27 July 2026
Access, not only quality: what the 2026 state laws on AI in prior authorization are really governing
Through 2026, a wave of US states enacted laws on how health insurers may use AI in prior authorization and claims decisions. Alabama, Indiana, Utah, Washington, Maryland, and Georgia took somewhat different routes, but they converge on a single rule: AI may assist and streamline insurance operations, but an insurer cannot rely on it as the sole basis for denying care, and an adverse determination must be made by a licensed professional. Several go further and make the oversight reportable: Maryland requires quarterly reporting of adverse decisions and lets the insurance commissioner investigate spikes in denials, and Washington requires insurers to report how many prior-authorization denials were made with the aid of AI.
Almost all of my own governance work, and most medical AI governance in general, is about the quality and safety of care for the patient in front of the system: what the model may claim, when it must escalate, who is accountable if it is wrong. These laws govern a different thing. The AI here does not diagnose or advise a patient. It decides whether the patient gets the treatment at all. And the patient is usually not in the room, often cannot tell that AI was involved, and never consented to it. That is a different accountability geometry, and it is worth stating plainly as a question every medical AI governance review should ask: does this system affect access to care, not only the quality of care?
Where the real governance question sits. It is easy to read these laws as “AI prior authorization now needs a human in the loop” and stop there. That reading misses the hard part. Every one of these laws reaches for human oversight, which means the load-bearing question is no longer whether a human is involved but whether that human actually decided. Utah’s law is explicit that adverse determinations must rest on the professional’s independent medical judgment, separate from and not dictated by the AI recommendation. Washington bars AI as the sole basis for a denial and requires a licensed professional for any adverse determination. Georgia permits AI in the process but prohibits it from issuing an adverse determination without a provider’s review and approval. Read together, the shift is precise: from “was a human involved?” to “can you prove the human, and not the model, made the call?”
That is the same shift I look for in clinical AI, which I have written about before: a control is only governance when there is a test that shows it works and a record that shows it held. “A licensed professional reviewed it” is a promise. A denial-rate that moves with the AI’s recommendations, an overturn-on-appeal rate that quietly climbs, a reviewer approving more cases per hour than independent judgment could support: those are the signals that the human in the loop has become a rubber stamp. Maryland’s move, letting a regulator investigate significant increases in adverse determinations, is exactly an attempt to turn the promise into a monitored, auditable signal. The state laws, taken as a set, are a natural experiment in making human-in-the-loop provable rather than assumed.
What this means if you build or deploy payer-side AI. The deployment-readiness question is not “does a human sign off.” It is: what is the audit trail that a human exercised independent judgment on this specific determination, and what monitored signal would show the oversight had degraded into approval-by-default before a regulator or a denied patient discovered it? That is the same risk-control logic I use for clinical systems, pointed at the access decision instead of the clinical one.
Patient-facing quality and payer-side access are two axes of the same discipline. A system can be clinically excellent and still deny people care through an unaudited human in the loop. Naming the second axis is how governance keeps up with where AI actually touches patients, which is increasingly not at the bedside but at the point where someone decides whether they will be treated at all.
Source: Holland & Knight, "States Continue Efforts to Regulate AI in Healthcare: A Review of Legislation Passed in 2026," May 2026, which summarizes the 2026 state laws referenced here (Alabama SB 63, Indiana HB 1271, Utah SB 319, Washington SB 5395, Maryland HB 1563, Georgia SB 544) and the CMS guardrails for Medicare Advantage prior authorization. This note is a governance reflection and not legal advice.