that practitioner — and the practitioner must match the ORDERING PROVIDER'S LICENSURE STATUS, which is a parity requirement rather than a general clinical-qualification requirement. Compare the District of Columbia, whose § 31-3875.06(a)(1) reserves the making of the adverse determination to a licensed physician of the same or similar specialty: Rhode Island reserves two further acts and ties the match to licensure status. An AI system may therefore support triage, surface guideline criteria, flag cases and prepare materials, but the adverse determination itself, its documentation and its signature must be a human licensed practitioner's. Two adjacent constraints in the same subsection. § 27-18.9-5(b)(2) preserves the ability of appropriately qualified review agency staff to discuss alternative service or treatment options with the attending provider and states that such a discussion does not constitute an adverse benefit determination — but any change to the attending provider's original order, or any decision for an alternative level of care, must be made by or appropriately consented to by the attending provider or their designee and must be documented by the review agent. § 27-18.9-5(b)(3) provides that a utilization review agent shall not RETROSPECTIVELY deny authorization for healthcare services once an authorization has been obtained, unless the approval was based upon inaccurate information material to the review or the services were not provided consistent with the submitted plan of care or the restrictions in the prior approval — which forecloses the common pattern of a later automated audit reversing an earlier approval. Internal and external appeal procedures sit at §§ 27-18.9-7 and 27-18.9-8; note for anyone working from a stale pointer that Rhode Island has no chapter 27-18.10, and external appeal lives inside chapter 27-18.9 itself.

Deadline: March 15, 2024

R.I. Gen. Laws § 27-18.9-5(b)(1)-(3) (utilization review agent procedural requirements), with internal and external appeal procedures at §§ 27-18.9-7 and 27-18.9-8 and enforcement at §§ 27-18.9-13 and 27-18.9-14

Bulletin 2024-03 — Written AI Systems (AIS) Program for Every Authorized Rhode Island Insurer

High Priority

All insurers authorized to do business in Rhode Island are EXPECTED to develop, implement and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make, or support decisions related to, regulated insurance practices. Note the normativity, because Rhode Island did not weaken it: the bulletin keeps the NAIC model's "are expected to" rather than downgrading it to a recommendation. The programme must be designed to mitigate the risk of Adverse Consumer Outcomes — defined as a decision by an insurer subject to insurance regulatory standards enforced by the Department that adversely impacts the consumer in a manner that violates those standards — including at a minimum the statutory provisions set out in Section 1. Rhode Island BROADENED the model here: where the model measures compliance against "unfair trade practice laws", Section 3 of this bulletin requires compliance with "the Unfair Competition and Practices Act and the Unfair Claims Settlement Practices Act and the Rating Laws", and states that robust governance mitigates the risk that AI-driven decisions "will violate any applicable insurance laws and regulations". Controls and processes must be reflective of and commensurate with the insurer's own assessment of the degree and nature of risk posed to consumers, weighing five stated factors: the nature of the decisions being made, informed or supported using the AI System; the type and Degree of Potential Harm to Consumers; the extent to which humans are involved in the final decision-making process; the transparency and explainability of outcomes to the impacted consumer; and the extent and scope of the insurer's use or reliance on data, Predictive Models and AI Systems from third parties. The programme must span the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, fraud detection) and the whole AI life cycle (design, development, validation, implementation of both systems and business, use, ongoing monitoring, updating, retirement), and must cover AI Systems whether developed in-house or by a third-party vendor. It may sit inside or outside the enterprise risk management programme and may adopt or rely upon a third-party framework such as the NIST Artificial Intelligence Risk Management Framework, Version 1.0.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, "Use of Artificial Intelligence Systems by Insurers" (March 15, 2024, Superintendent Elizabeth Kelleher Dwyer), Section 3 and Artificial Intelligence System Program Guidelines A.1-A.8; definitions at Section 2

Bulletin 2024-03 — Board-Accountable AI Governance Framework and Documented Decision Hierarchy

