Texas SB 1964 Compliance Guide — Government AI & Data
What state agencies and local governments need to know about SB 1964 — the regulation and use of AI systems and the management of data by governmental entities, effective September 1, 2025.
Overview
Texas SB 1964 (89th Legislature, Regular Session) adds Subchapter S, "Artificial Intelligence," to Government Code chapter 2054 and is captioned "Relating to the regulation and use of artificial intelligence systems and the management of data by governmental entities." Effective September 1, 2025, it directs Texas state agencies and local governments that procure, develop, deploy, or use AI. Its core building block is the Heightened Scrutiny AI system (HSAI) — an AI system specifically intended to autonomously make, or be a controlling factor in making, a consequential decision (one with a material legal or similarly significant effect on a person’s access to a government service) (§ 2054.003). Governmental entities must adopt the DIR AI Code of Ethics (§ 2054.702) and DIR minimum standards for HSAI (§ 2054.703), inventory their AI and HSAI systems (§§ 2054.068, 2054.0965), conduct confidential HSAI impact assessments (§ 2054.708), and provide public disclosures and a standardized notice (§§ 2054.707, 2054.711). DIR’s implementing rules were adopted as 1 TAC Chapter 219, effective March 18, 2026 — confirm current DIR guidance for specifics. SB 1964 is directed at governmental entities, not private deployers.
Who must comply?
SB 1964 applies to Texas governmental entities — state agencies and local governments — that procure, develop, deploy, or use AI systems; it is not a general mandate on private companies. Heightened obligations attach to any entity deploying a Heightened Scrutiny AI system (HSAI): AI intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003), subject to four statutory exclusions — systems intended only to perform a narrow procedural task, improve the result of a completed human activity, perform a preparatory task, or detect decision patterns or deviations. Some special-purpose units may also fall within scope: a hospital district, for example, gets a specific disclosure carve-out under § 2054.711(c), but whether the statute otherwise applies to it turns on the statutory definitions — confirm applicability with counsel.
Quick Facts
- Framework
- Texas SB 1964 — Government AI & Data
- Jurisdiction
- Texas, USA
- Status
- In effect — September 1, 2025
Get compliant with Risk Meridian
Start now — first AI system inventoried in under 10 minutes. No credit card required.
Start free trialRelated Resources
1 TAC Chapter 219 Guide →
The DIR rules that operationalize SB 1964 — AI Risk Officer, written risk assessments, and impact assessments.
Texas HB 3512 Guide →
Public-sector AI training requirements — the companion 2025 Texas statute for governmental entities.
Texas TRAIGA Guide →
Texas’s intent-based AI prohibition statute — a useful comparison point for governmental entities.
AI Governance Software →
How Risk Meridian helps governmental entities document AI use with written rationales and versioned assessments.
Key obligations under Texas SB 1964
What your organization must actually do to comply — broken down by obligation category.
Adopt the DIR AI Code of Ethics
State agencies and local governments shall adopt the DIR AI Code of Ethics (§ 2054.702), implemented at 1 TAC § 219.11 and effective March 18, 2026. It covers all AI systems the entity procures, develops, deploys, or uses — not just heightened-scrutiny systems; DIR expressly declined to narrow it — and addresses human oversight and control, fairness and accuracy, transparency including consumer disclosures, data privacy and security, redress with accountability, and the frequency of evaluations.
Adopt Minimum Standards for HSAI
Entities shall adopt DIR minimum standards for Heightened Scrutiny AI systems (§ 2054.703): accountability reports, acceptable-use policies, employee training, and — critically — assessing and documenting each HSAI’s known security risks, performance metrics, and transparency measures before deployment and at any material change. The standards also require contractually obligating vendors to implement risk-management frameworks.
Inventory AI & HSAI Systems
State agencies must include AI and HSAI systems in their IT inventory and information-resources review, with an evaluation of each system’s purpose and risk-mitigation measures (§§ 2054.068, 2054.0965(b)(6)). Local governments shall review their HSAI deployment and use and provide it to DIR on request (§ 2054.0965(c)).
HSAI Impact Assessments
A state agency (or a vendor contracting with one) that deploys or uses an HSAI shall conduct an impact assessment outlining risks of unlawful harm, system limitations, and information-governance practices, with a copy to DIR on request (§ 2054.708). The assessment is confidential and not subject to Public Information Act disclosure. Local governments are not mandated: 1 TAC § 219.23(e)(2) directs them to consider conducting one in alignment with the state-agency requirements.
