The Texas AI Act is intent-based. That changes what you have to prove.
TRAIGA does not sort your systems into risk tiers. It prohibits specific things done with specific intent, and it is enforced only by the Attorney General — with a 60-day window to cure, and substantial compliance with the NIST AI RMF available as an affirmative defence. Which means the compliance work is proving what your systems are for.
What is the Texas AI Act?
HB 149 — the Texas Responsible Artificial Intelligence Governance Act. It takes a different route from every other AI law you are likely to be reading: no risk tiers, no classification exercise, no impact-assessment template. Instead it names conduct that is prohibited when done with a particular intent, puts heavier duties on state agencies than on anyone else, and hands enforcement to a single office.
- Statute HB 149 (TRAIGA) Texas Responsible Artificial Intelligence Governance Act, 89th Legislature.
- In force 1 January 2026 Applies to conduct from that date, not to systems built before it.
- Enforcement Attorney General only No private right of action. A 60-day cure period follows written notice.
- Safe harbour NIST AI RMF Substantial compliance is available as an affirmative defence.
Who is covered?
Broader than most people assume on the private side, and heavier than most people expect on the public one. The trigger is doing business in Texas, not being headquartered there.
- Anyone doing business in Texas Developing or deploying an AI system that reaches Texas residents brings you in, wherever the company sits.
- Texas state agencies The heaviest duties in the Act fall on government: disclosure when a person is interacting with AI, and outright bans on social scoring and on biometric identification from public sources without consent.
- Healthcare providers using AI Where AI is used in care decisions, the person affected has to be told — and told before or at the time of the interaction, not afterwards.
- Anyone handling biometric identifiers TRAIGA reaches into the Texas biometric regime, so identification systems need reading against both at once.
Where the conduct can be fixed within the 60-day window after the Attorney General's written notice.
Where it cannot — the prohibited-intent conduct sits here.
Charged for each day a violation continues after the cure period closes.
Texas vs Colorado: what actually differs
Two US state AI laws landing months apart, built on opposite triggers. A programme designed for one does not answer the other, and that is the most expensive assumption on this page.
| Texas — TRAIGA | Colorado AI Act | |
|---|---|---|
| What triggers it | Intent — what you set out to do | Effect — algorithmic discrimination, however caused |
| Enforced by | Attorney General, exclusively | Attorney General, exclusively |
| Private right of action | None | None |
| Cure period | 60 days after written notice | Cure provisions apply |
| Risk-tier duties | No tiering — prohibited uses instead | Duties attach to "high-risk" systems |
| Impact assessments | Not mandated by the Act | Required for high-risk deployers |
| Safe harbour | Substantial NIST AI RMF compliance | Recognised frameworks, including NIST AI RMF |
| Sandbox | Regulatory sandbox, up to 36 months | None |
Running against the EU as well? The EU AI Act is tiered and effects-based, which puts it closer to Colorado than to Texas.
What counts as a prohibited use
Every one of these is an “intent to” clause. Read any other way the statute is misdescribed — and misdescribing it is how a programme ends up testing for the wrong thing.
Manipulation and harm
Intent to incite or encourage
- Self-harm, including suicide
- Harm to another person
- Criminal activity
- Behavioural manipulation that a person cannot reasonably resist
Constitutional rights
Intent to infringe
- Rights guaranteed by the US Constitution
- Speech, assembly and religious exercise
- Protections against unreasonable search
Unlawful discrimination
Intent to discriminate against a protected class
- Race, colour, national origin, sex, age, disability
- Religion and genetic information
- Disparate impact alone does not establish intent — but it is the evidence a claim starts from
Unlawful sexual material
Intent to produce or distribute
- Child sexual abuse material
- Sexually explicit deepfakes of identifiable people
- Material that is obscene under existing Texas law
Government only
Three duties that fall on Texas state agencies and not on private deployers — the part of the Act most often skimmed by readers who assume it does not apply to them, and then find their public-sector customer is asking about it.
- Social scoring — evaluating or classifying people on behaviour or characteristics to their detriment
- Biometric identification built from publicly available images or recordings without consent
- Disclosure whenever a person is interacting with an AI system, in plain language
Dates you should know
Including the Colorado date, because a multi-state programme is planning against both.
