Topic

Governance and Vendors

An AI tool can reach customer records, confidential processes and decisions before anyone has approved that access.

Law checked through

Short Answer

Start with the proposed task and the information the tool can reach through uploads, integrations and account permissions. Compare the vendor’s binding terms with its product settings: a training opt-out alone does not settle retention, support access or subcontractor use. When the Texas Data Privacy and Security Act applies and the vendor acts as a processor, Business and Commerce Code § 541.104(b) specifies contract terms, and Business and Commerce Code § 541.104(a)(2) now expressly covers assistance with the security of personal data processed by an AI system. Trade secret protection separately depends on reasonable secrecy measures. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) gives a practical reason to keep records of testing and internal review: several of its defenses turn on how a violation was discovered and whether the business follows a recognized risk framework. The National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) is voluntary, but TRAIGA names its Generative AI Profile.

Key Authorities

Texas AI-specific

Business and Commerce Code § 552.105(c) and (e) (presumption of reasonable care; defenses).

Generally applicable Texas law

TDPSA, Business and Commerce Code § 541.002 and Business and Commerce Code § 541.104; Texas Uniform Trade Secrets Act, Civil Practice and Remedies Code § 134A.002(6); Uniform Electronic Transactions Act, Business and Commerce Code § 322.014; Deceptive Trade Practices-Consumer Protection Act (DTPA); Business Organizations Code duties of directors.

Federal

Federal Trade Commission (FTC) Act § 5 where marketing claims are involved; NIST AI RMF (voluntary).

Guides

Before a Business Adopts an AI Tool

Identify the task, the information the service can reach, the binding vendor terms, and the person who may approve its output.

AI Vendor Contracts

The terms that matter in an AI services agreement, which ones Texas law requires, and how Texas courts read risk-shifting clauses.

AI Data Lifecycle and Minimization

What enters an AI system, what persists inside it and around it, and when it should leave.

AI Agents and Contract Formation

When software acts for a business, Texas law can treat its actions as the business’s own.

Board Oversight of AI

What directors of a Texas company should know and record about AI risk.

AI Governance Programs and the TRAIGA Defenses

Why testing, feedback channels and a recognized risk framework matter under Texas law, and what a workable program records.

AI in Healthcare under Texas Law

What Texas requires when AI touches patients: the Attorney General's enforcement record on accuracy claims, TRAIGA's disclosure duties, and the consumer protection rules that were already in place.

Insights

AI Data Duties in Texas Processor Contracts

HB 149 added AI to a processor’s security assistance duty under the Texas Data Privacy and Security Act (TDPSA). It did not add a new mandatory contract clause.

Related Reading