AI Governance
What your Texas health system customer will ask about AI disclosure
Two Texas laws put AI disclosure duties on the health care provider, not the vendor. Your health system customer will turn those duties into questions for you, and the answers have to live in the product.
September 29, 2026 · 7 min read

Since January 1, 2026, a Texas health care provider that uses an AI system in relation to a patient's service or treatment has had to disclose that use to the patient no later than the date the service is first provided. That duty comes from House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, which added Section 552.051 to the Business & Commerce Code. It sits on top of Senate Bill 1188, in effect since September 1, 2025, which requires practitioners who use AI for diagnostic purposes to disclose it and to review every record the AI creates.
Neither law puts the disclosure duty on the vendor. The provider owns it, and can only meet it if your product says when AI was in the loop. That is where the questions to you start.
This is advisory, not legal advice. Your counsel reads the statutes for your facts. What follows is how I read the text and what I expect it to produce in a procurement review.
What the two laws actually say
SB 1188 adds Chapter 183 to the Health and Safety Code. Section 183.005 lets a practitioner use AI "for diagnostic purposes, including the use of artificial intelligence for recommendations on a diagnosis or course of treatment based on a patient's medical record," on three conditions: the practitioner stays within the scope of their license, the use is not otherwise restricted by state or federal law, and the practitioner "reviews all records created with artificial intelligence in a manner that is consistent with medical records standards developed by the Texas Medical Board." Subsection (b) then requires the practitioner to disclose that use to patients.
Two other sections in the same chapter matter to vendors. Section 183.002 requires covered entities to keep electronic health records physically in the United States or a U.S. territory, including records held by a third party or cloud provider, and the bill applies that storage rule from January 1, 2026. Section 183.007(a)(2) directs state agencies to ensure that any algorithm or decision assistance tool included in an EHR to assist treatment decisions includes the patient's biological sex as recorded in a dedicated field.
HB 149 is broader. Section 552.051(f) says that if an AI system "is used in relation to health care service or treatment," the provider must give the disclosure to the patient or their personal representative no later than the date the service or treatment is first provided, or as soon as reasonably possible in an emergency. The disclosure must be clear and conspicuous, written in plain language, and free of dark patterns. It may be delivered by hyperlink. The act defines an AI system broadly: any machine-based system that infers from its inputs how to generate outputs such as content, decisions, predictions, or recommendations.
I started from the Phelps summary and checked every point above against the enrolled bill text.
Why a provider duty becomes a vendor question
Health systems push a new statutory duty into intake forms, EHR fields, and vendor questionnaires. The Phelps authors recommend exactly that: EHR fields that record when an AI disclosure was given, whether an AI transcription tool was used, and whether a clinician reviewed AI-generated content, plus vendor contracts that cover "patient disclosure and consent support." I have seen the same pattern in healthcare, fintech, and public safety: the law names the regulated party, and the regulated party turns it into a questionnaire for whoever built the tool.
There is a second reason the questions will reach you. Under Section 552.103 of HB 149, the Texas Attorney General can issue a civil investigative demand and request a description of the system's purpose and intended use, the type of data used to train it, the categories of input data, the outputs, the performance metrics used, known limitations, and the post-deployment monitoring and safeguards in place. A health system cannot answer that list without you. Expect it in the security review, nearly word for word.
The questions to expect
Each question below ties to a line in SB 1188 or HB 149.
- Which of your features meet the act's definition of an AI system, and which of those touch a service or treatment? That scopes Section 552.051(f).
- Which features produce a diagnosis or a recommendation on a diagnosis or course of treatment? That scopes Section 183.005 and its review requirement.
- For a given patient encounter, how do we know AI was used, so we can disclose by the date of service?
- How does a clinician review an AI-created record before it is relied on, and where is that review recorded?
- Where is the patient data physically stored, including by your subprocessors? That is Section 183.002.
- If your tool supports treatment decisions inside the EHR, does it use the recorded biological sex field? That is Section 183.007.
- Can you give us the purpose, training data type, inputs, outputs, metrics, limitations, and monitoring description the Attorney General can ask for?
If your tool captures voiceprints or face geometry to identify a person, expect an eighth question about Section 503.001, the Texas biometric identifier statute, which HB 149 amended.
A vendor-side checklist you can build against
Each item maps to one of those questions. Most of it is logging and state you probably half-have already.
- An AI-use event per encounter. Record the feature, model version, time, and encounter. Without it, the provider cannot show disclosure happened by the date of service under Section 552.051(f).
- A place to record the provider's disclosure. A field or API call that captures that notice was given, how it was delivered (verbally, in writing, or by hyperlink, which Section 552.051(e) expressly allows), and by whom. The disclosure is the provider's act. Your job is to make it recordable next to the AI event.
- Plain-language notice text the provider can adapt. The statute requires plain language with no dark patterns. Give them a one- or two-sentence draft per feature and let their counsel own the final wording.
- A clinician review state on every AI-created record. The record stays a draft until a named clinician reviews it, and you store who, when, and what changed. That supports the Section 183.005(a)(3) review requirement. I wrote about the per-inference record this needs in Build the healthcare AI audit trail before anyone asks for it.
- An emergency path. In an emergency, disclosure can come "as soon as reasonably possible." Surface encounters where AI was used and no disclosure is recorded yet, so the gap gets closed.
- A non-AI fallback. The Texas texts (SB 1188, HB 149) require disclosure, not patient consent. Health systems will still ask what happens when AI is off, unavailable, or declined, and Phelps recommends keeping alternative workflows for exactly that. The product should work with the AI feature disabled for one patient or one clinician.
- A data residency statement. List where records are stored and processed, including subprocessors, for Section 183.002.
- Documentation that answers Section 552.103. Write the seven items in question 7 once and version them with each release.
What the text does not settle
Some questions stay open. Say so in the review.
The two triggers differ. Section 183.005 covers diagnostic use and recommendations on diagnosis or treatment. Section 552.051(f) covers any AI system "used in relation to" a service or treatment, which reads broader. Whether an ambient scribe falls under one, both, or neither is a question for counsel, not your sales deck.
The review standard in Section 183.005 points to medical records standards developed by the Texas Medical Board, and Section 183.012 directs the state agencies to adopt rules as necessary. Track what they publish. Your review state may need to change with it.
Section 552.051(f) also borrows the disclosure described in subsection (b), which was written for government agencies telling people they are interacting with an AI system. How a provider words that notice for a clinical tool is their call.
Start with question 3. Pull your feature list, mark every feature whose output lands in a record or a treatment decision, and check whether you can tell a provider, for one specific encounter, that AI touched it. If you cannot, that is the first ticket.