The Responsible Artificial Intelligence Governance Act has been law since January 2026. It is far narrower than the draft that made headlines — and considerably sharper where it applies. It turns on intent, it carries penalties up to $200,000, and it writes a compliance framework into the statute as a defense.
Plain-language summary, not legal advice. Statute: Texas Business & Commerce Code chapters 552, 553 and 554, added by HB 149 (89th Legislature, 2025), effective January 1, 2026.
This is the detail most summaries skip. TRAIGA is not an outcomes statute. Nearly every prohibition requires that you meant to do the thing — and section 552.056 says so explicitly: disparate impact alone is not sufficient to prove intent to discriminate.
No developing or deploying an AI system “in a manner that intentionally aims to incite or encourage” self-harm, harm to others, or criminal activity.
No system developed or deployed with the intent to unlawfully discriminate against a protected class. Carve-outs for regulated insurers and federally insured financial institutions following their own rules.
No system developed with the sole intent of infringing a person's constitutional rights.
No system developed with the sole intent of producing child sexual abuse material, unlawful explicit deepfakes, or explicit text impersonating a minor.
Governmental entities may not use AI social scoring that leads to detrimental or disproportionate treatment.
Governmental entities may not use AI for unique biometric identification without consent, subject to security, fraud and law-enforcement exceptions.
An earlier draft of this bill was a full high-risk AI regime modeled on the EU AI Act. It did not pass. A great deal of the commentary still describes that draft.
The algorithmic impact assessment requirement was in the earlier draft and did not survive into HB 149.
Enforcement sits exclusively with the Attorney General. An individual cannot sue you under this chapter.
The AI-interaction disclosure in section 552.051 binds governmental agencies. The draft that reached employees and job applicants was cut.
A discriminatory outcome, without intent, does not establish a section 552.056 violation.
One important exception to the disclosure point: section 552.051(f) requires a provider of health care service or treatment to disclose AI involvement no later than the date the service is first provided, and the section does not limit “provider” to governmental entities. If you deliver care, treat that duty as reaching you and confirm the scope with counsel.
A defendant is protected where it “substantially complies with the most recent version of the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile published by NIST, or another nationally or internationally recognized risk management framework for artificial intelligence systems.”
Section 552.105 also creates a rebuttable presumption that a person used reasonable care, and bars the Attorney General from seeking penalties over a system that has not been deployed. Read plainly: running a documented NIST AI RMF program is not merely good practice in Texas. It is a statutory defense — provided you can actually produce the program, the internal review process behind it, and evidence that you followed it.
The safe harbor is a rebuttable presumption and an affirmative defense, not absolute immunity, and the precise subsection lettering should be confirmed against the enrolled bill with counsel before anyone relies on it.
“Substantial compliance with the NIST AI RMF” is not a certificate you buy. It is a program you run and can evidence — govern, map, measure, manage.
The NIST AI RMF MAP function starts with knowing what you run, what it does, and who owns it. Without an inventory there is nothing to substantially comply about.
The statute ties the presumption of reasonable care to having a real review process, not a framework on a shelf.
If your defense rests on the NIST AI RMF, your governing documents should be traceable to it clause by clause.
Sixty days is a short window in which to assemble a year of governance history from scratch after a written notice arrives.
Administered by the Texas Department of Information Resources. A participant may test for up to 36 months with relief from certain licensing and legal requirements, subject to quarterly reporting on performance, risk mitigation and consumer feedback. The chapter 552 prohibitions cannot be waived.
Seven members appointed by the Governor, Lieutenant Governor and Speaker on staggered four-year terms. It reports to the legislature, trains agencies and advises on the sandbox — but it is expressly barred from adopting binding rules or guidance.
Confirm the current operational status of the sandbox and of the Attorney General’s online complaint mechanism before relying on either.
There is no employee-count, revenue or small-business threshold anywhere in chapter 552. Applicability turns on what you do and where, not on how big you are.
Offering, selling, leasing or simply putting a system into use in the state. Where you are incorporated matters less than where the system operates.
The prohibitions require purpose, not outcome — but “we never intended that” is an argument you have to be able to evidence, not merely assert.
Both yes? The safe harbor is the most valuable paragraph in the statute for you, and it rewards work done in advance. Government entity? The disclosure, social-scoring and biometric provisions bind you directly as well. Neither? You still need an AI policy — Texas simply is not the reason.
Texas TRAIGA is a dedicated framework in the control library, included from Starter as part of the U.S. States jurisdiction. Enable the jurisdiction and every member statute comes with it, including the ones passed after you subscribe. TX-ENF-002 is highlighted because it is the control that carries the statutory defense.
Each obligation sits next to the document and clause in your program that answers it, so “where do you address this?” has a one-click answer — and so does “show me the NIST AI RMF program you are relying on.”
Take the free scorecard →Fifteen questions, ten minutes, free. No account and no sales call. You get a banded score and a named list of the gaps behind it.
This page is a plain-language summary of the Texas Responsible Artificial Intelligence Governance Act (HB 149), effective January 1, 2026. It is not legal advice, and GOVERNBOX.ai does not promise a regulatory outcome. Check your obligations with counsel. GOVERNBOX.ai is a product of Gradient Descent LLC, an independent commercial company that is not affiliated with, endorsed by, or sponsored by the State of Texas, the Texas Attorney General, or any U.S. government agency.