Texas's New AI Healthcare Laws: What SB 1188 and TRAIGA Require
Texas is the first state with statutory rules on clinical AI: patient disclosure, documented human review, and real penalties for getting it wrong. Here's what SB 1188 and TRAIGA actually require.
For years, "AI in healthcare compliance" sounded like a topic for a future training update, not this year's. That has changed. As of September 2025, Texas has a statute on the books that directly regulates how clinicians use artificial intelligence in diagnosis and treatment, and a second, broader law took effect January 1, 2026, that extends AI disclosure obligations across the state's healthcare sector. Together, these are the first state-level rules in the country to tell a practicing clinician, in plain statutory language, what they must tell a patient about AI, and what they must personally do before acting on an AI-generated recommendation.
For compliance leads and providers operating in Texas, or anywhere with staff, contractors, or telehealth patients touching Texas, this is no longer a hypothetical. It is a live obligation with a defined effective date, a named enforcement authority, and real financial exposure for getting it wrong.
What Texas's New AI Laws Actually Require
Texas approached AI in healthcare through two separate but related pieces of legislation, and it is worth understanding both, because compliance programs need to satisfy each.
Senate Bill 1188, which took effect September 1, 2025, amended the Texas Health and Safety Code to set conditions on when a healthcare practitioner may rely on artificial intelligence for diagnostic purposes. It applies to practitioners using AI within the scope of their license, certification, or authorization, and it imposes two core obligations:
- Patient disclosure. The practitioner must disclose to the patient that AI technology is being used in their care. The statute does not mandate a single rigid format — disclosure can be delivered verbally or in writing — but it does require that the patient actually be informed, not merely that a policy exist somewhere in the practice's files.
- Documented human review. The practitioner must review AI-generated records and recommendations, consistent with standards set by the Texas Medical Board, before those outputs inform a clinical decision. In practice, this means AI cannot be the sole basis for a diagnosis or treatment decision — a licensed clinician has to look at the output, apply professional judgment, and take responsibility for what happens next.
House Bill 149, the Texas Responsible AI Governance Act (TRAIGA), took effect January 1, 2026, and is the state's broader AI governance framework, covering far more than healthcare. Within it, however, is a healthcare-specific disclosure requirement that reinforces and extends what SB 1188 started: providers using AI systems in the diagnosis, treatment, or preventive care of a patient must disclose that use "clearly and conspicuously," in plain language, without dark patterns designed to bury or obscure the disclosure. That notice must be given no later than the time service or treatment begins, or, in an emergency, as soon as reasonably possible afterward.
TRAIGA is enforced exclusively by the Texas Attorney General, with no private right of action for patients. Before pursuing a penalty, the Attorney General's office is required to give notice and an opportunity to cure a violation within a set window; violations that go uncured, or that are not curable, carry civil penalties that scale with severity, including per-day penalties for ongoing violations. The financial stakes are real enough that "we'll figure out disclosure later" is not a viable compliance posture.
What This Means in Practice for Providers
Reading a statute and operationalizing it are two different exercises, and this is where most of the compliance work actually lives. A few practical implications stand out for healthcare organizations working through this now.
Documentation has to be built into the workflow, not bolted on after. "The practitioner reviewed the AI output" needs to be something the record can demonstrate, not just something that is generally true. That may mean a specific field in the EHR, a checkbox in the diagnostic workflow, or a note template that captures the fact of review — whatever the mechanism, it needs to survive an audit.
Patient-facing disclosure needs an actual owner. Intake forms, informed consent documents, treatment explanations, and patient education materials are the most commonly cited venues for delivering this disclosure, but someone in the organization needs to be responsible for making sure the language is current, that it is actually being presented (not just filed), and that it holds up against TRAIGA's "clear and conspicuous, plain language" standard rather than being buried in boilerplate.
Staff training can no longer treat AI as a back-office IT matter. Front-desk staff, clinical staff, and anyone documenting care need to understand which tools in use at the practice actually trigger a disclosure obligation, what the disclosure needs to say, and what "review" needs to look like in their specific role. This is squarely a compliance training issue, not just a systems configuration issue — and it sits alongside the training organizations already run on patient data handling. Given that many AI clinical tools ingest and process protected health information, it is worth reviewing this alongside existing HIPAA training requirements, since the privacy and security considerations around AI tools and patient data substantially overlap with obligations providers are already required to train on.
For a broader view of where AI disclosure fits alongside the rest of a US healthcare compliance calendar, providers may find it useful to start with a general healthcare compliance training guide before building out an AI-specific policy on top of it.
The First of Many State-Level AI Rules
Texas is not alone in moving on this, and it is unlikely to be the last state to act. California's AB 3030, effective January 1, 2025, took a related but distinct approach, requiring healthcare providers to attach a disclaimer to AI-generated patient communications about clinical information — flagging that the message was AI-generated and explaining how to reach a human provider — with an exception where a licensed clinician has reviewed the content. The details differ from Texas's approach: California's law centers on generative AI in patient communications specifically, while Texas's framework centers on AI used in diagnosis and treatment decisions more broadly. But the direction of travel is the same. State legislatures are no longer waiting for federal guidance to regulate how AI touches the clinician-patient relationship.
For compliance leads, the practical takeaway is to treat this as the opening chapter of an ongoing area, not a one-time policy update. Organizations that build a disclosure and human-review process now — with clear ownership, documentation, and staff training behind it — will be far better positioned as more states introduce their own versions of these rules. Building AI compliance literacy into ongoing staff development, alongside the CPD training your organization already runs, is a reasonable way to keep pace as this area continues to evolve.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


