Texas Enacts AI Governance Laws for Healthcare
Texas signed two AI governance laws in June 2025 that affect healthcare providers and, by extension, insurers and health plans operating in the state. Governor Greg Abbott signed HB 149, the Texas Responsible Artificial Intelligence Governance Act, on June 22, 2025, and signed SB 1188 on June 20, 2025. The two laws take effect on different dates and impose different obligations, but together they create a new compliance environment for AI use in healthcare decisions.
HB 149 establishes a broad statewide framework for responsible AI use across the public sector and selected private-sector applications, including healthcare. It requires a provider that uses AI in relation to a health care service or treatment to disclose that use to the patient no later than the date the service is first provided, or as soon as reasonably possible where the service is an emergency. The law also prohibits developing or deploying AI with the intent to unlawfully discriminate against a protected class, and it says a disparate impact is not by itself enough to show that intent. The subsection after that carves insurance back out: the discrimination section does not apply to an insurance entity providing insurance services where the entity is already subject to Texas statutes on unfair discrimination, unfair methods of competition, or unfair or deceptive acts in the business of insurance. A separate construction clause says nothing in the chapter authorizes any agency other than the Department of Insurance to oversee the business of insurance. Enforcement rests with the Texas attorney general, who has exclusive authority under the chapter, must give 60 days’ notice and a chance to cure, and then sues for civil penalties in court. HB 149 took effect on January 1, 2026.
SB 1188 is narrower and more technical. It allows a health care practitioner to use AI for diagnostic purposes, including recommendations on a diagnosis or a course of treatment. Three conditions attach: the practitioner is acting within the scope of the license, the particular use is not restricted by other state or federal law, and the practitioner reviews every record the AI created against medical-records standards set by the Texas Medical Board. A separate subsection requires the practitioner to disclose that use of AI to patients. The law also imposes a strict data localization mandate, requiring that electronic health records containing patient information be physically maintained in the United States or a US territory. That requirement covers records held by a third-party computing facility or a cloud service provider, not only records on a provider’s own systems. SB 1188 took effect on September 1, 2025, and the storage rule reaches back further than the rest of it: from January 1, 2026 it applies to any record in storage, whenever that record was created.
For insurers the relevance is not all indirect. One definition does the work. SB 1188 writes its duties onto a covered entity and borrows that term from the Texas Medical Records Privacy Act, where the definition names a health care payer outright alongside providers, business associates, and computer management entities. A health plan holding electronic health records for utilization review sits inside Chapter 183. The offshoring rule, the access limits, and the safeguards requirement land on those records the same way they land on a clinic’s. The diagnostic-AI provision runs to practitioners, so a plan does not pick that one up. The sharper constraint on claim decisions is in a third bill from the same session: SB 815 bars a utilization review agent from using an automated decision system to make an adverse determination wholly or partly. The commissioner may audit and inspect a reviewer’s use of these systems at any time, and the exemption written into the section is narrow: it covers administrative support and fraud-detection functions, and stops at the determination. TDI put the same section on its June 2026 list of statutes an insurer’s AI has to satisfy, which is where a carrier is most likely to meet it.
The enforcement design is worth a second look. SB 1188 runs through the attorney general too, with civil penalties scaled by whether the violation was negligent, knowing, or committed for financial gain, plus disciplinary action by the licensing agency after a third violation. That means both internal AI governance and vendor contracts need to account for Texas-specific requirements. If a vendor hosts those records offshore, the covered entity is the one that failed to ensure they stayed in the country, and where the plan is the covered entity that is the plan. Carriers should review their cloud hosting, business associate agreements, and data processing addendums for Texas-covered records.
The broader lesson is that states are moving beyond general AI principles to sector-specific rules. Texas has chosen healthcare as its first detailed target, and insurers should expect the same approach to spread to underwriting, claims, and distribution. Building a governance program that can accommodate state-by-state rules is becoming a necessity, not a luxury. Carriers should also consider whether their AI disclosures and review processes are consistent across states, because inconsistency creates compliance gaps and litigation exposure.
What is not settled is how far the sector-specific approach travels. Texas started with healthcare; underwriting, claims, and distribution are the obvious next targets, and the drafting choices in those bills will decide whether one cross-jurisdiction governance program can absorb them or whether carriers end up maintaining a separate build per state.
Official document
capitol.texas.gov →The instrument itself, issued by a government, court, legislature, or standard-setting body.