HI Commissioner's Memorandum 2025-13A
The Use of Artificial Intelligence Systems in Insurance
JOSH GREEN, M.D.
GOVERNOR | KE KIAʻĀINA
SYLVIA LUKE
LIEUTENANT GOVERNOR | KA HOPE KIAʻĀINA
STATE OF HAWAII | KA MOKUʻĀINA ʻO HAWAIʻI
DEPARTMENT OF COMMERCE AND CONSUMER AFFAIRS
KA ʻOIHANA PILI KĀLEPA
INSURANCE DIVISION
335 MERCHANT STREET, ROOM 213, HONOLULU, HAWAII 96813
P.O. BOX 3614, HONOLULU, HAWAII 96811
Phone Number: (808) 586-2790
Fax Number: (808) 587-6714
cca.hawaii.gov/ins/
NADINE Y. ANDO
DIRECTOR | KA LUNA HOʻOKELE
SCOTT K. SAIKI
INSURANCE COMMISSIONER
December 10, 2025
MEMORANDUM 2025-13A
To:
All Authorized Insurers Offering Policies in the State of Hawaii
From:
Scott K. Saiki, Insurance Commissioner
Subject:
The Use of Artificial Intelligence Systems in Insurance
This Memorandum is issued by the Hawaii Insurance Division (the “Division”) to remind
all Insurers authorized to do business in the state that decisions or actions impacting
consumers that are made or supported by advanced analytical and computational
technologies, including Artificial Intelligence (“AI”) Systems (as defined below), must
comply with all applicable insurance laws and regulations. This includes those laws that
address unfair trade practices and unfair discrimination. This memorandum sets forth
the Division’s expectations as to how Insurers will govern the development/acquisition
and use of certain AI technologies, including the AI Systems described herein. This
memorandum also advises Insurers of the type of information and documentation that
the Division may request during an investigation or examination of any Insurer regarding
its use of such technologies and AI Systems.
SECTION 1: INTRODUCTION, BACKGROUND, AND LEGISLATIVE AUTHORITY
Background
AI is transforming the insurance industry. AI techniques are deployed across all stages
of the insurance life cycle, including product development, marketing, sales and
distribution, underwriting and pricing, policy servicing, claim management, and fraud
detection.
AI may facilitate the development of innovative products, improve consumer interface
and service, simplify and automate processes, and promote efficiency and accuracy.
However, AI, including AI Systems, can present unique risks to consumers, including
the potential for inaccuracy, unfair discrimination, data vulnerability, and lack of
transparency and explainability. Insurers should take actions to minimize these risks.
Memorandum 2025-13A
December 10, 2025
Page 2
The Division is receptive to the development and use of innovation and AI Systems that
contribute to safe and stable insurance markets. However, the Division expects that
decisions made and actions taken by Insurers using AI Systems will comply with all
applicable federal and state laws and regulations.
The Division recognizes the Principles of Artificial Intelligence that the NAIC adopted in
2020 as an appropriate source of guidance for Insurers as they develop and use AI
systems. Those principles emphasize the importance of the fairness and ethical use of
AI; accountability; compliance with state laws and regulations; transparency; and a safe,
secure, fair, and robust system. These fundamental principles should guide Insurers in
their development and use of AI Systems and underlie the expectations set forth in this
memorandum.
Legislative Authority
The regulatory expectations and oversight considerations set forth in Section 3 and
Section 4 of this memorandum rely on the following laws and regulations:
The Unfair Methods of Competition and Unfair and Deceptive Acts and Practices in the
Business of insurance, codified in chapter 431, article 13, part I, HRS, regulates trade
practices in insurance by defining or providing for the determination of, all acts,
methods, and practices which constitute unfair methods of competition or unfair or
deceptive acts or practices in Hawaii and prohibits the trade practices so defined or
determined. This section also sets for the standards for the investigation and disposition
of claims arising under policies or certificates of insurance issued to residents of Hawaii.
