AI Governance for Fort Worth Businesses: How to Manage Shadow AI Under the New Texas Law
On January 1, 2026, Texas became one of the first states with a law governing how businesses build and use artificial intelligence. It is called the Texas Responsible AI Governance Act, or TRAIGA, and it has been in effect for about seven months. Most Fort Worth business owners we talk to have never heard of it, and that is fair. They have a business to run. But here is the part that connects. While the state was writing rules for AI, the people inside almost every business were already using it, usually without anyone deciding they could. Someone pastes client information into ChatGPT to speed up a proposal. A new hire connects an AI app to the company Microsoft 365 account with two clicks. None of it is malicious, and most of it is invisible to the owner. This post covers what is actually happening, what the new Texas law does and does not require, and a plain four-step way to get your arms around AI before it becomes a problem you did not know you had.
Two things are happening at the same time
To understand why AI governance is suddenly worth your attention, you have to hold two facts side by side. Your team is already using AI, and Texas has decided AI is something the state will now regulate. Neither of those is going away.
Your team is already using AI
The phrase for this is "shadow AI," meaning AI tools people use for work without anyone in charge signing off. It is not a fringe problem. IBM's 2025 Cost of a Data Breach Report, which studied 600 breached organizations, found one in five had a breach linked to shadow AI, and those breaches cost as much as $670,000 more than the average incident. The same report found 63 percent of breached organizations had no AI governance policy at all. The majority of businesses getting hit are flying blind on AI.
This does not happen because employees are careless. It happens because AI makes their jobs easier and nobody gave them an approved way to use it, so they found their own. The most common version we see is not even a website. It is an OAuth permission grant, the "Allow" button you click when an AI app asks to connect to your Microsoft 365 or Google account. One click, and that app can often read email and files. Your team is already using AI. The only real question is whether you are managing it or it is managing you. We covered how this sneaks in in our post on shadow AI risk for Fort Worth businesses, and it is why AI integration and shadow AI management is one of the first things we check when we take over an environment.
Texas now regulates AI, and it starts with disclosure
TRAIGA applies broadly. Per the analysis from law firm Norton Rose Fulbright, it reaches any company that conducts business in Texas, serves Texas residents, or develops or deploys an AI system in the state. Its definition of "AI system" is wider than the chatbots in the news. It covers predictive and recommendation systems too, the kind quietly built into software you may already run. The law is enforced only by the Texas Attorney General, not private lawsuits, and it gives a company 60 days to cure a violation after receiving notice. Civil penalties can reach $200,000 per violation for the most serious cases.
For most businesses, TRAIGA does not hand you a compliance checklist on day one. What it does is prohibit intentionally using AI to discriminate or to push people toward harm, and it adds real disclosure duties in two places that matter here. Government agencies, which in our world includes the water utility districts we support, have to tell people when they are interacting with an AI system. And healthcare providers have to disclose to a patient when AI is used in relation to that patient's treatment. If you run a home health, hospice, or assisted living agency, that is not abstract. That is a new operational requirement tied to how your systems already work.
A four-step framework for governing AI
Governing AI sounds like something only a big company with a compliance department does. It is not. For a Fort Worth business with six or sixty people, it comes down to four steps you can actually work through: find it, set the rules, give people an approved path, and put controls in place. You do not have to do all four this week. You do have to start.
Step one: find what is actually running
You cannot govern what you cannot see, and IBM's numbers show most organizations genuinely cannot. The first move is discovery: checking which third-party and AI apps have been granted access to your Microsoft 365 or Google Workspace tenant, because that OAuth "Allow" button leaves a record most people never look at. It also means a quick, blame-free conversation with your team about the tools they actually use. Nobody is in trouble. You are taking inventory. A proper Shadow AI audit pulls the full list of connected apps, flags which can read your email and files, and tells you what data each can reach. Almost every time we run one, the owner is surprised by something on the list.
