Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
US-VTMEDIUM coverage

Vermont — Insurance Bulletin No. 229 (NAIC AI Model RE-DOMESTICATED: every model-act name scrubbed, all five citation brackets filled, authority clause hedged with "primarily") + the Vein's BROADEST Rating Limb (P&C + health + life + long-term care) That Contradicts Its Own Operative Sentence + Mandatory Scoring-Model Filing (8 V.S.A. § 4727(j)) + Price-Optimization Disclosure Directive With Its Own Violation Hook (Bulletin No. 186) + Virtual/Image-Based Claims Adjusting Backstop Extended to All Lines (Bulletin No. 206 rev., 2026) + Mental-Health Review-Agent LICENSURE (8 V.S.A. § 4064) + Prior-Auth Deemed-Granted Clocks (18 V.S.A. § 9418b) + the AI-Utilization-Review Statute Vermont Passed the House and DID NOT ENACT (H.814 / Act 101 of 2026): AI Compliance Requirements

Vermont has no comprehensive private-sector AI statute reaching insurers, and its AI bulletin is among the EARLIEST adoptions of the national model anywhere — 12 March 2024, barely three months after the NAIC adopted it. What makes Vermont distinctive is not the bulletin's expectations, which are the model's almost word for word, but what Vermont did to the AUTHORITY section around them, how far its rating limb reaches, and a 2026 statute that came within one chamber of imposing the strictest AI-utilization-review rule in the country and then did not. (1) THE INSTRUMENT. Insurance Bulletin No. 229, "The Use of Artificial Intelligence Systems in Insurance" (12 March 2024, Commissioner Kevin Gaffney), issued by the Department of Financial Regulation on departmental letterhead to "all Insurers that hold certificates of authority to do business in the state". It is a bulletin, not an order and not a rule. Unlike Delaware's Bulletin 148 it carries NO express non-binding disclaimer and NO durability or effective-date clause of any kind — it simply ends with the Commissioner's signature and the date. (2) THE MODEL DIFF IS AN EIGHTH SHAPE, and the right name for it is RE-DOMESTICATED. The shapes recorded in this ledger so far are verbatim (Oklahoma, Arkansas), verbatim-plus-citations (District of Columbia), verbatim-plus-citations-and-broadened (Rhode Island), softened (Kentucky), gutted (West Virginia), tightened-and-thinned or bidirectional (New Hampshire) and broadened-but-disclaimed (Delaware). Vermont fits none. On the OPERATIVE text it is the most faithful copy in the vein: Sections 2, 3 and 4 are verbatim to the character once page furniture and OCR spacing are normalised. It KEEPS the four-sentence background paragraph on AI risk (New Hampshire deleted it); KEEPS "the Insurer's OWN ASSESSMENT of the degree and nature of risk" (New Hampshire deleted it); KEEPS Guideline 1.3's "senior management ACCOUNTABLE TO THE BOARD OR AN APPROPRIATE COMMITTEE OF THE BOARD"; KEEPS "to identify errors AND BIAS" and plain "bias analysis and minimization" at all four occurrences (New Hampshire deleted "and bias" and inserted "UNFAIR" at all four); KEEPS "the transparency and EXPLAINABILITY of outcomes" (New Hampshire substituted "articulable"); KEEPS "Third Party" defined as an "ORGANIZATION" (Rhode Island broadened it to "entity"); and RETAINS Section 4's itemised production list in full, including "or evidencing", "that is the subject of investigation or examination", and "where applicable" at 2.3 and Guideline 4.3. It does not even re-designate the defined party — it is "Insurer" throughout, where Delaware substituted "insurance carrier" at some forty places. The re-domestication is confined to Section 1, and it is thorough. Vermont DELETED EVERY NAIC MODEL-ACT NAME AND NUMBER from the authority bullets — "Unfair Trade Practices Model Act (#880)", "Unfair Claims Settlement Practices Model Act (#900)", "Corporate Governance Annual Disclosure Model Act (#305)", "Property and Casualty Model Rating Law (#1780)" and "Market Conduct Surveillance Model Law (#693)" are all gone — and substituted Vermont-native subject headings ("Insurance Trade Practices", "Claims Settlement Practices", "Corporate Governance Annual Disclosure", "Insurance Rate Requirements", "Market Conduct Examinations and Investigations"). No other adopter characterised in this ledger scrubbed the model scaffolding wholesale. Vermont then FILLED ALL FIVE citation brackets, including the market-conduct one that Delaware deleted outright and left uncited. And it inserted a two-word HEDGE the model does not contain: the expectations "rely, PRIMARILY, on the following laws and regulations", which converts the model's closed authority list into an open one. Read against the District of Columbia — which the ledger records as filling every bracket while softening nothing and adding no state-authored language — Vermont is the same instinct carried three steps further: more citation, less NAIC, and one hedge. (3) THE RATING LIMB IS THE BROADEST IN THE VEIN AND IT CONTRADICTS ITS OWN NEXT SENTENCE. This is the second break in the accident-and-health exclusion, after Delaware, and it is a wider break by a different mechanism. Where the model's bullet is the Property and Casualty Model Rating Law and confines itself to property and casualty, Vermont replaced the bullet's opening sentence with a compliance statement spanning FOUR lines of business — "property and casualty see 8 V.S.A. §§ 3861 and 4685, HEALTH see 8 V.S.A. §§ 4062, 4083 and 5104, LIFE see 8 V.S.A. § 3701, and LONG-TERM CARE see Rule H-2009-01" — and coined a defined term, the "Rating Laws", for the set. Vermont is therefore the first adopter in this vein to pull LIFE and LONG-TERM CARE into the AI rating expectation at all; Delaware reached health but its rate chapter expressly excludes life at 18 Del. C. § 2502(b)(3). Two honest qualifications must travel with that, and both matter to an insurer sizing its obligation. FIRST, the defined term is DEAD: "Rating Laws" appears exactly once in Bulletin 229, in the sentence that coins it, and is never used again. SECOND, and more consequential, the very next sentence is the model's VERBATIM and confines the operative duty to property and casualty — rates developed with AI and Predictive Models must not be "excessive, inadequate, or unfairly discriminatory with respect to all forms of casualty insurance—including fidelity, surety, and guaranty bond—and to all forms of property insurance—including fire, marine, and inland marine insurance". Delaware faced the same seam and resolved it by REPLACING that line-list with "all forms of insurance"; Vermont broadened the authority sentence and left the line-list untouched, so Bulletin 229's rating limb points wider than it reaches. Reading the cited statutes settles what actually binds. The tri-standard "excessive, inadequate, or unfairly discriminatory" genuinely attaches only to property and casualty, at 8 V.S.A. § 4685(a), and to HMO rates, at § 5104(a)(2). For life (§ 3701) and for non-HMO health (§ 4083 as issued, § 4013 today) the binding standard is narrower and different — no unfair discrimination between insureds "of the same class and of equal expectation of life", or "between individuals of substantially the same hazard". So a Vermont life insurer's AI model is answerable for discrimination but not for excessiveness; a Vermont property insurer's model is answerable for all three. (4) THE PRODUCTION DUTY HAS A CLOCK AND A PER-DAY PENALTY — Vermont sits between New Hampshire and Delaware. Vermont KEPT the market-conduct bullet and cited 8 V.S.A. §§ 3573 and 3574 for it, where Delaware deleted the bullet and cited nothing. It did NOT make New Hampshire's and Delaware's two-word tightening: the residual sentence is the model's plain "subject to investigation, including market conduct actions", with no "or examination" added. §§ 3573 and 3574 supply not a production window but an examination-report CYCLE — report filed within 60 days of completion, up to 30 days for the company's written submission or rebuttal, adoption within 30 days of the end of that period, administrative appeal within 30 days of the order, and a 15-day confidentiality window after it. Two clauses in § 3573 bite an AI examination specifically: under § 3573(b) the Commissioner may retain "independent actuaries, independent certified public accountants, or other professionals and specialists, THE COST OF WHICH SHALL BE BORNE BY THE COMPANY that is the subject of the examination" — the insurer pays for the specialist who audits its model — and under § 3573(e) the Commissioner may "use and make public" any report, work papers or information discovered during an examination. The actual production clock is general and sits at 8 V.S.A. § 13(a): a subpoena or notice to produce papers and records must allow "at least SIX BUSINESS DAYS" to comply, shortenable for good cause, with mailed service effective three business days after mailing. § 13(b) then prices refusal at "not more than $2,000.00 FOR EACH DAY of noncompliance" plus suspension of the authority to do business for up to six months. Against New Hampshire's ten-working-day statutory window and Delaware's no-deadline-at-all, Vermont has a shorter clock than New Hampshire and a per-day meter neither has. (5) THE HARD RULES ARE IN 8 V.S.A. § 4727, AND IT SITS INSIDE THE UNFAIR TRADE PRACTICES CHAPTER. This is the structural fact that makes Vermont's scoring rules bite harder than Delaware's: Delaware regulates credit-based insurance scoring in a standalone chapter (18 Del. C. ch. 83), whereas Vermont put it at § 4727 INSIDE chapter 129, the UTPA — which is why Bulletin 229 cites "§§ 4721-4724 and 4727" for unfair trade practices, and why a scoring violation is itself an unfair trade practice carrying the § 4726 penalties. § 4727 was added by 2017 Act 179 (Adj. Sess.), § 6, effective 28 May 2018, and it named algorithms and models in Vermont's insurance code years before the AI bulletin existed: § 4727(c)(8) defines an "insurance score" as "a number or rating that is derived from an ALGORITHM, COMPUTER APPLICATION, MODEL, or other process that is based in whole or in part on credit information". § 4727(j) is the Vermont analogue of Delaware's § 8309(a) and New Hampshire's RSA 412:16, II, and it is drafted more broadly than either: "Insurers that use insurance scores to underwrite and rate risks MUST FILE THEIR SCORING MODELS, OR OTHER SCORING PROCESSES, with the Department of Financial Regulation. A third party may file scoring models on behalf of insurers." The words "or other scoring processes" reach past a trained model to a rules engine or a vendor pipeline. § 4727(j) also adds a shield the Delaware provision does not carry: "Any filing relating to credit information is considered a trade secret and is not subject to disclosure under Vermont's Public Records Act." Scope is confined by § 4727(b) to PERSONAL insurance — private passenger automobile, homeowners, motorcycle, mobile home owners and noncommercial dwelling fire — and expressly not to commercial insurance. (6) UTILIZATION REVIEW — the standing sweep, and Vermont produces a bar found nowhere else in this vein: LICENSURE OF THE REVIEWER ITSELF. 