Public Disclosure & Standardized Notice
Public-facing AI must be disclosed under the code of ethics (§ 2054.707), and any AI that is public-facing or a controlling factor in a consequential decision requires a DIR-form standardized notice on related apps, websites, and public systems (§ 2054.711). Academic medical centers, state-owned and public hospitals, and hospital districts may instead satisfy disclosure with a generalized statement in patient consent forms that AI may be used in treatment (§ 2054.711(c)). Note: DIR’s Chapter 219 rule neither specifies disclosure methods nor references § 2054.711, so whether that statement also satisfies the rule’s § 219.11(g)(2)(C) disclosure duty is unresolved — confirm with counsel.
Enforcement & Vendor Cure
Entities and vendors aware of a violation must report it to DIR and the Attorney General, who maintains a public complaint web page (§§ 2054.709–.710). A vendor found in violation has 31 days to cure; if not, the agency issues a notice of intent to void, giving another 31 days, after which the contract may be voided. A vendor with more than one voided contract may be barred from state contracts by the comptroller.
What is Texas SB 1964?
SB 1964 (89th Legislature, Regular Session) adds Subchapter S, "Artificial Intelligence," to Government Code chapter 2054. Captioned "Relating to the regulation and use of artificial intelligence systems and the management of data by governmental entities," it took effect September 1, 2025 and governs how state agencies and local governments procure, develop, deploy, and use AI. It defines a Heightened Scrutiny AI system (HSAI) — AI specifically intended to autonomously make, or be a controlling factor in, a consequential decision affecting a person’s access to a government service (§ 2054.003) — and layers heightened duties on those systems. It also creates a Public Sector Artificial Intelligence Systems Advisory Board (§ 2054.705) and a DIR AI sandbox (§ 2054.706).
Who does SB 1964 apply to?
SB 1964 is directed at Texas governmental entities — state agencies and local governments — that procure, develop, deploy, or use AI, not at private companies as a general matter. The heightened obligations attach to Heightened Scrutiny AI systems (HSAI): AI intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003). Four exclusions narrow the definition — systems intended only to perform a narrow procedural task, improve the result of a completed human activity, perform a preparatory task, or detect decision patterns or deviations. A hospital district gets a specific disclosure carve-out (§ 2054.711(c)); whether the statute otherwise binds a given special-purpose unit turns on the definitions, so confirm applicability with counsel.
Code of ethics, minimum standards, and HSAI assessments
State agencies and local governments shall adopt the DIR AI Code of Ethics (§ 2054.702) — NIST AI RMF 1.0-aligned, covering human oversight, fairness and accuracy, transparency and consumer disclosures, data privacy and security, redress and accountability, and evaluation frequency — and the DIR minimum standards for HSAI (§ 2054.703). Those standards require assessing and documenting each HSAI’s known security risks, performance metrics, and transparency measures before deployment and at any material change, plus accountability reports, acceptable-use policies, employee training, and vendor contract clauses requiring risk-management frameworks. Separately, a state agency (or its vendor) deploying an HSAI must conduct a confidential impact assessment of unlawful-harm risks, system limitations, and information-governance practices (§ 2054.708); local governments are directed to consider one (1 TAC § 219.23(e)(2)). DIR’s implementing rules were adopted as 1 TAC Chapter 219, effective March 18, 2026 — verify specifics against the adopted rule and current DIR guidance.
Inventory, disclosure, and the standardized notice
Governmental entities must inventory their AI and HSAI systems and evaluate each system’s purpose and risk-mitigation measures (§§ 2054.068, 2054.0965(b)(6)); local governments must review HSAI deployment and provide it to DIR on request (§ 2054.0965(c)). Public-facing AI must be disclosed under the code of ethics (§ 2054.707), and any AI that is public-facing or a controlling factor in a consequential decision requires a DIR-form standardized notice on related apps, websites, and public computer systems (§ 2054.711). Academic medical centers, state-owned and public hospitals, and hospital districts may satisfy that disclosure through a generalized statement in patient consent forms that AI may be used in the course of treatment (§ 2054.711(c)). Whether that method also satisfies the separate disclosure duty in DIR’s Chapter 219 ethics rule (§ 219.11(g)(2)(C)) is unresolved — DIR declined to confirm it; check with counsel.
Enforcement: vendor cure, the advisory board, and the DIR sandbox
SB 1964’s enforcement lands mostly on vendors and contracts. Entities and vendors aware of a violation must report it to DIR and the Attorney General, who maintains a public complaint web page (§§ 2054.709–.710). When the AG (with DIR) finds a vendor violated, the vendor gets written notice and 31 days to cure; if uncured, the agency issues a notice of intent to void the contract, allowing another 31 days; if still uncured, the agency may void the contract. A vendor with more than one voided contract is referred to the comptroller and may be barred from future state contracts. SB 1964 also establishes a Public Sector Artificial Intelligence Systems Advisory Board (§ 2054.705) and a DIR-run AI sandbox for testing (§ 2054.706).
TRAIGA also reaches government — and how it is enforced
SB 1964 is not the only Texas AI law that touches governmental entities. TRAIGA (HB 149, Business & Commerce Code ch. 552, in force January 1, 2026) applies to state agencies and local governments too: a governmental agency that makes an AI system available to interact with consumers must disclose that (§ 552.051(b)); governmental entities are specifically barred from AI social scoring (§ 552.053) and certain biometric identification (§ 552.054); and the general prohibitions apply as well (§§ 552.052, 552.055–552.057). TRAIGA is enforced exclusively by the Texas Attorney General, with a 60-day cure period and no private right of action (§§ 552.101, 552.104). It starts from a rebuttable presumption that you used reasonable care (§ 552.105(c)); if the AG investigates, a civil investigative demand can require a description of a system’s purpose, training data, inputs, outputs, metrics, limitations, and your oversight process (§ 552.103) — exactly the record a governance program keeps. Penalties run $10,000–$12,000 (curable), $80,000–$200,000 (uncurable), and $2,000–$40,000 per day (continuing) (§ 552.105), and for licensed or certified personnel a licensing agency may add sanctions — up to suspension or revocation and a penalty up to $100,000 — but only after a violation finding and an AG recommendation (§ 552.106). Note that TRAIGA expressly excludes hospital districts and public universities from its “governmental entity” definition (Bus. & Com. Code § 552.001(3)), so those governmental-only provisions do not bind them under that chapter. SB 1964 adds its own governmental AI-use, data-management, procurement, DIR, and advisory-board structure on top of this.
Meet Texas SB 1964 requirements with Risk Meridian
Government is our depth. Risk Meridian’s TX Govt Compliance module keeps the whole SB 1964 record in one place. Every system gets a Heightened Scrutiny AI (HSAI) determination with a written rationale against the § 2054.003(6-a)(A)–(D) definition and its four statutory exclusions. For governmental organizations the risk model is binary, matching the statute: the HSAI determination is the classification that triggers the extra controls, and every non-HSAI system carries inventory and oversight duties only — the LOW/MODERATE/HIGH tier used by private organizations does not apply. That proportionality is the point: the documented exclusion analysis keeps ordinary agency AI out of the heavy workflow. Versioned § 219.22 risk assessments capture known security risks and available mitigation steps, performance metrics relating to accuracy and operational efficiency, and transparency — the algorithms and decision-making, the training data, and the availability of inputs and outputs for monitoring over time. § 219.23(b) impact assessments — mandatory for state agencies and institutions of higher education, advisory for local governments (§ 219.23(e)(2)) — run before deployment and at any material change, and stay confidential and exempt from public-disclosure requests under § 2054.708(c), so candid risk documentation stays candid. Each HSAI also carries the AI Risk Officer deployment decision — a documented approve or deny with notes and executive-head notification (§ 219.22(c)) — the governance act itself, not just a form. Entity-level artifacts record the code-of-ethics and minimum-standards adoptions (§§ 2054.702(c), 2054.703(c)), the AI Risk Officer designation (1 TAC § 219.21(a)), the Acceptable Use Policy with all-employee training (§ 219.24(b)), a Code-of-Ethics obligations checklist with per-obligation status, notes, and evidence across § 219.11(c)/(e)/(f)/(g)/(h)/(i) — covering all AI systems, not just HSAI — recurring periodic-evaluation records (§ 219.11(k)(2)), AI-records retention with Public Information Act consideration (§ 219.11(j)(3) — those records are not PIA-exempt, unlike impact assessments), and advisory data-source and modification records (§ 219.11(l)(2)). Training is tracked as three distinct duties — annual certified AI training (§§ 2054.5191, 2054.5193), all-employee AUP training (§ 219.24(b)), and per-HSAI risk training for employees and contractors (§ 219.24(c)) — no single course satisfies all three. The Disclosures module produces standardized-notice records (§ 2054.711) including the hospital-district consent-form carve-out (§ 2054.711(c) — whether that method also satisfies the rule’s separate § 219.11(g)(2)(C) public-facing disclosure duty is unresolved; confirm with counsel), and a separate auto-generated Public-Facing AI Disclosure control tracks the distinct § 2054.707 duty for state agencies and institutions of higher education. A Vendor AI Register tracks § 2054.709 notice-and-cure clauses on the 31/31-day timeline and records two distinct vendor clauses — the risk-framework clause, NIST’s or a comparable standard such as ISO/IEC 42001 (1 TAC § 219.24(d)), and the separate vendor ethical-principles clause binding vendors to the entity’s AI ethical principles and relevant laws (§ 219.11(j)(2)(B); DIR refused to let vendors substitute their own principles). Obligations render as Mandatory or Advisory to match the adopted rule’s modal verbs — advisory items are never flattened to Required. Three governmental reports ship today: the DIR Submission Pack for the on-request review (§ 2054.0965(c)) — entity-aware, now bundling the AUP adoption, the § 219.11 ethics-obligations checklist, per-HSAI review decisions, periodic evaluations, retention and PIA records, both vendor clauses, and a training breakdown by type; missing mandatory artifacts render NOT ON FILE for state agencies and universities, while a local government’s elective assessments are labeled advisory, never “missing”; the IRDR AI Answer Set for state agencies and institutions of higher education (§ 2054.0965(b)(6)–(7)) — per-system uses-AI, heightened-scrutiny, and risk-mitigation answers with purpose evaluation, strategic-plan-support analysis, and the (b)(7) compliance confirmation built from the adoption artifacts; and a Classification Crosswalk that reconciles TRAIGA-lineage vocabulary (high-risk, substantial factor) with the SB 1964/TAC 219 terms your statutory duties actually key to (heightened scrutiny, controlling factor), with a written reconciliation rationale per system. 1 TAC Chapter 219 was adopted effective March 18, 2026 — verify field-level details against the adopted rule and current DIR guidance, and IRDR mappings against DIR’s current instrument. Records are kept Encrypted · SSO (Google & Microsoft) · TOTP MFA · RBAC · Tamper-evident audit log. Risk Meridian helps you build a defensible record; it does not replace legal advice. The same record preserves TRAIGA’s rebuttable presumption of reasonable care (§ 552.105(c)) and answers a civil investigative demand (§ 552.103) if the Attorney General ever asks.
What Risk Meridian covers for Texas SB 1964
Adopt the DIR AI Code of Ethics
Adopt Minimum Standards for HSAI
Inventory AI & HSAI Systems
HSAI Impact Assessments
Public Disclosure & Standardized Notice
Enforcement & Vendor Cure
Texas SB 1964 — frequently asked questions
Common questions from compliance officers, legal teams, and executives evaluating Texas SB 1964 compliance obligations.
- When did SB 1964 take effect?
- SB 1964 (89th Legislature, Regular Session) is effective September 1, 2025, so it is now in effect. It adds Subchapter S to Government Code chapter 2054; confirm how its specific provisions apply to your governmental entity with counsel.
- Who does SB 1964 apply to?
- SB 1964 applies to Texas state agencies and local governments that procure, develop, deploy, or use AI — not private companies as a general matter. Heightened duties attach to Heightened Scrutiny AI systems (HSAI): AI intended to autonomously make, or be a controlling factor in, a consequential decision affecting access to a government service (§ 2054.003).
- What is a Heightened Scrutiny AI system (HSAI)?
- Under § 2054.003, an HSAI is an AI system specifically intended to autonomously make, or be a controlling factor in making, a consequential decision — a decision with a material legal or similarly significant effect on a person’s access to a government service. The definition excludes systems intended only to perform a narrow procedural task, improve the result of a completed human activity, perform a preparatory task, or detect decision patterns or deviations.
- What must a governmental entity actually do under SB 1964?
- State agencies and local governments shall adopt the DIR AI Code of Ethics (§ 2054.702) and the DIR minimum standards for HSAI (§ 2054.703), which require assessing and documenting each HSAI’s security risks, performance metrics, and transparency measures before deployment and at any material change, plus vendor risk-management clauses. Entities must inventory AI and HSAI systems (§§ 2054.068, 2054.0965), conduct confidential HSAI impact assessments (§ 2054.708 — mandatory for state agencies; local governments are directed to consider one under 1 TAC § 219.23(e)(2)), and provide public disclosure (§ 2054.707) and a DIR-form standardized notice (§ 2054.711). DIR’s implementing rules were adopted as 1 TAC Chapter 219, effective March 18, 2026 — verify specifics against the adopted rule and current DIR guidance.
- Does SB 1964 apply to public universities and other institutions of higher education?
