Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
US-NVMEDIUM coverage

Nevada AI Stack — DOI Bulletin 24-001 (NAIC AI Model Bulletin), AB 406 Mental/Behavioral Healthcare AI, Utilization-Review and Claim-Denial Law: AI Compliance Requirements

Nevada regulates AI through three separate surfaces. (1) INSURANCE — Division of Insurance Bulletin 24-001, "Use of Artificial Intelligence Systems by Insurers" (issued 23 February 2024, signed by Commissioner Scott J. Kipper), Nevada's adoption of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (NAIC-adopted 4 December 2023). It applies to all insurers subject to Title 57 of NRS holding a Nevada certificate of authority and expects each to develop, implement and maintain a written AI Systems Program ("AIS program") covering governance, risk management and internal controls, third-party AI/data oversight, and documentation producible on examination. The bulletin rests on three enumerated Nevada authorities and no others: the Unfair Trade Practices Act (NRS 686A.010–686A.310), the Corporate Governance Annual Disclosure Act (NRS 692C.3501–692C.3509 with NAC 692C.200–692C.220), and the Insurance Rating Law (NRS 686B.010–686B.1799 with NAC 686B.400–686B.610). (2) MENTAL AND BEHAVIORAL HEALTHCARE — AB 406 (signed 5 June 2025, effective 1 July 2025) prohibits offering an AI system that provides professional mental or behavioral healthcare and bars Nevada-licensed clinicians from using AI in direct patient care (administrative use permitted). (3) UTILIZATION REVIEW AND CLAIM DENIAL — Nevada has NO AI-specific utilization-review statute: SB 128 of the 83rd Session, which would have barred insurers from relying solely on an AI system or automated decision tool to deny or modify a prior authorization, was VETOED by Governor Lombardo on 10 June 2025. AI-driven utilization review is therefore governed by the generic law: independent UR agents must register with the Commissioner and keep a licensed physician (or dentist) medical director (NRS 683A.378), and every coverage denial must disclose the criteria used and how they were applied to the service (NRS 695G.230(3)(b)) — a transparency duty a black-box model cannot satisfy.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

February 23, 2024

Maximum Penalty

AB 406: civil penalties up to $15,000 per violation for providers offering prohibited mental/behavioral healthcare AI, plus Nevada licensing board discipline (suspension/revocation) for licensed clinicians. INSURANCE (Bulletin 24-001 routes through the Unfair Trade Practices Act): administrative fine of not more than $5,000 for each act or violation of NRS 686A.010–686A.310 where the person knew or reasonably should have known of the violation, except that for licensed agents, brokers, solicitors and adjusters the fine must not exceed $500 per act, plus suspension or revocation of the license (NRS 686A.183(1)); a further administrative fine of not more than $5,000 for each and every violation of a resulting cease-and-desist order, plus suspension or revocation (NRS 686A.187). Corporate Governance Annual Disclosure: civil penalty of $1,500 for each day of late filing, capped at $100,000 (NRS 692C.3509). Independent utilization-review agents: fine of not more than $1,000 for violating NRS 683A.375–683A.378 (NRS 683A.379).

What Your Business Must Do

15 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

No AI Therapy Services

Critical

If you operate or distribute an AI product that provides mental health, behavioral health, or therapeutic services (e.g., AI therapist, AI counselor, AI mental health support chatbot): this is PROHIBITED in Nevada as of July 1, 2025. Clearly restrict your product from providing mental/behavioral healthcare services. If your product claims therapeutic benefit, remove that framing.

Deadline: July 1, 2025

AB 406 (2025), Nev. Rev. Stat. Chapter 630 et seq. (implementing sections)

Nevada Unfair Trade Practices Act — AI-Made and AI-Supported Decisions (NRS 686A.010–686A.310)

Critical

Bulletin 24-001 rests first on the Unfair Trade Practices Act, NRS 686A.010 to 686A.310, which defines and prohibits unfair methods of competition and unfair or deceptive acts and practices in insurance. Nevada's position is that decisions subject to regulatory oversight that are made by insurers using AI systems must meet the same legal standards as any other decision: at a minimum they must not be inaccurate, arbitrary, capricious or unfairly discriminatory, and compliance is required regardless of the tools and methods used. Because AI can increase the risk of exactly those outcomes in the absence of proper controls, insurers are expected to adopt AI-specific controls designed to mitigate the risk of adverse consumer outcomes — where "adverse consumer outcome" is defined in the bulletin as a decision by an insurer, subject to insurance regulatory standards enforced by the Division, that adversely impacts the consumer in a manner that violates those standards. Enforcement follows the ordinary UTPA route: a hearing under NRS 686A.160, an order on hearing under NRS 679B.360, and if a violation is found, a cease-and-desist order plus, where the person knew or reasonably should have known of the violation, an administrative fine and/or licence action.

