Guide

AI Security Incidents and Breach Notification

When an AI system leaks or exposes data, Texas’s ordinary breach rules apply, and the clock starts when the business determines a breach occurred.

Law checked through

Short Answer

An AI incident can be a breach of system security when it involves unauthorized acquisition of computerized data compromising sensitive personal information. Business and Commerce Code § 521.053 governs that determination and the notices. Not every wrong output or exposed business document is a statutory personal-data breach. A covered breach triggers individual notice without unreasonable delay and generally within 60 days after determination, and AG notice as soon as practicable and within 30 days when at least 250 Texas residents are affected. Vendor escalation, other laws and a legal hold can require action sooner.

Which Laws Apply

Texas AI-specific: Business and Commerce Code § 541.104(a)(2); Business and Commerce Code § 552.105(e)(2) (testing defense under the Texas Responsible Artificial Intelligence Governance Act (TRAIGA)).

Generally applicable Texas law: Business and Commerce Code § 521.052 (reasonable procedures) and Business and Commerce Code § 521.053 (notification).

Federal: Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule; Gramm-Leach-Bliley Act (GLBA) Safeguards Rule; SEC incident disclosure for public companies; Federal Trade Commission (FTC) Act.

What Counts as a Breach

Texas notice duties apply to a breach of system security involving sensitive personal information, which generally means a name combined with a Social Security number, driver’s license or government ID number, or financial account information with access codes, and also health information that identifies a person. An AI incident triggers the statute only if it involves that kind of data and unauthorized acquisition. Exposure of other confidential information, such as trade secrets, can be a serious incident without being a notifiable breach.

Notice Timeline

The statute assigns different notice duties to different recipients:

Individual and maintainer notices under subsections (b) and (c) may be delayed at the request of a law enforcement agency while the agency determines that notification will impede a criminal investigation (subsection (d)).

WhoWhenWhat
Affected individualsWithout unreasonable delay, and no later than the 60th day after the person determines the breach occurredDisclosure of the breach to each individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person (§ 521.053(b))
The Attorney GeneralAs soon as practicable and no later than the 30th day after the determination, when the breach involves at least 250 Texas residentsElectronic notice through the Attorney General’s website form with the required contents (§ 521.053(i))
Consumer reporting agenciesWithout unreasonable delayNotice of the timing, distribution and content of the notices, when more than 10,000 persons must be notified at one time (§ 521.053(h))
A business that maintains computerized data for its ownerImmediately after discovering the breachNotice to the owner or license holder of the information (§ 521.053(c))

AI-Specific Failure Points

Prompt injection. Instructions hidden in a document, email or webpage cause an AI assistant to reveal data it can access.

Over-broad access. An assistant connected to mailboxes or file stores can surface records to users who should not see them.

Vendor retention and logs. Prompts containing personal data stored in vendor logs become part of the vendor’s attack surface.

Model leakage. Models trained on personal data can sometimes reproduce it.

Each is a reason to limit what an AI system can reach, to test it adversarially and to keep logs that show what it accessed. Testing records serve two purposes in Texas: security and TRAIGA’s defense for violations discovered through testing (Business and Commerce Code § 552.105(e)(2)).

Illustrative Example (Hypothetical)

A Texas law firm’s AI assistant, connected to its document system, is tricked by a document from opposing counsel into summarizing another client’s file in a response sent outside the firm. If the file contained client names with Social Security numbers, the firm has the elements of sensitive personal information, so it must assess whether unauthorized acquisition occurred. If the firm determines that a covered breach occurred, it must give individual notice without unreasonable delay and no later than 60 days after that determination, subject to the statutory law-enforcement-delay exception. The Attorney General notice clock (as soon as practicable and no later than 30 days) applies only if the breach involves at least 250 Texas residents, and the nationwide consumer reporting agency notice applies only if more than 10,000 persons are notified at one time. The firm also has professional duties of confidentiality under Texas Disciplinary Rule 1.05.

What Is Unsettled

When a business “determines” that an AI-caused exposure is a breach when logs are incomplete; whether model memorization of personal data is a breach.

Sources