The pressure on small and midsize businesses to demonstrate serious AI data security practices is arriving from two directions simultaneously — and most business owners aren’t fully aware of either.
The first is the insurance market. Cyber liability insurers have spent the last eighteen months rewriting their underwriting questionnaires to include specific questions about AI tool use, AI governance practices, and the security controls governing how AI systems handle business data. The businesses that can answer these questions with documented evidence — here is our AI policy, here are our vendor agreements, here is how we control access to AI systems — are getting coverage. The businesses that can’t are getting exclusions, coverage gaps, or premium increases that reflect the elevated risk their AI practices represent.
The second is the Texas regulatory environment. The Texas Data Privacy and Security Act (TDPSA), which took effect in July 2024, imposes specific obligations on businesses processing personal data of Texas residents — obligations that extend directly to AI systems that touch that data. For the large number of Texas small businesses that have deployed AI tools processing customer information without reviewing whether those tools meet state privacy requirements, compliance exposure is already accumulating.
Together, these two pressures are making AI data security for SMBs not just a best practice but a business necessity with direct financial consequences — in insurance costs, in regulatory exposure, and in the growing risk of client and partner relationships that require demonstrated AI security practices before they’re willing to move forward. This article addresses both dimensions and provides a practical framework for closing the gaps that are most likely to cost you.
What Cyber Insurers Are Now Asking About Your AI Practices
The cyber insurance market’s response to AI has been swift and significant. Underwriters who were still writing policies without AI-specific questions in 2023 have largely updated their applications to include a new category of inquiry specifically focused on AI tool use and governance. For small businesses renewing or applying for cyber liability coverage, these questions are no longer hypothetical future requirements — they are current underwriting factors that affect coverage availability, policy terms, and premium pricing right now.
Understanding what insurers are asking — and what the answers reveal about your AI data security posture — is the most practically urgent dimension of this conversation for most SMB owners.
AI Tool Inventory and Oversight: Insurers are asking whether businesses maintain a documented inventory of the AI tools they use, who is responsible for overseeing each tool, and whether that inventory is reviewed and updated on a regular cadence. The underlying underwriting question is whether leadership has visibility into the AI systems operating in the business — because you cannot manage risks you don’t know exist. Businesses that can produce a current, documented AI inventory demonstrate the foundational oversight that underwriters are looking for. Businesses that cannot are flagged as having unknown AI exposure, which underwrites as elevated risk.
AI Acceptable Use Policy: Insurers are asking whether the business has a written policy governing employee AI tool use — specifically whether it addresses which tools are approved, what data may not be shared with AI platforms, and the process for requesting new tool approvals. The existence of a written, communicated policy is one of the most commonly weighted AI governance factors in current cyber insurance underwriting. It signals that the business has thought through AI use as a risk category and has taken steps to manage it — which is meaningfully different from businesses where AI use is entirely unregulated.
Vendor Data Processing Agreements: Insurers are asking whether businesses have reviewed and executed data processing agreements with their AI vendors — particularly Business Associate Agreements for any AI tools processing healthcare-adjacent data, and equivalent contractual data protections for financial and personal data. The inability to confirm that DPAs are in place for AI vendors is increasingly treated as a coverage concern, particularly for businesses in regulated industries where the absence of these agreements creates direct regulatory exposure.
Employee AI Security Training: Insurers are asking whether employees have received training specifically addressing AI data security risks — not just general cybersecurity awareness training, but training that covers the specific risks created by AI tool use with business data. This question reflects the underwriting recognition that the most common AI data loss events are employee-driven rather than attacker-driven, and that training is the most effective control against inadvertent exposure.
AI Incident Response Integration: Insurers are asking whether the business’s incident response plan addresses AI-specific scenarios — including data exposure through AI platforms, AI vendor security incidents, and AI output errors that cause client harm. An incident response plan that doesn’t address AI is increasingly treated as incomplete, particularly for businesses where AI is embedded in customer-facing or data-intensive workflows.
The businesses that answer these questions with documented evidence — actual policies, actual vendor agreements, actual training records — are demonstrating an AI governance posture that underwriters reward with more favorable coverage terms. The businesses that answer “we don’t have that yet” are demonstrating an AI governance gap that underwriters price into the risk, often in the form of exclusions for AI-related incidents or higher deductibles for data breach claims that involve AI tools.
What the Texas Data Privacy and Security Act Requires of SMBs Using AI
The Texas Data Privacy and Security Act adds a layer of legal obligation to the AI data security conversation that is specific to Texas businesses — and that many small business owners in the state haven’t yet fully absorbed into their compliance thinking.
The TDPSA applies to businesses that process the personal data of Texas residents and meet either of two threshold conditions: annual revenue above $25 million, or processing the personal data of at least 25,000 consumers per year (with a lower threshold for businesses that derive more than 50 percent of revenue from selling personal data). For many Texas small businesses with active customer databases, website traffic, or marketing programs, the 25,000 consumer threshold is more accessible than owners realize — and the data processed through AI tools often includes the personal information that triggers TDPSA applicability.
For businesses that fall within the TDPSA’s scope, several provisions are directly relevant to AI data security practices. The Act requires businesses to implement reasonable data security practices commensurate with the volume and sensitivity of personal data they process — a standard that extends to AI systems processing that data. It requires businesses to conduct data protection assessments for certain high-risk processing activities, including activities involving personal data that present a heightened risk of harm to consumers — a category that can include AI-powered profiling, behavioral analytics, and automated decision-making that touches personal data.
The TDPSA also establishes consumer rights — including rights to access, correct, delete, and opt out of certain uses of their personal data — that create operational requirements for businesses whose AI systems make decisions based on consumer data. A business whose AI tool is making automated decisions about customer pricing, service eligibility, or product recommendations based on personal data profiles has a specific obligation to understand and implement the consumer rights framework that applies to those activities.
Enforcement of the TDPSA is handled by the Texas Attorney General, with a 30-day cure period before enforcement action can be initiated — but the existence of that cure period doesn’t make compliance optional. It means businesses that receive a complaint or inquiry have 30 days to address the identified deficiency, not that they can ignore compliance obligations until a complaint arrives. The cost of scrambling to address a compliance gap under that timeline — with legal counsel, remediation costs, and operational disruption — far exceeds the cost of building compliant AI data security practices proactively.
According to the Federal Trade Commission, Texas businesses are also subject to federal data security standards that apply independently of state law — including FTC Act Section 5 requirements for reasonable security practices, HIPAA for health-adjacent businesses, and GLBA for financial services firms. The intersection of federal and state requirements creates a compliance landscape that Texas small businesses using AI need to navigate carefully.
Closing the Gaps: A Prioritized Action Plan for Texas SMBs
For Texas small businesses facing both insurance market pressure and TDPSA compliance requirements, the most productive approach is a prioritized action plan that addresses the highest-consequence gaps first — rather than trying to build a comprehensive AI security program from scratch in a single project.
Priority One — Complete Your AI Vendor Agreement Audit: Review every AI tool your business uses and confirm whether a data processing agreement or equivalent contractual protection is in place. For any AI tool processing personal data of Texas residents, confirm whether the vendor’s DPA addresses TDPSA requirements, including data subject rights and security standards. For any AI tool processing protected health information, confirm whether a Business Associate Agreement is executed. Flag any vendor that cannot or will not provide appropriate data processing agreements — because using a vendor without these protections is an exposure that needs to be addressed either by securing the agreement or replacing the tool.
This audit is the most immediately actionable step because it surfaces the specific tools and relationships that carry the highest documented risk. It also produces the vendor agreement documentation that cyber insurers are asking for on renewal applications.
Priority Two — Build or Finalize Your AI Acceptable Use Policy: Draft a written AI acceptable use policy that covers the categories of tools approved for use with business data, the categories of data that may not be shared with external AI platforms, and the process for requesting new tool approvals. The policy should be simple enough for employees to understand and follow — not a 20-page legal document, but a clear, specific statement of what is and isn’t permitted. Communicate it actively to all employees, document that communication, and build it into onboarding for new hires.
This document addresses the most heavily weighted item on most cyber insurance AI questionnaires and establishes the policy foundation that makes other controls coherent. A security program without a policy is a collection of technical controls without organizational direction.
Priority Three — Conduct a TDPSA Applicability Assessment: Work with legal counsel or a qualified compliance advisor to assess whether your business meets the TDPSA’s applicability thresholds, and if so, what specific obligations apply to your current AI use cases. This assessment should identify any data protection assessments required for high-risk AI processing activities, any consumer rights workflows that need to be implemented, and any AI-specific data handling practices that need to be updated to meet the TDPSA’s reasonable security standard.
Priority Four — Deliver Focused AI Security Training: Schedule a one-hour AI data security training session for all employees — covering the approved AI tools, the prohibited data categories, the rationale for the restrictions, and the process for raising questions or requesting new tool approvals. Document attendance and repeat annually, or when significant policy changes occur. This training is both a genuine security control and a documented evidence item for cyber insurance purposes.
Priority Five — Update Your Incident Response Plan: Review your existing incident response plan — or create one if it doesn’t exist — and add AI-specific scenarios: what to do if an AI vendor experiences a security breach that involves your data, what to do if an employee inadvertently exposes sensitive data through an AI tool, and what to do if an AI system produces an output that causes client harm. Document the plan, ensure relevant personnel know it exists, and test it annually.
Research from CISA’s SMB cybersecurity resources confirms that small businesses implementing documented security programs — including written policies, employee training, and vendor management practices — experience significantly fewer security incidents and recover more quickly from those that occur than businesses without such programs. For Texas SMBs navigating both insurance market pressure and TDPSA compliance requirements, building that documented program around AI data security is both the right security investment and the right business investment.
The Financial Case Is Clear
The cost of building a documented AI data security program for a Texas small business — the vendor agreement audit, the acceptable use policy, the training session, the incident response update — is measured in hours and modest professional fees. The cost of the alternative — an insurance exclusion for an AI-related data breach, a TDPSA enforcement action, or a client relationship lost because the business couldn’t demonstrate compliant AI practices — is measured in multiples of that investment.
AI data security for Texas SMBs has crossed the threshold from optional to financially consequential. The businesses that recognize that reality now and build accordingly will navigate the next generation of AI adoption with confidence. The ones that don’t will eventually pay for that delay in the most expensive way possible — after something goes wrong, when the options are remediation rather than prevention.