Deadline: February 23, 2024

NRS 686A.010–686A.310 (Unfair Trade Practices Act); enforcement under NRS 686A.160, NRS 686A.183 and NRS 686A.187; cited as the first authority in Nevada DOI Bulletin 24-001 (23 February 2024)

Nevada Insurance Rating Law — AI-Derived Rates and Prohibited Classification Variables (NRS 686B.050, 686B.060)

Critical

The third authority enumerated in Bulletin 24-001 is the Insurance Rating Law, NRS 686B.010 to 686B.1799 with NAC 686B.400 to 686B.610. The bulletin's own framing is that the Rating Law applies regardless of the methodology used to develop rates, rating rules and rating plans, so an insurer is responsible for assuring that rates developed using AI techniques and predictive models that rely on data and machine learning do not produce excessive, inadequate or unfairly discriminatory rates with respect to all forms of insurance. The statutory standard read this session: rates must not be excessive, inadequate or unfairly discriminatory, and an insurer may not charge a rate which if continued will have or tend to have the effect of destroying competition or creating a monopoly (NRS 686B.050(1)); one rate is unfairly discriminatory in relation to another in the same class if it clearly fails to reflect equitably the differences in expected losses and expenses (NRS 686B.050(4)). Critically for model design, NRS 686B.060(2) permits risks to be classified in any reasonable way for establishing rates and minimum premiums EXCEPT that classifications may not be based on race, colour, creed, national origin, sexual orientation, or gender identity or expression — a hard variable prohibition that reaches proxy features a model learns as well as features an actuary selects.

Deadline: February 23, 2024

NRS 686B.010–686B.1799 (Insurance Rating Law), in particular NRS 686B.050(1) and (4) (standards) and NRS 686B.060(2) (permitted and prohibited risk classifications); NAC 686B.400–686B.610; cited as the third authority in Nevada DOI Bulletin 24-001

Nevada Utilization-Review Agents — Registration and Licensed Medical Director (NRS 683A.375–683A.379)

Critical

Nevada has no AI-specific utilization-review statute, so AI-assisted utilization review is governed by the generic UR-agent regime. A person must not conduct utilization review unless the person is registered with the Commissioner as an agent who performs utilization review AND has a medical director who is a physician — or, for an agent reviewing dental services, a dentist — licensed in any state, or is employed by such a registered agent (NRS 683A.378(1)). "Utilization review" means a system providing, at a minimum, for review of the necessity and appropriateness of the allocation of health care resources and services provided or proposed to be provided to an insured, excluding mere responses to coverage-clarification requests (NRS 683A.376(3)). The registration application must include the applicant's identifying and contact details, the name of the medical director and the state licensing that person, and a summary of the plan for utilization review INCLUDING the procedures for appealing determinations made through utilization review (NRS 683A.378(2)). Material changes to that information must be filed with the Commissioner within 30 days after the change occurs (NRS 683A.378(3)), and registration must be renewed on or before 1 March of each year (NRS 683A.378(5)). Two structural points matter for AI deployments: the licensed-human medical director is a registration prerequisite that an automated system cannot satisfy, and the Commissioner SHALL NOT evaluate the submitted UR plan (NRS 683A.378(4)) — there is no state pre-approval of an AI review methodology, only after-the-fact liability. The regime does not apply to authorized insurers, certified fraternal benefit societies, nonprofit hospital/medical/dental service corporations, HMOs or dental-care organizations performing their OWN utilization review, but it does reach their affiliates and subsidiaries and their contracts with independent UR agents (NRS 683A.377).

