TRAIGA Compliance: What Texas Companies Must Do Under HB 149 in 2026
TRAIGA took effect January 1, 2026. Here is what Texas companies developing or deploying AI must do under HB 149 to stay compliant with the Texas AG.
The Texas Responsible AI Governance Act (TRAIGA) — enacted as House Bill 149 — took effect on January 1, 2026, making this the first full calendar year that Texas companies developing or deploying artificial intelligence systems must comply with the state's own AI governance framework. If you are a founder building AI products in Texas, or a company deploying AI tools that touch Texas residents, TRAIGA creates obligations you cannot afford to misunderstand.
Here is what TRAIGA requires: who it covers, how developer and deployer obligations differ, what uses are prohibited, what documentation you need, how the Texas Attorney General enforces the law, and how TRAIGA compares to Colorado's revised AI Act (SB 26-189) and the EU AI Act.
What TRAIGA Covers: Scope and Key Definitions
TRAIGA applies to two categories of entities: "covered persons" (developers and deployers) and government entities. A covered person is anyone who promotes, advertises, or conducts business in Texas; produces a product or service Texas residents use; or develops or deploys an AI system in Texas. Critically, you do not need to be headquartered in Texas to be subject to the law. If your AI system affects Texas residents, TRAIGA applies to you.
The law defines an "artificial intelligence system" broadly: any machine-based system that, for any explicit or implicit objective, infers from the inputs it receives how to generate outputs — including content, decisions, predictions, or recommendations — that can influence physical or virtual environments. This definition captures everything from recommendation engines and hiring screeners to chatbots and loan underwriting models.
A "developer" is a person who develops an AI system that is offered, sold, leased, given, or otherwise provided in Texas. A "deployer" is a person who deploys an AI system for use in Texas. Your company can be both simultaneously — for example, if you build a proprietary AI tool and also use it internally.
The law defines "consumer" as an individual who is a Texas resident acting in an individual or household context. Employment and commercial uses fall outside this definition, which narrows the scope of consumer-facing disclosure obligations but does not eliminate the prohibited-practice rules that apply to all uses.
Developer vs. Deployer Obligations Under TRAIGA
TRAIGA imposes different obligations depending on whether you are developing an AI system, deploying one, or both.
Developer Obligations
Developers are responsible for the AI systems they create and make available in Texas. While TRAIGA does not impose the kind of detailed technical documentation requirements found in the EU AI Act or Colorado's SB 26-189, developers must ensure that their systems are not designed or deployed with prohibited intent. Because TRAIGA takes an intent-based approach to regulation — focusing on what an AI system was designed to do rather than whether it caused specific harm — developers bear the burden of documenting legitimate design purpose for each system.
Developers should also be aware that TRAIGA's safe harbor provisions reward proactive risk management. A developer who substantially complies with the NIST AI Risk Management Framework or similar recognized standards has an affirmative defense against liability. We have written separately about why the TRAIGA safe harbor makes NIST AI RMF alignment a business decision, not just a compliance exercise.
Deployer Obligations
Deployers face the most direct compliance burden under TRAIGA. If you deploy an AI system that interacts with Texas consumers, you must provide clear and conspicuous disclosure — before or at the time of interaction — that the consumer is interacting with AI. The disclosure must be written in plain language and must not use dark patterns.
For deployers that are government entities, additional obligations apply. Government agencies must disclose AI use to consumers before or during each interaction, even when the disclosure would be obvious to a reasonable consumer. Government entities are also subject to specific prohibited-use rules that do not apply to private actors.
Private-sector deployers should note that the consumer disclosure requirement applies specifically to consumer-facing interactions. Internal business uses — such as AI-assisted code review or internal document analysis — do not trigger the consumer disclosure obligation, but all deployers remain subject to the prohibited-practice rules.
Prohibited Uses of AI Under TRAIGA
TRAIGA establishes two tiers of prohibited practices: one applicable to government entities and one applicable to all persons, including private companies.
Prohibited for Government Entities
Government entities may not use AI to assign a social score or to uniquely identify a specific individual using biometric data without the individual's consent. Biometric data under TRAIGA includes fingerprints, voiceprints, retina or iris patterns, and other unique biological characteristics — but excludes physical or digital photographs, video or audio recordings, and information collected under HIPAA.
Prohibited for All Persons
No person — whether a government entity or private company — may use AI to incite or encourage self-harm, crime, or violence; infringe, restrict, or impair an individual's rights guaranteed under the U.S. Constitution; unlawfully discriminate against a protected class in violation of state or federal law; or produce or distribute certain sexually explicit content or child pornography, including deepfakes.
On discrimination, TRAIGA explicitly does not recognize disparate impact alone as sufficient to demonstrate an intent to discriminate. This is a significant distinction from Colorado's framework and from federal anti-discrimination doctrine. Under TRAIGA, the state must show that your AI system was designed or deployed with discriminatory intent — not merely that it produced a discriminatory outcome. This intent requirement makes documentation of design purpose and testing protocols especially important for your defense.
Documentation Requirements
TRAIGA does not impose the kind of mandatory risk assessments or annual impact reports found in Colorado's original SB 205. However, documentation is essential to mounting a defense if the Texas AG comes knocking. Here is what you should maintain:
First, an inventory of every AI system your company develops or deploys in Texas, including third-party tools such as chatbots and recommendation engines. Second, records demonstrating the intended purpose of each system — this is your primary defense against an intent-based violation. Third, evidence of alignment with recognized risk management frameworks, particularly the NIST AI RMF, which provides an affirmative defense under the law. Fourth, consumer disclosure records showing that AI interactions were disclosed in plain language without dark patterns. Fifth, vendor documentation: if you are a deployer using third-party AI, you should have records showing what your vendors provided and how their systems are intended to function.
If your company operates across state lines, your documentation should also address Colorado's requirements, since Colorado SB 26-189 imposes specific developer documentation duties — including descriptions of intended uses, known harmful uses, training data categories, known limitations, and instructions for appropriate use and human review. Building documentation that satisfies both TRAIGA and Colorado's framework is more efficient than maintaining separate records. For more on Colorado's revised requirements, see our guide to Colorado's AI Act compliance.
Enforcement: The Texas Attorney General
TRAIGA grants the Texas Attorney General exclusive enforcement authority. There is no private right of action — consumers cannot sue you directly under the law. But the AG's enforcement powers are substantial.
Before filing an enforcement action, the AG must send a written notice of violation and allow a 60-day cure period. During those 60 days, the alleged violator must cure the violation, provide supporting documentation, and update internal policies to prevent recurrence. This cure period is a built-in enforcement lag that gives companies time to remediate — but it also means that companies with no compliance infrastructure will struggle to build one from scratch in 60 days.
The penalty structure is per violation, not per company. Curable violations carry civil penalties of $10,000 to $12,000 per violation. Uncurable violations carry $80,000 to $200,000 per violation. Continuing violations accrue $2,000 to $40,000 per day. Because each deployment or use of a prohibited AI system constitutes a separate violation, a single AI hiring tool that processes thousands of applications could generate thousands of separate violations if found to have been deployed with discriminatory intent.
The AG is also required to create an online consumer complaint portal, which must be operational by September 1, 2026. Once that portal opens, consumers affected by AI-assisted decisions — job applicants, tenants, loan applicants — will have a formal channel to submit complaints. The first enforcement actions are likely to follow within months of the portal's launch.
State licensing agencies also have limited enforcement authority. If the AG finds that a licensed professional has violated TRAIGA and recommends additional enforcement, the agency may suspend or revoke licenses and impose fines up to $100,000.
Safe Harbors and Affirmative Defenses
TRAIGA provides three affirmative defenses. You are not liable if a third party misuses your AI in a prohibited manner; if you discover a violation through testing or good-faith audits; or if you substantially comply with the NIST AI Risk Management Framework or similar recognized standards. The NIST safe harbor is the most practically significant — it means that companies with documented AI risk management programs have a clear path to avoiding liability even if a technical violation occurs.
TRAIGA vs. Colorado SB 26-189 vs. the EU AI Act
Texas companies operating in multiple jurisdictions need to understand how TRAIGA interacts with other AI governance frameworks.
Colorado SB 26-189
Colorado revised its original AI Act (SB 205) with SB 26-189, signed on May 14, 2026, and effective January 1, 2027. The revised law shifts from regulating "high-risk AI systems" to "automated decision-making technology" (ADMT) used to materially influence consequential decisions in employment, education, lending, financial services, insurance, healthcare, and government services.
Key differences from TRAIGA: Colorado imposes specific developer documentation duties (descriptions of intended uses, training data categories, known limitations, human review instructions) and deployer disclosure obligations (pre-use notice and post-adverse-outcome notice with consumer rights to access, correct, and request human review). Colorado eliminated the mandatory risk management programs and annual impact assessments from SB 205, but it retains a documentation and disclosure framework that goes beyond TRAIGA's requirements.
Colorado also introduces a liability framework that voids contract provisions purporting to indemnify a party for its own discriminatory acts — a provision that demands immediate review of your AI vendor contracts. TRAIGA, by contrast, does not address indemnification for discriminatory AI use.
The EU AI Act
The EU AI Act applies to companies placing AI systems on the EU market, regardless of where they are headquartered. It classifies AI systems by risk tier, with "high-risk" systems — those used in areas like employment, education, law enforcement, and critical infrastructure — subject to the most stringent obligations, including conformity assessments, technical documentation, risk management systems, human oversight requirements, and post-market monitoring.
The EU's high-risk classification is broader and more prescriptive than TRAIGA's prohibited-practices list. While TRAIGA focuses on what you cannot do (prohibited uses), the EU AI Act focuses on what you must do (compliance obligations) before deploying high-risk systems. The European Commission has published draft guidelines to help companies classify their AI systems, with a stakeholder consultation open until July 23, 2026.
For Texas companies selling into the EU, the practical approach is to build documentation that satisfies both TRAIGA's intent-based requirements and the EU AI Act's technical documentation standards. The NIST AI RMF — which provides a safe harbor under TRAIGA — is also a useful bridge to EU compliance, as it maps conceptually to the EU's risk management requirements.
Building AI products in Texas? TRAIGA compliance starts with the right legal foundation. Our team helps founders navigate AI governance, vendor contracts, and multi-state regulatory requirements.
Actionable Next Steps
If you are a Texas founder or company developing or deploying AI, here is what we recommend doing now:
1. Conduct an AI inventory. Map every AI system your company develops, deploys, or uses — including third-party tools. Document the intended purpose of each system. This is your first line of defense under TRAIGA's intent-based framework.
2. Align with the NIST AI RMF. Substantial compliance with the NIST framework provides an affirmative defense under TRAIGA. Even if you are not subject to TRAIGA's most stringent requirements, NIST alignment is the single most cost-effective compliance investment you can make. Our guide to the TRAIGA safe harbor walks through this in detail.
3. Implement consumer-facing AI disclosures. If your AI system interacts with Texas consumers, ensure disclosures are clear, conspicuous, in plain language, and free of dark patterns. Document when and how disclosures were made.
4. Review vendor contracts. If you deploy third-party AI, ensure your vendor agreements address TRAIGA compliance — including vendor obligations to provide documentation of intended use and to notify you of material updates. Our AI vendor contract due diligence checklist covers the clauses that matter most.
5. Prepare for multi-state compliance. If you operate in Colorado or sell into the EU, build documentation that satisfies the stricter of the applicable frameworks. A single documentation set that covers TRAIGA, Colorado SB 26-189, and the EU AI Act is more efficient than maintaining parallel records.
6. Monitor the AG complaint portal. The Texas AG's consumer complaint portal is expected to be operational by September 1, 2026. Treat this date as your compliance deadline — not as a starting point. Companies with documented compliance records by that date will be in a fundamentally different legal position than companies that begin building records after receiving a civil investigative demand.