Your AI Vendor Had a Security Incident. Who Has to Tell Your Customer, and by When?
Updated October 2026
Your SaaS product sends customer content to a third-party AI provider: prompts to a model, documents to a summarizer, support transcripts to a classifier. Then the provider emails you that it found unauthorized access to a system that handled API traffic. Your customer's information may have been in it.
Several notice duties may be implicated: what your provider owes you, what you owe your customer, and what the owner or licensee of covered information owes affected individuals. The applicable statutes and agreements must be assessed for each link. Each link has its own contract, and Arizona, California and Texas each have their own statute for the notices that law requires.
The short answer
Each of the three states' breach-notification statutes separates two duties.
First, a person or business that maintains personal information it does not own must tell the owner or licensee of that information. Arizona says "as soon as practicable," Texas says "immediately after discovering the breach," and California says "immediately following discovery."123
Second, the owner or licensee then notifies the affected individuals, on a separate deadline. In Arizona, awareness of a security incident first requires a prompt investigation to determine whether a security system breach occurred.4 The deadlines: within 45 days after an investigation "results in a determination that there has been a security system breach" in Arizona, not later than the 60th day after it determines that the breach occurred in Texas, and within 30 calendar days of "discovery or notification" in California.567
All three statutes tie these duties to defined terms, not to every customer record or every incident. Arizona's definitions are in § 18-551, California's in § 1798.82(g) and (h), and Texas defines "sensitive personal information" in § 521.002 and "breach of system security" in § 521.053(a).891011 Application also depends on the statute's covered persons, data and residents. The owner-duty provisions in these three statutes address persons or businesses conducting business in the state;121314 Arizona separately excludes certain entities under § 18-552(N),12 while California's HIPAA provision addresses compliance with specified notice-content requirements rather than exempting covered entities from the section.14 Each statute also allows notice to be delayed in specified circumstances, including at a law enforcement agency's request.151617 Arizona also provides that subsection B notification is not required if, after a reasonable investigation, the person, an independent third-party forensic auditor, or law enforcement determines that the breach has not resulted in, or is not reasonably likely to result in, substantial economic loss to affected individuals.18 The deadlines below are therefore the general rule rather than the whole text.
The three states side by side
| State | A person or business that maintains data it does not own tells the owner or licensee | The owner or licensee tells affected individuals |
|---|---|---|
| Arizona | "as soon as practicable," on discovering a security system breach, and must "cooperate with the owner or the licensee," including "sharing information relevant to the breach"1 | "within forty-five days after the determination" that there has been a security system breach5 |
| California | "immediately following discovery," if the personal information "was, or is reasonably believed to have been, acquired by an unauthorized person"3 | "within 30 calendar days of discovery or notification of the data breach," subject to the delays specified in subsection (a)(2)(B)716 |
| Texas | "immediately after discovering the breach," if the sensitive personal information "was, or is reasonably believed to have been, acquired by an unauthorized person"2 | "without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred," subject to subsection (d)'s law-enforcement delay and to the time necessary to determine the scope of the breach and restore the reasonable integrity of the data system.6 |
Regulator notices run on their own thresholds:
- Arizona: a breach that requires notification of more than 1,000 individuals means notice to the three largest nationwide consumer reporting agencies, and to the attorney general and the director of the Arizona department of homeland security.5
- California: more than 500 California residents means one sample copy of the notice to the Attorney General within 15 calendar days of notifying affected consumers.19
- Texas: at least 250 Texas residents means notice to the Attorney General as soon as practicable and not later than the 30th day after the date the person determines the breach occurred; if notice to more than 10,000 persons is required at one time, notice must also be provided to each consumer reporting agency that maintains consumer files on a nationwide basis, without unreasonable delay.2021
Where the contract comes in
Arizona's subsection C ends with a sentence about contracts: the person that maintains the data under an agreement with the owner or licensee "is not required to provide the notifications required by subsection B of this section unless the agreement stipulates otherwise."1 Subsection B addresses the owner's or licensee's required notices to affected individuals and, if its threshold is met, to the specified agencies and officials.5 Whichever state's law applies to a given incident, check what each agreement in your chain says about who sends notices to individuals and to regulators, and who decides when one is due.
The vendor-to-owner provisions above use words ("immediately," "as soon as practicable") rather than a number of hours or days. A contract can name a number, and a customer's DPA or addendum can set one. Compare that number with the window your own AI provider gives you. Our guide to enterprise SaaS contracts covers where those provisions sit in an MSA and DPA.
Where an AI provider adds a link
The statutes speak of a person that "maintains" data it does not own. A prompt that travels from your customer, through your product, to a model provider raises questions the statutes do not answer for you. These are the ones to work through before an incident, not during one:
- Does your provider keep the data, and for how long? Prompts, outputs, logs, embeddings and fine-tuning files are different things with different retention. What the provider receives, stores or otherwise handles, and how its systems operate, are facts to assess against the applicable statutory language and its agreements.