Furthermore, this section also provides for the power of the commissioner and the
procedure by which a person may request a hearing.
Actions taken by Insurers in the state must not violate chapter 431, article 13, part I,
HRS, regardless of the methods the Insurer used to determine or support its actions. As
discussed below, Insurers are expected to adopt practices, including governance
frameworks and risk management protocols, that are designed to ensure that the use of
AI Systems does not result in: 1) unfair methods of competition and unfair and
deceptive acts and practices as defined in HRS § 431:13-103; or 2) unfair claim
settlement practices as defined in HRS § 431:13-103(a)(11).
The Corporate Governance Annual Disclosure, chapter 431, article 3G, HRS, requires
Insurers to report on governance practices and to provide a summary of the Insurer’s
corporate governance structure, policies, and practices. The content, form, and filing
requirements for corporate governance annual disclosure information are set forth in
title 16, chapter 186, of the Hawaii Administrative Rules (“HAR”).
The requirements of Corporate Governance Annual Disclosure apply to elements of the
Insurer’s corporate governance framework that address the Insurer’s use of AI Systems
to support actions and decisions that impact consumers.
Memorandum 2025-13A
December 10, 2025
Page 3
Hawaii’s laws on rate regulation, codified in chapter 431, article 14, HRS, require that
property and casualty insurance rates not be excessive, inadequate, or unfairly
discriminatory.
The requirements of chapter 431, article 14, HRS, apply regardless of the methodology
that the Insurer used to develop rates, rating rules, and rating plans subject to those
provisions. That means that an Insurer is responsible for assuring that rates, rating
rules, and rating plans that are developed using AI techniques and Predictive Models
that rely on data and Machine Learning do not result in excessive, inadequate, or
unfairly discriminatory insurance rates with respect to all forms of casualty insurance—
including fidelity, surety, and guaranty bond—and to all forms of property insurance—
including fire, marine, and inland marine insurance, and any combination of any of the
foregoing.
Hawaii’s Market Conduct laws, chapter 431, article 2D, HRS, establish the framework
pursuant to which the Division conducts market conduct actions. These are comprised
of the full range of activities that the Division may initiate to assess and address the
market practices of Insurers, beginning with market analysis and extending to targeted
examinations. Market conduct actions are separate from, but may result from, individual
complaints made by consumers asserting illegal practices by Insurers.
An Insurer’s conduct in the state, including its use of AI Systems to make or support
actions and decisions that impact consumers, is subject to investigation, including
market conduct actions. Section 4 of this memorandum provides guidance on the kinds
of information and documents that the Division may request in the context of an AI-
focused investigation, including a market conduct action.
SECTION 2: DEFINITIONS
For the purposes of this memorandum the following terms are defined:
“Adverse Consumer Outcome” refers to a decision by an Insurer that is subject to
insurance regulatory standards enforced by the Division that adversely impacts the
consumer in a manner that violates those standards.
“Algorithm” means a clearly specified mathematical process for computation; a set of
rules that, if followed, will give a prescribed result.
“Artificial Intelligence (“AI”)” refers to a branch of computer science that uses data
processing systems that perform functions normally associated with human intelligence,
such as reasoning, learning, and self-improvement, or the capability of a device to
perform functions that are normally associated with human intelligence such as
reasoning, learning, and self-improvement. This definition considers machine learning to
be a subset of artificial intelligence.
Memorandum 2025-13A
December 10, 2025
Page 4
“AI System” or “AIS” is a machine-based system that can, for a given set of
objectives, generate outputs such as predictions, recommendations, content (such as
text, images, videos, or sounds), or other output influencing decisions made in real or
virtual environments. AI Systems are designed to operate with varying levels of
autonomy.
“Degree of Potential Harm to Consumers” refers to the severity of adverse economic
impact that a consumer might experience as a result of an Adverse Consumer
Outcome.
