CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
      • IT Help Desk
      • 24/7 Emergency Support
      • Co-Managed IT
      • Remote IT Support
      • Onsite IT Support
      • Proactive Monitoring
      • Patch Management
      • Network Monitoring
      • Mobile Device Management
      • IT Procurement
      • IT Documentation
      • Server Management
      • Mac Support
      • Employee Onboarding & Offboarding
    • Cybersecurity
      • Endpoint Security
      • Network Security
      • Managed Firewall
      • Email Security
      • Phishing Protection
      • Security Awareness Training
      • Dark Web Monitoring
      • Penetration Testing
      • Multi-Factor Authentication
      • Zero Trust
      • Vulnerability Scanning
      • SIEM Services
      • Managed SOC
      • Virtual CISO (vCISO)
      • Password Management
      • Managed Detection & Response
    • Business Continuity & Disaster Recovery (BCDR)
      • Backup & Disaster Recovery
      • Microsoft 365 Backup
      • Cloud Disaster Recovery
      • Backup & DR Audit
      • Backup as a Service
      • Tabletop Exercises
    • Cloud Services
      • Microsoft 365
      • Microsoft Azure
      • Cloud Migration
      • SharePoint
      • Virtual Desktop
      • Azure Managed Services
      • Cloud Monitoring & Management
      • Microsoft Entra ID
      • Microsoft Teams
      • Microsoft Exchange
      • OneDrive for Business
      • Amazon Web Services (AWS)
    • AI Services
      • AI Policy & Governance
      • AI Security & Risk
      • AI Readiness Assessment
      • AI Strategy
      • AI Assistant Platforms
      • AI Training & Adoption
      • AI Workflow Automation
      • AI Development
      • Agentic AI
      • Business Intelligence
      • Business Process Automation
      • Data Analytics
    • Compliance
      • SOC 2
      • HIPAA
      • CMMC
      • NIST CSF
      • PCI DSS
      • FTC Safeguards
      • CIS Controls
      • Cyber Insurance
      • Compliance Audit
    • Network, Voice & Strategy
      • Software Defined Wide Area Networks (SD-WAN)
      • Voice Over IP (VoIP)
      • Virtual CTO & CIO Services
      • Teams Phones & Conferencing
      • Network Assessment
      • IT Consulting
      • IT Cost Assessment
      • Digital Transformation Strategy
      • Legacy System Assessment
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise
    • Architecture
    • Banking & Credit Unions
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Healthcare
    • Law Firms
    • Manufacturing
    • Non-Profit
    • Oil & Gas Services
    • Real Estate & Property Management
    • Transportation & Logistics
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Texas Breach Notice Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Reviews
  • Contact
I Need IT Support Now
A written AI record at the center, connected to policy, training, discovery and security icons
Shane Stevens
Shane Stevens October 8th, 2026

Texas AI Law (TRAIGA, HB 149): A 2026 Small Business Checklist

How The Texas Attorney General Enforces HB 149 – A Texas AI Law Checklist For Houston Small Businesses

2026 Texas Compliance Checklist
Texas AI Law: Does HB 149 Apply to Your Small Business? Build the Written Record the Attorney General Can Ask For.

What TRAIGA asks of a private Houston business, and the checklist that answers a demand letter.

TL;DR
The Texas AI law, HB 149, took effect January 1, 2026. Most of its duties bind government, but 4 intent-based prohibitions, a health care disclosure and a biometric consent rule reach private businesses. Only the attorney general enforces it, with 60 days to cure.
📜 What the Law Is 🏢 Who It Binds ⚖️ Enforcement ✅ The Checklist 🚀 How CinchOps Helps ❓ FAQ

The Texas AI law, HB 149, has covered any person who conducts business in Texas since January 1, 2026. A Houston owner whose staff already use ChatGPT, Microsoft 365 Copilot or an AI note-taker is inside its definition of an artificial intelligence system, and most have never been told what the statute asks of them.

The full name is the Texas Responsible Artificial Intelligence Governance Act, usually shortened to TRAIGA. Most of its duties fall on state and local government. A private business faces 4 intent-based prohibitions, a disclosure rule for health care providers and a consent rule for biometric identifiers. The enrolled text contains no registration, filing or audit requirement for a private business.

What the law does create is a letter. On a consumer complaint, the Texas attorney general can demand a written description of an AI system, and a business then has 60 days to cure any violation the attorney general identifies. CinchOps provides AI policy and governance specifically for small and mid-sized businesses in Houston with 10 to 200 employees, organized around the 7 categories of information that demand can request.

