Most of the Texas Responsible Artificial Intelligence Governance Act is written for state agencies. Read the bill's structure and you'll notice the pattern quickly: prohibited practices for government use of AI, sandbox programs for testing, disclosure duties aimed at agencies interacting with the public. Then, tucked inside Section 552.051, there's a subsection that breaks the pattern entirely. Section 552.051(f) doesn't care whether you're a state agency. If you provide health care services and you use AI in relation to a patient's care or treatment, you have to tell them. That single subsection is, as far as I can tell reading the statute, the only affirmative disclosure duty in TRAIGA that reaches a private business directly.
That distinction matters more than it might look like on a first read. TRAIGA (House Bill 149, signed by Governor Abbott on June 22, 2025, effective January 1, 2026) is codified at Texas Business & Commerce Code Chapter 552, with definitions carried in Chapter 551. A private hospital system, a physician group, a telehealth platform, or a solo behavioral health practice has no general TRAIGA disclosure obligation the way a state agency does under subsections (b) through (e). But the moment that same organization is a "provider" of "health care services" under subsection (a) and it deploys AI in connection with a service or treatment, subsection (f) pulls it into the statute directly. I want to walk through who that reaches, when the clock starts, what "used in relation to" a service or treatment actually covers, and how this sits next to Texas's other AI-disclosure law, SB 1188.
Where 552.051(f) Sits Inside TRAIGA
Section 552.051 is titled "Disclosure to Consumers," and it does two different jobs depending on which subsection you're reading. Subsections (b) through (e) set a general rule: a government agency that develops or deploys an AI system to interact with the public must tell people, clearly and before or at the point of interaction, that they're dealing with AI — and that duty applies whether or not a reasonable person would have figured it out on their own. Subsection (f) is a separate, narrower rule that happens to live in the same section. It doesn't say "government agency." It says "provider," full stop, and it's triggered by the nature of the service (health care), not by the nature of the entity delivering it.
Here's the section broken into its working parts.
| Subsection | What it does |
|---|---|
| (a) | Defines "health care services": services related to human health, or to diagnosing, preventing, or treating a human disease or impairment, provided by an individual licensed, registered, or certified under state or federal law to provide those services |
| (b) | Requires a government agency that offers an AI system for public interaction to disclose that fact before or at the time of interaction |
| (c) | Makes that duty apply even if a reasonable consumer would obviously know they're interacting with AI |
| (d) | Sets the form standard: disclosure must be clear, conspicuous, in plain language, and free of dark patterns |
| (e) | Allows the disclosure to be satisfied through a hyperlink to a separate page |
| (f) | Requires a provider of health care service or treatment involving AI to disclose that fact to the recipient (or their personal representative) no later than the date the service or treatment is first provided, except in an emergency, when disclosure must be made as soon as reasonably possible |
Subsection (f) borrows the form standard from (d) — clear, conspicuous, plain language — but it stands on its own as to who has to comply and when.
Who Must Disclose
The trigger in subsection (a) is built around the individual delivering the service, not the corporate structure around them: a person "licensed, registered, or certified under applicable state or federal law" to provide health care services. In practice that reaches physicians, nurse practitioners, physician assistants, psychologists, licensed counselors, physical therapists, and the facilities and groups that employ or credential them. It is not limited to hospitals or to entities that look like traditional "covered entities" under HIPAA. A solo telehealth practice, a diagnostic imaging center, a behavioral health app staffed by licensed clinicians, and a large integrated health system are all "providers" for purposes of subsection (f) if a licensed professional is delivering the underlying service.
What subsection (f) does not do is limit itself to government-run providers, public hospital districts, or state teaching hospitals. Because it's written around the health care service rather than the government-agency trigger that governs the rest of Section 552.051, a private, for-profit medical group is squarely inside its scope. That's the detail compliance teams miss most often, because it's natural to read "TRAIGA" and assume it's a government-AI statute with a healthcare carve-out for agencies. It's the reverse: subsection (f) is a healthcare-specific disclosure duty that happens not to distinguish between public and private providers at all.
One open question worth flagging for your own compliance review: is the "provider" who owes the disclosure duty the licensed individual, the practice group, or the facility that deployed the AI tool? The statute's language — "the provider of the service or treatment" — points toward whoever is actually delivering care to that patient, which in most settings means the disclosure obligation should be built into the entity's intake and consent workflow rather than left to individual clinician discretion.