- What triggers the provider's duty to tell you? Your provider's contract may say "security incident," "breach," "confirmed" or "suspected." The California and Texas provisions quoted above turn on personal information that "was, or is reasonably believed to have been, acquired by an unauthorized person." Line the words up.
- What window does your provider give you, and what window have you given your customer? A promise to your customer that is shorter than the one your provider makes to you is a gap you carry.
- Is the provider a named subprocessor in your customer contracts? If so, those contracts may already require notice of its incidents on a specific timetable. We cover that in what your customer contract says about AI subprocessors.
- What will the provider cooperate on, and what can you pass along? Arizona's text requires a maintainer to cooperate and share information relevant to the breach.1 Check what your provider's terms let it share with you, and what your customer contract lets you share onward.
- When does each clock start, and who is recording the dates? California states a 30-calendar-day period measured from "discovery or notification," subject to the statutory qualifications.7 Record when the provider discovered the event, when it notified you, and when you notified your customer; assess any statutory deadline with counsel on the particular facts.
Before an incident: a short checklist
- List every AI provider your product uses and the data each one receives.
- Pull each provider's current incident-notice terms: what triggers them, the window, what the notice must contain, and who notifies whom.
- Compare those terms with what your customer contracts and security questionnaire answers promise. Our post on security questionnaire drift explains how those answers fall out of step with the contracts.
- Decide in advance who in your company receives a provider's notice, and who decides, with counsel, whether the event is a breach under each state's definition.
- Keep a dated record of when the provider discovered the event, when it told you, when you told each customer, and what each notice said.
What this post does not cover
It covers three statutes only. It does not cover other states' laws that apply to customers elsewhere, federal or sector-specific rules, the definitions in your own agreements, insurance, or whether a particular event is a breach. Each of those depends on facts and documents this post does not have. For the buyer's side of incident clauses, see our guide to reviewing a SaaS contract, and for the questions to put to an AI provider before you connect, see 7 contract questions to ask before connecting an AI tool.
How we can help
Accord and Shield Legal reviews and negotiates SaaS agreements, data processing terms and AI-related contract terms for technology companies in Arizona, California and Texas. To better understand the scope of your matter, you can book a free 15-minute initial consultation.
This article is general information, not legal advice. Reading it does not create an attorney-client relationship. How any of these statutes applies to your business depends on your agreements and your facts; consult an attorney about your situation.
Citations
- Ariz. Rev. Stat. § 18-552, subsec. C, https://www.azleg.gov/ars/18/00552.htm ↩︎1↩︎2↩︎3↩︎4
- Tex. Bus. & Com. Code § 521.053(c), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎1↩︎2
- Cal. Civ. Code § 1798.82(b), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎1↩︎2
- Ariz. Rev. Stat. §§ 18-551(10), 18-552(A)–(B), https://www.azleg.gov/ars/18/00552.htm and https://www.azleg.gov/ars/18/00551.htm ↩︎
- Ariz. Rev. Stat. § 18-552, subsecs. A–B, https://www.azleg.gov/ars/18/00552.htm ↩︎1↩︎2↩︎3↩︎4
- Tex. Bus. & Com. Code § 521.053(b), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎1↩︎2
- Cal. Civ. Code § 1798.82(a)(1)–(2), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎1↩︎2↩︎3
- Ariz. Rev. Stat. § 18-551, https://www.azleg.gov/ars/18/00551.htm ↩︎
- Cal. Civ. Code § 1798.82(g)–(h), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎
- Tex. Bus. & Com. Code § 521.002, https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
- Tex. Bus. & Com. Code § 521.053(a), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
- Ariz. Rev. Stat. § 18-552(A), (N), https://www.azleg.gov/ars/18/00552.htm ↩︎1↩︎2
- Tex. Bus. & Com. Code § 521.053(b)–(c), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
- Cal. Civ. Code § 1798.82(a), (b), (e), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎1↩︎2
- Ariz. Rev. Stat. § 18-552, subsec. D, https://www.azleg.gov/ars/18/00552.htm ↩︎
- Cal. Civ. Code § 1798.82(a)(2)(B), (c), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎1↩︎2
- Tex. Bus. & Com. Code § 521.053(b), (d), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
- Ariz. Rev. Stat. § 18-552(J), https://www.azleg.gov/ars/18/00552.htm ↩︎
- Cal. Civ. Code § 1798.82(f), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82 ↩︎
- Tex. Bus. & Com. Code § 521.053(i), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
- Tex. Bus. & Com. Code § 521.053(h), https://statutes.capitol.texas.gov/Docs/BC/htm/BC.521.htm ↩︎
Book an Initial Consultation
Book a free 15-minute initial consultation to talk through the scope of your matter. Bring a short, nonconfidential description of the situation and any real deadline.
Please do not send contracts, documents or confidential information until the firm has agreed in writing to represent you.