CinchOps' analysis of U.S. Census Bureau survey data puts Houston-area business AI use at 20.6%, 18th of the 25 largest metros. This post is a plain-language reading of the enrolled bill text, not legal advice. A Texas attorney should confirm how HB 149 applies to a specific business.

TEXAS HB 149The Texas AI Law in 3 NumbersIN EFFECTJan 1, 2026Applies statewide in TexasTIME TO CURE60 daysAfter written noticePENALTY FLOOR$10,000Per curable violationCinchOps · cinchops.com
The short version: HB 149 forbids a short list of intentional AI misuses and gives a business 60 days to fix a problem. The work for a Houston small business is a written AI record, which is what AI policy and governance produces.

What Is the Texas AI Law?

HB 149 is a short statute with a wide definition and a narrow set of prohibitions.

The Texas AI law is the Texas Responsible Artificial Intelligence Governance Act, passed as HB 149 by the 89th Texas Legislature and in effect since January 1, 2026. HB 149 adds an Artificial Intelligence Protection subtitle to the Texas Business & Commerce Code, bans a short list of intentional AI misuses, and gives enforcement to the Texas attorney general alone.

Section 551.001 defines an artificial intelligence system as "any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments." That wording covers a chatbot, a meeting transcription tool and the scoring features built into accounting, hiring and customer software.

Section 551.002 applies the subtitle to a person who does any of the following:

  • Promotes, advertises or conducts business in Texas.
  • Produces a product or service used by Texas residents.
  • Develops or deploys an artificial intelligence system in Texas.

The Texas House passed HB 149 on April 23, 2025 by a vote of 146 to 3. The Senate passed an amended version on May 23, 2025 by 31 to 0, and the House concurred on May 30, 2025 by 121 to 17. The act set a second date as well: the attorney general had until September 1, 2026 to post an online complaint mechanism.

LEGISLATIVE RECORDHB 149 From Vote to EnforcementApr 23, 2025House passes146 to 3May 23, 2025Senate passes31 to 0May 30, 2025House concurs121 to 17Jan 1, 2026Law takeseffectSep 1, 2026AG complaintsite dueCinchOps · cinchops.com

HB 149 does 3 other things a Houston business should know. Section 552.003 preempts any city or county rule on the use of AI systems, so a business in Katy, Sugar Land or The Woodlands follows one statewide rule. Chapter 553 creates a regulatory sandbox, run by the Texas Department of Information Resources, where an approved participant can test an AI system for up to 36 months. Chapter 554 creates a 7-member Texas Artificial Intelligence Council, which under Section 554.103 may not adopt binding rules.

Which Parts of HB 149 Reach a Private Business?

The statute names who each rule binds. Reading it rule by rule removes most of the worry.

HB 149 puts its consumer disclosure, social scoring and biometric identification rules on government, and puts 4 intent-based prohibitions on every person. A private Houston business is also reached by the health care AI disclosure in Section 552.051(f) and by the biometric consent rule in Section 503.001 of the Business & Commerce Code.

The table below lists each HB 149 rule, the section it sits in, who the section binds, and what the rule means for a private Houston business.

