Binding law — in force
Disclose AI use and oversight in the filed utilization-review policies and keep the tool open to inspection (California SB 1120)
From 2025-01-01, disclosures pertaining to the use and oversight of the artificial intelligence, algorithm or other software tool must be contained in the written utilization-review policies and procedures (H&S 1367.01(k)(1)(H); Ins. 10123.135(j)(1)(H)), which are filed with the regulator and disclosed to providers, enrollees and the public on request ((b)); the tool's criteria and guidelines must comply with the chapter and state and federal law ((C)); and the tool must be open to inspection for audit or compliance reviews by the regulator ((G)), which for plans is reviewed in each onsite medical survey (1367.01(l)). Detect the absence of a written AI-use and oversight policy and an inspection record.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 1 Jan 2025
- Official source
- Cal. Health & Safety Code 1367.01(k)(1)(H) · captured 3 Oct 2026 · anchor hash (SHA-256)
cd7fe5943d96…· 22 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Policies held in a compliance system outside the repository
Who it applies to
- Duty falls on: insurer
- Sectors: insurance, healthcare
- Health care service plans (including specialized plans) and disability insurers covering hospital, medical or surgical expenses, and any entity they contract with or work through for utilization review or utilization management, that use an artificial intelligence (an engineered or machine-based system that infers from input how to generate outputs), algorithm or other software tool for prospective, retrospective or concurrent review of requests for covered health care services based in whole or in part on medical necessity, for enrollees and insureds in California. In force 2025-01-01.
- Not covered:
- Health care service plans: decisions for the care or treatment of the sick who depend upon prayer or spiritual means for healing in the practice of religion (H&S 1367.01(m))
- Medi-Cal managed care plans: subdivision (k) applies only to the extent the State Department of Health Care Services obtains any necessary federal approvals and federal financial participation is not otherwise jeopardized (H&S 1367.01(k)(7))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.
In the code path that calls a model for underwriting, rating, premium quoting, or claims decisions, send or render a consumer notice that AI systems are used (in the quote flow, claim acknowledgement, or decision letter) and record that it was delivered. The model is an entry in the insurer's written AIS Program, covering governance, risk-management controls, internal audit, lifecycle management, third-party systems, and an accountable leader, with an owner; keep the inventory entry or a pointer to it in the repository so each decision path is traceable to its program record.
Where it goes: 9 AI output handling, 14 user-facing text, 12 repository artifacts.
What this provision adds:
- File the policies with the Director (plans) or keep them for the Commissioner (insurers), and disclose them to providers, enrollees or insureds and the public on request.
Example (Python + OpenAI SDK), before:
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision)After:
AI_USE_NOTICE = ('An AI system helped evaluate your claim. '
'You can ask us how it was used and request review by a claims adjuster.')
resp = client.chat.completions.create(model=MODEL, messages=claim_msgs)
claim_decision = parse_decision(resp.choices[0].message.content)
claims.update(claim_id, status=claim_decision, ais_program_ref='AIS-012')
send_ai_notice(claimant, text=AI_USE_NOTICE)Control: Insurer AI decision system without a written AIS Program / consumer notice. The same guard addresses 5 items with binding law in 4 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Insurers adopting the NAIC model guidance should maintain an AIS Program and AI-use notice (NAIC AI Model Bulletin · NAIC Model Bulletin, AIS Program Guidelines 1.1-1.9)
Rule id ca-sb1120.ai-policies-disclosure-and-inspection · review status: primary source derived