Skip to main content
Adopted — effective March 18, 2026Texas, USA

1 TAC Chapter 219 — The DIR Rules Behind Texas SB 1964

What Texas state agencies — including institutions of higher education — and local governments need to know about the adopted DIR rules that operationalize SB 1964: the statewide AI Code of Ethics, the AI Risk Officer, written risk assessments, impact assessments, and vendor requirements. Adopted February 2026; effective March 18, 2026, with no transition period.

Overview

Chapter 219 of Title 1, Texas Administrative Code is the Department of Information Resources (DIR) rulemaking that operationalizes SB 1964 (Government Code chapter 2054, Subchapter S). The rules were adopted and filed with the Secretary of State on February 26, 2026 and took effect March 18, 2026 — with no transition period; DIR denied a request for 90 additional days. The chapter supplies the operating procedure behind the statute: a statewide AI Code of Ethics covering all AI systems an entity procures, develops, deploys, or uses (§ 219.11) — DIR expressly declined to narrow it to heightened-scrutiny systems — a designated AI Risk Officer with a repeatable process to identify and inventory heightened-scrutiny AI (§ 219.21), a written risk assessment the Risk Officer reviews and approves or denies (§ 219.22), an impact assessment keyed to deployment and material change (§ 219.23 — mandatory for state agencies, advisory for local governments), and acceptable-use, training, and vendor-contract requirements (§ 219.24). Sections 219.11, 219.21, 219.22, and 219.24 changed between proposal and adoption — a program built on the proposed text needs a refresh. Verify specifics against the adopted rule with counsel.

Who must comply?

Chapter 219 reaches Texas state agencies in full — and institutions of higher education are treated as state agencies under Government Code chapter 2054, so a public university carries the whole load. Local governments are reached in limited scope: the adoption preamble ties the local-government provisions to rural communities under Government Code § 2006.001(1-a), and § 219.23(e)(2) makes the impact assessment advisory rather than mandatory for them. Whether a particular county, city, school district, or hospital district falls inside the rule’s local-government definitions (§ 219.1) should be confirmed with counsel. The heightened-scrutiny triggers key to the SB 1964 definitions: an AI system specifically intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003), subject to four statutory exclusions.

Key obligations under 1 TAC Ch. 219

What your organization must actually do to comply — broken down by obligation category.

Adopt the Statewide AI Code of Ethics (§ 219.11) — mandatory

The widest obligation in the rule: the Code of Ethics covers all AI systems the entity procures, develops, deploys, or uses — DIR expressly declined to narrow it to heightened-scrutiny systems. It carries testable duties — human review of inputs and outputs, systems that can be paused, restricted, or disabled, accuracy monitoring, a redress mechanism with a point of contact, public-facing disclosure, PII minimization and training, and security testing — plus vendors contractually bound to the ethical principles themselves (§ 219.11(j)(2)(B)), retention schedules with Public Information Act consideration (§ 219.11(j)(3)), and documented periodic evaluations (§ 219.11(k)(2)).

Designate an AI Risk Officer (§ 219.21) — mandatory

A named AI Risk Officer (§ 219.21(a)) — the rule permits assigning the role to an existing employee (§ 219.21(a)(3)); record that election — plus a repeatable process to identify and inventory heightened-scrutiny AI systems (§ 219.21(b)). Retain negative determinations too: they are the evidence the process actually ran.

Written Risk Assessments (§ 219.22) — mandatory per HSAI

Before developing, procuring, deploying, or using an HSAI — and at each material change — a written assessment documenting the probability and severity of potential harm: known security risks and available mitigation steps; performance metrics relating to accuracy and operational efficiency; and transparency, including the algorithms and decision-making, the training data, and the availability of inputs and outputs for ongoing monitoring (§ 219.22(b), as adopted). The Risk Officer reviews pre-deployment, approves or denies, and at minimum notifies the executive head (§ 219.22(c)); the assessment is retained per the applicable records retention schedule (§ 219.22(d)).

Impact Assessments (§ 219.23) — mandatory for state agencies; advisory for local governments

State agencies (and vendors contracting with them) conduct the seven-element impact assessment before deployment and at material change, available to DIR on request — and confidential, exempt from Public Information Act disclosure (§ 2054.708(c)). Local governments are directed only to consider conducting one in alignment with the state-agency requirements (§ 219.23(e)(2)) — it is not a local-government mandate. The four statutory exclusions determine what needs one at all.

AUP, Training & Vendor Clauses (§ 219.24) — mandatory

Identify acceptable use cases and limitations, adopt an acceptable-use policy, and train all employees on it (§ 219.24(b)). Separately, train the narrower population — employees and contractors — who access, use, or manage each HSAI on that system’s risks and mitigations (§ 219.24(c)). Vendor contracts must require an AI risk management framework such as the one published by NIST or a comparable standard (§ 219.24(d)) — the NIST AI RMF is the named example, not the only option.

