{
  "$schema": "./schema.json",
  "id": "tx-traiga",
  "name": {
    "en": "Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) — AIO formalization",
    "ko": "텍사스 책임 AI 거버넌스법(TRAIGA, HB 149) — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Texas Responsible Artificial Intelligence Governance Act (TRAIGA) — Business & Commerce Code, Title 11, Subtitle D (Chapters 551–554), and amendments to Business & Commerce Code §§ 503.001 and 541.104 and Government Code §§ 325.011, 2054.068 and 2054.0965, added and amended by House Bill 149 (Capriglione)",
    "publisher": "Texas Legislature; enrolled text published by the Texas Legislative Council (Texas Legislature Online)",
    "version": "Acts 2025, 89th Legislature, Regular Session, H.B. 149 (enrolled). Signed by the Governor June 22, 2025; effective January 1, 2026. No amending act in force as of 2026-08-14.",
    "url": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM"
  },
  "vesMapping": [
    {
      "article": "Bus. & Com. Code § 552.051(b)-(e)",
      "summary": "A governmental agency that makes available an artificial intelligence system intended to interact with consumers must disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an artificial intelligence system; the disclosure is owed regardless of how obvious the fact would be to a reasonable consumer, must be clear, conspicuous and in plain language, may not use a dark pattern, and may be delivered by hyperlink to a separate web page.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "GOVERNMENT-SCOPED. The duty in Subsection (b) is imposed on a 'governmental agency', not on private developers or deployers; Subsection (c) then speaks of 'a person', but the disclosure it makes mandatory is 'the disclosure under Subsection (b)', so it does not by its terms create a private-sector duty. A private operator has no general AI-interaction disclosure duty under TRAIGA — only the health care duty at Subsection (f), mapped separately. The judgment correlate an item can reach is narrow and specific: whether obviousness, user sophistication or interface elegance is accepted as a reason to omit or soften the notice, which Subsection (c) forecloses. No item can observe whether an agency's actual interface carries the notice, whether it is conspicuous, or whether the hyperlink route under Subsection (e) is used.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.051(b), (c) and (d), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.051(b)] A governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an artificial intelligence system. [Sec. 552.051(c)] A person is required to make the disclosure under Subsection (b) regardless of whether it would be obvious to a reasonable consumer […] [Sec. 552.051(d)] A disclosure under Subsection (b): (1) must be clear and conspicuous; (2) must be written in plain language; and (3) may not use a dark pattern, as that term is defined by Section 541.001.",
        "rationale": "What the provision protects is the consumer's ability to know what kind of counterparty is answering and so to judge the exchange for themselves (Sdt). Subsection (c) is the operative move: the duty holds 'regardless of whether it would be obvious to a reasonable consumer', which converts a reasonableness judgment into a fixed rule and puts rule-following ahead of situational discretion (Cor); the agency that has made the system available is held to the notice as an obligation it owes each consumer (Bed). What discharges the duty is an artefact conforming to prescribed form — clear and conspicuous, plain language, no dark pattern — which is an established written standard rather than any measurement or expert opinion (Gui). On the source axis the Wave 1 rule applies: Gov is declared because the excerpt itself routes the operative term 'dark pattern' to Section 541.001, a legal instrument decisive on the substance of the duty. Ind is withheld: the duty-bearer here is a governmental agency, not the concerned industry, so the industry-source class does not fit even though the agency authors the notice. No professional body or scholarly source is named, so Pro and Pee are withheld. ADJUDICATION 2026-08-14: E ([Gui]) and S ([Gov]) agreed exactly. Gov survives the Wave 2 source-axis re-check because the excerpt routes the operative term 'dark pattern' to Section 541.001, an external instrument decisive on whether the disclosure complies — not because the duty-bearer is a governmental agency, a route both passes independently refused. V narrows to the intersection [Sdt]: both passes read the consumer's ability to know what kind of counterparty is answering as the protected interest, and each of the divergent codes rests on structure rather than words. Bed was v0.1's reading of a duty owed to each consumer, which is how every statutory duty is drafted; Cor was v0.1's reading of Subsection (c) as converting a reasonableness judgment into a fixed rule, which the second pass read instead as removing an excuse rather than ordering two values; and the second pass's Sda, taken from the dark-pattern prohibition and the plain-language requirement, was reached by one pass only. obligationType stays at mixed against the second pass's behavioral, under the wave-wide rule that a divergent obligationType resolves to the more conservative tag.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Bed, Cor] → [Sdt]; E ([Gui]) and S ([Gov]) agreed exactly and Gov survives the recipient≠source re-check on the Section 541.001 cross-reference; obligationType mixed retained against the second pass's behavioral."
    },
    {
      "article": "Bus. & Com. Code § 552.051(a), (f)",
      "summary": "Where an artificial intelligence system is used in relation to a health care service or treatment, the provider of that service or treatment must give the consumer-interaction disclosure to the recipient or the recipient's personal representative no later than the date the service or treatment is first provided, or, in an emergency, as soon as reasonably possible.",
      "v": [
        "Sdt",
        "Sep"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "PRIVATE-SECTOR REACH. This is the one disclosure duty in TRAIGA that is not confined to government: the addressee is 'the provider of the service or treatment', which on the Subsection (a) definition is an individual licensed, registered or certified under state or federal law to provide health care services — private clinicians and the organisations they practise in included. The duty is triggered by use of an AI system 'in relation to' the service, a phrase the act does not define and which this pack does not attempt to bound. The judgment correlate is the emergency limb: whether 'as soon as reasonably possible' is treated as a duty deferred or a duty dropped. Timing, delivery and record of the disclosure are organizational and unobservable by any item.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.051(a) and (f), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.051(a)] provided by an individual licensed, registered, or certified under applicable state or federal law to provide those services. [Sec. 552.051(f)] If an artificial intelligence system is used in relation to health care service or treatment, the provider of the service or treatment shall provide the disclosure under Subsection (b) to the recipient of the service or treatment […] not later than the date the service or treatment is first provided, except in the case of emergency, in which case the provider shall provide the required disclosure as soon as reasonably possible.",
        "rationale": "The interest protected is the patient's ability to know that a machine is involved in their care and to judge accordingly (Sdt), owed by the provider as an obligation attached to the treating relationship (Bed). The emergency carve-out is not a loophole but a declared ordering: where disclosure and urgent care compete, the provision lets care go first and the notice follow 'as soon as reasonably possible', so bodily safety of the person in front of the clinician is what prevails at that moment (Sep). Two evidence classes are designated. The disclosure itself is discharged by the prescribed form carried over from Subsection (b) (Gui). The emergency judgment — what is 'reasonably possible' in this case — is left to the treating provider, who under the Subsection (a) definition is a licensed, registered or certified individual, which is the considered judgment of one recognised specialist (Exp). Gov is declared because the excerpt names 'applicable state or federal law' as decisive on who counts as a provider. Pro is withheld: the excerpt designates an individual practitioner, not the collective position of a professional body, and the Wave 1 discipline does not allow Pro to be inferred from the presence of licensure. ADJUDICATION 2026-08-14: S ([Gov]) agreed exactly, on the same ground in both passes — 'applicable state or federal law' decides who counts as a provider — and both passes independently withheld Pro in terms, recording that a licensed individual is not a professional body and that licensure alone does not designate the professional source class. That is the clearest agreed withholding in the pack. V narrows to [Sdt, Sep]; Bed, v0.1's reading of the duty as attached to the treating relationship, was reached by one pass only. The two passes also agreed, independently and in almost the same words, on how the emergency proviso works: v0.1 called it 'a declared ordering: where disclosure and urgent care compete, the provision lets care go first', and the second pass wrote the array in AIO 20002 '<' order as Sdt<Sep for the same reason. The ranking is text-grounded — 'except in the case of emergency' — and is recorded here in prose, because the pack schema carries `v` as an unordered set and cannot express a demotion (Wave 2 gap 21, second sighting). E narrows to the intersection [Gui]: Exp was v0.1's reading of the 'as soon as reasonably possible' judgment as the considered opinion of the licensed provider, which the second pass did not reach. obligationType stays at mixed against the second pass's behavioral.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Sep, Bed] → [Sdt, Sep]; E [Gui, Exp] → [Gui]; S ([Gov]) agreed exactly; obligationType mixed retained against the second pass's behavioral. Both passes independently read the emergency proviso as ranking Sep above Sdt; the ranking is recorded in the rationale because the pack format carries unordered sets."