Deadline: March 1, 2027

NRS 683A.375–683A.379, in particular NRS 683A.376(3) (definition), NRS 683A.377 (exemptions), NRS 683A.378(1)–(5) (registration, medical director, appeal procedures, 30-day material-change filing, 1 March renewal) and NRS 683A.379 (penalty)

Nevada Claim-Denial Notice — Disclose the Criteria and How They Were Applied (NRS 695G.230)

Critical

This is the statutory duty that most directly constrains an opaque AI denial in Nevada. When a health carrier denies coverage of a health care service to an insured — including a managed care organization denying a claim under NRS 695G.340 — it must notify the insured and, where applicable, the submitting provider in writing within 21 days after receiving all information necessary to make the determination if that information was submitted electronically, within 30 days if it was not, or within 10 working days after the denial if no claim was received (NRS 695G.230(2)). The notice must state all reasons for the denial including the specific facts and plan provisions relied on; THE CRITERIA by which the carrier determines whether to authorize or deny the service AND a description of the manner in which the carrier applied those criteria to that health care service; a summary of any applicable NRS 687B.820 process for challenging the denial; the insured's rights to file a written complaint, to appeal the adverse determination under NRS 695G.241 to 695G.310, to receive expedited external review where the provider furnishes proof that ordinary timing may jeopardise life or health, and to be assisted by any person including an attorney; and the telephone number of the Office for Consumer Health Assistance (NRS 695G.230(3)). Parallel notice and content duties run to providers whose claims are denied, on the same 21-day/30-day clocks (NRS 695G.230(5)–(6)). A carrier that cannot articulate the criteria a model applied, and how it applied them to the individual service, cannot satisfy paragraph (3)(b) — the section was amended in the 2025 session (Stats. Nev. 2025, p. 2409).

Deadline: February 23, 2024

NRS 695G.230(1)–(6), as amended 2025 (Stats. Nev. 2025, p. 2409); cross-references NRS 687B.820, NRS 695G.241–695G.310 and NRS 695G.340

Provider AI Use Policy (Administrative Only)

High Priority

Nevada licensed mental/behavioral health providers: AI may only be used for administrative tasks (scheduling, billing, documentation). Document your AI use policy explicitly stating AI is not used in direct patient interactions or clinical decision-making. Train staff on this boundary.

Deadline: July 1, 2025

AB 406 (2025)

Nevada DOI Bulletin 24-001 — Written AI Systems Program (AIS Program)

High Priority

Nevada adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers as Division of Insurance Bulletin 24-001, issued 23 February 2024 and applying to all insurers subject to Title 57 of the Nevada Revised Statutes. Every insurer authorized to do business in Nevada is expected to develop, implement and maintain a written program (the "AIS program") for the responsible use of AI systems that make or support decisions related to regulated insurance practices, designed to mitigate the risk of adverse consumer outcomes. The bulletin sets nine general guidelines: the program must address governance, risk management controls and internal audit functions (1.2); it must vest responsibility for development, implementation, monitoring and oversight — and for setting AI strategy — with senior management accountable to the board or an appropriate board committee (1.3); it must be tailored to and proportionate with the insurer's use of and reliance on AI, with controls aligned to the degree of potential harm to consumers for each use case (1.4); it may sit inside or outside the enterprise risk management program and may adopt a third-party framework such as the NIST AI Risk Management Framework version 1.0 (1.5); it must cover the whole insurance life cycle — product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection (1.6); it must cover every phase of an AI system's own life cycle from design through retirement (1.7); and it must cover AI systems whether built in-house or supplied by a third-party vendor (1.8). Proportionality is judged against five named factors: the nature of the decision, the type and degree of potential consumer harm, the extent of human involvement in the final decision, the transparency and explainability of outcomes to the affected consumer, and the extent of reliance on third-party data, models and AI systems.