What is 1 TAC Chapter 219?

It is the DIR rulemaking that turns SB 1964’s statutory duties into an operating procedure — adopted, filed with the Secretary of State on February 26, 2026, and effective March 18, 2026. Government Code chapter 2054, Subchapter S tells entities what they must have — an adopted code of ethics (§ 2054.702), minimum standards for Heightened Scrutiny AI (§ 2054.703), HSAI impact assessments (§ 2054.708), inventory and review entries (§§ 2054.068, 2054.0965), and public disclosures (§§ 2054.707, 2054.711). Chapter 219 tells them how: a statewide Code of Ethics covering all AI systems (§ 219.11), a designated AI Risk Officer with an inventory process (§ 219.21), a written risk assessment with a Risk Officer decision (§ 219.22), an impact assessment keyed to deployment and material change (§ 219.23), and acceptable-use, training, and vendor-contract requirements (§ 219.24). Sections 219.11, 219.21, 219.22, and 219.24 changed between proposal and adoption — a program built on the proposed text needs a refresh.

Mandatory versus advisory — the modal verb is the specification

The adopted rule mixes must, shall, may, should, and strive within adjacent subsections — and the modal verb is the specification. Mandatory artifacts include the Code of Ethics adoption (§ 219.11(a)), the AI Risk Officer designation and HSAI inventory process (§ 219.21(a)–(b)), the written risk assessment with the Risk Officer decision and retention (§ 219.22(a)–(d)), the acceptable-use policy with all-employee training (§ 219.24(b)), HSAI-specific training for employees and contractors (§ 219.24(c)), the vendor risk-framework clause (§ 219.24(d)), vendors bound to the ethical principles (§ 219.11(j)(2)(B)), retention schedules with Public Information Act consideration (§ 219.11(j)(3)), and documented periodic evaluations (§ 219.11(k)(2)). Advisory items include the local-government impact assessment (§ 219.23(e)(2)) and data-source and modification records (§ 219.11(l)(2) — a should, and cheap defensibility). Treating every line as equally Required overstates some duties and understates others; a defensible program records which modal verb each obligation carries.

The seven-element impact assessment (§ 219.23(b))

Adopted without change from the proposal, § 219.23(b) prescribes seven elements: (1) a description of the system, including training data, model, and intended use; (2) how the entity will use it and who is responsible for deployment and for ongoing monitoring and evaluation; (3) whether it processes or stores personally identifiable information — provided by the entity or by users — and if so whether that information is used to train the model; (4) potential risks of unlawful harm and the steps available to limit them; (5) identified system limitations; (6) how output will be monitored for accuracy and harm, and the intervals at which monitoring occurs; and (7) the retention duration for inputs and outputs, and the method for deleting outputs after the retention period. The completed assessment is confidential and exempt from Public Information Act disclosure (§ 2054.708(c)) — a meaningful protection that does not extend to general AI-system records kept under § 219.11(j)(3).

The vocabulary trap: heightened scrutiny vs. TRAIGA-lineage terms

Many Texas institutions drafted internal AI policies in TRAIGA-lineage vocabulary — “high-risk,” “substantial factor,” “algorithmic discrimination,” with long excluded-technology lists inherited from the HB 149 line. Chapter 219 and SB 1964 key to a different vocabulary: “heightened scrutiny,” “controlling factor,” “unlawful harm,” and a four-item exclusion set (narrow procedural task; improving the result of a completed human activity; preparatory task; detecting decision patterns or deviations). The practical problem: an inventory classified under “substantial factor” does not map cleanly onto an impact-assessment trigger keyed to “controlling factor.” Whoever does the classification has to reconcile the two — and that written reconciliation, system by system, is exactly the artifact an auditor or DIR reviewer would ask for.

The exclusion analysis is where the effort goes

The heightened-scrutiny definition excludes systems intended only to perform a narrow procedural task, improve the result of a completed human activity, perform a preparatory task, or detect decision patterns or deviations (§ 2054.003). Applied honestly, those four exclusions take a large share of ordinary agency and campus AI — transcription tools, formatting assistants, search, document classification, plagiarism detection used to inform a human review — out of heightened scrutiny. Documenting which systems fall outside the definition, and why, is the difference between a handful of impact assessments and dozens. The written exclusion rationale is as important as the assessments themselves.

