Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
US-DCMEDIUM coverage

District of Columbia — DISB Bulletin 24-IB-002-05/21 (NAIC AI Model, Verbatim) + Price Optimization Ban 15-IB-06-8/15 + Prior Authorization Act (D.C. Law 25-100) + UITPA Rating Discrimination Bar: AI Compliance Requirements

The District of Columbia has no comprehensive private-sector AI statute — the recurring "Stop Discrimination by Algorithms Act" has never been enacted (see the standing-negative note below) — but it does regulate AI in INSURANCE, and it does so through a bulletin adopted word-for-word from the national model plus a set of older, harder-edged rating rules that most AI programmes overlook. (1) AI SYSTEMS — DISB Bulletin 24-IB-002-05/21 (May 21, 2024, Commissioner Karima M. Woods) adopts the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers VERBATIM. Diffed mechanically against the model this session, DC softened nothing (the normativity counts are identical on both sides, and the words "recommends", "suggests" and "ideally" appear nowhere), added no state-authored expectation, and — unlike West Virginia — KEPT the model's entire Section 4 itemised production list, so DC insurers have been told not merely that they will be asked about their AI but exactly which documents will be requested. Its one real deletion is structural: the model's separate unfair-claims-settlement bullet is folded into the District's single UITPA citation, because DC codifies unfair claim settlement practices inside its unfair-trade-practices chapter at § 31-2231.17. Where the model leaves blank citation brackets, DC filled every one. (2) ALGORITHMIC PRICING — the genuinely mandatory surface is DISB Bulletin 15-IB-06-8/15 (August 25, 2015), which BANS price optimization: charging like risks different premiums because of characteristics that "bear no relationship to the risk of loss and estimated expenses", such as a policyholder's modelled willingness to absorb an increase. It is written in obligatory voice — insurers "shall cease such practice", "every insurer shall ensure that no future filings utilize price optimization in any manner" — and it expressly reaches the practice however it is implemented, "directly or indirectly through methods including, but not limited to, tier placement, risk classification systems, underwriting, relativity factors, surcharges, fees". Any model trained on renewal-acceptance or shopping behaviour collides with it. (3) RATING DISCRIMINATION — D.C. Code § 31-2231.13(c) bars unfair discrimination between property "having like insuring or risk characteristics", and § 31-2231.13(d) goes further than any comparable provision in this vein: it prohibits any differential in ratings, premium payments or dividends based on marital status, race, colour, PERSONAL APPEARANCE, sexual orientation, gender identity or expression, matriculation, or political affiliation UNLESS there is actuarial justification. "Personal appearance" is a District-specific protected class with no analogue in the other NAIC-adopting states, and it bites directly on image-derived model features. (4) RATE SCOPE — the P&C rating chapter (§§ 31-2701 to 31-2714) requires AI-derived rates to be not excessive, inadequate or unfairly discriminatory, but § 31-2702(3) excludes accident and health insurance entirely; A&H is ROUTED to Chapter 33A instead, where § 31-3311.04 imposes an annual file-and-approve gate and § 31-3311.01 supplies a different substantive test built around medical loss ratios. (5) HEALTH PLANS — the Prior Authorization Reform Amendment Act (D.C. Law 25-100, effective January 17, 2024, codified at §§ 31-3875.01 to 31-3875.10) is the strongest AI constraint the District has enacted, and it is stronger than West Virginia's: § 31-3875.06(a)(1) requires that an ADVERSE DETERMINATION ITSELF — not merely the appeal — be made by a licensed physician of the same or similar specialty, and § 31-3875.03(c)(1) forces the denial notice to disclose that individual's licensing states, licence status and specialty. A fully automated first-instance denial cannot satisfy either. (6) GOVERNANCE — the Insurer Corporate Governance Annual Report Act (§§ 31-331 to 31-338) requires a CGAD by JUNE 1 each year carrying a CEO or corporate-secretary attestation, and the bulletin states that CGAD reaches the governance framework around AI use. STANDING NEGATIVE, verified this session against the Council's own LIMS rather than any aggregator: the Stop Discrimination by Algorithms Act exists in exactly two versions in the entire legislative record — B24-0558 (introduced December 9, 2021) and B25-0114 (introduced February 2, 2023, whose last recorded action is the February 10, 2023 notice of intent) — both of which LIMS marks with a dead status, and NEITHER was reintroduced in the 26th Council. It has never been law, and as of August 26, 2026 no successor is pending.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 21, 2024

Maximum Penalty

The District's insurance penalties are unusually LOW and unusually INDIRECT, and this should be read as a warning about the shape of the exposure rather than its size. Under D.C. Code § 31-2231.22 the Commissioner MAY (not shall) issue an order to cease and desist and to correct the violation, including restitution of money or property to the person aggrieved; a civil penalty of up to $1,000 per violation becomes available only where the violator FAILS TO COMPLY with that order — there is no first-instance fine. The real teeth are elsewhere in the same section: the Commissioner may suspend or revoke the licence or certificate of authority of a person that violates the chapter, a rule under it, or an order, with no knowledge predicate; and the Commissioner may refer the matter to the Attorney General for the District of Columbia, who may seek in the Superior Court "damages and other relief allowed by law, including restitution" and may be awarded the District's attorney's fees and costs. Before setting any monetary figure the Commissioner SHALL consider six statutory factors (§ 31-2231.22(d)): the seriousness of the violation, the good faith of the violator, the violator's history of previous violations, the deleterious effect on the public and the insurance industry, the assets of the violator, and any other relevant factor — a systemic, model-driven violation scores badly on the first and fourth. Prior-authorization violations under §§ 31-3875.01 to 31-3875.10 carry a distinctive non-monetary sanction that is often the costlier one: § 31-3875.08(a) provides that ANY failure to comply results in the health care service in question being DEEMED APPROVED, and § 31-3875.08(b) provides that a pattern or practice of repeated violations constitutes a violation of the unfair-trade-practices chapter, routing it back into § 31-2231.22. Bulletin 24-IB-002-05/21 imposes no penalty of its own — it is guidance whose sanctions arrive through the UITPA and the market-conduct process under §§ 31-1401 to 31-1407.

