Colorado’s SB26-189: New requirements for automated decision-making technology and compliance strategies
From the blog this month: Colorado has changed the rules for automated decision-making, and the changes land squarely on enterprises in insurance, financial services, and healthcare. SB26-189 is now law, repealing and replacing the state's 2024 AI Act. The old framework is gone. No more impact assessments, no duty of care. In its place are three obligations to build around:
Documentation and disclosure requirements for developers of covered systems
A 30-day window to explain adverse outcomes to affected consumers
A consumer right to meaningful human review of those decisions
The compliance date is January 1, 2027. Enforcement is currently subject to a federal court challenge worth monitoring, but legal counsel broadly advises building to the statute now rather than waiting for it to resolve. We broke down exactly what SB26-189 requires, what it eliminated, and what a defensible governance posture looks like before the deadline.
Two unusually blunt letters from ASIC and APRA signal that Australia’s financial regulators have run out of patience with the insurance industry’s slow response to AI risk. Artificial intelligence (AI) is reshaping the insurance industry faster than most boards can comprehend and Australia’s regulators are concerned. In two sharply worded letters issued in quick succession, the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) have put insurers on notice: the governance gap between the AI tools being adopted and the systems in place to control them is dangerously wide and the window for passive observation has closed.
Health AI governance policies have exploded in recent years, but remain fragmented, across more than 100 issuing bodies, according to a new Health & AI Policy Index developed by Mount Sinai researchers. The researchers analyzed 240 healthcare AI-related policies published between 2016 and 2025 to develop the Health & AI Policy Index. They published findings from a Jan. 1, 2026, snapshot of the index in npj Digital Medicine. The research comes as health AI governance in the U.S. remains fragmented across various coalitions and industry groups, as well as a patchwork of state laws. The researchers found that while the health AI governance landscape appears to have grown rapidly, activity is diffused across more than 100 issuers, including regulators, governments and standards organizations.
In March 2026, the NAIC published an Issue Brief formally articulating its position on AI regulation. The NAIC supports state-based oversight of insurers’ use of AI and opposes federal preemption that would undermine consumer protections and the McCarran-Ferguson framework, which delegates insurance regulation to the states. This is a direct response to Congressional proposals that would restrict or delay state-level AI oversight. In the NAIC’s view, the progress already made at the state level stands in stark contrast to what a federal override would produce: state regulators have built out a meaningful supervisory infrastructure — including AI-specific principles, interpretive guidance, and examination tools — and preemptive federal legislation would displace that work and leave consumers with diminished protections. The NAIC’s position is firm: “AI is a tool used in underwriting, pricing, claims, fraud detection, and utilization management” – it does not alter insurers’ legal obligations, and “existing state insurance laws apply regardless of whether decisions are made by humans, algorithms, or third-party vendors.”
Just over 200 state lawmakers from across the country are calling on members of the House and Senate to reject a proposal to preempt some state regulations of artificial intelligence for three years, citing the technology’s impact on kids, artists and creators and workers. The letter, sent by 203 state lawmakers to Congress on Tuesday, said “we take seriously our responsibility to safeguard our constituents from AI harms to children, workers, artists and creators, families, and consumers.”
House Bill 565 would prohibit insurers from using AI as the sole basis for denying healthcare claims or prior authorization requests, saying that humans must remain involved in those decisions. The legislation also seeks to crack down on hospitals and other healthcare providers that might use AI to inflate their profits through a strategy called “upcoding.”
The AMA adopted new AI policies in a bid to ensure that the technology supports evidence-based medicine, bolsters patient care and serves under a physician’s oversight, instead of replacing their discernment. According to an AMA press release, AI technologies could help with efficiency and synthesizing information, but there are still important concerns for bias, long-term impact on both physicians and patient outcomes, explainability and transparency.
Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester’s objectivity here.