Insights/Responsible AI

Texas AI Law Is Already Here. Most North Texas Companies Still Cannot Name the AI Systems They Use

Published July 19, 2026Updated July 20, 2026

In Brief

  • The Texas Responsible Artificial Intelligence Governance Act took effect January 1, 2026, and the Attorney General's AI complaint intake is already open — ahead of the September 1, 2026 statutory deadline.
  • The law does not require most private companies to keep an AI inventory. It does specify what the state can ask a company to describe about a system it operates. Those are different obligations with the same practical consequence.
  • The organizations that struggle will not be the ones using AI aggressively. They will be the ones that cannot say, on a Tuesday afternoon, which systems they run, who approved them, what data those systems receive, and which decisions they shape.

Executive Summary

Six months into the Texas AI law, the useful executive question is not "are we compliant?" It is narrower and considerably more uncomfortable: can you produce a list?

Most North Texas companies cannot — not from carelessness, but because artificial intelligence did not enter the enterprise through the door that generates records. Very little of it was purchased. Most arrived as a feature inside software the company already licensed, as an account an employee opened in ninety seconds, or as a capability a service provider adopted on the company's behalf without mentioning it. Traditional IT inventory is built on what you bought and what you installed. AI defeats both tests.

That gap now has a deadline that does not depend on anyone's roadmap. Under the act, the Attorney General can issue a civil investigative demand and ask a company to describe a system's purpose, its inputs and outputs, the data used to build it, the metrics used to evaluate it, its known limitations, and the monitoring around it. That is not a compliance framework. It is a list of questions. A company with the answers has a filing exercise. A company without them has a discovery project running against a legal clock.

The response is not a policy document. Policies describe intent. What executives need is a record of reality — a per-system account of what runs, who owns it, what it touches, and what it decides.

The Direct Answer

What does the Texas AI law require, and why does an inventory matter if the law does not mandate one?

For most private businesses, the enacted law is narrower than the headlines suggested. It prohibits developing or deploying AI with intent to incite self-harm or crime, to unlawfully discriminate against a protected class, to impair constitutional rights, or to produce illegal sexual material and deepfakes. Its affirmative disclosure duties fall principally on governmental agencies and on health care providers, who must tell patients when AI is used in their care. There is no high-risk classification scheme for private deployers, no mandatory impact assessment, and no private right of action.

The inventory matters anyway, for three reasons unrelated to whether a duty is written down. The statute defines what the Attorney General may demand a company describe, and those demands are descriptive — purpose, data, outputs, monitoring — so the ability to answer is the ability to respond. The law then gives an accused party sixty days to cure, and curing requires documentation showing how the violation was fixed and what policy changed; an organization that cannot identify the system cannot cure inside the window. And the statute rewards documented diligence directly, through a rebuttable presumption of reasonable care and favorable treatment for substantial compliance with a recognized AI risk management framework paired with internal review.

Texas did not order you to keep a register. It told you what it will ask you to describe, gave you sixty days to prove you fixed anything you got wrong, and made your documentation part of your defense. Companies reading that as "no requirement" have read the first clause and stopped.

What Changed on January 1 — and What Did Not

Three details deserve attention because they are routinely misreported.

The statutory definition of an AI system is deliberately wide. It covers any machine-based system that infers from its inputs how to generate outputs — content, decisions, predictions, or recommendations — capable of influencing physical or virtual environments. That does not describe chatbots. It describes the scoring model inside your applicant tracking system, the routing logic in your service desk, the anomaly detection in your payment stack, and the forecasting module finance enabled last quarter.

Reach is defined by market, not address. The law applies to a person who conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in the state. A company headquartered in Illinois with customers in Plano is inside the perimeter. Local rules are preempted, so Dallas, Fort Worth, Richardson, and every other North Texas municipality operate under one standard rather than a patchwork — which removes the excuse that the rules are too fragmented to plan against.

One further detail is instructive rather than binding. The same act amended the Government Code to require state agencies to inventory their own AI systems and report their use of them. The state wrote an inventory requirement for itself and did not extend it to private companies. Executives are reading that omission as relief. It is closer to a preview of what "reasonable" will come to mean.

