Overview
The Texas Capture or Use of Biometric Identifier Act (CUBI), codified as Texas Business & Commerce Code Chapter 503, regulates the capture, use, storage, and destruction of biometric identifiers by commercial entities operating in Texas. Chapter 503 was added by the Legislature's Business & Commerce Code recodification act (Acts 2007, 80th Leg., Ch. 885, H.B. 2278) and took effect April 1, 2009. The provision was then amended in 2009 by H.B. 3186 (signed June 19, 2009, amendments effective September 1, 2009), in 2017 by S.B. 1343, and in 2025 by H.B. 149.
CUBI predates the current AI regulation wave, and for years it sat largely dormant. That changed dramatically beginning in 2022, when the Texas Attorney General brought the first enforcement actions under the statute — and again on January 1, 2026, when the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, House Bill 149) took effect and amended CUBI to carve most AI model development out of its consent rules. As a result, CUBI today is best understood in two layers: the long-standing biometric-consent regime, and a new AI exemption that narrows when that regime applies. The most consequential implication is summarized in The HB 149 (TRAIGA) AI Amendment below.
Key requirements:
- Informed consent before capturing biometric identifiers
- Restrictions on disclosure to third parties
- Reasonable care in storing and protecting biometric data
- Destruction within one year of when the purpose for collection expires
- Prohibition on selling biometric identifiers
Important change (effective Jan. 1, 2026): HB 149 added a statutory AI exemption to CUBI. The capture and consent rules now do not apply to the training, processing, or storage of biometric identifiers used to develop, train, evaluate, disseminate, or otherwise offer AI models or systems, unless the system is used or deployed to uniquely identify a specific individual. A separate carve-out covers AI used for security, fraud, and identity-theft purposes. HB 149 also tightened consent in one respect: the mere existence of an image or other media on the internet or another publicly available source is not, by itself, notice or consent to capture the biometric identifier it contains. See The HB 149 (TRAIGA) AI Amendment.
The HB 149 (TRAIGA) AI Amendment
On June 22, 2025, Governor Greg Abbott signed House Bill 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA). Among other things, HB 149 amended CUBI's core provision (Section 503.001), and those amendments took effect January 1, 2026. This is the single most important update to CUBI since enactment for anyone working with AI.
What the amendment does
Before HB 149, the common reading was that any commercial system capturing or using a covered biometric identifier (including AI-powered facial recognition or voice systems) had to satisfy CUBI's notice and consent rules. HB 149 amended Subsections (a) and (e) of Section 503.001 and added new Subsections (b-1) and (f). It narrowed the consent rules with two new exemptions, and it tightened them with a new rule on publicly available images (covered below). The two exemptions:
1. AI development and training exemption. CUBI's capture/consent restrictions do not apply to the training, processing, or storage of biometric identifiers involved in developing, training, evaluating, disseminating, or otherwise offering an artificial intelligence model or system, unless the system is used or deployed for the purpose of uniquely identifying a specific individual.
2. Security and fraud-prevention exemption. CUBI's capture/consent restrictions also do not apply to the development or deployment of an AI model or system for purposes such as preventing, detecting, protecting against, or responding to security incidents, identity theft, fraud, harassment, malicious or deceptive activities, or other illegal activity; preserving the integrity or security of a system; or investigating, reporting, or prosecuting those responsible.
The "uniquely identify a specific individual" trigger
The AI development exemption is conditional. The moment an AI system is used or deployed to uniquely identify a specific individual, the exemption falls away and ordinary CUBI obligations apply again. In practice:
- Likely exempt: Using face or voice data to build, train, fine-tune, evaluate, or host a general AI model, provided the resulting system is not identifying particular people.
- Likely NOT exempt: Running facial recognition, facial verification, or speaker identification to determine who a specific person is. That is "uniquely identifying a specific individual," and CUBI's notice and consent rules still apply (unless a separate exemption, such as the security/fraud carve-out, applies).
Publicly available images are not consent
The amendment did not only loosen CUBI. New Section 503.001(b-1) provides that an individual has not been informed of, and has not consented to, the capture or storage of a biometric identifier based solely on the existence of an image or other media containing the identifier on the internet or another publicly available source, unless the individual made the image or media publicly available. Scraping faces or voices from the public web therefore does not create consent. The rule bears directly on face-identification systems built from scraped photos, which also fall outside the AI development exemption because they are deployed to uniquely identify specific individuals.