8 V.S.A. § 4064 (recodified from the former § 4089a by 2025 Act 11, § 2, eff. 1 September 2025) provides that "ANY PERSON who approves or denies payment, or who RECOMMENDS approval or denial of payment, for mental health services, or WHOSE REVIEW RESULTS IN approval or denial of payment for mental health services on a case-by-case basis, SHALL NOT REVIEW these services in this State unless the Commissioner has granted the person a REVIEW AGENT'S LICENSE", and § 4064(b)(4) defines "review agent" as "a person OR ENTITY". Every other bar recorded in this vein is a species-of-decider rule — the District of Columbia bars the adverse determination itself, Rhode Island requires it made, documented and signed, New Hampshire requires a clinician but expressly disclaims a specialty match at first review, Delaware requires same-or-similar specialty at first instance with compensation independence. Vermont is the first to put a STATE LICENCE between the reviewing apparatus and the file. On top of that the statute dictates the content of the Commissioner's rules, and three of those bite an automated pipeline directly: § 4064(c)(3) requires that any determination that may result in denial of reimbursement or precertification "include the evaluation, findings, and CONCURRENCE of a mental health professional whose training and expertise is AT LEAST COMPARABLE TO THAT OF THE TREATING mental health provider" — a comparison against the treating clinician, not against a specialty list, at first instance; § 4064(c)(5) provides that an adverse determination "SHALL NOT BE MADE UNTIL the review agent has COMMUNICATED WITH the patient's attending mental health provider concerning that care", a mandatory sequencing rule that no model can satisfy on its own; and § 4064(c)(10)(A) prohibits any payment arrangement between the review agent and the payor that "includes an INCENTIVE OR CONTINGENT FEE arrangement based on the reduction of mental health services, reduction of length of stay, reduction of treatment, or treatment setting selected". § 4064(c)(1) adds a disclosure duty with a clock — within 10 business days of request, at no cost, the specific review criteria and standards, the CREDENTIALS OF THE REVIEWING PROFESSIONALS, and the procedures and methods used. HONEST NEGATIVE, with method: § 4064, § 4063 and 18 V.S.A. § 9418b were each string-scanned in full this session for "artificial intelligence", "algorithm", "machine learning", "automated" and "predictive" — zero hits in all three. Vermont's utilization-review reservations are licensure and species-of-decider rules, not AI rules, which is precisely why they bite an AI system: a model cannot hold a review agent's licence, cannot be a mental health professional whose training is comparable to the treating provider's, and cannot place the call to the attending clinician. (7) THE AI-UTILIZATION-REVIEW STATUTE VERMONT DID NOT ENACT — the most important negative in this entry, and one that every secondary tracker gets wrong. H.814 of 2026, "An act relating to neurological rights and the use of artificial intelligence technology in health and human services", PASSED THE HOUSE at 32 pages carrying a Subchapter 3 ("Artificial Intelligence Applications Relating to Health Insurance") and a proposed 18 V.S.A. § 9771 ("USE OF ARTIFICIAL INTELLIGENCE IN UTILIZATION REVIEW"). That proposed section would have been the strictest AI-UR rule recorded anywhere in this vein: eleven affirmative conditions on any "artificial intelligence, algorithm, or other software tool" used for utilization review or utilization management based in whole or in part on medical necessity — including that it not "base its determination SOLELY ON A GROUP DATASET", that it "does not SUPPLANT health care provider decision making", that it be "OPEN TO INSPECTION for audit or compliance reviews by the Department of Financial Regulation", and that its "performance, use, and outcomes are PERIODICALLY REVIEWED AND REVISED" — capped by a categorical human-decider mandate at § 9771(b): "the artificial intelligence, algorithm, or other software tool SHALL NOT DENY, DELAY, OR MODIFY health care services based in whole or in part on medical necessity. A determination of medical necessity shall be made ONLY BY A LICENSED HUMAN HEALTH CARE PROVIDER who is competent to evaluate the specific clinical issues involved", applying prospectively, retrospectively and concurrently. NONE OF IT IS LAW. The bill was enacted as Act 101 of 2026, signed 18 May 2026 and effective on passage, at FIVE pages. The entire health-insurance subchapter was stripped. What survives is: a non-binding intent section; a new 18 V.S.A. chapter 42C ("Neurological Rights") whose § 1891 recognises six individual rights — mental and neural data privacy, freedom of thought, nondiscrimination in neurotechnology, the right to change a neurotechnology decision, protection from unauthorised access to or manipulation of brain activity, and protection from unauthorised neurotechnological alteration of mental functions critical to personality — with NO duty-holder, NO enforcement provision and NO penalty attached; an amendment to 3 V.S.A. § 5023 reconstituting the Artificial Intelligence Advisory Council and moving its sunset from 30 June 2027 to 30 June 2030; and a REPORT. That report is the live item: on or before 15 JANUARY 2027 the Council must recommend to the General Assembly any additional statutory changes, expressly including "(C) REGULATING THE USE OF ARTIFICIAL AND AUGMENTED INTELLIGENCE IN HEALTH INSURANCE UTILIZATION REVIEW PROCESSES". So the correct statement of Vermont law today is that it has no binding AI-utilization-review rule and a statutory instruction to design one, with a dated deliverable a health insurer should be tracking. Separately, H.341 of 2025 (oversight and safety standards for "inherently dangerous" AI systems) never left the House Committee on Commerce and Economic Development — last recorded action 25 February 2025, read first time and referred. (8) PRIVACY INTERPLAY, AND IT IS THE MIRROR IMAGE OF DELAWARE'S. Vermont enacted a comprehensive privacy statute at the same session — S.71, the Vermont Data Privacy and Online Surveillance Act, Act 145 of 2026, signed 16 JUNE 2026 per the act's own signature line and taking effect 1 JANUARY 2028. It does not reach insurers. § 2415c(a)(16) exempts, at ENTITY level, "a person regulated pursuant to 8 V.S.A. part 3 (chapters 101–165)", with a single carve-back for a person who "establishes and maintains a SELF-INSURANCE program and who does not otherwise engage in the business of entering into policies of insurance". Delaware's DPDPA has no insurer entity exemption at all and carves out only GLBA/HIPAA/FCRA data; Vermont exempts the insurer itself and leaves the pure self-insured plan sponsor inside. A third-party administrator is separately exempt under § 2415c(a)(19), but ONLY while "subject to and in compliance with" the Department's Regulation IH-2001-01 (Privacy of Consumer Financial and Health Information) — which is the privacy regime that actually governs a Vermont insurer's AI training and inference data. Enforcement of Act 145 is by the Attorney General under 9 V.S.A. § 2415j(a) with a mandatory notice-and-60-day-cure period between 1 January 2028 and 30 June 2029, and there is no private right of action, though the act records the General Assembly's intent to consider adding one if enforcement is not funded. (9) A STRUCTURAL FACT THE BULLETIN DOES NOT MENTION: the Department did not issue the rating rules it points at for health. Under 8 V.S.A. § 4026(a)(1) (the recodified § 4062) a health insurer files the form and the rules for the classification of risks with the Department of Financial Regulation, but files the PREMIUM RATES with the GREEN MOUNTAIN CARE BOARD, and it is the Board — a body that did not issue Bulletin 229 and has published no AI guidance of its own — that must "approve, modify, or disapprove a rate request WITHIN 90 CALENDAR DAYS after receipt of an initial rate filing". Vermont is the only state in this vein so far whose AI bulletin's rating limb points at statutes administered outside the issuing department, and a health insurer running an AI-assisted rate development therefore answers to two regulators on one filing. (10) THE DFR BULLETIN SHELF, SWEPT, WITH THE NEGATIVES BOUNDED. The Department publishes bulletins and regulations through a single filterable index at dfr.vermont.gov/view/regbul; the Insurance-Bulletin series was paged in full from No. 22 (20 December 1974) to No. 240 ("Withdrawal of Obsolete Bulletins", signed 10 April 2026, effective 8 May 2026), and the Insurance-Regulation series in full to Regulation I-2013-01 (Revised, effective 1 January 2026). A keyword sweep across every title for artificial, AI, algorithm, machine learning, predictive, model, analytic, big data, accelerated underwriting, insurance scoring, credit scoring, credit information, price optimization, external consumer data, ECDIS, telematics, aerial, drone, unmanned, imagery, utilization review, prior authorization, claims settlement, unfair discrimination and rate filing returns exactly THREE machine-decision instruments: Bulletin No. 229 (AI, 2024), Bulletin No. 186 (Price Optimization in Personal Lines Ratemaking, 24 June 2015, Commissioner Susan L. Donegan) and Bulletin No. 206 (revised) (Virtual Adjustment of Insurance Claims, 12 February 2026, executed 17 February 2026, Commissioner Kaj Samsom). Both of the latter are carried as requirements below and both were read in their own text — No. 186 has NO TEXT LAYER at all (2 pages, one extractable character) and was rendered to image and read visually rather than guessed at. THE NEGATIVES, and they are worth as much as the hits: Vermont has NO bulletin on credit-based insurance scoring, NO bulletin on external consumer data and information sources or ECDIS, NO bulletin on accelerated underwriting in life insurance, NO bulletin on telematics, and NO bulletin on aerial, drone or UAS imagery in underwriting. Bind the scoring negative correctly, because it is the same structural pattern seen in Delaware: Vermont regulates credit-based scoring BY STATUTE at 8 V.S.A. § 4727, which is why the bulletin shelf is bare there — the absence is not a gap. The other four are genuine absences, bounded through the most recent bulletin in the series (May 2026). Two adjacent items should not be mistaken for AI regulation: Bulletin No. 236 (Changes to Competitive Market Filing Requirements for Property and Casualty Rates, 26 August 2025) is filing-timing procedure whose only model-adjacent content is a passing checklist reference to generalized-linear-model questions, and Regulation I-2019-03 (Insurance Regulatory Sandbox; Innovation Waiver Regulation, effective 1 January 2020) is a general insurtech pilot-waiver mechanism, not a rule governing algorithmic decisions. One currency correction: Bulletin No. 178, which revised the § 9418b(g)(4) nonurgent prior-authorization timeframe, was formally WITHDRAWN by Bulletin No. 240 and must not be cited as current guidance; the prior-authorization clocks now live in the statute itself as amended in 2025.