What Is Actually at Stake

Business issue

Why it matters now

Operational risk

Leadership action

No list of AI systems in use

The state's questions are descriptive; answers require a record

Cannot respond to an inquiry, questionnaire, or insurer within a reasonable window

Commission a register, not a policy

AI arriving through product updates

No purchase, no security review, no record

Capabilities in production that no one authorized

Add a review trigger for vendor feature releases

Sensitive data entered without rules

Confidentiality and contractual commitments turn on it

Irreversible disclosure through routine work

Define approved and prohibited data per system

No named owner per system

Accountability defaults upward, then nowhere

No one able to answer for a system under pressure

Assign a business owner, not a ticket queue

Decisions influenced but not documented

Cure requires knowing what to fix

Sixty-day window spent on discovery

Map systems to the decisions they touch

Service providers using AI for you

Your obligations do not transfer with the work

Exposure sitting entirely outside your environment

Ask the question in writing at renewal

Four Doors, and Only One Leaves a Record

Competent organizations fail this exercise for structural reasons. AI does not enter through a single channel, and three of the four bypass every mechanism built to track what a company owns.

How it arrived

What it leaves behind

Why inventory misses it

Where to look first

Purchased outright

Contract, invoice, security review

It does not — this path usually works

Procurement and vendor files

Added to software you already license

A release note

No purchase, no new vendor, no trigger for review

Admin consoles and feature-release histories

Signed up by an individual

A browser session; sometimes an SSO entry

Nothing to install, nothing to approve

Identity logs, expense reports, network egress

Adopted by a service provider

Nothing inside your environment at all

Not your system, but your data and your obligation

Contracts, renewals, direct questions

The third-party path is the one executives find genuinely surprising. When a payroll processor, staffing agency, collections firm, or marketing partner adopts AI, your data and reputational exposure move with them while your visibility stays at zero. There is no log to check — only a question someone has to think to ask.

The second path deserves its own name, because "shadow AI" does not describe it. Shadow AI implies an employee acting outside the rules. What happens far more often is that a vendor ships a capability into a product approved years ago. Nobody circumvented anything. The software the company said yes to in 2023 is not the software running today, and the yes was never revisited. Metro Relay's analysis of shadow AI addresses employee-initiated adoption; this is the quieter and usually larger category beside it.

The Question That Separates a Tool List From a Register

Most organizations attempting an AI inventory produce a list of software. That is a start, and it is not the thing that matters.

Two companies can license identical tools and carry entirely different exposure, because exposure does not track the tool. It tracks the decision. A model summarizing meeting notes and the same model drafting adverse-action language for a declined applicant are the same product and completely different problems. An inventory answering "what do we have?" tells leadership almost nothing. A register answering "what does it influence?" tells leadership where to look.

Organize the record around decisions and data, not vendors and logins. When a regulator, a health system's procurement team, or a cyber insurer asks what a system does, none of them is asking for a product name.

Common Misconceptions

"We have an AI policy, so we're covered." A policy states what should happen; a register states what is happening. Under pressure — an inquiry, an incident, a customer audit — nobody asks for the policy first.

"We don't really use AI." Almost every organization saying this licenses software meeting the statutory definition. The systems were not adopted; they were inherited. That does not change the analysis.

"There's a human in the loop." Human review that cannot be evidenced is indistinguishable from no review. If someone overrides a recommendation and nothing records it, the control exists in practice and vanishes on paper.

"Free tools are lower risk." They are usually higher risk. A free or personal account has no negotiated contract, no data-processing terms, no administrative visibility, and no offboarding path when the employee leaves. The absence of a bill is the absence of a relationship.

"The law requires impact assessments for high-risk systems." It does not. That framework was in an earlier draft and removed before passage, yet several widely circulated compliance summaries still describe the bill that did not become law. Verify against the enacted text, and consult counsel on interpretation.

The Metro Relay AI System Accountability Register

This is Metro Relay's operational framework — not a statutory checklist, not a certification. Its purpose is narrow: to make an organization able to describe itself accurately, one system at a time.

Field

The question it answers

Sufficient evidence

The gap we expect to find

System

What is it, and where does it run?

Named entry with platform, environment, access path

AI inside a platform logged only as the platform

Business purpose

Why does this exist?

One sentence a non-technical executive would accept

Purpose stated as "productivity," which explains nothing

Owner

Who answers for it?

A named business leader, not a department

Ownership assigned to IT for a system IT does not use

Users

Who operates it, and how do they authenticate?

Access list tied to the identity provider

Personal accounts outside single sign-on

Data

What goes in, and what is prohibited?

Explicit approved and prohibited categories per system

A general policy with no per-system boundary

Decisions influenced

What does it change, recommend, or determine?

Named decisions and the humans who can override them

Not mapped at all — the most common gap

Vendor

Who supplies it, under what terms?

Contract, data terms, subprocessors, security posture

Terms accepted by clicking, never reviewed

Approval

Who authorized it, when, on what basis?

A dated record naming the approver

Nothing exists, because nothing was formally approved

Monitoring

How would we know it is misbehaving?

