Skip to main content

AI Compliance for Dallas Businesses & Public Entities

Dallas hosts corporate headquarters, financial and professional services firms, health systems, and city and county government — and each faces a different mix of the four Texas AI statutes. Here is the breakdown.

4 statutes
HB 149 · SB 1964 · SB 1188 · HB 3512
60 days
TRAIGA cure period after AG notice
$200K
max TRAIGA penalty per uncurable violation
NIST AI RMF
TRAIGA safe harbor (§ 552.105(e))

Which Texas AI Laws Apply to Dallas Organizations?

Obligations depend on what kind of entity you are, not where in Texas you sit:

  • Private enterprises and firmsTRAIGA (HB 149, effective January 1, 2026) imposes no inventory, assessment, disclosure, training, or reporting mandates. It prohibits specific AI uses under an intent standard (§§ 552.052–.057) — including intentional unlawful discrimination against a protected class (§ 552.056), where disparate impact alone is not sufficient to show intent (§ 552.056(c)).
  • City, county, and other governmental entitiesSB 1964 (effective September 1, 2025): DIR ethics-code and minimum-standards adoption, HSAI classification (§ 2054.003(6-a)), risk and impact assessments, standardized notices, annual review to DIR, vendor clauses, and an AI Risk Officer (1 TAC § 219.21). HB 3512 adds annual DIR-certified AI training for employees and officials using a computer for at least 25% of their duties.
  • Healthcare practitionersSB 1188 (effective September 1, 2025): patient disclosure for diagnostic AI (§ 183.005(b), alongside TRAIGA § 552.051(f) for any AI used in relation to care or treatment), Texas Medical Board-standard review of AI-created records (§ 183.005(a)(3)), and US EHR data residency (§ 183.002).

Penalties and the NIST AI RMF Safe Harbor

TRAIGA enforcement is exclusive to the Texas Attorney General, with no private right of action and a 60-day notice-and-cure period. Penalty bands: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, $2,000–$40,000 per day for ongoing violations. SB 1188 carries AG penalties of $5,000, $25,000, and $250,000 by tier.

§ 552.105(e) makes substantial compliance with the NIST AI RMF a safe harbor — so a documented, framework-aligned governance program is the core of a defensible Dallas AI posture.

How Risk Meridian Helps Dallas Organizations

Risk Meridian screens AI systems against the TRAIGA prohibited-use categories, documents intent and design decisions for the § 552.056 standard, builds the NIST AI RMF safe-harbor evidence pack, and — for public entities — runs SB 1964 assessments, DIR submission packs, and HB 3512 training tracking.

Frequently asked questions

Our Dallas company uses AI in hiring — do we owe TRAIGA disclosures?

No. TRAIGA's disclosure duties reach government agencies (§ 552.051(b)) and health care providers (§ 552.051(f)) — not employment AI, and 'consumer' excludes employment contexts. Your hiring AI remains subject to the intent-based prohibitions — notably § 552.056 — where disparate impact alone is not sufficient to show intent (§ 552.056(c)).

What should a Dallas city or county entity do first under SB 1964?

Adopt the DIR ethics code and minimum standards, classify each AI system under the binary HSAI definition (§ 2054.003(6-a)), run risk and impact assessments, stand up standardized notices and vendor clauses, designate an AI Risk Officer (1 TAC § 219.21), and prepare the annual review to DIR.

What is the realistic penalty exposure under TRAIGA?

After a 60-day notice-and-cure period: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for ongoing violations — enforced exclusively by the Texas Attorney General, with no private lawsuits.

Does the NIST AI RMF safe harbor require certification?

No certification exists or is required. § 552.105(e) turns on demonstrable substantial compliance with the NIST AI RMF — which means documentation: an inventory, risk assessments, controls, and evidence mapped to the framework.

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.