- Yes — institutions of higher education are treated as state agencies under Government Code chapter 2054, so they carry the full state-agency tier of SB 1964: the AI and HSAI inventory (§ 2054.068), the information-resources deployment review with per-system purpose, risk-mitigation, and strategic-plan-support evaluation plus the compliance confirmation (§ 2054.0965(b)(6)–(7)), confidential HSAI impact assessments (§ 2054.708), and the public-facing disclosure and standardized-notice duties (§§ 2054.707, 2054.711). At the same time, TRAIGA expressly excludes institutions of higher education from its “governmental entity” definition (Bus. & Com. Code § 552.001(3)), so TRAIGA’s governmental-entity-only rules do not bind them under that chapter. Risk Meridian models exactly that split: an Institution of Higher Education organization gets the full ch. 2054 treatment while the TRAIGA governmental-entity items are correctly excluded. Confirm your institution’s status with counsel.
- Does SB 1964 apply to a hospital district?
- SB 1964 gives hospital districts a specific disclosure carve-out: an academic medical center, state-owned or public hospital, or hospital district may satisfy the standardized-notice disclosure with a generalized statement in patient consent forms that AI may be used in the course of treatment (§ 2054.711(c)). Two cautions. First, DIR declined to confirm that the consent-form method also satisfies the separate disclosure duty in its Chapter 219 ethics rule (§ 219.11(g)(2)(C)) — that interplay is unresolved. Second, Chapter 219 reaches local governments only in limited scope, so whether the rule’s local-government provisions cover a given district turns on its definitions (§ 219.1). Confirm both, and the statute’s own applicability, with counsel.
- How does Risk Meridian classify risk for a governmental organization?
- With the binary model the statute actually uses. For a governmental organization — including an institution of higher education — each system receives a Heightened Scrutiny AI (HSAI) determination with a written rationale against the § 2054.003(6-a)(A)–(D) definition and its four exclusions. An HSAI determination is what triggers the per-system controls: § 219.22 risk assessments, the standardized notice, and the § 219.23(b) impact assessment — mandatory for state agencies and institutions of higher education, while local governments are directed to consider one (§ 219.23(e)(2)). Non-HSAI systems are not zero-obligation: the Code of Ethics covers all AI systems the entity procures, develops, deploys, or uses (§ 219.11), alongside inventory and acceptable-use training — they simply skip the per-HSAI assessment workflow. The LOW/MODERATE/HIGH tier that private organizations use does not apply to governmental organizations — a high score is not what creates the duty; meeting the statutory definition is.
- How is SB 1964 enforced, and how is it different from TRAIGA?
- SB 1964’s enforcement targets vendors and contracts: entities and vendors report violations to DIR and the Attorney General (§§ 2054.709–.710); a vendor gets 31 days to cure, then a further 31 days after a notice of intent to void, after which the contract may be voided — and repeat offenders may be barred from state contracts by the comptroller. TRAIGA (HB 149, in force January 1, 2026) is a separate, intent-based prohibition statute enforced exclusively by the Attorney General with a 60-day cure period, a rebuttable presumption of reasonable care (§ 552.105(c)), and tiered penalties (§ 552.105); governmental entities are also subject to TRAIGA’s consumer-interaction disclosure (§ 552.051(b)), social-scoring ban (§ 552.053), and biometric limits (§ 552.054). Risk Meridian helps you keep one governance record you can draw on for each.
- If TRAIGA applies to our agency, how is it enforced?
- Through the Texas Attorney General only — there is no private right of action, and the AG must give written notice and a 60-day opportunity to cure before suing (§§ 552.101, 552.104). TRAIGA begins with a rebuttable presumption that you used reasonable care (§ 552.105(c)); a current governance record is how you preserve it. If the AG opens an investigation, a civil investigative demand can require a description of the system’s purpose, training data, input categories, outputs, performance metrics, known limitations, and your monitoring and oversight process (§ 552.103). Civil penalties are tiered — $10,000–$12,000 curable, $80,000–$200,000 uncurable, and $2,000–$40,000 per day continuing (§ 552.105) — and substantial compliance with the NIST AI RMF, among other routes, is a named affirmative defense (§ 552.105(e)). For licensed or certified personnel, a licensing agency may add sanctions up to suspension or revocation and a penalty up to $100,000, but only after a violation finding and an AG recommendation (§ 552.106). Confirm how these apply to your entity with counsel.
Start your Texas SB 1964 compliance program today
Risk Meridian handles Texas SB 1964 compliance documentation — plus every other major AI regulation — from a single platform. Start now, first AI system inventoried in under 10 minutes.
Covers 6 AI frameworks simultaneously
Document once — reuse across multiple frameworks
Board governance reports in minutes