Texas enacted HB 149 in June 2025 — the Responsible Artificial Intelligence Governance Act — binding conduct from 1 January 2026. It prohibits developing or deploying an AI system with any of four kinds of intent, with each of the four named in the very next section of this page.
Under the Texas AI Act, a violation turns on what you meant to do.
Four prohibited intents, live since 1 January 2026, enforced by the Attorney General - and it turns on what you meant, not on outcome.
Our promise
“Intent is a defence. The record of it is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditTRAIGA, in three chapters
Most programmes arrive organised around risk tiers and impact assessments — what Colorado and the EU taught them. Neither answers a statute built on purpose. What does is a contemporaneous record of what each system was for, written before it shipped.
Our assessment builds that record for you. We inventory the systems with a stated purpose written against each one, screen those purposes against the four prohibited categories, and map each finding to the AI RMF category that the substantial-compliance defence will eventually rest on.
Four intents, not four risk tiers.
There is no classification to perform. The question is what you set out to do.
- To incite or encourage self-harm, harm to others, or crime
- To infringe rights guaranteed by the US Constitution
- To discriminate unlawfully against a protected class
- To produce or distribute unlawful sexual material
- Disclosure whenever a person interacts with an AI system
- An outright ban on social scoring by state agencies
- No biometric identification from public sources
- Carve-outs for certain law-enforcement uses, and no others
The system is theirs. The purpose is yours.
Whoever develops or deploys it
TRAIGA reaches anyone doing business in Texas whose AI system touches Texas residents, wherever the company itself happens to sit. Deploying a system you did not build puts you inside the Act on the same terms as building one - you deploy it, and you answer for it exactly as they would.
Where the heaviest duties actually fall
Government carries more than industry does here: disclosure whenever a person is interacting with an AI system, an outright ban on social scoring, and a ban on biometric identification built from publicly available images or recordings without the consent of the people who appear in any of them.
Intent is proved from the record
Design documents, system prompts, tuning and evaluation decisions, escalations raised and what actually happened to each of them. A programme with no contemporaneous record has nothing to point at - which is the worst place to be under a statute that turns on what you intended at the time.
“We never intended it, so nothing needs answering.”
Intent is proved from your record, not your memory.
It is the most common gap we write up.
- Who it is for
- Legal & compliance
- Model risk & data science
- Texas state agencies
- Healthcare providers
- Product & engineering
- Vendor management
Sixty days to cure, running from the Attorney General’s written notice — and the clock does not pause while that letter is being routed.
Colorado runs the opposite trigger — effect, not intent. A programme built for the one does not answer the other, and it never will.
No private right of action means no class actions. It does not mean small numbers, and it narrows none of the rest of your exposure at all.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a legal determination.
Your scope check
Four moments, and only one is a clock.
Nothing here falls due, so nothing prompts anybody - and the only clock that starts is one somebody else starts for you.
-
Signed
June 2025HB 149 enacted by the 89th Legislature: prohibited uses defined, AG enforcement set, and the sandbox opened.
-
In force
1 January 2026Prohibitions, agency duties and disclosure apply to conduct from that date - not to systems built before it.
-
Colorado
Alongside itThe effects-based sibling runs on the opposite trigger. Multi-state means answering both, not merging them.
-
The cure clock
60 daysIt starts on the Attorney General's written notice, and it does not pause while that letter is routed internally.
The Attorney General’s notice goes to whoever is registered, not whoever owns the AI, and programmes lose weeks to internal routing while the sixty days run. Most of a cure window goes on finding evidence, not fixing it — so the pack is built before the letter arrives.
What the statute says, what we ship
12 provisions, and the artefact that answers each one. Reading unverified.
- Manipulation and harm Intent to incite or encourage
- Every system read against this category with the reasoning recorded, rather than a blanket assertion across the estate.
- Constitutional rights Intent to infringe
- A prohibited-use policy naming the category, and design-review gates with the authority to refuse a use case.
- Unlawful discrimination Intent to discriminate against a protected class
- Subgroup and intersectional testing with the population definitions stated, and the investigation trail where a gap appears.
- Unlawful sexual material Intent to produce or distribute
- Screening against the category, with the content controls and the escalation route recorded per system.
- Government AI disclosure State agencies - before or at the time
- Plain-language notice at the point of interaction, and the record of what was shown and when.
- Social scoring ban State agencies - outright
- A written determination that no system classifies people on behaviour or characteristics to their detriment.
- Biometric identification From public sources without consent
- Identification systems read against TRAIGA and the Texas biometric regime together, because neither is complete alone.
- Stated purpose per system The record the intent question rests on
- Purpose, data, deployment context and affected people captured per system, with change control so purpose cannot drift.
- NIST AI RMF alignment The affirmative defence, evidenced not asserted
- Findings mapped to GOVERN, MAP, MEASURE and MANAGE, so the safe-harbour claim rests on evidence you can hand over.
- Adversarial testing Discovery through internal review or red-teaming
- Red-teaming conducted and dated, which is what a discovery-based defence is actually built on.
