What US AI Claims-Denial Litigation Is Previewing for APAC and Gulf Insurers
sourceCode | BFSI Technology Insight | 8 October 2026
Key Takeaways
-
A Minnesota federal magistrate's 9 March 2026 order in Estate of Lokken v. UnitedHealth Group compelled discovery into UnitedHealth's nH Predict AI tool - internal development files, AI review-board membership, and training materials - treating "how the model was built" as directly relevant to bad-faith claims, not a settled or privileged matter.
-
Neither Lokken nor Kisting-Leung v. Cigna (the PxDx case) has produced a verdict, a certified class, or a damages award. Both are surviving motions to dismiss and moving through discovery - meaningful signal, not proof of liability.
-
US state adoption of the NAIC's Model Bulletin on the Use of AI Systems by Insurers has reached at least 25 states plus DC as of the most recent confirmed update (Mississippi, 22 July 2026) - higher than commonly cited counts, and still climbing.
-
Washington and Colorado have gone further than the NAIC bulletin's disclosure-based approach, passing statutes that require a licensed clinician to review any denial based even partly on medical necessity before AI can be involved at all.
-
No APAC or Gulf insurance regulator has yet issued a binding, claims-specific requirement of this kind. India's IRDAI and Hong Kong's IA are both mid-process; the UAE's central bank guidance is explicitly non-binding. The documentation standard is being written in US courtrooms and statehouses well before it appears in APAC/Gulf regulatory text.

Introduction
Most Risk and Compliance functions in APAC and Gulf insurers track regulation the way it has always been tracked: watch the regulator, wait for a consultation paper, respond to a draft circular, implement once the rule is final. That sequence assumes the regulator is where the standard originates. For claims AI, it increasingly isn't.
In the United States, the operative definition of "adequate human oversight of an algorithmic claims decision" is being assembled inside two pieces of active litigation - through discovery orders, motion-to-dismiss rulings, and the specific categories of documents a court decides a plaintiff is entitled to see. That definition is moving faster, and with more granularity, than the parallel regulatory process running through the NAIC and individual state legislatures. And it is moving dramatically faster than anything on record from IRDAI, Hong Kong's Insurance Authority, MAS, or the UAE Central Bank.
This matters to a Head of Claims or a Chief Risk Officer in Sydney, Singapore, Mumbai, or Dubai for a specific reason: litigation discovery doesn't wait for your jurisdiction's regulator to catch up before it defines what "good" documentation looks like. It defines it now, in a US court file, and that definition travels - through reinsurers' underwriting questionnaires, through global parent-company governance standards, through the next generation of NAIC-style model language that regional regulators borrow wholesale. Waiting for a local circular to say so is a way of finding out last.
This piece verifies what the US litigation and regulatory record actually shows - not what has been assumed about it - and sets out what that record is previewing for the APAC and Gulf claims function.
The litigation record, precisely stated
Two cases anchor the current wave of US claims-AI litigation, and it is worth being exact about what each has and has not established, because the two are frequently conflated in secondary commentary.

Estate of Gene B. Lokken et al. v. UnitedHealth Group Inc. et al. (D. Minn., No. 0:23-cv-03514, filed 14 November 2023) alleges that UnitedHealth used its nH Predict algorithm to override physicians' post-acute care determinations for Medicare Advantage members, in some cases before the promised coverage period had elapsed. The plaintiffs' complaint alleges that more than 90% of nH Predict-influenced denials were later reversed on appeal - a figure that originates in the complaint itself and has not been adjudicated; it should be read as an allegation, not a proven fact (Tressler LLP, 2026; Healthcare Finance News, 2023).
The court granted UnitedHealth's motion to dismiss in part in 2025 - some claims were found preempted by federal Medicare Advantage statute - but allowed breach-of-contract and breach of the implied covenant of good faith and fair dealing claims to proceed into discovery. On 9 March 2026, a magistrate judge ruled on a motion to compel and ordered UnitedHealth to produce a substantial set of documents concerning nH Predict, including: internal analyses and discussions of how the tool works and what it was designed to achieve; materials from UnitedHealth's internal AI review board, including the identities of its members; post-acute-care policy and training materials dating back to January 2017 (i.e., pre-dating the tool's 2019 deployment); records tied to the naviHealth acquisition and projected cost savings; and government-investigation materials. UnitedHealth argued pre-2019 records were irrelevant; the magistrate rejected that argument, treating the earlier period as probative of how practice changed once the algorithm was introduced (ArentFox Schiff, 2026; Georgetown Health Care Litigation Tracker, 2026). Expert disclosures are due 14 October 2026. No class has yet been certified, and there is no finding of liability.