Logging, review cadence, escalation path

Monitoring of uptime, not of output quality

Retirement

How do we turn it off and prove we did?

Decommissioning steps, data disposition, confirmation

No plan, and no way to demonstrate removal

Two fields do most of the work. Decisions influenced converts an IT asset list into a business risk picture. Approval reveals how the organization actually operates, because in most companies it is blank — which means the honest first entry is "none," and that is a more useful starting point than a fabricated one.

What This Changes in Practice

Offboarding becomes incomplete without it. When an employee leaves, the organization disables the accounts it knows about. AI accounts opened with a personal email and a corporate card survive the exit interview, along with whatever was pasted into them. Incident response has the same blind spot: the first question in any serious investigation is where the data went, and "we're not sure what tools were involved" is expensive in a way that compounds.

Vendor review acquires a new trigger. Review historically happened at purchase and renewal. That cadence no longer matches reality, because material capability changes ship between renewals. The trigger has to become the feature release, not the contract date.

Customer-facing disclosure becomes answerable. Texas health care providers now carry an explicit obligation to disclose AI used in service or treatment — directly relevant to healthcare organizations across Dallas, Plano, and Fort Worth running ambient documentation and patient communication tools. Outside health care and government, most disclosure pressure arrives from customers as a questionnaire with a deadline.

Retention and retirement stop being theoretical. Prompts and outputs are records, sitting inside vendor environments under terms the organization may never have read, and they are discoverable. Retirement is the harder of the two: organizations are practiced at adopting systems and unpracticed at removing them, and demonstrating that a system was shut down with its data handled properly is a capability almost nobody has built.

Leadership Considerations

The instinct to delegate this to IT is understandable and wrong in an instructive way. IT can enumerate platforms, read admin consoles, and pull identity logs. IT cannot determine which business decisions a system influences, whether a data category should ever enter it, or who is accountable when an output is wrong. Those are business judgments, and a register assembled without business owners will be technically accurate and operationally useless.

The trade-off deserves stating plainly. Building a register costs real time from people who are already busy, and it will surface systems leadership would have preferred not to discover. That discomfort is the point. The alternative is not avoiding the cost but paying it later, compressed, while a sixty-day clock runs and someone else sets the agenda.

There is also a sequencing error worth avoiding. Written before the register, an AI policy is an aspiration that will not match the environment, and the mismatch becomes its own liability — a document showing the organization knew what it should be doing beside a reality showing it was not.

Metro Relay's Perspective

The pattern we consider most consequential in this region is not aggressive AI adoption. It is quiet accumulation — organizations that would describe themselves as cautious, running a dozen or more systems meeting the statutory definition, none formally approved, because nothing about how they arrived required an approval.

Our position is that AI governance begins as an inventory problem, not an ethics problem. Principles are easier to write than registers, which is precisely why so many organizations have the former and not the latter. A company that can name its systems, owners, data, and decisions can govern them. A company that cannot is not making governance decisions at all; it is making assumptions and calling them decisions. The related question of who holds rights to the data flowing through these systems, addressed in Metro Relay's analysis of AI data ownership, is one the register makes answerable rather than hypothetical.

Where to Start

Start with decisions, not software. Ask each function which recurring decisions are now influenced by a system, then work backward to the platform. This inverts the usual approach and finds embedded systems a software audit skips.

Pull the evidence that already exists. Identity provider logs show authentications to AI services, expense reports show subscriptions, and admin consoles show which AI features are enabled and by whom. Most of the first pass is retrieval, not investigation.

Write the question into vendor conversations. At the next renewal with every material service provider, ask in writing whether AI is used in delivering the service, on what data, and under what oversight.

Assign owners before controls. A system without a named business owner will not be monitored, whatever the policy says. Then tie the review cadence to change rather than the calendar — quarterly review catches drift, while a trigger on vendor feature releases catches systems arriving between reviews.

Only then write the policy: scoped to systems that actually exist, and supported by AI governance controls the organization can demonstrate rather than assert.

Future Outlook

The trajectory worth planning against is not primarily regulatory. Enforcement here is complaint-driven, intent-based, and centralized in one office, which suggests a measured pace rather than a wave.

The faster pressure will come from counterparties. Vendor security questionnaires are already growing AI sections, cyber insurers are beginning to ask at renewal, and acquirers ask in diligence. Health systems and government contractors are pushing the question down supply chains that reach deep into North Texas manufacturing, professional services, and technology firms. Each is a request to produce a list, and none offers a sixty-day cure period.

