Topic

Governance and Vendors

An AI tool can reach customer records, confidential processes and decisions before anyone has approved that access.

Law checked through

Short Answer

Start with the proposed task and the information the tool can reach through uploads, integrations and account permissions. Compare the vendor’s binding terms with its product settings: a training opt-out alone does not settle retention, support access or subcontractor use. When the Texas Data Privacy and Security Act applies and the vendor acts as a processor, Business and Commerce Code § 541.104(b) specifies contract terms, and Business and Commerce Code § 541.104(a)(2) now expressly covers assistance with the security of personal data processed by an AI system. Trade secret protection separately depends on reasonable secrecy measures. TRAIGA gives a practical reason to keep records of testing and internal review: several of its defenses turn on how a violation was discovered and whether the business follows a recognized risk framework. The NIST AI Risk Management Framework is voluntary, but TRAIGA names its Generative AI Profile. The first step is to identify the actual use, the actor, the affected information and the source of the asserted duty. Keep the tool’s instructions, applicable terms and material settings with the approval record. A statute, a court order and a practical control have different legal effects. The Guides below explain those differences; the Tracker preserves the effective dates and the dated enforcement or litigation events. Related Insights cover individual developments without replacing the underlying Guide.

Key Authorities

Texas AI-specific

Business and Commerce Code § 552.105(c) and (e) (presumption of reasonable care; defenses).

Generally applicable Texas law

TDPSA, Business and Commerce Code § 541.002 and Business and Commerce Code § 541.104; Texas Uniform Trade Secrets Act, Civil Practice and Remedies Code § 134A.002(6); Uniform Electronic Transactions Act, Business and Commerce Code § 322.014; DTPA; Business Organizations Code duties of directors.

Federal

FTC Act sec. 5 where marketing claims are involved; NIST AI RMF (voluntary).

Guides

Before a Business Adopts an AI Tool

Identify the task, the information the service can reach, the binding vendor terms, and the person who may approve its output.

AI Vendor Contracts

The terms that matter in an AI services agreement, which ones Texas law requires, and how Texas courts read risk-shifting clauses.

AI Data Lifecycle and Minimization

What enters an AI system, what persists inside it and around it, and when it should leave.

AI Agents and Contract Formation

When software acts for a business, Texas law can treat its actions as the business’s own.

Board Oversight of AI

What directors of a Texas company should know and record about AI risk.

AI Governance Programs and the TRAIGA Defenses

Why testing, feedback channels and a recognized risk framework matter under Texas law, and what a workable program records.

Insights

AI Data Duties in Texas Processor Contracts

HB 149 added AI to a processor’s security assistance duty under the TDPSA. It did not add a new mandatory contract clause.

Related Reading