Texas’s Responsible Artificial Intelligence Governance Act took effect on January 1, 2026. Most private companies that looked at it read one section, found the words “governmental agency,” and closed the tab.
That is an understandable mistake. The disclosure provision everyone reads is genuinely narrow. Several other provisions reach private parties.
Who the statute applies to
Start with scope, because “Texas company” is narrower than the statute.
Tex. Bus. & Com. Code § 551.002 provides that the subtitle applies only to a person who promotes, advertises, or conducts business in Texas; produces a product or service used by Texas residents; or develops or deploys an AI system in Texas. A company with no Texas office can be reached through the second clause alone.
The definition of the systems covered is broad. Under § 551.001, an artificial intelligence system is “any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.”
The section everyone reads is the wrong one
Section 552.051(b) expressly requires a governmental agency that makes an AI system available to interact with consumers to disclose that fact. Subsection (f) separately applies a disclosure obligation when AI is used in health care service or treatment. The section does not expressly impose the same disclosure duty on an ordinary private sales or support chatbot. We covered it in detail in what a website chatbot has to disclose.
Reading only § 552.051 and stopping is the error.
Four prohibitions that reach a person, not only a government
Manipulation of human behavior. Section 552.052 provides that a person may not develop or deploy an AI system “in a manner that intentionally aims to incite or encourage a person to: (1) commit physical self-harm, including suicide; (2) harm another person; or (3) engage in criminal activity.” The statute does not define that intent standard, so the provision is better treated as a design-and-deployment risk than as a general rule about objectionable AI output.
Constitutional rights. Section 552.055(a) provides that a person may not develop or deploy an AI system “with the sole intent for the artificial intelligence system to infringe, restrict, or otherwise impair an individual’s rights guaranteed under the United States Constitution.” The statute uses a “sole intent” standard and does not define it. Subsection (b) states the section is remedial and may not be construed to create or expand any constitutional right.
Unlawful discrimination, with significant carve-outs. Section 552.056(b) provides that a person may not develop or deploy an AI system “with the intent to unlawfully discriminate against a protected class in violation of state or federal law.” The statute expressly makes intent central: under § 552.056(c), disparate impact alone is not enough to demonstrate an intent to discriminate under this section.
Two exclusions matter. Under § 552.056(d) the section does not apply to an insurance entity providing insurance services where it is subject to the specified insurance-law regimes. Under § 552.056(e) a federally insured financial institution is considered in compliance if it complies with all federal and state banking laws and regulations.
Certain sexually explicit content. Section 552.057 prohibits developing or distributing an AI system with the sole intent of producing material violating specified Penal Code provisions, including deep fake material under Section 21.165. Subsection (2) separately prohibits intentionally developing or distributing an AI system that engages in text-based conversations simulating or describing sexual conduct while impersonating or imitating a child under 18.
Two sections that address government, and one cross-reference that does not
Section 552.053, on social scoring, opens “A governmental entity may not use or deploy…” Section 552.054(b), on the capture of biometric data, likewise begins “A governmental entity may not develop or deploy…”
But § 552.054(c) provides that “a violation of Section 503.001 is a violation of this section.” That does not extend the governmental-entity prohibition in § 552.054(b) to private parties. It does preserve a separate private-party exposure under Tex. Bus. & Com. Code § 503.001, which regulates the commercial capture, disclosure, protection, and destruction of biometric identifiers.
What enforcement actually looks like
Chapter 552 does not create a private right of action. Section 552.101(b) so provides, and § 552.101(a) gives the attorney general exclusive enforcement authority subject to § 552.106. That is specific to this chapter; it does not displace independent claims arising under other law.
There is a cure process, not merely a deadline. Under § 552.104, if the attorney general determines a person has violated or is violating the chapter, the attorney general must give written notice identifying the specific provisions alleged to be violated. An action is barred if, before the 60th day after that notice, the person cures the identified violation and provides the attorney general a written statement that it has cured the violation, supplied supporting documentation showing how, and made any necessary internal-policy changes to reasonably prevent further violation.
The penalties are tiered. Section 552.105(a) sets $10,000 to $12,000 for each violation the court determines curable or a breach of a statement submitted to the attorney general; $80,000 to $200,000 for each uncurable violation; and $2,000 to $40,000 for each day a violation continues.
Cure is not the only protection. Section 552.105 also supplies a rebuttable presumption that a person used reasonable care; an expedited hearing or declaratory judgment option for a defendant with a good-faith belief it has not violated the chapter; and enumerated circumstances in which a defendant may not be found liable — including where another person misuses the affiliated system, or where the defendant discovered the violation through feedback, adversarial or red-team testing, following applicable state agency guidelines, or an internal review process where the defendant substantially complies with the National Institute of Standards and Technology’s “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile” or another nationally or internationally recognized AI risk-management framework. No civil-penalty action lies for an AI system that has not been deployed.
Section 552.105 therefore identifies internal review as one way a defendant may discover a violation without liability, if the defendant substantially complies with the NIST Generative AI Profile or another recognized framework. The statute does not make framework adoption a general safe harbor, but it gives documented internal review a specific role in the no-liability provision.
Licensed businesses have a second exposure. Under § 552.106 a state agency may impose sanctions against a person it licenses, registers, or certifies following a § 552.105 finding where the attorney general has recommended further action.
Two construction provisions to read together
Section 552.002 states the chapter may not be construed to impose a requirement on a person that adversely affects the rights or freedoms of any person, including the right of free speech. Section 551.003 states the subtitle “shall be broadly construed and applied to promote its underlying purposes.” Both are in the enacted text. The statute does not specify how those provisions interact in a particular enforcement case.
Chapter 552 also broadly preempts local measures regulating the use of AI systems under § 552.003, though generally applicable local requirements may still matter to an AI-enabled business.
What this means in practice
For an ordinary private company, the more immediate Chapter 552 questions often concern the prohibitions and enforcement provisions rather than chatbot disclosure.
The questions that matter are narrower: does anything we build or deploy aim to incite self-harm, harm to others, or criminal activity; is any system making decisions about people in a way that could be characterized as intended discrimination against a protected class; and would we qualify for any of the § 552.105 protections if we had to rely on them.
That last question is the useful one, because the 60-day cure process is a central statutory off-ramp. But it is not just a response deadline: the company must cure the identified violation, document how it did so, and make policy changes reasonably designed to prevent a recurrence. A company with usable records can spend that period remediating and substantiating its response rather than reconstructing its system history under pressure.
So the practical test is not “could we answer a notice in sixty days.” It is “could we cure the identified issue, provide the required written statement and supporting documentation, and make any necessary policy changes inside sixty days.”