When: First Date of Service, and the Emergency Carve-Out
Subsection (f) sets a floor, not a per-encounter requirement: disclosure must reach the recipient, or their personal representative, "not later than the date the service or treatment is first provided." Read against how the rest of health care compliance works — think of how a Notice of Privacy Practices under HIPAA is typically delivered once, at intake, and covers an ongoing relationship — the more defensible reading is that a provider can satisfy subsection (f) with a single disclosure delivered at or before the first encounter where AI is used, rather than repeating it at every visit, so long as the AI use is ongoing and consistent with what was disclosed.
The emergency carve-out matters for exactly the settings you'd expect: emergency departments, urgent care, and any acute clinical situation where obtaining a signature or delivering a notice before treatment isn't realistic. In those cases, the statute doesn't excuse the disclosure. It moves the deadline: disclosure must happen "as soon as reasonably possible" after the fact, which in practice means documenting AI use in discharge materials, follow-up communications, or a post-encounter notice to the patient or their personal representative.
What Counts as AI "Used in Relation to" a Service or Treatment
TRAIGA's definitions provision describes an artificial intelligence system in the now-familiar broad terms used across state AI statutes: a machine-based system that, for an explicit or implicit objective, infers from its inputs how to generate outputs — content, decisions, predictions, or recommendations — capable of influencing a physical or virtual environment. That's intentionally broad, and subsection (f) doesn't narrow it with an exemption for AI that a licensed professional reviews before acting on it, the way some other states' health care AI provisions do. The trigger is use "in relation to" the service or treatment, not reliance on the AI's output without human review.
That points toward a fairly wide practical scope. In my reading, tools that plausibly trigger the subsection (f) duty include:
- Diagnostic support software that flags findings in imaging, pathology, or lab data
- Clinical decision support and treatment-planning algorithms, including dosing calculators
- AI-driven triage tools and patient-facing symptom checkers
- Ambient documentation and scribing tools that generate clinical notes feeding the treatment record
- Behavioral and mental health chatbots or monitoring tools used as part of care
- Robotic-assisted surgical systems with AI-driven guidance
Tools that sit further from the line, and where I'd want a documented rationale rather than an assumption either way, include scheduling and staffing optimization software, coding and billing automation with no clinical decision component, and general practice-management analytics. The statutory anchor is "in relation to health care service or treatment" — administrative AI with no bearing on the clinical encounter is a weaker fit for the duty, but AI embedded in utilization review or prior authorization that actually shapes what treatment a patient receives is a much harder case to argue out of scope.
How 552.051(f) Sits Next to SB 1188
Texas passed two AI-disclosure obligations touching health care within a few months of each other in 2025, and they don't fully overlap. Senate Bill 1188, effective September 1, 2025 — four months before TRAIGA — requires licensed practitioners who use AI for diagnostic purposes to disclose that use to patients and to review AI-generated records consistent with Texas Medical Board standards. TRAIGA's Section 552.051(f), effective January 1, 2026, is broader in the kind of AI use it reaches and more specific about the mechanics of the disclosure itself.
| SB 1188 | TRAIGA § 552.051(f) | |
|---|---|---|
| Effective date | September 1, 2025 | January 1, 2026 |
| Codified in | Texas Occupations Code (practitioner regulation) | Texas Business & Commerce Code Ch. 552 |
| Who it covers | Licensed practitioners using AI for diagnosis | Any "provider" of health care services, individual or entity |
| AI use covered | Diagnostic use specifically | Any AI use "in relation to" a service or treatment |
| Disclosure timing | Not specified in the statute | No later than first date of service; ASAP if emergency |
| Disclosure form | Not specified (statute is silent on method) | Clear, conspicuous, plain language, no dark patterns; hyperlink permitted |
| Enforcement | Texas Medical Board discipline; civil penalties up to $250,000 per violation | Texas Attorney General; no private right of action |
The practical upshot: a Texas physician using an AI diagnostic tool has to satisfy both laws, and they don't automatically satisfy each other. SB 1188 tells you that you have to disclose and review; it doesn't tell you how or when. TRAIGA's subsection (f) fills exactly that gap for anything that counts as a health care service, which is why I'd build one disclosure workflow that's written to satisfy the stricter of the two on every dimension, rather than treating them as separate checkboxes.
Building a Disclosure That Actually Meets the Standard
Subsection (f) borrows its form requirement from subsection (d): the notice has to be clear, conspicuous, and written in plain language, and it can't use dark patterns to bury or obscure it. A hyperlink to a fuller disclosure page is expressly permitted, which gives providers room to handle this through an intake form, a patient portal notice, or a consent document rather than inventing a new communication channel. What won't hold up, in my view, is a disclosure buried in a general terms-of-service document that a patient has to hunt for, or language so generic ("we may use technology to assist your care") that it doesn't actually tell the patient AI is involved.
