Research Library · Texas
The TRAIGA Safe Harbor: How NIST AI RMF Alignment Actually Works
Summary: Under Texas Business and Commerce Code section 552.105(e)(2)(D), a company has an affirmative defense to a TRAIGA violation if it substantially complies with the most current NIST AI Risk Management Framework, including its Generative AI Profile, or a comparable recognized framework. This is one of TRAIGA's most underused protections, and it works alongside a separate 60-day cure period under section 552.107 that gives companies a further chance to fix a violation before enforcement proceeds.
The two-layer protection structure
TRAIGA gives Texas employers two distinct chances to avoid liability, and they are easy to conflate but worth keeping separate.
The NIST safe harbor is a defense based on how you were operating before any violation was ever alleged. If you can show substantial compliance with the NIST AI Risk Management Framework, or a comparable framework, you have an affirmative defense regardless of when a problem is discovered.
The 60-day cure period is a separate, later opportunity. Once the Attorney General provides written notice of an alleged violation, the company has 60 days to cure it. A complete and timely cure, certified in writing, bars civil action for the noticed violation.
An employer with strong NIST alignment is defending an underlying claim. An employer using the cure period is stopping enforcement on a specific notice. The strongest position has both available.
What substantial compliance with NIST AI RMF actually means
The NIST AI Risk Management Framework is organized around four core functions: Govern, Map, Measure, and Manage. For a hiring context, substantial compliance does not require a full enterprise-scale implementation. It requires documented practice mapped to each function.
Govern. A documented AI governance structure: who owns decisions about which AI hiring tools are adopted, who is accountable for their outputs, and what policy governs their use.
Map. An inventory of where AI is actually used in the hiring process, and an understanding of the context each use sits in, including who is affected and how.
Measure. Testing and evaluation of AI tool outputs, including for discriminatory effects, rather than assuming a vendor's tool performs fairly without checking.
Manage. A documented process for responding to problems the measurement step identifies, including remediation and, where necessary, retiring a tool.
Organizations that already maintain NIST AI RMF documentation for federal contracts or for other regulatory purposes, including EU AI Act preparation, can generally extend that same documentation to support a TRAIGA safe harbor claim rather than building a separate program from scratch.
What "substantial" compliance does not require
This is not full enterprise implementation with dedicated headcount. For a small or mid-sized employer, alignment means documenting AI risk practices against the four functions in a way that is genuine and auditable, not a certification program. The bar is substantial compliance, not perfect compliance.
Building a defensible governance file
- Draft an AI governance policy, adapting an existing acceptable use policy if one already exists rather than starting from nothing. Cover prohibited AI uses aligned to TRAIGA's list, the approval process for adopting new AI tools, and an escalation path for concerns.
- Maintain a current AI tool inventory, including tools individual teams or staff have adopted independently, since an incomplete inventory undermines the Map function.
- Document testing and evaluation activity, even informal internal review, rather than relying solely on vendor assurances.
- Keep a dated record of governance activity, since a NIST safe harbor claim depends on showing substantial compliance existed before a violation was alleged, not documentation assembled afterward.
- Prepare an intake process for AG notices that can move quickly toward a written cure certification within the 60-day window, since that second layer of protection depends on speed once notice arrives.
Why documentation timing matters
A safe harbor built on NIST alignment is meaningfully weaker if the documentation was created after a violation was already alleged. The defense depends on showing the company was substantially complying with the framework as an ongoing practice, not that it produced paperwork retroactively once a problem surfaced. This is the strongest practical argument for building the governance file now, regardless of whether any specific concern currently exists.
Frequently asked questions
Does the NIST safe harbor require certification by NIST itself? No. NIST does not certify organizations. The defense rests on demonstrated substantial compliance with the framework's practices, documented by the company itself.
Can a comparable framework other than NIST AI RMF satisfy this defense? Yes. The statute allows another nationally or internationally recognized AI risk management framework, which can include frameworks like ISO/IEC 42001, provided the substance of the compliance is genuine.
What happens if we receive an AG notice and have no NIST documentation at all? The 60-day cure period is still available regardless of prior NIST alignment. A complete, timely, written cure can still bar civil action for the specific violation noticed, though the underlying affirmative defense is stronger with prior documented compliance.
Is the NIST safe harbor available for government use of AI as well as private employer use? This paper addresses the private employer context. Government use of AI under TRAIGA sits under separate, more extensive obligations.
How is this different from a bias audit under Local Law 144? A bias audit is an outcome-focused statistical exercise required annually. NIST AI RMF alignment is a broader governance framework covering how AI risk is managed generally, and it functions as a legal defense under TRAIGA rather than a standalone audit deliverable.
PeopleNotResumes builds TRAIGA governance files structured around the NIST AI RMF's four functions. Our methodology is grounded in behavioural science research from the London School of Economics.