Summary of publicly-available regulatory text as of 2026-08-27. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

March 12, 2024

Maximum Penalty

Vermont's headline number is small and deeply misleading, and an insurer that prices its AI exposure off the Unfair Trade Practices Act figure will understate it by an unbounded margin. THE UTPA FIGURE IS THE LOW ONE. 8 V.S.A. § 4726(b) provides that any person violating any provision of chapter 129 "may be subject to an administrative penalty of NOT MORE THAN $1,000.00 for each violation", rising to "not more than $10,000.00 each for those violations the Commissioner finds were WILLFUL", with power to suspend or revoke the licence of any insurer or organization "for any violation of this chapter OR THE FAILURE TO COMPLY WITH AN ORDER of the Commissioner". There is no aggregate cap and no six-month reset — unlike Delaware's § 2308(a), which caps the equivalent exposure at $100,000 in aggregate — so a defective model applied across a whole book multiplies without ceiling, but at $1,000 a consumer. § 4726(a) supplies the investigation power and § 4726(c) preserves every other penalty authorised by law. Because 8 V.S.A. § 4727 (credit information and insurance scores) sits INSIDE chapter 129, a scoring-model failure — including a failure to file the model under § 4727(j) — is itself an unfair trade practice priced at these figures. THE REAL EXPOSURE IS 8 V.S.A. § 13, WHICH IS UNCAPPED. § 13(d) empowers the Commissioner, "in addition to any other penalties or powers", to order a person "to make RESTITUTION or provide DISGORGEMENT of any sums shown to have been obtained in violation of provisions of this title and 18 V.S.A. chapter 221, PLUS INTEREST at the legal rate" — so an AI rating or underwriting model that overcharged is exposed to the full premium differential with interest, a figure that bears no relation to the per-violation caps. § 13(b) separately prices obstruction of the Section 4 production duty at "not more than $2,000.00 FOR EACH DAY of noncompliance" with the authority to do business suspendable for up to six months, and § 13(c) lets an unappealed final order be filed with a court and enforced as a judgment. OTHER ROUTES, EACH WITH A DIFFERENT NUMBER. Mental-health utilization review: 8 V.S.A. § 4064(e) provides that a person who violates any provision of that section, or submits false information in a licence application, "may be fined NOT MORE THAN $5,000.00 for each violation", and § 4064(d) additionally subjects review agents to chapter 129 — so an unlicensed or non-compliant review agent is exposed twice. Prior authorization: 18 V.S.A. § 9418b(e) is the SMALLEST figure and the hardest to trigger, requiring a finding that the plan "has engaged in a PATTERN AND PRACTICE of violating this section" before the Commissioner may impose "no more than $500.00 for each violation", order a cease and desist, and order remediation, weighing five statutory factors including "the economic benefit derived by the health plan". Property and casualty rate discrimination: 8 V.S.A. § 3861 carries its own "administrative penalty of not more than $2,000.00". Bulletin 229 itself creates NO penalty and is not a hook — it is neither a statute nor a rule adopted under 3 V.S.A. chapter 25, and it contains no enforcement clause whatever; every sanction above arrives through the statutes underneath it. Note finally that findings of fact from a market conduct examination are "PRIMA FACIE EVIDENCE in any legal or regulatory action" under 8 V.S.A. § 3573(d), and that the Commissioner may make examination work papers public under § 3573(e) — the reputational and evidentiary consequences of an adverse AI examination can exceed the fines.

What Your Business Must Do

16 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

8 V.S.A. § 4727(j) — MANDATORY Filing of Scoring Models "or Other Scoring Processes", With a Trade-Secret Shield

Critical

Vermont requires the model itself to be filed, not merely the rates it produces, and it does so in language broader than any comparable provision recorded in this vein. 8 V.S.A. § 4727(j): "Insurers that use insurance scores to underwrite and rate risks MUST FILE THEIR SCORING MODELS, OR OTHER SCORING PROCESSES, with the Department of Financial Regulation. A THIRD PARTY MAY FILE SCORING MODELS ON BEHALF OF INSURERS. A filing that includes insurance scoring may include loss experience justifying the use of credit information. Any filing relating to credit information is considered a TRADE SECRET and is not subject to disclosure under Vermont's Public Records Act." Three points of construction matter. First, "or other scoring processes" reaches beyond a trained statistical model to a rules engine, a vendor pipeline or any other process that produces the score — the obligation does not turn on the technique. Second, the definition it plugs into was written to catch algorithms: § 4727(c)(8) defines "insurance score" as "a number or rating that is derived from an ALGORITHM, COMPUTER APPLICATION, MODEL, or other process that is based in whole or in part on credit information for the purposes of predicting the future insurance loss exposure of an individual applicant or insured". Third, the vendor-filing permission does not move the obligation: a third party MAY file on the insurer's behalf, but the duty to have filed remains the insurer's. The scope limit is real and should be applied strictly — § 4727(b) confines the whole section to PERSONAL insurance, defined as private passenger automobile, homeowners, motorcycle, mobile home owners and noncommercial dwelling fire policies underwritten for personal, family or household use, and states that "this section applies to personal insurance and NOT TO COMMERCIAL INSURANCE" and that no other type is included. Commercial-lines scoring models carry no § 4727(j) filing duty. Because § 4727 sits inside chapter 129, a failure to file is itself an unfair trade practice rather than a mere filing default.

Deadline: May 28, 2018

8 V.S.A. § 4727(j) (filing of scoring models or other scoring processes; third-party filing; trade-secret treatment), with the definition of "insurance score" at § 4727(c)(8) and the personal-insurance scope limit at § 4727(b); added by 2017 Act 179 (Adj. Sess.), § 6, effective 28 May 2018.

8 V.S.A. § 4727(d) — Prohibited Model Inputs, the No-Sole-Basis Rule, and Two Hard Data-Currency Clocks

Critical

An insurer using credit information to underwrite or rate personal insurance in Vermont SHALL NOT do any of the following, and each is a design constraint on the model rather than a documentation duty. (1) Use an insurance score calculated using "INCOME, GENDER, ADDRESS, ZIP CODE, ETHNIC GROUP, RELIGION, MARITAL STATUS, OR NATIONALITY of the consumer as a factor" — a statutory proxy-variable ban that reaches ADDRESS and ZIP CODE, which most states do not; note it is narrower than Delaware's equivalent, which additionally names education, sexual orientation, gender identity and race. (2) Deny, cancel or nonrenew a personal insurance policy "SOLELY on the basis of credit information without consideration of any other applicable underwriting factor independent of credit information". (3) Base renewal rates "SOLELY upon credit information" without an independent factor. (4) Take adverse action solely because the consumer has no credit card account. (5) Consider an absence of credit information or an inability to calculate a score unless the insurer either treats the consumer as approved by the Commissioner on evidence that the absence relates to risk, treats them as having NEUTRAL credit information as the insurer defines it, or excludes credit information entirely and uses only other criteria. (6) Take adverse action based on credit information "unless an insurer obtains and uses a credit report issued or an insurance score calculated WITHIN 90 DAYS from the date the policy is first written or renewal is issued" — a hard staleness limit on the input to an adverse decision. (7) Use credit information unless, "not later than every 36 MONTHS" following the last time it obtained current credit information, the insurer recalculates the score or obtains an updated report; at annual renewal, on request of the consumer or their agent, the insurer SHALL reunderwrite and rerate on a current report or score, though not more often than once in any 12-month period, with four narrow exceptions including where the insured is already in the most favourably priced tier. (8) Use as a NEGATIVE FACTOR in any scoring methodology: consumer-initiated or self-inquiry credit inquiries; inquiries relating to insurance coverage where so identified; COLLECTION ACCOUNTS WITH A MEDICAL INDUSTRY CODE where so identified; and multiple home-mortgage or automobile-lending inquiries coded as such and made within 30 days of one another, unless only one is counted.

Deadline: May 28, 2018

8 V.S.A. § 4727(d)(1)-(8) (prohibited inputs, no-sole-basis rules, no-credit-history handling, 90-day score currency for adverse action, 36-month rescoring and annual-renewal rerating on request, prohibited negative factors), within the personal-insurance scope set by § 4727(b).

