TEXAS HB 149 · TRAIGA · FROM 1 JAN 2026

Under the Texas AI Act, a violation turns on what you meant to do.

Four prohibited intents, live since 1 January 2026, enforced by the Attorney General - and it turns on what you meant, not on outcome.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Intent is proved from the record, or not at all
Intent, not effect Four prohibited uses Attorney General only 60-day cure NIST AI RMF defence

Our promise

“Intent is a defence. The record of it is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.

Each additional tool
$1,500
Re-audit, same scope
$4,200
Renewal, every twelve months
$5,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

TRAIGA, in three chapters

The Law

Texas enacted HB 149 in June 2025 — the Responsible Artificial Intelligence Governance Act — binding conduct from 1 January 2026. It prohibits developing or deploying an AI system with any of four kinds of intent, with each of the four named in the very next section of this page.

The Gap

Most programmes arrive organised around risk tiers and impact assessments — what Colorado and the EU taught them. Neither answers a statute built on purpose. What does is a contemporaneous record of what each system was for, written before it shipped.

The Office

Our assessment builds that record for you. We inventory the systems with a stated purpose written against each one, screen those purposes against the four prohibited categories, and map each finding to the AI RMF category that the substantial-compliance defence will eventually rest on.

What is actually prohibited

Four intents, not four risk tiers.

There is no classification to perform. The question is what you set out to do.

Prohibited intents № 01
  • To incite or encourage self-harm, harm to others, or crime
  • To infringe rights guaranteed by the US Constitution
  • To discriminate unlawfully against a protected class
  • To produce or distribute unlawful sexual material
HB 149 · iDharma · Presented for review
Extra duties on government № 02
  • Disclosure whenever a person interacts with an AI system
  • An outright ban on social scoring by state agencies
  • No biometric identification from public sources
  • Carve-outs for certain law-enforcement uses, and no others
HB 149 · iDharma · Presented for review
Whose duty is it

The system is theirs. The purpose is yours.

You

Whoever develops or deploys it

TRAIGA reaches anyone doing business in Texas whose AI system touches Texas residents, wherever the company itself happens to sit. Deploying a system you did not build puts you inside the Act on the same terms as building one - you deploy it, and you answer for it exactly as they would.

The state

Where the heaviest duties actually fall

Government carries more than industry does here: disclosure whenever a person is interacting with an AI system, an outright ban on social scoring, and a ban on biometric identification built from publicly available images or recordings without the consent of the people who appear in any of them.

The catch

Intent is proved from the record

Design documents, system prompts, tuning and evaluation decisions, escalations raised and what actually happened to each of them. A programme with no contemporaneous record has nothing to point at - which is the worst place to be under a statute that turns on what you intended at the time.

What most teams assume

“We never intended it, so nothing needs answering.”

What the statute needs

Intent is proved from your record, not your memory.

It is the most common gap we write up.

  • Who it is for
  • Legal & compliance
  • Model risk & data science
  • Texas state agencies
  • Healthcare providers
  • Product & engineering
  • Vendor management
Why the record matters
An open legal volume lying under warm lamplight with a fountain pen and a pair of round tortoiseshell spectacles resting across its pages, three more bound volumes stacked behind it and a brass page tab at its lower edge.
01 Penalties are banded: modest where the conduct can be cured, six figures where it cannot, and charged per day while it continues. That last part is what turns one missed control into a real number.
02

Sixty days to cure, running from the Attorney General’s written notice — and the clock does not pause while that letter is being routed.

03

Colorado runs the opposite trigger — effect, not intent. A programme built for the one does not answer the other, and it never will.

04

No private right of action means no class actions. It does not mean small numbers, and it narrows none of the rest of your exposure at all.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a legal determination.

0 of 3

Reaches Texas -

Where the conduct lands, not where you are registered. Doing business in Texas or deploying a system that reaches Texas residents brings you in, wherever the company sits. A state agency carries more than this again.

Purpose screened -

Four categories, all written as intent. Inciting harm or crime, infringing constitutional rights, discriminating against a protected class, producing unlawful sexual material. The question is not whether harm happened - it is what the system was for.

What exists today -

The record is the defence. Design documents, prompts, tuning and evaluation decisions, escalations and what happened to them - plus the AI RMF mapping the affirmative defence rests on. Most of a cure window gets spent finding these, not fixing anything.

The sequence

Four moments, and only one is a clock.

Nothing here falls due, so nothing prompts anybody - and the only clock that starts is one somebody else starts for you.

  1. Signed

    June 2025

    HB 149 enacted by the 89th Legislature: prohibited uses defined, AG enforcement set, and the sandbox opened.

  2. In force

    1 January 2026

    Prohibitions, agency duties and disclosure apply to conduct from that date - not to systems built before it.

  3. Colorado

    Alongside it

    The effects-based sibling runs on the opposite trigger. Multi-state means answering both, not merging them.

  4. The cure clock

    60 days

    It starts on the Attorney General's written notice, and it does not pause while that letter is routed internally.

The trap

The Attorney General’s notice goes to whoever is registered, not whoever owns the AI, and programmes lose weeks to internal routing while the sixty days run. Most of a cure window goes on finding evidence, not fixing it — so the pack is built before the letter arrives.

Expectation & coverage

What the statute says, what we ship

12 provisions, and the artefact that answers each one. Reading unverified.

Manipulation and harm Intent to incite or encourage
Every system read against this category with the reasoning recorded, rather than a blanket assertion across the estate.
Constitutional rights Intent to infringe
A prohibited-use policy naming the category, and design-review gates with the authority to refuse a use case.
Unlawful discrimination Intent to discriminate against a protected class
Subgroup and intersectional testing with the population definitions stated, and the investigation trail where a gap appears.
Unlawful sexual material Intent to produce or distribute
Screening against the category, with the content controls and the escalation route recorded per system.
Government AI disclosure State agencies - before or at the time
Plain-language notice at the point of interaction, and the record of what was shown and when.
Social scoring ban State agencies - outright
A written determination that no system classifies people on behaviour or characteristics to their detriment.
Biometric identification From public sources without consent
Identification systems read against TRAIGA and the Texas biometric regime together, because neither is complete alone.
Stated purpose per system The record the intent question rests on
Purpose, data, deployment context and affected people captured per system, with change control so purpose cannot drift.
NIST AI RMF alignment The affirmative defence, evidenced not asserted
Findings mapped to GOVERN, MAP, MEASURE and MANAGE, so the safe-harbour claim rests on evidence you can hand over.
Adversarial testing Discovery through internal review or red-teaming
Red-teaming conducted and dated, which is what a discovery-based defence is actually built on.
Vendor systems You deploy it, you answer for it
The evidence to ask each supplier for, and your own screening over what an attestation does not cover.
Cure readiness 60 days from written notice
Named recipient, escalation route and evidence set assembled in advance, so the window is spent fixing rather than finding.
The engagement

Your AI estate, independently assessed

From a chatbot to a screening model.

  1. Inventory and purpose

    Every system, and the stated purpose the whole intent question rests on.

  2. Screen and test

    The four prohibited intents, subgroup testing, and the disclosure moments.

  3. Sign off and map

    You see the draft first. Then the findings, mapped to the AI RMF categories.

Request an assessment
An auditor in a charcoal suit and white shirt, with grey hair, standing against a warm pale wall and pointing into the open space alongside.
Shown, not asserted - that is what a defence is.
Struck in your favour

Why teams choose iDharma for TRAIGA

Genuinely independent

We build and resell no AI systems of our own, and take no fee tied to what the assessment finds.

Written to the statute

Every finding names the provision it answers, so counsel can check it against HB 149.

The safe harbour, shown

Findings map to the AI RMF categories, so the defence rests on evidence, not a claim.

Texas is not Colorado

We scope the two separately, because a programme built for one does not answer the other.

Four marks, struck on every assessment.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

TRAIGA assessment report

The full assessment in one document: what you run, what each system is for, and where a stated purpose comes close to a prohibited one - every system screened against the four intent categories with its reasoning, each finding mapped to its AI RMF category, and the whole written in plain language rather than the Act's.

Register

AI system inventory

Purpose, data, deployment context and affected people per system - the record the whole intent question rests on when it is asked.

Memo

Prohibited-use screening

Each system read against the four intent categories, with the reasoning per system rather than one blanket assertion over the estate.

Report

Discrimination testing

Subgroup and intersectional performance results with the population definitions stated, so the numbers stay readable a year later.

Mapping

NIST AI RMF map

Findings against GOVERN, MAP, MEASURE and MANAGE, with gaps recorded and owned - the evidence behind the affirmative defence.

Templates

Disclosure review

Where notice is owed, whether it lands at the right moment, and whether the wording survives contact with a non-specialist.

Index

Cure-readiness pack

Named recipient, escalation route and the evidence set assembled in advance, so a 60-day clock is spent fixing rather than finding.

Format & fee

Real numbers, upfront.

Scope
Set by the statute, not by us
Input
Your systems and their purposes
Re-assess
On material change — $5,500 against your known baseline

The statute fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
TRAIGA · Named engagement $6,500 flat
  • Prohibited-use screening, per system
  • Inventory with a stated purpose each
  • Subgroup testing, populations stated
  • NIST AI RMF map and the cure pack
Show your hand

Four things you have to be able to produce

The statute prescribes no format. Each of these is either on file the day it is asked for, or it is not.

The purpose,
stated

What each system is for, written down before it shipped. Under a statute that turns on intent, an undocumented purpose is the weakest position available.

The screen,
per system

Each system read against the four prohibited intents with the reasoning recorded - not one blanket assertion covering an estate nobody has listed.

The testing,
dated

Subgroup results and red-teaming, with the populations defined and the date on the file. Disparate impact is not the trigger under this Act - it is the evidence for one.

The map,
to NIST

Substantial AI RMF compliance shown across GOVERN, MAP, MEASURE and MANAGE. A policy naming the framework is a claim; the mapping is the defence.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Risk tiers, reach, intent and penalties. Answered straight.

Request this review
Is it a risk-tiered law like the EU AI Act?

No, and this is the most common misreading. There is no high-risk classification exercise and no tier that switches on a duty list. It prohibits specific intentional conduct, and it mandates no impact assessment.

Does it apply to us if we are not based in Texas?

If you do business in Texas or your AI system reaches Texas residents, yes. The trigger is where the conduct lands, not where the company is registered.

How is intent actually established?

From the record: design documents, system prompts, tuning and evaluation decisions, escalations raised and what happened to them. A programme with no contemporaneous documentation is in the weakest position, not the strongest.

What is the NIST AI RMF safe harbour?

Substantial compliance with the NIST AI Risk Management Framework is available as an affirmative defence - which makes AI RMF the most useful thing a Texas-exposed programme can adopt, and it has to be shown rather than claimed.

What are the penalties?

Civil penalties on a banded structure: a lower band for curable violations, a substantially higher one running to six figures for those that cannot be cured, and a per-day penalty while a violation continues.

Get started

Request a TRAIGA assessment

Tell us what you run and what it is for, and we come back within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of your model governance records in an afternoon, and we tell you exactly which extracts before you commit.

  1. Whether your systems reach people in Texas, and how
  2. What each system is for, in your own words
  3. Your AI inventory, if you already have one
  4. How much came from a vendor, and what they supplied
  5. Whether you already claim NIST AI RMF alignment

What happens next

  1. We agree the scope with you first.
  2. Four to eight weeks, longer for a big estate.
  3. Nothing is charged until you approve the scope.
Request a TRAIGA assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • HB 149, 89th Legislature, Regular Session
  • General knowledge of how it is read
Signed
June 2025
In force
1 January 2026

What it means

  • General information about what the statute prohibits — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Written from general knowledge of HB 149, not line-checked against the enrolled text. The penalty bands are the least certain figures here, and they are stated as a structure rather than as precise numbers for that reason.
  • It covers HB 149 alone - Colorado, the EU AI Act and your sector rules bind you separately.
  • On an engagement we work from the enrolled text. Use this as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us