High Priority

Vest responsibility for the development, implementation, monitoring and oversight of the AIS Program — and for setting the insurer's strategy for AI Systems — in senior management accountable to the board or an appropriate committee of the board. The governance framework should prioritise transparency, fairness and accountability in the design and implementation of AI Systems, recognising that proprietary and trade secret information must be protected; the insurer may adopt new internal governance structures or rely on existing ones. The framework should address: the policies, processes and procedures, including risk management and internal controls, to be followed at each stage of an AI System life cycle from proposed development to retirement; the requirements adopted by the insurer to DOCUMENT compliance with the AIS Program policies, processes, procedures and standards, with the express instruction that documentation requirements "should be developed with Section 4 in mind" — a pointed instruction in Rhode Island, because the state retained Section 4's itemised production list in full; and the internal AI System governance accountability structure, covering the formation of centralized, federated or otherwise constituted committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of responsibility and authority, chains of command and decisional hierarchies; the independence of decision-makers and lines of defence at successive stages of the AI System life cycle; monitoring, auditing, escalation and reporting protocols; and the development and implementation of ongoing training and supervision of personnel. Specifically as to Predictive Models, the framework should cover the processes and procedures for designing, developing, verifying, deploying, using, updating and monitoring them, including a description of the methods used to detect and address errors, performance issues, outliers or unfair discrimination in the insurance practices resulting from the model's use. This governance layer is not free-standing: the bulletin states that the Corporate Governance Annual Disclosure Act, R.I. Gen. Laws § 27-1.2-1 et seq., and the Corporate Governance Regulation, 230-RICR-20-40-11, apply to the elements of the insurer's corporate governance framework that address its use of AI Systems, so the AI governance structure is reportable through the existing CGAD filing rather than only on examination.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, Program Guidelines A.2, A.3 and B.1-B.4 (Governance), read with Section 1.B.2 and R.I. Gen. Laws § 27-1.2-1 et seq. and 230-RICR-20-40-11

Bulletin 2024-03 — Risk Management, Internal Controls, Model Drift Testing and Data Practices

High Priority

The AIS Program should document the insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each stage of the AI System life cycle. The bulletin asks that these address: the oversight and approval process for the development, adoption or acquisition of AI Systems, together with the identification of constraints and controls on automation and design to align and balance function with risk; data practices and accountability procedures, including data currency, lineage, quality, integrity, BIAS ANALYSIS AND MINIMIZATION, and suitability; the management and oversight of Predictive Models including the algorithms used within them; validating, testing and retesting as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model; the protection of non-public information, particularly consumer information, including unauthorized access to the Predictive Models themselves; and data and record retention. The Department separately "encourages the development and use of verification and testing methods to identify errors and bias in Predictive Models and AI Systems, as well as the potential for unfair discrimination in the decisions and outcomes resulting from" their use. MODEL DRIFT is a defined term in Section 2 — "the decay of a model's performance over time arising from underlying changes such as the definitions, distributions, and/or statistical properties between the data used to train the model and the data on which it is deployed" — and Section 4 tells insurers that documentation of validation, testing and auditing INCLUDING EVALUATION OF MODEL DRIFT will be requested, so drift monitoring is not optional in practice even though the guideline voice is "should". An honest caution inherited from the NAIC model and reproduced in Rhode Island: "Data Currency" is capitalised as though defined and is used in Section 4, but it appears nowhere in the Section 2 definitions. It is undefined in the instrument.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, Program Guidelines C.1-C.7 (Risk Management and Internal Controls) and Section 3 paragraph on verification and testing methods; "Model Drift" defined at Section 2

Bulletin 2024-03 — Third-Party AI and Data: Diligence, Audit Rights, Regulator Cooperation (Broadened Definition)

High Priority

Each AIS Program should address the insurer's process for acquiring, using or relying on third-party data to develop AI Systems and on AI Systems developed by a third party. Record the definitional broadening, because it widens the population caught: the NAIC model defines "Third Party" as "an ORGANIZATION other than the Insurer that provides services, data, or other resources related to AI"; Rhode Island substitutes "an ENTITY other than the Insurer". The bulletin contemplates: due diligence and the methods employed by the insurer to assess the third party and its data or AI Systems, so that decisions made or supported by them which could lead to Adverse Consumer Outcomes will meet the legal standards imposed ON THE INSURER ITSELF — the vendor's own compliance posture is not a defence, and the sentence is stated flatly rather than hedged; where appropriate and available, the inclusion of contract terms providing audit rights and/or entitling the insurer to receive audit reports by qualified auditing entities, and requiring the third party to COOPERATE with the insurer in regulatory inquiries and investigations relating to the insurer's use of the third party's products or services; and the actual PERFORMANCE of those contractual audit rights and other activities to confirm the third party's compliance with contractual and, where applicable, regulatory requirements. Read the qualifier honestly: the audit-rights and cooperation clauses are conditioned on being "where appropriate and available", so no specific clause is mandated — but the diligence standard, and the expectation that the insurer actually exercises rather than merely holds its audit rights, are not so qualified. Rhode Island retained Section 4 item B.2, which tells insurers that their vendor CONTRACTS will be requested on examination including the terms relating to cooperation with regulators, so the contractual position is discoverable. Note the interaction with Bulletin 2025-3, which extends its aerial-imagery standards to "any third-party roof scores or similar mechanism", and with Bulletin 2024-8, which deems non-compliant third-party vehicle history scores a violation of the rating statutes: in both cases Rhode Island has already applied the principle that a bought score is the insurer's responsibility.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, Program Guidelines A.8 and D.1-D.3 (Third-Party AI Systems and Data), read with Section 4 items B.1-B.4 and the Section 2 definition of "Third Party"