What Your Business Must Do

14 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

DISB Bulletin 15-IB-06-8/15 — Price Optimization Is BANNED: No Demand-Elasticity Features Anywhere in a Rating Model

Critical

This is the District's hardest algorithmic-pricing rule and the one most likely to be missed, because it predates the AI bulletin by nine years, is not mentioned in it, and exists only as a scanned image PDF that text search does not reach. It was located by sweeping the DISB bulletin directory and read by rendering the pages. The Department defines price optimization as "an insurer's practice of charging the maximum premium that it expects an individual or class of individuals to bear, based upon factors that are neither risk of loss related nor estimated expense related" — for example charging a non-price-sensitive individual more than a price-sensitive one despite equal risk characteristics — and states flatly that "this practice is discriminatory and it violates the District's anti-discrimination insurance laws". The mandatory language is unambiguous: any insurer using price optimization "shall cease such practice", and "every insurer shall ensure that no future filings utilize price optimization in any manner". Critically for model builders, the ban is method-agnostic and reaches indirect implementations: "adjusting rates directly or indirectly through methods including, but not limited to, tier placement, risk classification systems, underwriting, relativity factors, surcharges, fees, without regard to the risk of loss and estimated expenses, is a violation of D.C. Official Code § 31-2703(b)", and "charging different premiums to like risks or risk classes due wholly or in part to characteristics that bear no relationship to the risk of loss and estimated expenses is unfairly discriminatory". Note "wholly or IN PART" — a model does not escape by blending an elasticity signal with genuine risk signals. The Department expressly identified the offending data type as behavioural rather than actuarial: "how a policyholder has responded to rate increases in prior years", used "to project the policyholder's expected willingness to pay increased premiums". Practical consequence for an AI rating programme: renewal-acceptance history, shopping and quote-comparison behaviour, churn propensity, retention scores and price-sensitivity segments must be excluded as rating, tiering or underwriting features for District risks — including as inputs to an ostensibly risk-based model, since the prohibition reaches indirect effect. The original transition deadlines have long passed (a compliant SERFF filing was due by November 30, 2015, identifying the tracking number of the filing being replaced, with proposed effective dates no later than March 31, 2016 for both new and renewal business), but the forward-looking duty on all future filings is continuing and is what binds a model built today.

Deadline: November 30, 2015

DISB Bulletin 15-IB-06-8/15, "Price Optimization Ban" (August 25, 2015, Acting Commissioner Stephen C. Taylor), Purpose and Scope, Supporting Documentation and Conclusion; statutory basis as cited in the bulletin: D.C. Official Code §§ 31-2231.13(c), 31-2703(a) and 31-2703(b)

D.C. Code § 31-2231.13 — Like Risks Must Be Rated Alike, and Nine Protected Classes Including PERSONAL APPEARANCE Require Actuarial Justification

Critical

The District's rating-discrimination bar is materially broader than the comparable provision in any other state in this vein, and it is the statute an AI underwriting or pricing model most plausibly breaches without anyone intending it. Two distinct prohibitions operate. First, § 31-2231.13(c): "No insurer shall make or permit an unfair discrimination between insured property having like insuring or risk characteristics, in the premium or rates charged for insurance, in the dividends or other benefits payable thereon, or in any other of the terms and conditions of the insurance." This is the like-risks-alike rule the price optimization ban is built on, and it reaches the terms and conditions of the policy, not merely price — so a model that varies deductibles, coverage limits, payment plans or non-renewal treatment between equivalent risks is within its scope. Second, and with no analogue elsewhere in this vein, § 31-2231.13(d): "an insurer shall not make or permit a differential in ratings, premium payments, or dividends based on the marital status, race, color, PERSONAL APPEARANCE, sexual orientation, gender identity or expression, matriculation, or political affiliation of an applicant or policy holder unless there is actuarial justification for the differential", with "matriculation" carrying the meaning given in § 2-1401.02(18) of the DC Human Rights Act. Read the structure carefully. The bar is not absolute — actuarial justification is a defence — but it is the INSURER that must be able to produce that justification, which for a machine-learned model means being able to show that a differential correlated with one of these characteristics is actuarially supported rather than merely predictive. "Personal appearance" is the District-specific class with the sharpest AI consequence: any model consuming photographs, video, facial analysis, body-worn or vehicle telematics imagery, aerial or street-level property imagery of the insured, or social-media profile images is capable of producing an appearance-correlated differential, and DC is the jurisdiction where that is separately actionable. Political affiliation and matriculation are similarly unusual and are both plausibly inferable from consumer-data brokers' segments. The subsection closes by preserving filed programmes: "Nothing in this section shall limit or otherwise restrict any discount, rating, or credit program filed with the Commissioner" — which points to the practical mitigation, namely filing the programme rather than relying on the model's opacity.

