Guide

AI Security Incidents and Breach Notification

When an AI system leaks or exposes data, Texas’s ordinary breach rules apply, and the clock starts when the business determines a breach occurred.

Law checked through

Short Answer

An AI incident can be a breach of system security when it involves unauthorized acquisition of computerized data compromising sensitive personal information. Business and Commerce Code § 521.053 governs that determination and the notices. Not every wrong output or exposed business document is a statutory personal-data breach. A covered breach triggers individual notice without unreasonable delay and generally within 60 days after determination, and AG notice as soon as practicable and within 30 days when at least 250 Texas residents are affected. Vendor escalation, other laws and a legal hold can require action sooner.

Which Laws Apply

Texas AI-specific: Business and Commerce Code § 541.104(a)(2); Business and Commerce Code § 552.105(e)(2) (testing defense under TRAIGA).

Generally applicable Texas law: Business and Commerce Code § 521.052 (reasonable procedures) and Business and Commerce Code § 521.053 (notification).

Federal: HIPAA Breach Notification Rule; GLBA Safeguards Rule; SEC incident disclosure for public companies; FTC Act.

What Counts as a Breach

Texas notice duties apply to a breach of system security involving sensitive personal information, which generally means a name combined with a Social Security number, driver’s license or government ID number, or financial account information with access codes, and also health information that identifies a person. An AI incident triggers the statute only if it involves that kind of data and unauthorized acquisition. Exposure of other confidential information, such as trade secrets, can be a serious incident without being a notifiable breach.

Notice Timeline

AI-Specific Failure Points

Prompt injection. Instructions hidden in a document, email or webpage cause an AI assistant to reveal data it can access.

Over-broad access. An assistant connected to mailboxes or file stores can surface records to users who should not see them.

Vendor retention and logs. Prompts containing personal data stored in vendor logs become part of the vendor’s attack surface.

Model leakage. Models trained on personal data can sometimes reproduce it.

Each is a reason to limit what an AI system can reach, to test it adversarially and to keep logs that show what it accessed. Testing records serve two purposes in Texas: security and TRAIGA’s defense for violations discovered through testing (Business and Commerce Code § 552.105(e)(2)).

Illustrative Example (Hypothetical)

A Texas law firm’s AI assistant, connected to its document system, is tricked by a document from opposing counsel into summarizing another client’s file in a response sent outside the firm. If the file contained clients’ Social Security numbers, the firm must assess whether unauthorized acquisition occurred and, if so, start the 60-day and 30-day clocks. The firm also has professional duties of confidentiality under Texas Disciplinary Rule 1.05.

What Is Unsettled

When a business “determines” that an AI-caused exposure is a breach when logs are incomplete; whether model memorization of personal data is a breach.

Sources

Related Reading