Texas TAC Chapter 219: What It Requires

Scinary Logo

This year in Texas, new AI governance rules for state agencies and local governments got adopted, TAC Chapter 219. It reaches state agencies, institutions of higher education, and local governments. Anytime rules get added it always seems, and often is, daunting. But TAC 219, honestly, isn’t too bad. The big thing preventing this from being a huge nightmare is the scope that has been defined. That being a “heightened scrutiny AI system.”

Now, what is a heightened scrutiny AI system, you may ask. Well, it’s defined as an AI system specifically intended to autonomously make, or be a controlling factor in making, a consequential decision. It excludes systems intended to do the following:

  • A Narrow Procedural Task
  • Improve Already-Completed Human Work
  • Do Preparatory Work

Another definition that we believe is important is "consequential decisions.” Which means a decision that has a material legal or similarly significant effect on the provision, denial, or conditions of a person's access to a government service.

Now, before we get into why that’s a major deal, let’s first address the very first step in this process, the assignment of an AI Risk Officer. TAC 219 requires you to delegate this responsibility to an employee. That employee can be an existing employee, or you can hire someone to fill the role. Let me know if you have the budget to do that one! The rule does outline the responsibilities of this role as follows:

“The AI Risk Officer is responsible for promoting ethical AI system procurement, development, deployment, and use within the state agency or local government, consistent with the AI Code of Ethics established by this chapter and the AI Risk Management Framework published by the National Institute of Standards and Technology.”

AND

“If a state agency or local government deploys a heightened scrutiny AI system, the AI Risk Officer is responsible for ensuring that the risk assessment is completed for that system. The AI Risk Officer shall evaluate the completed risk assessment and ensure that the heightened scrutiny AI system is deployed consistent with the minimum standards established by this chapter.”

So before doing anything else, start here, pick someone, run a lottery, draw straws. No matter how you come to your selection, you need to assign this role within your organization before moving on.

Now, as mentioned, the defined scopes are what trigger additional requirements for you as a local government or state agency. But they are specific enough that, in our view, they leave most instructional and productivity AI outside the line. If you are unclear if an AI system falls into the category of a heighted scrutiny AI system during your inventory process, I believe asking the following question can help:

Does my AI system, or an AI feature of a system, decide or substantially drive a decision, about a stakeholder’s access to a government service?

If the answer is yes, you most likely have a system that falls under the heightened scrutiny classification. As such, one or even both of the following assessments are going to be required.

THE RISK ASSESSMENT

This is a requirement that applies to state agencies and local governments alike.

Before you develop, procure, deploy, or use a heightened scrutiny AI system, and again at the time a material change is made to the AI system, you need to conduct this assessment. It must also be written and retained, so, no storing it in your head! The assessment has three major requirements to consider and document;

Known security risks and available mitigation steps;

Performance metrics relating to accuracy and operational efficiency and;

Transparency

Specifically documenting:

  • The system's algorithms and how it makes decisions
  • The data used to train the model
  • The availability of inputs and outputs to monitor decision-making over time

Once this risk assessment is completed, the AI Risk officer is to review the assessment and prior to deployment of the AI system, make a decision to approve or deny the system. At a minimum they must notify the agency head of the decision, then the AI risk assessment needs to be retained.

Now, the way we read this is that it does not establish any specific risk level that you can or cannot accept. This is why it’s important for you as an organization to define risk tolerance. Without that understanding, decisions like this are reliant on the individuals’ risk acceptance which may not be representative of the organizations’ risk acceptance. You can watch our podcast episode where we talk about this very thing here.

Should Private Companies Be Allowed to Hack Back?

This week, we review the new executive order pushing for "free" cybersecurity for critical infrastructure and question how it will actually be funded. We also debate the controversial authorization of private companies to launch offensive cyber "hack-backs" and the potential collateral damage to shared infrastructure like AWS and Cloudflare.

For the main topic, we answer a viewer question: What do you do if you inherit an organization with no cybersecurity? We lay out a foundational plan starting with risk analysis and immediate network segmentation to stop the bleeding. From locking down firewalls to avoiding the "bystander effect," we outline how to build a security program that continuously improves.

THE AI IMPACT ASSESSMENT

This is a requirement written for state agencies. Meaning school districts, because of their definition as local government, are only required to consider conducting an impact assessment. I will mention that public junior colleges sit in an unusual spot here. Given the standing Chapter 2054 exemption in 2054.0075, which labels them as local government and not a state agency. As such, we believe that the only requirement for public junior colleges is also the consideration of the impact assessment. But we are not lawyers. So, I would consult with your legal counsel here.

As a state agency, if you plan on deploying or using a heightened scrutiny AI system, you’re going to need to conduct an AI impact assessment. Specifically, before deploying the system and at the time of any material change to the system, the state or local data the system uses, or to the intended use of the system.

The impact assessment must include:

  • A description of the system, including: its training data, model, and intended use.
  • How the institution will use it, and who internally owns deployment plus ongoing monitoring and evaluation.
  • Whether the system will process or store PII provided by the institution or its users, and if so, whether it will use that information to train the model.
  • Potential risks of unlawful harm the institution identifies, and the steps it can take to limit them.
  • System limitations the institution identifies
  • How the institution will monitor outputs to evaluate accuracy and harm, and at what intervals.
  • The retention duration for inputs and outputs, and the method for deleting outputs once that period has passed.

All of these requirements are fairly standard. Now the first step is the one that may sound a little difficult to achieve. However, based on the public notice example provided by DIR, it may be that a more generalized answer on what the model was trained on is okay. As an example,

Our AI agent is a pre-trained model from Anthropic. It also pulls from our public facing website to help stakeholders answer questions and find information within the website quickly.

One concern here is that it’s not expressly defined what is needed to satisfy the training data description. If they want more detailed information on training data, this may be hard to source. Additionally, with embedded AI functions that would fall under this requirement, ones you may get from a vendor or third-party, could add additional issues to the mix. As it may be hard to get them to give up information on what they are utilizing on the backend.

HOW SCINARY CAN HELP

Scinary customers utilizing our Centurion package have access to Governance, Risk, and Compliance help. We can provide consulting and templates for the drafting of AI policies and language tailored to your district or organization. We can also help you answer whether a given system constitutes a heightened scrutiny AI system.

Additionally, through the use of our endpoint detection & response agent, ThreatDown, we can see which AI systems end users are running on the machines where it is deployed. This lets us build inventories and alert on unauthorized use of AI systems in your environment. Combined with the DNS filtering add-on, we can block domains associated with unauthorized AI applications to ensure compliance with your policy.