Skip to main content

AI Compliance for Houston Businesses & Public Entities

Houston organizations — from energy and enterprise businesses to health systems, hospital districts, and city and county government — face four Texas AI statutes with very different obligations. Here is who owes what.

4 statutes
HB 149 · SB 1964 · SB 1188 · HB 3512
Jan 1, 2026
TRAIGA in force
$200K
max TRAIGA penalty per uncurable violation
NIST AI RMF
TRAIGA safe harbor (§ 552.105(e))

Which Texas AI Laws Apply to Houston Organizations?

The four statutes divide cleanly by entity type:

  • Private businessesTRAIGA (HB 149, effective January 1, 2026) imposes no inventory, assessment, disclosure, training, or reporting mandates. It prohibits specific AI uses under an intent standard (§§ 552.052–.057) and rewards documented governance through the NIST AI RMF safe harbor (§ 552.105(e)).
  • City, county, and other governmental entitiesSB 1964 (effective September 1, 2025) requires DIR ethics-code and minimum-standards adoption, binary HSAI classification (§ 2054.003(6-a)), risk and impact assessments, standardized notices, annual review to DIR, vendor clauses, and an AI Risk Officer (1 TAC § 219.21). HB 3512 adds annual DIR-certified AI training for employees and officials who use a computer for at least 25% of their duties. TRAIGA § 552.051 adds a consumer AI-interaction disclosure duty for government agencies.
  • Healthcare practitionerstwo Texas patient-disclosure duties apply: TRAIGA § 552.051(f) (any AI used in relation to a health care service or treatment; disclose by the first service, emergencies as soon as reasonably possible) and SB 1188 § 183.005(b) (AI used for diagnostic purposes). SB 1188 also requires review of AI-created records under Texas Medical Board standards (§ 183.005(a)(3)) and US data residency for EHRs (§ 183.002).
  • Hospital districtsSB 1964 governmental duties (including the consent-form carve-out at § 2054.711(c)) plus TRAIGA's person-level prohibitions, while being excluded from TRAIGA's government-agency disclosure rule.

Penalties and the NIST AI RMF Safe Harbor

TRAIGA is enforced exclusively by the Texas Attorney General — no private right of action — with a 60-day notice-and-cure period. Penalties run $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for ongoing violations. SB 1188 carries AG penalties of $5,000, $25,000, and $250,000 by tier.

TRAIGA § 552.105(e) recognizes substantial compliance with the NIST AI RMF as a safe harbor — which makes documented, framework-aligned governance the highest-leverage compliance investment a Houston business can make.

How Risk Meridian Helps Houston Organizations

Risk Meridian screens every AI system against the TRAIGA prohibited-use categories, assembles a NIST AI RMF safe-harbor evidence pack, runs SB 1964 HSAI classification and assessments for governmental entities, generates SB 1188 diagnostic-AI patient disclosures, and tracks HB 3512 training completion — all from one inventory.

Frequently asked questions

Do Houston companies have to file or register anything under TRAIGA?

No. HB 149 imposes no registration, filing, audit, or reporting duty on private companies. It prohibits specific AI uses under an intent standard and offers a safe harbor for substantial compliance with the NIST AI RMF (§ 552.105(e)).

What do Houston-area hospital districts owe?

Hospital districts follow SB 1964's governmental framework (including the consent-form carve-out at § 2054.711(c)), their practitioners follow SB 1188's diagnostic-AI duties, HB 3512 training applies to qualifying employees, and TRAIGA's person-level prohibitions apply — though hospital districts are excluded from TRAIGA's government-agency disclosure rule.

Who enforces these laws?

The Texas Attorney General enforces TRAIGA (exclusively, with 60-day notice-and-cure and no private right of action) and SB 1188 ($5,000/$25,000/$250,000 penalty tiers). SB 1964 and HB 3512 compliance runs through DIR — annual review submissions and verified training reporting respectively.

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.