What did NOT change
The amendment narrows when consent is required; it does not repeal CUBI. The statute's other duties continue to apply to non-exempt activity, and they can re-attach to AI-training data that is later put to a non-exempt commercial purpose. Reasonable-care storage obligations, the disclosure/sale restrictions, the one-year destruction rule, and the $25,000-per-violation penalty all remain in force. If biometric identifiers gathered under the AI-development exemption are subsequently used to uniquely identify individuals (or otherwise deployed for a non-exempt commercial purpose), CUBI's full obligations apply to that use.
Who It Applies To
Persons (Entities)
CUBI applies to any person (defined broadly to include corporations, partnerships, associations, and other legal entities) that captures, possesses, or uses biometric identifiers for a commercial purpose in connection with Texas residents.
Commercial Purpose Requirement
CUBI's consent and handling requirements apply when biometric identifiers are collected for a commercial purpose, subject to the HB 149 AI exemptions described above. Common commercial uses include:
- Employee time-and-attendance tracking
- Customer identity verification
- Access control systems
- AI-powered facial recognition deployed to identify specific individuals in retail or services (note: training such a model may be exempt, but deploying it to identify people is not)
- Voice authentication for financial transactions
Exemptions
Section 503.001(e) contains exactly three statutory exemptions:
- AI model development: the training, processing, or storage of biometric identifiers used to develop, train, evaluate, disseminate, or offer AI models or systems, unless the system is used or deployed to uniquely identify a specific individual (added by HB 149, effective Jan. 1, 2026)
- AI for security and fraud purposes: developing or deploying AI to address security incidents, identity theft, fraud, harassment, malicious or deceptive activity, or other illegal activity (added by HB 149)
- Voiceprint data retained by a financial institution or an affiliate of a financial institution as those terms are defined under the Gramm-Leach-Bliley Act (15 U.S.C. § 6809), a financial-institution carve-out tied to GLBA-covered entities, not a general "fraud prevention" exception
CUBI has no healthcare or scientific-research exemption, a common misreading imported from Illinois BIPA, whose definitions do carve those out. A healthcare provider or research institution capturing biometric identifiers for a commercial purpose is subject to CUBI like anyone else.
Two further limits come from the statute's structure rather than an express carve-out:
- Capture that is not for a commercial purpose, including capture by or on behalf of a law enforcement agency, falls outside the consent rule because that rule applies only to capture "for a commercial purpose." The statute's only express law-enforcement provision is a disclosure exception, which requires a warrant.
- Photographs, voice recordings, and video recordings are generally understood to fall outside the definition of "biometric identifier" unless used to extract a covered identifier. This is an interpretive reading of the definition, not a listed exclusion.
Biometric Identifiers Covered
CUBI covers the following biometric identifiers:
| Identifier | Examples |
|---|---|
| Retina or iris scan | Eye-scanning biometric systems |
| Fingerprint | Time clocks, device authentication, physical access control |
| Voiceprint | Voice authentication, speaker recognition systems |
| Record of hand geometry | Hand scanners for access control |
| Record of face geometry | Facial recognition, facial verification, emotion detection |
Exclusions
The definition of "biometric identifier" is a closed list: only the five identifier types in the table above are covered. Photographs, voice recordings, and video recordings are generally understood to fall outside that list unless they are used to extract a covered identifier, an interpretive reading of the definition, not an express statutory exclusion.
The only data-type exemption the statute states expressly is for voiceprint data retained by a financial institution or its affiliate under the Gramm-Leach-Bliley Act (15 U.S.C. § 6809). CUBI contains no exclusion for data captured for healthcare purposes or for scientific research.
Note: As of January 1, 2026, the activities of training, processing, and storing biometric identifiers to develop AI models or systems are also exempt from CUBI's capture/consent rules unless the system uniquely identifies a specific individual. See The HB 149 (TRAIGA) AI Amendment.
Consent & Notice Requirements
Informed Consent
Before capturing a biometric identifier for a non-exempt commercial purpose, the collecting entity must inform the individual and receive the individual's consent to the capture. Unlike Illinois BIPA, CUBI does not explicitly require the consent to be written, but obtaining written or electronic consent is strongly recommended as evidence of compliance.
Because of the HB 149 amendment, the threshold question is now whether the activity is exempt at all: training or building an AI model is generally exempt, while deploying a system to uniquely identify a specific individual is not and therefore triggers these notice and consent duties.
No Specific Notice Format
CUBI does not prescribe a specific format for notice or consent. However, best practices include:
- Clear written notice that biometric data will be collected
- Description of what biometric identifiers will be captured
- Explanation of the purpose of collection
- Documented consent (electronic checkbox, signed form, or equivalent)
Publicly Available Images Are Not Consent
Since January 1, 2026, Section 503.001(b-1) makes clear that the mere existence of an image or other media containing a biometric identifier on the internet or another publicly available source is not notice or consent, unless the individual made it publicly available. Consent must come from the individual; it cannot be inferred from a photo being public. See The HB 149 (TRAIGA) AI Amendment.
