AI governance for Texas universities — the full state-agency load
Institutions of higher education are treated as state agencies under Government Code chapter 2054 — carrying the complete SB 1964 and 1 TAC Chapter 219 stack: AI inventory, HSAI determinations, impact assessments, an AI Risk Officer, the IRDR AI questions, and annual certified training. At the same time, TRAIGA expressly excludes institutions of higher education from its governmental entity definition (Bus. & Com. Code § 552.001(3)). Risk Meridian models exactly that split.
Pre-TX-RAMP: preparing our Level 2 package · agency-sponsored provisional certification supports contracting during certification

Entity compliance artifacts — ethics-code and minimum-standards adoptions (§§ 2054.702(c), 2054.703(c)), AI Risk Officer designation (1 TAC § 219.21(a)), and the training compliance certification (§ 2056.002(b)(12)) — from a demo university organization.
The obligation stack
What a Texas university actually owes
Six duties, each with a citation and a work product. The DIR rules implementing this stack (1 TAC Chapter 219) took effect March 18, 2026 with no transition period — verify specifics against the adopted rule and current DIR guidance, and confirm applicability with counsel.
§ 2054.068(b)
AI inventory reported to DIR
The institution’s IT inventory must include its AI systems — including any Heightened Scrutiny AI — reported to the Department of Information Resources.
§ 2054.0965(b)(6)–(7)
IRDR with per-system AI evidence
The information-resources deployment review must inventory deployed AI and HSAI with an evaluation of each system’s purpose, its risk-mitigation measures, and its support of the strategic plan — plus a confirmation of compliance with the § 2054.702 ethics code and § 2054.703 minimum standards. A filing someone signs, backed by per-system evidence.
§ 2054.708 + 1 TAC § 219.23
Impact assessments, before deployment and at material change
Mandatory for state agencies — including institutions of higher education (advisory only for local governments, § 219.23(e)(2)). Each Heightened Scrutiny AI system needs the seven-element § 219.23(b) impact assessment — system description and training data, responsible parties, PII processing and whether it trains the model, unlawful-harm risks, limitations, monitoring intervals, and input/output retention and deletion — confidential and exempt from Public Information Act disclosure (§ 2054.708(c)).
1 TAC §§ 219.21–219.22
AI Risk Officer + written risk assessments
A designated AI Risk Officer with a repeatable process to identify and inventory heightened-scrutiny systems (§ 219.21), and a written risk assessment per system — known security risks and available mitigations, performance metrics relating to accuracy and operational efficiency, and algorithm and training-data transparency (§ 219.22(b), as adopted) — that the Risk Officer approves or denies with notice to the executive head, retained per the records retention schedule (§ 219.22(c)–(d)).
§§ 2054.707, 2054.711
Public-facing disclosure + standardized notice
Two distinct duties: public-facing AI disclosure under the ethics code (with a reasonable-person exception), and the DIR-form standardized notice for AI that is public-facing or a controlling factor in a consequential decision.
§§ 2054.5191, 2054.5193
Annual certified AI training
Employees who use a computer for at least 25% of their duties — plus elected and appointed officers — complete a DIR-certified AI training program annually, with completion verified to DIR and certified in the strategic plan (§ 2056.002(b)(12)).
How Risk Meridian helps
Built for the seam campus policies sit on
One record across both Texas AI vocabularies — the TRAIGA-lineage terms your institutional policy may use, and the SB 1964 / Chapter 219 terms your statutory duties key to.
HSAI determinations with written rationales
Every campus AI system gets a Heightened Scrutiny determination against the § 2054.003(6-a)(A)–(D) definition and its four statutory exclusions, with a written, attributable rationale. Applied honestly, the exclusions take much ordinary campus AI — transcription, formatting, search, document classification — out of heightened scrutiny, and the documented exclusion analysis is the difference between a handful of impact assessments and dozens.
The classification crosswalk your policy office needs
Many institutional AI regulations were drafted in TRAIGA-lineage vocabulary — high-risk, substantial factor, algorithmic discrimination — while the statutory duties key to heightened scrutiny and controlling factor. The Classification Crosswalk reconciles both vocabularies for every system, with a written reconciliation rationale per system: the artifact an auditor asks for at that seam.
Versioned § 219.22/.23(b) assessments
Written risk assessments capture known security risks and available mitigation steps, performance metrics relating to accuracy and operational efficiency, and algorithm and training-data transparency; impact assessments run before deployment and at material change and stay confidential per § 2054.708(c). Chapter 219 was adopted effective March 18, 2026 — verify field-level details against the adopted rule and confirm with counsel.
IRDR AI Answer Set
Per-system uses-AI, heightened-scrutiny, and risk-mitigation answers with the purpose evaluation, strategic-plan-support analysis, and the (b)(7) compliance confirmation drawn from your recorded code-of-ethics and minimum-standards adoptions — assembled from live records rather than a scramble before the filing. Verify field mappings against DIR’s current instrument.
Entity artifacts and training, in one place
The code-of-ethics and minimum-standards adoption records (§§ 2054.702(c), 2054.703(c)), the AI Risk Officer designation (1 TAC § 219.21(a)), the Acceptable Use Policy (§ 219.24(b)), a Code-of-Ethics obligations checklist across § 219.11(c)–(i) covering all AI systems, periodic evaluations (§ 219.11(k)(2)), AI-records retention with PIA consideration (§ 219.11(j)(3)), and three separately tracked training duties — annual DIR-certified (§§ 2054.5191, 2054.5193), all-employee AUP (§ 219.24(b)), and per-HSAI risk training including contractors (§ 219.24(c)) — with the § 2054.5191(e) completion export and § 2056.002(b)(12) certification.
Security posture, stated plainly
Encrypted in transit and at rest; single sign-on with Google and Microsoft (OIDC); TOTP multi-factor authentication with a server-enforced, organization-level required policy; role-based access control; and a tamper-evident, append-only audit log. Hosted on AWS in United States regions; customer data is stored and processed in the United States.

One health score for the whole program — with a governmental-artifacts sub-score that activates for state agencies and institutions of higher education, alongside prohibited-practice clearance, NIST AI RMF alignment, controls completion, and incident posture. Supports your NIST AI RMF safe-harbor posture under TRAIGA § 552.105(e).
Higher-education FAQ
- Is a public university really a "state agency" for Texas AI law?
- Under Government Code chapter 2054, institutions of higher education are treated as state agencies — which means the full state-agency tier of SB 1964 applies: the AI and HSAI inventory (§ 2054.068), the information-resources deployment review with per-system purpose, risk-mitigation, and strategic-plan-support evaluation plus the compliance confirmation (§ 2054.0965(b)(6)–(7)), confidential HSAI impact assessments (§ 2054.708), the disclosure duties (§§ 2054.707, 2054.711), and the 1 TAC Chapter 219 workflow. Confirm your institution’s status and any carve-outs with counsel.
- How does TRAIGA fit, if we are excluded from its definition?
- TRAIGA expressly excludes institutions of higher education from its "governmental entity" definition (Bus. & Com. Code § 552.001(3)) — so TRAIGA’s governmental-entity-only rules, like the consumer-interaction disclosure (§ 552.051(b)), do not bind a university under that chapter. TRAIGA’s general, intent-based prohibitions still apply to persons deploying AI in Texas, and an academic health center’s practitioners face the healthcare disclosure duty (§ 552.051(f)) on their own terms. The practical takeaway: your TRAIGA posture and your SB 1964/Chapter 219 posture are different questions in different vocabularies — Risk Meridian models both, separately, and reconciles them in the Classification Crosswalk. Confirm the specifics with counsel.
- Which campus systems are likely to be heightened scrutiny?
- The trigger is an AI system specifically intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003) — subject to four exclusions (narrow procedural task; improving the result of a completed human activity; preparatory task; detecting decision patterns or deviations). On a campus, the candidates worth a careful look are admissions application triage, financial-aid packaging, student-conduct screening, and clinical decision support at an academic health center. Much of the rest of campus AI — transcription, search, drafting assistants used to inform human work — tends to fall within the exclusions, but the written exclusion rationale is what makes that defensible. Classification is a legal judgment; confirm with counsel.
- How are institutions answering the IRDR AI questions?
- DIR’s deployment-review instrument asks whether reported business applications use AI, whether they involve heightened scrutiny, and what risk-mitigation measures are in place (§ 2054.0965(b)(6)) — alongside the confirmation of compliance with the ethics code and minimum standards (§ 2054.0965(b)(7)). That is a signed filing backed by per-system evidence. Risk Meridian’s IRDR AI Answer Set assembles those answers from your live inventory, determinations, and assessments, with the compliance confirmation built from your recorded adoptions. Verify field mappings against DIR’s current instrument.
- Is Risk Meridian TX-RAMP certified?
- Not yet. Risk Meridian is preparing its TX-RAMP Level 2 package. Texas agencies may sponsor provisional certification and can contract during the provisional period. Get audit-ready now — agency-sponsored provisional certification lets you contract while full certification completes. And the compliance work itself is procurement-independent: your inventory, classifications, assessments, and § 2054.0965 filings are your institution’s own obligations, which your team can prepare regardless of any vendor’s certification status.
- Does Risk Meridian guarantee compliance?
- No — and no vendor can. Risk Meridian helps your institution document its governance program and build a defensible, attributable record across SB 1964, 1 TAC Chapter 219, and HB 3512. Obligations, applicability, and the adopted Chapter 219 rule text should always be confirmed against the statutes, current DIR guidance, and your counsel.
Get audit-ready before the next IRDR cycle
The compliance work is procurement-independent: your inventory, determinations, assessments, and filings are your institution’s own obligations. Start building the record now — and contract through agency-sponsored provisional certification while our full TX-RAMP Level 2 certification completes.
HSAI determinations with written rationales
IRDR AI Answer Set from live records
Classification crosswalk across both vocabularies