The most important lesson in Christopher M. Jacobs’s new Defending the Algorithm essay is not the proposed “human-in-the-loop” checklist. It is that an insurer using AI to value, route, flag, or communicate about a claim must be able to reconstruct the decision later — and the article’s own treatment of Colossus shows why. The record supports the broader warning, but it also exposes a factual problem that claim leaders, legal teams, and IT administrators should not carry into policy or litigation strategy uncorrected.
Published by JD Supra on August 4, Jacobs’s article traces insurance automation from Computer Sciences Corporation’s Colossus bodily-injury valuation software to current computer-vision, predictive, fraud-detection, and generative-AI tools. It argues that the duty of good-faith claims handling remains with the carrier even when software supplies an estimate, a risk score, or a draft coverage letter. That central conclusion is sound and increasingly reflected in state insurance oversight.
But “From Colossus to ChatGPT” is more useful as a warning about records management and accountability than as a settled map of AI case law. Its biggest practical gap is that it invokes ChatGPT in the title while providing no evidence that ChatGPT itself is being deployed to make claims decisions, nor any specific carrier implementation, product configuration, or documented loss outcome. The article describes possible uses of generative text systems; it does not establish a ChatGPT claims-handling event.
Colossus remains the most relevant historical analogy because the controversy was never simply that insurers used software. The allegation was that a supposedly neutral valuation tool could become a mechanism for systematically narrowing settlements, especially if adjusters were pressured to accept outputs they could not meaningfully interrogate.
The Arkansas litigation cited in the essay, Hensley v. Computer Sciences Corporation, was filed in 2005 as a putative nationwide class action involving CSC, other software vendors, and numerous insurers. Court records show allegations that the defendants used claims software including Colossus to reduce bodily-injury claim payments and concealed aspects of how it worked. CSC denied wrongdoing.
The article says the “most notable” action culminated in a national class-action settlement “approved in 2005.” That date does not hold up. The federal docket shows active proceedings in late 2005, while reporting on CSC’s separate settlement places that agreement in 2009. CSC’s own 2009 annual report also described the litigation and settlement discussions. The discrepancy matters because it changes the history from a quick 2005 resolution into a multi-year fight over software transparency, discovery, and insurer practices.
That is not a trivial editorial correction. For today’s AI governance teams, the longer chronology is the point: when a claims platform becomes disputed, the litigation timeline can outlast several model releases, vendor upgrades, data-retention cycles, and personnel changes. A carrier that cannot preserve the version of the tool used on the date of a disputed decision may be unable to explain what actually happened, even if its current platform works differently.
The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023. The bulletin does not prohibit AI-assisted insurance decisions. Instead, it tells insurers that decisions or actions supported by AI remain subject to insurance law, including unfair-trade-practice and unfair-discrimination rules. It also sets expectations for a written AI-systems program, governance, risk management, internal controls, and documentation regulators may request in an examination or investigation.
The NAIC’s own survey results make one assertion in the article look dated: it says relatively few insurers use AI in live claim environments. The NAIC reports widespread AI or machine-learning use, planned use, or exploration across responding auto, homeowners, life, and health insurers. Those figures cover insurer operations generally rather than claim adjudication alone, so they do not prove every carrier is letting a model estimate property damage or triage fraud. They do show that the issue is no longer confined to a handful of experimental deployments.
Colorado has moved further than a generic policy statement. Its amended Regulation 10-1-1, effective October 15, 2025, imposes governance and risk-management obligations on life, private-passenger auto, and health-benefit insurers using external consumer data, algorithms, and predictive models in insurance practices. The regulation is principally aimed at preventing unfair discrimination and requires documented cross-functional governance, testing, monitoring, and remediation. That is an important distinction from the article’s claims-centered framing: the regulatory pressure extends beyond a final claim payment or denial and reaches the systems that support insurance decisions throughout the business.