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001, "Use of Artificial Intelligence Systems by Insurers" (23 February 2024), Regulatory Guidance and Expectations; AIS Program Guidelines 1.0–1.8; adopting the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (NAIC-adopted 4 December 2023)

Nevada DOI Bulletin 24-001 — AI Governance Framework and Predictive-Model Procedures

High Priority

The AIS program must include a governance framework for oversight of the insurer's AI systems that prioritises transparency, fairness and accountability while protecting proprietary and trade-secret information. Nevada names the items the framework should address: the policies, processes and procedures — including risk management and internal controls — to be followed at each stage of an AI system life cycle from proposed development to retirement (2.1); the requirements the insurer adopts for documenting compliance with its own AIS program, developed with the examination-production expectations in mind (2.2); and the internal accountability structure (2.3), specifically the formation of centralised, federated or other committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; the scope of responsibility and authority, chains of command and decisional hierarchies; the independence of decision-makers and lines of defence at successive life-cycle stages; monitoring, auditing, escalation and reporting protocols; and ongoing training and supervision of personnel. Separately for predictive models (2.4), the framework must describe the processes for designing, developing, verifying, deploying, using, updating and monitoring them, including the methods used to detect and address errors, performance issues, outliers or unfair discrimination in the insurance practices that result from the model.

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001 (23 February 2024), AIS Program Guidelines 2.0–2.4 (Governance)

Nevada DOI Bulletin 24-001 — Risk Management, Model Inventory, Validation and Drift Testing

High Priority

The AIS program must document the insurer's risk identification, mitigation and management framework and its internal controls, both for AI systems generally and at each life-cycle stage. Nevada enumerates seven areas: the oversight and approval process for developing, adopting or acquiring AI systems, including identification of constraints and controls on automation and design (3.1); data practices and accountability procedures covering data currency, lineage, quality, integrity, bias analysis and minimisation, and suitability (3.2); management and oversight of predictive models and the algorithms in them — inventories and descriptions of the models, detailed documentation of their development and use, and assessments such as interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, model drift and the auditability of those measurements (3.3); validating, testing and retesting as necessary to assess how AI system outputs generalise on implementation, including the suitability of the data used to develop, train, validate and audit the model, with validation able to take the form of comparing performance on unseen data available at development against post-implementation performance, measurement against expert review, or other methods (3.4); protection of non-public information, particularly consumer information, including unauthorised access to the predictive models themselves (3.5); data and record retention (3.6); and, specifically for predictive models, a narrative description of the model's intended goals and objectives and of how it was developed and validated to ensure the AI systems relying on it correctly and efficiently predict or implement those goals (3.7).

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001 (23 February 2024), AIS Program Guidelines 3.0–3.7 (Risk Management and Internal Controls)

Nevada DOI Bulletin 24-001 — Third-Party AI Systems and Data: Diligence, Audit Rights, Regulator Cooperation

High Priority

The AIS program must address how the insurer acquires, uses or relies on (i) third-party data used to develop AI systems and (ii) AI systems developed by a third party. Nevada names three areas. Due diligence: the methods the insurer employs to assess the third party and its data or AI systems, so that decisions made or supported by them which could lead to adverse consumer outcomes will meet the legal standards imposed on the insurer itself (4.1) — accountability does not transfer to the vendor. Contract terms, where appropriate and available (4.2): terms that provide audit rights and/or entitle the insurer to receive audit reports by qualified auditing entities, and terms requiring the third party to cooperate with the insurer on regulatory inquiries and investigations relating to the insurer's use of the vendor's products or services. Exercise of those rights (4.3): actually performing the contractual audit rights and other activities that confirm the third party's compliance with contractual and, where applicable, regulatory requirements — a negotiated audit clause that is never exercised does not satisfy the guideline.

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001 (23 February 2024), AIS Program Guidelines 4.0–4.3 (Third-Party AI Systems and Data)

Nevada DOI Bulletin 24-001 — Examination Production File for AI Systems

High Priority

Regardless of whether a written AIS program exists or how broad it is, in an investigation or market conduct action an insurer can expect to be asked about its development, deployment and use of AI systems, about any specific predictive model or application, and about the outcomes — including adverse consumer outcomes — produced by them. Nevada lists what the Division may request: the written AIS program itself and documentation evidencing its adoption; the program's scope, including any AI systems and technologies NOT covered by it; evidence of how the program is tailored to and proportionate with the insurer's reliance on AI and the degree of potential consumer harm; the policies, procedures, guidance and training materials for adopting, implementing, maintaining, monitoring and overseeing the program, including processes for development/adoption/acquisition of AI systems (constraints and controls on automation and design; data governance covering lineage, quality, integrity, bias analysis and minimisation, suitability and currency), processes for management and oversight of predictive models including the measurements, standards or thresholds used, and protections of non-public information; pre-acquisition and pre-use diligence, monitoring, oversight and auditing of third-party data or AI systems; evidence of the formation and ongoing operation of the coordinating bodies; the insurer's inventories and descriptions of the predictive models and AI systems used to make or support decisions that can result in adverse consumer outcomes; for any specific model under examination, documentation of compliance with the insurer's own policies, information about the data used including source, provenance and lineage, and the techniques, measurements and thresholds applied; and documentation of validation, testing and auditing including model-drift evaluation, with the nature of that testing reflecting whether the system is predictive-model-based or generative. For third-party components the Division may additionally request the due diligence performed, the vendor contracts including terms on representations and warranties, data security and privacy, data sourcing, intellectual property, confidentiality and disclosures and cooperation with regulators, the audits or confirmation processes performed, and the validation, testing and drift documentation.

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001 (23 February 2024), Regulatory Oversight and Examination Considerations, items 1.1–1.3 and 2.1–2.4

Nevada Corporate Governance Annual Disclosure — AI Governance Reporting (NRS 692C.3501–692C.3509)

High Priority

Bulletin 24-001's second enumerated authority is the Corporate Governance Annual Disclosure Act, NRS 692C.3501 to 692C.3509, with the content, form and filing requirements set out in NAC 692C.200 to 692C.220. The bulletin states expressly that CGAD and its regulations apply to the elements of the insurer's corporate governance framework that address the insurer's use of AI systems to support actions and decisions that impact consumers — so the AIS program's governance and accountability structure is reportable, not merely internal. The statutory mechanics read this session: each insurer, or the insurance group of which it is a member, must submit the corporate governance annual disclosure to the Commissioner not later than 1 June of each calendar year (NRS 692C.3504(1)); an insurer that is a member of an insurance group files with the lead-state commissioner determined under the NAIC Financial Analysis Handbook; and in every year after the first filing the insurer submits an amended version indicating where changes have been made, or expressly stating that no changes have been made (NRS 692C.3504(2)). A significant scope limit the bulletin does not state: CGAD applies only to insurers DOMICILED in Nevada — including hospital, medical or dental service corporations, health maintenance organizations, plans for dental care, prepaid limited health service organizations, and risk retention groups (NRS 692C.3503(1)) — so a foreign insurer merely authorised in Nevada is reached by the bulletin but not by this filing duty.

Deadline: June 1, 2027

NRS 692C.3501–692C.3509 (Corporate Governance Annual Disclosure Act), in particular NRS 692C.3503(1) (applicability), NRS 692C.3504(1)–(2) (submission by 1 June annually; amended versions thereafter) and NRS 692C.3509 (penalties); NAC 692C.200–692C.220; cited as the second authority in Nevada DOI Bulletin 24-001

Nevada Grievance, Review Board and External Review of Adverse Determinations (NRS 695G.200–695G.241)

High Priority

Every managed care organization must establish a system, approved by the Commissioner, for resolving insured complaints about payment or reimbursement, about the availability, delivery or quality of covered services — expressly including an adverse determination made pursuant to utilization review — and about the terms and conditions of the health care plan (NRS 695G.200(1)). The system must include an initial investigation, review by a review board the MAJORITY of whose members are insureds receiving services from the organization, and a procedure for appealing the board's determination (NRS 695G.210(1)). The review board must complete its review and notify the insured of its determination not later than 30 days after the complaint or appeal is filed unless a longer period is agreed; where the complaint involves an imminent and serious threat to the insured's health the organization must immediately inform the insured of the right to expedited review and the board must notify the insured in writing within 72 hours (NRS 695G.210(2)–(3)). The organization must assign an employee on request to help an insured file a complaint or appeal, must allow the insured to appear and testify, and may require the insured's documentation no earlier than 5 business days before the hearing (NRS 695G.200(3)). An annual report on the complaint system — describing the procedures, the total complaints and appeals since the last report with a compilation of underlying causes, the current status of each, and the average time to resolve — must be submitted to the Commissioner on a prescribed form (NRS 695G.220(1)). Separately, an insured, or the provider or dentist acting for them, may within 4 months after receiving notice of an adverse determination request external review by an independent review organization (NRS 695G.241 et seq.), and the carrier must supply the documents relied on including the criteria and the reasons for the determination. For an AI-assisted programme this means every automated adverse determination must be reconstructible for a lay review board, for an independent reviewer, and for the Commissioner's annual report on the same clocks as a human decision.

NRS 695G.200(1)–(4), NRS 695G.210(1)–(4), NRS 695G.220(1)–(2), NRS 695G.241 et seq. (external review of adverse determination); "adverse determination" defined at NRS 695G.012; "utilization review" and "utilization review organization" defined at NRS 695G.080 and NRS 695G.085

Nevada DOI Bulletin 24-001 — Notice to Consumers That AI Systems Are In Use

Medium Priority

Guideline 1.9 requires the AIS program to include processes and procedures providing notice to impacted consumers that AI systems are in use, and providing access to appropriate levels of information based on the phase of the insurance life cycle in which the AI systems are being used. This is a graduated duty rather than a single blanket disclosure: the level of information owed rises with the phase (underwriting and pricing, claim administration, fraud detection) and, under the proportionality factors in the Regulatory Guidance and Expectations section, with the transparency and explainability of outcomes to the impacted consumer and the degree of potential harm. Nevada does not prescribe the wording, the medium or the timing, and the bulletin expressly states that its goal is not to prescribe specific practices or documentation formats; insurers may demonstrate compliance through practices that differ from those described. The duty interacts directly with the claim-denial notice content required by NRS 695G.230(3)(b), which is a statutory obligation and is not discretionary.

Deadline: February 23, 2024

Nevada Division of Insurance Bulletin 24-001 (23 February 2024), AIS Program Guidelines 1.9

HONEST NEGATIVE — Nevada Has NO AI Prior-Authorization Statute: SB 128 Was Vetoed

Medium Priority

Do not plan around a Nevada ban on AI-driven prior-authorization denials: there is none. Senate Bill 128 of the 83rd Legislative Session (2025), sponsored by Senator Dina Neal, would have prescribed requirements governing the denial of prior-authorization requests, including barring insurers and public employee benefit programmes from relying solely on an AI system or automated decision tool to deny or modify a prior authorization. Governor Joe Lombardo VETOED it on 10 June 2025. His veto message, read in full this session, states that the bill "goes too far", that it "unnecessarily micromanages how private insurers and public employee insurance programs use AI, risking the stifling of innovation even when such technology can improve efficiency and lower costs", and that because AI is still a relatively new technology it makes more sense to understand its benefits before imposing restrictive measures. The 83rd Session had already adjourned sine die on 2 June 2025, so the veto was not subject to an override vote, and the Nevada Legislature sits only in odd-numbered years — the next regular session is in 2027. The practical consequence: through at least early 2027 an AI-assisted utilization-review programme in Nevada is constrained by the generic duties in this entry (UR-agent registration and licensed medical director under NRS 683A.378; denial-criteria disclosure under NRS 695G.230(3)(b); grievance, review-board and external-review clocks under NRS 695G.200–695G.241) and by Bulletin 24-001's AIS-program expectations — not by any AI-specific prohibition. Companion negative: SB 186 of the same session, which would have required a generative-AI disclaimer on AI-generated patient communications, was also not enacted; it is absent from the Governor's 2025 veto list, and secondary trackers report it died under Joint Standing Rule 14.3.1 — that disposition was NOT independently confirmed against a primary legislative record this session and should not be relied on beyond the fact of non-enactment.

Nevada SB 128, 83rd Legislative Session (2025) — VETOED 10 June 2025; Governor's veto message to Secretary of State Francisco Aguilar dated 10 June 2025; 83rd Session adjourned sine die 2 June 2025

Who Does This Apply To?

Three distinct populations. (1) INSURANCE — Bulletin 24-001 applies to all insurers subject to Title 57 of NRS that hold a Nevada certificate of authority and use advanced analytical or computational technologies, including AI systems, in decisions or actions impacting consumers. There is no size, premium or revenue threshold; the bulletin instead calibrates the depth of expected controls to five proportionality factors (nature of the decision, type and degree of potential consumer harm, extent of human involvement in the final decision, transparency and explainability to the affected consumer, and extent of reliance on third-party data/models/AI). Two of the three authorities the bulletin invokes have their own narrower scopes: the Corporate Governance Annual Disclosure duty reaches only insurers DOMICILED in Nevada (NRS 692C.3503(1)), while the Unfair Trade Practices Act and the Insurance Rating Law reach any person doing insurance business in the state. (2) MENTAL AND BEHAVIORAL HEALTHCARE — AB 406 reaches any provider or distributor of an AI system offered to Nevada residents that is designed to provide, or is represented as providing, professional mental or behavioral health care (prohibited outright since 1 July 2025), and separately Nevada-licensed mental and behavioral health professionals, who may use AI only for administrative support such as scheduling, billing and documentation and never in direct clinical interaction. The prohibition turns on whether the AI provides or simulates clinical mental-health treatment, not on company size. (3) UTILIZATION REVIEW — the NRS 683A.375–683A.379 registration regime reaches independent agents who perform utilization review and the affiliates, subsidiaries and contracted UR vendors of carriers, but NOT an authorized insurer, certified fraternal benefit society, NRS 695B nonprofit service corporation, NRS 695C HMO or NRS 695D dental-care organization performing its own review in-house (NRS 683A.377); the denial-notice, grievance and external-review duties in NRS 695G reach health carriers and managed care organizations, subject to the disapplications in NRS 695G.090. Enforcement runs through Nevada healthcare licensing boards (AB 406), the Insurance Commissioner's UTPA cease-and-desist and administrative-fine powers, market conduct actions, and civil penalties.

Recent Regulatory Guidance

guidance2025-06

Nevada — AB 406 (2025): limits on AI in mental and behavioral healthcare, effective July 1, 2025

Nevada AB 406 (signed June 5, 2025; effective July 1, 2025) prohibits offering an AI system that provides — or representing that an AI system can provide — professional mental or behavioral healthcare to Nevada users, and bars Nevada-licensed providers from using AI to deliver care directly to patients (administrative-support use is permitted). The licensed professions covered include marriage and family therapists, clinical professional counselors, psychologists, social workers and other clinicians. Violations carry civil penalties up to $15,000 per incident for AI providers, with potential disciplinary action for licensed professionals.

guidance2024-02-23

Nevada Division of Insurance Bulletin 24-001 — Use of Artificial Intelligence Systems by Insurers

Nevada's adoption of the NAIC Model Bulletin, issued 23 February 2024 over the signature of Commissioner Scott J. Kipper and applying to all insurers subject to Title 57 of NRS. Eleven pages. Reminds insurers holding a Nevada certificate of authority that consumer-impacting decisions made or supported by advanced analytical and computational technologies, including AI systems, must comply with all applicable insurance laws — expressly those addressing unfair trade practices and unfair discrimination. Recognises the NAIC 2020 Principles of Artificial Intelligence as appropriate guidance. Authority section enumerates exactly three Nevada instruments: the Unfair Trade Practices Act (NRS 686A.010–686A.310), the Corporate Governance Annual Disclosure Act (NRS 692C.3501–692C.3509 with NAC 692C.200–692C.220) and the Insurance Rating Law (NRS 686B.010–686B.1799 with NAC 686B.400–686B.610); market conduct authority is asserted in prose without a statutory citation and no unfair-claims-settlement act is cited. Defines adverse consumer outcome, algorithm, AI system, artificial intelligence, degree of potential harm to consumers, generative artificial intelligence, machine learning, model drift, predictive model and third party. Expects a written AIS program (guidelines 1.0–4.3) and sets out what the Division may request on investigation or market conduct action (oversight items 1.1–1.3 and 2.1–2.4). Closes by stating that the goal is not to prescribe specific practices or documentation formats and that insurers may demonstrate compliance by alternative means. Questions to insinfo@doi.nv.gov.

guidance2026-04-01

NAIC — Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (map, status as of 1 April 2026)

The NAIC's own adoption map and reference list, used this round to identify Nevada's instrument rather than relying on memory or secondary trackers. The reference list records "Nevada: Bulletin 24-001 — Adopted February 23, 2024" among 25 adopted jurisdictions, alongside a separate "Insurance Specific Regulation/Guidance" group (California Bulletin 2022-5, Colorado 3 CCR 702-10 with amendments effective 15 October 2025, New York Insurance Circular Letter No. 7 of 11 July 2024, Texas Bulletin B-0036-20). The April 2024 edition of the same map was also pulled and carries the identical Nevada line, so the identification does not rest on a single compilation. Page count verified with pypdf rather than file metadata.

