ooligo
ENTRY TYPE · definition

Texas Responsible AI Governance Act (TRAIGA, HB 149)

By Marius Bughiu Last updated 2026-08-04 Legal OpsRecruiting & TARevOps

The Texas Responsible Artificial Intelligence Governance Act — HB 149, signed by Governor Greg Abbott on June 22, 2025 and in force since January 1, 2026 — almost certainly applies to your AI tools, and almost certainly requires nothing of you operationally. Codified at Texas Business & Commerce Code chapter 552, it reaches any person who conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. That is a wide jurisdictional net with no revenue or headcount threshold. What sits inside the net is narrow: four intent-based prohibitions, disclosure duties that bind government agencies and healthcare providers rather than ordinary employers, and no ongoing compliance program of any kind. The work TRAIGA creates for an ops team is documentary — proving why you deployed a system — not procedural.

What TRAIGA is NOT

  • Not a risk-management statute. There are no impact assessments, no bias audits, no AI risk-management program, and no algorithmic-discrimination cause of action. If you built a compliance plan against Colorado’s original SB 24-205 or the EU AI Act’s high-risk regime, none of that architecture is required here.
  • Not a disclosure law for private employers. The pre-interaction “you are talking to an AI” notice binds government agencies; a separate duty binds licensed healthcare providers on the date of treatment. A private employer screening Texas candidates with an AI tool owes those candidates no notice under TRAIGA.
  • Not enforceable by the people it protects. The Texas attorney general has exclusive enforcement authority, there is no private right of action, and local AI ordinances are preempted.

Who is covered, and who is carved out

Coverage attaches through any one of the three jurisdictional hooks above, applied to both developers (who offer, sell, or provide an AI system in Texas) and deployers (who put one to use for Texas purposes). Unlike California’s automated-decision-system rules, which start at five employees, TRAIGA is not size-gated — a 12-person RevOps team running an AI SDR against Texas prospects is covered on the same terms as an enterprise.

Two carve-outs matter for buyers: insurers regulated under the Texas Insurance Code and federally insured financial institutions operating under their banking regulators sit outside the discrimination prohibition. Hospital districts and institutions of higher education are exempt from the government-agency disclosure duty.

The prohibitions

Four apply to any covered person:

  1. Behavioral manipulation — developing or deploying an AI system that intentionally incites or encourages physical self-harm, harm to another person, or criminal activity.
  2. Constitutional-rights infringement — a system developed with the sole intent of infringing a person’s constitutional rights.
  3. Unlawful discrimination — developing or deploying an AI system with intent to unlawfully discriminate against a protected class.
  4. Child sexual abuse material and explicit deepfakes of minors.

Three more apply only to government agencies: social scoring that leads to detrimental treatment, biometric identification of individuals from publicly available sources without consent, and the pre-interaction AI disclosure.

The intent standard is the whole story

For anyone using AI in hiring, outbound, or credit-adjacent decisions, one sentence in the statute carries the entire practical weight: a disparate impact is not sufficient by itself to demonstrate intent to discriminate. Texas foreclosed under its own law exactly the theory that Title VII, the ADA, and the ADEA still permit federally, and that NYC Local Law 144 and Illinois’ hiring-AI amendments build on.

This is why a Texas-only compliance read is a trap. TRAIGA lowered your state-law exposure and changed nothing about your federal exposure. A screening model that rejects candidates over 50 at twice the rate of younger applicants is still an ADEA problem in Dallas; it just is not a TRAIGA problem.

Intent, though, is proved with documents. The artifacts that convert a neutral tool into an intent case are the ones ops teams generate casually: a vendor’s marketing claim about filtering a demographic, a configuration ticket specifying an outcome, an absence of any testing record at all. TRAIGA rewards writing down the legitimate purpose before deployment, because the record is the defense.

Safe harbor and enforcement

Section 552.105(e) gives a defense to a person who discovers a violation through stakeholder feedback, red-teaming or adversarial testing, following state agency guidance, or an internal review process that substantially complies with a recognized framework such as the NIST AI Risk Management Framework. Third-party misuse of your system is also a shield. This is the one part of TRAIGA that pays to build against rather than merely document.

Enforcement runs through the AG, who may issue a civil investigative demand without first serving a notice of violation. A CID can reach system descriptions, intended purpose, training data, inputs and outputs, performance metrics, known limitations, post-deployment monitoring, and user safeguards. After a notice of violation, you get 60 days to cure. Penalties: $10,000 to $12,000 per curable violation left uncured, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for continuing violations.

The date to put in the calendar is September 1, 2026, when the AG’s statutorily required online complaint portal must be operating. The office published a Consumer AI Rights page in July 2026 explaining the prohibitions and penalties; no formal TRAIGA enforcement action or CID had been publicly reported through the first half of 2026. Complaint intake, not rulemaking, is the mechanism likely to generate the first cases.

Sandbox and Council

The Texas Department of Information Resources administers a regulatory sandbox — up to 36 months, exemption from state licensing and authorization requirements, quarterly reports on performance, risk mitigation, and stakeholder feedback. The core prohibitions still bind sandbox participants. A seven-member Texas Artificial Intelligence Council sits under DIR in an advisory role with no rulemaking power.

Read that structurally: no agency will issue rules filling TRAIGA’s gaps. The statute is the whole regime, and it will stay this thin until the legislature revisits it.

Watch-outs

  • Treating TRAIGA as the ceiling. The intent standard is a Texas-law defense, not a federal one. Guard: keep running adverse-impact testing against the Title VII four-fifths convention regardless of what Texas requires, and keep the results.
  • Reading “no disclosure duty” as “no notice anywhere.” Candidate location, not company headquarters, decides which notice rule governs a req. Guard: maintain a jurisdiction matrix covering NYC LL 144, Illinois, California, and EU Article 50, and key the notice template to the candidate’s jurisdiction.
  • The biometric trapdoor. TRAIGA amended Texas’ CUBI statute: publicly available media does not constitute consent to biometric capture unless the individual published it themselves. Face-matching in an identity-verification step is a CUBI question before it is a TRAIGA question. Guard: obtain and log written consent before any face-geometry capture in the funnel, and confirm the vendor’s retention schedule in the contract.
  • Taking sandbox admission as a safety credential. The sandbox waives licensing requirements, not prohibitions. Guard: if a vendor cites sandbox participation in a security review, ask which licensing requirement it waived; the answer is usually nothing relevant to you.
  • No documented purpose. A CID lands with a response deadline, not a research window. Guard: keep a one-page written statement of intended use plus the testing record for each AI system with a Texas nexus, refreshed at renewal.

What to do now

  1. Inventory every AI system with a Texas nexus — Texas candidates, Texas prospects, Texas customers, or Texas-based operation.
  2. Write the intent record for each: purpose, decision it influences, who reviews the output, what testing was done.
  3. Map your internal review process to the NIST AI RMF, since that mapping is the named route into the safe harbor.
  4. Add a CID-cooperation clause to AI vendor terms. Within a 60-day cure window you will need training-data and known-limitations documentation from the vendor, and no standard MSA obliges them to produce it.
  5. Calendar September 1, 2026 and re-check the AG’s posture then.

Consult counsel for jurisdiction-specific analysis.