    },
    {
      "article": "Bus. & Com. Code § 552.052",
      "summary": "No person may develop or deploy an artificial intelligence system in a manner that intentionally aims to incite or encourage a person to commit physical self-harm including suicide, to harm another person, or to engage in criminal activity.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "behavioral",
      "note": "BINDS ANY PERSON, including private developers and deployers, subject to the applicability test at § 551.002. This is the closest TRAIGA comes to a duty that is discharged in the act itself, which is why it is tagged behavioral: an item can put commercial or engagement pressure behind a request that shades toward incitement and observe whether the model treats the incitement limb as a bright line. Read the statutory threshold honestly, though: the prohibition bites only where the manner of development or deployment 'intentionally aims' at the listed outcomes. It is not a duty of care, not a duty to prevent foreseeable harm, and not a duty to build safeguards; a system that in fact encourages self-harm without that aim is outside this section. Nothing in an AIO measurement establishes the aim with which a real system was developed or deployed.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.052, added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "A person may not develop or deploy an artificial intelligence system in a manner that intentionally aims to incite or encourage a person to: (1) commit physical self-harm, including suicide; (2) harm another person; or (3) engage in criminal activity.",
        "rationale": "Limbs (1) and (2) protect the physical and psychological safety of the person addressed and of the person they might be turned against (Sep). Limb (3) protects something wider than any one victim — the ordinary lawful order the incitement would erode (Ses) — and, because the limb is defined by the criminality of the conduct urged rather than by its harm, it also puts compliance with law ahead of the requester's purpose (Cor). The evidence axis is an INFERENCE and is flagged for RFC: the provision designates no evidence class at all, and the only thing that can discharge or establish the operative element is reasoning about the manner and aim of the development or deployment from premises about the case, with no outside findings admitted or required (Log). The source axis is left EMPTY, and deliberately so. Under the Wave 1 source-axis rule Gov may be declared only where the excerpt itself names the governing authority or the instrument decisive on the substance; 'criminal activity' names no statute and no authority, and the fact that Chapter 552 is itself a state instrument is never carried in. Leaving the layer undeclared is the honest signal that this provision gives the source axis nothing to grip. ADJUDICATION 2026-08-14: S ([]) and obligationType (behavioral) agreed exactly, and the agreement is worth stating plainly — this is the first entry in the AIO pack series where two independent passes left the source layer undeclared and tagged the provision behavioral at the same time. Both refused the same tempting inference: 'criminal activity' names no statute and no authority, and the fact that Chapter 552 is itself a state instrument is never carried in. V narrows to [Sep, Ses]. Cor was v0.1's reading of limb (3) as putting conformity with law ahead of the requester's purpose; the second pass read the same limb as Ses alone and declared no third code. E is emptied. v0.1's Log was flagged INFERENCE by its own author, and the second pass left the layer undeclared for exactly the reason v0.1 had itself given — the provision designates nothing that discharges or establishes the mental element. Under the standing rule that a code flagged INFERENCE survives only where both passes reached it, and under the textual-determinacy rule that an undeclared layer beats an inferred code, the layer is left empty.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses, Cor] → [Sep, Ses]; E [Log] → []; S ([]) and obligationType (behavioral) agreed exactly. The first entry in the series where two independent passes agreed on an undeclared source layer and a behavioral tag together."
    },
    {
      "article": "Bus. & Com. Code § 552.053",
      "summary": "A governmental entity may not use or deploy an artificial intelligence system that evaluates or classifies natural persons on the basis of social behaviour or personal characteristics, whether known, inferred or predicted, with the intent to calculate or assign a social score, where that score results or may result in detrimental treatment in an unrelated social context, in detrimental treatment that is unjustified or disproportionate, or in the infringement of a constitutional or statutory right.",
      "v": [
        "Unc"
      ],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "GOVERNMENT-SCOPED. The addressee is 'a governmental entity', defined at § 552.001(3) as a state or political-subdivision administrative unit exercising governmental functions, and expressly excluding hospital districts and institutions of higher education. Private social scoring is not prohibited by this section; a private developer's exposure arises only if it is the deployer acting for a governmental entity, or through other law. The judgment correlate an item can reach is the classification move itself — whether a composite estimation of a person built from behaviour or inferred characteristics is treated as portable into an unrelated decision context. Whether a public body has in fact procured or deployed such a system is organizational and outside any measurement. The mapping does not attempt to carry limb (2)'s proportionality test into the value layer, because the vocabulary has no proportionality carrier.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.053, added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "A governmental entity may not use or deploy an artificial intelligence system that evaluates or classifies a natural person or group of natural persons based on social behavior or personal characteristics, whether known, inferred, or predicted, with the intent to calculate or assign a social score […] that results or may result in: (1) detrimental or unfavorable treatment of a person or group of persons in a social context unrelated to the context in which the behavior or characteristics were observed or noted; […] (3) the infringement of any right guaranteed under the United States Constitution, the Texas Constitution, or state or federal law.",
        "rationale": "The interest the section protects is the person's claim not to be subjected to detrimental treatment that is unrelated to, unjustified by or disproportionate to what was actually observed about them — equality of treatment and protection against arbitrary state classification (Unc). Limb (3) routes the prohibition through rights 'guaranteed under the United States Constitution, the Texas Constitution, or state or federal law', which makes conformity with those instruments the second thing that must prevail (Cor). Limb (1)'s object — the movement of an observation out of the context in which it was made — is contextual integrity, an interest the AIO 00011 value layer does not name; the layer is left at two codes rather than papered over with Sep or Sda, and the gap is recorded in the pack notes. The evidence axis is an INFERENCE flagged for RFC: the operative element is an intent to calculate or assign, and nothing but reasoning from the facts of the case establishes it (Log). Gov is declared under the Wave 1 rule on the strength of the named constitutions and 'state or federal law' in limb (3) — not on the strength of the addressee being a governmental entity, which is a duty-bearer relation and not a source relation. ADJUDICATION 2026-08-14: S ([Gov]) agreed exactly and survives the re-check — the two named constitutions and 'state or federal law' in limb (3) are external instruments decisive on whether a right was infringed — and both passes stated expressly that the addressee being a governmental entity is a duty-bearer relation and not a source relation. V narrows to [Unc]. Cor was v0.1's reading of limb (3)'s routing through those instruments as a second thing that must prevail; the second pass read the same limb as part of what Unc already protects and declined a second code, recording separately that the control interest social scoring serves 'is what the provision forbids, not what it protects', which is the same restraint v0.1 showed in leaving limb (1)'s contextual-integrity interest uncoded. E is emptied on the INFERENCE rule: v0.1's Log was flagged by its own author and the second pass left the layer undeclared, both on the ground that nothing is designated as establishing the intent to calculate or assign a social score. obligationType stays at mixed against the second pass's behavioral.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Unc, Cor] → [Unc]; E [Log] → []; S ([Gov]) agreed exactly; obligationType mixed retained against the second pass's behavioral."
    },
    {
      "article": "Bus. & Com. Code § 552.054(b)-(c)",
      "summary": "A governmental entity may not develop or deploy an artificial intelligence system for the purpose of uniquely identifying a specific individual using biometric data, or by targeted or untargeted gathering of images or other media from the internet or any other publicly available source, without the individual's consent, where the gathering would infringe a right of that individual under the United States Constitution, the Texas Constitution, or state or federal law; a violation of Section 503.001 is also a violation of this section.",
      "v": [
        "Sda"
      ],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "GOVERNMENT-SCOPED, with one private-sector hook. The prohibition in Subsection (b) binds a 'governmental entity' only. Subsection (c) then makes any violation of Section 503.001 — the pre-existing Texas biometric identifier statute, which does bind private commercial actors and was itself amended by this Act — a violation of this section, so the private-sector route into Chapter 552 runs through § 503.001, mapped separately in this pack. Two limits worth stating: the definition of 'biometric data' in Subsection (a) excludes photographs and video or audio recordings and data generated from them, and excludes information held for HIPAA treatment, payment or operations; and the Subsection (b) prohibition is conditional on the gathering infringing a right, not on the absence of consent alone. No item can observe what a public body has actually built, scraped or retained.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.054(b) and (c), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.054(b)] A governmental entity may not develop or deploy an artificial intelligence system for the purpose of uniquely identifying a specific individual using biometric data or the targeted or untargeted gathering of images or other media from the Internet or any other publicly available source without the individual's consent, if the gathering would infringe on any right of the individual under the United States Constitution, the Texas Constitution, or state or federal law. [Sec. 552.054(c)] A violation of Section 503.001 is a violation of this section.",
        "rationale": "Two interests are protected at once. The first is the individual's security against being singled out and tracked by the state through their own body — the closest carrier in the value layer is personal security (Sep), used here as an acknowledged stopgap for a privacy interest AIO 00011 does not name. The second is the individual's authority over that use, expressed in the words 'without the individual's consent', which is freedom to determine one's own course (Sda). The rights proviso — 'if the gathering would infringe on any right of the individual under the United States Constitution, the Texas Constitution, or state or federal law' — makes lawfulness the condition of the prohibition and puts rule-conformity in the mapping (Cor). The evidence axis is an INFERENCE flagged for RFC: the operative determinations are purpose and rights-infringement, both established by reasoning from premises rather than by measurement, expert opinion or documented procedure (Log). Consent, the other operative fact, has no carrier in the evidence layer at all; that gap is recorded in the pack notes rather than filled with Gui. Gov is declared on the two named constitutions, 'state or federal law', and the express cross-reference to Section 503.001, each decisive on the substance of the duty. ADJUDICATION 2026-08-14: S ([Gov]) agreed exactly, on the named constitutions, 'state or federal law' and the express cross-reference to Section 503.001 — an instrument outside this section, which is what distinguishes this Gov from the self-reference emptied at § 503.001(f) in this same adjudication. V narrows to [Sda], the one code both passes reached, and this is the sharpest narrowing in the pack. v0.1's Sep was declared in its own rationale as 'an acknowledged stopgap for a privacy interest AIO 00011 does not name'; the second pass reached Unc instead, from the rights proviso; and v0.1's Cor came from that same proviso. Where two independent passes take different nearest codes for the same absent concept the code is not carried and the gap is recorded — Wave 1 gap 2, privacy and personal data, confirmed here for a fifth instrument. What survives is the code the words do carry: 'without the individual's consent' is authority over one's own course (Sda). E is emptied on an empty intersection in which both candidates were flagged by their own authors — v0.1's Log as an INFERENCE, and the second pass's Gui as 'an inference that §4 requires me to flag', read from Subsection (c) importing § 503.001's consent regime. obligationType stays at mixed against the second pass's behavioral.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Sda, Cor] → [Sda]; E [Log] → []; S ([Gov]) agreed exactly; obligationType mixed retained against the second pass's behavioral. Both passes' evidence codes were flagged as inferences by their own authors and neither is carried."
    },
    {
      "article": "Bus. & Com. Code § 503.001(b-1), (e)(2), (f) (as amended)",
      "summary": "For the pre-existing Texas biometric identifier statute, the mere presence online of media containing a person's biometric identifiers is not consent to capture or storage for a commercial purpose unless that person made the media public; the training, processing and storage of biometric identifiers for developing or offering artificial intelligence models or systems is carved out of the section unless a system is used or deployed to uniquely identify a specific individual; and an identifier captured for training that is later put to a commercial purpose outside the carve-out falls back under the section's possession, destruction and penalty provisions.",
      "v": [
        "Sda"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "BINDS PRIVATE COMMERCIAL ACTORS. This is the only place in the Act where a substantive constraint on biometric handling reaches ordinary businesses, and it sits in Chapter 503 rather than Chapter 552 — it is enforced by the attorney general under § 503.001(d), and by § 552.054(c) a violation is also a violation of Chapter 552. Read the carve-out at (e)(2) precisely: it is broad on its face, exempting training, processing and storage for developing, training, evaluating, disseminating or otherwise offering AI models or systems, and it stops only where a system 'is used or deployed for the purpose of uniquely identifying a specific individual'. Subsection (f) is the reversion rule that makes the carve-out purpose-bound rather than permanent. Nothing here is observable in an item-based measurement; what an item can reach is whether public availability of an image is treated as consent, which (b-1) forecloses. ADJUDICATION NOTE (2026-08-14): the source layer of this entry is now undeclared. v0.1 read the excerpt's references to 'Subsection (e)' and to this section's own penalty provisions as a Gov ground; the blind second pass found no external instrument named at all, and the dual formalization resolved that a statutory section is not its own decisive source. Nothing about the substance of the duty changed; what changed is that the pack no longer claims an external authority the excerpt does not name.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 503.001(b-1), (e)(2) and (f), as amended by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 2",
        "quote": "[Sec. 503.001(b-1)] an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier […] based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual […] [Sec. 503.001(e)(2)] the training, processing, or storage of biometric identifiers involved in developing, training, evaluating, disseminating, or otherwise offering artificial intelligence models or systems, unless a system is used or deployed for the purpose of uniquely identifying a specific individual [Sec. 503.001(f)] If a biometric identifier captured for the purpose of training an artificial intelligence system is subsequently used for a commercial purpose not described by Subsection (e) […]",
        "rationale": "Subsection (b-1) protects the individual against having their bodily identifiers taken from public media and treated as freely available — again personal security standing in for a privacy interest the value layer does not name (Sep) — and it locates the decisive act in the individual's own publication choice, which is self-determination in action (Sda). Subsection (f) supplies the third value: an identifier taken under a training purpose may not quietly be repurposed, so the person holding it is bound to the terms on which it was obtained (Bed). The evidence axis is an INFERENCE flagged for RFC. Two determinations carry the provisions — who made the media publicly available, and whether a subsequent use is 'a commercial purpose not described by Subsection (e)' — and both are settled by reasoning about the case rather than by any evidence class the text designates (Log). Gov is declared on the express references to 'Subsection (e)' and to this section's own possession, destruction and penalty provisions, which are the instruments decisive on the substance, following the Wave 1 treatment of self-referential statutory cross-references. Ind is withheld: the possessor of the identifier is regulated by the section, not made the unilateral author of any artefact the section requires. ADJUDICATION 2026-08-14: obligationType (mixed) agreed exactly — the only entry in the pack where the two passes reached the same tag without the conservative rule being applied. V narrows to [Sda]: both passes located the decisive act in the individual's own publication choice, while v0.1's Sep (again an acknowledged privacy stopgap) and Bed (the repurposing bar at Subsection (f)) were reached by one pass only. E is emptied. v0.1's Log was flagged INFERENCE; the second pass's Gui, read from the (e)(2) enumerated carve-out and the (f) purpose test, describes the scope of the provision rather than anything that discharges it, and under §4 the question is what the provision accepts as discharging the duty. Neither code survives the textual-determinacy rule, and the consent record that actually decides Subsection (b-1) fits none of the ten evidence codes — the gap v0.1 recorded, now confirmed from both sides. S is emptied, and this is the entry that settles a question v0.1 itself put to the RFC round. v0.1 declared Gov on the excerpt's references to 'Subsection (e)' and to this section's own possession, destruction and penalty provisions, following the Wave 1 treatment of the Chinese pack's ben banfa, and recorded in the same breath that 'whether an instrument may be its own decisive source is unresolved'. The blind second pass, reading the same excerpt, found that it 'names no constitution, authority, professional body or industry material' and left the layer undeclared. The Wave 2 source-axis rule requires an EXTERNAL public instrument or authority whose content decides the question; a section's cross-reference to its own subsections is not external, and a code flagged as unresolved by the pass that declared it survives only where both passes reached it. The layer is undeclared. The general question is not thereby closed — it is carried to the RFC round as the ruling this entry makes, so that the Chinese pack's treatment can be re-examined against it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Sda, Bed] → [Sda]; E [Log] → []; S [Gov] → []; obligationType (mixed) agreed exactly. The S removal rules that a statutory section's cross-reference to its own subsections is not an external decisive source — the Wave 1 self-reference question, which v0.1 had itself flagged as unresolved."
    },
    {
      "article": "Bus. & Com. Code § 552.055",
      "summary": "No person may develop or deploy an artificial intelligence system with the sole intent that the system infringe, restrict or otherwise impair an individual's rights guaranteed under the United States Constitution; the section is remedial and creates or expands no constitutional right.",
      "v": [],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "behavioral",
      "note": "BINDS ANY PERSON, but on the narrowest threshold in the Act. 'Sole intent' means that a system built with any other substantial purpose is outside this section however severe its effect on constitutional rights; the provision reaches the purpose-built instrument and nothing else. It is tagged behavioral because the duty is discharged, or breached, in the act of building or deploying for that purpose, and because Subsection (b) forecloses any reading that turns it into a source of new rights. Read together with § 552.002(1), which provides that the chapter may not be construed to impose a requirement adversely affecting any person's rights including free speech, this section is best understood as a floor against deliberate instrumentalisation rather than as a positive rights-protection duty. No AIO measurement establishes the intent behind a real system. ADJUDICATION NOTE (2026-08-14): the value layer of this entry is undeclared after dual formalization. v0.1 carried Sdt and Sda as the nearest carriers of the federal constitutional rights catalogue; the blind second pass carried Unc for the same words. Two independent readings reaching different substitutes for the same absent concept is the standing signal that the vocabulary has no carrier, so the layer is left empty and the gap recorded rather than papered over. An item written against this entry must take its direction from the source and obligation layers and from the quoted words, not from a value code the pack does not assert.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.055(a) and (b), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.055(a)] A person may not develop or deploy an artificial intelligence system with the sole intent for the artificial intelligence system to infringe, restrict, or otherwise impair an individual's rights guaranteed under the United States Constitution. [Sec. 552.055(b)] This section is remedial in purpose and may not be construed to create or expand any right guaranteed by the United States Constitution.",
        "rationale": "The protected object is the body of individual rights guaranteed by the federal constitution, which in the AIO value vocabulary is carried principally by the two self-direction codes — freedom to think and judge for oneself, the interest that speech, belief and press protections serve (Sdt), and freedom to choose one's own actions, the interest that assembly, movement and the criminal-procedure guarantees serve (Sda). Because the prohibition is defined entirely by reference to a legal instrument rather than by any harm, conformity with that instrument is itself what must prevail (Cor). The evidence axis is an INFERENCE flagged for RFC: 'sole intent' is established by reasoning from the design and deployment record, and the section designates no evidence class (Log). Gov is declared on the express naming of the United States Constitution in both subsections, which is the instrument decisive on the substance. No professional or scholarly source is named, so Pro and Pee are withheld; no artefact is authored by the regulated person, so Ind is withheld. ADJUDICATION 2026-08-14: S ([Gov]) and obligationType (behavioral) agreed exactly, and the second pass supplied decisive wording v0.1 had not used. Subsection (b)'s statement that the section 'may not be construed to create or expand any right guaranteed by the United States Constitution' makes the Constitution, not this statute, the instrument that fixes the protected position — the cleanest Gov ground in the pack, and the exact inverse of the self-reference at § 503.001(f), where the same axis is emptied in this same adjudication. V is emptied, and this is the pack's only entry with an undeclared value layer. v0.1 read 'an individual's rights guaranteed under the United States Constitution' through the catalogue of interests those rights serve and declared Sdt and Sda; the second pass read the same words as protection and justice owed to persons as such and declared Unc; the two sets share no code. Neither reading is in the quoted words — the provision names a body of rights and does not say which interest within it must prevail — and the standing rule where two independent passes reach different nearest codes for the same absent concept is that no code is carried and the gap is recorded (Wave 3 gap 30). v0.1's Cor, from the prohibition being defined by reference to a legal instrument, was reached by one pass only. E is emptied on the INFERENCE rule: 'sole intent' is established by reasoning, and the section designates no evidence class, which is what v0.1's own flag said.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Sda, Cor] → []; E [Log] → []; S ([Gov]) and obligationType (behavioral) agreed exactly. The pack's only undeclared value layer: the two passes shared no value code, each reaching a different nearest carrier for 'rights guaranteed under the United States Constitution' (Wave 3 gap 30)."
    },
    {
      "article": "Bus. & Com. Code § 552.056(a)(3), (b)-(c)",
      "summary": "No person may develop or deploy an artificial intelligence system with the intent to unlawfully discriminate against a protected class in violation of state or federal law; for the purposes of the section a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.",
      "v": [
        "Unc"
      ],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "behavioral",
      "note": "BINDS ANY PERSON, and is the provision on which TRAIGA most clearly departs from other AI statutes. Subsection (c) is a deliberate legislative choice, not an oversight: a demonstrated statistical disparity in outcomes, standing alone, does not establish the intent the section requires. TRAIGA imposes no algorithmic-discrimination impact assessment, no bias testing duty, no notice duty before a consequential decision, and no duty to offer a human alternative. Two carve-outs narrow it further: Subsection (d) removes insurance entities acting as such where they are subject to the insurance unfair-discrimination regime, and Subsection (e) deems a federally insured financial institution in compliance if it complies with all federal and state banking laws and regulations. The measurable judgment correlate is precise and worth stating plainly: whether the model, presented with an observed outcome disparity, treats it as proof of intent to discriminate or reasons to the standard the statute actually sets — while not treating the intent standard as a reason to dismiss the disparity as unimportant. ADJUDICATION NOTE (2026-08-14): the evidence layer is undeclared, and the emptiness is a positive finding rather than a gap in the reading. Both independent passes identified Subsection (c) as a determination about statistical evidence; the pack records that determination here in prose — measured outcome disparity is expressly denied sufficiency to establish the operative element — rather than by placing Dat in the `e` array, where an unordered set would present the demoted code as a decisive one.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.056(a)(3), (b) and (c), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.056(a)(3)] \"Protected class\" means a group or class of persons with a characteristic, quality, belief, or status protected from discrimination by state or federal civil rights laws, and includes race, color, national origin, sex, age, religion, or disability. [Sec. 552.056(b)] A person may not develop or deploy an artificial intelligence system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. [Sec. 552.056(c)] For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.",
        "rationale": "The interest protected is equal treatment of persons who hold a characteristic, quality, belief or status that civil rights law shields, which is the universalism-concern code in its core sense (Unc). The prohibition is defined by reference to 'state or federal law' and to 'state or federal civil rights laws', so conformity with those instruments is the second thing that must prevail (Cor). Unt was considered and withheld: 'belief' and 'religion' appear in the protected-class list, but the code denotes acceptance of differing views as a disposition, not a legal shield, and the Wave 1 discipline does not permit the extension. The evidence axis carries the most textually grounded assignment in this pack, and it is negative as well as positive. Subsection (c) expressly denies that measured outcome disparity — the statistical-data class — is by itself sufficient to establish the operative element, so Dat is withheld notwithstanding that a discrimination provision would ordinarily attract it; what is left to establish intent is reasoning from the design, deployment and decision record (Log), flagged as INFERENCE only in the sense that the text names no affirmative class. Gov is declared on the named civil rights laws and 'state or federal law'. ADJUDICATION 2026-08-14: S ([Gov]) and obligationType (behavioral) agreed exactly, on 'state or federal civil rights laws' and 'in violation of state or federal law'. V narrows to [Unc]. The second pass declared Unt from 'belief', 'religion' and 'national origin' in the protected-class list; v0.1 had considered and rejected exactly that code in terms, on the ground that Unt denotes acceptance of those who differ as a disposition rather than a legal shield. Where one pass rejects in terms what the other declares, the reasoned rejection is the better-grounded reading. Cor, v0.1's second code, was not reached by the second pass. E is undeclared, and the reasoning is the most consequential in the pack. Both passes read Subsection (c) — 'a disparate impact is not sufficient by itself to demonstrate an intent to discriminate' — as a determination about the statistical-data class, and said so in almost the same words; they divided only on what to do with a code the text expressly demotes. v0.1 withheld Dat outright and recorded the negative determination in prose. The second pass declared it in a demoted position, writing the array in AIO 20002 '<' order as Dat<Gui while flagging that the ordering was 'partly structural' because the text 'names no affirmative evidence type for intent itself'. The pack schema carries `e` as an unordered set, so a demoted code sitting in the array would be read as a decisive one — the precise misreading Subsection (c) exists to prevent — and Dat is therefore not carried. Gui is not carried either: the enumerated definition at (a)(3) fixes who is in a protected class, not what discharges the prohibition. The negative determination stands in prose, where it cannot be inverted, and the schema's inability to express a text-ranked demotion is raised as a second sighting of Wave 2 gap 21 (recorded in the wave-end consolidation, 2026-08-14).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Unc, Cor] → [Unc]; E [Log] → []; S ([Gov]) and obligationType (behavioral) agreed exactly. Both passes read § 552.056(c) as demoting the statistical-data class; Dat is not carried in the array because `e` is an unordered set in which a demoted code would read as a decisive one (Wave 2 gap 21, second sighting)."
    },
    {
      "article": "Bus. & Com. Code § 552.057",
      "summary": "No person may develop or distribute an artificial intelligence system with the sole intent of producing, assisting in producing, or distributing material unlawful under Penal Code § 43.26 or unlawful deep fake videos or images under Penal Code § 21.165, or intentionally develop or distribute an artificial intelligence system that engages in text-based conversations simulating or describing sexual conduct while impersonating or imitating a child younger than 18.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "behavioral",
      "note": "BINDS ANY PERSON. Note the asymmetry between the two limbs, which the mapping does not smooth over: limb (1) requires 'sole intent' and so reaches only the purpose-built generator, whereas limb (2) requires only that the person 'intentionally develop or distribute' a system that engages in the described conversations — a materially lower threshold, and the only place in Subchapter B where the prohibited element is the system's behaviour rather than the builder's aim as to a downstream outcome. Limb (2) is accordingly the strongest judgment correlate in the pack: whether a model asked to sustain a sexualised exchange in a simulated-minor persona treats the persona as the disqualifying fact. Whether a person developed or distributed such a system is not observable in any measurement.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.057, added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "A person may not: (1) develop or distribute an artificial intelligence system with the sole intent of producing, assisting or aiding in producing, or distributing: (A) visual material in violation of Section 43.26, Penal Code; or (B) deep fake videos or images in violation of Section 21.165, Penal Code; or (2) intentionally develop or distribute an artificial intelligence system that engages in text-based conversations that simulate or describe sexual conduct, as that term is defined by Section 43.25, Penal Code, while impersonating or imitating a child younger than 18 years of age.",
        "rationale": "The protected interest is the safety of children, both the identifiable child whose depiction or likeness is at stake and the child on the other side of a simulated-minor exchange (Sep), together with the shared prohibition the criminal law expresses against that category of material (Ses). Because every limb is defined by reference to a Penal Code offence rather than by a described harm, conformity with those provisions is itself what must prevail (Cor). The evidence axis is an INFERENCE flagged for RFC: limb (1) turns on sole intent and limb (2) on what the system does while carrying a persona, and neither designates a class of evidence, leaving reasoning from the case (Log). Gov is declared on the three named Penal Code sections — 43.26, 21.165 and 43.25 — each of which is decisive on the substance of what the limb prohibits. ADJUDICATION 2026-08-14: S ([Gov]) and obligationType (behavioral) agreed exactly, on the three named Penal Code sections — 43.26, 21.165 and 43.25 — each decisive on the substance of what its limb prohibits. V narrows to [Sep, Ses]: both passes read the safety of children and the shared prohibition the criminal law expresses, while v0.1's Cor, from every limb being defined by reference to a Penal Code offence, was reached by one pass only. E is emptied. v0.1's Log was flagged INFERENCE, and the second pass's Gui rests on the same three cross-references that ground Gov on the source axis: they fix what the prohibited material is, not what establishes that a person developed or distributed the system with the required intent or that the system carried the disqualifying persona. Carrying Gui there would make every statutory cross-reference generate an evidence code and leave the evidence axis with no discriminating power at all — which is the criticism v0.1 levelled at its own uniform Log.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses, Cor] → [Sep, Ses]; E [Log] → []; S ([Gov]) and obligationType (behavioral) agreed exactly."
    },
    {
      "article": "Bus. & Com. Code § 552.103(b); § 552.104(b)(2)",
      "summary": "On a civil investigative demand following a consumer complaint, the attorney general may require a person to produce a high-level description of the system's purpose, intended use, deployment context and benefits, the type of data used to program or train it, the categories of input data and of outputs, any metrics the person uses to evaluate its performance, any known limitations, and a high-level description of post-deployment monitoring and user safeguards; and a person who cures a notified violation within 60 days must state that it has made any necessary changes to internal policies to reasonably prevent further violation.",
      "v": [
        "Hum",
        "Cor"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This is the only records-facing provision in TRAIGA and it is emphatically organizational: no item-based measurement produces, or evidences the existence of, any of the artefacts listed. It is mapped because the list is the closest thing the statute has to a documentation standard, and because it is the operative surface an operator meets if a complaint is filed. Two honest limits. First, the duty is contingent — it arises on a civil investigative demand issued under § 552.103(a) following a complaint through the § 552.102 online mechanism, which the attorney general was to post by September 1, 2026, not as a standing filing obligation. Second, § 552.105(c) creates a rebuttable presumption that a person used reasonable care, and § 552.105(e) supplies defences including substantial compliance with the NIST AI Risk Management Framework Generative AI Profile; those provisions are excluded from this mapping as liability rules rather than conduct duties, and no AIO result bears on either. ADJUDICATION NOTE (2026-08-14): the source layer of this entry is now [Ind] alone. The open question v0.1 carried here — whether the attorney general, as the addressee of a production, belongs on the source axis — is answered no. Every item the demand can reach is authored unilaterally by the regulated person about its own system; the attorney general selects what must be produced and contributes none of its content, and a recipient is not a source however compulsory the demand. The counter-reading is recorded in the rationale rather than discarded.",
      "provenance": {
        "sourceUrl": "https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM",
        "article": "Business & Commerce Code § 552.103(b) and § 552.104(b)(2)(B)(iii), added by Acts 2025, 89th Leg., R.S., H.B. 149, SECTION 4",
        "quote": "[Sec. 552.103(b)] The attorney general may request from the person reported through the online mechanism, pursuant to a civil investigative demand issued under Subsection (a): […] (2) a description of the type of data used to program or train the artificial intelligence system; […] (5) any metrics the person uses to evaluate the performance of the artificial intelligence system; (6) any known limitations of the artificial intelligence system; (7) a high-level description of the post-deployment monitoring and user safeguards the person uses for the artificial intelligence system […] [Sec. 552.104(b)(2)] made any necessary changes to internal policies to reasonably prevent further violation of this chapter.",
        "rationale": "Paragraph (6) asks for 'any known limitations of the artificial intelligence system', which is a demand that the operator state where its own system fails rather than where it performs (Hum); the cure provision requires the person to have actually changed internal policy and to say so to the attorney general, which is being answerable for an undertaking already given (Bed); and the whole apparatus operates as conformity with a statutory demand (Cor). Two evidence classes are named in the excerpt itself rather than inferred, which makes this the best-grounded evidence assignment in the pack: 'any metrics the person uses to evaluate the performance' is measurement against declared quantities (Dat), and the post-deployment monitoring, user safeguards and internal policies are documented standing procedure (Gui). On the source axis Gov is declared because the attorney general is named as the party whose demand fixes what must be produced, and Ind because the excerpt makes the regulated person the unilateral author of every artefact listed — the descriptions, the metrics, the account of monitoring, the internal policies — which is the Wave 1 criterion for the industry class. One open question travels with the Gov assignment and is carried to RFC: the attorney general here is the ADDRESSEE of a production, and whether the source axis should carry addressee relations at all was left unresolved at Commitment 9 of the eu-gpai-code pack. ADJUDICATION 2026-08-14: E ([Dat, Gui]) and obligationType (organizational) agreed exactly. This is the pack's only agreed non-empty evidence layer and its best-grounded assignment, and both passes reached both codes from words in the excerpt rather than from structure: 'any metrics the person uses to evaluate the performance' is measurement against declared quantities (Dat), and the descriptions of training-data types, known limitations, post-deployment monitoring and user safeguards, together with the internal policies at § 552.104(b)(2), are documented standing material (Gui). V narrows to [Hum, Cor]: both passes read paragraph (6)'s demand that the operator state its own system's known limitations as Hum and the apparatus as conformity with a statutory demand as Cor, while Bed — v0.1's reading of the cure statement as answerability for an undertaking already given — was reached by one pass only. S is [Ind] and Gov is removed. Both passes declared Ind on the same ground: the excerpt makes the regulated person the unilateral author of every item demanded, which is the source-axis rule's Ind limb. Gov was declared by v0.1 alone, and v0.1 flagged it in the same sentence — 'the attorney general here is the ADDRESSEE of a production, and whether the source axis should carry addressee relations at all was left unresolved at Commitment 9 of the eu-gpai-code pack'. Three independent grounds remove it. First, the recipient≠source convention settled in Wave 2 binds directly: the attorney general requests and receives this material and supplies none of its substance. Second, a code flagged as an open question by the pass that declared it survives only where both passes reached it, and the second pass expressly withheld Gov here. Third, the statutory list at § 552.103(b)(1)–(7) that fixes which items may be demanded sits in the same chapter as the duty, and the self-reference ruling made at § 503.001(f) in this same adjudication denies that an instrument is its own external source. The second pass called this 'the single most contestable call in this pack' and stated the counter-reading itself — that a civil investigative demand is an exercise of decisive public authority rather than a mere request. That counter-reading is recorded and rejected on a stated ground: compulsion goes to whether the material must be produced, not to whose account of the system is to be trusted, and every sentence of what is produced is written by the regulated person about its own system, its own metrics and its own internal policies. The ruling extends the Wave 2 recipient limb from the recipient of a voluntary filing to the issuer of a compulsory demand, which is the strongest form the addressee argument takes anywhere in the series, and it closes the eu-gpai-code Commitment 9 question in the same direction.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Hum, Bed, Cor] → [Hum, Cor]; E ([Dat, Gui]) and obligationType (organizational) agreed exactly; S [Gov, Ind] → [Ind]. The Gov removal extends the Wave 2 recipient≠source convention to the issuer of a compulsory civil investigative demand: the attorney general fixes what must be produced but authors none of it."
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with each provision's normative direction. They do not assess whether a governmental agency actually discloses that a consumer is interacting with an artificial intelligence system, whether a health care provider gave the required notice, whether a governmental entity has deployed a social-scoring or biometric-identification system, whether a person could answer a civil investigative demand under § 552.103, or whether any person falls within the applicability test at § 551.002 at all. Every prohibition in Subchapter B of Chapter 552 turns on a mental element — 'intentionally aims', 'with the intent to', 'sole intent' — and no item-based measurement establishes the intent with which a real system was developed or deployed. Nothing measured against this pack is a defence to an action by the Texas attorney general under § 552.105, evidence of cure under § 552.104, evidence of the reasonable care presumed by § 552.105(c), or evidence of the substantial compliance described in § 552.105(e)(2)(D). After the dual formalization and adjudication of 2026-08-14 the obligationType distribution is unchanged — four behavioral, five mixed, one organizational — and the four behavioral entries (§§ 552.052, 552.055, 552.056, 552.057) are the first group of behavioral entries in the AIO pack series to survive dual formalization, each tagged behavioral by two independent passes without prompting. That is not a claim of measurability: every one of the four turns on an intent element no measurement can establish about a real system. The evidence layer moved in the opposite direction and is now undeclared in seven of the ten entries, because a statute that turns entirely on intent designates no class of evidence that establishes it.",
  "notes": [
    "draft-verified, not active. Every vesMapping entry carries a verbatim excerpt of the enrolled text and a rationale argued from it, and on 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the sourceNorm and each entry's provenance.article and quote, mechanically extracted into .pack-verify/wave3-blind-excerpts-tx-traiga.json; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped before any file was opened, and neither the pack-authoring guideline nor the management guide nor any other pack was opened. One protocol deviation was disclosed by the second pass and is recorded in the contamination notice below. Human review is still outstanding, and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc. Certificates issued against this pack carry a draft-basis notice and record this status as basisStatus in the signed payload. No certificate may be issued against this pack in any case, because no item bank exists for it (see below).",
    "Primary source and retrieval. The text formalized is the enrolled version of House Bill 149, 89th Legislature, Regular Session (2025) — the Texas Responsible Artificial Intelligence Governance Act — retrieved on 2026-08-14 from Texas Legislature Online, the official publication service of the Texas Legislative Council, at https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.HTM. The enrolled version is the text as finally passed by both chambers and signed. No commentary, law-firm summary, trade-press explainer or mirror site was used at any point. Texas statutes are government edicts and are not subject to copyright (Georgia v. Public.Resource.Org, Inc., 590 U.S. 255 (2020)), so verbatim quotation carries no licensing constraint; excerpts are nonetheless kept as short as the provision allows and are cited to the subsection.",
    "Retrieval limitation, recorded rather than hidden. The codified display of the new law — Business & Commerce Code, Title 11, Subtitle D (Chapters 551-554) at statutes.capitol.texas.gov — could NOT be retrieved on 2026-08-14. That site is now a client-rendered single-page application: every document path (Docs/, docs/, GetStatute, StatutesByDate, download) returns the same application shell rather than statutory text, and the underlying document endpoint could not be located from the published bundle. The codified section history lines, which would ordinarily be the second independent confirmation of currency and would carry the session-law chapter number, were therefore not obtained. Currency was established instead by the enacted-bill route described in the next note. The session-law chapter number for H.B. 149 is accordingly NOT asserted anywhere in this pack; the act is cited as Acts 2025, 89th Leg., R.S., H.B. 149.",
    "Currency verification (2026-08-14). H.B. 149 was signed by the Governor on June 22, 2025 and takes effect January 1, 2026 (SECTION 10 of the act; bill history and actions on Texas Legislature Online). It was therefore in force for roughly seven and a half months at the date of this formalization. Amendment was checked positively rather than assumed: the Texas Legislature meets in regular session in odd-numbered years, Texas Legislature Online lists only three sessions of the 89th Legislature (89R, 89(1) and 89(2)) and no 2026 session of any kind, the First Called Session enacted no bills at all ('Bills Signed by the Governor' report for 89(1), retrieved 2026-08-14: none), and of the 31 measures signed in the Second Called Session not one caption mentions artificial intelligence or amends the Business & Commerce Code. No amending act had taken effect as at retrieval. What was NOT verified: attorney general rulemaking or published guidance under Chapter 552, Department of Information Resources rules for the Chapter 553 sandbox, and any litigation construing the chapter. Operators should re-check the codified text before relying on this pack.",
    "Quote verification method. The enrolled HTML was converted to text, normalized to a single-spaced corpus, and every quoted fragment across the ten entries was matched as an exact substring of that corpus — 26 of 26 fragments matched byte for byte. Elisions are marked […] and bracketed citations such as [Sec. 552.051(b)] precede excerpts where one entry quotes more than one subsection; everything outside brackets is verbatim. Quote length: the 400-character convention is exceeded in nine of the ten entries, which is worth recording rather than glossing. Two causes. Most entries span two or three subsections that the statute makes operative only together — a prohibition and its rule of construction, a duty and the definition that fixes its addressee — and splitting them across entries would misrepresent what the section prohibits. And several prohibitions are drafted as one sentence with lettered and numbered limbs that cannot be elided without dropping a limb. Because Texas statutes are government edicts, length carries no licensing risk here, and completeness of the operative limbs was preferred to brevity. Promotion check (2026-08-14): every quote in v0.2 is byte-identical to the corresponding quote in v0.1 — the promotion changed no character of any excerpt, and the blind second pass was given those same strings mechanically extracted from the v0.1 file. A duplicated closing sentence in the v0.1 wording of this note is corrected here; no quoted text was affected.",
    "WHO IS ACTUALLY BOUND — the scoping question this pack exists to answer honestly. TRAIGA is widely described as an AI law for business; most of Subchapter B is not. Of the ten mapped provisions, three bind GOVERNMENT ONLY: § 552.051(b)-(e) (the AI-interaction disclosure, imposed on 'a governmental agency'), § 552.053 (social scoring, 'a governmental entity'), and § 552.054(b) (biometric identification, 'a governmental entity'). 'Governmental entity' is defined at § 552.001(3) as a state or political-subdivision administrative unit exercising governmental functions and expressly EXCLUDES hospital districts and institutions of higher education, so even within the public sector the reach is incomplete. Six bind ANY PERSON within the § 551.002 applicability test: § 552.052 (manipulation), § 552.055 (constitutional infringement), § 552.056 (discrimination), § 552.057 (sexually explicit content and child sexual abuse material), § 503.001 as amended (biometric identifiers for a commercial purpose), and the § 552.103(b) production duty. One — § 552.051(f) — binds the provider of a health care service or treatment, public or private. A private developer or deployer with no health care involvement therefore faces four intent-based prohibitions, one biometric constraint and a contingent production duty, and no general disclosure, assessment, testing, registration or documentation obligation whatsoever. Any reading of this pack that treats it as a private-sector compliance regime is a misreading of the statute.",
    "THE INTENT STANDARD, stated precisely. Every prohibition in Subchapter B is keyed to a mental element, and the drafting is graduated rather than uniform. § 552.052 requires a manner of development or deployment that 'intentionally aims to incite or encourage'. § 552.053 requires 'the intent to calculate or assign a social score'. § 552.056(b) requires 'the intent to unlawfully discriminate'. § 552.055(a) and § 552.057(1) set the highest bar in the act: 'sole intent', which excludes any system built with a substantial additional purpose. § 552.057(2) sets the lowest: 'intentionally develop or distribute' a system that in fact engages in the described conversations. On top of that, § 552.056(c) provides in terms that 'a disparate impact is not sufficient by itself to demonstrate an intent to discriminate'. That subsection is a deliberate legislative choice and this pack states it without softening: TRAIGA does not adopt a disparate-impact standard, imposes no algorithmic-discrimination impact assessment, no bias-testing duty, no pre-decision notice duty and no human-alternative duty, and a demonstrated outcome disparity standing alone does not establish a violation. The consequence for measurement is symmetrical and both halves matter. An AIO item can test whether a model reasons to the standard the statute sets rather than to the standard the model expects a discrimination provision to have — and equally, whether it treats the intent standard as licence to dismiss a measured disparity as unimportant, which the statute nowhere says. What no AIO measurement can do is establish the intent with which a real system was developed or deployed, which is the element on which every one of these prohibitions turns. The dual formalization confirmed the consequence for the evidence axis from the other side. v0.1 read the absence of any designated evidence class as licensing a uniform flagged Log across seven entries, and said in terms that the choice was itself an RFC question. The blind second pass, reading the same excerpts, left the evidence layer undeclared in five of those seven and reached a different inferred code in the other two. The adjudication answers the question v0.1 raised: the diagnosis was right and the coding was wrong. An intent-based prohibition designates no evidence class, and undeclared is the honest way to say so.",
    "ENFORCEMENT AND THE CURE PERIOD. The attorney general has exclusive authority to enforce Chapter 552 (§ 552.101(a)) and the chapter provides no private right of action (§ 552.101(b)). Enforcement begins with a consumer complaint through an online mechanism the attorney general was required by SECTION 8 of the act to post by September 1, 2026, followed by a civil investigative demand under § 552.103. Before suit the attorney general must give written notice identifying the specific provisions alleged to be violated, and may not bring an action before the 60th day after that notice or at all if, within those 60 days, the person cures the violation and provides a written statement that it has cured, supplied supporting documentation, and made any necessary changes to internal policies (§ 552.104). Penalties on failure to cure run from $10,000-$12,000 per curable violation, $80,000-$200,000 per uncurable violation, and $2,000-$40,000 per day of continued violation (§ 552.105(a)); a licensing agency may add sanctions up to $100,000 after an attorney general recommendation (§ 552.106). § 552.105(c) creates a rebuttable presumption that a person used reasonable care, and § 552.105(f) bars a penalty action for a system that has not been deployed. These provisions are excluded from the mapping as enforcement machinery, and nothing measured against this pack is a defence, a cure, or evidence of reasonable care.",
    "THE NIST SAFE HARBOUR, and why it is not mapped. § 552.105(e)(2)(D) provides that a defendant may not be found liable if it discovers a violation through an internal review process where it 'substantially complies with the most recent version of the \"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile\" published by the National Institute of Standards and Technology or another nationally or internationally recognized risk management framework for artificial intelligence systems'; the same subsection also shields discovery through feedback, through adversarial or red-team testing, and through following applicable state agency guidelines. This is the single most consequential provision in the act for a private operator and the only place where TRAIGA names a technical standard. It is nevertheless EXCLUDED from the mapping, under the pack-authoring rule that liability rules and procedural provisions are not conduct norms: it imposes no duty, and reading a normative direction out of a defence would be an inference the text does not support. It is instead covered in the management-system guide, and operators are pointed to the separate AIO nist-ai-rmf pack — with the warning that AIO's formalization of the AI RMF is not the Generative AI Profile the Texas provision names, and that no AIO result evidences substantial compliance with either.",
    "THE SANDBOX, and why it is skipped. Chapter 553 establishes an artificial intelligence regulatory sandbox program administered by the Texas Department of Information Resources, allowing an approved participant to test a system for up to 36 months without a licence or registration, with the attorney general and state agencies barred from acting on waived laws during the testing period. It is excluded from the mapping as a promotional and industry-support programme under the pack-authoring rule that excludes provisions creating institutions, incentives or procedures with no measurable judgment direction. Two features are worth recording rather than merely excluding. First, § 553.051(e) provides that the requirements of Subchapter B, Chapter 552 may NOT be waived, so nothing in this pack is suspended for a sandbox participant — the prohibitions mapped here apply to a participant exactly as they apply to anyone else. Second, § 553.102(b) requires a quarterly report to the department covering performance metrics, risk-mitigation updates and consumer feedback; that is a genuine reporting duty, but it binds only the small set of approved participants and is organizational throughout, so it is left to the management-system guide. Chapter 554 (Texas Artificial Intelligence Council) is excluded on the same ground, reinforced by § 554.103, which bars the council from adopting binding rules or guidance.",
    "Other provisions deliberately excluded, with reasons. (i) §§ 551.001-551.003 (definitions, applicability, rule of construction) and §§ 552.001-552.003 (definitions, construction, local preemption) impose no conduct duty; they are used throughout the rationales and notes instead. (ii) §§ 552.101-552.102 and 552.105-552.106 are enforcement machinery (see the enforcement note). (iii) The Government Code amendments at SECTIONS 5-7 of the act — § 325.011 (Sunset Advisory Commission review criteria), § 2054.068(b)(5) (Department of Information Resources collection of an evaluation of each state agency's use or considered use of AI systems) and § 2054.0965(b)(2) (inventory of agency AI systems in the information resources deployment review) — bind state agencies and the department, not developers or deployers, and create no measurable judgment direction. (iv) The amendment at SECTION 3 to § 541.104(a)(2) extends a processor's existing security-assistance duty under the Texas Data Privacy and Security Act to personal data collected, stored and processed by an AI system; it is a management-system duty inside a different statute, is excluded here, and is carried in the guide. (v) SECTION 9 makes state agency duties under the act contingent on specific appropriation, which is a fiscal provision. Each exclusion is an RFC agenda item.",
    "Applicability and reach, and the limits of this pack's position on it. § 551.002 applies Subtitle D to a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas. The 'consumer' the disclosure duties protect is defined at § 551.001(2) as a Texas resident acting only in an individual or household context, expressly excluding an individual acting in a commercial or employment context — so a workplace or B2B deployment is outside the consumer-facing duties even where it is within the prohibitions. § 552.003 preempts contrary local ordinances and rules. § 552.002 provides that the chapter may not be construed to impose a requirement adversely affecting any person's rights or freedoms including free speech, or to authorise any body other than the Department of Insurance to regulate the business of insurance; § 552.056(d)-(e) carve out insurance entities and deem compliant federally insured financial institutions that comply with banking law. This pack takes no position on when an out-of-state or non-US developer falls within § 551.002, on how the free-speech construction clause interacts with the prohibitions, or on any question of federal preemption. Applicability is a question for the operator's counsel.",
    "Source-axis policy (settled in Wave 1, extended in Wave 2, applied here and extended again). **Gov is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty.** Being the addressee of a duty does not earn it, being the recipient of a report or a production does not earn it, and the fact that the pack's own instrument is a statute does not earn it. **Ind is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is a filter, never a generator: it may remove a code both passes declared and may decide which of two divergent readings prevails, but it never adds a code neither pass declared. After adjudication Gov stands in seven entries and in every one of them on an instrument OUTSIDE the provision: Section 541.001 at § 552.051(d); 'applicable state or federal law' at § 552.051(a); the two constitutions and 'state or federal law' at §§ 552.053(3), 552.054(b) and 552.055; the express cross-reference to Section 503.001 at § 552.054(c); the civil rights laws at § 552.056(a)(3); and Penal Code §§ 43.26, 21.165 and 43.25 at § 552.057. It is absent from § 552.052, where both passes independently refused to read 'criminal activity' as naming an instrument. Two removals were made at adjudication and each settles a question this pack's v0.1 had itself flagged. (1) SELF-REFERENCE — Gov is removed from § 503.001(f), where v0.1 had grounded it on the excerpt's references to 'Subsection (e)' and to this section's own possession, destruction and penalty provisions. A statutory section is not its own external decisive source. The Wave 1 treatment of the Chinese pack's ben banfa rests on the same reasoning and is carried to the RFC round for re-examination against this ruling. (2) COMPULSORY DEMAND — Gov is removed from § 552.103(b), where the attorney general issues a civil investigative demand. This extends the Wave 2 recipient≠source convention, settled on the ca-sb53-tfaia pack for the recipient of a voluntary filing, to the issuer of a compulsory demand: compulsion decides whether material must be produced, not whose account is to be trusted, and every item on the § 552.103(b) list is authored by the regulated person about its own system. Ind survives at § 552.103(b) and appears nowhere else in the pack, exactly as v0.1 predicted. Pro and Pee appear nowhere, and both passes reached that withholding independently at § 552.051(a): TRAIGA names no professional body, accreditation scheme or scholarly source anywhere in Subchapter B, and the licensure reference designates an individual practitioner rather than a collective professional position.",
    "Codes assigned by inference rather than by the words of the text — none survive. v0.1 carried seven flagged Log assignments on the evidence axis (§§ 552.052, 552.053, 552.054, 503.001, 552.055, 552.056 and 552.057) and flagged three further open questions (the self-referential cross-reference at § 503.001(f), the addressee-versus-source problem at § 552.103(b), and the Sep and Sdt/Sda vocabulary stopgaps). Not one of the seven Log assignments was reached by the blind second pass, and all seven are removed under the standing rule that a code flagged INFERENCE by its own pass survives only where both passes reached it. The inference codes the second pass introduced and v0.1 did not reach were treated identically and none survives either: Gui at §§ 552.054, 503.001, 552.056 and 552.057 (flagged as an inference by its own author at § 552.054), Sda at § 552.051(b)-(e), Unc at § 552.054, and Unt at § 552.056, which v0.1 had considered and rejected in terms. The three open questions are all now answered — self-reference no, addressee no, vocabulary stopgaps not carried — and the answers are recorded in the source-axis note and the gap list. The result is that no code in v0.2 rests on the structure of a provision rather than on its words.",
    "Undeclared layers, and what they now mean. After adjudication the evidence layer is undeclared in seven of the ten entries (§§ 552.052, 552.053, 552.054, 503.001, 552.055, 552.056 and 552.057), the source layer in two (§ 552.052 and § 503.001), and the value layer in one (§ 552.055) — the pack's only empty value layer and the second in the AIO series after paragraph 71 of the UNESCO pack. Every one of them is the outcome of two independent readings failing to agree on any code the quoted words carry, and FORMALIZATION_METHODOLOGY.md §4 treats an undeclared layer as the honest signal that the layer is outside scoring scope rather than as a defect. The seven-entry evidence emptiness is the pack's central finding and it is a finding about TRAIGA, not about the formalization: a prohibited-practices statute that turns entirely on a mental element and requires no assessment, no testing, no documentation and no publication designates nothing that discharges or establishes the operative element. The consequence for item authoring is concrete. Seven entries give an item writer no evidence direction to score, one gives no value direction, and § 552.052 gives neither evidence nor source. Items written against those entries must take their direction from the layers that are declared and from the quoted words, and a scoring denominator built from this pack must not count an undeclared layer as an unmet expectation.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack adds two new items, canonical Wave 3 numbers 30 and 31 (renumbered from provisional 24/25 in the wave-end consolidation, 2026-08-14), continuing the consolidated Wave 1 list of ten and the Wave 2 list of eleven to twenty-three; its third finding is recorded as a second sighting of Wave 2 gap 21 rather than a new number. **(30) CONSTITUTIONAL AND FUNDAMENTAL RIGHTS AS A VALUE** — § 552.055 protects 'an individual's rights guaranteed under the United States Constitution' as an undifferentiated body, and the 19-value vocabulary has no carrier for it. v0.1 reached for Sdt and Sda, the second pass for Unc; neither is carried, and the entry's value layer is empty. This is new and is the most likely of the four to recur, since constitutional and fundamental-rights clauses appear in most AI statutes. **(31) MENS REA AS AN EVIDENCE CLASS** — the whole of Subchapter B turns on 'intentionally aims', 'with the intent to' and 'sole intent', and the evidence hierarchy has no code for the state-of-mind determination that establishes such an element. v0.1 raised this as its own fourth gap and used Log as the nearest carrier; the blind pass did not reach Log anywhere, and all seven Log assignments are gone. The gap is confirmed from both sides and is promoted from a v0.1 observation to numbered Wave 3 item 31. **(W2-21 CONFIRMED, SECOND SIGHTING — NOT A NEW NUMBER) TEXT-RANKED DEMOTION HAS NO PLACE IN THE SCHEMA** — this is a schema gap rather than a vocabulary gap and it is the sharpest finding of the second formalization. § 552.056(c) expressly demotes an evidence class ('a disparate impact is not sufficient by itself to demonstrate an intent to discriminate') and the emergency proviso at § 552.051(f) expressly ranks one value below another, but `v`, `e` and `s` are unordered arrays: a code the text demotes cannot be recorded without being read as decisive. The two passes solved it in opposite directions — v0.1 withheld the demoted code and recorded the demotion in prose, the second pass carried the code in AIO 20002 '<' order — and the adjudication took the prose route because the file format cannot carry the ordering. The same problem was recorded independently at Wave 2 gap 21 on the cn-ai-labelling pack, and two independent sightings make it an RFC item about the pack schema itself. Confirmed again rather than newly found: **Wave 1 gap 2 (PRIVACY AND PERSONAL DATA)**, at § 552.054 and § 503.001, where v0.1's Sep was declared a stopgap in its own rationale and did not survive; **CONSENT AS AN EVIDENCE CLASS**, recorded by v0.1 and now confirmed by both passes leaving the layer empty at § 552.054 and § 503.001; and **CONTEXTUAL INTEGRITY** at § 552.053(1), where both passes independently declined to code the interest in an observation not travelling out of the context it was made in.",
    "Relationship to the other packs in this series. TRAIGA is not a stricter or looser version of anything already formalized and no crosswalk between packs is asserted. Against eu-ai-act: the EU regulation classifies systems by risk and imposes conformity assessment, technical documentation, quality management and post-market monitoring; TRAIGA imposes none of these on private actors and works entirely through intent-based prohibitions plus attorney general enforcement. Its prohibited-practice list superficially resembles Article 5 of the EU AI Act — manipulation, social scoring, biometric identification — but the Texas versions of social scoring and biometric identification bind government only, and the Texas manipulation prohibition requires that the deployment 'intentionally aims' at incitement rather than materially distorting behaviour. Against ca-sb53-tfaia: TFAIA is a disclosure statute binding a handful of very large model developers by compute and revenue threshold; TRAIGA binds any person doing business in Texas but demands almost nothing of them affirmatively. Against nist-ai-rmf: TRAIGA does not adopt the AI RMF, but § 552.105(e)(2)(D) makes substantial compliance with the NIST Generative AI Profile part of a liability defence, which is the only cross-reference of its kind in the series and is discussed in the safe-harbour note above.",
    "Measurement scope (per-entry obligationType, pack-level measurementScope). After adjudication the distribution is unchanged from v0.1 — four behavioral (§§ 552.052, 552.055, 552.056, 552.057), five mixed (§ 552.051(b)-(e), § 552.051(a) and (f), §§ 552.053, 552.054 and 503.001) and one organizational (§ 552.103(b)) — but the stability is an outcome rather than a default. The two passes agreed on the tag in six of the ten entries; in the other four the blind pass read a behavioral duty where v0.1 read a mixed one, and each of the four resolved back to mixed under the wave-wide rule that a divergent obligationType takes the more conservative tag. The four behavioral entries, by contrast, were tagged behavioral by both passes independently. That matters for the series: Wave 2 recorded that the only behavioral entry surviving dual formalization anywhere was paragraph 36 of the UNESCO pack, and the behavioral-first claims of two packs were withdrawn at that adjudication. TRAIGA adds four, and the roster's production-time correction — that this is the most behavior-weighted pack in the series — survives the second pass. Read it as the roster records it rather than as praise. The distribution is behavior-weighted because TRAIGA imposes almost no management-system duties on anyone, so there is little organizational material to tag; and each of the four behavioral entries turns on an intent element that no item-based measurement establishes about a real system, so a behavioral tag here reports what kind of duty the provision is, not that the duty is easy to measure. What an item reaches is whether the model reasons to the standard the statute sets when pressure is applied, and nothing about what any organization did. A pass measured against this pack is never evidence that a governmental agency disclosed, that a health care provider gave notice, that no social scoring or biometric system was deployed, or that a person could answer a civil investigative demand.",
    "V/E/S codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary — the same codes an AIO 20002 record carries. Article-to-V/E/S translation methodology: /content/standards-packs/FORMALIZATION_METHODOLOGY.md.",
    "No item bank exists for this pack (itemBankRef.publicSet and privateSet are both null). No certification of any tier can be issued against it, and it is published as a formalization artefact only, listed as catalogued and not yet measurable.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under the fixed policy carried forward from Waves 1 and 2: a code stands only where the quoted text designates it; the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); an undeclared layer beats an inferred code unless the inference was flagged and text-grounded in both passes, or unless one pass cites decisive wording the other missed; ordered hierarchies are accepted only where the text itself ranks; the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two standing sub-rules applied throughout: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent obligationType always resolves to the more conservative tag. Agreement statistics for this pack, across ten entries: V 0/10, E 2/10, S 8/10, obligationType 6/10, all four axes together 0/10. The shape of those numbers is the finding. The source axis agreed at 8/10 — the highest of any pack in any wave — because TRAIGA is unusually dense with express cross-references to named external instruments, which is exactly the condition the source-axis rule was written for; the two disagreements are the two entries where the named instrument was the statute's own text or the attorney general's own demand, and both resolved to undeclared. The value axis agreed at 0/10, and the systematic cause is the same one Wave 2 found on the SB 53 pack: v0.1 declared more value codes than the quoted words carry, reading prohibitions through the interests the referenced instruments protect. Seven of the ten entries lost at least one value code and one lost all of them. Only one entry — § 552.103(b), the single organizational provision, which is also the only one that describes artefacts rather than states of mind — agreed on both evidence codes.",
    "Contamination notice — one protocol deviation, disclosed by the second pass itself and recorded here rather than discovered afterwards. FORMALIZATION_METHODOLOGY.md §4 does not contain the AIO 00011 code tables; it defers the code list to /api/framework/vocabulary. To obtain the actual V/E/S codes the second formalizer followed that pointer through src/app/api/framework/vocabulary/route.ts and src/app/lib/frameworkVocabulary.ts to the VALUES, EVIDENCE_CAT and SOURCE_CAT catalogues in src/app/components/standards/workshopData.ts, lines 1–200. Those files carry code, name and definition data only: no TRAIGA content, no pack field, no first-pass mapping, no obligationType distribution and no prior adjudication. The second pass also saw the file names of sibling .pack-verify second-pass files while listing its own input directory and opened none of them. The assessment is that this is a neutral-codebook deviation and not contamination: the material read is the vocabulary the methodology itself points the formalizer to, it is the same catalogue both passes must use, and it carries nothing about this norm or about how anyone else formalized it. No axis of this pack is reported with a contamination caveat. The deviation is nonetheless recorded because the Wave 1 verification found real contamination through the pack-authoring guideline and the standing practice since then is that the second pass discloses everything it opened. The operational lesson for Wave 4 is that the blind-input bundle should carry the vocabulary catalogue with it, so that a formalizer never has to leave the bundle to learn the code list.",
    "AIO certifies conformance to AIO's own formalization of the Texas Responsible Artificial Intelligence Governance Act. This is not a legal conformity assessment and confers no presumption of compliance. The State of Texas, the Texas Legislature, the Texas Legislative Council, the Office of the Attorney General of Texas, the Texas Department of Information Resources and the Texas Artificial Intelligence Council took no part in this formalization, have not reviewed or endorsed it, and it is not an official interpretation of the act. Nothing measured against this pack is a defence to an action under § 552.105, evidence of cure under § 552.104, or evidence of the reasonable care presumed by § 552.105(c)."
  ]
}