For IT professionals, this means AI governance cannot live only in the claims department. The systems of record may span vendor SaaS portals, document-management repositories, data warehouses, Microsoft 365 communications, image-upload tools, identity platforms, and model-monitoring services. A policy that says “an adjuster reviews the output” is inadequate if no one can later identify the model version, input files, prompt template, confidence score, override, or human rationale.
The minimum defensible evidence package for an AI-influenced claim should include:
The article overstates one case in this area. It cites In re State Farm Lloyds as a 2020 Texas Supreme Court decision about electronic claim-handling databases and the calculation of loss values. The cited decision is actually a 2017 Texas Supreme Court electronic-discovery case. It addressed proportionality and the formats for producing electronically stored information in hail-damage litigation; it was not an AI-explainability ruling, and it did not establish a broad rule that insurers must disclose an algorithm’s internal logic whenever software helps calculate a loss value.
That correction does not weaken the article’s advice. It sharpens it. There is no settled nationwide judicial rule compelling disclosure of every AI model’s source code in an insurance dispute. There is, however, a predictable discovery fight over what information is relevant and proportional when an insurer relied on software in making a decision. A carrier that has preserved a clear claim-specific audit trail enters that dispute with far better facts than one trying to reconstruct a black-box process from scattered logs.
Still, forensic detection tools should be treated as investigative leads, not as automatic proof of fraud. Image detectors can produce false positives, metadata can be missing for innocent reasons, and photos may be edited through conventional tools rather than generative models. The same discipline that applies to an AI-generated estimate applies to an AI-generated fraud flag: preserve the original artifact, document the system result, independently verify the facts, and ensure a person makes and explains the consequential decision.
For organizations running Windows-based claims operations, the immediate control is mundane but valuable: preserve originals separately from transformed copies, restrict who can overwrite claim attachments, collect audit logs across file shares and collaboration systems, and ensure retention policies do not silently purge decision records while a dispute is reasonably foreseeable. An attractive dashboard is not evidence. Immutable timestamps, access logs, version history, and reproducible exports are.
Insurance carriers do not need to wait for a court to issue an “AI claims” rule. The NAIC model bulletin and state-level requirements already make governance, testing, documentation, and vendor oversight immediate compliance work. The Colossus precedent adds the harder historical lesson: a human override button is meaningless if production quotas, workflow design, or management incentives make the algorithm’s recommendation functionally mandatory.
The practical test is simple. If a claimant challenges a valuation, fraud referral, coverage letter, or payment delay years from now, the carrier should be able to show the exact system used, the information it saw, its output, the human reviewer’s independent reasoning, and the controls in place at the time. Without that record, “AI-assisted” will read less like efficiency and more like an unexplained delegation of responsibility.
But “From Colossus to ChatGPT” is more useful as a warning about records management and accountability than as a settled map of AI case law. Its biggest practical gap is that it invokes ChatGPT in the title while providing no evidence that ChatGPT itself is being deployed to make claims decisions, nor any specific carrier implementation, product configuration, or documented loss outcome. The article describes possible uses of generative text systems; it does not establish a ChatGPT claims-handling event.
Colossus is the right precedent, but the timeline needs correction
Colossus remains the most relevant historical analogy because the controversy was never simply that insurers used software. The allegation was that a supposedly neutral valuation tool could become a mechanism for systematically narrowing settlements, especially if adjusters were pressured to accept outputs they could not meaningfully interrogate.The Arkansas litigation cited in the essay, Hensley v. Computer Sciences Corporation, was filed in 2005 as a putative nationwide class action involving CSC, other software vendors, and numerous insurers. Court records show allegations that the defendants used claims software including Colossus to reduce bodily-injury claim payments and concealed aspects of how it worked. CSC denied wrongdoing.
The article says the “most notable” action culminated in a national class-action settlement “approved in 2005.” That date does not hold up. The federal docket shows active proceedings in late 2005, while reporting on CSC’s separate settlement places that agreement in 2009. CSC’s own 2009 annual report also described the litigation and settlement discussions. The discrepancy matters because it changes the history from a quick 2005 resolution into a multi-year fight over software transparency, discovery, and insurer practices.
