TEXAS AI ACT · TRAIGA (HB 149) · IN FORCE 1 JANUARY 2026

The Texas AI Act is intent-based. That changes what you have to prove.

TRAIGA does not sort your systems into risk tiers. It prohibits specific things done with specific intent, and it is enforced only by the Attorney General — with a 60-day window to cure, and substantial compliance with the NIST AI RMF available as an affirmative defence. Which means the compliance work is proving what your systems are for.


A black legal binder with a brass plate and a red wax seal on a dark desk, beside a card reading evidence over promises Illustrative materials
Under an intent-based statute, the record is the defence
Intent-based AG enforcement 60-day cure NIST AI RMF safe harbour Sandbox

What is the Texas AI Act?

HB 149 — the Texas Responsible Artificial Intelligence Governance Act. It takes a different route from every other AI law you are likely to be reading: no risk tiers, no classification exercise, no impact-assessment template. Instead it names conduct that is prohibited when done with a particular intent, puts heavier duties on state agencies than on anyone else, and hands enforcement to a single office.

  • Statute HB 149 (TRAIGA) Texas Responsible Artificial Intelligence Governance Act, 89th Legislature.
  • In force 1 January 2026 Applies to conduct from that date, not to systems built before it.
  • Enforcement Attorney General only No private right of action. A 60-day cure period follows written notice.
  • Safe harbour NIST AI RMF Substantial compliance is available as an affirmative defence.

Who is covered?

Broader than most people assume on the private side, and heavier than most people expect on the public one. The trigger is doing business in Texas, not being headquartered there.

  • Anyone doing business in Texas Developing or deploying an AI system that reaches Texas residents brings you in, wherever the company sits.
  • Texas state agencies The heaviest duties in the Act fall on government: disclosure when a person is interacting with AI, and outright bans on social scoring and on biometric identification from public sources without consent.
  • Healthcare providers using AI Where AI is used in care decisions, the person affected has to be told — and told before or at the time of the interaction, not afterwards.
  • Anyone handling biometric identifiers TRAIGA reaches into the Texas biometric regime, so identification systems need reading against both at once.
$10k–$12k
Curable violation

Where the conduct can be fixed within the 60-day window after the Attorney General's written notice.

$80k–$200k
Uncurable violation

Where it cannot — the prohibited-intent conduct sits here.

$2k–$40k
Per day, continuing

Charged for each day a violation continues after the cure period closes.

In context

Texas vs Colorado: what actually differs

Two US state AI laws landing months apart, built on opposite triggers. A programme designed for one does not answer the other, and that is the most expensive assumption on this page.

  Texas — TRAIGA Colorado AI Act
What triggers it Intent — what you set out to do Effect — algorithmic discrimination, however caused
Enforced by Attorney General, exclusively Attorney General, exclusively
Private right of action None None
Cure period 60 days after written notice Cure provisions apply
Risk-tier duties No tiering — prohibited uses instead Duties attach to "high-risk" systems
Impact assessments Not mandated by the Act Required for high-risk deployers
Safe harbour Substantial NIST AI RMF compliance Recognised frameworks, including NIST AI RMF
Sandbox Regulatory sandbox, up to 36 months None

Running against the EU as well? The EU AI Act is tiered and effects-based, which puts it closer to Colorado than to Texas.

The prohibitions

What counts as a prohibited use

Every one of these is an “intent to” clause. Read any other way the statute is misdescribed — and misdescribing it is how a programme ends up testing for the wrong thing.

Manipulation and harm

Intent to incite or encourage

  • Self-harm, including suicide
  • Harm to another person
  • Criminal activity
  • Behavioural manipulation that a person cannot reasonably resist

Constitutional rights

Intent to infringe

  • Rights guaranteed by the US Constitution
  • Speech, assembly and religious exercise
  • Protections against unreasonable search

Unlawful discrimination

Intent to discriminate against a protected class

  • Race, colour, national origin, sex, age, disability
  • Religion and genetic information
  • Disparate impact alone does not establish intent — but it is the evidence a claim starts from

Unlawful sexual material

Intent to produce or distribute

  • Child sexual abuse material
  • Sexually explicit deepfakes of identifiable people
  • Material that is obscene under existing Texas law

Government only

Three duties that fall on Texas state agencies and not on private deployers — the part of the Act most often skimmed by readers who assume it does not apply to them, and then find their public-sector customer is asking about it.

  • Social scoring — evaluating or classifying people on behaviour or characteristics to their detriment
  • Biometric identification built from publicly available images or recordings without consent
  • Disclosure whenever a person is interacting with an AI system, in plain language
The timeline

Dates you should know

Including the Colorado date, because a multi-state programme is planning against both.

  1. Active

    HB 149 signed

    TRAIGA enacted by the 89th Legislature

    • Prohibited uses defined
    • AG enforcement
    • Sandbox authorised
  2. Active

    TRAIGA takes effect

    Prohibitions, agency duties and disclosure apply

    • Intent-based prohibitions
    • Government disclosure
    • Biometric provisions
  3. Active

    Regulatory sandbox opens

    Time-limited relief for supervised testing

    • Up to 36 months
    • Reporting obligations
    • AI Council oversight
  4. Active

    Colorado AI Act applies

    The effects-based sibling, for multi-state programmes

    • Algorithmic discrimination
    • High-risk duties
    • Impact assessments
The programme

The four compliance pillars

What a TRAIGA-ready programme is actually built out of. Each one produces evidence — which under an intent-based statute is the only thing that answers the question.

Intent controls

The statute turns on purpose, so purpose has to be on the record

  • A stated, documented purpose per AI system
  • A prohibited-use policy naming the four categories
  • Design-review gates that can refuse a use case
  • Change control, so purpose cannot drift silently

Discrimination testing

Disparate impact is not the trigger — it is the evidence

  • Subgroup performance testing across protected classes
  • Results recorded with the population definitions used
  • Investigation trail where a gap appears
  • Red-teaming and adversarial testing, dated

Disclosure

Told before or at the time, not afterwards

  • Plain-language notice that AI is in use
  • Placed at the point of interaction
  • Healthcare disclosures handled specifically
  • Records of what was shown, and when

NIST AI RMF alignment

The affirmative defence, evidenced rather than asserted

  • Mapped against GOVERN, MAP, MEASURE and MANAGE
  • Substantial compliance shown, not claimed
  • Gaps recorded with owners and dates
  • Re-assessed on a fixed cadence

What lands at the end of it

Not a certificate — there is nothing to certify against. What you get is the evidence set that answers an intent question, and the ranked list of what to fix before someone else asks.

  • A system inventory with a stated purpose per system
  • Prohibited-use screening, reasoned per system rather than asserted
  • Subgroup testing results with population definitions recorded
  • An AI RMF map supporting the safe-harbour position
  • A cure-readiness pack: owner, route and evidence, in advance
  • Findings ranked by consequence, not by ease
Start your TRAIGA assessment
A printed risk snapshot on a dark desk showing a risk summary, inherent versus residual risk, top risk areas and a likelihood-impact heat map
Illustrative materials

Ranked by consequence, not by how easy it is to close

How we help

How iDharma supports TRAIGA compliance

Every line pairs an obligation with what the assessment produces against it, so each claim here can be checked against the requirement beside it.

RequirementWhat the assessment does
Prohibited-use screeningEvery system read against the four intent categories, with the reasoning recorded per system rather than as a blanket assertion.
AI system inventoryPurpose, data, deployment context and affected people captured per system — the record the whole intent question rests on.
Discrimination testingSubgroup and intersectional performance testing, with population definitions stated so the numbers stay readable a year later.
Disclosure reviewWhere notice is owed, whether it is given at the right moment, and whether the wording survives contact with a non-specialist.
NIST AI RMF mappingFindings mapped to the AI RMF categories, so the safe-harbour claim rests on evidence you can hand over.
Biometric reviewIdentification systems read against TRAIGA and the Texas biometric regime together, because they overlap and neither is complete on its own.
Red-teaming recordsAdversarial testing conducted and dated, which is what the discovery-through-testing defence is built on.
Cure-readiness packOwner, escalation route and evidence set assembled in advance, so a 60-day clock is spent fixing rather than finding.
Watch for

Common mistakes to avoid

The patterns we see in Texas-exposed programmes. Expect them to resurface when work lands on you.

Treating Texas like Colorado

They are built on opposite triggers. A Colorado programme organised around risk tiers and impact assessments does not answer an intent-based statute, and a Texas programme does not answer an effects-based one. Multi-state means both, not the union of the paperwork.

Assuming "we did not mean to" is enough

Intent is proved from the record — design documents, prompts, tuning decisions, what was known and when. A programme with no contemporaneous record has nothing to point at, which is the worst position to be in under a statute that turns on purpose.

Relying on the vendor's assurance

You deploy it, you answer for it. A supplier attestation is useful evidence and is not a defence, and the systems bought in are usually the ones nobody in-house can describe.

Claiming the NIST safe harbour without the evidence

Substantial compliance has to be shown. A policy naming the framework, with no measurement plan, no results and no owners behind it, is a claim rather than a defence.

Losing the 60-day cure window

The Attorney General's notice goes to whoever is registered, not to whoever owns AI. Programmes lose weeks to internal routing — and the clock does not pause while a letter is forwarded.

Reading "AG-only" as low risk

No private right of action means no class actions. It does not mean small numbers: uncurable violations are charged in six figures and a continuing violation is charged for every day it continues.

Questions

Frequently asked questions

What legal, compliance and data-science teams ask when TRAIGA first lands on the roadmap.

1 Scope and application
What is the Texas AI Act, in one paragraph?

HB 149, the Texas Responsible Artificial Intelligence Governance Act, effective 1 January 2026. It prohibits developing or deploying AI with certain intents — inciting harm or criminal activity, infringing constitutional rights, unlawfully discriminating against a protected class, or producing unlawful sexual material — places extra duties on state agencies, and is enforced exclusively by the Attorney General with a 60-day period to cure.

Does it apply to us if we are not based in Texas?

If you do business in Texas or your AI system reaches Texas residents, yes. The trigger is where the conduct lands, not where the company is registered.

Is it a risk-tiered law like the EU AI Act?

No, and this is the most common misreading. There is no high-risk classification exercise to perform and no tier that switches on a duty list. It prohibits specific intentional conduct and imposes disclosure duties on government, and the compliance work is proving your purposes rather than sorting systems into buckets.

What extra duties fall on state agencies?

Disclosure whenever a person is interacting with an AI system, an outright ban on social scoring, and a ban on building biometric identification from publicly available images or recordings without consent, with carve-outs for certain law-enforcement uses.

2 Intent, evidence and defences
How is intent actually established?

From the record. Design documents, system prompts, tuning and evaluation decisions, escalations that were raised and what happened to them. The practical consequence is that a programme with no contemporaneous documentation is in the weakest position under this statute, not the strongest.

If our model shows disparate impact, have we broken the law?

Not on its own. TRAIGA requires intent to discriminate, and disparate impact by itself does not establish it. That is not a reason to stop testing: impact data is where a claim starts, and finding it yourself, recording it and acting on it is a materially better position than having someone else find it.

What is the NIST AI RMF safe harbour?

Substantial compliance with the NIST AI Risk Management Framework is available as an affirmative defence. That makes AI RMF the most useful thing a Texas-exposed programme can adopt — and it is why we map every finding to its AI RMF category. We have a full page on the framework itself.

Are there other defences?

The Act contemplates discovery through internal review or adversarial testing — red-teaming — among the routes to a defence. All of them share one requirement: the work has to have been done and dated before the problem became someone else's question.

3 Enforcement and what to do now
What are the penalties?

Civil penalties on a banded structure: a lower band for violations that can be cured, a substantially higher one for those that cannot, and a per-day penalty for a violation that continues after the cure period closes. The per-day element is what turns a single missed control into a number that matters.

What is the cure period?

Sixty days from the Attorney General's written notice. In practice the useful preparation is knowing in advance who receives that notice, who owns the response, and where the evidence lives — most of the window gets spent finding things rather than fixing them.

Can individuals sue us under it?

No. There is no private right of action; enforcement rests with the Attorney General. Existing civil-rights and consumer-protection routes are unaffected by that, so it narrows this statute rather than your overall exposure.

What is the regulatory sandbox?

A supervised programme allowing time-limited testing of AI systems with relief from some requirements, for up to thirty-six months, with reporting obligations attached. It is worth considering for a genuinely novel deployment; it is not a way to defer ordinary compliance work.

Where should we start?

An inventory with a stated purpose per system, then screening those purposes against the four prohibited categories, then AI RMF alignment so the safe harbour is available. That is the order we run an assessment in, and scoping is agreed with you before anything is charged.

Get started

Ready for 1 January 2026?

Inventory, purpose, prohibited-use screening and an AI RMF map that makes the safe harbour real. Scoped with you before you are charged.

This page is guidance on how we scope an assessment, not legal advice. Where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.