8 V.S.A. § 4064 — REVIEW AGENT LICENSURE: the Only Bar in This Vein That Puts a State Licence Between the Reviewing Apparatus and the File

Critical

Vermont regulates who — or what — may perform mental health service review at all. § 4064(c): "ANY PERSON who approves or denies payment, or who RECOMMENDS approval or denial of payment, for mental health services, or WHOSE REVIEW RESULTS IN approval or denial of payment for mental health services ON A CASE-BY-CASE BASIS, shall not review these services in this State unless the Commissioner has granted the person a REVIEW AGENT'S LICENSE." § 4064(b)(4) defines "review agent" as "a PERSON OR ENTITY" performing service review activities who is affiliated with, under contract with, or acting on behalf of a business entity in the State and who provides or administers mental health benefits to members of health insurance plans subject to the Department's jurisdiction, "INCLUDING A HEALTH INSURER"; § 4064(b)(5) defines "service review" to include "activities of UTILIZATION REVIEW and MANAGED CARE", excluding only professional peer review that does not affect reimbursement or provision of services. The statute then dictates what the Commissioner's implementing rules must contain, and four of those provisions bear directly on an automated pipeline. FIRST, a determination that may result in denial of reimbursement or of precertification "shall include the evaluation, findings, and CONCURRENCE of a mental health professional whose TRAINING AND EXPERTISE IS AT LEAST COMPARABLE TO THAT OF THE TREATING mental health provider" (§ 4064(c)(3)) — a comparison against the actual treating clinician, applied at first instance, and requiring concurrence rather than mere availability. SECOND, a determination that care is inappropriate "SHALL NOT BE MADE UNTIL the review agent has COMMUNICATED WITH the patient's attending mental health provider concerning that care", and the review "shall be prospective or concurrent with the treatment" (§ 4064(c)(5)) — a mandatory sequencing step before any adverse determination. THIRD, such a determination "shall include the WRITTEN EVALUATION AND FINDINGS of the review agent" (§ 4064(c)(6)). FOURTH, § 4064(c)(10)(A) prohibits any agreement between the review agent and a business entity or third-party payor in which payment "includes an INCENTIVE OR CONTINGENT FEE ARRANGEMENT based on the reduction of mental health services, reduction of length of stay, reduction of treatment, or treatment setting selected" — a compensation-independence rule aimed at the review contract itself. There is also a disclosure duty with a clock: within 10 BUSINESS DAYS of a request the review agent must make available at no cost to affected clients, patients and providers "the specific review criteria and standards, CREDENTIALS OF THE REVIEWING PROFESSIONALS, and procedures and methods to be used in evaluating proposed or delivered mental health services" (§ 4064(c)(1)). HONEST NEGATIVE: § 4064 contains no reference to artificial intelligence, algorithms, machine learning, automation or predictive models — string-scanned in full this session. It reaches AI because of what it demands of the decider, not because it names the technology.

Deadline: September 1, 2025

8 V.S.A. § 4064(c) (review agent licence requirement) with definitions at § 4064(b)(4)-(5), mandated rule content at § 4064(c)(1), (3), (5), (6) and (10)(A), UTPA application at § 4064(d) and penalties at § 4064(e); recodified from the former 8 V.S.A. § 4089a by 2025 Act 11, § 2, effective 1 September 2025.

18 V.S.A. § 9418b — Prior Authorization: DEEMED GRANTED on a Missed Clock, No Prior Auth at All for Primary-Care Orders, and an Annual Attestation

Critical

Vermont's prior authorization statute constrains an automated utilization management system harder through timing and scope than through any AI-specific rule. CATEGORICAL SCOPE BAR: under § 9418b(c)(1)(A) a health plan "shall NOT impose ANY prior authorization requirement for any admission, item, service, treatment, or procedure ORDERED BY A PRIMARY CARE PROVIDER", excepting only prescription drugs and out-of-network care — so no model may route PCP-ordered care into prior authorization at all. CLOCKS. For URGENT requests the plan must approve, deny, or inform the requester that information is missing WITHIN 24 HOURS of receipt, and has a further 24 hours to approve or deny once the missing information arrives. For NONURGENT requests the plan must approve or deny a completed request WITHIN TWO BUSINESS DAYS of receipt, must acknowledge receipt within 24 hours and flag any missing information at that time, and has 24 hours after receiving it to decide. THE DEFAULT IS APPROVAL: § 9418b(g)(4)(C) provides that if a plan fails within those limits to respond to a completed request, to acknowledge receipt, or to request missing information, "THE PRIOR AUTHORIZATION REQUEST SHALL BE DEEMED TO HAVE BEEN GRANTED" — a queueing failure or an unavailable model is a coverage grant, not a delay. DURABILITY: an approval is valid for the duration of the prescribed treatment or ONE YEAR, whichever is longer, and for treatment continuing beyond a year renewal may not be required more than once every FIVE YEARS (§ 9418b(g)(4)(D)); and for an insured stable on a treatment approved under a previous plan, the new plan may not restrict coverage for at least 90 DAYS after enrolment (§ 9418b(g)(4)(E)). INTAKE: the plan must accept either the HIPAA 278 standard transaction or the Department's uniform prior authorization form, and must be capable of accepting both. TRANSPARENCY: on request from a provider the plan must furnish a current list of services and supplies requiring prior authorization, and must publish that list on its website. ANNUAL PRUNING: § 9418b(h)(1) requires the plan to review its prior authorization list at least annually and to ELIMINATE requirements "no longer justified or for which requests are ROUTINELY APPROVED with such frequency as to demonstrate that the prior authorization requirement does not promote health care quality or reduce health care spending to a degree sufficient to justify the administrative costs", and § 9418b(h)(2) requires attestation to the Department of Financial Regulation and the Green Mountain Care Board annually ON OR BEFORE 15 SEPTEMBER that the review and elimination have been done. A high automated approval rate is therefore itself evidence that the requirement should be removed. HONEST NEGATIVE: § 9418b names no AI, algorithm, automation or predictive model — string-scanned in full this session.

Deadline: March 5, 2025

18 V.S.A. § 9418b(c)(1) (no prior authorization for primary-care-ordered services), § 9418b(d) (list furnished on request and published), § 9418b(g)(1) and (4)(A)-(E) (HIPAA 278 or uniform form; 24-hour urgent and two-business-day nonurgent clocks; deemed granted on default; one-year and five-year durability; 90-day continuity), § 9418b(h)(1)-(2) (annual review, elimination, and 15 September attestation) and § 9418b(e) (penalties); as amended by 2023 Act 111 (Adj. Sess.), §§ 3-4, effective 1 January 2025 and 2025 Act 3, § 2, effective 5 March 2025.

Bulletin No. 186 — Price Optimization: Non-Risk Rating Factors Barred AND Affirmatively Disclosable on Every Personal-Lines SERFF Filing, With Non-Disclosure Deemed a Statutory Violation

Critical

Vermont banned algorithmic price optimization nine years before it addressed AI, and did it with a filing mechanic that makes the bar auditable — which is why this bulletin, not Bulletin 229, is the sharpest constraint on a modern personal-lines pricing model. Bulletin No. 186 (24 June 2015, Commissioner Susan L. Donegan) applies to "all property and casualty insurers issuing personal lines policies in Vermont". It describes price optimization as "the judgmental use of factors NOT SPECIFICALLY RELATED TO A POLICYHOLDER'S RISK PROFILE to help determine or adjust his or her insurance premium", giving as the example "using an individual policyholder's response to previous premium increases to determine how much of a premium increase the policyholder will tolerate at renewal before engaging in comparison shopping or switching to a different insurer", and observing that the practice "can result in two policyholders receiving different premium increases even though they have the SAME LOSS HISTORY AND RISK PROFILE". Reading 8 V.S.A. § 4685(d) with § 4686(2), the Department states the substantive rule in italics: "BOTH BASE RATES AND RATING CLASSES MUST BE BASED ON FACTORS SPECIFICALLY RELATED TO AN INSURER'S EXPECTED LOSSES AND EXPENSES." Judgment in setting rates remains permitted, but "judgmental adjustments to a rate MAY NOT be based on non-risk-related factors such as \u2018price elasticity of demand\u2019", and such use "not only unfairly discriminates between policyholders of the same risk profile, but is also directly in conflict with the statutory principles that underlie Vermont's \u2018open and competitive\u2019 property and casualty marketplace". THE OPERATIVE DIRECTIVE IS AFFIRMATIVE AND ONGOING: "insurers are directed that henceforth ALL PERSONAL LINES RATE FILINGS MUST DISCLOSE ON THE SERFF GENERAL INFORMATION PAGE whether the company uses non-risk-related factors such as \u2018price elasticity of demand\u2019 ... to help determine the insured's final premium", and filings then under review had to be amended to add the disclosure. The authority is 8 V.S.A. § 4688(a), which requires every insurer in a competitive market to file "all rates and supplementary rate information, and supporting information which are to be used in this State" not later than 30 days before the effective date; the Department reasons that the definitions of those terms at 8 V.S.A. § 4683(18) and (19) "make it clear that these terms include ALL FACTORS that are used to help determine a policyholder's final premium". The bulletin then supplies its own enforcement hook, which Bulletin 229 conspicuously lacks: "A FAILURE TO COMPLY WITH THIS DIRECTIVE SHALL BE CONSIDERED A VIOLATION OF SECTION 4688(a)." For an AI pricing model the practical test is not whether the model is called an optimizer but whether any feature, weight or post-model adjustment is driven by expected customer behaviour — retention propensity, shopping likelihood, elasticity, conversion — rather than by expected losses and expenses. If any is, the model is both substantively non-compliant and, unless disclosed on the SERFF General Information page, in violation of § 4688(a) independently.