That is not a trivial editorial correction. For today’s AI governance teams, the longer chronology is the point: when a claims platform becomes disputed, the litigation timeline can outlast several model releases, vendor upgrades, data-retention cycles, and personnel changes. A carrier that cannot preserve the version of the tool used on the date of a disputed decision may be unable to explain what actually happened, even if its current platform works differently.
The current regulatory record is more concrete than the article suggests
Jacobs correctly argues that insurers cannot outsource their good-faith obligations to an opaque model. State regulators are already treating that as an operational compliance issue rather than a distant theoretical concern.The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023. The bulletin does not prohibit AI-assisted insurance decisions. Instead, it tells insurers that decisions or actions supported by AI remain subject to insurance law, including unfair-trade-practice and unfair-discrimination rules. It also sets expectations for a written AI-systems program, governance, risk management, internal controls, and documentation regulators may request in an examination or investigation.
The NAIC’s own survey results make one assertion in the article look dated: it says relatively few insurers use AI in live claim environments. The NAIC reports widespread AI or machine-learning use, planned use, or exploration across responding auto, homeowners, life, and health insurers. Those figures cover insurer operations generally rather than claim adjudication alone, so they do not prove every carrier is letting a model estimate property damage or triage fraud. They do show that the issue is no longer confined to a handful of experimental deployments.
Colorado has moved further than a generic policy statement. Its amended Regulation 10-1-1, effective October 15, 2025, imposes governance and risk-management obligations on life, private-passenger auto, and health-benefit insurers using external consumer data, algorithms, and predictive models in insurance practices. The regulation is principally aimed at preventing unfair discrimination and requires documented cross-functional governance, testing, monitoring, and remediation. That is an important distinction from the article’s claims-centered framing: the regulatory pressure extends beyond a final claim payment or denial and reaches the systems that support insurance decisions throughout the business.
For IT professionals, this means AI governance cannot live only in the claims department. The systems of record may span vendor SaaS portals, document-management repositories, data warehouses, Microsoft 365 communications, image-upload tools, identity platforms, and model-monitoring services. A policy that says “an adjuster reviews the output” is inadequate if no one can later identify the model version, input files, prompt template, confidence score, override, or human rationale.
Discovery will focus on the chain of custody, not a magic source-code reveal
The article is strongest when it treats preservation as an engineering problem. Machine-learning systems change. Generative-AI tools can change more often still, particularly if a vendor modifies a hosted model, retrieval layer, safety setting, prompt library, or image-analysis pipeline. A claim record that preserves only the final estimate or letter may omit the information needed to show whether that output was reasonable.The minimum defensible evidence package for an AI-influenced claim should include:
- The exact source inputs, including original photos, uploaded documents, structured claim data, and relevant metadata.
- The model, rules-engine, or vendor-service version that processed the claim, along with configuration settings and timestamps.
- The complete output delivered to the adjuster, including scores, suggested estimates, explanations, and any system warnings.
- The human review record showing what the adjuster accepted, changed, rejected, or escalated and why.
- The retention history showing whether a later update altered the tool, its training corpus, its calibration, or its output format.
The article overstates one case in this area. It cites In re State Farm Lloyds as a 2020 Texas Supreme Court decision about electronic claim-handling databases and the calculation of loss values. The cited decision is actually a 2017 Texas Supreme Court electronic-discovery case. It addressed proportionality and the formats for producing electronically stored information in hail-damage litigation; it was not an AI-explainability ruling, and it did not establish a broad rule that insurers must disclose an algorithm’s internal logic whenever software helps calculate a loss value.
That correction does not weaken the article’s advice. It sharpens it. There is no settled nationwide judicial rule compelling disclosure of every AI model’s source code in an insurance dispute. There is, however, a predictable discovery fight over what information is relevant and proportional when an insurer relied on software in making a decision. A carrier that has preserved a clear claim-specific audit trail enters that dispute with far better facts than one trying to reconstruct a black-box process from scattered logs.