Where institutions of higher education fit

Institutions of higher education are treated as state agencies under Government Code chapter 2054 — so a public university carries the full state-agency tier: the AI and HSAI inventory (§ 2054.068), the information-resources deployment review with per-system purpose, risk-mitigation, and strategic-plan-support evaluation plus the compliance confirmation (§ 2054.0965(b)(6)–(7)), impact assessments (§ 2054.708), disclosures (§§ 2054.707, 2054.711), and the Chapter 219 workflow on top. At the same time, TRAIGA expressly excludes institutions of higher education from its “governmental entity” definition (Bus. & Com. Code § 552.001(3)) — so a university’s TRAIGA posture and its SB 1964/Chapter 219 posture are different questions with different vocabularies. Likely heightened-scrutiny candidates on a campus: admissions application triage, financial-aid packaging, student-conduct screening, and clinical decision support at an academic health center. Confirm scope with counsel.

Adopted with no grace period — and no DIR forms coming

The rules took effect March 18, 2026 with no transition window — DIR denied a 90-day implementation extension — so an entity that has not yet designated an AI Risk Officer or adopted the Code of Ethics is currently out of conformance. DIR also declined to publish assessment forms or templates, a statewide governance repository, or a shared platform for small entities, stating that neither the rule nor the statute requires them: each entity supplies its own format and system of record. Two questions remain genuinely open — precisely which local governments the rule reaches (§ 219.1; the adoption preamble describes a limited scope keyed to Government Code § 2006.001(1-a)), and whether the hospital consent-form statement under Government Code § 2054.711(c) also satisfies the rule’s § 219.11(g)(2)(C) disclosure duty. Confirm both with counsel before relying on them.

How Risk Meridian helps

Meet 1 TAC Ch. 219 requirements with Risk Meridian

Risk Meridian’s TX Govt Compliance module implements the Chapter 219 workflow end to end: an AI Risk Officer designation record (§ 219.21(a)); a process view for identifying and inventorying heightened-scrutiny systems, with an HSAI determination and written rationale against the § 2054.003(6-a)(A)–(D) definition and its four exclusions for every system — negative determinations included, because they are the evidence the process ran; versioned § 219.22 risk assessments covering known security risks and available mitigations, performance metrics relating to accuracy and operational efficiency, and algorithm and training-data transparency, each closed by the AI Risk Officer deployment decision — approve or deny, with executive-head notification (§ 219.22(c)); and § 219.23(b) impact assessments — mandatory for state agencies and institutions of higher education, advisory for local governments (§ 219.23(e)(2)) — kept confidential per § 2054.708(c). The module also keeps the wider § 219.11 record: the Acceptable Use Policy with all-employee training (§ 219.24(b)), per-HSAI risk training for employees and contractors (§ 219.24(c)), a Code-of-Ethics obligations checklist with per-obligation status and evidence across § 219.11(c)/(e)/(f)/(g)/(h)/(i) covering all AI systems, recurring periodic evaluations (§ 219.11(k)(2)), AI-records retention with Public Information Act consideration (§ 219.11(j)(3)), advisory data-source records (§ 219.11(l)(2)), and both vendor clauses — the risk-framework clause (§ 219.24(d)) and the separate ethical-principles clause (§ 219.11(j)(2)(B)). A Classification Crosswalk report reconciles TRAIGA-lineage policy vocabulary (high-risk, substantial factor) with the Chapter 219 triggers (heightened scrutiny, controlling factor) system by system, with a written reconciliation rationale — the artifact the vocabulary seam otherwise leaves missing. Obligations render as Mandatory or Advisory to match the adopted rule’s modal verbs — advisory items are never flattened to Required. Chapter 219 is adopted and effective March 18, 2026; verify field-level details against the adopted rule and current DIR guidance, and confirm applicability with counsel. Records are kept Encrypted · SSO (Google & Microsoft) · TOTP MFA · RBAC · Tamper-evident audit log. Risk Meridian helps you evidence the workflow; it does not replace legal advice.

What Risk Meridian covers for 1 TAC Ch. 219

  • Adopt the Statewide AI Code of Ethics (§ 219.11) — mandatory

  • Designate an AI Risk Officer (§ 219.21) — mandatory

  • Written Risk Assessments (§ 219.22) — mandatory per HSAI

  • Impact Assessments (§ 219.23) — mandatory for state agencies; advisory for local governments

  • AUP, Training & Vendor Clauses (§ 219.24) — mandatory

1 TAC Ch. 219 — frequently asked questions

Common questions from compliance officers, legal teams, and executives evaluating 1 TAC Ch. 219 compliance obligations.

Is 1 TAC Chapter 219 in effect?
Yes. The rules were adopted and filed with the Secretary of State on February 26, 2026 and took effect March 18, 2026 — with no transition period; DIR denied a request for 90 additional days. Sections 219.1, 219.20, and 219.23 were adopted without changes from the November 7, 2025 proposal, while §§ 219.11, 219.21, 219.22, and 219.24 were adopted with changes — so material quoted from the proposal may be stale. An entity that has not yet designated an AI Risk Officer or adopted the Code of Ethics is currently out of conformance. Confirm specifics against the adopted rule and with counsel.
Does the Code of Ethics apply only to heightened-scrutiny systems?
No — and this is the scope most programs get wrong. § 219.11 covers all AI systems a governmental entity procures, develops, deploys, or uses. During adoption, commenters asked DIR to narrow the code to heightened-scrutiny systems only; DIR declined, noting SB 1964 directed a code of ethics for entities that use AI systems generally. The heightened-scrutiny test governs the per-system assessment workflow — not the reach of the Code of Ethics, the acceptable-use policy, or the entity-wide training duty. An entity with zero HSAI systems still adopts the code, designates a Risk Officer, maintains the inventory process, and trains its employees.
What does the AI Risk Officer actually do?
Under § 219.21(a), the entity designates an AI Risk Officer — the rule permits assigning the role to an existing employee (§ 219.21(a)(3)); record that election — and maintains a repeatable process to identify and inventory heightened-scrutiny AI systems (§ 219.21(b)). Under § 219.22(c), the Risk Officer reviews each written risk assessment pre-deployment, approves or denies based on the identified risks and mitigations, and at minimum notifies the executive head of the decision. In practice the Risk Officer is the named, accountable owner of the assessment record — the person a DIR reviewer or auditor asks for first.
What must the written risk assessment cover?
Per the adopted § 219.22(b), the assessment considers and documents the probability and severity of potential harm across three areas: the system’s known security risks and the mitigation steps available to limit them; the HSAI’s performance metrics relating to accuracy and operational efficiency; and the HSAI’s transparency — its algorithms and how it makes decisions, the data used to train the model, and the availability of inputs and outputs to monitor its decision-making over time. Note the adoption struck the proposal’s enumerated latency, uptime, and error-rate fields in favor of that single accuracy-and-operational-efficiency clause. It is a living document — a material change re-opens it — and it is retained per the applicable records retention schedule (§ 219.22(d)).
Which systems need an impact assessment — and which do not?
Two filters. First, entity type: the impact assessment is mandatory for state agencies — including institutions of higher education — and for vendors contracting with them (§ 219.23; § 2054.708), while local governments are directed only to consider conducting one in alignment with the state-agency requirements (§ 219.23(e)(2)). Second, the heightened-scrutiny test: AI specifically intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003), narrowed by four exclusions — narrow procedural task, improving the result of a completed human activity, preparatory task, or detecting decision patterns or deviations. Applied honestly, the exclusions take much ordinary agency AI out of scope — which is why the documented exclusion analysis matters as much as the assessments. The completed assessment runs before deployment and again at any material change, and is confidential under § 2054.708(c).
Do the Chapter 219 rules apply to public universities?
Institutions of higher education are treated as state agencies under Government Code chapter 2054, so a public university carries the state-agency tier of SB 1964 and the Chapter 219 workflow — while remaining excluded from TRAIGA’s “governmental entity” definition (Bus. & Com. Code § 552.001(3)), which is a separate statute with separate vocabulary. Risk Meridian models exactly that split for Institution of Higher Education organizations. Confirm your institution’s status with counsel.
What do the rules require from vendors?
Two separate contract duties — do not merge them. First, § 219.24(d): vendor contracts must require the vendor to implement an AI risk management framework such as the one published by NIST or a comparable standard — the NIST AI RMF is the named example, not the only acceptable framework. Second, § 219.11(j)(2)(B): vendors must be contractually bound to the entity’s AI ethical principles and any relevant laws or regulations — DIR declined to let vendors substitute their own principles and declined to narrow the clause to Texas law. Separately, SB 1964’s enforcement gives vendors a 31-day cure window, then a further 31 days after a notice of intent to void, after which the agency may void the contract (§§ 2054.709–.710). Contract language and clause tracking become compliance artifacts.
Will DIR publish assessment forms or a template?
No. DIR stated that neither the rule nor the statute requires it to create forms or templates — or requires entities to use one — and it declined requests for a statewide governance repository and a shared platform for small entities as beyond its authority and unfunded by the Legislature. Each entity supplies its own format and system of record; what matters is that the artifacts exist, carry the required content, and can be produced when DIR asks.

Start your 1 TAC Ch. 219 compliance program today

Risk Meridian handles 1 TAC Ch. 219 compliance documentation — plus every other major AI regulation — from a single platform. Start now, first AI system inventoried in under 10 minutes.

Covers 6 AI frameworks simultaneously

Document once — reuse across multiple frameworks

Board governance reports in minutes