Step two: write an AI acceptable use policy people will actually read
Once you know what is running, you decide what should be allowed. An AI acceptable use policy does not need to be twenty pages of legal language. The best ones are two pages a normal person can read in five minutes, answering plain questions: which AI tools are approved, what information must never be pasted into a public AI tool (patient records, client financials, passwords, anything under a confidentiality agreement), and who to ask before trying a new tool. This is also where TRAIGA quietly rewards you. The law includes a safe harbor for companies that catch and fix problems through their own documented review, and a written policy is the foundation of that. A short, clear policy backed by IT strategy and vCIO guidance does more good than a long one nobody opens.
Step three: give people an approved path
This is the step most businesses skip, and the one that actually works. If you tell people they cannot use AI but give them no alternative, they will use it anyway, just more quietly. The fix for shadow AI is not yelling at your team. It is giving them a sanctioned tool that does the same job safely. For the many Fort Worth businesses already paying for Microsoft 365, that path runs through Microsoft 365 and Copilot, configured with data loss prevention, audit logging, and permissions before anyone turns it on. Turned on carelessly, Copilot can surface data across your tenant people were never meant to see, which is what we covered in our breakdown of the Microsoft 365 Copilot SearchLeak flaw. Configured on purpose, it gives your team the speed they were chasing without sending your data to an app you have never vetted.
Step four: put controls and monitoring in place
The last step is the boring one that pays off. IBM found that among organizations with AI-related breaches, 97 percent lacked proper access controls. The single most common thread in AI breaches is that nobody put a fence around what the AI could reach. Controls means limiting which accounts and apps can touch sensitive data, turning on logging so you can see what happened, and reviewing the connected-app list on a schedule instead of once. For a recognized structure to hang this on, the NIST AI Risk Management Framework organizes the work into four plain functions: govern, map, measure, and manage. It is voluntary, it is free, and TRAIGA's safe harbor specifically points to frameworks like it as evidence you are doing the right things. Following it is the difference between hoping you are covered and being able to show it.
Not sure what AI tools are connected to your systems right now? IT Integrations runs Shadow AI audits and builds AI governance for Fort Worth businesses and the surrounding DFW area. Call us at (817) 808-1816 or contact us for a free IT assessment.
What this means for Fort Worth's regulated businesses
AI governance matters more for some businesses than others, and Fort Worth is full of the ones where it matters most: the healthcare corridor around the Medical District and Near Southside, the home health and hospice agencies across Tarrant and Parker counties, the water utility districts, the law and accounting firms holding confidential files. These are exactly the places where an unmanaged AI tool stops being a shortcut and becomes a compliance problem.
Healthcare is the sharpest example. A hospice or home health agency already lives under HIPAA, so patient information has strict rules about where it can go. Drop in a free AI tool that can read a shared mailbox full of patient details and you have a HIPAA exposure no audit will forgive. Add TRAIGA's new duty to disclose to patients when AI is used in their care, and two rulebooks now point at the same systems. That is why we treat AI governance as part of healthcare IT and HIPAA compliance, not a separate project.
It is not only healthcare. A water utility district is a government agency under TRAIGA, so the public-disclosure duty applies to it directly. A law firm in Sundance Square has confidentiality obligations a public AI tool can quietly break. A construction company working out of Weatherford and the surrounding area keeps years of contracts and bid data in the cloud that should never train someone else's model. The pattern holds across every regulated business we support around Fort Worth. The data is the business, and an ungoverned AI tool is a door into it nobody meant to leave open.
What we see when we audit a new client's AI usage
We have been running IT for Fort Worth businesses since 2003, and AI is the newest thing on a list of gaps we see repeat. When we take over an environment and actually look, the findings are consistent, and none of them mean anyone did anything wrong.
The most common is a list of connected apps nobody remembers approving: an AI note-taker somebody tried in a meeting a year ago, still able to read the calendar and join calls, or a tool a former employee linked to their work account that stayed connected after they left. The second is Microsoft 365 Copilot switched on because it came with the license, with none of the data protection or permission work done first, so it can reach across the whole tenant. The third tells the real story: a business quietly running on one person's personal AI account, because that person found something that made their work faster and never mentioned it. They are not being sneaky. They are getting their job done.
