Your Insurer Can't Use a Robot to Deny You Anymore. It Can Still Use One to Say Yes.
Six states just made a human sign your denial. Here is what those laws still let the software do to your claim — and the six things worth doing before you need them.
The most honest thing I can tell you about health insurance is that I have never once known who decided.
Some years ago I wrecked a knee while snowboarding. The orthopedist wanted an MRI. What I got was a line of text in a patient portal — Prior authorization: pending review — and eleven days of refreshing it like a man waiting on a jury. I called twice. Both times a kind person told me the request was "with clinical review." Both times I asked who, specifically. Both times she couldn't tell me — not because she was hiding anything, but because there was no name on her screen either. On day twelve the line changed to Approved. No reasoning, nothing to read, nothing to argue against.
Here is my confession: I was so relieved that I never asked the question that actually mattered. Not "will they say yes," but what is the thing that says yes — and what would it have taken to make it say no?
This summer, several American states finally wrote an answer into law. Washington's took effect in June; Indiana's and Iowa's switched on July 1. And the answer is more interesting — and more slippery — than the headlines suggest.
First, the part that is genuinely good news
Three words first, because the argument collapses without them. Prior authorization is your insurer's permission slip: before the scan or the surgery, your doctor must ask the plan to agree it is medically necessary. Claims review asks the same question afterward, when the bill arrives. Downcoding is a third thing — the plan agrees you got care, but decides you got a cheaper kind than your doctor billed for. Three levers, all quietly handed to software.
The 2026 laws go after the denial; Indiana, at the downcode. The pattern the law firms describe is now nearly uniform: an insurer cannot rely upon it as the sole basis for denying care. Six states, red and blue, passed versions of that sentence in a single season, a few weeks apart — Iowa and Indiana under Republican majorities, Washington and Maryland under Democratic ones. Washington's cleared the Senate and House 48–1 and 94–0. If you have been told AI regulation is a partisan fight, this is your counter-example.
And parts of it are genuinely strong. Iowa requires that a denial come from a "qualified reviewer" — a physician practicing in the same or a similar specialty as the doctor who asked. Not a rubber stamp: a named professional with a license to lose. Washington went past the ban into structure — carriers' AI policies open to audit by the insurance commissioner, and mandatory reporting of the percentage of denials "aided by" artificial intelligence. Indiana added disclosure: insurers must tell you when AI made an adverse determination or downcoded a claim. California, two years earlier, chose harder words still, barring the software from denying, delaying or modifying care based in whole or in part on medical necessity. Sen. Tina Orwall, who sponsored the Washington bill, put the promise plainly: only licensed providers are now ultimately making these decisions, not AI.
So far, so good. I want that on the record before I take it apart.
The word doing all the work is "sole"
Here is where things get interesting.
Read Washington's own bill report and the architecture is stated in one breath: algorithms may be used to process and approve prior authorization requests, but may not be used without human review to deny care based on medical necessity. Iowa is more explicit still: its law affirmatively permits the algorithm to run the initial review of a request, forbidding it only as the sole basis of a denial, delay or downgrade.
Notice what that is. Not a restriction on automation — a division of labour between machine and human, with the machine taking the larger half. The software may still read every file, still approve without a human looking, still rank and score and pend and route — which means it decides in practice which files a human ever sees. And when it recommends a denial, the law does not require the human to disagree. It requires the human to exist.
Indiana shows how thin that can get when you read the statute instead of the summary. Its new chapter bars using AI as the sole basis to downcode a claim without review of the medical record — by whom? By an employee or contractor of the insurer. Not a physician. Not a clinical peer. Not anyone holding a medical license. One law-firm alert described Indiana as requiring "a healthcare professional's review"; the enrolled statute says no such thing, and the text is what gets enforced.
Meanwhile the yes-side is where the money is. Testifying before Minnesota legislators, the health plans' lobbyist, Dan Endreson, described the technology as a way to get us to a "yes" as fast as possible and not to a "no." When Kansas's legislative researchers surveyed individual-market carriers, the category that lit up was AI for approval processes — 68 percent using or exploring it. And Aetna reported in April 2026 that it had standardized 88% of its prior authorization volume.
None of that is illegal. All of it is what these laws permit. The statutes drew a line around the one decision the industry was least eager to automate in public, and left the pipeline that produces it untouched.
We have already run this experiment
The human-review requirement is not a hypothesis; insurers have been running it for years. ProPublica reported in 2023 that Cigna physicians refused to pay for 300,000 claims in two months — averaging 1.2 seconds per claim, per internal spreadsheets — without ever opening a patient file. A licensed human was in the loop the entire time. The loop was 1.2 seconds long. A class action followed; Cigna disputes the characterisation. Note who else objected: House Republicans wrote to Cigna, asking how patients could be told a clinician had found their care unnecessary when no clinician had read the file, and noting that roughly 80 percent of Medicare Advantage coverage denials were overturned when challenged.