HB 149 ruleSectionWho the rule bindsWhat it means for a private Houston business
AI interaction disclosure to consumers552.051(b)Governmental agenciesHB 149 places no chatbot disclosure duty on a private business outside health care.
Health care AI disclosure552.051(f)Providers of a health care service or treatmentA practice that uses an AI system in relation to care discloses it to the patient no later than the date of service, or as soon as reasonably possible in an emergency.
Manipulation of human behavior552.052Any personNo AI system may be developed or deployed in a manner that intentionally aims to incite self-harm, harm to another person or criminal activity.
Social scoring552.053Governmental entitiesNo duty for a private business.
Biometric identification without consent552.054(b)Governmental entitiesNo direct duty, but Section 552.054(c) makes a violation of the biometric identifier law a violation of HB 149.
Biometric identifier consent503.001, as amendedAny person capturing a biometric identifier for a commercial purposeA photo or recording found online is not consent unless the individual made it public themselves.
Constitutional protection552.055Any personNo AI system may be developed or deployed with the sole intent to infringe rights guaranteed by the U.S. Constitution.
Unlawful discrimination552.056Any personNo AI system may be developed or deployed with the intent to unlawfully discriminate against a protected class. A disparate impact alone does not show intent.
Sexually explicit content and child exploitation material552.057Any personNo AI system may be developed or distributed with the sole intent of producing unlawful explicit material or unlawful deepfakes.
Processor duties under the Texas data privacy law541.104(a), as amendedProcessors of personal dataA vendor processing personal data assists the controller with securing personal data that an AI system collects, stores and processes.
WHO IS BOUNDWho Each HB 149 Rule BindsGOVERNMENT ONLYANY BUSINESS IN TEXASAI disclosure to consumersSocial scoringBiometric identificationManipulation toward harm or crimeIntent to infringe constitutional rightsIntent to unlawfully discriminateUnlawful explicit content and deepfakesHealth care AI disclosureBiometric consent, Section 503.001CinchOps · cinchops.com
Key insight: Three details in the enrolled text matter for a small employer. Section 551.001 defines a consumer as a Texas resident acting in an individual or household context, and the definition excludes a person acting in a commercial or employment context. The discrimination rule in Section 552.056 is not limited to consumers, so an AI hiring or screening tool deployed with intent to unlawfully discriminate is covered. Outside the voluntary sandbox, HB 149 sets no impact assessment or reporting duty for a private business.

Houston has a large health care sector, and Section 552.051(f) is the rule most likely to touch a Houston practice in daily operations. A dental office, clinic or therapy practice that uses an AI system in relation to a health care service or treatment has a disclosure duty that a CPA practice or engineering firm using the same software does not.

Only the Texas Attorney General Enforces HB 149

The enforcement chapter is a fixed sequence, and each step is something a business can prepare for.

The Texas attorney general has exclusive authority to enforce HB 149, and Section 552.101 states that the law creates no private right of action. Enforcement follows a fixed sequence: a consumer complaint filed online, a civil investigative demand, a written notice of violation, 60 days to cure, and a civil penalty only if the violation is not cured.

Section 552.102 requires the attorney general to maintain an online mechanism for consumer complaints. As of October 8, 2026, the attorney general's File a Consumer Complaint page lists an AI complaint form for concerns that an AI system "is being developed or deployed in a way that violates Texas law."

ENFORCEMENT PATHThe HB 149 Enforcement Sequence1Consumer files a complaint online2AG issues a civil investigative demand3AG sends written notice of violation4Business has 60 days to cure5Civil penalty only if not curedCinchOps · cinchops.com

On a complaint, Section 552.103 lets the attorney general issue a civil investigative demand. The demand can request 7 named categories of information, plus other relevant documentation:

  • A high-level description of the purpose, intended use, deployment context and associated benefits of the AI system.
  • A description of the type of data used to program or train the system.
  • A high-level description of the categories of data processed as inputs.
  • A high-level description of the outputs the system produces.
  • Any metrics the business uses to evaluate the system's performance.
  • Any known limitations of the system.
  • A high-level description of post-deployment monitoring and user safeguards, including, for a deployer, the oversight, use and learning process set up to address issues.

Section 552.104 then requires written notice naming the specific provisions at issue. The attorney general may not bring an action before the 60th day after that notice, or at all if the business cures the violation within the 60 days and sends a written statement that it has cured the violation, supplied supporting documentation and changed internal policies to prevent a repeat.

Civil penalties under Section 552.105 are $10,000 to $12,000 for each curable violation, $80,000 to $200,000 for each uncurable violation, and $2,000 to $40,000 for each day a violation continues. The attorney general can also seek an injunction and recover attorney's fees and costs. For a business licensed, registered or certified by a Texas agency, Section 552.106 lets that agency add sanctions on the attorney general's recommendation, including license suspension or revocation and a monetary penalty of up to $100,000. That reaches Houston CPA practices, engineering firms and medical practices.

Section 552.105 also writes in defenses. The statute presumes a person used reasonable care unless shown otherwise. A defendant may not be found liable if another person misuses its AI system, or if the defendant discovers a violation through feedback, through testing such as red-team testing, by following state agency guidelines, or through an internal review process while substantially complying with the NIST Generative Artificial Intelligence Profile or another recognized AI risk management framework.

Key insight: Every defense in HB 149 rests on something that existed before the complaint: a test result, a framework review, a written policy. A business that starts writing after the notice arrives has 60 days to produce what a prepared business already has on file.

In 35+ years of IT work I have watched new rules reach small businesses the same way each time. The business that struggles is the one that cannot show, in writing, what it was doing.