A defensible disclosure, in practice, names that an AI system is used, describes in plain terms what it's used for (imaging review, documentation, triage, treatment recommendations), and is delivered through a channel the patient will actually see before or at the first encounter where that AI is in use. Where the same tool is used across a patient population consistently, a single intake-stage disclosure, refreshed if the AI use materially changes, is a reasonable way to operationalize the "first date of service" standard without re-disclosing at every visit.
Enforcement: The Attorney General, the Cure Window, and the Penalty Tiers
TRAIGA gives the Texas Attorney General exclusive enforcement authority over Section 552.051 and creates no private right of action, so patients can't bring their own suit for a missed disclosure. Before penalties attach, the statute builds in a cure opportunity: on finding a violation, the Attorney General must give written notice, and the provider gets 60 days to cure the violation and document that it did. Only if the violation isn't cured, or falls into a category the statute treats as uncurable, do civil penalties apply — and the tiers are meaningful: penalties run from $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for a continuing violation. Separately, SB 1188 violations run through Texas Medical Board discipline and carry their own civil penalty range of $5,000 to $250,000 depending on intent and whether protected health information was involved.
A Practical Starting Checklist
Before year-end, a Texas health care provider using any form of AI in clinical care should be able to answer:
- Have we inventoried every AI system touching diagnosis, treatment planning, documentation, or patient-facing triage?
- For each one, has someone made and documented a scope call on whether it's "used in relation to" a service or treatment under 552.051(f)?
- Is our disclosure delivered at or before the first date of service, with a documented emergency-exception process?
- Does the disclosure language pass the clear, conspicuous, plain-language, no-dark-patterns test on its own — not just as part of a longer consent form?
- Have we separately confirmed SB 1188 compliance for any diagnostic AI, since satisfying one statute doesn't automatically satisfy the other?
That kind of AI inventory and risk mapping is foundational work, and it's the same exercise we walk regulated organizations through on our AI risk assessment engagements — because the honest answer for most provider organizations right now is that nobody has mapped which of their clinical tools even contain an AI component, let alone documented whether each one triggers a state disclosure duty. If your organization operates across state lines, it's also worth reading how Colorado's AI Act and New York City's Local Law 144 frame disclosure differently than Texas does — the patchwork is real, and a Texas-only compliance program will not travel.
FAQ
Does TRAIGA's healthcare disclosure duty apply to private practices, or only public hospitals? It applies to both. Subsection (f) is triggered by whether an entity is a "provider" of health care services as defined in subsection (a), not by whether the entity is a government agency. A private physician group is covered the same as a public hospital district.
Do we need to disclose AI use at every single patient visit? The statute requires disclosure no later than the date the service or treatment is first provided. Read alongside how similar health care notices typically work, a single disclosure at first use, refreshed when the AI tool or its role in care changes materially, is the more defensible operational approach rather than re-disclosing every visit.
Does scheduling or billing AI trigger the disclosure requirement? Probably not on its own. The statutory trigger is AI "used in relation to" a health care service or treatment. Purely administrative tools with no bearing on the clinical encounter sit outside that language more comfortably than diagnostic, treatment-planning, or documentation AI does.
Is satisfying SB 1188's disclosure requirement enough to satisfy TRAIGA too? Not necessarily. SB 1188 requires disclosure for diagnostic AI use but doesn't specify timing or format. TRAIGA's Section 552.051(f) adds specific timing (first date of service, or as soon as reasonably possible in an emergency) and specific form requirements (clear, conspicuous, plain language, no dark patterns) that apply to a broader set of AI uses. A disclosure built to satisfy both is safer than treating either as sufficient on its own.
What happens if a provider misses the disclosure requirement? The Texas Attorney General has exclusive enforcement authority and must give written notice with a 60-day cure period before penalties attach. If uncured, or if the violation is treated as uncurable, penalties range from $10,000-$12,000 per curable violation up to $80,000-$200,000 per uncurable violation, plus $2,000-$40,000 per day for a continuing violation.
Texas health care organizations building an AI governance program from scratch shouldn't treat 552.051(f) as an isolated checkbox. It's one piece of a larger obligation to know what AI is actually running inside patient care, and our healthcare and pharma governance work is built around exactly that mapping exercise. If you want a second set of eyes on whether your current disclosure practices would hold up under an Attorney General inquiry, that's a conversation worth having before a complaint forces it.
Last updated: 2026-09-10
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.