-
Active
HB 149 signed
TRAIGA enacted by the 89th Legislature
-
Active
TRAIGA takes effect
Prohibitions, agency duties and disclosure apply
-
Active
Regulatory sandbox opens
Time-limited relief for supervised testing
-
Active
Colorado AI Act applies
The effects-based sibling, for multi-state programmes
The four compliance pillars
What a TRAIGA-ready programme is actually built out of. Each one produces evidence — which under an intent-based statute is the only thing that answers the question.
Intent controls
The statute turns on purpose, so purpose has to be on the record
- A stated, documented purpose per AI system
- A prohibited-use policy naming the four categories
- Design-review gates that can refuse a use case
- Change control, so purpose cannot drift silently
Discrimination testing
Disparate impact is not the trigger — it is the evidence
- Subgroup performance testing across protected classes
- Results recorded with the population definitions used
- Investigation trail where a gap appears
- Red-teaming and adversarial testing, dated
Disclosure
Told before or at the time, not afterwards
- Plain-language notice that AI is in use
- Placed at the point of interaction
- Healthcare disclosures handled specifically
- Records of what was shown, and when
NIST AI RMF alignment
The affirmative defence, evidenced rather than asserted
- Mapped against GOVERN, MAP, MEASURE and MANAGE
- Substantial compliance shown, not claimed
- Gaps recorded with owners and dates
- Re-assessed on a fixed cadence
What lands at the end of it
Not a certificate — there is nothing to certify against. What you get is the evidence set that answers an intent question, and the ranked list of what to fix before someone else asks.
- A system inventory with a stated purpose per system
- Prohibited-use screening, reasoned per system rather than asserted
- Subgroup testing results with population definitions recorded
- An AI RMF map supporting the safe-harbour position
- A cure-readiness pack: owner, route and evidence, in advance
- Findings ranked by consequence, not by ease
Ranked by consequence, not by how easy it is to close
How iDharma supports TRAIGA compliance
Every line pairs an obligation with what the assessment produces against it, so each claim here can be checked against the requirement beside it.
| Requirement | What the assessment does |
|---|---|
| Prohibited-use screening | Every system read against the four intent categories, with the reasoning recorded per system rather than as a blanket assertion. |
| AI system inventory | Purpose, data, deployment context and affected people captured per system — the record the whole intent question rests on. |
| Discrimination testing | Subgroup and intersectional performance testing, with population definitions stated so the numbers stay readable a year later. |
| Disclosure review | Where notice is owed, whether it is given at the right moment, and whether the wording survives contact with a non-specialist. |
| NIST AI RMF mapping | Findings mapped to the AI RMF categories, so the safe-harbour claim rests on evidence you can hand over. |
| Biometric review | Identification systems read against TRAIGA and the Texas biometric regime together, because they overlap and neither is complete on its own. |
| Red-teaming records | Adversarial testing conducted and dated, which is what the discovery-through-testing defence is built on. |
| Cure-readiness pack | Owner, escalation route and evidence set assembled in advance, so a 60-day clock is spent fixing rather than finding. |
Common mistakes to avoid
The patterns we see in Texas-exposed programmes. Expect them to resurface when work lands on you.
Treating Texas like Colorado
They are built on opposite triggers. A Colorado programme organised around risk tiers and impact assessments does not answer an intent-based statute, and a Texas programme does not answer an effects-based one. Multi-state means both, not the union of the paperwork.
Assuming "we did not mean to" is enough
Intent is proved from the record — design documents, prompts, tuning decisions, what was known and when. A programme with no contemporaneous record has nothing to point at, which is the worst position to be in under a statute that turns on purpose.
Relying on the vendor's assurance
You deploy it, you answer for it. A supplier attestation is useful evidence and is not a defence, and the systems bought in are usually the ones nobody in-house can describe.
Claiming the NIST safe harbour without the evidence
Substantial compliance has to be shown. A policy naming the framework, with no measurement plan, no results and no owners behind it, is a claim rather than a defence.
Losing the 60-day cure window
The Attorney General's notice goes to whoever is registered, not to whoever owns AI. Programmes lose weeks to internal routing — and the clock does not pause while a letter is forwarded.
Reading "AG-only" as low risk
No private right of action means no class actions. It does not mean small numbers: uncurable violations are charged in six figures and a continuing violation is charged for every day it continues.
Frequently asked questions
What legal, compliance and data-science teams ask when TRAIGA first lands on the roadmap.
What is the Texas AI Act, in one paragraph?
HB 149, the Texas Responsible Artificial Intelligence Governance Act, effective 1 January 2026. It prohibits developing or deploying AI with certain intents — inciting harm or criminal activity, infringing constitutional rights, unlawfully discriminating against a protected class, or producing unlawful sexual material — places extra duties on state agencies, and is enforced exclusively by the Attorney General with a 60-day period to cure.
Does it apply to us if we are not based in Texas?
If you do business in Texas or your AI system reaches Texas residents, yes. The trigger is where the conduct lands, not where the company is registered.
Is it a risk-tiered law like the EU AI Act?
No, and this is the most common misreading. There is no high-risk classification exercise to perform and no tier that switches on a duty list. It prohibits specific intentional conduct and imposes disclosure duties on government, and the compliance work is proving your purposes rather than sorting systems into buckets.
What extra duties fall on state agencies?
Disclosure whenever a person is interacting with an AI system, an outright ban on social scoring, and a ban on building biometric identification from publicly available images or recordings without consent, with carve-outs for certain law-enforcement uses.
How is intent actually established?
From the record. Design documents, system prompts, tuning and evaluation decisions, escalations that were raised and what happened to them. The practical consequence is that a programme with no contemporaneous documentation is in the weakest position under this statute, not the strongest.
If our model shows disparate impact, have we broken the law?
Not on its own. TRAIGA requires intent to discriminate, and disparate impact by itself does not establish it. That is not a reason to stop testing: impact data is where a claim starts, and finding it yourself, recording it and acting on it is a materially better position than having someone else find it.
What is the NIST AI RMF safe harbour?
Substantial compliance with the NIST AI Risk Management Framework is available as an affirmative defence. That makes AI RMF the most useful thing a Texas-exposed programme can adopt — and it is why we map every finding to its AI RMF category. We have a full page on the framework itself.
Are there other defences?
The Act contemplates discovery through internal review or adversarial testing — red-teaming — among the routes to a defence. All of them share one requirement: the work has to have been done and dated before the problem became someone else's question.
What are the penalties?
Civil penalties on a banded structure: a lower band for violations that can be cured, a substantially higher one for those that cannot, and a per-day penalty for a violation that continues after the cure period closes. The per-day element is what turns a single missed control into a number that matters.
What is the cure period?
Sixty days from the Attorney General's written notice. In practice the useful preparation is knowing in advance who receives that notice, who owns the response, and where the evidence lives — most of the window gets spent finding things rather than fixing them.
Can individuals sue us under it?
No. There is no private right of action; enforcement rests with the Attorney General. Existing civil-rights and consumer-protection routes are unaffected by that, so it narrows this statute rather than your overall exposure.
What is the regulatory sandbox?
A supervised programme allowing time-limited testing of AI systems with relief from some requirements, for up to thirty-six months, with reporting obligations attached. It is worth considering for a genuinely novel deployment; it is not a way to defer ordinary compliance work.
Where should we start?
An inventory with a stated purpose per system, then screening those purposes against the four prohibited categories, then AI RMF alignment so the safe harbour is available. That is the order we run an assessment in, and scoping is agreed with you before anything is charged.
Primary sources
This page is a summary. These are the documents behind it, plus the two of our own pages a Texas-exposed programme needs next.
The enrolled text, analyses and history from the Texas Legislature.
https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149 Office of the Texas Attorney GeneralThe enforcing authority — notices, guidance and consumer protection.
https://www.texasattorneygeneral.gov/ Texas Department of Information ResourcesState AI policy and the administration of the regulatory sandbox.
https://dir.texas.gov/ NIST AI Risk Management FrameworkThe framework behind the affirmative defence, from NIST directly.
https://www.nist.gov/itl/ai-risk-management-framework NIST AI RMF, assessed end to endThe framework behind TRAIGA’s affirmative defence, and what an assessment against it covers. The single most useful thing a Texas-exposed programme can adopt.
The EU AI ActTiered and effects-based — the comparison most multi-jurisdiction programmes need after Colorado.
Ready for 1 January 2026?
Inventory, purpose, prohibited-use screening and an AI RMF map that makes the safe harbour real. Scoped with you before you are charged.
This page is guidance on how we scope an assessment, not legal advice. Where a scope question is genuinely arguable, we say so in writing rather than pick the convenient answer.