Insurtech Regulation: ZestyAI’s 2026 Policy Hurdles

Listen to this article · 8 min listen

Insurtech is moving fast, applying new tech to an old industry, but it’s slamming into a wall of complex regulations. Take a company like ZestyAI which uses artificial intelligence and huge datasets for property risk assessment. They represent both the potential of this new world and the real dangers. Their experience shows just how hard it is to plug advanced analytics into a heavily regulated field, leaving us to wonder if the old rulebooks can even keep up without killing innovation or leaving consumers exposed.

Key Takeaways

  • Insurtechs like ZestyAI are stuck in a fragmented US regulatory system, where scaling an AI model nationwide means fighting 50 different battles.
  • California’s recent directives on wildfire risk models show that regulators are demanding transparency and clear explanations for how AI underwriting works.
  • Laws like New York’s proposed AI in Insurance Act are a preview of what’s coming: hard guidelines on data use, fighting bias, and giving consumers a way to appeal decisions.
  • Companies have to get in front of regulators now, proving their models are fair and accurate with solid validation to build trust and prevent future crackdowns.
  • Compliance is no longer just about a traditional actuarial review. It has to include continuous AI model governance, using tools for explainable AI (XAI) and bias detection.

The Patchwork Quilt of State-Level Regulation

The biggest obstacle for any insurtech in the US is that insurance is regulated state by state, not federally. There’s no single rulebook. This means a company like ZestyAI, which sells property risk solutions to insurers all over the country, has to deal with 50 different sets of regulations covering everything from data privacy to model validation. This isn’t just paperwork. It dictates how products are built and where they can be sold.

For example, you might get an AI model approved in Florida, where everyone is focused on hurricane risk, only to have it face a completely different level of scrutiny in California, where wildfire exposure is the top concern. The required data sources, the validation methods, even what counts as “fair discrimination” can change completely from one state line to the next. Scaling a sophisticated AI solution then becomes a game of regulatory agility, not just tech superiority. I’ve seen companies spend years just tweaking their models and documentation to satisfy one state’s specific demands, all while their go-to-market plans are on hold and costs are piling up. The lack of a federal framework has always been a feature of US insurance, but for tech built to scale, it’s a massive point of friction.

Explainability and Bias: The Black Box Dilemma

ZestyAI’s core business is using tons of data, satellite imagery, aerial photos, building permits, to create incredibly specific risk scores for individual properties. These scores are supposed to make underwriting decisions and pricing more accurate. The problem is the “black box” perception of AI. Regulators and customers want to know *why* a property got a high-risk score, and they need proof that the model isn’t biased against certain people or places.

The California Department of Insurance (CDI) has been especially loud about this. In 2023 and 2024, Commissioner Ricardo Lara put out bulletins demanding that insurers justify how they use AI models, particularly for wildfire risk. These directives require detailed breakdowns of model inputs, the methods used, and an analysis of the model’s impact on different demographic groups. A Reuters report in late 2023 confirmed the mounting pressure on insurers and their tech partners to prove their models are fair, especially in high-risk zones where getting coverage is already tough. This is about building public trust in systems that have a huge impact on a homeowner’s finances. In my view, companies like ZestyAI have no choice but to invest heavily in explainable AI (XAI), so they can provide not just a score, but a clear, defensible reason behind it.

Data Privacy and Ethical Data Use

The sheer amount of data that AI risk models ingest is a double-edged sword, raising major privacy questions. ZestyAI, for instance, analyzes property details that, while technically public, can be combined to create a very intimate risk profile of a homeowner. So where is the line between innovation and privacy? States are drawing that line themselves, with laws like California’s California Consumer Privacy Act (CCPA) imposing tough rules on how personal data is handled. Even though property data isn’t the same as your health records, that distinction gets blurry when an algorithm’s analysis of your roof and yard directly affects your insurance premium.

Ethical data use is about more than just checking compliance boxes. It means being open about what data you’re collecting, locking it down against breaches, and ensuring your models aren’t learning from biased historical data that just reinforces old prejudices. A Pew Research Center report from early 2024 showed that the public is getting more nervous about AI making financial decisions for them. That feeling turns directly into regulatory pressure. Insurtechs need to do more than follow today’s privacy laws. They have to anticipate the next wave of legislation on data ethics and consumer consent. Getting ahead of this is just smart business.

The Path Forward: Collaboration and Standardization

Getting through this regulatory minefield is going to take a few different tactics. For ZestyAI and other insurtechs, talking directly with regulators is non-negotiable. That means showing up to industry working groups, lending them technical expertise, and being open about their technology’s benefits and guardrails. The goal is to help regulators write smart, flexible rules that allow for new tech while still protecting people.

I think we’re going to see a slow move toward more standardization of insurtech rules across states over the next few years. A federal regulator is still a fantasy, but model laws from groups like the National Association of Insurance Commissioners (NAIC) could bring some consistency. New York’s proposed AI in Insurance Act, on the table for 2026, is a perfect preview of this future, laying out specific rules for data governance, bias testing, and consumer notifications. If that kind of law gets widely adopted, it could create a much more predictable environment for everyone. In the end, it’s on companies like ZestyAI to lead the way on regulatory compliance and turn these challenges into a chance to set the standard for the entire industry.

The regulatory environment is a serious challenge for insurtechs like ZestyAI, but it’s not a deal-breaker. Success will come down to being transparent, having bulletproof model validation, and working with state regulators to build a future where technology and consumer protection can actually work together.

What’s the biggest regulatory hurdle for US insurtechs?

The fragmented, state-by-state regulatory system. It forces companies to comply with 50 different sets of rules for model approvals, data standards, and consumer protection, making a national rollout incredibly difficult.

What does “explainability” mean for insurance AI?

It’s the model’s ability to show its work, to clearly articulate why it produced a specific risk score or decision. Regulators need this transparency to ensure the AI is fair, free of bias, and not just an impenetrable “black box.”

Any state leading the charge on AI regulation?

The California Department of Insurance (CDI) is definitely one of the most active. It has pushed insurers hard to provide justification for their AI models, especially those used to assess wildfire risk, demanding both explainability and bias checks.

What kind of data does a company like ZestyAI use?

ZestyAI uses massive amounts of property-specific data. This includes everything from satellite and aerial imagery to public building permit records, all to analyze individual risk factors like roof condition or the distance to dense vegetation.

Are there efforts to create a single AI insurance rulebook?

Yes, though a single federal standard isn’t likely soon. Instead, states like New York are taking the lead with proposals like the AI in Insurance Act. This legislation aims to create clear guidelines for AI governance and consumer rights, which could serve as a model for other states.

April Martin

Investigative News Strategist Certified Information Integrity Analyst (CIIA)

April Martin is a seasoned Investigative News Strategist with over a decade of experience navigating the complexities of the modern news landscape. He currently serves as Lead Analyst at the prestigious Veritas News Institute, where he focuses on identifying emerging trends and developing innovative approaches to news dissemination. Prior to Veritas, April honed his skills at the independent news organization, Global Reporting Syndicate. He is widely recognized for his pioneering work in data-driven journalism, culminating in his development of the Martin Algorithm, a tool used to detect and combat misinformation campaigns. April is a sought-after speaker and consultant, sharing his expertise with news organizations worldwide.