Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
Context fileUnder Texas Responsible AI Governance Act (TRAIGA), Business and Commerce Code Section 551.054
What does it require?
A governmental entity may not develop or deploy an AI system for the purpose of uniquely identifying a specific individual using biometric data, or of gathering images or other media from the internet or another public source without the individual's consent, where doing so would infringe a right guaranteed under the United States or Texas constitutions or violate state or federal law. The Act preserves lawful uses that comply with existing biometric-privacy law.
Practical action
Require legal sign-off on lawful basis and constitutional review before any agency biometric-matching or public-image scraping project.
Who does it apply to?
Texas governmental entities using AI for biometric identification or collection of public images.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessAI governance lead · once per ai systemProhibited and unacceptable-use screening gate
Serves 7 recorded duties · evidence: Prohibited-use screening record, Screening list and escalation procedure
Screens biometric projects against the ban.
-
supportsProcessData protection officer · once per ai systemPrivacy and data-protection controls for AI
Serves 13 recorded duties · evidence: Data protection impact assessment for an AI system, AI data-flow and legal-basis record, Privacy notice section on AI use
Consent and lawful basis for biometric data.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Legal review of biometric AI use | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every Texas (United States) duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | GOVERN 1.1, MEASURE 2.10 | Legal requirements and privacy risk. | medium |
| ISO/IEC 42001:2023 | Annex A.5.2, A.7.3 | Impact assessment and data acquisition. | medium |
Cite this record
AIPolicyTracker (2026). “Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights (Texas Responsible AI Governance Act (TRAIGA))”. https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: HB 149 (89R) history and enrolled text, Texas Legislature Online, https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149.
Similar obligations in other instruments
- Do not deploy or provide AI for prohibited practices — EU AI Act, European Union
- Developers and deployers must not use AI to incite self-harm, harm to others or crime — Texas Responsible AI Governance Act (TRAIGA), Texas (United States)
- Governmental entities must not use AI for social scoring — Texas Responsible AI Governance Act (TRAIGA), Texas (United States)
- Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class — Texas Responsible AI Governance Act (TRAIGA), Texas (United States)
- Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes — Texas Responsible AI Governance Act (TRAIGA), Texas (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.