- Vendor systems You deploy it, you answer for it
- The evidence to ask each supplier for, and your own screening over what an attestation does not cover.
- Cure readiness 60 days from written notice
- Named recipient, escalation route and evidence set assembled in advance, so the window is spent fixing rather than finding.
Your AI estate, independently assessed
From a chatbot to a screening model.
-
Inventory and purpose
Every system, and the stated purpose the whole intent question rests on.
-
Screen and test
The four prohibited intents, subgroup testing, and the disclosure moments.
-
Sign off and map
You see the draft first. Then the findings, mapped to the AI RMF categories.
Why teams choose iDharma for TRAIGA
Genuinely independent
We build and resell no AI systems of our own, and take no fee tied to what the assessment finds.
Written to the statute
Every finding names the provision it answers, so counsel can check it against HB 149.
The safe harbour, shown
Findings map to the AI RMF categories, so the defence rests on evidence, not a claim.
Texas is not Colorado
We scope the two separately, because a programme built for one does not answer the other.
Four marks, struck on every assessment.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
TRAIGA assessment report
The full assessment in one document: what you run, what each system is for, and where a stated purpose comes close to a prohibited one - every system screened against the four intent categories with its reasoning, each finding mapped to its AI RMF category, and the whole written in plain language rather than the Act's.
AI system inventory
Purpose, data, deployment context and affected people per system - the record the whole intent question rests on when it is asked.
Prohibited-use screening
Each system read against the four intent categories, with the reasoning per system rather than one blanket assertion over the estate.
Discrimination testing
Subgroup and intersectional performance results with the population definitions stated, so the numbers stay readable a year later.
NIST AI RMF map
Findings against GOVERN, MAP, MEASURE and MANAGE, with gaps recorded and owned - the evidence behind the affirmative defence.
Disclosure review
Where notice is owed, whether it lands at the right moment, and whether the wording survives contact with a non-specialist.
Cure-readiness pack
Named recipient, escalation route and the evidence set assembled in advance, so a 60-day clock is spent fixing rather than finding.
Real numbers, upfront.
- Scope
- Set by the statute, not by us
- Input
- Your systems and their purposes
- Re-assess
- On material change — $5,500 against your known baseline
The statute fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Prohibited-use screening, per system
- Inventory with a stated purpose each
- Subgroup testing, populations stated
- NIST AI RMF map and the cure pack
Four things you have to be able to produce
The statute prescribes no format. Each of these is either on file the day it is asked for, or it is not.
The purpose,
stated
What each system is for, written down before it shipped. Under a statute that turns on intent, an undocumented purpose is the weakest position available.
The screen,
per system
Each system read against the four prohibited intents with the reasoning recorded - not one blanket assertion covering an estate nobody has listed.
The testing,
dated
Subgroup results and red-teaming, with the populations defined and the date on the file. Disparate impact is not the trigger under this Act - it is the evidence for one.
The map,
to NIST
Substantial AI RMF compliance shown across GOVERN, MAP, MEASURE and MANAGE. A policy naming the framework is a claim; the mapping is the defence.
Four cards, and the date on each one is part of the card.
Is it a risk-tiered law like the EU AI Act?
No, and this is the most common misreading. There is no high-risk classification exercise and no tier that switches on a duty list. It prohibits specific intentional conduct, and it mandates no impact assessment.
Does it apply to us if we are not based in Texas?
If you do business in Texas or your AI system reaches Texas residents, yes. The trigger is where the conduct lands, not where the company is registered.
How is intent actually established?
From the record: design documents, system prompts, tuning and evaluation decisions, escalations raised and what happened to them. A programme with no contemporaneous documentation is in the weakest position, not the strongest.
What is the NIST AI RMF safe harbour?
Substantial compliance with the NIST AI Risk Management Framework is available as an affirmative defence - which makes AI RMF the most useful thing a Texas-exposed programme can adopt, and it has to be shown rather than claimed.
What are the penalties?
Civil penalties on a banded structure: a lower band for curable violations, a substantially higher one running to six figures for those that cannot be cured, and a per-day penalty while a violation continues.
Request a TRAIGA assessment
Tell us what you run and what it is for, and we come back within one business day.
What we need from you
Nothing you do not already have. Most of this comes out of your model governance records in an afternoon, and we tell you exactly which extracts before you commit.
- Whether your systems reach people in Texas, and how
- What each system is for, in your own words
- Your AI inventory, if you already have one
- How much came from a vendor, and what they supplied
- Whether you already claim NIST AI RMF alignment
What happens next
- We agree the scope with you first.
- Four to eight weeks, longer for a big estate.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- HB 149, 89th Legislature, Regular Session
- General knowledge of how it is read
- Signed
- June 2025
- In force
- 1 January 2026
What it means
- General information about what the statute prohibits — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Written from general knowledge of HB 149, not line-checked against the enrolled text. The penalty bands are the least certain figures here, and they are stated as a structure rather than as precise numbers for that reason.
- It covers HB 149 alone - Colorado, the EU AI Act and your sector rules bind you separately.
- On an engagement we work from the enrolled text. Use this as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.