Texas TRAIGA

HB 149: safe harbor and prohibited-use detection

Texas HB 149 (Responsible AI Governance Act) takes effect 2026-01-01 and applies an intent-based liability framework to AI development and deployment in Texas. The Act provides a safe harbor at BCC 552.105(e)(2)(D) for organisations that substantially comply with the NIST Generative AI Profile and operate an internal review process.

Asqav signs every AI agent action with ML-DSA, retains it under the longer of HIPAA six years or any Texas-required period, and emits stable reason codes for the prohibited-use categories of BCC 552.052.

The receipt format is profiled in the IETF Internet-Draft draft-marques-asqav-compliance-receipts.

How Asqav supports HB 149 obligations

Section Requirement Asqav binding
BCC 552.105(e)(2)(D) Safe harbor for substantial compliance with NIST Generative AI Profile and an internal review process. Audit pack as evidence. NIST AI RMF binding co-applied via the same receipt substrate.
BCC 552.052 Prohibited-use categories: incitement of self-harm, harm to another, criminal activity. Three stable reason codes on deny receipts: prohibited_self_harm_incitement, prohibited_harm_to_another, prohibited_criminal_activity.

Bring-your-own KMS, customer-owned storage, and on-prem mode are available for deployer profiles that disallow outbound traffic. See the docs for the full mapping and the IETF draft for the binding text.