Skip to main content

AI Compliance for Austin Businesses & Public Entities

As the state capital and a technology hub, Austin concentrates both sides of Texas AI law: private developers and deployers under TRAIGA, and state agencies and local government under SB 1964 and HB 3512.

4 statutes
HB 149 · SB 1964 · SB 1188 · HB 3512
Jan 1, 2026
TRAIGA in force
Sept 1, 2025
SB 1964, SB 1188 & HB 3512 effective
NIST AI RMF
TRAIGA safe harbor (§ 552.105(e))

Which Texas AI Laws Apply to Austin Organizations?

The split runs between private and governmental deployers:

  • Tech companies and startupsTRAIGA (HB 149, effective January 1, 2026) applies to developers and deployers of AI systems in Texas. It imposes no inventory, assessment, training, or reporting mandates on private companies (the sole private-sector disclosure duty is for health care providers, § 552.051(f)) — it prohibits specific uses under an intent standard (§§ 552.052–.057) and recognizes substantial compliance with the NIST AI RMF as a safe harbor (§ 552.105(e)). HB 149 also created a regulatory sandbox program (Chapter 553) and the Texas AI Council (Chapter 554).
  • State agencies and local governmentSB 1964 (effective September 1, 2025): DIR ethics-code and minimum-standards adoption, HSAI classification (§ 2054.003(6-a)), risk and impact assessments, standardized notices, annual review to DIR, vendor clauses, and an AI Risk Officer (1 TAC § 219.21). HB 3512 requires annual DIR-certified AI training for employees and officials using a computer for at least 25% of their duties. TRAIGA adds the § 552.051 consumer AI-interaction disclosure duty and the governmental prohibitions on social scoring (§ 552.053) and biometric identification without consent (§ 552.054).
  • Healthcare practitionersSB 1188 (effective September 1, 2025): patient disclosure for diagnostic AI (§ 183.005(b), alongside TRAIGA § 552.051(f) for any AI used in relation to care or treatment), review of AI-created records under Texas Medical Board standards (§ 183.005(a)(3)), and US EHR data residency (§ 183.002).

Penalties and the NIST AI RMF Safe Harbor

TRAIGA is enforced exclusively by the Texas Attorney General — no private right of action — with 60-day notice-and-cure. Penalties: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, $2,000–$40,000 per day for ongoing violations. SB 1188 carries AG penalty tiers of $5,000, $25,000, and $250,000.

For Austin builders, the practical takeaway: TRAIGA rewards exactly the engineering-culture artifacts you can generate anyway — documented testing, good-faith audits, and NIST AI RMF-aligned governance evidence.

How Risk Meridian Helps Austin Organizations

Risk Meridian gives startups a lightweight prohibited-use screen and NIST AI RMF safe-harbor evidence pack, and gives agencies and local governments SB 1964 HSAI classification, assessments, DIR submission packs, and HB 3512 training tracking — all from a single AI inventory.

Frequently asked questions

Do Austin startups have TRAIGA paperwork obligations?

No. HB 149 imposes no inventory, assessment, disclosure, training, or reporting mandates on private companies. The obligations are negative — avoid the prohibited uses in §§ 552.052–.057 — and the smart move is building NIST AI RMF safe-harbor evidence (§ 552.105(e)).

What do Austin-based state agencies owe?

SB 1964 duties (ethics code, minimum standards, HSAI classification, assessments, notices, annual DIR review, vendor clauses, AI Risk Officer), HB 3512 annual DIR-certified AI training for qualifying staff, and TRAIGA § 552.051 consumer disclosure plus the §§ 552.053–.054 governmental prohibitions.

What is the TRAIGA sandbox?

HB 149 created a regulatory sandbox program in Chapter 553 and the Texas AI Council in Chapter 554. The sandbox provides a supervised path for testing AI systems; participation is separate from the Chapter 552 prohibitions and safe harbors.

What is the fastest path to a defensible posture?

Screen systems against the prohibited-use categories, document intent and design decisions, and assemble evidence of substantial compliance with the NIST AI RMF — the safe harbor named in § 552.105(e).

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.