Texas Public-Sector AI Rules Are in Force: What IT Leaders Should Do Before August 31

Texas public-sector organizations now have two related—but distinct—artificial intelligence responsibilities to manage: annual AI-awareness training and a broader governance framework for government AI systems. With the Texas Department of Information Resources (DIR) setting August 31 as the annual date for government entities to certify training compliance, late August is a useful checkpoint for both requirements.

The most important legal-status update is that the rules first proposed in November 2025 are no longer merely proposals. DIR’s final rules in 1 Texas Administrative Code Chapters 218 and 219 were adopted with an effective date of March 18, 2026, according to the March 13, 2026 Texas Register adoption notice. Chapter 219 establishes an AI code of ethics and minimum governance standards for state agencies and local governments.

The August 31 training deadline

Texas Government Code Sections 2054.5191 and 2054.5193 created an annual certified AI-awareness training program for covered state and local government personnel. DIR’s current public-sector AI awareness training page says government entities must certify compliance annually by August 31 using DIR’s reporting form.

For state agencies, the requirement generally covers employees who use a computer for at least 25 percent of their duties and elected or appointed officers. For local governments, it generally covers employees and officials who meet the 25-percent computer-use threshold and have access to a government computer system or database. DIR also explains an important K-12 distinction: only a school district’s cybersecurity coordinator is specifically required to complete the annual AI training; the district determines any additional covered employees in coordination with that official.

DIR provides a certified training option at no cost, but it does not track completion or issue certificates. Employers therefore remain responsible for keeping their own completion records. DIR also says entities may use any tracking method they choose and should not submit individual training records or employee certificates with the annual certification.

Training is only one part of the new framework

The annual awareness course should not be mistaken for the full AI-governance program. Under the adopted Chapter 219 rules, state agencies and local governments must adopt the state AI code of ethics and follow its principles when procuring, developing, deploying, or using AI systems. Those principles cover human oversight, fairness, accuracy, transparency, redress, privacy, security, and accountability.

The rules impose additional controls when an organization develops, procures, deploys, or uses a heightened scrutiny AI system—an AI system intended to autonomously make, or serve as a controlling factor in making, a consequential decision. The final Texas Register text requires state agencies and local governments to designate an AI Risk Officer and establish a process for identifying and inventorying heightened-scrutiny systems.

Before deploying such a system—and again after a material change—the organization must complete a written risk assessment. The assessment must address known security risks and mitigations, performance metrics related to accuracy and operational efficiency, and transparency concerning algorithms, training data, inputs, and outputs. The AI Risk Officer must review the assessment and approve or deny deployment. Relevant documentation must be retained under the applicable records-retention schedule.

Chapter 219 also requires acceptable-use policies and role-appropriate risk training for employees or contractors who access, use, or manage heightened-scrutiny systems. Contracts for vendor-deployed heightened-scrutiny AI must require the vendor to implement the NIST Artificial Intelligence Risk Management Framework or a comparable standard.

A practical readiness checklist

  1. Confirm the covered population. Apply DIR’s role, system-access, and computer-use criteria rather than assigning the course based only on job title.
  2. Complete and document certified training. Keep an internal roster or equivalent evidence because DIR’s free course does not track completion.
  3. Submit the annual certification. Use the reporting link on DIR’s current training page by August 31.
  4. Name the AI Risk Officer and inventory higher-risk uses. Look beyond standalone chatbots; consider AI embedded in hiring, benefits, eligibility, discipline, fraud detection, public services, and other consequential workflows.
  5. Review policies and contracts. Check acceptable-use rules, privacy controls, human-review procedures, incident escalation, vendor transparency, risk-assessment obligations, and records retention.

The NIST connection is still evolving

Texas explicitly anchors its governance approach to the NIST AI RMF. NIST states that AI RMF 1.0 is currently being revised, and its newly final NIST IR 8578, published August 3, 2026, summarizes governance and operational issues raised during development of a Cybersecurity Framework Community Profile for AI. IR 8578 is a workshop summary—not a new compliance standard—but it reinforces the value of connecting AI governance with existing cybersecurity processes.

The immediate priority is straightforward: complete and certify required training by August 31, while treating that course as the beginning—not the end—of an operational AI-risk program.

This article provides general information and is not legal advice. Organizations should review the current statutes, rules, and DIR guidance and consult qualified counsel regarding their specific obligations.

Primary sources