Then there is the case still in federal court in Minnesota, which needs fencing. The complaint against UnitedHealth alleges that an algorithm called nH Predict was used to override treating physicians' judgments on post-acute care, that the company knew the model had a 90% error rate, and that it kept using it because only about 0.2% of policyholders appeal. Those are allegations; Optum disputes them. Procedurally, a magistrate judge ordered broad discovery into the insurer's AI-driven claims processes in March — a ruling about what plaintiffs may see, not a finding about what happened.
Nobody disputes what a Senate investigation found in 2024, though: UnitedHealthcare, Humana and CVS each denied post-acute prior authorization at far higher rates than other care as predictive technology spread. And researchers in npj Digital Medicine note that a 1.2-second review does not allow for meaningful human confirmation. That is the honest shape of my worry: these laws mandate the exact safeguard that was in place when all this happened, and that failed.
The strongest case against me
The other side, put properly, is not weak.
This was already the standard. The health plans' 2025 pledge affirms that non-approved requests based on clinical reasons will continue to be reviewed by medical professionals — a standard already in place — plus a promise that by 2027, 80 percent of fully documented electronic approvals come back in real time. Their point: the laws codify practice, not change it. Either reassuring or damning depending on how you read Cigna — but the yes-side benefit is real. Had an algorithm approved my knee MRI in eleven seconds instead of eleven days, I would not have complained once.
The mandate may also be unenforceable at scale. The free-market objection from Paragon Health Institute — written in late 2024, before these laws — is that monitoring every AI recommendation is difficult, and that overly broad rules raise costs and distort development. They are right about the monitoring. That is an argument for regulating outcomes and audits, not for regulating nothing.
Most importantly: a thin law is still the only law there is. Federal preemption is live — a December 2025 executive order created an AI Litigation Task Force to challenge state AI rules. KFF's analysts note flatly that preemption could nullify state consumer protections governing AI in prior authorization and claims review. Criticising these statutes is not wanting them gone. I want them stronger, and I want them to survive.
One irony deserves naming. While states restricted AI denials, the federal government launched its own AI prior-authorization pilot — the WISeR Model, begun January 1, 2026, running in six states including Washington. It covers Original Medicare only, not Medicare Advantage, and state law cannot reach a federal demonstration. All non-payment recommendations come from licensed clinicians. Participating companies also receive a percentage of the savings their review generates: the states' safeguard, bolted to an incentive the states never addressed.
The comparison that reframed this for me
Set all that beside a question America never asks out loud: who decides, and at what altitude?
In Germany, the big coverage questions — is this therapy in the benefit basket, on what evidence, under what conditions — are settled centrally, once, by a federal committee that sets what the sickness funds reimburse for 74 million people. Its directives are legally binding for all stakeholders, and nothing about them is quiet: the committee publishes a full report, the directive runs in the Federal Gazette with its justification, and a hearing is required by law before the vote. Where an individual case needs a medical judgment, the fund refers it out to the Medizinischer Dienst, which a 2020 law deliberately reorganised outside the funds' control. In England, NICE asks in public whether a treatment works and whether it is value for money, consults on the draft, hears appeals and publishes them — and where it recommends, commissioners carry a statutory responsibility to fund it within ninety days.
I am not romanticising either. Both say no — NICE explicitly, on reasoning anyone can read and attack, and people are furious about it, often rightly. Rationing is real.
But look at where the no happens. There, the hard call is made at the level of the rule — publicly, with reasons, contestable by anyone, once, for everybody. In the American model it is made at the level of the file: privately, without reasons, contestable only by you, one claim at a time. That was what I could not reach from my kitchen table. There was no rule to argue with — only my file, and something on the other side of it.
Which is why altitude matters more than any human-in-the-loop clause: a public rule is a terrible thing to automate in secret, because anyone can check it. A private per-file judgment is a wonderful thing to automate in secret, because nobody can. The sole-basis laws put a signature on the file when we needed daylight on the rule.
Now imagine the compliant version
Give the industry five years, and picture a fully law-abiding claims operation in 2031.
Every request is read by a model. Ninety-odd percent are approved in under a second — and honestly, good; that part is a gift. The rest are not denied by the model, because that would be illegal. They are pended. Routed. Assigned a queue. The queue is the product.
Each escalated file lands on a reviewer's screen pre-summarised: clinical history compressed into six bullets the model chose, a policy citation it selected, a recommended disposition already filled in, and a counter showing how far behind the day's target they are running. That reviewer is licensed — in Iowa, a same-specialty physician. The signature is real. The statute is satisfied on every file.