D.C. Code § 31-2231.13 ("Unfair discrimination and rebates prohibited; property, casualty, and surety insurance"), subsections (c) and (d), with "matriculation" defined by cross-reference to § 2-1401.02(18)

D.C. Code § 31-3875.06 — The Adverse Determination ITSELF Must Be Made by a Same-Specialty Physician: No Automated First-Instance Denial

Critical

This is the strongest AI constraint the District has enacted, and it is stronger than the equivalent in West Virginia, which reserved only the peer review ON APPEAL. Section 31-3875.06(a)(1) provides that "a utilization review entity SHALL ensure that AN ADVERSE DETERMINATION IS MADE BY A PHYSICIAN" who possesses a current, valid, non-restricted licence to practise medicine in the District, Maryland or Virginia, AND who is of the same or similar specialty as a physician who typically manages the medical condition or disease or provides the health care service involved in the request — with a pediatric specialty required for pediatric care. The reviewing physician must be under the clinical direction of one of the entity's medical directors licensed in the District who is responsible for providing health care services to District enrollees, and must NOT receive any financial incentive based on the number of adverse determinations made (medically appropriate performance standards remain permissible). The consequence for automation is direct and unavoidable: an AI System may triage, may surface evidence, may draft, and may approve, but the adverse determination is reserved to a named licensed human physician of matching specialty. Section 31-3875.03(c)(1) then makes that reservation auditable rather than merely aspirational, because the denial notice must disclose "the qualifications of the individual making the determination, including the states in which the individual is licensed, the status of their medical licenses, and their medical specialty" — a requirement no automated denial can satisfy and no insurer can paper over without a false statement. Appeals carry a second, independent layer under § 31-3875.06(b): the appeal reviewer must hold the same licensure, be of the same or similar specialty (with five years' practice for pediatric appeals), be knowledgeable of and experienced in providing the service on appeal, take no financial incentive tied to adverse determinations made OR UPHELD on appeal, and must not have been directly involved in making the original adverse determination nor be a subordinate of the physician who made it. Before issuing any adverse determination the entity must also notify the treating provider that medical necessity is being questioned and give the responsible physician an opportunity to supply additional information or clarification — a mandatory human-in-the-loop step that sits upstream of the determination itself.

Deadline: January 17, 2024

D.C. Code § 31-3875.06 ("Review personnel qualifications"), subsections (a) and (b), enacted by the Prior Authorization Reform Amendment Act of 2023, D.C. Law 25-100, § 106 (Jan. 17, 2024, 70 DCR 15238); reviewer-qualification disclosure at § 31-3875.03(c)(1); pre-denial provider consultation at § 31-3875.03(d)(2)

Bulletin 24-IB-002-05/21 — Written AI Systems (AIS) Program for Insurers

High Priority

Every insurer authorized to do business in the District of Columbia is EXPECTED to develop, implement and maintain a written AIS Program governing the responsible use of AI Systems that make or support decisions related to regulated insurance practices. Note the normativity, because it distinguishes DC from most of this vein: the District kept the NAIC model's "are expected to" rather than downgrading it to a recommendation, and the words "recommends", "suggests" and "would ideally" appear nowhere in the text. The programme must be designed to mitigate the risk of Adverse Consumer Outcomes — defined as a decision subject to insurance regulatory standards enforced by the Department that adversely impacts the consumer in a manner that violates those standards — including at a minimum the statutory provisions in Section 1 of the bulletin. Controls must be proportionate to the insurer's own assessment of the degree and nature of risk, weighing five stated factors: the nature of the decisions being made, informed or supported using the AI System; the type and Degree of Potential Harm to Consumers; the extent to which humans are involved in the final decision-making process; the transparency and explainability of outcomes to the impacted consumer; and the extent and scope of reliance on data, Predictive Models and AI Systems from third parties. It must span the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, fraud detection) and the whole AI life cycle (design, development, validation, implementation of both systems and business, use, ongoing monitoring, updating, retirement), and must reach AI whether developed in-house or bought from a third-party vendor. It may sit inside or outside the enterprise risk management programme and may adopt or rely upon a third-party framework such as the NIST AI Risk Management Framework, Version 1.0.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, "The Use of Artificial Intelligence Systems in Insurance" (May 21, 2024, Commissioner Karima M. Woods), Section 3 (Regulatory Guidance and Expectations) and AIS Program Guidelines 1.0-1.8; definitions at Section 2

Bulletin 24-IB-002-05/21 — Board-Accountable AI Governance Framework and Documented Decision Hierarchy

High Priority

Vest responsibility for the development, implementation, monitoring and oversight of the AIS Program — and for setting the insurer's strategy for AI Systems — in senior management accountable to the board or an appropriate committee of the board. The governance framework should prioritise transparency, fairness and accountability in the design and implementation of AI Systems, recognising that proprietary and trade-secret information must be protected, and the insurer may either build new internal governance structures or rely on existing ones. The bulletin asks the framework to address: the policies, processes and procedures, including risk management and internal controls, to be followed at each stage of an AI System life cycle from proposed development to retirement; the requirements adopted to DOCUMENT compliance with those policies, processes, procedures and standards — with the express instruction that "documentation requirements should be developed with Section 4 in mind", which in the District is a pointed instruction because DC retained Section 4's full itemised list; and the internal AI System governance accountability structure, covering the formation of centralized, federated or otherwise constituted committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of responsibility and authority, chains of command and decisional hierarchies; the independence of decision-makers and lines of defence at successive stages of the AI System life cycle; monitoring, auditing, escalation and reporting protocols and requirements; and the development and implementation of ongoing training and supervision of personnel.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, AIS Program Guidelines 1.2, 1.3 and 2.0-2.3 (governance framework and accountability structure)

Bulletin 24-IB-002-05/21 — Predictive Model Inventory, Validation Against Unseen Data, and Model Drift

High Priority

Document the insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each stage of the AI System life cycle. The bulletin asks these to address: the oversight and approval process for the development, adoption or acquisition of AI Systems, and the identification of constraints and controls on automation and design to align and balance function with risk; data practices and accountability procedures including data currency, lineage, quality, integrity, bias analysis and minimization, and suitability; management and oversight of Predictive Models and the algorithms used in them, comprising INVENTORIES and descriptions of the models, detailed documentation of their development and use, and assessments such as interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, MODEL DRIFT and the auditability of those measurements where appropriate; validating, testing and retesting as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model — where validation "can take the form of comparing model performance on UNSEEN DATA available at the time of model development to the performance observed on data post-implementation, measuring performance against expert review, or other methods"; the protection of non-public information, particularly consumer information, including unauthorized access to the Predictive Models themselves; data and record retention; and, specifically for Predictive Models, a narrative description of the model's intended goals and objectives and how it is developed and validated to ensure the AI Systems relying on it correctly and efficiently predict or implement those goals. Guideline 2.4 separately requires the processes for designing, developing, verifying, deploying, using, updating and monitoring Predictive Models to include a description of the methods used to detect and address errors, performance issues, outliers or UNFAIR DISCRIMINATION in the insurance practices resulting from the model's use. DC retained the model's formal definitions of Model Drift and Predictive Model in Section 2, so these terms carry defined meanings here rather than being left to the insurer.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, AIS Program Guidelines 2.4 and 3.0-3.7 (risk management, internal controls and Predictive Model oversight), with the defined terms "Model Drift" and "Predictive Model" at Section 2

Bulletin 24-IB-002-05/21 — Third Party AI and Data: Diligence, Audit Rights and Regulator Cooperation

High Priority

Address in the AIS Program the insurer's process for acquiring, using or relying on third party data to develop AI Systems, and on AI Systems developed by a third party. The bulletin contemplates standards, policies, procedures and protocols covering: due diligence and the methods employed to assess the third party and its data or AI Systems, so that decisions made or supported by them which could lead to Adverse Consumer Outcomes will meet the legal standards imposed ON THE INSURER ITSELF — the vendor's own compliance posture is not a defence, and this sentence is stated flatly rather than hedged; where appropriate and available, the inclusion of contract terms that provide audit rights and/or entitle the insurer to receive audit reports by qualified auditing entities, and that REQUIRE THE THIRD PARTY TO COOPERATE with the insurer with regard to regulatory inquiries and investigations related to the insurer's use of the third party's product or services; and the actual PERFORMANCE of those contractual audit rights and other activities to confirm the third party's compliance with contractual and, where applicable, regulatory requirements. Read the qualifier honestly: the audit-rights and cooperation clauses are conditioned on being "where appropriate and available", so no specific clause is mandated — but the diligence standard, and the requirement that the insurer actually exercise rather than merely hold its audit rights, are not so qualified. This matters more in DC than in states that condensed the model, because Section 4 item 2.2 tells insurers in terms that their vendor CONTRACTS will be requested on examination, including the terms relating to cooperation with regulators.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, AIS Program Guidelines 1.8 and 4.0-4.3 (Third Party AI Systems and Data), read with Section 4 items 2.1-2.4

Bulletin 24-IB-002-05/21 Guideline 1.9 — Notice to Impacted Consumers That AI Systems Are in Use

High Priority

Include in the AIS Program processes and procedures providing notice to impacted consumers that AI Systems are in use, and providing access to appropriate levels of information based on the phase of the insurance life cycle in which the AI Systems are being used. Scope the disclosure to the life-cycle phase — marketing, underwriting, rating and pricing, case management, claim administration — rather than publishing one generic notice, because the guideline expressly ties the level of information to the phase. RECORDED PRECISELY, because this is where the District differs from West Virginia in the one place West Virginia was stronger: DC adopted the NAIC model's plain wording and did NOT add the word "free". A diff of the two texts this session returns zero hits for "free access" in the DC bulletin, exactly as in the model. So the District expects notice and access, but has not on the face of the bulletin barred an insurer from attaching a cost to the information. That said, an access fee is still exposed under the unfair-trade-practices chapter if it operates to make the disclosure illusory, and it sits badly against § 31-3875.03(c), which for prior-authorization denials requires the notice to carry "all information necessary to support a successful appeal" at no charge.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, AIS Program Guideline 1.9 (notice to impacted consumers and access to appropriate levels of information)

Bulletin 24-IB-002-05/21 Section 4 — The Itemised Document List DC Actually Published (Retained in Full)

