TRAIGA & SB 1188: what Texas's new AI laws actually require of a small business
Updated August 27, 2026 · by Edgar D. Reyna, Azuryc · Boerne, Texas
Texas passed two AI laws in 2025. One of them probably applies to you; the other applies if you touch health records. Here's what each one says, when it bites, and the short list of things a small business should actually do — without the fearmongering that usually comes wrapped around this topic.
The two laws at a glance
| TRAIGA (HB 149) | SB 1188 | |
|---|---|---|
| What it is | The Texas Responsible Artificial Intelligence Governance Act — the general-purpose AI law. | An electronic health records law with AI provisions bolted on. |
| Who it touches | Broadly: anyone doing business in Texas who develops, deploys, or offers AI systems — with stricter rules for government entities. | Healthcare providers, covered entities, and their vendors handling Texas patients' EHRs. |
| Effective | January 1, 2026 — in force now. | September 1, 2025 generally; the data-localization requirement January 1, 2026 — in force now. |
| Enforced by | Texas Attorney General (no private lawsuits), with a notice-and-cure period before penalties. | Civil penalties tiered by intent — reported from $5,000 up to $250,000 per violation. |
TRAIGA in plain English
TRAIGA is narrower than the early drafts that made headlines. The version that became law focuses on prohibited uses and transparency, not on auditing every business that uses ChatGPT.
What it prohibits (for everyone)
- Developing or deploying AI that intentionally manipulates human behavior to incite self-harm, harm to others, or criminal activity.
- Using AI to unlawfully discriminate against protected classes — with intent as the operative standard for private businesses.
- AI for producing or distributing child sexual abuse material or unlawful deepfakes.
- Using AI to infringe constitutional rights.
What it requires operationally
- Disclosure when consumers interact with AI in certain contexts — government agencies must disclose always; businesses should disclose whenever a reasonable person could be misled into thinking they're dealing with a human.
- Accountability for what your AI actually does — "the vendor built it" is not a defense if you deployed it.
- A 60-day cure window: the AG must give you notice and a chance to fix a violation before penalties. Documentation of your practices is what makes a cure credible.
SB 1188 in plain English (healthcare only)
- EHRs must be physically stored in the United States — as of January 1, 2026. If your EHR vendor or backup provider stores data offshore, that's now your problem. Ask them in writing.
- Access limits: records may only be accessed for treatment, payment, and healthcare operations — least-privilege isn't just good hygiene anymore, it's statutory.
- AI disclosure: if a practitioner uses AI in diagnosis or treatment, the patient must be told.
- Human review: AI-generated records must be reviewed by the practitioner, per Texas Medical Board standards.
- Parental access to minors' records is required except where law or a court order restricts it.
The small-business checklist
- Inventory your AI. One page: every place AI touches your operation — chatbots, drafting tools, scoring, automation with AI components, what data each touches, and who's responsible for it. This single artifact does more for you in a cure period than anything else.
- Add disclosure lines wherever a customer interacts with AI that could pass for a human — chat widgets, phone bots, generated emails. One sentence each.
- Put a human gate on consequential decisions. Anything touching hiring, credit, housing, healthcare, or legal outcomes gets a documented human sign-off. (This is also just how you avoid the discrimination prohibition by design.)
- Keep logs. If you can't show what the system did and who approved it, you can't cure. Audit trails are the cheapest insurance the statute offers.
- Send your vendors three questions in writing: Where is our data stored? What AI features are on by default? Will you certify TRAIGA/SB 1188 compliance for your product?
- Healthcare: confirm US-only storage for EHRs and backups, review who has access against the treatment/payment/operations standard, and script the AI-use disclosure into the visit workflow.
- Write down your framework. A two-page AI policy referencing NIST AI RMF categories — govern, map, measure, manage — is proportionate for a small business and squarely inside the statute's safe-harbor logic.
What you don't need
- You don't need to stop using AI tools. The law regulates specific harmful uses and specific disclosures, not AI use generally.
- You don't need an "AI ethics board" or an enterprise GRC platform at small-business scale.
- You don't need to panic about the penalty numbers you've seen quoted — the AG process starts with notice and a cure window, and documented good-faith practices are exactly what it's designed to credit.
Want this handled instead of explained?
Azuryc builds automation and AI systems with the sign-off gates, audit trails, and NIST-aligned governance these laws expect — because we run systems like that ourselves, every day. Fixed prices, published at azuryc.com.
Get your top 3 fixes — free, 2 minutes →