Kisting-Leung et al. v. Cigna Corporation et al. (E.D. Cal., No. 2:23-cv-01477, filed 24 July 2023) grew directly out of a March 2023 ProPublica investigation into Cigna's PxDx review system, which reported - from internal Cigna records and interviews - that Cigna's own doctors spent an average of 1.2 seconds per claim under the system, and that Cigna doctors denied more than 300,000 payment requests over a two-month period examined, with one doctor alone denying roughly 60,000 claims in a single month (ProPublica, 2023). On 31 March 2025, the court granted in part and denied in part Cigna's motion to dismiss, allowing California Unfair Competition Law and implied-covenant claims to proceed while narrowing others. Cigna answered the third amended complaint in May 2025, and a discovery deadline of 30 September 2026 was set. As with Lokken, there is no verdict, no certified class, and no damages finding - the case is a live, contested discovery process, not a settled precedent. (See "Note for internal review" below on docket activity after August 2026.)
Neither case has "won" anything for plaintiffs on the merits. What has been established, in both, is that a federal court is willing to treat the internal engineering record of a claims algorithm - design goals, training documentation, review-board deliberations - as discoverable and relevant to whether a denial was made in good faith. That is the operative precedent, and it is a discovery standard, not a verdict.
Why the courtroom is outrunning the regulator
The regulatory response to AI-driven claims denial in the US is real, but it is running on a different clock than the litigation, for a structural reason: litigation discovery is decided case-by-case, immediately, by a judge applying existing procedural rules to a live dispute; regulation requires either a legislature to pass a statute or 50-plus state insurance departments to individually adopt guidance, each on its own timeline.
The NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers illustrates this well. It is a principles-based, non-binding template that each state insurance department must separately choose to adopt - it does not become law simply because the NAIC issued it. As of the most recent confirmed adoption (Mississippi, 22 July 2026), the bulletin has been adopted by at least 25 states plus the District of Columbia - a total of 26 jurisdictions - up from 24 states plus DC as of April 2026 (NAIC, 2026; Tech Savvy Insurance, 2026; Openlayer, 2026). This is a materially higher and still-moving figure than the "23 states and DC" sometimes cited, and roughly eight further states are reported to be in active legislative or regulatory process (Openlayer, 2026). Even where adopted, the bulletin asks insurers to demonstrate AI governance and fair-practice compliance - it does not, by itself, mandate a licensed-physician sign-off on individual denials.
That stronger, more specific requirement is arriving through separate state statutes, and only in a handful of states so far. Washington's E2SSB 5395, signed 25 March 2026 and effective 11 June 2026, is explicit: "a licensed provider must review [a case] to deny care based on a determination of medical necessity," and AI cannot be the sole basis for denying, delaying, or modifying a service (Washington State Senate Democrats, 2026). Colorado's HB26-1139 - passed 47-15 in the House on 16 March 2026 and 32-3 in the Senate on 11 May 2026 - requires that "denial or delay of coverage for a service based in whole or in part on medical necessity must be reviewed by a licensed clinician or physician" (Colorado General Assembly, 2026). Georgia, Iowa, Utah, Alabama, and Illinois have each passed related but narrower measures in 2026 - some restricting AI as the sole basis for a decision, one (Illinois) targeting automated "downcoding" of claims specifically - with effective dates ranging from mid-2026 into 2028 (Becker's Payer Issues, 2026).
That is: as of today, a documented, binding, licensed-human-sign-off requirement for AI-influenced medical necessity denials exists in perhaps half a dozen US states, phasing in through 2028. Meanwhile, the specific categories of internal documentation a plaintiff's lawyer can compel - model development records, review-board minutes, training data provenance - have already been defined by a federal magistrate, for one insurer, in March 2026. The litigation isn't just faster; it is more granular, because a court order responds to a specific factual dispute rather than trying to draft a rule general enough to cover an entire industry.
What most APAC and Gulf insurers get wrong
The most common mistake we see in APAC and Gulf claims and risk functions is treating "no binding local rule yet" as equivalent to "no current exposure." Three specific gaps follow from that assumption.