High Priority

This is the requirement that separates the District from the condensing adopters, and it is the practical centre of gravity for anyone preparing for a DC market conduct action. Regardless of the existence or scope of a written AIS Program, an insurer can expect to be asked about its development, deployment and use of AI Systems, or any specific Predictive Model, AI System or application and its outcomes including Adverse Consumer Outcomes. Unlike West Virginia — which told insurers they would be asked but deleted the model's schedule of what would be asked for — DC RETAINED Section 4 in full, so the document list is published and can be prepared against directly. Expect requests for: the written AIS Program itself; documentation evidencing its ADOPTION; the SCOPE of the programme, expressly including any AI Systems and technologies NOT included in or addressed by it; how the programme is tailored to and proportionate with the insurer's use and reliance on AI Systems, the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers; policies, procedures, guidance and TRAINING MATERIALS relating to its adoption, implementation, maintenance, monitoring and oversight, including processes for development, adoption or acquisition of AI Systems (identification of constraints and controls on automation and design; data governance and controls covering lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency), processes for management and oversight of Predictive Models including the measurements, standards or THRESHOLDS the insurer uses, and the protection of non-public information including unauthorized access to the models; pre-acquisition and pre-use diligence, monitoring, oversight and auditing of third-party data or AI Systems; documentation evidencing implementation of and compliance with the programme, including the formation and ongoing operation of coordinating bodies, data practices and accountability procedures, the insurer's INVENTORIES and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes, and — as to any specific model under investigation — documentation of compliance with all applicable policies, information about the data used including source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, and information on the techniques, measurements, thresholds and similar controls used; and documentation of validation, testing and auditing including evaluation of MODEL DRIFT, with the bulletin noting that the nature of that work should reflect whether the AI System rests on Predictive Models or on Generative AI. Two honest cautions. First, the bulletin closes by stating that its goal "is not to prescribe specific practices or to prescribe specific documentation requirements" and that insurers may demonstrate compliance through alternative means — so the list is the Department's expectation of what it will ask for, not a mandated filing. Second, DC inherited a defect from the model: "Data Currency" is capitalised as a defined term and used three times in Section 4, but it appears in neither the model's nor the District's Section 2 definitions. It is undefined in the instrument.

Deadline: May 21, 2024

DISB Bulletin 24-IB-002-05/21, Section 4 (Regulatory Oversight and Examination Considerations), items 1.1-1.3 and 2.1-2.4, and closing paragraphs; market conduct authority at D.C. Code §§ 31-1401 to 31-1407

D.C. Code §§ 31-2701 to 31-2714 — AI-Derived P&C Rates Must Not Be Unfairly Discriminatory (and Accident & Health Is Excluded and Routed Elsewhere)

High Priority

The bulletin names this chapter as one of the four legal bases for its expectations and states, in the District's own words, that its requirements "apply regardless of the methodology that the Insurer used to develop rates, rating rules, and rating plans", so that an insurer "is responsible for assuring that rates, rating rules, and rating plans that are developed using AI techniques and Predictive Models that rely on data and Machine Learning do not result in excessive, inadequate, or unfairly discriminatory insurance rates". The substantive standard is at § 31-2703(a): rates for insurance within the scope of the chapter shall not be excessive, inadequate or unfairly discriminatory. Section 31-2703(b) then enumerates what due consideration must be given to — past and prospective loss experience within and outside the District, physical hazards, safety and loss prevention factors, underwriting practice and judgment, catastrophe hazards, a reasonable margin for underwriting profit and contingencies, dividends and unabsorbed premium deposits, past and prospective expenses, whether classification rates exist generally for the risks under consideration, the rarity or peculiar characteristics of the risks, all other relevant factors, and net investment income including realized capital gains (with unrealized gains and losses expressly excluded from ratemaking). That enumeration is what the price optimization ban weaponises: a factor that is neither loss-related nor expense-related is not among them. Section 31-2703(c) preserves genuine classification: nothing is to be taken as unfairly discriminatory in establishing or modifying classifications based on size, expense, management, individual experience, location or dispersion of hazard, "or any other reasonable considerations attributable to such risks", PROVIDED the classifications apply to all risks under the same or substantially similar circumstances — the proviso, not the licence, is the operative half for a model that produces bespoke per-policy adjustments. SCOPE LIMIT, and the fifth consecutive NAIC-adopting state in this vein to carry one: § 31-2702 applies the chapter to fire, casualty, motor vehicle, explosion, sprinkler leakage and inland marine insurance and to all forms within Chapter 25, but excludes reinsurance other than joint reinsurance, ocean marine, TITLE INSURANCE, ACCIDENT AND HEALTH INSURANCE, aircraft hull and non-workers-compensation aircraft liability, and excess insurance issued to self-insurers above at least $10,000 per occurrence unless rated by a rating organisation. An AI model pricing accident and health risk in the District is therefore outside this chapter entirely — but, as in West Virginia and unlike Arkansas, that is a routing rather than a gap: A&H rates go to Chapter 33A (see the separate requirement), which imposes its own filing gate and its own substantive test.