Build the Written AI Record Before a Complaint Arrives

The checklist follows the statute: each step produces a document the attorney general can request or a defense the law recognizes.

A Houston small business prepares for the Texas AI law by building one written AI record that answers the 7 categories of information the attorney general can request under Section 552.103. The record lists each AI tool, its purpose, its data, its limits, the rules staff follow and the framework used to review it.

CHECKLISTThe Texas AI Law Record ChecklistList every AI system in useSection 551.001 definitionWrite each tool's purpose and useSection 552.103(b)(1)Record data in and outputsSection 552.103(b)(2) to (4)Note metrics and known limitsSection 552.103(b)(5) and (6)Write the use and oversight policySection 552.103(b)(7)Review against a NIST frameworkSection 552.105(e)Check health care and biometricsSections 552.051(f) and 503.001Name who answers within 60 daysSection 552.104CinchOps · cinchops.com
  • List every AI system in use, measured against the Section 551.001 definition. Include AI features inside software the business already pays for and accounts staff opened on their own.
  • Write each tool's purpose and intended use in 2 or 3 plain sentences. Section 552.103(b)(1) asks for exactly this.
  • Record the data going in and the outputs coming out. Sections 552.103(b)(2) to (4) cover training data, input categories and outputs. For a purchased tool, keep the vendor's documentation.
  • Note how the business judges each tool and where the tool fails. Sections 552.103(b)(5) and (6) ask for performance metrics and known limitations.
  • Write the use and oversight policy: who may use which tool with which data, who reviews the output, and how staff report a problem. Section 552.103(b)(7) calls this the oversight, use and learning process.
  • Review the record against a recognized framework and date the review. Section 552.105(e) names the NIST Generative Artificial Intelligence Profile.
  • Check the 2 rules that reach private businesses directly: the health care disclosure in Section 552.051(f) and biometric consent under Section 503.001. Also review any tool that makes decisions about people.
  • Name the person who answers an attorney general notice, and put the 60-day cure period in Section 552.104 on that person's calendar the day a notice arrives.

The NIST Generative Artificial Intelligence Profile is NIST AI 600-1, published by the National Institute of Standards and Technology on July 26, 2024. HB 149 refers to "the most recent version," so the review should name the version it used. The statute's standard is substantial compliance, which a 40-person firm can meet with a short written review and without an outside certification.

Start with the inventory. Every later step depends on knowing which tools exist, and a SaaS audit usually finds AI accounts the owner did not know about. The same record answers the AI questions that now appear on customer security reviews, which CinchOps covers in its guide to responding to a security questionnaire.

"The Texas AI law does not ask a 40-person firm to register anything or file anything. It asks you to answer a letter within 60 days. If you can already say which AI tools you run, what data goes into them and who checks the output, most of that answer is written."
Shane Stevens, CEO, CinchOps - LinkedIn

Put Your AI Use in Writing Before Someone Asks

CinchOps builds the AI inventory, the written use policy and the review record through its AI policy and governance work for Houston-area businesses.

See AI policy and governance →

How CinchOps Can Help Houston Businesses Document Their AI Use

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

CinchOps is an IT provider, not a law firm, and the legal reading of HB 149 belongs with a Texas attorney. The written AI record is IT work: finding the accounts, documenting the data and enforcing the policy. AI policy and compliance projects are scoped by an audit and quoted after it. The published CinchOps managed IT rate is a flat $100 to $250 per user per month under Zero-Zero-Zero terms: no long-term contracts, no hidden fees, no cancellation penalties.

CINCHOPS SERVICESWhere CinchOps Fits in the RecordSaaS auditFinds every AI accountAI policy and governanceWrites the rules and the recordAI trainingTeaches staff the policyAI securityMonitors accounts and devicesWrittenAI recordCinchOps · cinchops.com
  • A SaaS audit and shadow IT discovery finds every AI account in use, which is the first line of the record.
  • AI policy and governance writes the rules and the record: purpose, data, limits, oversight and the framework review.
  • AI training and user adoption teaches staff the policy, and AI security and risk management monitors the accounts and devices the tools run on.
  • Compliance services and cybersecurity with 24/7 threat monitoring sit under the record, and help desk requests are answered in under 15 minutes during office hours.
  • Managed IT in Houston, Katy, Sugar Land and Cypress, with programs for CPA firms, law firms and engineering firms.