Bulletin 2024-03 Guideline A.9 — Notice to Impacted Consumers That AI Systems Are in Use

High Priority

Include in the AIS Program processes and procedures providing notice to impacted consumers that AI Systems are in use, and providing access to appropriate levels of information based on the phase of the insurance life cycle in which the AI Systems are being used. Scope the disclosure to the life-cycle phase — marketing, underwriting, rating and pricing, case management, claim administration — rather than publishing one generic notice, because the guideline expressly ties the level of information to the phase. Recorded precisely: Rhode Island adopted the model's plain wording here and, like the District of Columbia, did NOT add the word "free", so the bulletin does not on its face bar an insurer from attaching a cost to the information. An access fee would nonetheless be exposed under chapter 27-29 if it operated to make the disclosure illusory. Read this guideline together with the two data-specific bulletins, which convert the same instinct into concrete practice for the lines they cover: Bulletin 2025-3 states that where an insurer uses aerial imagery as a basis for nonrenewal it is best practice to notify the homeowner BEFORE initiating the nonrenewal action, to provide the homeowner with copies of any aerial images used, and to allow the homeowner to provide updated information or dispute the accuracy of the imagery. That is a model-output disclosure and contest right in all but name, and it is the clearest published indication of what the Department expects "access to appropriate levels of information" to mean in practice.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, Program Guideline A.9 (notice to impacted consumers and access to appropriate levels of information); compare Bulletin 2025-3 (August 18, 2025) on pre-nonrenewal notice, provision of images and dispute opportunity

Bulletin 2024-03 Section 4 — The Itemised Document List Rhode Island Retained in Full

High Priority

Rhode Island kept the model's Section 4 production schedule intact, so the list of what a Rhode Island examiner will ask for is published and can be prepared against directly — unlike West Virginia, which told insurers they would be asked but deleted the schedule of what would be asked for. Regardless of the existence or scope of a written AIS Program, an insurer can expect to be asked about its development, deployment and use of AI Systems, or about any specific Predictive Model, AI System or application and its outcomes including Adverse Consumer Outcomes. Expect requests for: the written AIS Program itself; documentation evidencing its ADOPTION; the SCOPE of the programme, expressly including any AI Systems and technologies NOT included in or addressed by it — so a narrow scope is itself a disclosable fact rather than a way of avoiding the inquiry; how the programme is tailored to and proportionate with the insurer's use and reliance on AI Systems, the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers; policies, procedures, guidance and TRAINING MATERIALS relating to adoption, implementation, maintenance, monitoring and oversight, including the processes for development, adoption or acquisition of AI Systems, data governance and controls covering lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, the measurements, standards or THRESHOLDS used in managing and overseeing Predictive Models, and protection of non-public information including unauthorized access to the models; pre-acquisition and pre-use diligence, monitoring, oversight and auditing of third-party data or AI Systems; documentation evidencing implementation of and compliance with the programme, including the formation and ongoing operation of coordinating bodies, data practices and accountability procedures, and the insurer's INVENTORIES and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes; as to any specific model under investigation, documentation of compliance with all applicable policies, information about the data used including source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, and information on the techniques, measurements, thresholds and similar controls used; and documentation pertaining to validation, testing and auditing including evaluation of MODEL DRIFT. Two honest cautions. First, the bulletin's closing states that its goal is not to prescribe specific practices or documentation requirements and that insurers may demonstrate compliance through alternative means — so the list is the Department's expectation of what it will request, not a mandated filing. Second, Rhode Island localised the closing sentence: where the model refers only to the NAIC's Market Regulation Handbook, the bulletin states that work performed may include any of the continuum of market actions described in "R.I. Gen. Laws § 27-71-1 et seq. or the NAIC's Market Regulation Handbook" — adding a statutory hook the model does not have.

Deadline: March 15, 2024

Rhode Island DBR Insurance Bulletin Number 2024-03, Section 4 (Regulatory Oversight and Examination Considerations) items A.1-A.3 and B.1-B.4 and closing paragraphs; examination authority at R.I. Gen. Laws § 27-13.1-1 et seq.; market conduct continuum at § 27-71-1 et seq.

