Skip to main content
San Antonio, Texas · TRAIGA

TRAIGA & Texas AI compliance in San Antonio

San Antonio organizations — from healthcare, military, cybersecurity, and financial services — are subject to the Texas Responsible AI Governance Act (TRAIGA / HB 149), in force January 1, 2026. This is a plain-English, statute-accurate guide to what the law actually does, and how Risk Meridian helps San Antonio businesses, agencies, and hospital districts build a defensible record.

Intent-based prohibitionAG-only enforcement60-day cure periodNIST AI RMF safe harborEncrypted · RBAC · Tamper-evident audit log

Who it applies to in San Antonio

Your obligations depend on what kind of deployer you are. Know exactly what you owe — Private, Government, Healthcare, or Hospital District.

Private businesses in San Antonio

Any company operating in San Antonio that develops or deploys AI is within TRAIGA's reach. But for private deployers the law imposes almost no affirmative mandates — no required AI inventory, risk tiers, public disclosures, incident reporting, or registration. It prohibits certain intentional harmful uses and gives you affirmative defenses you have to evidence.

Government agencies in San Antonio

San Antonio-area state agencies and local governments carry the most obligations. TRAIGA adds AI-use disclosure duties, and SB 1964 and HB 3512 layer on data-management, procurement, advisory-board, and AI-training requirements for public-sector personnel.

Healthcare providers in San Antonio

Hospitals, clinics, and physician groups across San Antonio must disclose the use of AI in a patient's treatment under TRAIGA, and comply with SB 1188 — provider review of AI-generated records, EMR-offshoring limits, and patient-notification rules for AI in treatment and healthcare services.

Hospital districts in San Antonio

Public hospital districts serving San Antonio sit at the intersection of the healthcare and government rules. Depending on how a district is organized, SB 1964 and HB 3512 may apply as well as SB 1188 — confirm applicability with counsel, and plan for the strictest set that could apply.

What TRAIGA actually is

For San Antonio deployers, TRAIGA is an intent-based prohibition statute with affirmative defenses — not a checklist of mandates.

Intent-based prohibitions

TRAIGA prohibits developing or deploying AI with the intent to incite self-harm, harm, or crime; (as the sole intent) to infringe constitutional rights; to unlawfully discriminate against a protected class; or to produce unlawful sexual content involving minors or unlawful deepfake sexual material. Liability turns on intent — not disparate impact alone.

AG-only enforcement, 60-day cure

Enforcement is exclusively by the Texas Attorney General, with a mandatory 60-day cure period before penalties can attach. There is no private right of action — individuals cannot sue you directly under TRAIGA.

Penalty bands

Civil penalties run roughly $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable violations, and $2,000–$40,000 per day for continuing violations.

NIST AI RMF safe harbor

Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense. Other safe harbors include internal, adversarial, or red-team testing; following state-agency guidance; and third-party misuse. The statute rewards evidenced good faith.

The broader Texas AI stack

TRAIGA does not stand alone. San Antonio organizations — especially in healthcare and the public sector — should track three companion laws enacted in 2025.

SB 1188 — Healthcare

Effective September 1, 2025. For San Antonio providers: review of AI-generated records to Texas Medical Board standards, EMR-offshoring limits, and patient-notification rules for AI used in treatment and healthcare services.

SB 1964 — Governmental entities

Effective September 1, 2025. Governs AI use and data management by state agencies and local governments — touching ethics, procurement, the Texas Department of Information Resources (DIR), and a Public Sector AI Systems Advisory Board. For specifics, see the statute and consult counsel.

HB 3512 — AI training

Effective September 1, 2025. Establishes AI-training requirements for certain employees and officials of state agencies and local governments. Confirm applicability and specifics with counsel.

HB 149 (TRAIGA) — The core statute

In force January 1, 2026. The intent-based prohibition statute above, plus a voluntary 36-month DIR regulatory sandbox for testing AI systems and preemption of conflicting local AI ordinances across San Antonio and the rest of Texas.

How Risk Meridian helps San Antonio organizations

We help you document intent, testing, and oversight so you can evidence good faith and qualify for TRAIGA's safe harbors — audit-ready in under an hour.

Prohibited-practice screening

A guided questionnaire flags the TRAIGA-prohibited intentional uses and produces a clearance record — the first thing every San Antonio deployer should have on file.

NIST AI RMF safe-harbor builder

Maps your controls to Govern, Map, Measure, and Manage, computes an alignment percentage, and emits a Safe Harbor Evidence Pack you can hand to the AG, a board, or an insurer.

Government & hospital-district module

Our moat for San Antonio agencies and hospital districts: a governmental-AI classifier with written rationales, versioned assessments, a DIR submission pack, vendor-clause tracking, an HB 3512 training tracker, and an SB 1188 patient-disclosure generator.

60-day cure workflow

A regulatory-notice tracker with a cure-deadline countdown, milestone checklist, and cure-evidence export — so if the Attorney General ever contacts you, the clock is already handled.

Security posture: Encrypted (in transit & at rest) · RBAC · Tamper-evident audit log. This guide is general information, not legal advice — confirm how each statute applies to your San Antonio organization with counsel.

TRAIGA in San Antonio — FAQs

Common questions from San Antonio businesses, agencies, and hospital districts.

Does TRAIGA apply to businesses in San Antonio?
Yes — TRAIGA applies to organizations operating in Texas, including those in San Antonio. But for private deployers it is an intent-based prohibition statute, not a mandate regime: it bars certain intentional harmful uses of AI and is enforced exclusively by the Texas Attorney General after a 60-day cure period, with no private right of action. It does not require a private company to build an AI inventory, adopt risk tiers, publish disclosures, report incidents, or register its systems.
Can a San Antonio resident sue our company under TRAIGA?
No. TRAIGA creates no private right of action. Only the Texas Attorney General can enforce it, and only after giving you a 60-day period to cure an alleged violation before civil penalties attach.
What should a San Antonio government agency or hospital district do first?
Public-sector employers in San Antonio carry the most obligations. Start by mapping which laws apply — TRAIGA's government disclosure duties, SB 1964's data-management and procurement requirements, and HB 3512's AI-training requirements — and, for hospital districts, SB 1188's healthcare rules. Because applicability can be fact-specific, confirm the details with counsel. Risk Meridian's government module is built to document these systematically.
How does the NIST AI RMF safe harbor help San Antonio deployers?
Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense under TRAIGA. For San Antonio deployers, that means aligning your governance to NIST's Govern, Map, Measure, and Manage functions and keeping the evidence is one of the highest-value things you can do. Risk Meridian's safe-harbor builder assembles that evidence into a shareable pack.

Build your TRAIGA defense in San Antonio

Screen for prohibited uses, build your NIST AI RMF safe-harbor evidence, document intent, and stay cure-ready — from one platform.

No credit card required.