AI Acceptable Use Policy for Texas Businesses (Template and TRAIGA Checklist)

An AI acceptable use policy names the AI tools staff may use, the data that can never be pasted into them, and the person who signs off on AI output before a customer sees it. Every other clause in the document exists to support those 3 decisions.

Texas employers got a new reason to write this down. The Texas Responsible Artificial Intelligence Governance Act took effect January 1, 2026, and the statute offers a rebuttable presumption of reasonable care to businesses that substantially comply with a recognized AI risk framework. This guide gives you the 9 sections, a data classification table you can paste in, the controls that make the policy enforceable, and the evidence to file. If you would rather have the whole program built and run for you, start with our managed AI services.

Texas business leadership team reviewing a printed AI acceptable use policy together in a downtown office conference room
Most AI policies fail at the review table, not the drafting table. Decide who owns enforcement before you circulate a draft.

What Is an AI Acceptable Use Policy?

An AI acceptable use policy is a short internal rulebook that defines which artificial intelligence tools employees may use for work, which categories of company and customer data are off limits to those tools, and who is accountable for reviewing AI output before it reaches a customer, a regulator, or a court.

It is not the same document as an AI governance policy, though the 2 terms get swapped constantly. Governance covers the whole program. Model inventories, vendor due diligence, bias testing, board reporting. Acceptable use is the employee-facing slice of that program. It is the part people actually read. Our AI governance and compliance page covers the wider structure this policy plugs into.

It is also not your existing acceptable use policy with the letters AI dropped in. Your old AUP was written for devices and networks. It assumes the threat is somebody installing unlicensed software or streaming video on the guest Wi-Fi. Generative AI flips the direction of travel. Data walks out through a text box, voluntarily, typed by someone who is trying to do a good job faster.

Why January 1, 2026 Changed the Math for Texas Employers

The Texas Responsible Artificial Intelligence Governance Act, better known as TRAIGA or HB 149, took effect on January 1, 2026. It reaches any business that develops or deploys an AI system in Texas, promotes or conducts business in the state, or offers a product or service used by Texas residents. Read the scope twice. That last clause is wide enough to catch a 30-person firm in Sugar Land running Microsoft Copilot on a handful of licenses. You do not have to build AI to be covered. You only have to use it.

The statute is intent-based, so it targets deliberate misuse rather than accidental harm. The Attorney General holds exclusive enforcement authority, must give written notice, and must allow 60 days to cure before filing suit. There is no private right of action. Then the numbers start. A curable violation runs $10,000 to $12,000. An uncurable one runs $80,000 to $200,000, and continuing violations add $2,000 to $40,000 per day. You can read the enrolled text of HB 149 or Baker Botts on what companies need to know for the full scope.

The Detail Almost Every TRAIGA Summary Gets Wrong

Section 552.105 creates a rebuttable presumption that a person used reasonable care, and it lists what earns that presumption. One route is discovering a violation through your own testing, and the statute specifically names adversarial testing and red-team testing. Another is substantial compliance with, in the statute’s own words, “the most recent version of the Artificial Intelligence Risk Management Framework: Generative AI Profile published by the National Institute of Standards and Technology or another nationally or internationally recognized risk management framework.”

Read that carefully. Almost every article we have seen cites the general NIST AI Risk Management Framework. The Texas statute names the Generative AI Profile, catalogued as NIST AI 600-1, which is a separate companion document with its own control list. If your policy header cites a framework, cite that one by name and version. It costs nothing. It is also the exact string a regulator would go looking for.

Worth knowing. TRAIGA also adds sector rules. Healthcare providers using AI in relation to a service or treatment must tell the patient they are interacting with an AI system, no later than the date that service is first provided. Holland & Knight has the healthcare-specific breakdown. Texas practices should read that alongside our HIPAA IT compliance checklist.

What Actually Goes Wrong Without a Policy

The failure mode is not a rogue employee. It is a good one, moving fast, with no rule to check against.

Employee working at a dual monitor desk with an AI chat tool open next to a company spreadsheet
Shadow AI rarely looks like misconduct. It looks like a spreadsheet on one screen and a chat window on the other.

Here is what the record shows.

