There is now a state law covering this, and it applies to the business deploying the system.
The Texas Responsible Artificial Intelligence Governance Act took effect on 1 January 2026. It sets out prohibitions and some disclosure duties, covering harmful, misleading and discriminatory uses, and it has particular things to say about biometric data. Which duties apply depends on the use case and on who is deploying the system, and in most of these projects that is you.
Alongside it, the ordinary rules have not gone anywhere. Advertising claims still have to be supportable, and the Federal Trade Commission has already acted against a company over unsupported claims about the accuracy of an AI product. Privacy, employment, health and children's data rules apply by context as they always did.
None of this is legal advice and nothing on this page should be read as it. What it means practically is that the use case gets chosen with the question already asked: does this touch consumers directly, sensitive data, biometrics, hiring, or health. Where the answer is yes, that is a conversation to have with a lawyer before anything is built, and it is better raised at the start than discovered later. No provider can make you compliant.