“Generative Artificial Intelligence (“Generative AI”)” refers to a class of AI Systems
that generate content in the form of data, text, images, sounds, or video, that is similar
to, but not a direct copy of, pre-existing data or content.
“Machine Learning” Refers to a field within artificial intelligence that focuses on the
ability of computers to learn from provided data without being explicitly programmed.
“Model Drift” refers to the decay of a model’s performance over time arising from
underlying changes such as the definitions, distributions, and/or statistical properties
between the data used to train the model and the data on which it is deployed.
“Predictive Model” refers to the mining of historic data using algorithms and/or
machine learning to identify patterns and predict outcomes that can be used to make or
support the making of decisions.
“Third-Party” for purposes of this memorandum means an organization other than the
Insurer that provides services, data, or other resources related to AI.
SECTION 3: REGULATORY GUIDANCE AND EXPECTATIONS
Decisions subject to regulatory oversight that are made by Insurers using AI Systems
must comply with the legal and regulatory standards that apply to those decisions,
including unfair trade practice laws. These standards require, at a minimum, that
decisions made by Insurers are not inaccurate, arbitrary, capricious, or unfairly
discriminatory. Compliance with these standards is required regardless of the tools and
methods Insurers use to make such decisions. However, because, in the absence of
proper controls, AI has the potential to increase the risk of inaccurate, arbitrary,
capricious, or unfairly discriminatory outcomes for consumers, it is important that
Insurers adopt and implement controls specifically related to their use of AI that are
designed to mitigate the risk of Adverse Consumer Outcomes.
Consistent therewith, all Insurers authorized to do business in this state are expected to
develop, implement, and maintain a written program (an “AIS Program”) for the
responsible use of AI Systems that make, or support decisions related to regulated
insurance practices. The AIS Program should be designed to mitigate the risk of
Memorandum 2025-13A
December 10, 2025
Page 5
Adverse Consumer Outcomes, including, at a minimum, the statutory provisions set
forth in Section 1 of this memorandum.
The Division recognizes that robust governance, risk management controls, and internal
audit functions play a core role in mitigating the risk that decisions driven by AI Systems
will violate unfair trade practice laws and other applicable existing legal standards. The
Division also encourages the development and use of verification and testing methods
to identify errors and bias in Predictive Models and AI Systems, as well as the potential
for unfair discrimination in the decisions and outcomes resulting from the use of
Predictive Models and AI Systems.
The controls and processes that an Insurer adopts and implements as part of its AIS
Program should be reflective of, and commensurate with, the Insurer’s own assessment
of the degree and nature of risk posed to consumers by the AI Systems that it uses,
considering: (i) the nature of the decisions being made, informed, or supported using
the AI System; (ii) the type and Degree of Potential Harm to Consumers resulting from
the use of AI Systems; (iii) the extent to which humans are involved in the final decisionmaking process; (iv) the transparency and explainability of outcomes to the impacted
consumer; and (v) the extent and scope of the insurer’s use or reliance on data,
Predictive Models, and AI Systems from third parties. Similarly, controls and processes
should be commensurate with both the risk of Adverse Consumer Outcomes and the
Degree of Potential Harm to Consumers.
As discussed in Section 4, the decisions made as a result of an Insurer’s use of AI
Systems are subject to the Division’s examination to determine that the reliance on AI
Systems is compliant with all applicable existing legal standards governing the conduct
of the Insurer.
AIS Program Guidelines
1.0
General Guidelines
a. The AIS Program should be designed to mitigate the risk that the Insurer’s
use of an AI System will result in Adverse Consumer Outcomes.
b. The AIS Program should address governance, risk management controls,
and internal audit functions.
c. The AIS Program should vest responsibility for the development,
implementation, monitoring, and oversight of the AIS Program and for
setting the Insurer’s strategy for AI Systems with senior management
accountable to the board or an appropriate committee of the board.
d. The AIS Program should be tailored to and proportionate with the Insurer’s
use and reliance on AI and AI Systems. Controls and procedures should
be focused on the mitigation of Adverse Consumer Outcomes and the
scope of the controls and procedures applicable to a given AI System use
Memorandum 2025-13A
December 10, 2025
Page 6
case should reflect and align with the Degree of Potential Harm to
Consumers with respect to that use case.
e. The AIS Program may be independent of or part of the Insurer’s existing
Enterprise Risk Management program. The AIS Program may adopt,
incorporate, or rely upon, in whole or in part, a framework or standards
developed by an official Third-Party standard organization, such as the
National Institute of Standards and Technology Artificial Intelligence Risk
Management Framework, Version 1.0.
f. The AIS Program should address the use of AI Systems across the
insurance life cycle, including areas such as product development and
design, marketing, use, underwriting, rating and pricing, case
management, claim administration and payment, and fraud detection.
g. The AIS Program should address all phases of an AI System’s life cycle,
including design, development, validation, implementation (both systems
and business), use, on-going monitoring, updating and retirement.
h. The AIS Program should address the AI Systems used with respect to
regulated insurance practices whether developed by the Insurer or a
Third-Party vendor.
i. The AIS Program should include processes and procedures providing
notice to impacted consumers that AI Systems are in use and provide
access to appropriate levels of information based on the phase of the
insurance life cycle in which the AI Systems are being used.
2.0
Governance
The AIS Program should include a governance framework for the oversight of AI
Systems used by the Insurer. Governance should prioritize transparency, fairness, and
accountability in the design and implementation of the AI Systems, recognizing that
proprietary and trade secret information must be protected. An Insurer may consider
adopting new internal governance structures or rely on the Insurer’s existing
governance structures; however, in developing its governance framework, the Insurer
should consider addressing the following items:
a. The policies, processes, and procedures, including risk management and
internal controls, to be followed at each stage of an AI System life cycle,
from proposed development to retirement.
b. The requirements adopted by the Insurer to document compliance with the
AIS Program policies, processes, procedures, and standards.
Documentation requirements should be developed with Section 4 in mind.
Memorandum 2025-13A
December 10, 2025
Page 7
c. The Insurer’s internal AI System governance accountability structure, such
as:
i.
The formation of centralized, federated, or otherwise constituted
committees comprised of representatives from appropriate
disciplines and units within the Insurer, such as business units,
product specialists, actuarial, data science and analytics,
underwriting, claims, compliance, and legal.
ii.
Scope of responsibility and authority, chains of command, and
decisional hierarchies.
iii.
The independence of decision-makers and lines of defense at
successive stages of the AI System life cycle.
iv.
Monitoring, auditing, escalation, and reporting protocols and
requirements.
v.
Development and implementation of ongoing training and
supervision of personnel.
d. Specifically with respect to Predictive Models: the Insurer’s processes and
procedures for designing, developing, verifying, deploying, using,
updating, and monitoring Predictive Models, including a description of
methods used to detect and address errors, performance issues, outliers,
or unfair discrimination in the insurance practices resulting from the use of
the Predictive Model.
3.0
Risk Management and Internal Controls
The AIS Program should document the Insurer’s risk identification, mitigation, and
management framework and internal controls for AI Systems generally and at each
stage of the AI System life cycle. Risk management and internal controls should
address the following items:
a. The oversight and approval process for the development, adoption, or
acquisition of AI Systems, as well as the identification of constraints and
controls on automation and design to align and balance function with risk.
b. Data practices and accountability procedures, including data currency,
lineage, quality, integrity, bias analysis and minimization, and suitability.
c. Management and oversight of Predictive Models (including algorithms
used therein), including:
i. Inventories and descriptions of the Predictive Models.
Memorandum 2025-13A
December 10, 2025
Page 8
ii. Detailed documentation of the development and use of the
Predictive Models.
iii. Assessments such as interpretability, repeatability, robustness,
regular tuning, reproducibility, traceability, model drift, and the
auditability of these measurements where appropriate.
d. Validating, testing, and retesting as necessary to assess the
generalization of AI System outputs upon implementation, including the
suitability of the data used to develop, train, validate and audit the model.
Validation can take the form of comparing model performance on unseen
data available at the time of model development to the performance
observed on data post-implementation, measuring performance against
expert review, or other methods.
e. The protection of non-public information, particularly consumer
information, including unauthorized access to the Predictive Models
themselves.
f. Data and record retention.
g. Specifically with respect to Predictive Models: a narrative description of
the model’s intended goals and objectives and how the model is
developed and validated to ensure that the AI Systems that rely on such
models correctly and efficiently predict or implement those goals and
objectives.
4.0
Third-Party AI Systems and Data
Each AIS Program should address the Insurer’s process for acquiring, using, or relying
on (i) Third-Party data to develop AI Systems; and (ii) AI Systems developed by a Third-
Party, which may include, as appropriate, the establishment of standards, policies,
procedures, and protocols relating to the following considerations:
a. Due diligence and the methods employed by the Insurer to assess the
Third-Party and its data or AI Systems acquired from the Third-Party to
ensure that decisions made or supported from such AI Systems that could
lead to Adverse Consumer Outcomes will meet the legal standards
imposed on the Insurer itself.
b. Where appropriate and available, the inclusion of terms in contracts with
third parties that:
i. Provide audit rights and/or entitle the Insurer to receive audit
reports by qualified auditing entities.
Memorandum 2025-13A
December 10, 2025
Page 9
ii. Require the Third-Party to cooperate with the Insurer with regard to
regulatory inquiries and investigations related to the Insurer’s use of
the Third-Party’s product or services.
c. The performance of contractual rights regarding audits and/or other
activities to confirm the Third-Party’s compliance with contractual and,
where applicable, regulatory requirements.
SECTION 4: REGULATORY OVERSIGHT AND EXAMINATION CONSIDERATIONS
The Division’s regulatory oversight of Insurers includes oversight of an Insurer’s conduct
in the state, including its use of AI Systems to make or support decisions that impact
consumers. Regardless of the existence or scope of a written AIS Program, in the
context of an investigation or market conduct action, an Insurer can expect to be asked
about its development, deployment, and use of AI Systems, or any specific Predictive
Model, AI System or application and its outcomes (including Adverse Consumer
Outcomes) from the use of those AI Systems, as well as any other information or
documentation deemed relevant by the Division.
Insurers should expect those inquiries to include (but not be limited to) the Insurer’s
governance framework, risk management, and internal controls (including the
considerations identified in Section 3). In addition to conducting a review of any of the
items listed in this Memorandum, a regulator may also ask questions regarding any
specific model, AI System, or its application, including requests for the following types of
information and/or documentation:
1.0
Information and Documentation Relating to AI System Governance, Risk
Management, and Use Protocols
a. Information and documentation related to or evidencing the Insurer’s AIS
Program, including:
i. The written AIS Program.
ii. Information and documentation relating to or evidencing the
adoption of the AIS Program.
iii. The scope of the Insurer’s AIS Program, including any AI Systems
and technologies not included in or addressed by the AIS Program.
iv. How the AIS Program is tailored to and proportionate with the
Insurer’s use and reliance on AI Systems, the risk of Adverse
Consumer Outcomes, and the Degree of Potential Harm to
Consumers.
Memorandum 2025-13A
December 10, 2025
Page 10
v. The policies, procedures, guidance, training materials, and other
information relating to the adoption, implementation, maintenance,
monitoring, and oversight of the Insurer’s AIS Program, including:
(1) Processes and procedures for the development, adoption,
or acquisition of AI Systems, such as:
(a) Identification of constraints and controls on
automation and design.
(b) Data governance and controls, any practices related
to data lineage, quality, integrity, bias analysis and
minimization, suitability, and Data Currency.
(2) Processes and procedures related to the management and
oversight of Predictive Models, including measurements,
standards, or thresholds adopted or used by the Insurer in
the development, validation, and oversight of models and AI
Systems.
(3) Protection of non-public information, particularly consumer
information, including unauthorized access to Predictive
Models themselves.
b. Information and documentation relating to the Insurer’s preacquisition/pre-use diligence, monitoring, oversight, and auditing of data or
AI Systems developed by a Third-Party.
c. Information and documentation relating to or evidencing the Insurer’s
implementation and compliance with its AIS Program, including
documents relating to the Insurer’s monitoring and audit activities
respecting compliance, such as:
i. Documentation relating to or evidencing the formation and ongoing
operation of the Insurer’s coordinating bodies for the development,
use, and oversight of AI Systems.
ii. Documentation related to data practices and accountability
procedures, including data lineage, quality, integrity, bias analysis
and minimization, suitability, and Data Currency.
iii. Management and oversight of Predictive Models and AI Systems,
including:
(1) The Insurer’s inventories and descriptions of Predictive
Models, and AI Systems used by the Insurer to make or
Memorandum 2025-13A
December 10, 2025
Page 11
support decisions that can result in Adverse Consumer
Outcomes.
(2) As to any specific Predictive Model or AI System that is the
subject of investigation or examination:
(a) Documentation of compliance with all applicable AI
Program policies, protocols, and procedures in the
development, use, and oversight of Predictive
Models and AI Systems deployed by the Insurer.
(b) Information about data used in the development and
oversight of the specific model or AI System,
including the data source, provenance, data lineage,
quality, integrity, bias analysis and minimization,
suitability, and Data Currency.
(c)
Information related to the techniques,
measurements, thresholds, and similar controls
used by the Insurer.
iv. Documentation related to validation, testing, and auditing, including
evaluation of Model Drift to assess the reliability of outputs that
influence the decisions made based on Predictive Models. Note
that the nature of validation, testing, and auditing should be
reflective of the underlying components of the AI System, whether
based on Predictive Models or Generative AI.
2. Third-Party AI Systems and Data
In addition, if the investigation or examination concerns data, Predictive Models, or AI
Systems collected or developed in whole or in part by third parties, the Insurer should
also expect the Division to request the following additional types of information and
documentation.
a. Due diligence conducted on third parties and their data, models, or AI
Systems.
b. Contracts with Third-Party AI System, model, or data vendors, including
terms relating to representations, warranties, data security and privacy,
data sourcing, intellectual property rights, confidentiality and disclosures,
and/or cooperation with regulators.
c. Audits and/or confirmation processes performed regarding Third-Party
compliance with contractual and, where applicable, regulatory obligations.
Memorandum 2025-13A
December 10, 2025
Page 12
d. Documentation pertaining to validation, testing, and auditing, including
evaluation of Model Drift.
The Division recognizes that Insurers may demonstrate their compliance with the laws
that regulate their conduct in the state in their use of AI Systems through alternative
means, including through practices that differ from those described in this
memorandum. The goal of the memorandum is not to prescribe specific practices or to
prescribe specific documentation requirements. Rather, the goal is to ensure that
Insurers in the state are aware of the Division’s expectations as to how AI Systems will
be governed and managed and of the kinds of information and documents about an
Insurer’s AI Systems that the Division expects an Insurer to produce when requested.
As in all cases, investigations and market conduct actions may be performed using
procedures that vary in nature, extent, and timing in accordance with regulatory
judgment. Work performed may include inquiry, examination of company
documentation, or any of the continuum of market actions described in the NAIC’s
Market Regulation Handbook. These activities may involve the use of contracted
specialists with relevant subject matter expertise. Nothing in this memorandum limits the
authority of the Division to conduct any regulatory investigation, examination, or
enforcement action relative to any act or omission of any Insurer that the Division is
authorized to perform.
Please contact the Insurance Division at insurance@dcca.hawaii.gov or (808) 586-2790
if you have any questions.