Recent Regulatory Guidance

guidance2025-08-18

DBR Insurance Bulletin 2025-3 — Aerial Imagery Used by Homeowners Insurers

Sets currency (less than 15 months), resolution and clarity standards for aerial and satellite imagery used in homeowners underwriting, tiering, non-renewal and claim settlement; bars cosmetic-only roof findings from independently supporting nonrenewal; and extends every standard to third-party roof scores derived from imagery. Enforcement stated through chapter 27-29 and the Unfair Claims Settlement Practices Act.

guidance2024-09-09

DBR Insurance Bulletin 2024-8 — Vehicle History Used in Private Passenger Automobile Insurance Rating

Deems any rating program using a vehicle history score that counts losses other than Chargeable Accidents or Moving Violations, or losses outside the three-year lookback, to be in violation of the Rhode Island rating statutes and 230-RICR-20-05-3 § 3.7; required a corrective SERFF filing by November 30, 2024 and bars the elements from future filings.

guidance2025-01-01

DBR Insurance Bulletin 2025-01 — Implementation of Insurance Data Security Statute

Listed in the DBR insurance bulletin directory alongside the AI bulletin and relevant to the non-public information and model-access controls that Bulletin 2024-03 Guideline C.5 asks the AIS Program to address. Recorded from the directory listing; its full text was not read this session, so no requirement has been derived from it.

Frequently Asked Questions

Does Rhode Island — DBR Insurance Bulletin 2024-03 (NAIC AI Model, Verbatim-Plus-BROADENED) + Vehicle History Score Ban (2024-8) + Aerial Imagery Underwriting Rules (2025-3) + UR Same-Licensure Signature Reservation (§ 27-18.9-5(b)(1)) apply to my business?

Rhode Island has no comprehensive private-sector AI statute (the "Artificial Intelligence Act", S 0627 of 2025, died in committee — held for further study on May 12, 2025), but it regulates AI in INSURANCE, and the instrument most compliance… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Rhode Island — DBR Insurance Bulletin 2024-03 (NAIC AI Model, Verbatim-Plus-BROADENED) + Vehicle History Score Ban (2024-8) + Aerial Imagery Underwriting Rules (2025-3) + UR Same-Licensure Signature Reservation (§ 27-18.9-5(b)(1)) is: Rhode Island's insurance penalties are shaped so that the first instance of an AI-driven unfair practice draws an ORDER, not a fine — the money arrives only on defiance, and it arrives through a court. Under R.I. Gen. Laws § 27-29-9(a) a person who violates a cease and desist order of the insurance commissioner issued under § 27-29-6, after it has become final and while it is in effect, "shall, upon proof of the violation to the satisfaction of the court, forfeit and pay to the state" a sum not to exceed $25,000, recoverable in a CIVIL ACTION — rising to not more than $250,000 where the violation is found to be willful. § 27-29-9(b) adds discretionary suspension or revocation of the insurer's licence after notice and hearing. There is no first-instance per-violation fine attached to the underlying unfair method of competition itself. The rating chapter is the opposite shape and is the more dangerous one for a model deployed at scale: § 27-44-18(a) lets the director impose up to $1,000 for EACH violation of the chapter, or up to $50,000 for each violation found to be willful, expressly "in addition to any other penalty provided by law"; § 27-44-18(b) provides that an insurer using a rate for which it failed to file the rate, supplementary rate information or supporting information "has committed a separate violation for each day that failure continues", so an unfiled model-derived rating element accrues daily; § 27-44-18(c) permits suspension or revocation of the licence of any rating organization or insurer that fails to comply with an order; and § 27-44-18(e) requires that no penalty be imposed and no licence suspended or revoked except upon a written order stating the director's findings, made after a hearing. Utilization review carries no bespoke figure: § 27-18.9-14 routes healthcare entities and review agents to "the penalty and enforcement provisions of title 27 and chapters 14 and 14.5 of title 42", in the same manner as a licensee. Bulletin 2024-03 imposes no penalty of its own — it is guidance whose sanctions arrive through the Unfair Competition and Practices Act (chapter 27-29), the Unfair Claims Settlement Practices Act (chapter 27-9.1), the Rating Laws, examination authority under chapter 27-13.1 and market conduct actions under chapter 27-71.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Rhode Island — DBR Insurance Bulletin 2024-03 (NAIC AI Model, Verbatim-Plus-BROADENED) + Vehicle History Score Ban (2024-8) + Aerial Imagery Underwriting Rules (2025-3) + UR Same-Licensure Signature Reservation (§ 27-18.9-5(b)(1))?

The 11 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://dbr.ri.gov/bulletinsguidance-documentsnotices-insurance

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan