TRAIGA & Texas AI compliance in Dallas
Dallas organizations — from banking, insurance, telecom, and a fast-growing technology sector — are subject to the Texas Responsible AI Governance Act (TRAIGA / HB 149), in force January 1, 2026. This is a plain-English, statute-accurate guide to what the law actually does, and how Risk Meridian helps Dallas businesses, agencies, and hospital districts build a defensible record.
Who it applies to in Dallas
Your obligations depend on what kind of deployer you are. Know exactly what you owe — Private, Government, Healthcare, or Hospital District.
Private businesses in Dallas
Any company operating in Dallas that develops or deploys AI is within TRAIGA's reach. But for private deployers the law imposes almost no affirmative mandates — no required AI inventory, risk tiers, public disclosures, incident reporting, or registration. It prohibits certain intentional harmful uses and gives you affirmative defenses you have to evidence.
Government agencies in Dallas
Dallas-area state agencies and local governments carry the most obligations. TRAIGA adds AI-use disclosure duties, and SB 1964 and HB 3512 layer on data-management, procurement, advisory-board, and AI-training requirements for public-sector personnel.
Healthcare providers in Dallas
Hospitals, clinics, and physician groups across Dallas must disclose the use of AI in a patient's treatment under TRAIGA, and comply with SB 1188 — provider review of AI-generated records, EMR-offshoring limits, and patient-notification rules for AI in treatment and healthcare services.
Hospital districts in Dallas
Public hospital districts serving Dallas sit at the intersection of the healthcare and government rules. Depending on how a district is organized, SB 1964 and HB 3512 may apply as well as SB 1188 — confirm applicability with counsel, and plan for the strictest set that could apply.
What TRAIGA actually is
For Dallas deployers, TRAIGA is an intent-based prohibition statute with affirmative defenses — not a checklist of mandates.
Intent-based prohibitions
TRAIGA prohibits developing or deploying AI with the intent to incite self-harm, harm, or crime; (as the sole intent) to infringe constitutional rights; to unlawfully discriminate against a protected class; or to produce unlawful sexual content involving minors or unlawful deepfake sexual material. Liability turns on intent — not disparate impact alone.
AG-only enforcement, 60-day cure
Enforcement is exclusively by the Texas Attorney General, with a mandatory 60-day cure period before penalties can attach. There is no private right of action — individuals cannot sue you directly under TRAIGA.
Penalty bands
Civil penalties run roughly $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable violations, and $2,000–$40,000 per day for continuing violations.
NIST AI RMF safe harbor
Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense. Other safe harbors include internal, adversarial, or red-team testing; following state-agency guidance; and third-party misuse. The statute rewards evidenced good faith.
The broader Texas AI stack
TRAIGA does not stand alone. Dallas organizations — especially in healthcare and the public sector — should track three companion laws enacted in 2025.
SB 1188 — Healthcare
Effective September 1, 2025. For Dallas providers: review of AI-generated records to Texas Medical Board standards, EMR-offshoring limits, and patient-notification rules for AI used in treatment and healthcare services.
SB 1964 — Governmental entities
Effective September 1, 2025. Governs AI use and data management by state agencies and local governments — touching ethics, procurement, the Texas Department of Information Resources (DIR), and a Public Sector AI Systems Advisory Board. For specifics, see the statute and consult counsel.
HB 3512 — AI training
Effective September 1, 2025. Establishes AI-training requirements for certain employees and officials of state agencies and local governments. Confirm applicability and specifics with counsel.
HB 149 (TRAIGA) — The core statute
In force January 1, 2026. The intent-based prohibition statute above, plus a voluntary 36-month DIR regulatory sandbox for testing AI systems and preemption of conflicting local AI ordinances across Dallas and the rest of Texas.
How Risk Meridian helps Dallas organizations
We help you document intent, testing, and oversight so you can evidence good faith and qualify for TRAIGA's safe harbors — audit-ready in under an hour.
Prohibited-practice screening
A guided questionnaire flags the TRAIGA-prohibited intentional uses and produces a clearance record — the first thing every Dallas deployer should have on file.
NIST AI RMF safe-harbor builder
Maps your controls to Govern, Map, Measure, and Manage, computes an alignment percentage, and emits a Safe Harbor Evidence Pack you can hand to the AG, a board, or an insurer.
Government & hospital-district module
Our moat for Dallas agencies and hospital districts: a governmental-AI classifier with written rationales, versioned assessments, a DIR submission pack, vendor-clause tracking, an HB 3512 training tracker, and an SB 1188 patient-disclosure generator.
60-day cure workflow
A regulatory-notice tracker with a cure-deadline countdown, milestone checklist, and cure-evidence export — so if the Attorney General ever contacts you, the clock is already handled.
Security posture: Encrypted (in transit & at rest) · RBAC · Tamper-evident audit log. This guide is general information, not legal advice — confirm how each statute applies to your Dallas organization with counsel.
TRAIGA in Dallas — FAQs
Common questions from Dallas businesses, agencies, and hospital districts.
- Does TRAIGA apply to businesses in Dallas?
- Yes — TRAIGA applies to organizations operating in Texas, including those in Dallas. But for private deployers it is an intent-based prohibition statute, not a mandate regime: it bars certain intentional harmful uses of AI and is enforced exclusively by the Texas Attorney General after a 60-day cure period, with no private right of action. It does not require a private company to build an AI inventory, adopt risk tiers, publish disclosures, report incidents, or register its systems.
- Can a Dallas resident sue our company under TRAIGA?
- No. TRAIGA creates no private right of action. Only the Texas Attorney General can enforce it, and only after giving you a 60-day period to cure an alleged violation before civil penalties attach.
- What should a Dallas government agency or hospital district do first?
- Public-sector employers in Dallas carry the most obligations. Start by mapping which laws apply — TRAIGA's government disclosure duties, SB 1964's data-management and procurement requirements, and HB 3512's AI-training requirements — and, for hospital districts, SB 1188's healthcare rules. Because applicability can be fact-specific, confirm the details with counsel. Risk Meridian's government module is built to document these systematically.
- How does the NIST AI RMF safe harbor help Dallas deployers?
- Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense under TRAIGA. For Dallas deployers, that means aligning your governance to NIST's Govern, Map, Measure, and Manage functions and keeping the evidence is one of the highest-value things you can do. Risk Meridian's safe-harbor builder assembles that evidence into a shareable pack.
Build your TRAIGA defense in Dallas
Screen for prohibited uses, build your NIST AI RMF safe-harbor evidence, document intent, and stay cure-ready — from one platform.
No credit card required.