Now add the layer nobody legislated. The model has learned which denials get appealed and which do not — by procedure, by ZIP code, by whether the patient has an advocate. It never needs to deny a thing. It only needs to decide which files reach a human running eleven minutes behind, and when. Route the contestable ones to the careful reviewer; route the rest to the queue at 4:50 on a Friday. Underneath, the third lever hums along: downcoding, approved at a lower level of service across thousands of claims at once, each too small for anyone to fight.
A dystopia? No. A compliance department doing its job well. Every step defensible, documented and lawful under every 2026 statute — which is exactly what worries me. We did not build a guardrail. We published a specification for routing around one.
What the people who study this actually find
I would not lean this hard on intuition. Start with the mechanism: a study in PLOS ONE tested human-in-the-loop review against straight delegation and found the human-supervised decisions were less accurate — and worse, monitors intervened least when the machine was most wrong: 64% corrected a small error, only 60% a large one.
Ben Green, who studies exactly this at the University of Michigan, puts it bluntly: oversight requirements provide a false sense of security, legitimising faulty algorithms without touching the underlying problem, because people cannot actually perform the function assigned to them.
Applied to insurance, Michelle Mello and colleagues at Stanford — she holds appointments in both the law and medical schools — warn that insurance reviewers lack the time, expertise, and incentives to check AI recommendations, and that models trained on an insurer's past decisions lock in whatever was wrong with them.
Clinicians report the outcome already: the American Medical Association found three in five physicians concerned that health plans' use of AI is increasing denials, three-quarters saying denials rose over five years. Even the radiologists' college is now tracking the legislative trend toward mandating human review and barring determinations made solely by AI.
And the worry spans the spectrum. From the patient-advocacy left, the National Health Law Program warns federal pressure will push states toward reforms "easier for payers to evade." Georgetown's Medicare Policy Initiative notes AI can worsen disparities when trained on biased data. From the industry-facing right, Paragon's caution about unmonitorable recommendations finds the same hole from the other side. And the state insurance commissioners have objected to federal preemption of their oversight.
Nobody serious wants the software banned. Nearly everybody serious is saying a signature is not oversight.
What does this mean for you?
Practical, in rough order of return:
Appeal. Almost nobody does, and that is the whole business model. The Minnesota complaint alleges only about 0.2% of policyholders appeal; Congress found roughly 80 percent of Medicare Advantage coverage denials overturned when someone did. An appeal is a form and a deadline — possibly the highest-return hour of paperwork in American life.
Ask, in writing, whether AI was involved and who the reviewer was. Indiana now requires that disclosure for adverse prior-auth determinations and downcodes; Iowa requires a same-specialty physician. Elsewhere, ask anyway — the question changes how a file gets handled.
Read your explanation of benefits for downcoding, not just denial. "Paid, but less than billed" is the lever the new laws barely reach and almost no patient contests. If the code does not match the care you received, dispute it.
Save the timeline. Submission dates, every call, every status change. Delay is not denial — which is precisely why it is the tactic least constrained by these laws, and a timeline is the only thing that makes it visible to a regulator.
Complain to your state insurance commissioner. That office takes complaints, and in Washington it can now audit a carrier's AI policies. Regulators act on patterns; patterns are made of filings like yours.
When your legislature revisits this, ask for the four things "sole basis" left out: outcome reporting, published appeal and overturn rates, independent audits of the models, and a ban on paying reviewers a share of the savings. Those reach the pipeline. A signature never will.
The lesson, as I see it
I have thought about why those eleven days of refreshing a portal bothered me more than the possibility of a no. It was not the waiting, and it was not the software. It was that the decision had no address — nothing to read, nobody to name, no rule to point at, only an outcome arriving from somewhere and a company that could not tell me where. The 2026 laws are a real attempt to fix that, and I have no interest in sneering at the first serious guardrail anyone built.
But they answer "who signs" when the live question is "who decides." The two came apart the moment a machine could read ten thousand files a day and a physician could sign one every 1.2 seconds. You do not restore accountability by stationing a human at the end of a process no human can inspect. You restore it by making the process legible: publish what gets denied and how often, audit the models that route the files, let reviewers refuse a quota, and never pay anyone a share of the savings.
My vote? Keep the laws — they are the floor, and a floor is worth defending against anyone who would preempt it away. Then go get the ceiling. Because the promise on offer is that no robot will deny your care, and that promise is being kept. It is simply not the promise that protects you.
The HAIA Foundation works on the gap between what a rule says and what a system actually does — which is where most of our autonomy quietly goes. If that is your kind of question, subscribe, and bring someone who has waited on a portal.





