AI in prior authorization: the 2026 laws putting a licensed human back in the loop.
Health plans have quietly used automation to triage prior-authorization requests for years. In 2026 a cluster of states drew a line: an algorithm may help, but a qualified human, not software alone, has to own any denial based on medical necessity.
What changed in 2026
The trend started with California’s SB 1120, the “Physicians Make Decisions Act,” in force since January 1, 2025. It requires that when a plan uses AI in utilization review, the tool draws on the patient’s own clinical history, does not supplant the clinician, and that the final medical-necessity determination is made by a licensed physician or other qualified professional.
2026 turned that single statute into a pattern. Washington’s SB 5395 took effect June 11, 2026 and is among the most detailed: only a licensed physician or health professional acting within their scope may deny a prior-authorization request on medical-necessity grounds, and carriers must not rely solely on AI to make that call. Comparable measures passed in Alabama, Georgia, Indiana (effective July 1, 2026), Maryland (effective June 1, 2026), and Utah. The specifics differ, but the through-line is the same.
What the laws actually require
Three obligations recur. First, human ownership: a licensed clinician must make or personally stand behind any medical-necessity denial. Second, individualized review: Washington, for example, directs the human reviewer to weigh the requesting provider’s recommendation, the enrollee’s medical history, and their specific clinical circumstances, not just a model’s output. Third, disclosure: when a denial is issued, the carrier must identify the credentials, board certifications, and specialty of the clinician who exercised oversight, to both the patient and the requesting provider.
Notice what these laws do not do. They do not ban AI in utilization review. They permit the tool to assist, they simply require that a licensed human, applying the individual’s facts, remains accountable for the outcome.
Who this reaches, and the federal layer
The direct targets are health carriers, health-care benefit managers, and public employee health plans. But the practical burden lands on the vendors selling AI utilization-review tools, because their systems now have to support, and evidence, a genuine human review step rather than an automated decision dressed up as one.
A federal layer is arriving alongside the states. Beginning in 2026, CMS requires payers to give a specific reason for every AI-assisted denial and to publish aggregate approval data, and its broader prior-authorization rule shortens decision timelines (72 hours for expedited requests, seven calendar days for standard ones). Separately, CMS is testing an AI-assisted prior-authorization model in Original Medicare beginning January 2026; the details of that pilot are still developing, so treat any specifics as provisional and confirm against CMS guidance before acting.
What to do now
If your organization builds, buys, or operates AI in coverage or utilization decisions, the compliance question is no longer “is the model accurate?” It is “can you prove a licensed human owned the decision, saw the individual’s facts, and is on the record?” That is an evidence problem, and evidence has to be designed in, not reconstructed after a complaint.
Concrete steps
- Map where AI touches a coverage or medical-necessity decision, intake triage, scoring, recommendation, and final determination are different roles with different exposure.
- Verify a licensed human owns every medical-necessity denial, and that the system logs who reviewed it, their credentials, and that they saw the individual’s clinical facts.
- Wire the disclosure in: denials should automatically carry the reviewing clinician’s credentials, board certification, and specialty to patient and provider.
- Keep an audit trail that shows the AI assisted rather than decided, the record is your defense if a determination is challenged.
- Track the map by state and by CMS: obligations and effective dates differ, and the CMS pilot is still moving.
These laws reward the same thing across every jurisdiction: a documented, individualized, human-owned decision. Build the record once and it holds up wherever the request comes from.
This briefing is general information from Sentinel Assurance Group, not legal or medical advice. Regulatory dates and requirements change, and the CMS prior-authorization pilot is still developing, so verify against primary sources and counsel before acting. Last reviewed July 10, 2026.
See how the Sentinel Control Map works →Not sure where AI touches your decisions?
Find out in 30 minutes.
The free AI Risk Exposure call maps your AI footprint to the obligations that actually apply, and the ones that don’t.
Book the call →