A business built on discriminating
Here is the tension that makes insurance regulation unlike any other AI domain. Insurance is a business whose core function is discrimination, in the literal, neutral sense: distinguishing between risks and charging them differently. Lesson 1 showed why it must. Adverse selection punishes an insurer that fails to separate risks, so risk classification is not an abuse of the model, it is the model.
At the same time, the law forbids unfair discrimination: distinguishing on the basis of protected characteristics such as race, or on grounds with no legitimate actuarial basis.
So insurance regulation does not ask "is this model discriminating?" It obviously is. It asks a harder question: is this distinction one the law permits? The traditional answer is the principle of actuarial justification, a rating factor is permissible if it genuinely predicts loss and is not a prohibited characteristic. Charging more for a sports car than a minivan is fine; charging more by race is not, no matter what the data says.
That framework worked reasonably well when models had a dozen hand-chosen variables an actuary could defend one at a time. Modern AI breaks it, not by being evil, but by being complicated, and the rest of this lesson is about how regulators responded.

