
Key takeaways
- TRAIGA (
HB 149) has applied since 1 January 2026 and reaches any organisation that develops or deploys an AI system used by Texas residents, whatever the state of incorporation. - The statute bans seven specific practices. Three bind government entities only, which is why most private deployers clear the prohibitions on a first read.
- TRAIGA turns on intent, not outcome. Section
552.056states that disparate impact alone does not establish unlawful discrimination. - The practical obligation is evidentiary. Section
552.105(e)(2)(D)grants an affirmative defense for substantial compliance with the NIST AI Risk Management Framework. - Enforcement sits solely with the Texas Attorney General, with a 60-day cure period and penalties reaching 200,000 dollars for an uncurable violation.
What TRAIGA is, and what changed on 1 January 2026
The Texas Responsible Artificial Intelligence Governance Act, universally shortened to TRAIGA, was signed by Governor Greg Abbott on 22 June 2025 and took effect on 1 January 2026. Almost every analysis still circulating was written in the fortnight after signature, when the interesting question was what the legislature had just done. That question is settled. The interesting question now is what a compliance owner has to be able to show. TRAIGA arrives as HB 149 and adds four new chapters to the Texas Business and Commerce Code. Chapter 551 carries general provisions and definitions. Chapter 552 holds the prohibitions and the enforcement machinery, and is the chapter that matters for most readers. Chapter 553 creates a regulatory sandbox administered by the Texas Department of Information Resources. Chapter 554 establishes the Texas Artificial Intelligence Council. The law also amends the state’s existing biometric statute at 503.001, which is the provision most often missed. What makes TRAIGA worth reading closely is not its breadth. It is narrower than the drafts that preceded it and narrower than most comparable regimes in our global map of AI laws. What makes it worth reading is its shape. TRAIGA is the first significant US state AI law built around prohibited conduct and an affirmative defense rather than around filings, assessments and registrations. That shape has since proved contagious.
Who is actually covered
Scope is behavioural rather than geographic. TRAIGA reaches a person who develops or deploys an AI system in Texas, who advertises, promotes or conducts business in the state, or who offers a product or service used by Texas residents. A company headquartered in Boston or Berlin with Texas customers is inside the perimeter. Incorporation is not the test, and there is no revenue or headcount threshold to fall below. The practical consequence is that scoping cannot be answered by the legal entity chart. It has to be answered from an inventory of AI systems and the populations they touch, which for most organisations is the single hardest input to produce.
The prohibited practices, section by section
TRAIGA prohibits seven things. Reading them as one undifferentiated block is the most common mistake, because they do not all apply to the same people.
Duties that fall on government entities only
Section 552.051 requires a government agency to disclose, in clear and conspicuous language, that a person is interacting with an AI system. The disclosure must come before or during the interaction and cannot be buried in a terms-of-service page. Section 552.053 prohibits a governmental entity from using AI to assign a social score or similar categorical estimation that results in detrimental treatment. Section 552.054 prohibits a governmental entity from using AI to uniquely identify a specific individual using biometric data without consent. These three are the reason commentary describes TRAIGA as a law aimed principally at the public sector. For a private deployer, they are context rather than obligation, unless you sell into Texas agencies, in which case they arrive through your contracts.
Duties that reach private developers and deployers
Section 552.052 prohibits developing or deploying an AI system intended to incite or encourage a person to commit physical self-harm, harm to another, or criminal activity. Section 552.055 prohibits developing or deploying an AI system with the sole intent to infringe, restrict or otherwise impair an individual’s constitutional rights. Section 552.056 prohibits developing or deploying an AI system with intent to unlawfully discriminate against a protected class. The section says expressly that disparate impact is not sufficient on its own to demonstrate intent. Section 552.057 prohibits AI systems designed to produce child sexual abuse material or sexually explicit deepfakes. Read honestly, a normally run enterprise clears all four. Nobody builds a hiring model with the intent to discriminate, and the statute does not ask whether the model in fact discriminates. That is precisely why the prohibitions are not where your compliance effort should go. The bias testing you already run remains worth running, but under TRAIGA it functions as evidence rather than as a duty.
Intent, not impact: the standard that defines TRAIGA
The defining choice in TRAIGA is the intent standard. The EU AI Act and the original Colorado statute both asked whether a system could produce a prohibited outcome and obliged you to find out in advance. TRAIGA asks whether you meant to produce it. This is genuinely lighter, and the relief is real. There is no duty of care, no mandatory impact assessment, no registration, no algorithm filing. Earlier drafts contained a general disclosure obligation for private deployers and a mandatory risk-mitigation policy; both were removed before enactment, as K&L Gates documented at the time. The trap is what an intent standard does to a dispute. When liability turns on outcome, the argument is about statistics. When it turns on intent, the argument is about what you knew, what you were warned of, and what you did next. Every internal document becomes potential evidence in both directions: a red-team report showing you found a problem and fixed it is exculpatory, and the same report showing you found a problem and shipped anyway is not. TRAIGA does not require you to run AI risk management. It quietly makes the record of it the thing you will be judged on.
The safe harbour is the whole game
This is the provision that most summaries mention in a sentence and then leave. Section 552.105(e)(2)(D) gives a person an affirmative defense to a TRAIGA violation where they substantially comply with the most current version of the NIST Artificial Intelligence Risk Management Framework, including the Generative AI Profile NIST-AI-600-1, or with another nationally or internationally recognised risk management framework for AI systems. Read that back slowly. A law with no mandatory assessment and no filing obligation nonetheless names a specific external framework and makes conformance with it a defense. The obligation did not disappear. It moved from the front of the process, where a regulator would have collected it, to the back, where your own counsel will need it.
What substantial compliance has to look like
Substantial compliance is not a certificate and there is no Texas registry of conformant firms. It is a claim you make and then have to support, which means it lives or dies on documentation. In practice that means the four NIST AI RMF functions with evidence attached to each: GOVERN as recorded policy, roles and accountable owners; MAP as a system inventory with documented purpose and context; MEASURE as test results, evaluations and red-team findings with dates; MANAGE as tracked treatment of the risks those measurements surfaced. The operative word is dated. A framework adopted after receiving an Attorney General notice is not substantial compliance, it is a reaction. The defense only exists if the record predates the complaint.
The other three routes to a defense
Substantial compliance is not the only path. TRAIGA also recognises violations discovered through internal testing, red-teaming or adversarial evaluation, which rewards organisations that go looking for their own faults. It recognises compliance with guidance issued by an applicable state agency. And it recognises action taken on feedback from a documented internal review process. Separately, the statute shields developers and deployers where a third party misuses their system in violation of the Act. The shield is not automatic in effect: showing that misuse was the third party’s requires that you can show what your system was designed and instructed to do, which is again a documentation question. Our guide to auditing AI systems covers how to structure those tests so their output is usable later.
Enforcement: who acts, how fast, and what it costs
Enforcement is centralised and narrow. Section 552.101 gives the Texas Attorney General exclusive authority to enforce the chapter. There is no private right of action, so TRAIGA does not open a class-action channel, a point critics including EFF-Austin have raised as a weakness in consumer protection. The sequence is worth memorising. Section 552.102 requires the Attorney General to maintain an online mechanism for consumer complaints. Section 552.103 authorises a civil investigative demand once a complaint is received, and that demand can reach into operational detail including training data. Section 552.104 requires written notice and bars suit before the sixtieth day after that notice, giving a cure window. Penalties under 552.105 are tiered. A curable violation runs from 10,000 to 12,000 dollars. An uncurable violation runs from 80,000 to 200,000 dollars. A continuing violation adds 2,000 to 40,000 dollars per day. Section 552.106 lets state agencies layer further sanctions on licensed entities, including suspension and fines up to 100,000 dollars. The number that should shape your design is not the 200,000 dollar ceiling. It is the 60 days. A cure period is only useful to an organisation that can identify every affected system, establish what it did, and change it inside two months. That is an operational capability, and it is the same capability that AI incident reporting readiness demands. Organisations that cannot inventory quickly will watch curable violations mature into uncurable ones by default. One caveat on the current state of play. TRAIGA is young, the Attorney General’s enforcement apparatus and the Department of Information Resources rulemaking have been standing up across 2026, and there is no meaningful body of enforcement practice yet. Plan against the statute, not against precedent, because precedent does not exist.
TRAIGA and Colorado after the 2026 reset
For eighteen months the standard framing was that Colorado had the demanding US state AI law and Texas had the light one. That framing is obsolete. On 14 May 2026 Governor Polis signed SB 26-189, which repeals the Colorado AI Act and replaces it with the Automated Decision-Making Technology Act, effective 1 January 2027. The replacement drops the duty of care, the risk management programme requirement and the mandatory impact assessments in favour of a disclosure-based framework, as Skadden set out in its analysis. Colorado moved toward Texas, not the other way round. That matters for how you build. The two surviving state regimes now differ in mechanism but converge in what they ask you to hold: <table header-row=”true”> <tr> <td></td> <td>TRAIGA (Texas, in force)</td> <td>Colorado ADMT Act (from Jan 2027)</td> </tr> <tr> <td>Trigger</td> <td>Intent to cause a prohibited harm</td> <td>Consequential decisions about consumers</td> </tr> <tr> <td>Discrimination test</td> <td>Intentional only, disparate impact insufficient</td> <td>Not a general duty of care</td> </tr> <tr> <td>Impact assessment</td> <td>Not required</td> <td>Not required after the repeal</td> </tr> <tr> <td>Core private-sector duty</td> <td>Avoid prohibited practices</td> <td>Disclose, including adverse outcomes</td> </tr> <tr> <td>Protection mechanism</td> <td>Affirmative defense via NIST AI RMF</td> <td>Disclosure compliance</td> </tr> <tr> <td>Enforcement</td> <td>Attorney General only, 60-day cure</td> <td>Attorney General, state-specific</td> </tr> </table> One control set serves both, and it is not a state-specific control set. It is an inventory, a documented purpose per system, evaluation evidence, and a disclosure capability. Our analysis of the Colorado AI Act after SB 26-189 works through the second column in detail.
The regulatory sandbox: who it is actually for
Chapter 553 creates a sandbox administered by the Department of Information Resources that lets an approved participant test an AI system without first obtaining a licence, registration or other regulatory authorisation. Section 553.053 caps participation at 36 months, extendable with approval. Entry is not casual. Section 553.052 requires a description of the system, a benefit assessment, mitigation plans for identified risks, and proof of compliance with any applicable federal AI law. Sections 553.101 to 553.103 require quarterly reporting to DIR, which coordinates with affected agencies and reports annually to the legislature. The honest read, which vendor commentary tends to avoid: the sandbox is valuable if a state licensing regime is what stands between you and a pilot, which in practice means healthcare, insurance, financial services and some public-sector work. If nothing is currently blocking you, the sandbox adds a reporting obligation and a benefit-assessment exercise in exchange for relief you do not need. It is a tool for regulated-sector entrants, not a general compliance shortcut, and it should be assessed alongside the rest of the AI regulatory landscape rather than as a Texas curiosity.
A 90-day TRAIGA operating plan
If you are starting from nothing, this is the order that produces defensible ground fastest.
- Inventory what touches Texas. Every AI system with Texas users, including procured features inside SaaS tools and the shadow AI nobody registered. Scope is defined by users, not by entities, so this list is the foundation for everything else.
- Screen against the seven prohibitions. Expect to clear all seven. Record the screening anyway, with a date and a named owner, because the absence of prohibited intent is a claim you may later need to evidence.
- Stand up NIST AI RMF conformance as a defense asset. Not as a poster. GOVERN, MAP, MEASURE and MANAGE, each with artefacts attached and timestamped, sized to the risk of the system. This is the work that makes
552.105(e)(2)(D)available to you, and it is the single highest-value item on this list. - Wire the 60-day cure into incident response. Rehearse the path from Attorney General notice to identified systems, changed behaviour and written response. Test whether you can do it, rather than assuming.
- Log the intent-relevant record. Purpose statements per system, evaluation and red-team results, review sign-offs, and decisions taken on findings. Under an intent standard this record is the case, and an AI policy that specifies who writes it and when is what stops it being reconstructed after the fact.
None of this is Texas-specific work, which is the point. It is the same substrate that auditability requires everywhere.
FAQ
What does TRAIGA stand for? TRAIGA is the Texas Responsible Artificial Intelligence Governance Act, enacted as HB 149 in the 89th Texas Legislature. It was signed on 22 June 2025 and took effect on 1 January 2026. The acronym is also a common Spanish verb form, so searches for the term return a mix of results; the statute is the one that adds Chapters 551 to 554 to the Texas Business and Commerce Code. Does TRAIGA apply to companies outside Texas? Yes. The Act reaches any person who develops or deploys an AI system in Texas, who advertises, promotes or conducts business in the state, or who offers products or services used by Texas residents. There is no headquarters requirement and no size threshold. A company with no Texas presence but Texas customers is covered, which is why scoping has to start from an inventory of systems and the users they serve. Does TRAIGA require an AI impact assessment? No. Unlike the EU AI Act and the original Colorado statute, TRAIGA imposes no mandatory impact assessment, no registration and no algorithm filing. Earlier drafts included a risk-mitigation policy requirement that was removed before enactment. The nuance is that the affirmative defense at 552.105(e)(2)(D) rewards documented conformance with the NIST AI Risk Management Framework, so most organisations end up producing similar artefacts for a different reason. What are the penalties for violating TRAIGA? Curable violations carry 10,000 to 12,000 dollars. Uncurable violations carry 80,000 to 200,000 dollars. Continuing violations add 2,000 to 40,000 dollars per day. State agencies may impose additional sanctions on licensed entities, including suspension and fines up to 100,000 dollars. The Attorney General must give written notice and wait 60 days before suing, so whether a violation is curable often depends on how quickly you can respond. How does TRAIGA differ from the Colorado AI Act? TRAIGA turns on intent and prohibits specific conduct. Colorado’s original Act turned on the risk of algorithmic discrimination and imposed a duty of care with impact assessments. That contrast narrowed sharply in May 2026, when Colorado repealed and replaced its Act with the Automated Decision-Making Technology Act, effective January 2027, dropping the duty of care and impact assessments in favour of disclosure. Does TRAIGA give consumers the right to sue? No. Section 552.101 gives the Texas Attorney General exclusive enforcement authority and the statute creates no private right of action. Consumers can file complaints through the mechanism the Attorney General maintains under 552.102, but they cannot bring their own claim. The Act also nullifies conflicting city and county AI ordinances, so the enforcement picture in Texas is deliberately single-channel. Is the Texas AI regulatory sandbox worth applying to? Only if state licensing is genuinely blocking a deployment. Participation runs up to 36 months and suspends the need for certain authorisations, but entry requires a benefit assessment, mitigation plans and proof of federal AI-law compliance, and participants report quarterly. For most private deployers who are not licence-constrained, the sandbox adds obligations without removing any that were binding.
Conclusion
TRAIGA is easy to underestimate because the headline reading is accurate: the prohibitions are narrow, most private deployers clear them, and nothing has to be filed with anyone. Treating that as the end of the analysis is the mistake. An intent standard does not remove the need for evidence, it relocates it, and section 552.105(e)(2)(D) states plainly what evidence the state will credit. Colorado’s retreat to a disclosure model makes this more consequential rather than less, because the Texas approach is now the likely template for the states that follow. The organisations that will handle the next five state AI laws cheaply are the ones building one inventory, one control set and one evidence trail against a recognised framework. That is an AI governance framework problem, not a Texas problem, and it is worth solving once.