  • Samsung lifted an internal ChatGPT ban and had 3 separate confidential data leaks within about 20 days, including source code pasted in to debug it. Forbes covered the reinstated ban.
  • IBM’s 2025 Cost of a Data Breach research found that breaches involving a high level of shadow AI cost roughly $670,000 more than average, that 1 in 5 organizations studied had a breach linked to shadow AI, and that 97% of organizations reporting an AI-related breach lacked proper AI access controls. The full report is worth 20 minutes.
  • A British Columbia tribunal held Air Canada liable for a discount its chatbot invented, and rejected the argument that the chatbot was a separate legal entity responsible for its own statements. The American Bar Association write-up is the clearest summary.
  • Courts have now issued more than 1,000 US decisions responding to AI-fabricated citations, and sanctions have climbed from the original $5,000 in Mata v. Avianca to five figures per attorney plus bar suspensions, per Norton Rose Fulbright’s 2026 update.
  • Closer to home, the Texas Attorney General settled with a Dallas healthcare AI company over accuracy claims under the Deceptive Trade Practices Act, before TRAIGA even existed. Read the office’s announcement.

None of those started with bad intent. Not one. Every one of them would have been caught by a 2-page rule and a single review step.

The 9 Sections Your AI Policy Needs

Keep it to 2 or 3 pages. A 14-page policy is a policy nobody finishes. Each section below includes starter language you can adapt, and you should adapt it, because a policy that does not name your actual tools and your actual data is decoration.

1. Scope and Who It Covers

Cover employees, contractors, temporary staff, and interns. Cover company devices and personal devices used for work. Then watch the scope line. The trap is scoping to company-provided tools only, which quietly exempts the exact behavior you are trying to govern. Starter line. “This policy applies to all AI use for company work, regardless of whether the tool was provided by the company or the account is personal.”

2. The Approved Tools List

Name products, not categories. “Approved generative AI platforms” means nothing to a salesperson at 4 pm. “Microsoft 365 Copilot on your work account” means something. Put the list in an appendix so you can update it without reopening the whole policy for signature.

3. Data That Never Goes Into an AI Tool

This is the clause that prevents the Samsung outcome. List the data categories explicitly rather than saying “confidential information,” because everyone privately defines that differently. The table in the next section is built to be pasted here.

4. Human Review Before Anything Leaves

Somebody signs. Require a named person to review AI-assisted output before it goes to a customer, into a contract, into a filing, or into anything safety related. Air Canada lost because nobody owned the chatbot’s answers. Starter line. “The employee who submits AI-assisted work is accountable for its accuracy, the same as work produced without AI.”

5. Disclosure to Customers and Patients

Say when you tell people they are talking to an AI. Texas healthcare providers now have a statutory duty here, and government agencies have their own. Even where disclosure is not required, it is cheaper than explaining later why you hid it.

6. Prohibited Uses

Ban AI as the sole decider in hiring, promotion, termination, lending, and pricing decisions. TRAIGA targets intentional unlawful discrimination, and a model making the call unsupervised is how unintentional turns into indefensible. Also ban using AI to impersonate a real person or generate synthetic media of employees or customers.

7. How to Request a New Tool

Make it fast. If the approval process is slower than the business need, staff will route around it and you will have built shadow AI on purpose. Days, not quarters. A 1-page request form, a named reviewer, and a stated turnaround is enough.

8. Incident Reporting

Define what counts as an AI incident and where it gets reported. Sensitive data pasted into an unapproved tool. AI output that reached a customer and was wrong. A tool that changed its terms. Say plainly that self-reporting within 24 hours will not be punished, because a policy that punishes disclosure buys you silence.

9. Review Cycle and Owner

Name a role, not a person. Then set a review date. Quarterly for the tools appendix, annually for the policy body. Undated policies are the first thing an auditor circles.

The Data Classification Table to Paste Into Section 3

This is the version we hand to Texas clients. Adjust the middle column to your actual contracts, because “enterprise tier” is a marketing phrase and a data processing agreement is not.

Hands sorting orange and navy file folders into separate stacks to illustrate AI data classification tiers
Three tiers is enough. Most policies fail from too many categories, not too few.
Data typeApproved enterprise AIPersonal or free AI accountWhy it matters
Customer names, addresses, contact recordsAllowed with a signed data processing agreementNeverTDPSA duties follow the data wherever it goes
Protected health informationOnly under a business associate agreementNeverHIPAA plus Texas HB 300 both apply
Cardholder and payment dataNeverNeverPCI DSS scope expands to anything that touches it
Passwords, API keys, certificatesNeverNeverPrompt history is a credential store you do not control
Proprietary source codeAllowed for approved code assistants onlyNeverThis is the exact Samsung failure
Unreleased financials, M&A material, board packetsAllowed with a data processing agreement and manager sign-offNeverSelective disclosure and insider trading exposure
Third-party material under NDAOnly if the NDA permits subprocessorsNeverYou can breach a contract by pasting
Published marketing copy, public web contentAllowedAllowedAlready public, no added exposure

Building an Approved Tools List Without Freezing Everyone Out

The instinct is to approve 1 tool and ban the rest. It feels tidy and it reliably backfires, because the banned tools are usually better at something the approved one is not. Approve a small set that covers the real jobs. Writing and summarizing. Code. Meeting notes. Research.