ruling2025-06-10

Governor Lombardo — veto message for Senate Bill 128 of the 83rd Legislative Session

Two-page veto message dated 10 June 2025 to Secretary of State Francisco Aguilar, returning SB 128 without approval. The bill was titled as an act relating to health care prescribing requirements governing the denial of requests for prior authorization, making legislative findings, and encouraging licensed physicians, physician assistants, advanced practice registered nurses and osteopathic physicians to discuss stem cell treatment, storage and donation with patients in certain circumstances. The Governor wrote that the bill "goes too far", that it "unnecessarily micromanages how private insurers and public employee insurance programs use AI, risking the stifling of innovation even when such technology can improve efficiency and lower costs", and that because AI is still a relatively new technology it makes more sense to understand its benefits before imposing restrictive measures; he separately objected to government pressure to promote stem cell therapies lacking full FDA approval. The 83rd Session had adjourned sine die on 2 June 2025, so no override vote was possible, and Nevada's Legislature meets only in odd-numbered years.

Key Case Law & Precedent

FTC v. Cerebral, Inc. (D.D.C. 2024)

US Federal Trade Commission + DOJ · 2024

FTC/DOJ settlement against telehealth mental-health platform Cerebral for deceptive cancellation practices and unauthorized sharing of sensitive mental-health data (names, medical histories, IP addresses of 3.2M+ people) with third parties including LinkedIn and TikTok via tracking pixels. Cited here as an illustrative federal consumer-protection precedent for digital mental-health platforms; no Nevada-specific source found this cycle confirming the Nevada AG has cited this case by name.

Outcome: Order imposed a $10M civil penalty, suspended to $2M actually payable due to Cerebral's documented inability to pay the full amount, plus ~$5.1M in consumer redress (total actual payment ~$7.1M, of which over 40,000 consumers received refunds by May 2025) and a permanent injunction banning use/disclosure of sensitive health data for advertising.

Case reference

Frequently Asked Questions

Does Nevada AI Stack — DOI Bulletin 24-001 (NAIC AI Model Bulletin), AB 406 Mental/Behavioral Healthcare AI, Utilization-Review and Claim-Denial Law apply to my business?

Nevada regulates AI through three separate surfaces. (1) INSURANCE — Division of Insurance Bulletin 24-001, "Use of Artificial Intelligence Systems by Insurers" (issued 23 February 2024, signed by Commissioner Scott J. Kipper), Nevada's adoption of… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Nevada AI Stack — DOI Bulletin 24-001 (NAIC AI Model Bulletin), AB 406 Mental/Behavioral Healthcare AI, Utilization-Review and Claim-Denial Law is: AB 406: civil penalties up to $15,000 per violation for providers offering prohibited mental/behavioral healthcare AI, plus Nevada licensing board discipline (suspension/revocation) for licensed clinicians. INSURANCE (Bulletin 24-001 routes through the Unfair Trade Practices Act): administrative fine of not more than $5,000 for each act or violation of NRS 686A.010–686A.310 where the person knew or reasonably should have known of the violation, except that for licensed agents, brokers, solicitors and adjusters the fine must not exceed $500 per act, plus suspension or revocation of the license (NRS 686A.183(1)); a further administrative fine of not more than $5,000 for each and every violation of a resulting cease-and-desist order, plus suspension or revocation (NRS 686A.187). Corporate Governance Annual Disclosure: civil penalty of $1,500 for each day of late filing, capped at $100,000 (NRS 692C.3509). Independent utilization-review agents: fine of not more than $1,000 for violating NRS 683A.375–683A.378 (NRS 683A.379).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Nevada AI Stack — DOI Bulletin 24-001 (NAIC AI Model Bulletin), AB 406 Mental/Behavioral Healthcare AI, Utilization-Review and Claim-Denial Law?

The 15 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://doi.nv.gov/uploadedFiles/doinvgov/_public-documents/News-Notices/Bulletins/Bulletin_2024_24-001.pdf

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan