Texas · TRAIGA · HB 149

Texas already regulates your AI. It is not what you were told.

The Responsible Artificial Intelligence Governance Act has been law since January 2026. It is far narrower than the draft that made headlines — and considerably sharper where it applies. It turns on intent, it carries penalties up to $200,000, and it writes a compliance framework into the statute as a defense.

Plain-language summary, not legal advice. Statute: Texas Business & Commerce Code chapters 552, 553 and 554, added by HB 149 (89th Legislature, 2025), effective January 1, 2026.

Days in force
There is no deadline left to prepare for.TRAIGA took effect on January 1, 2026. If your organization does business in Texas and has not looked at it, the question is no longer whether you are ready — it is what you would produce if the Attorney General sent a written notice.
What it actually prohibits

Six prohibitions, and each one turns on intent

This is the detail most summaries skip. TRAIGA is not an outcomes statute. Nearly every prohibition requires that you meant to do the thing — and section 552.056 says so explicitly: disparate impact alone is not sufficient to prove intent to discriminate.

§552.052
Everyone

Inciting harm

No developing or deploying an AI system “in a manner that intentionally aims to incite or encourage” self-harm, harm to others, or criminal activity.

§552.056
Everyone

Intentional discrimination

No system developed or deployed with the intent to unlawfully discriminate against a protected class. Carve-outs for regulated insurers and federally insured financial institutions following their own rules.

§552.055
Everyone

Constitutional rights

No system developed with the sole intent of infringing a person's constitutional rights.

§552.057
Everyone

Explicit content and CSAM

No system developed with the sole intent of producing child sexual abuse material, unlawful explicit deepfakes, or explicit text impersonating a minor.

§552.053
Government only

Social scoring

Governmental entities may not use AI social scoring that leads to detrimental or disproportionate treatment.

§552.054
Government only

Biometric capture

Governmental entities may not use AI for unique biometric identification without consent, subject to security, fraud and law-enforcement exceptions.

Read the chapter, not the headlines

What TRAIGA does not require

An earlier draft of this bill was a full high-risk AI regime modeled on the EU AI Act. It did not pass. A great deal of the commentary still describes that draft.

No mandatory impact assessments.

The algorithmic impact assessment requirement was in the earlier draft and did not survive into HB 149.

No private right of action.

Enforcement sits exclusively with the Attorney General. An individual cannot sue you under this chapter.

No general private-sector disclosure duty.

The AI-interaction disclosure in section 552.051 binds governmental agencies. The draft that reached employees and job applicants was cut.

Disparate impact alone is not enough.

A discriminatory outcome, without intent, does not establish a section 552.056 violation.

One important exception to the disclosure point: section 552.051(f) requires a provider of health care service or treatment to disclose AI involvement no later than the date the service is first provided, and the section does not limit “provider” to governmental entities. If you deliver care, treat that duty as reaching you and confirm the scope with counsel.

The part that should change what you do

Texas wrote your compliance program into the statute

A defendant is protected where it “substantially complies with the most recent version of the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile published by NIST, or another nationally or internationally recognized risk management framework for artificial intelligence systems.”

Section 552.105 also creates a rebuttable presumption that a person used reasonable care, and bars the Attorney General from seeking penalties over a system that has not been deployed. Read plainly: running a documented NIST AI RMF program is not merely good practice in Texas. It is a statutory defense — provided you can actually produce the program, the internal review process behind it, and evidence that you followed it.

The safe harbor is a rebuttable presumption and an affirmative defense, not absolute immunity, and the precise subsection lettering should be confirmed against the enrolled bill with counsel before anyone relies on it.

Claiming the defense

Four things the safe harbor asks you to have

“Substantial compliance with the NIST AI RMF” is not a certificate you buy. It is a program you run and can evidence — govern, map, measure, manage.

An inventory you can produce on demand

The NIST AI RMF MAP function starts with knowing what you run, what it does, and who owns it. Without an inventory there is nothing to substantially comply about.

In GOVERNBOX: the AI Use Case Log, plus a staff intake portal that reaches your whole workforce at no per-seat cost — because the systems that sink a safe-harbor claim are the ones nobody registered.

A documented internal review process

The statute ties the presumption of reasonable care to having a real review process, not a framework on a shelf.

In GOVERNBOX: a seven-section impact assessment per use case that creates risk register entries on completion, so review produces a record rather than a meeting.

Policy that cites the framework it claims to follow

If your defense rests on the NIST AI RMF, your governing documents should be traceable to it clause by clause.

In GOVERNBOX: every generated clause cites a control from the library, and the NIST AI RMF crosswalk shows coverage and named gaps line by line. The system retrieves controls; it never invents them.

Evidence you actually ran it

Sixty days is a short window in which to assemble a year of governance history from scratch after a written notice arrives.

In GOVERNBOX: training completions, signed attestations, an incident log and a quarterly board report, all retained — the program's own audit trail rather than a reconstruction.
Two things Texas built alongside the rules

A sandbox and a council

Chapter 553

The regulatory sandbox

Administered by the Texas Department of Information Resources. A participant may test for up to 36 months with relief from certain licensing and legal requirements, subject to quarterly reporting on performance, risk mitigation and consumer feedback. The chapter 552 prohibitions cannot be waived.

Chapter 554

The Texas AI Council

Seven members appointed by the Governor, Lieutenant Governor and Speaker on staggered four-year terms. It reports to the legislature, trains agencies and advises on the sandbox — but it is expressly barred from adopting binding rules or guidance.

Confirm the current operational status of the sandbox and of the Attorney General’s online complaint mechanism before relying on either.

Does it apply to you?

Two questions decide it

There is no employee-count, revenue or small-business threshold anywhere in chapter 552. Applicability turns on what you do and where, not on how big you are.

Question one

Do you develop or deploy AI for use in Texas?

Offering, selling, leasing or simply putting a system into use in the state. Where you are incorporated matters less than where the system operates.

Question two

Could anyone argue about your intent?

The prohibitions require purpose, not outcome — but “we never intended that” is an argument you have to be able to evidence, not merely assert.

Both yes? The safe harbor is the most valuable paragraph in the statute for you, and it rewards work done in advance. Government entity? The disclosure, social-scoring and biometric provisions bind you directly as well. Neither? You still need an AI policy — Texas simply is not the reason.

What the library actually contains

eleven Texas controls, four domains

Texas TRAIGA is a dedicated framework in the control library, included from Starter as part of the U.S. States jurisdiction. Enable the jurisdiction and every member statute comes with it, including the ones passed after you subscribe. TX-ENF-002 is highlighted because it is the control that carries the statutory defense.

TX-ENF-002NIST AI Risk Management Framework Substantial Compliance Safe Harbor
TX-ENF-00160-Day Attorney General Violation Cure Management
TX-ENF-003Developer Misuse Immunity and Audit Trail Maintenance
TX-PRO-001Harm Incitement and Criminal Activity Prohibition
TX-PRO-002Governmental Social Scoring Safeguards
TX-PRO-003Intentional Unlawful Discrimination Prevention
TX-PRO-004Biometric Identification Restrictions and CUBI Compliance
TX-DIS-001Point-of-Interaction Mandatory AI Disclosure
TX-DIS-002Dark Pattern Prohibition in AI Transparency Interfaces
TX-SBX-001Regulatory Sandbox Authorization and Testing Management
TX-GOV-001Texas Artificial Intelligence Council Policy Alignment
Where to start

The Texas crosswalk, line by line

Each obligation sits next to the document and clause in your program that answers it, so “where do you address this?” has a one-click answer — and so does “show me the NIST AI RMF program you are relying on.”

Take the free scorecard →
Your coverage, sample
NIST AI RMF substantial compliance70%
Prohibited-use controls45%
Audit trail & cure readiness30%
Sample result. Placeholder for a real product screen.
Common questions

What people ask about TRAIGA

Under TRAIGA, generally no — section 552.051 places that disclosure duty on governmental agencies. The significant exception is section 552.051(f), which requires a provider of health care service or treatment to disclose AI involvement no later than the date the service is first provided, and it does not limit "provider" to government. If you deliver care, treat that duty as reaching you and confirm the scope with counsel. Other Texas statutes, and other states, may impose disclosure duties of their own.

Find out where you actually stand

Fifteen questions, ten minutes, free. No account and no sales call. You get a banded score and a named list of the gaps behind it.

This page is a plain-language summary of the Texas Responsible Artificial Intelligence Governance Act (HB 149), effective January 1, 2026. It is not legal advice, and GOVERNBOX.ai does not promise a regulatory outcome. Check your obligations with counsel. GOVERNBOX.ai is a product of Gradient Descent LLC, an independent commercial company that is not affiliated with, endorsed by, or sponsored by the State of Texas, the Texas Attorney General, or any U.S. government agency.