First, regional insurers are tracking their own regulator's AI guidance and treating US litigation as a foreign curiosity, rather than as a leading indicator of what their own regulator will eventually specify. Regional frameworks are, on the current evidence, still at the scoping stage. Hong Kong's Insurance Authority issued a revised Guideline 16 on fair customer treatment, effective 31 March 2026 - but it addresses the policy lifecycle broadly and does not contain AI-specific claims, audit-trail, or override-documentation requirements (DLA Piper, 2026). India's IRDAI formed an AI working group on 18 June 2026, naming claims processing and fraud detection as the functions warranting closest attention first - but its recommendations, due roughly three months later, had not yet produced binding rules as this piece went to research (Business Standard, 2026). The UAE Central Bank published AI guidance for licensed financial institutions on 11 February 2026 that sets out a risk-tiered human-oversight model ("human in/on/out of the loop") and requires documented governance frameworks - but it is explicitly non-binding guidance, not a claims-specific statute, and does not name insurance claims decisions directly (Pinsent Masons, 2026). None of this is a criticism of the pace - building good AI governance rules takes real deliberation - but it means the region's regulatory floor is, for now, softer and less specific than what US courts are already demanding as a matter of civil procedure.
Second, most claims AI implementations in the region were built to satisfy an operational efficiency case - faster turnaround, lower unit cost - and treat documentation as a compliance afterthought rather than as litigation-grade evidence. The US cases show what a court actually wants to see: not just a decision log, but the reasoning behind the model's design, who approved it, what alternatives were considered, and whether a qualified human genuinely exercised judgment or rubber-stamped an output. Most claims platforms in the region were not built to produce that record, because nobody has yet demanded it of them.
Third, there is a governance-structure gap. A licensed-physician (or licensed-clinician) sign-off requirement, as now written into Washington and Colorado law, presumes a specific operating model: AI proposes, a named credentialed professional disposes, and that professional's review is itself documented and attributable. Very few APAC or Gulf claims operations are currently structured this way for AI-assisted decisions - the more common pattern is a human "in the loop" in a general supervisory sense, without individual attribution, credential logging, or a record of what the human actually considered before concurring with the model.
Business and technology implications
If the US litigation record is a genuine leading indicator - and the March 2026 discovery order suggests it is - then the practical requirement being previewed for claims AI is not "have a human somewhere in the process." It is a specific evidentiary architecture: a system that can reconstruct, for any denial, what the model recommended, what a named and credentialed reviewer decided, why, and what the model's design and training history were at the time.
That has direct technology consequences. Decision logs need to capture not just the outcome but the override event itself - whether a human accepted, modified, or rejected the model's recommendation, and on what stated basis. Model documentation needs to be retained as a living artefact, not a one-time build record, because a court (or a future regulator modelling itself on the NAIC bulletin) will ask what the model was designed to do and how that has changed. Reviewer identity and credentials need to be logged against each denial, not just "reviewed: yes/no." And architecturally, none of this can be assembled retroactively with any credibility - the Lokken order is instructive precisely because it reached back to 2017, before the tool even existed, to establish a baseline. Systems that don't already generate this record today will not be able to manufacture it under pressure later.
A decision framework: The Override Docket

To make this concrete, we use a framework we call The Override Docket - a deliberately courtroom-framed readiness check, built directly from what US discovery orders have actually demanded, rather than from a generic AI-governance checklist. It asks whether a claims AI's records would survive being subpoenaed tomorrow, organised as four exhibits:
- Exhibit A - Decision Provenance. For any denial, can you reconstruct exactly what the model recommended, on what inputs, and when - independent of what a human ultimately decided?
- Exhibit B - Override Attribution. Is every human override (or concurrence) logged against a named, credentialed individual, with a stated rationale - not just a binary "reviewed" flag?
- Exhibit C - Model Development File. Can you produce, on request, the model's design objectives, material version changes, and internal governance sign-off history - the equivalent of what UnitedHealth was ordered to produce for nH Predict?
- Exhibit D - Reviewer Credentialing Trail. Can you show, for the population of denials over a given period, that the individuals reviewing AI-flagged medical-necessity or coverage determinations held the relevant licence or qualification at the time of review?
An insurer that cannot produce all four exhibits today for its claims AI is not necessarily in breach of any current APAC or Gulf regulation. It is, however, one step behind a standard that a US court has already treated as reasonable to demand, and that regional regulators are demonstrably moving toward defining.
Counterargument and nuance
Two cautions belong here, because overstating the litigation's significance is its own risk.
First, US litigation outcomes are not regulation, and they are not final. Neither Lokken nor Kisting-Leung has produced a verdict or a settlement; both could still be dismissed, settled confidentially, or lost by plaintiffs at trial. A discovery order compelling document production establishes what a court considers relevant to a dispute, not a generally applicable legal standard - it binds the parties to that case, not the industry. Treating a single magistrate's discovery ruling as a settled national standard would be its own analytical overreach.
Second, the transmission mechanism from US litigation to APAC/Gulf practice is real but indirect, and legal systems differ. Most APAC and Gulf jurisdictions do not have US-style class-action mechanisms or the same discovery scope, so the direct legal pressure that produced the Lokken order will not simply replicate locally. The relevant transmission channels are more likely to be: global parent or reinsurer governance standards that get set to the highest common denominator; regional regulators explicitly borrowing NAIC-style model language (as several already have with other frameworks); and the fact that the same core AI vendors and claims platforms often serve both US and APAC/Gulf insurers, carrying design assumptions across markets. The signal is real, but it arrives translated, not identically.
The sourceCode’s perspective
The organisations we see managing this well are not the ones racing to publish an AI ethics policy. They are the ones that have already asked their claims technology function a narrower, harder question: if a regulator or a plaintiff's lawyer asked for the full development and override history of our claims AI tomorrow, could we produce it inside a week, not a quarter? In our experience, most claims platforms in the region were architected for throughput and cost, with documentation bolted on afterward - which means the honest answer, today, is usually no.
The fix is not more policy language; it is specific engineering: override logging with named attribution, retained model-version history, and credential checks wired into the review workflow itself. That is unglamorous infrastructure work, and it is exactly the work that the US litigation record shows gets asked for first.
Conclusion
The claims AI audit-trail and human-review standard is being written right now - not primarily in Canberra, Singapore, Mumbai, Riyadh, or Abu Dhabi, but in a Minnesota federal courtroom and a handful of US state legislatures. That standard has not yet crystallised into a single, settled rule even in the US: two anchor cases remain active and contested, and only a small number of states have gone as far as requiring licensed-clinician sign-off. But the direction is unambiguous, and the specific documentation categories a court has already found relevant - model design history, review-board records, individually attributed overrides - are a more concrete and demanding blueprint than anything currently on the record from an APAC or Gulf regulator. Insurers that wait for a local circular to say so will be building this architecture under deadline pressure, rather than on their own schedule.
We'd suggest starting with a narrower question than "are we AI-compliant": if your claims AI's override decisions and development history were subpoenaed tomorrow, could your team produce all four exhibits above within a week? If the honest answer is no, that gap - not the absence of a local rule - is the thing worth closing first. Contact us here!
FAQ
Has any US court ruled that AI-driven claims denials are illegal? No. Both anchor cases (Lokken v. UnitedHealth and Kisting-Leung v. Cigna) have survived partial motions to dismiss and are in active discovery. Neither has reached a verdict, a certified class, or a finding of liability as of this writing.
What exactly did the March 2026 court order require? A magistrate judge in Lokken v. UnitedHealth ordered UnitedHealth to produce internal documents about its nH Predict algorithm - including development records, AI review-board materials and member identities, and post-acute-care policy materials dating to 2017 - rejecting UnitedHealth's argument that pre-deployment records were irrelevant.
How many US states now require NAIC Model Bulletin-style AI governance from insurers? At least 25 states plus the District of Columbia have formally adopted the NAIC Model Bulletin as of the most recent confirmed update (Mississippi, July 2026), with roughly 8 more reported in progress. This bulletin is principles-based guidance on governance, not a physician-sign-off mandate.
Do any US states require a licensed physician to review AI claims denials specifically? Yes, a small but growing number. Washington (effective June 2026) and Colorado (passed 2026) both require that a licensed clinician or physician review any denial based even partly on medical necessity before AI can be involved. Several other states have passed narrower AI-disclosure or partial-restriction laws in 2026.
Has any APAC or Gulf regulator issued an equivalent binding requirement? Not yet, based on the record available at time of writing. Hong Kong's revised customer-treatment guideline (effective March 2026), India's IRDAI AI working group (formed June 2026), and the UAE Central Bank's AI guidance (published February 2026) are all real but are either non-binding, not claims-specific, or still in the recommendation stage.
