Texas Bans Price Optimization in Ratemaking (09/02/2026)

September 2, 2026
Texas Bans Price Optimization in Ratemaking (09/02/2026)
Key Intel / TL;DR
  • Texas Commissioner's Bulletin B-0007-26 declares any use of price optimization in ratemaking unfairly discriminatory under the Texas Insurance Code.
  • Colorado's Attorney General has proposed rules implementing the Colorado AI Act that place obligations on deployers and not only on developers.
  • Baylor Genetics disclosed that the electronic protected health information of 2.8 million patients was exposed in a cybersecurity incident.
  • Nutex Health confirmed that sensitive data was stolen in an August cyberattack across its 27 micro-hospitals and outpatient sites.
  • A new executive order ties import entry filing privileges to CTPAT validation status, moving a voluntary program toward a condition of doing business.

Two regulators moved today on the same underlying question, which is who answers for a decision that a model produced. Texas told insurers that a pricing practice they have run for years violates the Insurance Code, and Colorado proposed rules that put obligations on the organization deploying an AI tool and not only on the company that built it. Both changes land on operators who did not write the algorithm and now own its output.

Top 5 Critical Compliance Alerts

1. Texas Declares Price Optimization Unfairly Discriminatory

The Texas Department of Insurance issued Commissioner’s Bulletin B-0007-26 on September 2, taking the position that any use of price optimization in the ratemaking or pricing process is unfairly discriminatory and violates the Texas Insurance Code. The bulletin frames the test in terms an auditor can actually apply, stating that any practice producing different premium increases for two policyholders with the same risk profile is unfairly discriminatory under Texas law. That standard does not care whether the differentiation came from a pricing team or from a model nobody in the building can explain. JD Supra has the analysis.

Operator Note: The compliance question here is whether you can reproduce, on demand, why two similar customers were quoted differently, and if the answer lives inside a vendor’s model you do not have that evidence.

2. Colorado Proposes AI Act Rules That Reach Deployers

The Colorado Attorney General proposed rules on August 11 to clarify and implement the Colorado AI Act, and the practical effect is to pull deployers into scope alongside developers. Organizations that assumed the obligations sat with whoever built the tool now have to document their own use of it, which is a records problem before it is a technology problem. Most companies deploying AI in hiring, lending, or claims cannot currently produce an inventory of where it is running. JD Supra covers the proposed rules.

Operator Note: Start with the inventory, because every obligation in these regimes assumes you already know which systems make or influence consequential decisions about people.

3. Baylor Genetics Reports 2.8 Million Patients Exposed

The clinical genomics company Baylor Genetics confirmed that the electronic protected health information of 2.8 million patients was exposed in the cybersecurity incident first reported on August 19. Genomic data has no expiry and cannot be reissued the way a card number can, so the downstream obligation created by a breach of this type outlasts the credit monitoring period by decades. Covered entities that sent samples to a clinical lab own a piece of this exposure through their business associate agreements. HIPAA Journal has the disclosure.

4. Nutex Health Confirms Data Stolen in August Attack

Nutex Health, a Houston-based healthcare management company delivering care through 27 micro-hospitals, specialty hospitals, and outpatient facilities, confirmed that sensitive data was stolen during an August cyberattack. A distributed operating model concentrates the compliance exposure at the management company while spreading the patient relationships across dozens of sites, which complicates notification timelines and makes the affected-population count slow to settle. Expect the reported figure to move more than once before the notification window closes. HIPAA Journal has the confirmation.

5. Executive Order Ties Entry Filing Privileges to CTPAT Status

A new executive order overhauls the US Importer of Record framework and conditions entry filing privileges on Customs Trade Partnership Against Terrorism validation status, alongside raised penalties. CTPAT has operated for years as a voluntary program that traded supply chain security commitments for faster clearance, and tying filing privileges to it converts those commitments into a requirement for continued market access. Importers who never pursued validation now have a project with a customs deadline attached. JD Supra has the breakdown.

Operator Note: CTPAT validation is a physical security assessment of your facilities and your vendors’ facilities, so the work here belongs to operations and not to the trade compliance desk alone.

Additional Compliance Alerts

Regulatory Updates

  • SEC proposes modernized rules for registered transfer agents: The Securities and Exchange Commission (SEC) proposed updates to the rules and forms governing transfer agents, which sit in the clearance and settlement chain for registered securities. SEC
  • SEC sets its agenda for the 24-hour trading roundtable: The Commission published panelists and agenda for the September 17 roundtable on preparations for round-the-clock trading, which carries operational and surveillance implications for member firms. SEC
  • Federal court upholds Oregon’s packaging EPR law: In the first constitutional test of a state extended producer responsibility program for packaging, a federal court upheld Oregon’s recycling law on the merits following a five-day trial. JD Supra

Third-Party Risk and Due Diligence

  • SEC charges private fund executives in a Ponzi-like scheme: The Commission charged the former CEO of Novato-based Pacific Private Money Group and the former COO of a subsidiary over a multimillion dollar scheme, a reminder that fund-level diligence is the control that catches this. SEC
  • Rehabilitative care and senior living providers disclose hacking incidents: Multiple North Carolina rehabilitative care practices and skilled nursing providers announced breaches, a segment that typically runs the thinnest security staffing of any covered entity type. HIPAA Journal

Policy and Governance Updates

  • Highlands Oncology Group settles ransomware litigation: The Arkansas-based physician-owned community cancer care and research practice settled the litigation arising from its 2025 ransomware attack, adding to the pattern of provider breaches resolving through class settlement rather than regulator action. HIPAA Journal
  • Quantum computing framed as a present-tense governance issue: Counsel are being advised that the uncertain arrival date for cryptographically relevant quantum computing is itself the governance problem, because waiting for certainty creates the material risk. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)