Guide
AI Governance Programs and the TRAIGA Defenses
Why testing, feedback channels and a recognized risk framework matter under Texas law, and what a workable program records.
Law checked through
Short Answer
TRAIGA does not require private businesses to run an AI governance program. It rewards one. A defendant is presumed to have used reasonable care; is not liable if another person misused its system; and is not liable if it discovers a violation through feedback, through testing including red-team testing, by following state agency guidelines or, if it substantially complies with NIST’s Generative AI Profile or another recognized framework, through an internal review process (Business and Commerce Code § 552.105(c), (e)). The Act’s cure process also asks for documentation and policy changes, and a civil investigative demand can ask for a system’s purpose, data, metrics, limitations and monitoring (Business and Commerce Code § 552.103(b), Business and Commerce Code § 552.104(b)). A program built to produce that documentation serves Texas law, and its core elements also meet most other states’ expectations. State agencies and local governments have mandatory equivalents under SB 1964 and DIR’s rules.
Which Laws Apply
- Texas AI-specific: Business and Commerce Code § 552.103(b), Business and Commerce Code § 552.104(b), Business and Commerce Code § 552.105(c) to (f); Government Code § 2054.702, Government Code § 2054.703, Government Code § 2054.708; 1 TAC chapter 219.
- Generally applicable Texas law: TDPSA data protection assessments (Business and Commerce Code § 541.105).
- Federal: NIST AI RMF 1.0 and Generative AI Profile (voluntary); ISO/IEC 42001 (voluntary standard).
What TRAIGA Rewards
| Provision | Rule | Useful record |
|---|---|---|
| Business and Commerce Code § 552.105(c) | Rebuttable reasonable-care presumption; no certification condition in this subsection | Evidence of actual care, not a claim that the presumption requires a program. |
| Business and Commerce Code § 552.105(e)(1) | Another person’s prohibited misuse can prevent liability in the covered AG action | Intended use, instructions, safeguards and misuse facts. |
| Business and Commerce Code § 552.105(e)(2) | Listed routes for discovery of a violation; substantial-compliance condition accompanies internal review | Feedback, test results, agency guidelines or internal-review documentation matching the relied-on route. |
| Business and Commerce Code § 552.104(b) | Timely cure plus statement, evidence and necessary policy changes | Remediation and recurrence-prevention record. |
| Business and Commerce Code § 552.103(b) | Investigative-demand documentation list | Current system, data, metrics, limitations and monitoring record. |
The text ties substantial compliance with NIST’s Generative AI Profile or another recognized AI risk-management framework to the internal-review route in Business and Commerce Code § 552.105(e)(2). Feedback, testing and following applicable state-agency guidelines are separately listed discovery routes. A court must still apply the provision to the facts. NIST’s framework is voluntary unless a statute, rule or contract gives it a specific role; a framework reference is not a certification of legal compliance.
Elements of a Workable Program
- Inventory. A list of AI systems in use, what each does, whose data it touches and who owns it.
- Risk tiers. Higher scrutiny for systems that make or shape decisions about people, speak to the public or handle sensitive data.
- Policies. Acceptable use for employees, procurement review and an approval path for higher-risk uses.
- Testing. Pre-deployment and periodic testing for accuracy, bias and misuse, including adversarial testing for public-facing systems.
- Feedback. A channel for users, customers and employees to report problems, with tracking to resolution.
- Documentation. Records that answer each Business and Commerce Code § 552.103(b) category for every higher-risk system.
- Incidents. A process to investigate, fix and document, which doubles as the cure record.
- Framework alignment. A mapping of the program to the NIST AI RMF and its Generative AI Profile, or to ISO/IEC 42001.
Government Programs
State agencies and local governments must adopt DIR’s AI code of ethics and minimum standards for heightened scrutiny systems, both aligned with the NIST AI RMF, and assess those systems (Government Code § 2054.702, Government Code § 2054.703, Government Code § 2054.708). See Government AI and Public Records.
Illustrative Example (Hypothetical)
A Texas software company offers a public chatbot. During quarterly red-team testing, its team finds prompts that lead the bot to give instructions for self-harm. It fixes the problem, records the test, the finding and the fix, and updates its policy. If the Attorney General later received a complaint under Business and Commerce Code § 552.052, the company’s records would support the Business and Commerce Code § 552.105(e)(2) defense and a cure statement.
What Is Unsettled
What “substantially complies” with a framework means; whether a framework other than NIST’s will be accepted in practice; and how the presumption of reasonable care will be rebutted.
Sources
- Business and Commerce Code Chapter 552
- Government AI and Information Resources
- DIR Adopted AI Rules
- Texas Data Privacy and Security Act
- NIST AI Risk Management Framework 1.0
- NIST Generative AI Profile
