Written and maintained by CASRAI Editorial Board
Last updated
The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), enacted as House Bill 149, takes effect January 1, 2026. It is Texas’s first comprehensive AI statute, and it is built on a different regulatory model than Colorado’s AI law or the frontier-model transparency laws in California and New York. TRAIGA does not create a general duty to assess AI systems for risk before deploying them. Instead, it bans a short, specific list of AI uses outright — regardless of industry, company size, or how the underlying model was built — and layers narrower disclosure duties on top for government agencies and health care providers.
Who TRAIGA covers
TRAIGA applies to any person who promotes, advertises, or conducts business in Texas; produces a product or service used by Texas residents; or develops or deploys an AI system in Texas. That reaches developers (who build or substantially modify an AI system) and deployers (who put one into use), with no size or revenue threshold. A “consumer” under the act is a Texas resident acting in a personal or household capacity, not a business.
Two categories of the act’s obligations — the social-scoring and biometric-identification prohibitions described below — apply only to governmental entities: state agencies and political subdivisions, though the act specifically excludes hospital districts and public higher-education institutions from that definition.
What TRAIGA actually prohibits
TRAIGA’s core is Subchapter B of Chapter 552, a set of bright-line prohibitions rather than a risk-assessment framework:
- Behavioral manipulation. No person may develop or deploy an AI system that intentionally aims to incite or encourage physical self-harm (including suicide), harm to another person, or criminal activity.
- Social scoring (governmental entities only). No governmental entity may use AI to evaluate or classify people by social behavior or characteristics to assign a score used for detrimental, unjustified, or disproportionate treatment, or in a way that infringes constitutional rights.
- Biometric identification without consent (governmental entities only). No governmental entity may deploy AI to uniquely identify a specific individual using biometric data without consent, where doing so would infringe constitutional rights.
- Constitutional-rights infringement. No person may develop or deploy AI with the sole intent of infringing, restricting, or impairing an individual’s rights under the U.S. Constitution.
- Unlawful discrimination. No person may develop or deploy AI with the intent to unlawfully discriminate against a protected class (race, color, national origin, sex, age, religion, or disability). The act specifies that disparate impact alone is not sufficient to establish that intent.
- Sexually explicit and child-exploitation content. No person may develop or distribute an AI system with the sole intent of producing illegal visual material, illegal deep-fake images or video, or a chatbot that simulates or describes sexual conduct while impersonating a minor.
Every one of these bans is written around intent. An AI system that happens to produce a discriminatory or harmful outcome is not, by itself, a TRAIGA violation; the act requires that the prohibited purpose be the reason the system was built or deployed that way.
Disclosure duties for government and health care
Separately from the prohibitions above, Section 552.051 requires governmental agencies to disclose, clearly and before or at the point of interaction, that a consumer is interacting with an AI system rather than a human. Health care providers must disclose their use of AI in a patient’s treatment no later than when that service is first provided, or as soon as reasonably possible in an emergency. Disclosures must be in plain language and may not rely on dark patterns.
Exemptions and the regulatory sandbox
TRAIGA carves out several categories from its biometric-data provisions, including voiceprint data held by financial institutions, biometric data used only in training or processing an AI model (not to identify a specific person), and AI used for cybersecurity, fraud prevention, or investigating crime. Insurance entities that comply with existing insurance regulation, and federally insured banks that follow applicable federal and state banking law, are treated as compliant with the discrimination provisions. The act also establishes a 36-month regulatory sandbox allowing companies to test AI systems without certain licensing requirements — though Subchapter B’s core prohibitions cannot be waived through the sandbox, and the Attorney General retains authority to pursue violations regardless.
Enforcement
The Texas Attorney General has exclusive authority to enforce TRAIGA. There is no private right of action. Before bringing an action, the Attorney General must give written notice identifying the specific provisions violated, and cannot sue until 60 days after that notice; a violation can be cured within that window by fixing the problem, submitting a written statement with supporting documentation, or revising internal policies to prevent recurrence. If cured in time, no action may be brought.
Penalties scale with curability: $10,000–$12,000 per violation for curable violations or a breached cure statement, and $80,000–$200,000 per violation for violations the Attorney General deems uncurable, plus $2,000–$40,000 per day a violation continues. Companies that discover a violation through their own testing, that substantially follow the NIST AI Risk Management Framework, or whose system was misused by someone else in a way outside their control, have defenses available. The Attorney General cannot bring an action over an AI system that has not yet been deployed, and must stand up a public online complaint portal by September 1, 2026.
How TRAIGA compares to Colorado’s AI Act
TRAIGA and Colorado’s SB 26-189 are both frequently filed under “state AI law,” but they regulate on entirely different principles. Colorado’s law is a consequential-decision framework: it applies whenever automated decision-making technology is used in specific high-stakes contexts — employment, housing, lending, insurance, health care, education, government benefits — and imposes affirmative duties on developers and deployers regardless of intent: technical documentation, consumer notice, and post-decision explanations. TRAIGA imposes none of that. It has no consequential-decision trigger, no impact-assessment or documentation requirement, and no duty to notify consumers before an adverse decision (outside the narrow AI-interaction disclosure for government agencies).
Instead, TRAIGA is a prohibited-use, intent-based statute: it does not ask what sector an AI system operates in or what kind of decision it makes, only whether it was built or deployed for one of six specifically banned purposes. A hiring or lending tool that Colorado’s law would reach because of its use case is largely untouched by TRAIGA unless it was intentionally built to discriminate, manipulate, or infringe a constitutional right — and, conversely, TRAIGA’s chatbot and deepfake prohibitions apply to conduct entirely outside the high-stakes-decision categories Colorado regulates. The two laws can both apply to the same company, but they are answering different questions: Colorado asks “was this system used to decide something important about a person, and did you follow the process for that,” while TRAIGA asks “was this system built or used on purpose to do one of these specific harmful things.”
How TRAIGA compares to SB 53 and the RAISE Act
California’s SB 53 and New York’s RAISE Act regulate a third way entirely: by the scale of the model itself, using a training-compute threshold (1026 operations) plus revenue, irrespective of how that model is later used. TRAIGA has no compute threshold and does not distinguish frontier models from any other AI system — a small company’s simple classifier is squarely inside TRAIGA’s prohibitions if it is built with a prohibited intent, while a lab training a model well above SB 53’s threshold has no TRAIGA exposure at all unless it develops or deploys that model for one of the six banned uses. TRAIGA’s concern is misuse of any AI system for specific harms; SB 53 and the RAISE Act’s concern is catastrophic risk from the most capable models, regardless of use case. CASRAI’s comparison of California, Colorado, and New York’s AI laws covers that use-case-vs-compute-threshold distinction in more depth; TRAIGA adds a fourth model — intent-based prohibition — to that landscape rather than fitting into either existing category.
Frequently asked questions
When does TRAIGA take effect?
January 1, 2026. The Texas Attorney General’s online complaint mechanism has a separate, later deadline of September 1, 2026.
Does TRAIGA require AI impact assessments, like Colorado’s law?
No. TRAIGA does not impose a general risk-assessment, documentation, or notice-and-explanation regime. It prohibits a specific, enumerated list of AI uses built or deployed with a prohibited intent, and adds narrower disclosure duties only for government agencies and health care providers.
Is there a private right of action under TRAIGA?
No. The Texas Attorney General has exclusive enforcement authority, with a mandatory 60-day notice-and-cure period before an enforcement action can be filed.
Does disparate impact alone violate TRAIGA’s discrimination prohibition?
No. TRAIGA’s unlawful-discrimination prohibition requires intent to discriminate against a protected class; the statute specifies that disparate impact by itself is not sufficient to demonstrate that intent.
Does TRAIGA regulate frontier AI models the way SB 53 or the RAISE Act do?
No. TRAIGA has no training-compute threshold and does not single out large, general-purpose models. It applies based on whether an AI system, of any scale, was built or deployed for one of six specifically prohibited purposes.
What are the penalties for a TRAIGA violation?
$10,000–$12,000 per violation if curable, $80,000–$200,000 per violation if the Attorney General deems it uncurable, and $2,000–$40,000 per day a violation continues, after a 60-day notice-and-cure period.