Law Enforcement Capture
CUBI contains no express consent exception for law enforcement. Capture by or on behalf of a law enforcement agency falls outside the consent rule only because that rule applies to capture "for a commercial purpose." The statute's one express law-enforcement provision is a disclosure exception: identifiers may be disclosed by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
Retention & Destruction
Destruction Deadline
Biometric identifiers must be destroyed within a reasonable time, but not later than the first anniversary (one year) of the date the purpose for collecting the identifier expires. There is one statutory exception (Section 503.001(c-1)): if the identifier is used in connection with an instrument or document that another law requires to be maintained for a longer period, destruction is due within one year after the date that instrument or document is no longer required to be maintained.
The default one-year rule is notably shorter than Illinois BIPA's three-year retention window, making Texas CUBI's destruction requirements more aggressive. These possession and destruction duties continue to apply even where the original collection was exempt as AI development: for example, once biometric identifiers are repurposed for a non-exempt commercial use, the destruction clock and other duties attach.
What Triggers the Clock
The destruction deadline starts when the purpose for collection expires, for example:
- An employee leaves the company (for time-and-attendance fingerprints)
- A customer closes their account (for facial verification data)
- A vendor contract ends (for access control biometrics)
For biometric identifiers an employer collects for a security purpose, Section 503.001(c-2) presumes the purpose expires when the employment relationship ends.
Scope of Destruction
Destruction must cover:
- The original biometric identifier
- All copies and backups
- Derived templates or mathematical representations
- Data held by third-party processors
Disclosure Restrictions
Prohibition on Sale
CUBI prohibits the sale, lease, or other disclosure of biometric identifiers unless one of four narrow exceptions in Section 503.001(c)(1) applies:
- The individual consents to the disclosure for identification purposes in the event of the individual's disappearance or death; general consent to disclosure is not an authorizing basis
- The disclosure completes a financial transaction that the individual requested or authorized
- The disclosure is required or permitted by a federal statute or a state statute other than Chapter 552, Government Code (the Texas Public Information Act)
- The disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant
Third-Party Sharing
Because the statutory exceptions are this narrow, routine sharing of biometric identifiers with technology vendors, processors, or affiliates does not fit neatly under any of them; the statute does not recognize general consent as a basis for disclosure. Organizations using cloud-based biometric processing services should assess whether each transfer constitutes a disclosure under Section 503.001(c) and structure vendor arrangements accordingly, rather than relying on consent language to authorize the transfer.
Penalties & Enforcement
Attorney General Enforcement Only
Unlike Illinois BIPA, CUBI does not provide a private right of action. Only the Texas Attorney General can bring enforcement actions for CUBI violations.
Civil Penalties
| Violation | Maximum Penalty |
|---|---|
| Per violation | $25,000 |
The AG may also seek:
- Injunctive relief
- Civil investigative demands
- Consent decrees
Notable Enforcement
| Entity | Action | Year | Details |
|---|---|---|---|
| Meta (Facebook) | AG lawsuit | 2022 | Settled for $1.4 billion on July 30, 2024 over capturing facial geometry of millions of Texans without consent through Facebook's "tag suggestions" feature, the largest settlement ever obtained from an action brought by a single state |
| AG lawsuit / settled | 2022 → 2025 | Settled for $1.375 billion; the AG announced the settlement agreement on May 9, 2025 and finalized it on October 31, 2025. Resolved CUBI biometric claims (voiceprints and facial geometry captured via Google Photos, Google Assistant, and Nest Hub Max) alongside geolocation and Incognito claims | |
| Meta (AI Glasses) | AG investigation / CID | 2026 | On May 20, 2026, the AG announced an investigation and issued a Civil Investigative Demand to Meta over its Meta AI Glasses, citing always-on video processing, collection of facial geometry from bystanders, and the planned "Name Tag" facial-recognition feature |
The Meta and Google resolutions together represent the two largest privacy settlements ever obtained by a single state, with Meta's $1.4 billion edging out Google's $1.375 billion.
Increased Enforcement Trend
The Texas AG's office significantly increased biometric privacy enforcement from 2022 onward, signaling that CUBI, once considered dormant, is now actively enforced against major technology companies. Enforcement has continued past the settlements: the May 2026 Meta AI Glasses investigation shows the AG applying CUBI to wearable AI devices that capture bystanders' facial geometry. The HB 149 amendment narrows the consent rules for AI development, but it does not blunt enforcement against systems deployed to identify specific individuals without consent.
Compliance Steps
-
Inventory biometric collection points. Identify every system capturing biometric identifiers: fingerprint scanners, facial recognition cameras, voice authentication, AI-powered identity verification, and access control systems.
-
Classify AI uses against the HB 149 exemptions. For each AI use, determine whether it is exempt model development/training or non-exempt deployment to uniquely identify a specific individual. Document the classification; it determines whether CUBI's notice and consent rules apply at all. Watch for downstream repurposing of training data into identification, which removes the exemption.
-
Implement consent workflows for non-exempt uses. Before capturing any biometric identifier for a non-exempt commercial purpose, provide clear notice and obtain the individual's consent. Document consent electronically for each individual. Do not treat the public availability of a photo, recording, or other media as consent; Section 503.001(b-1) rules that out unless the individual made it publicly available.
-
Review the commercial purpose and exemptions. Confirm that your biometric data collection is for a commercial purpose (triggering CUBI) and check whether any of the three statutory exemptions applies (AI development, AI security/fraud, or GLBA financial-institution voiceprints). Do not assume a healthcare, research, or general law-enforcement exemption; none exists in the statute.
-
Set destruction timelines. Configure systems to destroy biometric identifiers within one year of when the purpose for collection expires. This is shorter than BIPA's timeline; audit retention periods accordingly. These duties can apply even to data initially gathered under the AI-development exemption once it is repurposed.
-
Audit third-party sharing. Review all vendor and processor agreements involving biometric data. CUBI's disclosure exceptions are narrow and do not include general consent, so assess whether each transfer fits one of the Section 503.001(c)(1) exceptions, and ensure vendors have destruction obligations.
-
Implement security safeguards. Store biometric identifiers using reasonable care and in a manner that is the same as or more protective than the manner in which you store other confidential information.
-
Monitor AG enforcement and TRAIGA guidance. Track Texas Attorney General enforcement actions and guidance for evolving interpretation of CUBI and the new HB 149 exemptions, particularly the line between exempt AI training and non-exempt identification.
-
Coordinate with other biometric laws. If you operate across multiple states, coordinate CUBI compliance with Illinois BIPA and other state biometric privacy laws; requirements differ significantly on consent form, retention periods, AI carve-outs, and enforcement mechanisms.
Frequently Asked Questions
What biometric identifiers does CUBI cover? Retina or iris scans, fingerprints, voiceprints, and records of hand or face geometry. Photographs and recordings are generally understood to fall outside the definition unless used to extract one of those identifiers. There is no healthcare or scientific-research exclusion.
Does CUBI have a private right of action? No. Only the Texas Attorney General can enforce CUBI. Individuals cannot file private lawsuits, unlike under Illinois BIPA.
How does CUBI compare to Illinois BIPA? Both regulate biometric data, but BIPA allows private lawsuits with statutory damages while CUBI is AG-enforced only. CUBI requires destruction within one year (vs. BIPA's three years). BIPA requires written consent; CUBI requires informed consent without specifying written form. CUBI also now contains an AI-development exemption (HB 149) that BIPA does not.
Does CUBI apply to AI systems? Not uniformly anymore. Effective January 1, 2026, HB 149 (TRAIGA) exempts the training, processing, and storage of biometric identifiers used to develop, train, evaluate, disseminate, or offer AI models or systems, unless the system is used or deployed to uniquely identify a specific individual. So building or training an AI model with biometric data is generally exempt, but deploying a system that identifies specific people (e.g., facial recognition or speaker identification) still triggers CUBI's notice and consent rules, subject to a separate security/fraud carve-out.
What are the destruction requirements? Biometric identifiers must be destroyed within a reasonable time, not later than one year after the purpose for collection expires. If the identifier is used with an instrument or document that another law requires to be kept longer, destruction is due within one year after that retention requirement ends.
How large can CUBI fines be? Up to $25,000 per violation. Aggregated across millions of individual violations, penalties can be enormous: Texas's CUBI-related matters produced the $1.4 billion Meta settlement (2024) and the $1.375 billion Google settlement (2025).
Official Sources
- TX CUBI full text: Business & Commerce Code Chapter 503 (Texas Statutes)
- HB 149 (TRAIGA) enrolled bill text: 89th Legislature (Texas Legislature Online)
- Texas AG: Paxton finalizes $1.375 billion Google settlement (Oct. 31, 2025)
- Texas AG: $1.4 billion Meta settlement, largest ever by a single state (July 2024)
- Texas AG: investigation into Meta AI Glasses (May 20, 2026)
Timeline
Also in The Ledger
Get updates from the register
Regulation changes and new deadlines, by email.