AI fraud creates a second evidentiary problem
The article’s discussion of fabricated damage photographs is not speculative. The National Insurance Crime Bureau warned in 2024 that generative AI could support insurance fraud by producing fake documents and images, including images depicting vehicle and property damage. Zurich UK and other insurers have also publicly warned about manipulated or synthetic evidence in claims.Still, forensic detection tools should be treated as investigative leads, not as automatic proof of fraud. Image detectors can produce false positives, metadata can be missing for innocent reasons, and photos may be edited through conventional tools rather than generative models. The same discipline that applies to an AI-generated estimate applies to an AI-generated fraud flag: preserve the original artifact, document the system result, independently verify the facts, and ensure a person makes and explains the consequential decision.
For organizations running Windows-based claims operations, the immediate control is mundane but valuable: preserve originals separately from transformed copies, restrict who can overwrite claim attachments, collect audit logs across file shares and collaboration systems, and ensure retention policies do not silently purge decision records while a dispute is reasonably foreseeable. An attractive dashboard is not evidence. Immutable timestamps, access logs, version history, and reproducible exports are.
The defensible position is decision support, with proof
Jacobs’s most durable conclusion is that AI should support an adjuster rather than silently become one. The legal authorities discussed in the article, including Pennsylvania’s Rancosky bad-faith decision and Wisconsin’s State v. Loomis decision involving a proprietary criminal-risk assessment tool, arise in different settings and do not create a dedicated insurance-AI doctrine. But they point toward a familiar result: courts scrutinize whether a party relied reasonably on a process affecting individual rights and whether the decision-maker can articulate the basis for the outcome.Insurance carriers do not need to wait for a court to issue an “AI claims” rule. The NAIC model bulletin and state-level requirements already make governance, testing, documentation, and vendor oversight immediate compliance work. The Colossus precedent adds the harder historical lesson: a human override button is meaningless if production quotas, workflow design, or management incentives make the algorithm’s recommendation functionally mandatory.
The practical test is simple. If a claimant challenges a valuation, fraud referral, coverage letter, or payment delay years from now, the carrier should be able to show the exact system used, the information it saw, its output, the human reviewer’s independent reasoning, and the controls in place at the time. Without that record, “AI-assisted” will read less like efficiency and more like an unexplained delegation of responsibility.
References
- Primary source: JD Supra
Published: 2026-08-04T16:40:40.026419
From Colossus to ChatGPT: Artificial Intelligence in Modern Claim Handling — Efficiency, Explainability, and Exposure | Houston Harbaugh, P.C. - JDSupra
I. Introduction and Historical Context - The integration of artificial intelligence into the insurance industry has not occurred in a si...www.jdsupra.com - Related coverage: legalnewsline.com
CSC settles out of Colossus class action
www.legalnewsline.com
- Related coverage: jdsupra.com
Artificial Intelligence Quarterly Update | Herbert Smith Freehills Kramer - JDSupra
In this quarterly update, we review the latest developments in three subjects salient to corporate use of artificial intelligence (AI). First, we...www.jdsupra.com - Related coverage: content.naic.org
Insurance Topics | Artificial Intelligence | NAIC
Discover the impact of AI in insurance, from underwriting to customer service. Learn about AI's role in claims processing, big data utilization, and the future of risk management.
content.naic.org
- Related coverage: content.naic.org
- Related coverage: americanbar.org
AI Legal Updates in the Insurance Industry
Many jurisdictions have adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and AI-related legislation is being introduced across the country.www.americanbar.org
- Related coverage: tomshardware.com
Major insurers move to avoid liability for AI lawsuits as multi-billion dollar risks emerge — Recent public incidents have lead to costly repercussions | Tom's Hardware
Major insurers seek permission to exclude AI-related claims from corporate policies.www.tomshardware.com - Related coverage: debevoise.com
Use of AI-Generated Images for Fake Insurance Claims and Other Frauds
PDF documentwww.debevoise.com
- Related coverage: axios.com
Colorado lawmakers introduce new AI rules - Axios Denver
State lawmakers plan to scrap their first-in-the-nation AI law.www.axios.com