HB 149 is a narrow law, and a Houston business that uses AI for ordinary office work is unlikely to break one of its prohibitions. The exposure is being unable to describe that ordinary use in writing when a complaint lands. Write the record this quarter, while nobody is asking for it. To see what that takes for your headcount, talk to CinchOps.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

Does the Texas AI law apply to small businesses?

Yes. Texas HB 149 covers any person who conducts business in Texas, with no exemption by size. Most of its duties bind government. A private small business is reached by 4 intent-based prohibitions, a health care AI disclosure rule and the biometric consent rule, and can receive an attorney general demand for information after a complaint.

What is the penalty for violating Texas HB 149?

Civil penalties under Texas HB 149 are $10,000 to $12,000 for each curable violation, $80,000 to $200,000 for each uncurable violation, and $2,000 to $40,000 for each day a violation continues. A business first gets written notice and 60 days to cure. A state licensing agency can add a penalty of up to $100,000.

Can a customer sue my business under the Texas AI law?

No. Section 552.101 of Texas HB 149 gives the Texas attorney general exclusive enforcement authority and states that the law creates no private right of action. A consumer who believes an AI system violates the law files a complaint with the attorney general, who decides whether to issue a civil investigative demand.

Do I have to tell customers they are talking to an AI chatbot in Texas?

Under Texas HB 149, the duty to disclose an AI interaction applies to governmental agencies and to providers of a health care service or treatment. HB 149 places no chatbot disclosure duty on other private businesses. A Houston medical or dental practice using AI in relation to care must disclose it by the date of service.

What is the NIST defense in the Texas AI law?

Section 552.105(e) of Texas HB 149 says a defendant may not be found liable if it discovers a violation through an internal review process while substantially complying with the most recent NIST Generative Artificial Intelligence Profile or another recognized AI risk management framework. A dated, written framework review is what makes the defense available.

What does Texas AI law compliance cost in Houston?

Texas HB 149 charges no registration or filing fee, so the cost is the work of building the written AI record. CinchOps scopes AI policy and compliance work with an audit and quotes it after the audit. Separately, the published CinchOps managed IT rate is a flat $100 to $250 per user per month.

Discover More

AI Governance for Small Business: A Practical 2026 Guide
Which Compliance Rules Apply to a Houston Small Business?
AI Security Roadmap for Houston Businesses: The Four-Phase Guide
How to Implement AI in a Small Business: A Houston Rollout Plan
State of AI 2026: What Deloitte's Survey Means for Houston Businesses
Houston Small Business AI Adoption: The 2026 Census Report

Resource

Infographic: Texas AI law HB 149 enforcement sequence, civil penalties and the written AI record checklist for a Houston small business
Texas AI Law: What HB 149 Asks of a Houston Small Business Open Full Size

Sources

  • Texas Legislature, HB 149 enrolled text, Texas Responsible Artificial Intelligence Governance Act, 89th Regular Session
  • Office of the Texas Attorney General, File a Consumer Complaint (AI complaint form), viewed October 8, 2026
  • National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1), July 26, 2024
  • CinchOps, Houston Small Business AI Adoption: The 2026 Census Report (analysis of the U.S. Census Bureau Business Trends and Outlook Survey)
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 19th, 2026
Law Firm IT
How a Law Firm IT Partner Helps Houston Firms Meet Texas Bar Cybersecurity Standards

Managed IT Support Designed for Houston Law Firms – Law Firm IT Governance: Policies, Controls, and Documentation

March 17th, 2026
Security Scorecard
CinchOps Launches Houston Area Security Index: A Free Resource for Local Businesses to Understand Regional Cyber Risk

From A To F: Where Does Your Houston Business Score? – Free Cybersecurity Benchmarking For Houston Businesses

June 12th, 2026
Managed IT Houston
Managed IT Houston: What the Data Center Power Squeeze Means

The Grid Is Telling You To Spread Your Risk – One Outage Should Not Take Your Whole Business Down

June 23rd, 2026
Managed IT Houston
Houston Small Business AI Adoption: The 2026 Census Report

Houston Is 18th of 25 Metros on AI – The Head Start Is Still Open

March 26th, 2026
AI Impacts Cybersecurity
SentinelOne Annual Threat Report: 8 Attack Strategies Targeting Your Houston Business Right Now

Understanding the Priority Gap Between Patching and Operations – What the SentinelOne Annual Report Means for Houston Businesses

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Compliance
  • Virtual CTO & CIO
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy