Research Library · Texas
What to Actually Get From an AI Hiring Vendor Under TRAIGA
Summary: TRAIGA's safe harbor under Texas Business and Commerce Code section 552.105(e) protects a company from liability where a third party misused its AI system in a way it could not reasonably have anticipated. For an employer procuring a hiring tool from a vendor, this creates a real incentive to structure procurement so that any later problem sits clearly on the vendor's side of a documented line, rather than in an undocumented gap that leaves both parties exposed.
The safe harbor provision procurement should be built around
Under section 552.105(e), a company cannot be found liable if someone else uses the company's AI system in a way that violates TRAIGA. Read from the deploying employer's side, the practical question becomes: if your hiring vendor's tool turns out to have a problem you did not know about and could not reasonably have discovered, does your procurement process show that clearly, or does it leave the question genuinely unclear?
The safe harbor rewards employers who can point to a documented, reasonable process, not employers who got lucky. A procurement file with no meaningful diligence does not support a "could not reasonably have anticipated" argument nearly as well as one that shows real questions were asked and real answers were recorded.
What a procurement file should actually contain
A written record of what you asked the vendor. Specific questions about how the tool works, what data it uses, whether it has been tested for discriminatory outcomes, and what happens when it is updated. A generic sales conversation is not documentation.
The vendor's specific answers, in writing. Not marketing claims about "fairness" in the abstract, but concrete responses to concrete questions, ideally referencing testing methodology or a recognized framework.
Vendor contract terms covering AI liability, data handling, and the vendor's own TRAIGA-relevant obligations. A contract silent on these points leaves the employer with nothing to point to if a problem later emerges.
A regular review schedule for the tool, at minimum annual, with dated records. A safe harbor argument weakens considerably if the employer never revisited the tool after initial procurement, since ongoing use without review looks less like reasonable diligence and more like inattention.
A defined process for retiring or modifying a tool found to be producing problematic outputs. Evidence that the employer acts when a problem surfaces is part of what distinguishes reasonable reliance from willful blindness.
Why this differs from the independence requirements elsewhere
Employers used to Local Law 144's rule that a vendor cannot serve as an independent auditor sometimes assume TRAIGA works the same way. It does not, because TRAIGA is not built around an audit requirement at all. The relevant question under TRAIGA is not vendor independence, but whether the employer's own diligence and documentation support a claim that any TRAIGA-relevant problem originated with the vendor's system in a way the employer could not reasonably have caught.
This makes the procurement documentation itself the safe harbor, in a way that is genuinely different from the audit-centric compliance work these employers may already be doing for New York City or EU obligations.
Building this into procurement without slowing hiring down
- Standardize a short vendor questionnaire covering data sources, testing methodology, and update practices, used consistently rather than improvised per vendor.
- Require written answers, not verbal assurances in a sales call, and keep them on file.
- Add TRAIGA-relevant language to vendor contracts as a standard clause, not a one-off negotiation each time.
- Calendar an annual review of every AI vendor in the hiring stack, tied to contract renewal if that is a natural trigger point.
- Define, in advance, who decides to pause or replace a tool if a problem surfaces, so the response is a documented process rather than an ad hoc scramble.
Frequently asked questions
Does the safe harbor mean we are never liable for a vendor's tool? No. It protects against liability specifically where the misuse was something the employer could not reasonably have anticipated. A documented, reasonable diligence process is what supports that claim. It is not automatic.
Is a vendor's general compliance marketing enough documentation? Generally not. The stronger position comes from specific written answers to specific questions, kept on file, rather than general assurances taken from marketing material.
Does this safe harbor interact with the NIST AI Risk Management Framework safe harbor? They are related but distinct. The NIST alignment safe harbor under section 552.105(e)(2)(D) is about the employer's own internal risk management practices. The third-party misuse safe harbor under section 552.105(e)(1) is specifically about problems originating with someone else's system. Building both strengthens the overall position.
How often should vendor documentation be refreshed? At minimum annually, and whenever the vendor materially updates the tool, since a stale procurement file from years earlier does less to support a current safe harbor claim.
Does this replace the need for our own AI governance policy? No. Vendor procurement documentation and an internal AI governance policy address different parts of TRAIGA's safe harbor structure, and a complete position generally needs both.
PeopleNotResumes builds vendor procurement documentation that actually supports a TRAIGA safe harbor claim, not just a signed contract. Our methodology is grounded in behavioural science research from the London School of Economics.