D.C. Code § 31-2703 ("Making of rates"), subsections (a)-(d) and (f); scope and exclusions at § 31-2702 ("Applicability of chapter"), with definitions at § 31-2701; cited as legal authority in DISB Bulletin 24-IB-002-05/21, Section 1

D.C. Code §§ 31-3311.01 to 31-3311.04 — Where AI-Priced Accident & Health Rates Actually Go: Annual Filing, Approval, and a Medical-Loss-Ratio Test

High Priority

This is the destination of the line that § 31-2702(3) removes from the rating chapter, and it is the reason the District's A&H position is a routing rather than an absence. Section 31-3311.04 requires ALL insurers subject to the chapter to file ANNUALLY their rates, rating schedule and supporting documentation — including ratios of incurred losses to earned premiums by policy form or certificate form — FOR APPROVAL by the Commissioner. The supporting documentation must demonstrate, "in accordance with actuarial principles and standards, using reasonable assumptions", that the appropriate medical loss ratio standards can be expected to be met over the entire period for which rates are computed and that the insurer complies with the chapter's ratemaking principles. The procedural clock is specific and worth building to: if the submitted data does not confirm compliance, the Commissioner SHALL notify the insurer in writing of the deficiency within 30 BUSINESS DAYS of submission; the insurer then has 30 DAYS from the notice to file amended rates; and if it fails to do so, the Commissioner SHALL ORDER the filed rates for the nonconforming policies reduced to an amount bringing them into compliance. A hearing is available on request before any order or notice becomes final, on not less than 10 business days' written notice. Section 31-3311.01 supplies the substantive standard, which is NOT the standard an AI programme built to the NAIC model bulletin would document against: rates shall not be excessive, inadequate or unfairly discriminatory, but in determining whether they are excessive or unfairly discriminatory the Commissioner MAY consider historical and projected loss ratios, any anticipated change in the number of enrollees if the proposed rate is approved, changes to covered benefits or plan design, and changes in the insurer's health care cost and quality improvement efforts since the last filing for the same category of plan. Due consideration must be given to eight enumerated ratemaking factors including past and prospective loss experience, catastrophe hazards, expenses, underwriting profits, contingencies, investment income and reserves as reported in the insurer's financial statements, and returned dividends or unabsorbed premium deposits. And § 31-3311.01(e) sets a hard demonstrable floor: for any rate filing the carrier shall demonstrate a target medical loss ratio of 70 percent or greater for individual and small group policies and 75 percent or greater for large group policies, with the Commissioner able to grant an exemption in his or her discretion on justification and after a 30-day period of public notice. Section 31-3311.03b separately reserves to the Commissioner, with Health Benefit Exchange Authority approval, the power to set by rule the District's geographic rating area, age rating or curve, and tobacco rating — meaning those three rating dimensions are not the insurer's model to choose — and § 31-3311.01(c) requires individual and group experience to be merged for rate-setting purposes.

D.C. Code § 31-3311.04 ("Annual rate filing requirement") and § 31-3311.01 ("Ratemaking principles and standards"), subsections (b), (c) and (e); rating-dimension rulemaking reserved at § 31-3311.03b

D.C. Code § 31-3875.03 — Prior-Authorization Decision Clocks, With Automatic Approval as the Sanction for Missing Them

High Priority

Automated prior-authorization systems are usually sold on speed, which makes the District's deadlines the easy half of compliance and its auto-approval remedy the expensive half. After receiving all required information, a utilization review entity shall make an approval or adverse determination and notify the enrollee, the enrollee's representative and the enrollee's health care provider within 24 HOURS for an urgent health care service, and within 3 BUSINESS DAYS where the request arrived via electronic portal or 5 BUSINESS DAYS where it arrived by mail, telephone or facsimile — note that the District ties the clock to the intake CHANNEL, so an AI intake pipeline that normalises everything into one queue must still preserve and honour the original channel. Section 31-3875.03(b) provides that the service is DEEMED APPROVED if notice is not given within those time frames. "Required information" expressly includes the results of any face-to-face clinical evaluation or second opinion the entity's own prior authorization requirements may demand. Where information is missing the entity shall promptly notify the enrollee, representative and provider of the need for more. The adverse-determination notice must explain the entity's reasons by reference to its prior authorization requirements, the enrollee's right to appeal, the process to file one, and — a demanding drafting standard for any generated notice — "all information necessary to support a successful appeal of the adverse determination". Emergency care is separately protected: the entity must allow at least 24 hours excluding weekends and legal public holidays after an emergency admission or service for notification; where the provider certifies in writing within 72 hours that the enrollee's condition required the service, medical necessity is PRESUMED and may be rebutted only by CLEAR AND CONVINCING EVIDENCE; and the entity may neither consider that an emergency service came from a nonparticipating provider when judging medical necessity nor impose greater coverage restrictions on nonparticipating emergency care. RECORDED HONESTLY, because it is a genuine oddity of the District's code rather than a transcription error: § 31-3875.03(a)(2) reads in its entirety "Not Funded", and § 31-3875.02(a)(2)(A)(i) and (ii) are likewise "Not Funded" — the Council conditioned parts of D.C. Law 25-100 on the fiscal effect being included in an approved budget and financial plan, and those subsections have not been implemented. The deadlines in (a)(1) and (a)(3) and the reviewer-qualification rules are in force.