We lead with discovery rather than a policy binder because the binder is useless until you know what is happening. Once the list is on the table, the conversation gets practical fast. Most tools stay. A few get shut off. One or two get replaced with an approved version that does the same job without the exposure. That is governance in the real world: not a lecture, not a ban, just a business deciding on purpose how it uses a technology its people already reached for.
Frequently Asked Questions
What is shadow AI, and why should a small business care?
Shadow AI is any AI tool your employees use for work without IT or ownership approving it. It matters for small businesses because the risk scales with the sensitivity of your data, not the size of your company. A ten-person medical billing office handles more regulated information than a hundred-person retailer. IBM's 2025 research found one in five breached organizations had an incident tied to shadow AI, and those breaches cost as much as $670,000 more than average, partly because the exposed data was more likely to include customer personal information. The danger is not that AI is evil. It is that a useful tool quietly connected to your email or files can move sensitive data somewhere you cannot see, and you will not know until something goes wrong.
Does the Texas AI law apply to my small business?
Quite possibly, yes. TRAIGA applies to anyone conducting business in Texas or serving Texas residents, with no small-business exemption in its core duties. For most businesses using ordinary AI tools in good faith, the day-one obligations are limited, mainly the prohibition on intentionally misusing AI to discriminate or cause harm. But two groups have immediate duties: government agencies, including water utility districts, must disclose when the public interacts with an AI system, and healthcare providers must disclose to patients when AI is used in their care. Even if none of that is you today, the law's safe harbor rewards businesses that can show a documented, framework-based approach to AI, so basic governance is worth having regardless. This is general information, not legal advice, and a lawyer can tell you exactly how TRAIGA touches your operation.
Should we just ban AI tools at work?
You can, but it rarely works and usually backfires. A flat ban does not stop people from using AI. It pushes them onto personal accounts and devices where you have zero visibility, which is worse than where you started. What actually reduces risk is giving people an approved, safer path to do what they were already trying to do. For many businesses that means a properly configured tool like Microsoft 365 Copilot, a short list of what is allowed, and a clear rule about what data can never go into a public AI tool. You get the productivity your team is chasing and keep sensitive data inside systems you control. Governed enablement beats prohibition almost every time.
We are a healthcare practice. What does TRAIGA change for us?
The most concrete change is a disclosure duty. Under TRAIGA, healthcare providers must tell a patient, or their representative, when an AI system is used in relation to that patient's treatment. In practice that can often be handled through the intake forms and consents patients already sign, but it has to actually reflect when AI is used, not a vague "we might use technology" line. This sits on top of your existing HIPAA obligations, not instead of them, which is why AI and compliance have to be handled together for a healthcare business. If an AI tool has access to patient information, that is both a HIPAA question and a TRAIGA question, and the safest position is to know exactly which tools touch patient data and to have documented how you govern them.
How do we start if we have no AI policy at all?
Start with discovery, not the policy. Before you write a single rule, find out what is actually connected to your Microsoft 365 or Google environment and what your team is really using. That list is the whole picture, and it usually reframes the conversation. From there, a two-page acceptable use policy that names approved tools and off-limits data types is enough to begin, and you tighten it over time. Most Fort Worth businesses we work with do not have the time or in-house expertise to run discovery cleanly, which is where a managed IT provider comes in. We pull the full connected-app inventory, flag what has access to what, and help you write a policy your team will actually follow.
Next Steps
Two things are true at once for every Fort Worth business right now. Your people are already using AI, and Texas has started regulating it. The businesses that handle this well are not the ones that panic or the ones that ban everything. They are the ones that take a breath, find out what is actually running, decide on purpose what is allowed, give their team a safe way to work, and put a few real controls in place. That is governance, and it is well within reach for a small business. You do not need a compliance department. You need visibility, a short policy, and someone to help you set the controls.
Ready to find out what AI is connected to your business and get ahead of the new Texas law? IT Integrations provides Shadow AI audits, AI governance, and cybersecurity for Fort Worth businesses and the surrounding DFW metro. Call (817) 808-1816 or schedule a free IT consultation today.