The reasonable expectation is that within a few years, being unable to describe your AI systems will read the way being unable to describe your data backups reads today: not a violation of anything specific, and a clear signal about how the organization is run.

Conclusion

The Texas Responsible Artificial Intelligence Governance Act did not create the problem most North Texas companies have. It exposed one that was already there and attached questions and a clock to it.

The requirement executives should act on is not written in the statute. It is implied by every part of it: an organization operating AI should be able to say what it runs, who authorized it, what information it receives, and which decisions it shapes. That capability is not compliance. It is the minimum condition for governing anything — and for now it remains a distinguishing one, because most organizations still cannot do it.

Key Takeaways

  • The act took effect January 1, 2026, and the Attorney General's AI complaint intake is already live, ahead of the September 1, 2026 statutory deadline.
  • The enacted law is narrower than early coverage suggested: intent-based prohibitions, no private right of action, and disclosure duties falling mainly on government agencies and health care providers.
  • Its consequence is documentary — the statute specifies what the state may ask you to describe, gives sixty days to cure, and treats documented diligence favorably.
  • AI enters through four paths, and only outright purchase leaves a record; product updates, individual sign-ups, and service providers do not.
  • A list of tools is not a register: exposure tracks the decisions a system influences, not the software licensed.
  • The AI System Accountability Register defines ten fields per system, of which decisions influenced and approval expose the real gap.
  • Build the register before the policy, and expect counterparty pressure from customers, insurers, and acquirers to arrive faster than regulatory pressure.

Frequently Asked Questions

Does the Texas AI law require my company to keep an inventory of AI systems? Not directly, for most private businesses. The act requires state agencies to inventory their AI systems and specifies what the Attorney General may ask a company to describe during an investigation — purpose, inputs, outputs, training data types, evaluation metrics, known limitations, and monitoring. The practical requirement follows from the questions rather than from an inventory mandate.

My company is not based in Texas. Does this apply to us? Possibly. The statute reaches persons who conduct business in Texas, produce a product or service used by Texas residents, or develop or deploy an AI system in the state. Headquarters location is not the test.

What counts as an AI system under the law? Any machine-based system that infers from its inputs how to generate outputs — content, decisions, predictions, or recommendations — that can influence physical or virtual environments. That covers embedded scoring, routing, forecasting, and detection features, not just conversational tools.

Do we have to tell customers when they are interacting with AI? Under this statute, the affirmative disclosure duty applies to governmental agencies making AI available to consumers, and to health care providers using AI in relation to a service or treatment. Other businesses may still face disclosure expectations through contracts, sector regulators, or customers rather than through this law.

What are the penalties? Civil penalties range from $10,000 to $12,000 for a violation the court determines to be curable, $80,000 to $200,000 for one determined uncurable, and $2,000 to $40,000 per day for a continuing violation. Written notice and a sixty-day cure opportunity precede an action.

How do we find AI that arrived inside software we already own? Check administrative consoles of your core platforms for AI features and who enabled them, review vendor release notes since your last security review, and pull authentication logs from your identity provider.

Who should own the AI register — IT, legal, or the business? It is assembled by IT and owned by the business. IT can enumerate what runs; only business leaders can state what a system decides, what data belongs in it, and who answers for an incorrect output. Legal review of interpretation is a separate step.

Responsible AI Readiness Review

Metro Relay works with organizations across Dallas–Fort Worth to establish what AI is actually running, who owns it, what data it touches, and what evidence exists to support it. A Responsible AI Readiness Review produces the register, identifies systems that arrived without approval, and defines the monitoring and retirement paths that make the record durable rather than a one-time snapshot.

If your leadership team could not, this week, produce a list of the AI systems the organization operates, that is the finding — and it is a solvable one. Start the conversation, or review Metro Relay's AI governance and AI automation capabilities.

Sources

Texas Legislature Online, House Bill 149, 89th Legislature (Regular Session), enrolled text — Texas Responsible Artificial Intelligence Governance Act. Supports: the January 1, 2026 effective date; the statutory definition of an artificial intelligence system; applicability and local preemption; the scope of civil investigative demands; the sixty-day cure process and civil penalty ranges; the rebuttable presumption of reasonable care and related safe-harbor provisions; the September 1, 2026 deadline for the complaint mechanism; and the amendments requiring state agencies to inventory their AI systems. https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm

Office of the Attorney General of Texas, Consumer AI Rights. Supports: prohibitions and requirements under the act; disclosure obligations applying to governmental agencies and health care providers; exclusive enforcement authority and the absence of a private right of action; penalty ranges; key definitions; and the availability of the online AI complaint portal. https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-ai-rights