Deadline: January 17, 2024

D.C. Code § 31-3875.03 ("Prior authorization in non-urgent, urgent, and emergency circumstances"), subsections (a)-(f), enacted by D.C. Law 25-100, § 103 (Jan. 17, 2024); unimplemented subsections flagged by § 301 of D.C. Law 25-100

DISB Bulletin 24-IB-003-05/31 — A First Weather Claim Must Be Invisible to Your Renewal Model, Not Merely to Your Non-Renewal Decision

High Priority

Issued ten days after the AI bulletin and never linked to it, this is a hard feature-exclusion rule that an automated homeowners renewal-rating model will violate by default, because the model will see the claim in the loss history and price it. The bulletin reissues Bulletin 05-I-002-3/15 and construes Title 26 DCMR, Chapter 50 (Unfair Trade Practices). Subsection 5000.1 provides that an insurer shall not refuse to renew a homeowners policy solely due to claim or loss frequency unless there have been two or more claims during the most recent three-year experience period, and paragraph (a) provides that in counting claims the insurer "shall not consider the first claim for a loss caused by weather, unless the insurer can provide evidence that the insured unreasonably failed to maintain the property and such failure to maintain contributed to the loss". The Department then closes the loophole an insurer — or a model — would otherwise take: some insurers believed it proper to significantly increase the premium, change the rating classification, or impose a surcharge because of a first weather-related claim so long as the policyholder was not non-renewed, and "such treatment of policyholders is prohibited". The stated intent is that the first weather claim "shall be disregarded FOR UNDERWRITING PURPOSES related to the renewal", and the Department will treat ANY change in the premium, coverage or treatment of the policy due to that claim as an attempt to circumvent the regulation. What survives: the bulletin does not prevent an insurer modifying the rates it charges to a CLASS of insureds, subject to regulatory review, provided the change applies to all persons in the rating class and no policyholder has his or her rating class changed because of a first weather claim. Implementation consequence: the first weather-related claim in the experience period must be suppressed as an input to renewal underwriting, rating, tiering and surcharge logic for District homeowners risks — not merely excluded from the non-renewal rule — unless the insurer holds evidence of unreasonable failure to maintain that contributed to the loss, which is an evidentiary burden on the insurer and cannot be inferred by the model.

Deadline: May 31, 2024

DISB Bulletin 24-IB-003-05/31, "Clarification of Unfair Trade Practices Regulations for Homeowners Insurance" (May 31, 2024, Commissioner Karima M. Woods), reissuing Bulletin 05-I-002-3/15 and construing D.C. Mun. Regs. tit. 26, ch. 50, § 5000.1 and § 5000.1(a)

D.C. Code §§ 31-331 to 31-338 — AI Governance Is Reportable in the June 1 CGAD Under CEO Attestation

Medium Priority

The bulletin cites the Insurer Corporate Governance Annual Report Act as one of its four legal bases and states expressly that "the requirements of CGAD and CGAD-R apply to elements of the Insurer's corporate governance framework that address the Insurer's use of AI Systems to support actions and decisions that impact consumers" — so unlike West Virginia, which deleted this citation, the District tells insurers directly that their AI governance is CGAD-reportable. Section 31-333(a)(1) requires that BY JUNE 1 OF EACH YEAR an insurer, or the insurance group of which it is a member, submit to the Commissioner a Corporate Governance Annual Disclosure containing the information required by the chapter or rules issued under it; where the insurer belongs to a group for which DISB is not the primary regulator, the disclosure goes to the lead state commissioner in accordance with that state's laws as outlined in the most recent edition of the NAIC Financial Analysis Handbook. An insurer not otherwise required to submit must provide a copy on the Commissioner's request. Section 31-333(b) is the provision that converts advisory guidance into personal exposure: the disclosure shall include the signature of the insurer's or group's CHIEF EXECUTIVE OFFICER or CORPORATE SECRETARY attesting, to the best of that individual's belief and knowledge, that the insurer HAS IMPLEMENTED the corporate governance practices described in it, and that a copy has been provided to the board of directors or the appropriate board committee. Section 31-333(c) permits reporting at the ultimate controlling parent level, an intermediate holding company level, or the individual legal entity level, depending on how the system of corporate governance is structured. Practical effect: the board-accountable AI governance structure that Bulletin 24-IB-002-05/21 merely expects becomes, once described in a CGAD, something a named officer has personally attested is actually in place. Content requirements sit at § 31-334, and the form and filing requirements at D.C. Mun. Regs. tit. 26-A, § 2511.

Deadline: June 1, 2027

D.C. Code § 31-333 ("Disclosure requirement"), subsections (a)-(c), Insurer Corporate Governance Annual Report Act, D.C. Law 24-26 (Sept. 22, 2021); contents at § 31-334; form and filing at D.C. Mun. Regs. tit. 26-A, § 2511 (CGAD-R); cited as legal authority in DISB Bulletin 24-IB-002-05/21, Section 1

Recent Regulatory Guidance

guidance2024-05-21

DISB Bulletin 24-IB-002-05/21 — The Use of Artificial Intelligence Systems in Insurance (May 21, 2024)

The District's adoption of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, issued by Commissioner Karima M. Woods to all insurers holding certificates of authority in the District. Verified verbatim against the NAIC model this session by mechanical diff: all four sections retained (Introduction and Legislative Authority, Definitions, Regulatory Guidance and Expectations, Regulatory Oversight and Examination Considerations), identical normativity vocabulary, no state-authored additions, and the full Section 4 itemised production list preserved. The single substantive deletion is the model's stand-alone Unfair Claims Settlement Practices bullet, folded into the District's UITPA citation because DC codifies unfair claim settlement practices at D.C. Code § 31-2231.17. Every one of the model's blank citation brackets was filled with a real District citation.

