The 2026 statutory layer — statute-linked, honestly labeled
In 2026, state legislatures wrote licensed-human review of AI coverage decisions into general insurance law. Each statute asks for something slightly different — a licensed professional, a specialty match, individual-history review, a report, a receipt. The Review Rail's answer to each is a mechanism, not a promise. Here is the map.
No medical-necessity denial solely on AI output; human review by a licensed clinician "competent in the relevant clinical area"; determinations based on the patient's individual history, not group data; AI use disclosed to regulators. (Also bars payer reimbursement for AI-delivered psychotherapy.)
Rail mechanism: specialty-and-state matched routing is the default, not an option — a Colorado spine denial routes to a Colorado-licensed physician in the relevant specialty, NPI-verified at signing, with the individual chart as the review object. The receipt records reviewer specialty, so "competent in the relevant clinical area" is a provable fact, not an attestation.
Both sides of the claim: insurers may not AI-downcode without human review of the medical record, and providers may not submit AI-drafted claims without human review. 180-day recoupment limit.
Rail mechanism: the same review-and-receipt loop serves both directions — payer-side downcoding review, and provider-side sign-off on AI-drafted claims. A draft-then-sign workflow with a receipt per claim is the statutory minimum in Indiana today; the Rail makes it provable.
Insurers must disclose AI use, base authorization decisions on the patient's individual medical history, and issue any denial through a licensed professional.
Rail mechanism: licensed-professional denial is the Rail's only mode; the receipt's content hash proves the individual record was the review object.
No coverage decisions based solely on AI systems or software tools; no adverse determination until a qualified natural person conducts a utilization review with a clinical peer participating.
Rail mechanism: "not solely AI" needs evidence, not assertion — a per-determination receipt naming the licensed human is the difference between complying and being able to prove you complied.
Two-step: AI may perform the initial review, but it may not be the sole basis of a decision to deny, delay, or downgrade a medical-necessity request.
Rail mechanism: this is the Rail's architecture verbatim — the model flags, the clinician decides, the receipt separates the two steps so an auditor can see where the human began.
Quarterly reports on AI-assisted adverse decisions; the insurance commissioner may investigate denial spikes, especially for emergency services.
Rail mechanism: receipts aggregate into reports — reviewer credential class, determination type, and timestamp per decision means the quarterly filing is an export, not a project. When the commissioner asks about a spike, the answer is a verifiable record set.
Disclosure of AI use in preauthorization; independent medical judgment by reviewers; minimum validity periods for chronic-condition authorizations.
Rail mechanism: independence is Test 2 of the published standard — reviewers organizationally independent of the AI developer, compensation not tied to verdict direction — and it's in the receipt, not the marketing.
Denials only by a licensed physician or health professional within scope, per the patient's clinical history and the treating provider's recommendation; AI may not be the sole means to deny, delay, or modify services — the broadest prohibition enacted.
Rail mechanism: the review object includes modifications, downgrades, and delays — any adverse change routes through the licensed human, receipted.
AI may not bypass provider documentation to downcode claims; a natural person must review any downcoding determination.
Rail mechanism: same as Indiana's payer side — human downcoding review with the provider's documentation as the hashed review object.
NY = the most detailed utilization-review and reporting mandates proposed to date. PA = covers providers as well as insurers. Both would extend the pattern above rather than change it.
Rail mechanism: nothing new required — the same matched-reviewer-plus-receipt loop, with reporting exports.
CMS WISeR (2026–2031): licensed clinicians behind every non-payment recommendation in six states, vendors paid on averted expenditures. Counter-trend: H.R. 238 would let AI qualify as a prescriber — if it advances, it collides with every statute on this page. We watch both.
Rail mechanism: the Review Rail was built for the WISeR requirement; the state layer is the same requirement, generalized.