
Most DFW business owners can't tell you, with any real confidence, which AI tools their people used last week. That's not a knock on anybody. It's just where things stand in the summer of 2026. The tools showed up faster than the policies did, and for a lot of organizations the honest answer to what AI are we running is some version of more than we've written down.
That gap carries new weight in Texas. The Texas Responsible AI Governance Act, usually shortened to TRAIGA, has been on the books since January 1, and the state is now standing up the machinery to enforce it. For leaders around North Texas, this is the rare compliance story that is less about buying something new and more about finally seeing what you already have.
What Texas changed, and the date that actually matters
TRAIGA took effect on January 1, 2026, putting Texas among the first states with real guardrails around how businesses develop and deploy AI. The good news for operators is that the final law is narrower and friendlier than the early drafts. It targets intentional misuse, things like using AI to discriminate against a protected class, manipulate behavior or infringe on someone's constitutional rights, rather than punishing ordinary productivity tools. Enforcement sits entirely with the Texas Attorney General. There is no private right of action, and you get a 60-day window to cure a problem before the AG can pursue it.
So why is this surfacing now instead of back in January? The statute requires the Attorney General to have a consumer complaint portal live on its website by September 1, 2026. That is the date worth circling. Once people have an easy way to file a complaint, most observers expect enforcement to pick up. The penalties give that some teeth. Uncurable violations run from $80,000 to $200,000 each, and violations that drag past the cure period can add $2,000 to $40,000 a day. The law has been in force all year. September is simply when the path to a complaint gets paved, which is exactly why summer is the right time to get your house in order rather than the fall.
Shadow AI is the exposure most leaders cannot see
Here is where it gets practical. The thing most likely to create a problem under TRAIGA usually isn't the AI tool your company officially chose. It's the dozen tools nobody chose. The industry has started calling this shadow AI, and it is the natural successor to the shadow IT messes we've been helping organizations untangle for years.
The scale is bigger than most leaders assume. Microsoft's 2025 Work Trend Index found that roughly seven in ten workers have used unapproved AI tools on the job, a number that holds steady across industries and company sizes. IBM's 2025 Cost of a Data Breach Report put a price on the fallout. Breaches involving shadow AI cost organizations about $670,000 more than the average, and one in five breached companies had a shadow AI component. Roughly a third of employees admit to feeding sensitive company information, internal research, financials or employee records, into tools their employer never vetted. None of those people thought they were doing anything wrong. They were trying to finish a report before lunch.
Why Microsoft 365 is where this shows up first
For most DFW businesses, the front line of all this is Microsoft 365. Copilot is genuinely useful, and it is also only as careful as the permissions sitting underneath it. Copilot will happily surface whatever a user already has access to, which means years of loosely shared folders, stale permissions and forgotten files suddenly become searchable with a single prompt. We have a saying about this that we didn't invent but believe completely. Data is the fuel for AI. If the underlying data is a mess, AI doesn't clean it up. It just exposes the mess faster.
That is why we treat AI readiness as a data governance question well before it becomes a licensing question. Tightening permissions, clearing out redundant and obsolete files and knowing where your sensitive information actually lives is unglamorous work. It's also the work that turns Copilot from a quiet liability into the productivity tool it was sold as.
What the law actually expects from you
The reassuring part of TRAIGA is that it doesn't expect perfection. Because liability hinges on intent, the organizations in the strongest position are the ones that can show their work. The legal commentary around the law all points the same direction. Adopt a recognized framework like the NIST AI Risk Management Framework, document the business purpose behind each AI tool, test those tools and keep a record of how you keep an eye on them over time. That paper trail is what builds a safe-harbor-style defense if a complaint ever lands. The short version we give clients is simple. Document the intent, document the testing and document the oversight. You can't prove you meant no harm if you never wrote anything down.
What we would actually do about it
None of this requires a moonshot. It requires visibility and a plan, which happens to be the work we do every day with North Texas organizations. When we sit down with a leadership team on this, the path tends to look the same.
First, we find the shadow AI. SaaS and application discovery inside SPOT Managed IT surfaces which cloud and AI tools your people are actually using, so what are we running stops being a guess and becomes a list. Then we look hard at Microsoft 365, the permissions, the sharing, the data governance and the Secure Score, because that is where the real exposure lives. From there we set guardrails people can actually follow: a plain AI use policy, a set of approved tools and clear lines on what should never be pasted into a public chatbot.
Underneath all of it sits the documentation TRAIGA rewards, mapped to the NIST AI Risk Management Framework so your intent, testing and oversight are written down rather than assumed. Our STARLight visibility layer keeps aging risk, permission drift and AI adoption gaps in view, and our Quarterly Success Reviews give leadership a regular, plain-language read on where things stand. For organizations that want senior leadership on the security and governance side, a fractional CIO or vCISO can own it directly. This is the heart of our SPOT AI Services and AI readiness work, and the philosophy behind it is boring on purpose. Practical AI, smarter IT, stronger business outcomes, with a human keeping watch wherever client data or real money is involved.
A short reality check for leadership
You don't need a big AI project to start. You need honest answers to a handful of questions:
- Could you produce a list today of every AI tool your team is actually using?
- Do you know what your people have pasted into ChatGPT, Copilot or Gemini in the last month?
- If Copilot can read a file, should everyone who can prompt Copilot be able to read it too?
- Have you documented why you use the AI tools you use, and how you test them?
- When did leadership last get a plain-language picture of your AI exposure and your TRAIGA position?
If those questions are hard to answer, that is not a failure. It is just the gap, and the gap is fixable. Most of it comes down to visibility and a few operational habits, not a pile of new software.
Not sure what AI your team is really running, or where you stand on TRAIGA? A short First Look conversation is an easy place to start.
We will help you see your shadow AI exposure across Microsoft 365, employee activity and vendor tools before a complaint or an incident does it for you.
Call (817) 337-0300 or visit www.fulcrumgroup.net.
Frequently Asked Questions
What is the Texas Responsible AI Governance Act (TRAIGA), and does it apply to my business?
TRAIGA is the Texas law governing how businesses develop and deploy artificial intelligence. It took effect January 1, 2026, and applies broadly to organizations that operate in Texas or whose products and services are used by Texas residents, which covers most DFW businesses. The law is enforced only by the Texas Attorney General, focuses on intentional misuse of AI rather than ordinary tools, and gives a 60-day period to cure most violations before enforcement.
Is using Microsoft 365 Copilot or ChatGPT against the law in Texas?
No. TRAIGA does not ban everyday AI tools. It targets intentional prohibited uses, such as using AI to discriminate or manipulate. The real risk for most businesses is not the tool itself but ungoverned use, where sensitive data is exposed and no one can show why a tool was used or how it was tested. The practical answer is to govern and document AI use, not avoid it.
What is shadow AI, and why is it a problem?
Shadow AI is the use of AI tools without IT approval or oversight, the AI-era version of shadow IT. It matters because it is everywhere and largely invisible. Microsoft's 2025 Work Trend Index found that roughly seven in ten workers have used unapproved AI tools at work, and IBM's 2025 Cost of a Data Breach Report found that breaches involving shadow AI cost about $670,000 more than average. You cannot protect or document data flowing to tools you cannot see.
What happens on September 1, 2026?
September 1, 2026 is the date by which the Texas Attorney General must have an online consumer complaint portal live for TRAIGA. The law itself has been in effect since January 1, but once consumers have an easy way to file complaints, enforcement is widely expected to increase. That is why summer is a sensible window for DFW leaders to map their AI use and get their documentation in order.
How does the NIST AI Risk Management Framework help with TRAIGA?
Because TRAIGA liability hinges on intent, being able to show your work is the strongest defense. Documenting your AI program against a recognized standard like the NIST AI Risk Management Framework, including the business purpose of each tool, your testing and your ongoing oversight, supports a safe-harbor-style position if a complaint is filed. In plain terms, document the intent, the testing and the oversight.
How does Fulcrum help DFW businesses get ready for TRAIGA and shadow AI?
Fulcrum starts by finding the shadow AI through SaaS and application discovery inside SPOT Managed IT, then reviews Microsoft 365 permissions, sharing, data governance and Secure Score where the real exposure sits. From there we set a practical AI use policy, build the documentation TRAIGA rewards mapped to the NIST AI Risk Management Framework, and keep risk visible through STARLight and Quarterly Success Reviews. Fractional CIO and vCISO leadership is available for organizations that want senior ownership of AI governance, all through SPOT AI Services and our AI readiness work.