For most Texas SMBs the anchor is Microsoft 365 Copilot, since the tenant boundary and the commitment not to train foundation models on tenant data are already in the agreement you signed. Our Microsoft Copilot deployment services page covers the licensing and permission cleanup that has to happen first, and an AI readiness assessment tells you whether your file permissions can survive Copilot before you turn it on.

For each approved tool, record 4 things in the appendix. The exact product and tier. Who the data processing agreement is with. Whether prompts are used for model training. The date you last checked, because vendors change terms quietly and your policy is only as current as that date.

Enforcement Is the Part Everyone Skips

A policy that says do not paste PHI into a chatbot, with nothing stopping anyone from pasting PHI into a chatbot, is a sign on an open door. It is not a control. This is also where most published AI policy templates stop, which is the whole gap between a document that reads well and a rule that holds.

IT security administrator monitoring dashboards that track AI tool usage across a company network
If you cannot see which AI tools are in use this week, you cannot enforce the policy you just signed.

Here is the control stack we deploy, roughly in order of effort.

  • See it first. Pull the AI domains out of your DNS or secure web gateway logs for the last 30 days. Nearly every engagement turns up tools nobody mentioned in the kickoff.
  • Steer, do not just block. Point the consumer version of a tool at a coaching page and leave the enterprise tenant open. Hard blocks with no alternative push people to their phones, where you have no visibility at all.
  • Force the corporate identity. Conditional Access on the approved tool means work happens in the tenant you can audit, not a personal login.
  • Turn on DLP for Copilot. Microsoft Purview has a policy location for Microsoft 365 Copilot and Copilot Chat that stops it processing files carrying specific sensitivity labels. Microsoft documents the setup here, and label enforcement for commercial tenants with Purview licensing has been rolling out through 2026.
  • Review OAuth grants quarterly. AI browser extensions and note-takers ask for Microsoft Graph consent and then keep it forever. Check Entra ID enterprise applications on a schedule.
  • Log the reviews. The statutory cure period is 60 days. Sixty days is generous if you have records and brutal if you are reconstructing them from memory.

If you want the tenant-side settings that make this stick, our post on the Microsoft 365 security settings Texas SMBs should change covers the configuration layer underneath. Broader monitoring and response sits with cybersecurity solutions.

How to Document the TRAIGA Reasonable Care Presumption

A presumption is only worth what you can produce on request. Paper beats memory. Keep these 7 artifacts in one folder, dated, with version numbers.

ArtifactWhat it evidencesRefresh
Signed policy with version and effective dateA governance program existed before the incidentAnnually
Approved tools register with agreement referencesVendor diligence was performed, not assumedQuarterly
Data classification mapSensitive categories were identified and restrictedAnnually
Human review log for customer-facing AI outputOutput was supervised by a named personContinuous
Adversarial or red-team test notesNamed in the statute as a route to the presumptionSemi-annually
Training completion recordsStaff were informed, so misuse was not sanctionedAnnually
Framework mapping to NIST AI 600-1 controlsSubstantial compliance with a recognized frameworkAnnually

If you want something heavier than a mapping document, ISO/IEC 42001 is the certifiable AI management system standard and qualifies as an internationally recognized framework. Budget 4 to 9 months and a five-figure audit cost, and know that an existing ISO 27001 certification cuts a meaningful chunk of that. For most Texas SMBs under 200 people, the NIST mapping is the right call and 42001 is a later conversation.

Your Cyber Insurance Renewal Will Ask About This

The era of silent AI coverage is ending. In January 2026 Verisk released 2 commercial general liability endorsements, CG 40 47 and CG 40 48, that give carriers ready-made language to carve generative AI claims out of standard coverage. Policyholder Pulse tracks the exclusion language, and carriers are split between clarifying coverage by endorsement and cutting it.

What that means at renewal is simple. The application now asks about AI use. Documented governance is what separates workable terms from sublimits, exclusions, and outright declines. Bring the policy, the tools register, and the training records to the meeting. We have watched brokers move quickly on exactly that packet.

A 30-Day Rollout That Does Not Stall

Policies die in legal review. Every time. Give this one 30 days and a named owner.

Manager leading an AI acceptable use policy training session for staff in a company meeting room
One 30-minute session with real examples beats a policy PDF nobody opens.
WeekWhat happensOwnerEvidence produced
1Pull 30 days of AI domain traffic and survey managers on what their teams actually useITShadow AI inventory
2Draft the 9 sections and the data table, then pick the approved toolsIT with legal reviewDraft policy v0.9
3Turn on Conditional Access, DLP, and gateway steering for the tools you approvedITControl configuration record
4Run a 30-minute all-hands walkthrough using your own near-miss examples, then collect acknowledgementsHR with ITSigned policy and training log

The week 4 session matters more than the document. Far more. Use examples from your own week 1 inventory. People remember “somebody in this room pasted a client list into a free summarizer last month” far longer than they remember a numbered clause.

