AI Compliance for Dallas Businesses & Public Entities
Dallas hosts corporate headquarters, financial and professional services firms, health systems, and city and county government — and each faces a different mix of the four Texas AI statutes. Here is the breakdown.
- 4 statutes
- HB 149 · SB 1964 · SB 1188 · HB 3512
- 60 days
- TRAIGA cure period after AG notice
- $200K
- max TRAIGA penalty per uncurable violation
- NIST AI RMF
- TRAIGA safe harbor (§ 552.105(e))
Which Texas AI Laws Apply to Dallas Organizations?
Obligations depend on what kind of entity you are, not where in Texas you sit:
- Private enterprises and firms — TRAIGA (HB 149, effective January 1, 2026) imposes no inventory, assessment, disclosure, training, or reporting mandates. It prohibits specific AI uses under an intent standard (§§ 552.052–.057) — including intentional unlawful discrimination against a protected class (§ 552.056), where disparate impact alone is not sufficient to show intent (§ 552.056(c)).
- City, county, and other governmental entities — SB 1964 (effective September 1, 2025): DIR ethics-code and minimum-standards adoption, HSAI classification (§ 2054.003(6-a)), risk and impact assessments, standardized notices, annual review to DIR, vendor clauses, and an AI Risk Officer (1 TAC § 219.21). HB 3512 adds annual DIR-certified AI training for employees and officials using a computer for at least 25% of their duties.
- Healthcare practitioners — SB 1188 (effective September 1, 2025): patient disclosure for diagnostic AI (§ 183.005(b), alongside TRAIGA § 552.051(f) for any AI used in relation to care or treatment), Texas Medical Board-standard review of AI-created records (§ 183.005(a)(3)), and US EHR data residency (§ 183.002).
Penalties and the NIST AI RMF Safe Harbor
TRAIGA enforcement is exclusive to the Texas Attorney General, with no private right of action and a 60-day notice-and-cure period. Penalty bands: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, $2,000–$40,000 per day for ongoing violations. SB 1188 carries AG penalties of $5,000, $25,000, and $250,000 by tier.
§ 552.105(e) makes substantial compliance with the NIST AI RMF a safe harbor — so a documented, framework-aligned governance program is the core of a defensible Dallas AI posture.
How Risk Meridian Helps Dallas Organizations
Risk Meridian screens AI systems against the TRAIGA prohibited-use categories, documents intent and design decisions for the § 552.056 standard, builds the NIST AI RMF safe-harbor evidence pack, and — for public entities — runs SB 1964 assessments, DIR submission packs, and HB 3512 training tracking.
Frequently asked questions
Our Dallas company uses AI in hiring — do we owe TRAIGA disclosures?
No. TRAIGA's disclosure duties reach government agencies (§ 552.051(b)) and health care providers (§ 552.051(f)) — not employment AI, and 'consumer' excludes employment contexts. Your hiring AI remains subject to the intent-based prohibitions — notably § 552.056 — where disparate impact alone is not sufficient to show intent (§ 552.056(c)).
What should a Dallas city or county entity do first under SB 1964?
Adopt the DIR ethics code and minimum standards, classify each AI system under the binary HSAI definition (§ 2054.003(6-a)), run risk and impact assessments, stand up standardized notices and vendor clauses, designate an AI Risk Officer (1 TAC § 219.21), and prepare the annual review to DIR.
What is the realistic penalty exposure under TRAIGA?
After a 60-day notice-and-cure period: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for ongoing violations — enforced exclusively by the Texas Attorney General, with no private lawsuits.
Does the NIST AI RMF safe harbor require certification?
No certification exists or is required. § 552.105(e) turns on demonstrable substantial compliance with the NIST AI RMF — which means documentation: an inventory, risk assessments, controls, and evidence mapped to the framework.
Related resources
Start your AI governance program today
Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.
✓ No credit card ✓ Full platform access ✓ Cancel anytime