Deadline: June 24, 2015

Vermont Insurance Bulletin No. 186, "Price Optimization in Personal Lines Ratemaking" (24 June 2015, Commissioner Susan L. Donegan), read with 8 V.S.A. § 4685(d) (unfair discrimination), § 4686(2) (rating plans recognising probable variations in hazards or expenses), § 4688(a) (filing of all rates, supplementary rate information and supporting information at least 30 days before the effective date) and the definitions at § 4683(18)-(19).

Bulletin No. 206 (Revised) — Virtual and Image-Based Claims Adjustment: a Mandatory In-Person Inspection Backstop That the Claimant's Earlier Consent CANNOT Waive, Now Extended to ALL Lines

Critical

This is the constraint that bites an automated or computer-vision claims pipeline, and it was deliberately broadened in 2026 because insurers were extending virtual adjusting beyond motor vehicles. Bulletin No. 206 was first issued 5 December 2019 for motor vehicle partial and total loss claims; the revised bulletin (12 February 2026, executed 17 February 2026, Commissioner Kaj Samsom) states that the Division is "revising and updating the Bulletin to BROADEN ITS APPLICATION TO THE SETTLEMENT OF ALL TYPES OF INSURANCE CLAIMS due to insurers' increased use of virtual claims adjusting and expansion of that use to other lines of insurance". The authority is the unfair claims settlement practices statute: 8 V.S.A. § 4724(9)(D) makes it an unfair claim settlement practice to fail to conduct "a reasonable investigation based upon ALL AVAILABLE EVIDENCE", and § 4724(9)(F) requires "prompt, fair, and equitable settlements of claims in which liability has become reasonably clear". The Department's factual premise is squarely aimed at image-based estimation: "there is COMPELLING EVIDENCE that photographs, videos, and other virtual representations DO NOT ALWAYS REVEAL THE TRUE EXTENT OF THE DAMAGES that have been sustained." FOUR OPERATIVE RULES FOLLOW. (1) "insurers MUST PROVIDE AN IN-PERSON INSPECTION of damages by a licensed adjuster within a reasonable period of time IF REQUESTED BY A CLAIMANT or if the use of virtual adjusting is inappropriate." (2) The Division "WILL NOT consider the use of virtual adjusting to be appropriate IN ANY SITUATION in which the nature of the claim indicates that there is a reasonable basis to believe the true extent of the damages cannot be properly assessed without an in-person inspection" — an objective appropriateness test the insurer must apply per claim, not a claimant-election question. (3) CONSENT DOES NOT LOCK THE CLAIMANT IN: "Insurers MAY NOT DENY a claimant's request for an in-person inspection by an adjuster ON THE GROUNDS THAT THE CLAIMANT INITIALLY ELECTED TO USE A VIRTUAL ADJUSTMENT SYSTEM." (4) "Unreasonable delays in making an adjuster available for an in-person inspection may, in certain circumstances, be considered a violation of the insurer's obligation under Section 4724(9)(F)." For motor vehicle TOTAL LOSSES the bulletin adds a documentary rule with real force: under Department Regulation I-79-2 (Revised), Section 8(B)(2)(d), reconditioning and tune-up costs may not be deducted from a settlement offer unless "such deductions are justified and detailed as a result of an ACTUAL INSPECTION by [a] licensed adjuster or appraiser", and it is the Department's position that "actual inspection" REQUIRES AN IN-PERSON INSPECTION by a Vermont licensed adjuster or appraiser "rather than the use of virtual evidence such as photographs or videos". Condition deductions may be taken only where conditions exceed normal wear and tear for the vehicle's age and mileage, may NOT be taken for engine or transmission cleaning or for tires meeting inspection standards, and where warranted "the justification for those deductions must be DOCUMENTED IN DETAIL on the valuation report provided to the consumer". An AI damage-estimation system therefore cannot be the sole path to settlement in Vermont: the workflow must expose an unconditional claimant-triggered route to a human in-person inspection, must independently screen each claim for whether virtual assessment is appropriate at all, and must not take image-derived condition deductions on a total loss.

Deadline: February 12, 2026

Vermont Insurance Bulletin No. 206 (revised), "Virtual Adjustment of Insurance Claims" (12 February 2026, executed 17 February 2026, Commissioner Kaj Samsom), superseding the original bulletin of 5 December 2019 and extending it from motor vehicle claims to all lines; authority at 8 V.S.A. § 4724(9)(D) and (F), with total-loss deduction rules under Department Regulation I-79-2 (Revised), Section 8(B)(2)(d).

Bulletin 229 — Written AI Systems (AIS) Program, on the Model's Text Unaltered

High Priority

All Insurers authorized to do business in Vermont are EXPECTED to develop, implement and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make, or support decisions related to, regulated insurance practices. The AIS Program should be designed to mitigate the risk of Adverse Consumer Outcomes, including at a minimum the statutory provisions set out in Section 1 of the Bulletin. Vermont preserved the model's self-assessment discretion in full: controls "should be reflective of, and commensurate with, the INSURER'S OWN ASSESSMENT of the degree and nature of risk posed to consumers", weighing the nature of the decision, the type and Degree of Potential Harm to Consumers, the extent of human involvement in the final decision, the transparency and EXPLAINABILITY of outcomes to the impacted consumer, and reliance on third-party data and models. The Program must span the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, fraud detection), all phases of an AI System's own life cycle from design through retirement, and systems built in-house as well as bought. Guideline 1.9 requires processes providing NOTICE TO IMPACTED CONSUMERS that AI Systems are in use, with access to appropriate levels of information for the life-cycle phase. The Program may sit inside or outside the Insurer's ERM programme and may adopt the NIST AI Risk Management Framework, Version 1.0. Because the Bulletin was issued on 12 March 2024 with no transition period, no phase-in and no effective-date clause, the expectation has run from that date.

Deadline: March 12, 2024

Vermont Department of Financial Regulation Insurance Bulletin No. 229, "The Use of Artificial Intelligence Systems in Insurance" (12 March 2024, Commissioner Kevin Gaffney), Section 3 (Regulatory Guidance and Expectations) and AIS Program Guidelines 1.1-1.9.

Bulletin 229 — Governance Framework, With the Board-Accountability Tie and the CGAD Hook Both Intact

High Priority

Vest responsibility for the development, implementation, monitoring and oversight of the AIS Program — and for setting the Insurer's strategy for AI Systems — with "senior management ACCOUNTABLE TO THE BOARD OR AN APPROPRIATE COMMITTEE OF THE BOARD" (Guideline 1.3, kept in full where New Hampshire cut the board tie). The governance framework must "prioritize transparency, fairness, and accountability in the design and implementation of the AI Systems, recognizing that proprietary and trade secret information must be protected", and should address: policies, processes and procedures at each stage of the AI System life cycle from proposed development to retirement; documentation requirements developed WITH SECTION 4 IN MIND; and an internal accountability structure covering committee composition drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal, scope of responsibility and chains of command, the INDEPENDENCE OF DECISION-MAKERS and lines of defence at successive life-cycle stages, monitoring, auditing, escalation and reporting protocols, and ongoing training and supervision of personnel. Guideline 2.4 adds a Predictive-Model-specific duty: documented processes for designing, developing, verifying, deploying, using, updating and monitoring models, including the methods used to detect and address errors, performance issues, outliers or unfair discrimination. The separate statutory limb is Vermont's Corporate Governance Annual Disclosure — 8 V.S.A. § 3316 and Regulation I-2015-01 — whose requirements the Bulletin states "APPLY TO ELEMENTS OF THE INSURER'S CORPORATE GOVERNANCE FRAMEWORK THAT ADDRESS THE INSURER'S USE OF AI SYSTEMS". Unlike the AIS Program expectation, the CGAD filing is a genuine statutory obligation, and AI governance is now expressly within its subject matter.

Deadline: March 12, 2024

Insurance Bulletin No. 229 (12 March 2024), AIS Program Guidelines 1.2, 1.3 and 2.0-2.4, read with Section 1 (Corporate Governance Annual Disclosure) citing 8 V.S.A. § 3316 and the Corporate Governance Annual Disclosure Regulation I-2015-01.

Bulletin 229 — Risk Management, Model Drift, and "Bias" Left UNNARROWED

High Priority

The AIS Program should document the Insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each stage of the AI System life cycle, addressing: the oversight and approval process for development, adoption or acquisition, with identification of constraints and controls on automation and design "to align and balance function with risk"; data practices and accountability procedures covering data currency, lineage, quality, integrity, BIAS ANALYSIS AND MINIMIZATION, and suitability; management and oversight of Predictive Models including inventories and descriptions, detailed development and use documentation, and assessments of interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, MODEL DRIFT and the auditability of those measurements; validating, testing and RETESTING as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model, by comparing model performance on unseen data available at development time against performance observed post-implementation, by measuring against expert review, or by other methods; protection of non-public information including unauthorised access to the Predictive Models themselves; and data and record retention. Guideline 3.7 requires, for Predictive Models specifically, a narrative description of the model's intended goals and objectives and of how it was developed and validated to ensure the AI Systems relying on it correctly and efficiently predict or implement those goals. Vermont left the model's bias language completely unnarrowed: the Section 3 verification paragraph still encourages methods "to identify errors AND BIAS in Predictive Models and AI Systems, as well as the potential for unfair discrimination", and plain "bias analysis and minimization" survives at all four of its occurrences — where New Hampshire deleted "and bias" and inserted "unfair" before "bias" at every one.

