The 2026 statutory layer — statute-linked, honestly labeled

Nine states, one rail.

In 2026, state legislatures wrote licensed-human review of AI coverage decisions into general insurance law. Each statute asks for something slightly different — a licensed professional, a specialty match, individual-history review, a report, a receipt. The Review Rail's answer to each is a mechanism, not a promise. Here is the map.

States with licensed-review laws on the books

Colorado — HB26-1139effective Jan 1, 2027

No medical-necessity denial solely on AI output; human review by a licensed clinician "competent in the relevant clinical area"; determinations based on the patient's individual history, not group data; AI use disclosed to regulators. (Also bars payer reimbursement for AI-delivered psychotherapy.)

Rail mechanism: specialty-and-state matched routing is the default, not an option — a Colorado spine denial routes to a Colorado-licensed physician in the relevant specialty, NPI-verified at signing, with the individual chart as the review object. The receipt records reviewer specialty, so "competent in the relevant clinical area" is a provable fact, not an attestation.

Indiana — HB1271in effect July 1, 2026

Both sides of the claim: insurers may not AI-downcode without human review of the medical record, and providers may not submit AI-drafted claims without human review. 180-day recoupment limit.

Rail mechanism: the same review-and-receipt loop serves both directions — payer-side downcoding review, and provider-side sign-off on AI-drafted claims. A draft-then-sign workflow with a receipt per claim is the statutory minimum in Indiana today; the Rail makes it provable.

Alabama — SB 63signed Apr 16 · effective Oct 1, 2026

Insurers must disclose AI use, base authorization decisions on the patient's individual medical history, and issue any denial through a licensed professional.

Rail mechanism: licensed-professional denial is the Rail's only mode; the receipt's content hash proves the individual record was the review object.

Georgia — SB 444enacted · effective Jan 1, 2027

No coverage decisions based solely on AI systems or software tools; no adverse determination until a qualified natural person conducts a utilization review with a clinical peer participating.

Rail mechanism: "not solely AI" needs evidence, not assertion — a per-determination receipt naming the licensed human is the difference between complying and being able to prove you complied.

Iowa — HF 2635in effect July 1, 2026

Two-step: AI may perform the initial review, but it may not be the sole basis of a decision to deny, delay, or downgrade a medical-necessity request.

Rail mechanism: this is the Rail's architecture verbatim — the model flags, the clinician decides, the receipt separates the two steps so an auditor can see where the human began.

Maryland — HB 1563enacted Apr 28, 2026

Quarterly reports on AI-assisted adverse decisions; the insurance commissioner may investigate denial spikes, especially for emergency services.

Rail mechanism: receipts aggregate into reports — reviewer credential class, determination type, and timestamp per decision means the quarterly filing is an export, not a project. When the commissioner asks about a spike, the answer is a verifiable record set.

Utah — SB 319enacted · effective Jan 1, 2027

Disclosure of AI use in preauthorization; independent medical judgment by reviewers; minimum validity periods for chronic-condition authorizations.

Rail mechanism: independence is Test 2 of the published standard — reviewers organizationally independent of the AI developer, compensation not tied to verdict direction — and it's in the receipt, not the marketing.

Washington — SB 5395signed Mar 25, 2026

Denials only by a licensed physician or health professional within scope, per the patient's clinical history and the treating provider's recommendation; AI may not be the sole means to deny, delay, or modify services — the broadest prohibition enacted.

Rail mechanism: the review object includes modifications, downgrades, and delays — any adverse change routes through the licensed human, receipted.

Illinois — SB 3114awaiting signature

AI may not bypass provider documentation to downcode claims; a natural person must review any downcoding determination.

Rail mechanism: same as Indiana's payer side — human downcoding review with the provider's documentation as the hashed review object.

Also on the map

Pending: New York S7896/A8556 · Pennsylvania HB 1925

NY = the most detailed utilization-review and reporting mandates proposed to date. PA = covers providers as well as insurers. Both would extend the pattern above rather than change it.

Rail mechanism: nothing new required — the same matched-reviewer-plus-receipt loop, with reporting exports.

The federal layer

CMS WISeR (2026–2031): licensed clinicians behind every non-payment recommendation in six states, vendors paid on averted expenditures. Counter-trend: H.R. 238 would let AI qualify as a prescriber — if it advances, it collides with every statute on this page. We watch both.

Rail mechanism: the Review Rail was built for the WISeR requirement; the state layer is the same requirement, generalized.

Honest labels. Every enacted statute above was checked against primary or law-firm sources (state legislature texts; Holland & Knight; Becker's) before publication, and each is linked so your counsel can read it — statutory compliance is your counsel's call, not a vendor page's. Effective dates vary; two entries are not yet law. And one thing we won't claim: that human review makes AI more accurate. The published evidence is mixed. What these laws require — and what the Rail provides — is accountability you can prove, per determination, against a published standard.
See the Review Rail — the two-week pilot