Mistakes We See in Draft Policies

We review a lot of these, and the same 5 problems show up.

  1. The policy bans AI generally, then lists 1 approved tool nobody has a license for. Staff read that as permission to improvise.
  2. It says “confidential information” without defining it. Ask 5 employees what that includes and you get 5 answers, which is 5 different risk appetites.
  3. It has no incident path, so the first real mistake gets hidden instead of contained.
  4. It cites a framework in the header that nobody has mapped a single control to. That is worse than citing none, because it invites the question.
  5. It was written once and never dated. Model behavior, vendor terms, and Texas law have all moved in the last 18 months.

Honest correction to something we used to advise. Two years ago we told clients to block consumer AI outright and revisit later. That was wrong in practice. Blocking without a sanctioned alternative moved the activity to personal phones, where there is no logging, no DLP, and no chance of catching a problem early. Steering beats banning almost every time.

Find out what your team is already using

We will pull 30 days of AI tool activity from your network, map it against the 9 policy sections above, and hand you a draft policy plus the control list to enforce it. You keep the report whether or not you work with us.

Questions Texas Leaders Ask Before They Sign

Does TRAIGA require my business to have an AI policy?

No. TRAIGA does not mandate a written AI policy for private employers. It prohibits specific intentional uses and gives the Attorney General enforcement authority.

The reason to write one anyway is Section 552.105. Substantial compliance with a recognized risk framework, along with your own testing, supports a rebuttable presumption that you used reasonable care. You cannot claim substantial compliance with nothing written down. A policy is how you get the argument started.

Is Microsoft 365 Copilot safe enough for client data?

For most Texas SMBs, yes, with 1 condition. Copilot inherits your existing file permissions exactly, so it is only as safe as the sharing hygiene underneath it.

The common failure is a folder overshared 3 years ago that nobody ever cleaned up. Copilot will happily surface that content to anyone who asks the right question, and it will do it in seconds instead of never. Audit permissions before you deploy, not after the first surprise.

We already have an acceptable use policy. Can we just add a paragraph?

You can, and it will be thin. Your existing AUP governs devices and network behavior, which is a different risk shape.

A paragraph cannot carry a data classification table, an approved tools appendix with agreement references, a human review requirement, and an incident path. Those are the parts that matter at renewal and in an enforcement conversation. Write the standalone document and reference it from the existing AUP.

Can we just ban AI instead?

You can try. It rarely holds past the first quarter, and it makes your exposure invisible rather than smaller.

When staff have a job to finish and no sanctioned tool, the work moves to a personal phone or a home laptop. Now the data is still leaving, and you have no logs, no DLP, and no way to answer an auditor asking what happened. A narrow approved list is safer than a ban you cannot enforce.

Who should own the policy, IT or legal?

IT owns the tools appendix and the controls. Legal or compliance owns the prohibited uses and disclosure clauses. One named person signs the whole thing.

Split ownership with nobody accountable is the most common reason these documents sit in draft for 6 months. In companies under about 150 people, the practical answer is usually the operations lead holding the pen with IT and outside counsel reviewing.

How often does the policy need updating?

Review the approved tools appendix quarterly and the policy body annually, and update out of cycle whenever a vendor changes its data terms or Texas law moves.

Quarterly sounds aggressive until you watch how fast vendor terms shift. Two of the tools on a typical approved list changed their training and retention language in the last year alone.

Does any of this apply if we only use AI features built into software we already own?

Yes, and this is the most commonly missed case. Meeting transcription, CRM summarization, and inbox drafting are all AI processing of company data.

Those features usually arrive switched on by default in a vendor update, which means no one made a decision about them. Inventory them the same way you inventory standalone tools, and record whether each one processes data outside your tenant.

Where to Start This Week

Pull the last 30 days of AI domain traffic before you write a word. Look first, draft second. The inventory decides everything else, because a policy written against imagined usage governs an imagined company. Then draft the 9 sections, pick your tools, and put the controls in before the all-hands, not after.

Uprite has supported Texas businesses across Houston, San Antonio, and Dallas for over 25 years, and our average response time is just over 5 minutes when something breaks. If AI governance is the piece you want handled end to end, our managed AI services and AI governance and compliance pages cover what that looks like in practice. If data residency and storage rules are also on your list, our guide to the Texas data storage compliance deadline is the companion read.

About Author