Reference List
ArentFox Schiff (2026) Federal Court Orders Broad Discovery Against UHC in AI Coverage Denial Lawsuit. Available at: https://www.afslaw.com/perspectives/alerts/federal-court-orders-broad-discovery-against-uhc-ai-coverage-denial-lawsuit (Accessed: 8 October 2026).
Becker's Payer Issues (2026) 7 AI health insurance state laws passed in 2026. Available at: https://www.beckerspayer.com/policy-updates/7-ai-health-insurance-state-laws-passed-in-2026/ (Accessed: 8 October 2026).
Business Standard (2026) Irdai sets up working group to guide AI adoption in insurance sector. Available at: https://www.business-standard.com/finance/insurance/irdai-sets-up-working-group-to-guide-ai-adoption-in-insurance-sector-126061801084_1.html (Accessed: 8 October 2026).
Colorado General Assembly (2026) HB26-1139: Use of Artificial Intelligence in Health Care. Available at: https://leg.colorado.gov/bills/HB26-1139 (Accessed: 8 October 2026).
DLA Piper (2026) Insurance Authority of Hong Kong Issues Revised Guideline. Available at: https://dlapiper.com/en/insights/publications/2026/03/insurance-authority-of-hong-kong-issues-revised-guideline (Accessed: 8 October 2026).
Georgetown Health Care Litigation Tracker (2026) Estate of Gene B. Lokken et al. v. UnitedHealth Group Inc. et al. Available at: https://litigationtracker.law.georgetown.edu/litigation/estate-of-gene-b-lokken-the-et-al-v-unitedhealth-group-inc-et-al/ (Accessed: 8 October 2026).
Georgetown Health Care Litigation Tracker (2026) Kisting-Leung et al. v. Cigna Corporation et al. Available at: https://litigationtracker.law.georgetown.edu/litigation/kisting-leung-et-al-v-cigna-corporation-et-al/ (Accessed: 8 October 2026).
Healthcare Finance News (2023) UnitedHealth AI algorithm allegedly led to Medicare Advantage denials, lawsuit claims. Available at: https://www.healthcarefinancenews.com/news/unitedhealth-ai-algorithm-allegedly-led-medicare-advantage-denials-lawsuit-claims (Accessed: 8 October 2026).
InsuranceIndustry.ai (2026) Six Regulators, Six Answers: The AI Insurance Governance Map Nobody's Drawn. Available at: https://insuranceindustry.ai/six-regulators-six-answers-the-ai-insurance-governance-map-nobodys-drawn/ (Accessed: 8 October 2026).
National Association of Insurance Commissioners (NAIC) (2026) Legal Adoption Map: Use of Artificial Intelligence Systems by Insurers. Available at: https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf (Accessed: 8 October 2026).
Openlayer (2026) NAIC Model Bulletin: What Insurers Must Prepare for in July 2026. Available at: https://www.openlayer.com/blog/naic-model-bulletin-ai-governance (Accessed: 8 October 2026).
Pinsent Masons (2026) UAE Central Bank publishes responsible AI guidance for financial sector. Available at: https://www.pinsentmasons.com/out-law/news/uae-central-bank-responsible-ai-guidance-financial-sector (Accessed: 8 October 2026).
ProPublica (2023) Cigna PxDx: Medical Health Insurance Rejection Claims. Available at: https://www.propublica.org/article/cigna-pxdx-medical-health-insurance-rejection-claims (Accessed: 8 October 2026).
Tech Savvy Insurance (2026) Which states have adopted the NAIC AI Model Bulletin? Available at: https://techsavvyinsurance.com/answers/which-states-adopted-naic-ai-model-bulletin/ (Accessed: 8 October 2026).
Tressler LLP (2026) Estate of Gene B. Lokken, et al. v. UnitedHealth Group, Inc. - AI Risks in Medical Insurance Coverage Disputes. Available at: https://www.tresslerllp.com/thought-leadership/estate-of-gene-b-lokken-et-al-v-unitedhealth-group-inc-ai-risks-in-medical-insurance-coverage-disputes/ (Accessed: 8 October 2026).
Washington State Senate Democrats (2026) Orwall bill to improve prior authorization transparency signed into law. Available at: https://senatedemocrats.wa.gov/orwall/2026/03/25/orwall-bill-to-improve-prior-authorization-transparency-signed-into-law/ (Accessed: 8 October 2026).