Deadline: March 12, 2024

Insurance Bulletin No. 229 (12 March 2024), AIS Program Guidelines 3.0-3.7 (Risk Management and Internal Controls) and the Section 3 verification-and-testing paragraph.

Bulletin 229 — Third-Party AI and Data: Diligence, Audit Rights, Regulator Cooperation

High Priority

Each AIS Program should address the Insurer's process for acquiring, using or relying on (i) third-party data to develop AI Systems and (ii) AI Systems developed by a third party, which may include establishing standards, policies, procedures and protocols for: due diligence and the methods used to assess the third party and its data or AI Systems, so that decisions made or supported by them "WILL MEET THE LEGAL STANDARDS IMPOSED ON THE INSURER ITSELF"; the inclusion, where appropriate and available, of contract terms that provide AUDIT RIGHTS or entitle the Insurer to receive audit reports by qualified auditing entities, and that REQUIRE THE THIRD PARTY TO COOPERATE with the Insurer on regulatory inquiries and investigations relating to the Insurer's use of the vendor's product or services; and the performance of those contractual audit rights or other activities to confirm the vendor's compliance with contractual and, "where applicable", regulatory requirements. Guideline 1.8 makes the whole AIS Program apply to AI Systems used in regulated insurance practices "whether developed by the Insurer or a THIRD-PARTY VENDOR". Section 4 item 2.0 then converts this into a production exposure: where an investigation or examination concerns data, models or AI Systems collected or developed in whole or in part by third parties, the Insurer should expect the Department to request the due diligence conducted, the CONTRACTS themselves (including terms on representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and cooperation with regulators), the audits or confirmation processes performed, and the validation, testing and auditing documentation including Model Drift evaluation. Vermont kept "Third Party" defined as "an ORGANIZATION other than the Insurer that provides services, data, or other resources related to AI" — it did not broaden the word to "entity" as Rhode Island did.

Deadline: March 12, 2024

Insurance Bulletin No. 229 (12 March 2024), AIS Program Guidelines 1.8 and 4.0-4.3 (Third-Party AI Systems and Data), read with Section 4 items 2.1-2.4 and the Section 2 definition of "Third Party".

Bulletin 229 Section 4 Production List — Retained in Full, With the Market-Conduct Authority CITED (Unlike Delaware) and a Six-Business-Day Subpoena Clock

High Priority

Regardless of the existence or scope of a written AIS Program, in the context of an investigation or market conduct action an Insurer can expect to be asked about its development, deployment and use of AI Systems, or any specific Predictive Model, AI System or application and its outcomes including Adverse Consumer Outcomes. Vermont retained the model's itemised list in full: the written AIS Program itself; documentation evidencing its ADOPTION; the Program's scope, "including any AI Systems and technologies NOT INCLUDED IN OR ADDRESSED BY the AIS Program"; how the Program is tailored and proportionate to the Insurer's reliance on AI, the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers; policies, procedures, guidance and TRAINING MATERIALS; processes for development, adoption or acquisition including constraints and controls on automation and data governance covering lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency; measurements, standards or THRESHOLDS used in model development, validation and oversight; documentation of the formation and ongoing operation of coordinating bodies; INVENTORIES AND DESCRIPTIONS of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes; and, as to any specific model "that is the subject of investigation or examination", documentation of compliance with all applicable policies in its development, use and oversight, information about the data used including source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and Data Currency, information on techniques, measurements, thresholds and similar controls, and documentation of validation, testing and auditing including MODEL DRIFT evaluation, with the nature of that work reflecting whether the system is Predictive-Model-based or Generative AI. Vermont KEPT the market-conduct bullet Delaware deleted and cited real authority for it — 8 V.S.A. §§ 3573 and 3574 — but did not adopt New Hampshire's and Delaware's "or examination" tightening, leaving the model's plain "subject to investigation, including market conduct actions". The examination cycle those sections create is: report filed within 60 days of completion of the examination; a reasonable opportunity of not more than 30 days for the company's written submission or rebuttal; adoption of the report within 30 days of the end of that period, with power to order any action necessary to cure a violation; administrative appeal within 30 days under 3 V.S.A. chapter 25; and a 15-day confidentiality window after the order. Two clauses matter to an AI examination in particular: § 3573(b) allows the Commissioner to retain independent actuaries, independent certified public accountants "or other professionals and specialists, THE COST OF WHICH SHALL BE BORNE BY THE COMPANY", and § 3573(e) allows the Commissioner to use and MAKE PUBLIC any report, examiner or company work papers, or other information discovered during the examination. The operative production clock is general: 8 V.S.A. § 13(a) requires any subpoena or notice to produce papers and records to allow "at least SIX BUSINESS DAYS" to comply, shortenable for good cause, with mailed service effective three business days after mailing.

Deadline: March 12, 2024

Insurance Bulletin No. 229 (12 March 2024), Section 4 (Regulatory Oversight and Examination Considerations) items 1.0-1.3 and 2.0-2.4, with authority cited at 8 V.S.A. §§ 3573 and 3574 and the production clock and penalty supplied by 8 V.S.A. § 13(a)-(b).

Rating Limb — the Vein's Broadest (P&C + Health + Life + Long-Term Care), Contradicted by Its Own Operative Sentence, and Now Mis-Citing After a 2025 Recodification

High Priority

Bulletin 229 states that "Insurers must comply with ALL Vermont insurance laws and regulations regarding rates, rating plans, rating rules, practices and standards", citing property and casualty at 8 V.S.A. §§ 3861 and 4685, HEALTH at §§ 4062, 4083 and 5104, LIFE at § 3701 and LONG-TERM CARE at Rule H-2009-01, and defines that set as the "Rating Laws" — a term it then never uses again. Those requirements "apply regardless of the METHODOLOGY that the Insurer used to develop rates, rating rules, and rating plans", so an Insurer is responsible for assuring that rates developed using AI techniques and Predictive Models relying on data and Machine Learning are not excessive, inadequate or unfairly discriminatory. TWO CAVEATS TRAVEL WITH THIS AND BOTH ARE OPERATIONAL. FIRST, the sentence stating the operative duty is the NAIC model's verbatim and confines it to "all forms of casualty insurance—including fidelity, surety, and guaranty bond—and to all forms of property insurance—including fire, marine, and inland marine insurance", so the bulletin's authority list reaches four lines while its duty sentence reaches two. Reading the cited statutes resolves it: the tri-standard applies to property and casualty at § 4685(a) and to HMO rates at § 5104(a)(2); for life at § 3701 and for other health the standard is unfair discrimination only — between insureds "of the same class and of equal expectation of life" for life, and "between individuals of substantially the same hazard" for health. A life insurer's AI model is answerable for discrimination but not excessiveness. SECOND, THE HEALTH CITATIONS NOW MIS-POINT. 2025 Act 11, § 2 (effective 1 September 2025) recodified Title 8 chapter 107 after the Bulletin issued: former § 4062 ("Filing and approval of policy forms and premiums") is now § 4026, and former § 4083 ("Discrimination prohibited") is now § 4013 — today's § 4083 is "Services for victims of sexual assault" and has nothing to do with rating. Use the current numbers. WHAT § 4685 ACTUALLY REQUIRES an AI pricing model to survive: rates "shall not be excessive, inadequate, or unfairly discriminatory"; a rate in a COMPETITIVE MARKET is not excessive, and excessiveness bites only in a noncompetitive market where rates produce unreasonably high profits or expenses are unreasonably high relative to services; rates are inadequate only if insufficient to sustain projected losses and expenses or if their use substantially lessens competition; and — the test a model must be able to evidence — "unfair discrimination exists if, AFTER ALLOWING FOR PRACTICAL LIMITATIONS, PRICE DIFFERENTIALS FAIL TO REFLECT EQUITABLY THE DIFFERENCES IN EXPECTED LOSSES AND EXPENSES", with the express safe harbours that different premiums for like loss exposures with different expenses (or vice versa) are not unfair provided the rate "equitably reflects the differences with reasonable accuracy", and that broad averaging across a group, franchise, blanket or mass-marketed plan is not unfair. FINALLY, A JURISDICTIONAL SPLIT THE BULLETIN DOES NOT MENTION: under § 4026(a)(1) a health insurer files forms and the rules for classification of risks with the Department of Financial Regulation but files PREMIUM RATES with the GREEN MOUNTAIN CARE BOARD, which must approve, modify or disapprove an initial rate request within 90 CALENDAR DAYS. The Board did not issue Bulletin 229.

Deadline: March 12, 2024

Insurance Bulletin No. 229 (12 March 2024), Section 1 "Insurance Rate Requirements" bullet, citing 8 V.S.A. §§ 3861 and 4685 (property and casualty), §§ 4062, 4083 and 5104 (health, now §§ 4026, 4013 and 5104 after 2025 Act 11, § 2), § 3701 (life) and Rule H-2009-01 (long-term care); rate standards at 8 V.S.A. § 4685(a)-(d); health rate approval by the Green Mountain Care Board within 90 days under § 4026(a)(2)(A).

8 V.S.A. § 4727(e)-(i) — Four-Factor Explainability, the Extraordinary-Life-Circumstances Override, and Two 30-Day Correction Clocks

High Priority

Vermont converts an automated adverse decision into three separate consumer-facing duties, each with its own clock. EXPLAINABILITY. Where an insurer takes adverse action based on credit information it must give notice under FCRA, 15 U.S.C. § 1681m(a), AND, under § 4727(h)(2), notice "explaining the REASON for the adverse action ... in sufficiently clear and specific language so that a person can IDENTIFY THE BASIS for the insurer's decision", including "a description of UP TO FOUR FACTORS that were the PRIMARY INFLUENCES of the adverse action". The statute then forecloses the answers a model most easily gives: "the use of generalized terms such as \u2018poor credit history,\u2019 \u2018poor credit rating,\u2019 or \u2018poor insurance score\u2019 DOES NOT MEET the explanation requirements", though standardized credit explanations supplied by consumer reporting agencies or third-party vendors are deemed to comply. § 4727(i) adds that any written communication under the section must use "clear and plain language that is understandable to the average consumer". EXTRAORDINARY LIFE CIRCUMSTANCES. Under § 4727(e)(1), "notwithstanding any other law or rule", an insurer using credit information SHALL on written request provide "REASONABLE EXCEPTIONS to the insurer's rates, rating classifications, company or tier placement, or underwriting rules or guidelines" for a consumer whose credit information was directly influenced by a declared catastrophic event, serious illness or injury to the consumer or an immediate family member, death of a spouse, child or parent, divorce or involuntary interruption of alimony or support, IDENTITY THEFT, involuntary loss of employment for three months or more, overseas military deployment, or other events the insurer determines. The insurer may require written independently verifiable documentation, may require the request within 60 days of application or renewal, and must notify the consumer that exceptions are available; it must inform the consumer of the outcome WITHIN 30 DAYS of receiving sufficient documentation. Granting an exception does not put the insurer out of compliance with any rating or rate-filing rule. ERROR CORRECTION. Under § 4727(f), where the FCRA dispute process at 15 U.S.C. § 1681i(a)(5) determines that a current insured's credit information was incorrect or incomplete and the insurer receives notice from the agency or the insured, the insurer "SHALL REUNDERWRITE AND RERATE THE CONSUMER WITHIN 30 DAYS" of the notice, make any adjustments consistent with its guidelines, and refund any overpayment "calculated back to the shorter of either the last 12 months of coverage or the actual policy period". Practically, an automated underwriting stack must support a human-triggered override path and a retrospective rerate, not merely a rescore.

Deadline: May 28, 2018

8 V.S.A. § 4727(h)(1)-(2) (adverse action notice; up to four primary-influence factors; generalized terms insufficient), § 4727(e)(1)-(5) (extraordinary life circumstances; reasonable exceptions; 30-day outcome notification), § 4727(f) (FCRA error correction; reunderwrite and rerate within 30 days; refund period), § 4727(g) (initial disclosure and safe-harbour wording) and § 4727(i) (plain language).

8 V.S.A. § 4063 — Independent External Review: Binding, Evidence-Based, Credentialed Reviewers, and the Insurer Pays When It Loses

High Priority

A covered individual who has exhausted the plan's internal review procedures has a statutory right to independent external review of a decision "to DENY, REDUCE, OR TERMINATE health care coverage or to deny payment for a health care service", available on written request where the decision requires the plan to expend at least $100 and rests on one of the enumerated grounds — that a covered benefit was determined NOT MEDICALLY NECESSARY, that a limitation on provider selection is inconsistent with the plan and applicable law, or that treatment was determined EXPERIMENTAL OR INVESTIGATIONAL. The Department must adopt rules ensuring the reviews have specified characteristics, and several constrain what an AI-driven denial must be able to withstand. Reviews are conducted by independent review organizations under contract with the Department, and "the REVIEWERS SHALL INCLUDE HEALTH CARE PROVIDERS CREDENTIALED WITH RESPECT TO THE HEALTH CARE SERVICE UNDER REVIEW and shall have NO CONFLICT OF INTEREST relating to the performance of their duties" (§ 4063(d)(1)(A)). Reviews proceed "in accordance with standards of decision making based on OBJECTIVE CLINICAL EVIDENCE, shall resolve all issues in a TIMELY MANNER, and shall provide EXPEDITED RESOLUTION when the decision relates to emergency or urgent health care services" (§ 4063(d)(1)(B)). The IRO "shall issue to both parties a WRITTEN REVIEW DECISION THAT IS EVIDENCE-BASED", and that decision "SHALL BE BINDING ON THE HEALTH INSURANCE PLAN" (§ 4063(d)(4)). The cost structure penalises weak denials: the covered individual pays an application fee of $25 per request capped at $75 annually, waivable or reducible on financial hardship, and "THE APPLICATION FEE SHALL BE PAID BY THE HEALTH INSURER, NOT THE COVERED INDIVIDUAL, IF THE INDEPENDENT REVIEW ORGANIZATION REVERSES THE HEALTH INSURER'S DECISION"; all other costs of the review are paid by the plan (§ 4063(d)(2)(C), (d)(3)). Covered individuals must receive adequate notice of their review rights, may use outside assistance and submit evidence, and are protected from retaliation for exercising the right. Medicaid and Department of Corrections decisions are routed elsewhere (§ 4063(e)). The practical consequence for an AI-assisted medical-necessity engine is that every adverse determination is appealable into a forum that applies objective clinical evidence, is decided by a credentialed clinician, produces a binding evidence-based written decision, and shifts costs to the insurer on reversal — so a model with a high reversal rate is directly and measurably expensive.

Deadline: September 1, 2025

8 V.S.A. § 4063(b) (right to external review; $100 threshold; enumerated grounds), § 4063(d)(1)(A)-(B) (credentialed conflict-free reviewers; objective clinical evidence; expedited resolution), § 4063(d)(2)-(4) (consumer protections; fee shifting on reversal; binding evidence-based written decision) and § 4063(e) (exclusions); recodified by 2025 Act 11, § 2, effective 1 September 2025.

Act 101 of 2026 (H.814) — Vermont Passed the Strictest AI-Utilization-Review Rule in the Country Through One Chamber and DID NOT ENACT It; What Survives Is a Report Due 15 January 2027

Medium Priority

RECORDED ABSENCE, with the method for bounding it, because the secondary trackers get this wrong. H.814 of 2026 passed the Vermont House at 32 pages carrying "Subchapter 3. Artificial Intelligence Applications Relating to Health Insurance" and a proposed 18 V.S.A. § 9771, "USE OF ARTIFICIAL INTELLIGENCE IN UTILIZATION REVIEW". As passed by the House it would have imposed eleven affirmative conditions on any "artificial intelligence, algorithm, or other software tool" used by a health plan — or by an entity the plan contracts with — for utilization review or utilization management based in whole or in part on medical necessity: that the tool base its determination on the individual's medical or clinical history, the specific clinical circumstances presented by the requesting provider, and other relevant clinical information in the record; that it "does not base its determination SOLELY ON A GROUP DATASET"; that its criteria comply with 8 V.S.A. chapter 107 and 18 V.S.A. chapter 221; that it "does not SUPPLANT HEALTH CARE PROVIDER DECISION MAKING"; that its use not discriminate directly or indirectly; that it be fairly and equitably applied; that it be "OPEN TO INSPECTION for audit or compliance reviews by the Department of Financial Regulation"; that disclosures on its use and oversight sit in the plan's written policies; that its "performance, use, and outcomes are PERIODICALLY REVIEWED AND REVISED to maximize accuracy and reliability"; that patient data not be used beyond its stated purpose; and that it "does not directly or indirectly cause harm". § 9771(b) would then have overridden all of it with a categorical human-decider mandate: the tool "SHALL NOT DENY, DELAY, OR MODIFY health care services based in whole or in part on medical necessity. A determination of medical necessity shall be made ONLY BY A LICENSED HUMAN HEALTH CARE PROVIDER who is COMPETENT to evaluate the specific clinical issues involved", applying to prospective, retrospective and concurrent review alike. NONE OF THIS IS LAW. The bill was enacted as Act 101 of 2026, signed 18 May 2026 and effective on passage, at FIVE pages with the entire health-insurance subchapter removed. What was enacted is: a non-binding intent section; 18 V.S.A. chapter 42C ("Neurological Rights"), whose § 1891 recognises six individual rights including mental and neural data privacy, freedom of thought, nondiscrimination in the development and application of neurotechnologies, and protection from unauthorised access to or manipulation of brain activity — a rights declaration with no duty-holder, no enforcement mechanism and no penalty; an amendment to 3 V.S.A. § 5023 reconstituting the Artificial Intelligence Advisory Council, whose remit reaches only AI "developed, employed, or procured in STATE GOVERNMENT", and moving its sunset from 30 June 2027 to 30 June 2030; and a reporting duty. THE LIVE ITEM IS THE REPORT: on or before 15 JANUARY 2027 the Council, with the Director of the Division of Artificial Intelligence, must submit written recommendations to the General Assembly for additional statutory changes expressly including "(C) REGULATING THE USE OF ARTIFICIAL AND AUGMENTED INTELLIGENCE IN HEALTH INSURANCE UTILIZATION REVIEW PROCESSES", together with guidance on generative AI use by regulated professions and protections for neurological rights. A Vermont health insurer should treat 15 January 2027 as the date the design of a Vermont AI-UR regime becomes public, and should not assume the House text is a safe harbour or a dead letter — it is the drafting baseline the Council will work from. Separately and for completeness: H.341 of 2025, creating oversight and safety standards for developers and deployers of "inherently dangerous" AI systems, never left committee, its last recorded action being first reading and referral to the House Committee on Commerce and Economic Development on 25 February 2025.

Deadline: January 15, 2027

Vermont Act 101 of 2026 (H.814), signed 18 May 2026, effective on passage: Sec. 2 adding 18 V.S.A. chapter 42C § 1891 (neurological rights), Sec. 3 amending 3 V.S.A. § 5023 (Artificial Intelligence Advisory Council; sunset moved to 30 June 2030) and Sec. 4(b)(1)(C) (report due on or before 15 January 2027 recommending regulation of artificial and augmented intelligence in health insurance utilization review); contrasted with the unenacted 18 V.S.A. § 9771 in H.814 as passed by the House.

Act 145 of 2026 (VDPOSA) EXEMPTS Insurers at ENTITY Level — the Mirror Image of Delaware — Leaving Regulation IH-2001-01 as the Operative Data Regime

Medium Priority

Vermont enacted a comprehensive privacy statute in the same session as its AI act, and an insurer must know that it does NOT apply to it — the opposite of the position in Delaware, where the DPDPA has no insurer entity exemption and carves out only GLBA, HIPAA and FCRA DATA. S.71, the Vermont Data Privacy and Online Surveillance Act, was enacted as Act 145 of 2026, signed 16 June 2026 per the act's own signature line, and takes effect 1 JANUARY 2028. Its exemption section, 9 V.S.A. § 2415c(a)(16), excludes "a PERSON REGULATED PURSUANT TO 8 V.S.A. PART 3 (CHAPTERS 101-165)" — that is, the whole of the Vermont insurance code, at entity level rather than by data type — subject to a single carve-back for a person who "establishes and maintains a SELF-INSURANCE PROGRAM and who does not otherwise engage in the business of entering into policies of insurance". A pure self-insured plan sponsor is therefore INSIDE the Act while a licensed insurer is outside it. Adjacent exemptions matter to the same supply chain: § 2415c(a)(17) exempts health care providers and facilities maintaining protected health information under 18 V.S.A. § 1881 and HIPAA; § 2415c(a)(18) exempts protected health information itself; and § 2415c(a)(19) exempts a THIRD-PARTY ADMINISTRATOR, but only while it "is SUBJECT TO AND IN COMPLIANCE WITH the Department of Financial Regulation's REGULATION IH-2001-01 (Privacy of Consumer Financial and Health Information)" — a conditional exemption that fails if the TPA's compliance fails. The practical consequence is that the privacy regime actually governing a Vermont insurer's AI training data, inference inputs and model outputs is Regulation IH-2001-01 together with 8 V.S.A. § 4728 (insurance data security) and the § 4727 credit-information rules, not the VDPOSA — so an AI governance programme built to a VDPOSA control set would be aimed at the wrong instrument. For completeness on the Act's own shape: enforcement is by the Attorney General under 9 V.S.A. § 2415j(a); between 1 January 2028 and 30 June 2029 the Attorney General must first issue a notice of violation where a cure is possible and allow 60 DAYS to cure; and there is no private right of action, though the Act records the General Assembly's intent that one may be considered if enforcement is not adequately resourced.

Deadline: January 1, 2028

Vermont Act 145 of 2026 (S.71, Vermont Data Privacy and Online Surveillance Act), signed 16 June 2026, effective 1 January 2028: 9 V.S.A. § 2415c(a)(16) (entity-level exemption for persons regulated under 8 V.S.A. part 3, chapters 101-165, with the self-insurance carve-back), § 2415c(a)(17)-(19) (health care providers, protected health information, and third-party administrators conditional on DFR Regulation IH-2001-01), § 2415j(a) (Attorney General enforcement) and Sec. 3 (notice and 60-day cure period, 1 January 2028 to 30 June 2029).

Frequently Asked Questions

Does Vermont — Insurance Bulletin No. 229 (NAIC AI Model RE-DOMESTICATED: every model-act name scrubbed, all five citation brackets filled, authority clause hedged with "primarily") + the Vein's BROADEST Rating Limb (P&C + health + life + long-term care) That Contradicts Its Own Operative Sentence + Mandatory Scoring-Model Filing (8 V.S.A. § 4727(j)) + Price-Optimization Disclosure Directive With Its Own Violation Hook (Bulletin No. 186) + Virtual/Image-Based Claims Adjusting Backstop Extended to All Lines (Bulletin No. 206 rev., 2026) + Mental-Health Review-Agent LICENSURE (8 V.S.A. § 4064) + Prior-Auth Deemed-Granted Clocks (18 V.S.A. § 9418b) + the AI-Utilization-Review Statute Vermont Passed the House and DID NOT ENACT (H.814 / Act 101 of 2026) apply to my business?

Vermont has no comprehensive private-sector AI statute reaching insurers, and its AI bulletin is among the EARLIEST adoptions of the national model anywhere — 12 March 2024, barely three months after the NAIC adopted it. What makes Vermont… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Vermont — Insurance Bulletin No. 229 (NAIC AI Model RE-DOMESTICATED: every model-act name scrubbed, all five citation brackets filled, authority clause hedged with "primarily") + the Vein's BROADEST Rating Limb (P&C + health + life + long-term care) That Contradicts Its Own Operative Sentence + Mandatory Scoring-Model Filing (8 V.S.A. § 4727(j)) + Price-Optimization Disclosure Directive With Its Own Violation Hook (Bulletin No. 186) + Virtual/Image-Based Claims Adjusting Backstop Extended to All Lines (Bulletin No. 206 rev., 2026) + Mental-Health Review-Agent LICENSURE (8 V.S.A. § 4064) + Prior-Auth Deemed-Granted Clocks (18 V.S.A. § 9418b) + the AI-Utilization-Review Statute Vermont Passed the House and DID NOT ENACT (H.814 / Act 101 of 2026) is: Vermont's headline number is small and deeply misleading, and an insurer that prices its AI exposure off the Unfair Trade Practices Act figure will understate it by an unbounded margin. THE UTPA FIGURE IS THE LOW ONE. 8 V.S.A. § 4726(b) provides that any person violating any provision of chapter 129 "may be subject to an administrative penalty of NOT MORE THAN $1,000.00 for each violation", rising to "not more than $10,000.00 each for those violations the Commissioner finds were WILLFUL", with power to suspend or revoke the licence of any insurer or organization "for any violation of this chapter OR THE FAILURE TO COMPLY WITH AN ORDER of the Commissioner". There is no aggregate cap and no six-month reset — unlike Delaware's § 2308(a), which caps the equivalent exposure at $100,000 in aggregate — so a defective model applied across a whole book multiplies without ceiling, but at $1,000 a consumer. § 4726(a) supplies the investigation power and § 4726(c) preserves every other penalty authorised by law. Because 8 V.S.A. § 4727 (credit information and insurance scores) sits INSIDE chapter 129, a scoring-model failure — including a failure to file the model under § 4727(j) — is itself an unfair trade practice priced at these figures. THE REAL EXPOSURE IS 8 V.S.A. § 13, WHICH IS UNCAPPED. § 13(d) empowers the Commissioner, "in addition to any other penalties or powers", to order a person "to make RESTITUTION or provide DISGORGEMENT of any sums shown to have been obtained in violation of provisions of this title and 18 V.S.A. chapter 221, PLUS INTEREST at the legal rate" — so an AI rating or underwriting model that overcharged is exposed to the full premium differential with interest, a figure that bears no relation to the per-violation caps. § 13(b) separately prices obstruction of the Section 4 production duty at "not more than $2,000.00 FOR EACH DAY of noncompliance" with the authority to do business suspendable for up to six months, and § 13(c) lets an unappealed final order be filed with a court and enforced as a judgment. OTHER ROUTES, EACH WITH A DIFFERENT NUMBER. Mental-health utilization review: 8 V.S.A. § 4064(e) provides that a person who violates any provision of that section, or submits false information in a licence application, "may be fined NOT MORE THAN $5,000.00 for each violation", and § 4064(d) additionally subjects review agents to chapter 129 — so an unlicensed or non-compliant review agent is exposed twice. Prior authorization: 18 V.S.A. § 9418b(e) is the SMALLEST figure and the hardest to trigger, requiring a finding that the plan "has engaged in a PATTERN AND PRACTICE of violating this section" before the Commissioner may impose "no more than $500.00 for each violation", order a cease and desist, and order remediation, weighing five statutory factors including "the economic benefit derived by the health plan". Property and casualty rate discrimination: 8 V.S.A. § 3861 carries its own "administrative penalty of not more than $2,000.00". Bulletin 229 itself creates NO penalty and is not a hook — it is neither a statute nor a rule adopted under 3 V.S.A. chapter 25, and it contains no enforcement clause whatever; every sanction above arrives through the statutes underneath it. Note finally that findings of fact from a market conduct examination are "PRIMA FACIE EVIDENCE in any legal or regulatory action" under 8 V.S.A. § 3573(d), and that the Commissioner may make examination work papers public under § 3573(e) — the reputational and evidentiary consequences of an adverse AI examination can exceed the fines.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Vermont — Insurance Bulletin No. 229 (NAIC AI Model RE-DOMESTICATED: every model-act name scrubbed, all five citation brackets filled, authority clause hedged with "primarily") + the Vein's BROADEST Rating Limb (P&C + health + life + long-term care) That Contradicts Its Own Operative Sentence + Mandatory Scoring-Model Filing (8 V.S.A. § 4727(j)) + Price-Optimization Disclosure Directive With Its Own Violation Hook (Bulletin No. 186) + Virtual/Image-Based Claims Adjusting Backstop Extended to All Lines (Bulletin No. 206 rev., 2026) + Mental-Health Review-Agent LICENSURE (8 V.S.A. § 4064) + Prior-Auth Deemed-Granted Clocks (18 V.S.A. § 9418b) + the AI-Utilization-Review Statute Vermont Passed the House and DID NOT ENACT (H.814 / Act 101 of 2026)?

The 16 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://dfr.vermont.gov/sites/finreg/files/regbul/dfr-insurance-bulletin-229-ai.pdf

Last updated: 2026-08-27 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan