AI Acceptable Use & Governance Policy - Texas

Texas Compliance & Regulatory Updated September 27, 2026 Free Word and PDF

AI ACCEPTABLE USE & GOVERNANCE POLICY — TEXAS

Organization: [________________________________]

Policy owner: [________________________________]

Effective date and version: [________________________________]

Approved by and date: [________________________________]

1. Purpose and scope

This Policy governs AI systems developed, procured, deployed or used for [ORGANIZATION NAME]. It applies to employees, contractors and vendors acting for the organization. The organization maintains an inventory, assigns an owner to each system, reviews the proposed use and data, approves controls before deployment, and revisits the decision when the use changes.

An AI system under this Policy is a machine-based system that infers from inputs how to generate outputs such as content, decisions, predictions or recommendations. An internal high-risk tier means the organization requires enhanced review; it is an internal control label, not a statutory classification.

2. Roles and approval

  • Executive sponsor: Approves the policy, risk tolerance and unresolved material risks.
  • AI governance lead: Maintains the inventory and risk register, convenes reviews and tracks corrective actions.
  • System owner: Documents purpose, users, outputs, data, vendors, testing and monitoring; requests approval for material changes.
  • Privacy and legal reviewers: Determine which laws and disclosures apply to the actual actor, activity, data and people affected.
  • Security and technical reviewers: Test security, accuracy, reliability, misuse controls and incident response.

Approval authority and escalation contact: [________________________________]

3. Acceptable use and internal restrictions

Use only approved AI systems and approved data sources for the documented purpose. Do not enter confidential, regulated or personal data into an unapproved service. Verify material outputs before relying on them. Preserve the human decision maker and an appeal or correction path for consequential decisions when the approved use requires one.

The organization prohibits using its AI systems to intentionally encourage physical self-harm, harm to others or criminal activity. It also prohibits developing or deploying systems with intent to unlawfully discriminate against a protected class. These restrictions reflect Tex. Bus. & Com. Code §§ 552.052 and 552.056 and apply alongside the organization's broader conduct rules.

Additional organization-specific prohibited uses: [________________________________]

Permitted tools, accounts and data classes: [________________________________]

4. Intake and risk classification

Before procurement, development or deployment, the system owner completes Appendix A. Review the intended users, outputs, affected people, data, integration, vendor access, misuse paths, error impact, human oversight and foreseeable changes. The governance lead assigns an internal tier of standard or enhanced review and records the reasons.

Enhanced review is required by this Policy for systems used in employment, lending, housing, health care, safety, identity recognition, large-scale profiling, or decisions with a significant effect on an individual. This is an internal review trigger; the legal reviewer separately decides whether a statutory duty applies.

5. Texas legal applicability register

Tex. Bus. & Com. Code Subtitle D, enacted in 2025 and effective January 1, 2026, applies according to § 551.002's Texas business, resident-use or in-state AI development/deployment connections. The legal reviewer records the precise actor and activity before selecting a control. Complete one row per system and keep the current official source and decision with the inventory.

Issue Trigger facts and official source Decision and required action Reviewer/date
Subtitle D Texas connection; developer/deployer role [________________] [________________] [________________]
Government agency consumer interaction or health-care service disclosure under § 552.051 [________________] [________________] [________________]
Intentional harm or unlawful-discrimination prohibition under §§ 552.052, 552.056 [________________] [________________] [________________]
Commercial biometric capture and § 503.001 exceptions [________________] [________________] [________________]
TDPSA controller coverage under § 541.002 and assessment under § 541.105 [________________] [________________] [________________]
Other Texas, federal, sector or out-of-state law [________________] [________________] [________________]

For a government agency making AI available to interact with consumers, § 552.051(b) requires a clear disclosure before or at interaction. A health-care service or treatment provider using AI has the separate disclosure route in § 552.051(f), including its emergency timing rule. Record the actual notice, recipient and delivery evidence if either route applies.

Section 503.001(b) generally requires advance notice and consent for commercial capture of a biometric identifier. Subsection (e) has specific exceptions, including an AI development/training route that does not cover a system used or deployed to uniquely identify a person. Review the full section before applying an exception or setting retention and disclosure controls.

For a controller covered by Chapter 541, § 541.105 requires a documented data protection assessment for listed personal-data activities, including targeted advertising, sale, sensitive-data processing, and profiling with a reasonably foreseeable listed consumer risk. The reviewer records any applicable assessment and links its decision in Appendix A; this Policy's internal review is not a substitute for it.

6. Testing, deployment and monitoring

The system owner documents data provenance, intended and prohibited uses, baseline performance, representative test populations, known limits and foreseeable misuse. Technical and legal reviewers approve tests suited to the system's risk, including accuracy, harmful outputs, bias, privacy, access controls and resilience. Record each finding, owner, remediation and residual risk in Appendix B.

Deploy only after the required reviewers approve. Monitor errors, drift, complaints, security events and changes in data or context. Pause or restrict the system when a material finding exceeds the approved risk tolerance. Reassess before materially changing the model, purpose, data source, vendor or affected population.

7. Vendor, data and incident controls

The owner records each vendor's service, data access, training or retention terms, security evidence, subcontractors, audit rights and exit process. The organization approves external transfer of personal or confidential data only after the applicable legal and contract review.

Report a suspected AI failure, harmful output, unauthorized data disclosure or misuse to [INCIDENT CONTACT] within [HOURS] after discovery. The incident lead preserves evidence, contains the issue, assesses affected people and legal notification routes, assigns corrective actions and records the closure decision. This internal reporting period is an organization rule; legal notification deadlines are determined separately.

8. Training, enforcement and review

Personnel receive training before access and at [FREQUENCY]. Additional training applies to system owners, developers and reviewers. Violations are investigated under [POLICY OR PROCESS]; corrective action may include access limits, retraining, vendor remedy or employment/contract action subject to applicable procedures.

The governance lead reviews this Policy at least annually and after a material legal, system or incident change. The executive sponsor approves revisions. Retain the approved version, inventory, legal decisions, assessments, tests, incidents and training evidence at [RECORD LOCATION] under [RETENTION SCHEDULE].

Appendix A — AI system intake and approval record

Field Completed entry
System, version, owner and vendor [________________]
Purpose, users, outputs and affected people [________________]
Data sources, categories, retention and recipients [________________]
Texas connection and developer/deployer role [________________]
Internal tier and reason [________________]
Applicable law, disclosure, consent and assessment decisions [________________]
Human oversight and correction process [________________]
Tests, limitations and mitigation evidence [________________]
Approval, conditions, reviewers and dates [________________]
Monitoring owner and next review [________________]

Appendix B — Risk and action register

Risk, affected people and evidence Likelihood/impact Control, owner and due date Residual risk and approval
[________________] [____________] [________________] [________________]
[________________] [____________] [________________] [________________]

Sources and references

Texas Legislature, Business and Commerce Code Chapters 551, 552, 503, and 541, accessed September 27, 2026.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
ai_acceptable_use_and_governance_policy_tx.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the Texas version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
September 27, 2026
Citations checked
September 27, 2026
Jurisdiction
Texas
Category
Compliance & Regulatory

Legal authority

  • Tex. Bus. & Com. Code § 551.001(1)
  • Tex. Bus. & Com. Code § 551.002
  • Tex. Bus. & Com. Code § 552.051(b)
  • Tex. Bus. & Com. Code § 552.051(f)
  • Tex. Bus. & Com. Code § 552.052
  • Tex. Bus. & Com. Code § 552.056(b)
  • Tex. Bus. & Com. Code § 503.001(b)
  • Tex. Bus. & Com. Code § 503.001(e)(2)
  • Tex. Bus. & Com. Code § 541.002(a)
  • Tex. Bus. & Com. Code § 541.105(a)

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on September 27, 2026.

Tex. Bus. & Com. Code § 551.001(1) (checked September 27, 2026): ""Artificial intelligence system" means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments."

Tex. Bus. & Com. Code § 551.002 (checked September 27, 2026): "This subtitle applies only to a person who: (1) promotes, advertises, or conducts business in this state; (2) produces a product or service used by residents of this state; or (3) develops or deploys an artificial intelligence system in this state."

Tex. Bus. & Com. Code § 552.051(b) (checked September 27, 2026): "A governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an artificial intelligence system."

Tex. Bus. & Com. Code § 552.051(f) (checked September 27, 2026): "If an artificial intelligence system is used in relation to health care service or treatment, the provider of the service or treatment shall provide the disclosure under Subsection (b) to the recipient of the service or treatment or the recipient's personal representative not later than the date the service or treatment is first provided, except in the case of emergency, in which case the provider shall provide the required disclosure as soon as reasonably possible."

Draft your AI Acceptable Use & Governance Policy - Texas in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.