guidance2015-08-25

DISB Bulletin 15-IB-06-8/15 — Price Optimization Ban (August 25, 2015)

Mandatory prohibition on rating that turns on a policyholder's expected willingness to absorb a premium increase rather than on risk of loss and estimated expenses, addressed to all property and casualty insurers. Reaches the practice however implemented — "directly or indirectly through methods including, but not limited to, tier placement, risk classification systems, underwriting, relativity factors, surcharges, fees" — and bars differentials caused "wholly or in part" by non-risk characteristics. Grounded in D.C. Official Code §§ 31-2231.13(c), 31-2703(a) and 31-2703(b). Distributed only as a scanned image PDF with no extractable text layer, which is why it is routinely missed by text-based research; read this session by rendering the pages.

guidance2024-05-31

DISB Bulletin 24-IB-003-05/31 — Clarification of Unfair Trade Practices Regulations for Homeowners Insurance (May 31, 2024)

Reissue of Bulletin 05-I-002-3/15 construing Title 26 DCMR Chapter 50. Confirms that the first weather-related claim in the three-year experience period must be disregarded for renewal underwriting purposes generally, and that raising premium, changing rating classification or imposing a surcharge on account of that claim is prohibited as circumvention even where the policy is renewed. A direct feature-exclusion constraint on automated homeowners renewal-rating models.

guidance2026-08-26

DC Council legislative status verified from LIMS (checked August 26, 2026)

The Stop Discrimination by Algorithms Act has NEVER been enacted and is NOT currently pending. The Council's own Legislation Information Management System records exactly two versions across all council periods — B24-0558, Stop Discrimination by Algorithms Act of 2021 (introduced December 9, 2021) and B25-0114, Stop Discrimination by Algorithms Act of 2023 (introduced February 2, 2023, referred February 7, 2023, notice of intent published February 10, 2023 and no action thereafter) — both carrying a dead status, and NO successor was introduced in the 26th Council. Three AI-adjacent bills are live but unenacted as of this check: B26-0491, Artificial Intelligence Literacy in Education Act of 2025 (introduced November 17, 2025); B26-0524, Distribution of False Sexual Imagery Prohibition Amendment Act of 2025 (introduced December 1, 2025); and B26-0667, Surveillance Pricing Prohibition Amendment Act of 2026 (introduced April 20, 2026, which would prohibit algorithmic pricing of consumer goods and is the nearest legislative analogue to the DISB price optimization ban). None of the three has had a hearing recorded. No 2025-26 District bill addresses AI in utilization review; the District's prior-authorization rules come from D.C. Law 25-100, already enacted January 17, 2024.

Frequently Asked Questions

Does District of Columbia — DISB Bulletin 24-IB-002-05/21 (NAIC AI Model, Verbatim) + Price Optimization Ban 15-IB-06-8/15 + Prior Authorization Act (D.C. Law 25-100) + UITPA Rating Discrimination Bar apply to my business?

The District of Columbia has no comprehensive private-sector AI statute — the recurring "Stop Discrimination by Algorithms Act" has never been enacted (see the standing-negative note below) — but it does regulate AI in INSURANCE, and it does so… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under District of Columbia — DISB Bulletin 24-IB-002-05/21 (NAIC AI Model, Verbatim) + Price Optimization Ban 15-IB-06-8/15 + Prior Authorization Act (D.C. Law 25-100) + UITPA Rating Discrimination Bar is: The District's insurance penalties are unusually LOW and unusually INDIRECT, and this should be read as a warning about the shape of the exposure rather than its size. Under D.C. Code § 31-2231.22 the Commissioner MAY (not shall) issue an order to cease and desist and to correct the violation, including restitution of money or property to the person aggrieved; a civil penalty of up to $1,000 per violation becomes available only where the violator FAILS TO COMPLY with that order — there is no first-instance fine. The real teeth are elsewhere in the same section: the Commissioner may suspend or revoke the licence or certificate of authority of a person that violates the chapter, a rule under it, or an order, with no knowledge predicate; and the Commissioner may refer the matter to the Attorney General for the District of Columbia, who may seek in the Superior Court "damages and other relief allowed by law, including restitution" and may be awarded the District's attorney's fees and costs. Before setting any monetary figure the Commissioner SHALL consider six statutory factors (§ 31-2231.22(d)): the seriousness of the violation, the good faith of the violator, the violator's history of previous violations, the deleterious effect on the public and the insurance industry, the assets of the violator, and any other relevant factor — a systemic, model-driven violation scores badly on the first and fourth. Prior-authorization violations under §§ 31-3875.01 to 31-3875.10 carry a distinctive non-monetary sanction that is often the costlier one: § 31-3875.08(a) provides that ANY failure to comply results in the health care service in question being DEEMED APPROVED, and § 31-3875.08(b) provides that a pattern or practice of repeated violations constitutes a violation of the unfair-trade-practices chapter, routing it back into § 31-2231.22. Bulletin 24-IB-002-05/21 imposes no penalty of its own — it is guidance whose sanctions arrive through the UITPA and the market-conduct process under §§ 31-1401 to 31-1407.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with District of Columbia — DISB Bulletin 24-IB-002-05/21 (NAIC AI Model, Verbatim) + Price Optimization Ban 15-IB-06-8/15 + Prior Authorization Act (D.C. Law 25-100) + UITPA Rating Discrimination Bar?

The 14 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://disb.dc.gov/page/insurance-bulletins

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan