Guide

Before a Business Adopts an AI Tool

Identify the task, the information the service can reach, the binding vendor terms, and the person who may approve its output.

Law checked through

Short Answer

Approval begins with a specific use. Map the data that uploads and connected accounts will expose, read the order form and every incorporated policy, test the tool with material the business is authorized to share, and assign a reviewer with access to the underlying record. Repeat the review when the service or its use changes. Where the Texas Data Privacy and Security Act applies, Business and Commerce Code § 541.104(b) requires particular controller-processor contract terms. Other allocations of error and intellectual property risk are negotiated choices, not legal requirements. Keep a short record of each step; under the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), testing and internal review records can matter if the Attorney General ever asks.

Which Laws Apply

  • Texas AI-specific: Business and Commerce Code § 552.105(e) (defenses tied to testing and internal review); Business and Commerce Code § 552.103(b) (what a civil investigative demand may request).
  • Generally applicable Texas law: Texas Data Privacy and Security Act (TDPSA) Business and Commerce Code § 541.002 and Business and Commerce Code § 541.104; Texas Uniform Trade Secrets Act (TUTSA) Civil Practice and Remedies Code § 134A.002(6); Deceptive Trade Practices-Consumer Protection Act (DTPA); contract law.
  • Federal: Federal Trade Commission (FTC) Act § 5; Title VII or the Fair Credit Reporting Act (FCRA) if the tool affects decisions about people; National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) (voluntary).

Define the Task

Record what the tool is approved to do, who will see its output and who can change its scope. An internal summary of meeting notes is a different legal problem from a customer-facing answer or an applicant ranking, even if the same product performs all three. The written scope is also the business’s first answer if a regulator later asks how the system is used, which is the first item on TRAIGA’s list of what the Attorney General may demand (Business and Commerce Code § 552.103(b)(1)).

Identify the Data and the Permissions

List what can reach the vendor: uploads, attachments, connected email and file accounts, employee records, customer data, source code and information held under someone else’s confidentiality agreement. Possession of a record does not grant permission to share it with a new provider. Personal data brings in the TDPSA, biometric identifiers bring in the biometric statute, and health information may bring in the Health Insurance Portability and Accountability Act (HIPAA). Confidential business information brings in trade secret law, because protection depends on reasonable measures to keep it secret (Civil Practice and Remedies Code § 134A.002(6)).

Read the Binding Terms

Identify every document that governs the service: the order form, master terms, data processing addendum and any policies incorporated by link. Record the versions, how conflicts are resolved and whether the vendor can change terms unilaterally. Then check:

  • whether inputs or outputs may be used to train or improve models, and how to turn that off;
  • retention and deletion periods, including for logs and backups;
  • access by affiliates, subprocessors and support staff;
  • security commitments and incident notice;
  • rights in inputs and outputs;
  • infringement indemnities, warranties, liability caps and exit terms.

Where the TDPSA applies and the vendor acts as a processor, the contract must contain the terms Business and Commerce Code § 541.104(b) lists, such as processing instructions, confidentiality, deletion or return, information to demonstrate compliance and flow-down to subcontractors. Label those as required; label the rest as business requests. AI Vendor Contracts covers terms in depth.

Test Claims and Consequences

Test the tool with authorized material, including incomplete inputs, false premises and requests outside its scope. Decide how wrong or unsupported answers will be caught before anyone relies on them. If the business will describe the tool’s accuracy to customers, substantiate the claim first. The Attorney General’s 2024 assurance with Pieces Technologies, which had advertised a clinical hallucination rate below one in 100,000, required clear disclosure of how accuracy metrics are calculated and barred unsubstantiated accuracy claims.

Assign Review and Keep Useful Records

Name who approves the use, who administers access and who reviews output. Keep the approved scope, key settings, contract version, test results and material changes. A complete archive of every prompt is not automatically the right answer: retain what the business needs and what preservation duties require. See AI Conversations Are Records.

Revisit

Reassess when the vendor changes models or terms, when a new integration is enabled or when the use expands. The NIST AI Risk Management Framework organizes these steps into govern, map, measure and manage functions. It is voluntary, and following it does not by itself establish compliance with any statute, but TRAIGA names NIST’s Generative AI Profile in one of its defenses (Business and Commerce Code § 552.105(e)(2)).

Real Example

Pieces Technologies (Texas Attorney General, 2024). The Attorney General treated marketed accuracy metrics for a clinical AI product as a DTPA matter and resolved the investigation with disclosure and substantiation commitments running through 2029. A business adopting a health or high-stakes AI tool should ask the vendor how its own metrics were calculated.

Questions to Ask

  • What task is approved, and who may change it?
  • What information reaches the vendor through uploads or connected accounts?
  • Which terms restrict training, access, retention and later use?
  • Who can test, reject or correct a result before it is relied on?
  • What change would trigger a new review?

Sources