Skip to main content
In effect — September 1, 2025Texas, USA

Texas HB 3512 Compliance Guide — Public-Sector AI Training

What state agencies and local governments need to know about HB 3512 — artificial intelligence training programs for certain employees and officials, effective September 1, 2025.

Overview

Texas HB 3512 (89th Legislature, Regular Session) adds Government Code §§ 2054.5191 and 2054.5193 and is captioned "Relating to artificial intelligence training programs for certain employees and officials of state agencies and local governments." Effective September 1, 2025, it requires state agencies and local governments to identify personnel who use a computer for at least 25% of their duties and, at least once a year, have those employees — along with elected and appointed officers and officials — complete a certified cybersecurity training program and a DIR-certified AI training program (§ 2054.5191). DIR must annually certify at least five AI-training programs and publish the list (§ 2054.5193). Completion is verified and reported to DIR on a DIR form, subject to periodic audits, and a state agency’s strategic plan must certify compliance (§§ 2054.5191(b),(c),(e); 2056.002(b)(12)).

Who must comply?

HB 3512 concerns Texas state agencies and local governments — not private companies. State agencies must identify employees who use a computer for at least 25% of their duties; each identified employee and each elected or appointed officer of the agency must complete the required trainings at least annually (§ 2054.5191(a)). Local governments must annually identify employees and elected or appointed officials who have access to a local-government computer system or database and use a computer for at least 25% of their duties, and require the same trainings (§ 2054.5191(a-1)). Some special-purpose units, such as a hospital district, may qualify as governmental entities depending on the statutory definitions — confirm applicability with counsel.

Key obligations under Texas HB 3512

What your organization must actually do to comply — broken down by obligation category.

Identify In-Scope Personnel

State agencies must identify employees who use a computer for at least 25% of their duties (§ 2054.5191(a)); local governments must annually identify employees and elected or appointed officials with computer-system or database access who use a computer for at least 25% of their duties (§ 2054.5191(a-1)). Elected and appointed officers and officials are covered alongside identified employees.

Annual Cybersecurity + AI Training

At least once each year, each identified employee and each elected or appointed officer or official must complete a certified cybersecurity training program and a DIR-certified AI training program (§§ 2054.5191(a), (a-1); 2054.5193).

Use DIR-Certified AI Programs

DIR annually certifies at least five AI-training programs and publishes the list on its website (§ 2054.5193). A certified program must focus on how AI may be used in relation to an employee’s responsibilities and teach best practices on literacy in deploying and operating AI. Track completions against programs on the current DIR list.

Verify & Report to DIR

The governing body or executive head verifies completion and reports it to DIR (§ 2054.5191(b),(c)); DIR provides a verification form indicating the percentage of employee completion (§ 2054.5191(e)). Local governments must also require periodic audits to ensure compliance.

Strategic-Plan Certification

A state agency’s strategic plan must include written certification of compliance with the cybersecurity and AI training requirements (§ 2056.002(b)(12)). Keep completion evidence organized so this certification is straightforward each cycle.

Track Completion, Expiry & Reminders

Because the trainings recur at least annually, evidencing that in-scope personnel stay current matters. Risk Meridian tracks completion and expiry, sends reminders as refreshers come due, and retains records in a tamper-evident, append-only audit log.

What is Texas HB 3512?

HB 3512 (89th Legislature, Regular Session) adds Government Code §§ 2054.5191 and 2054.5193 and is captioned "Relating to artificial intelligence training programs for certain employees and officials of state agencies and local governments." Effective September 1, 2025, it requires governmental entities to identify personnel who use a computer for at least 25% of their duties and have them — with elected and appointed officers and officials — complete a certified cybersecurity program and a DIR-certified AI training program at least annually.

Who does HB 3512 apply to?

HB 3512 applies to Texas state agencies and local governments, not to private companies. State agencies identify employees who use a computer for at least 25% of their duties, and each identified employee plus each elected or appointed officer completes the trainings annually (§ 2054.5191(a)). Local governments annually identify employees and elected or appointed officials with access to a local-government computer system or database who use a computer for at least 25% of their duties, and require the same trainings (§ 2054.5191(a-1)). Whether a special-purpose unit such as a hospital district is covered turns on the statutory definitions — confirm applicability with counsel.

What the training must cover

The AI training must be one of the programs DIR certifies. Under § 2054.5193, DIR annually certifies at least five AI-training programs and publishes the list on its website; a certified program must focus on how AI may be used in relation to an employee’s responsibilities and duties and teach best practices on literacy in deploying and operating AI. Alongside it, in-scope personnel must complete a certified cybersecurity training program (§ 2054.5191). Track completions against programs on the current DIR-certified list.

Verification, reporting, and how to prepare

The governing body or executive head verifies completion and reports it to DIR on a DIR-provided form that indicates the percentage of employee completion (§ 2054.5191(b),(c),(e)), and local governments must require periodic audits to ensure compliance. A state agency’s strategic plan must certify compliance with the cybersecurity and AI training requirements (§ 2056.002(b)(12)). To prepare, maintain a current roster of in-scope personnel (≥25% computer use plus officers and officials), track completion and expiry against DIR-certified programs, and keep fiscal-year and audit-ready records. Risk Meridian supports this end to end.

How Risk Meridian helps

Meet Texas HB 3512 requirements with Risk Meridian

Risk Meridian includes an HB 3512 training tracker built for public-sector programs. It maintains a roster of in-scope personnel — employees who use a computer for at least 25% of their duties plus elected and appointed officers and officials (§ 2054.5191(a),(a-1)) — tracks completion and expiry against the DIR-certified AI programs (§ 2054.5193), exports the completion-percentage data that populates the DIR verification form (§ 2054.5191(e)) — the form itself is prescribed by DIR — organizes periodic-audit and fiscal-year records (§ 2054.5191(c)), and records the strategic-plan training compliance certification (§ 2056.002(b)(12)). Reminders fire as refreshers come due, and records are kept Encrypted · SSO (Google & Microsoft) · TOTP MFA · RBAC · Tamper-evident audit log. Note that under the adopted 1 TAC Chapter 219, HB 3512 training is one of three distinct public-sector training duties — alongside all-employee Acceptable Use Policy training (§ 219.24(b)) and per-HSAI risk training for employees and contractors (§ 219.24(c)) — and Risk Meridian tracks each separately; no single course satisfies all three. It helps you evidence a current program; it does not replace legal advice on exactly who is covered or which DIR-certified program to use.

What Risk Meridian covers for Texas HB 3512

  • Identify In-Scope Personnel

  • Annual Cybersecurity + AI Training

  • Use DIR-Certified AI Programs

  • Verify & Report to DIR

  • Strategic-Plan Certification

  • Track Completion, Expiry & Reminders

Texas HB 3512 — frequently asked questions

Common questions from compliance officers, legal teams, and executives evaluating Texas HB 3512 compliance obligations.

When did HB 3512 take effect?
HB 3512 (89th Legislature, Regular Session) is effective September 1, 2025, so it is now in effect. It adds Government Code §§ 2054.5191 and 2054.5193; confirm how its provisions apply to your entity with counsel.
Who has to take AI training under HB 3512?
For a state agency, every employee who uses a computer for at least 25% of their duties, plus each elected or appointed officer of the agency (§ 2054.5191(a)). For a local government, employees and elected or appointed officials who have access to a local-government computer system or database and use a computer for at least 25% of their duties (§ 2054.5191(a-1)). Identified personnel must complete the trainings at least once each year.
How often is the training required, and what must it cover?
At least once each year, in-scope personnel must complete both a certified cybersecurity training program and a DIR-certified AI training program (§ 2054.5191). Under § 2054.5193, DIR annually certifies at least five AI-training programs and publishes the list; a certified program must focus on how AI relates to an employee’s duties and teach best practices on literacy in deploying and operating AI.
What must be reported, and to whom?
The governing body or executive head verifies completion and reports it to DIR on a DIR-provided form that indicates the percentage of employee completion (§ 2054.5191(b),(c),(e)); local governments must also require periodic audits. In addition, a state agency’s strategic plan must include written certification of compliance with the cybersecurity and AI training requirements (§ 2056.002(b)(12)).
Does HB 3512 apply to a hospital district?
Possibly. A hospital district may qualify as a governmental entity, which could bring covered personnel within HB 3512, but this depends on the statutory definitions and your structure. Confirm applicability with counsel rather than assuming either way.
How does Risk Meridian help with HB 3512?
Risk Meridian provides an HB 3512 training tracker that maintains a roster of in-scope personnel (≥25% computer use plus officers and officials), records completion and expiry against DIR-certified programs, produces the DIR-form percentage-completion reporting, organizes periodic-audit and fiscal-year records, and supports the strategic-plan certification — with everything retained in a tamper-evident audit log. It helps you evidence a current program; it does not determine who is legally covered, which you should confirm with counsel.

Start your Texas HB 3512 compliance program today

Risk Meridian handles Texas HB 3512 compliance documentation — plus every other major AI regulation — from a single platform. Start now, first AI system inventoried in under 10 minutes.

Covers 6 AI frameworks simultaneously

Document once — reuse across multiple frameworks

Board governance reports in minutes