top of page
  • Facebook
  • Linkedin

New Year, New Texas Rules: Do the AI and Privacy Laws Actually Apply to You?

Store fronts signage displaying store names and information.
Store fronts signage displaying store names and information.

If you run a small or mid-size business in Texas, you've probably heard there's a new AI law on the books. Maybe you've also heard your business might be "exempt" from the state's privacy law and figured that meant you could stop paying attention.

Not quite. Two things changed in Texas recently:

  • The Texas Data Privacy and Security Act (TDPSA), which governs how businesses collect, use, and protect customer data.

  • The Texas Responsible AI Governance Act (TRAIGA), which took effect January 1, 2026, and regulates how AI tools can be built and used in the state.

Most small businesses aren't the target of either law. But "not the target" isn't the same as "not affected." Here are five plain-English questions to ask yourself to figure out where you actually stand.

(Quick note: this isn't legal advice — just a practical starting point. For anything specific to your business, talk to an attorney. We're happy to help with the IT and security side of it.)

1. Do you use AI tools in your business — even ones you didn't "install"?

TRAIGA isn't just about companies building AI. It applies broadly to anyone who "develops or deploys" an AI system while doing business in Texas — and that net is wider than most owners think. If you use an AI chatbot on your website, AI-generated marketing copy, an AI scheduling assistant, or even a CRM with AI features baked in, you're a "deployer."

The law mainly targets specific bad uses — things like AI used to discriminate, manipulate people, or create illegal deepfakes. If you're using mainstream, reputable tools for normal business purposes, you're very unlikely to run into trouble. The takeaway is simpler than the law itself: know what AI tools your business actually uses, and make sure they're not making automated decisions about people (like hiring or lending) without a human checking the work.

2. Do you collect more customer information than a name and email?

This is the real trigger for the privacy law. The TDPSA has a small business exemption (generally, under 500 employees, per the SBA definition), so most ByteBak-sized clients are technically outside its main requirements.

But here's the catch: even exempt small businesses aren't exempt from everything. If you collect "sensitive" data — things like health information, precise location data, or anything related to children under 13 — different rules kick in regardless of your size.

Ask yourself: does your business handle medical details, financial account info, or anything a customer would consider private beyond basic contact info? If yes, it's worth a closer look, exemption or not.

3. Do you ever sell or share customer data with anyone else?

This is the one place the small business exemption doesn't fully protect you. Even exempt small businesses in Texas are required to get a customer's consent before selling their sensitive personal data.

Most local service businesses don't sell customer lists — but "sharing" can be broader than people assume. If you pass customer data to a marketing partner, a data broker, or even a lead-gen tool in exchange for something of value, that can count. Worth a five-minute gut check with whoever handles your marketing.

4. If your data got exposed tomorrow, could you show you tried to protect it?

This is where the AI and privacy laws connect to the everyday IT and security work ByteBak already does for clients. Under the TDPSA, the Texas Attorney General enforces the law and — importantly — has to notify a business and give it a 30-day window to fix a violation before any penalty applies. That's a real opportunity, but only if you'd actually know something was wrong and could act on it quickly.

That means the best protection isn't a legal document — it's the basics: knowing where your customer data lives, who can access it, whether it's backed up, and whether you'd even notice a breach. If you can't answer those confidently, that's a bigger risk than the law itself.

5. Does your IT provider know what tools you're actually using?

New tools get adopted fast — a free AI writing assistant here, a new booking app there — often without anyone looping in whoever handles security. That's normal. But it also means your risk picture can change without you realizing it.

The simplest fix: once a quarter, run through the AI tools and data-sharing relationships your team is actually using and make sure your IT partner knows about them too. It takes fifteen minutes and closes most of the gap between "probably fine" and "actually fine."

Bottom line: most Round Rock and Central Texas small businesses aren't who these laws were written for. But "exempt" isn't the same as "off the hook" — a few of the requirements apply no matter your size, and good data habits protect you whether or not a specific law technically covers you.

If you want a second set of eyes on where your business's data lives and who can get to it, that's exactly the kind of thing we help clients sort out. Reach out to ByteBak Solutions and we'll walk through it together — plain English, no jargon.


Call 737.263.2323, email info@bytebak.net or schedule an appointment

 
 
 

Comments


Contact Us

Thanks for submitting!

ByteBak Solutions, Inc.  Round Rock, TX 78683

© 2025 by ByteBak Solutions, Inc.

Tel. 737-263-2323

bottom of page