Skip to content

Texas TRAIGA: What Changed on 1 January 2026

10 min read · updated August 11, 2026

TRAIGA prohibits developing or deploying AI with certain intentions. It does not regulate outcomes, it does not require impact assessments, and that single drafting decision is why it passed where a Colorado-style bill would not have.

How TRAIGA is shaped

House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, was signed by Governor Abbott on 22 June 2025 and took effect on 1 January 2026. It sits in the Texas Business and Commerce Code. The bill that became law is substantially narrower than the version introduced in the 2025 session, which had contained a Colorado-style framework of developer and deployer duties around high-risk systems; that framework was removed during passage and what remains is a prohibitions statute with a government-transparency component and a sandbox.

The history matters because commentary written during the session describes the introduced version. Read the enacted text, whose history and final version are at the Texas Legislature Online.

Not legal advice. TRAIGA interacts with the Texas Data Privacy and Security Act and with the biometric statute in Business and Commerce Code Chapter 503, and a real analysis has to consider all three together on your facts.

The prohibited-use list

The core of the Act is a list of things it is unlawful to develop or deploy an AI system to do. In substance:

  • Behavioural manipulation toward harm — developing or deploying a system with the intent to incite or encourage a person to commit physical self-harm, to harm another person, or to engage in criminal activity.
  • Infringement of constitutional rights — with the intent to infringe, restrict or otherwise impair a person’s rights under the United States Constitution.
  • Unlawful discrimination — with the intent to unlawfully discriminate against a protected class, with the statute expressly providing that disparate impact alone is not sufficient to demonstrate that intent.
  • Sexual and child-abuse material — developing or distributing systems for producing child sexual abuse material or unlawful deepfake sexual content.
  • Government biometric capture — a government agency using AI to capture biometric identifiers of an individual without consent, where doing so would infringe a right under state or federal law.
  • Government social scoring — a government agency using AI to assign a social score or similar categorisation based on behaviour or characteristics in a way that results in detrimental treatment.

Two of the six bind only government agencies. That asymmetry is deliberate and recurs across American AI legislation: a legislature willing to constrain its own agencies is often unwilling to impose the same constraint on private business. Compare California SB 896, which is entirely a government statute.

Why the intent element decides everything

Every private-sector prohibition in TRAIGA carries an intent element, and the discrimination provision goes further by stating expressly that disparate impact alone does not establish it. That is the opposite of the drafting choice made in Illinois HB 3773, which prohibits AI use that has the effect of discriminating, and it is a narrower rule than Colorado’s duty of reasonable care, which asks about care rather than about purpose.

The practical consequence for a deployer is large. A hiring model that produces a disparity nobody wanted is a serious problem under Illinois law, a duty-of-care problem in Colorado, and — on the face of the statute — not a TRAIGA violation at all, absent evidence of intent. What TRAIGA reaches is the deliberate case: a system built to do the prohibited thing, or deployed knowing that it does.

Where intent would be found is genuinely unresolved. Internal documents showing that a disparity was identified and the system shipped anyway sit somewhere between knowledge and intent, and no Texas court has construed the provision. It is not yet clear whether the Attorney General will read intent to include conscious disregard, and until a case is brought the safest characterisation is that the boundary is untested.

Government agencies and health care disclosure

TRAIGA imposes a disclosure duty on state agencies: an agency that makes an AI system available for interaction with consumers must disclose, before or at the time of the interaction, that the person is interacting with an AI system. The disclosure must be clear and conspicuous, in plain language, and must not use a dark pattern. That last clause is the one worth noting — a disclosure buried in a way designed not to be read is treated as no disclosure.

A parallel duty applies to health care: where an AI system is used in the provision of health care services or treatment, the patient must be informed. As with California AB 3030, the duty attaches to the provider rather than to the software vendor, and as with AB 3030 the timing is specified rather than left open.

TRAIGA also amended the Texas biometric statute, Chapter 503 of the Business and Commerce Code, to clarify the treatment of biometric data used in training where the data is not used to identify a specific individual. That amendment is significant for anyone training vision or voice models on Texas-sourced data, and it moves Texas further from the Illinois BIPA position rather than closer to it.

Enforcement, cure period and the sandbox

Enforcement belongs exclusively to the Texas Attorney General. There is no private right of action. The Attorney General maintains an online mechanism for consumer complaints, and before bringing an action must give written notice identifying the alleged violation and allow a cure period of 60 days.

The penalty structure distinguishes curable from uncurable violations, with the enacted ranges set materially higher for the latter, and provides for daily penalties for continuing violations. A cure period of this kind changes the compliance posture considerably: the realistic first event is a letter rather than a suit, and an organisation that can respond substantively within 60 days is in a very different position from one that cannot locate its own system inventory in that time. That is an argument for maintaining evidence you can produce on demand rather than for producing it in advance.

Finally, TRAIGA establishes a regulatory sandbox administered through the Department of Information Resources, allowing approved participants to test AI systems for a defined period — reported at 36 months — with relief from certain requirements, alongside an artificial intelligence council. Texas and Utah are the two American states to have built a sandbox into their AI statute, which makes the comparison with Utah’s learning laboratory the useful one.

The penalty figures, the sandbox terms and the scope of the biometric amendment are the items most likely to be affected by implementing guidance or by the 2027 legislative session. Verify current figures against the enacted text before relying on them.