Texas
Texas AI Regulations (TRAIGA): What's Actually Required
Texas's Responsible AI Governance Act is built around proof of intent, not foreseeable risk — a narrower standard than Colorado's, with a broader jurisdictional reach than most companies expect.
Texas doesn't have a Colorado-style AI law, and the legislature wrote it that way on purpose. The Texas Responsible Artificial Intelligence Governance Act — TRAIGA, enacted as House Bill 149 and in force since January 1, 2026 — skips the duty-of-care, foreseeable-risk framework that Colorado built its statute around and replaces it with something narrower and harder to trigger: a requirement that the state prove intent. That single design choice shapes almost everything else worth knowing about the law, and it's the detail most compliance checklists built for Colorado or the EU miss when they get applied to Texas by habit.
Who TRAIGA actually covers
The statute's scope is broader than its substantive requirements are deep. TRAIGA reaches any person or entity that develops or deploys an AI system and promotes, advertises, or conducts business in Texas, or whose product or service is used by Texas residents — a jurisdictional trigger built around conduct and customers, not headquarters. A company incorporated in Delaware with no Texas office is squarely in scope the moment a Texas resident uses its AI-powered product.
There's no revenue or employee-count threshold carving out smaller companies, which is a real point of contrast with how this bill looked earlier in the process. A December 2024 draft, and a separate stalled bill (HB 1709), had included a small-business exemption pegged to Small Business Administration size standards. The version Governor Greg Abbott signed on June 22, 2025 doesn't carry that exemption forward — every covered developer, deployer, or distributor is in scope regardless of size, though as the next section covers, "in scope" doesn't mean "facing the same exposure a comprehensive duty-of-care statute would create."
The intent standard that sets Texas apart
Here's the detail that actually determines how much legal exposure TRAIGA creates: it's an intent-based statute, not a risk-based one. The prohibited practices described below only trigger liability if the AI system was developed or deployed with the sole intent to cause the listed harm. The statute goes further and explicitly forecloses the easier path a plaintiff or regulator might otherwise take — it states that a disparate impact on a protected class, by itself, doesn't establish a violation.
Compare that to Colorado's approach, which imposes a duty of reasonable care against known or reasonably foreseeable risks of algorithmic discrimination, regardless of what anyone intended. Under a foreseeability standard, a company can be liable for a risk it should have caught even without any intent to cause harm. Under TRAIGA's intent standard, the state has to show the system was built or used for the purpose of discriminating, manipulating, or causing one of the other prohibited harms — a meaningfully higher bar, and one that narrows the law's practical reach even though its jurisdictional scope is broad. Our full breakdown of Colorado's AI Act covers the reasonable-care framework in detail if you're tracking exposure in both states at once.
The six things TRAIGA actually prohibits
TRAIGA's prohibited-practices list is short and specific, and it splits cleanly into two groups. Four prohibitions apply to any developer or deployer, public or private:
- Developing or deploying an AI system with the sole intent to incite or further self-harm, suicide, or harm to another person, or to incite criminal activity.
- Developing or deploying an AI system with the sole intent to unlawfully discriminate against a protected class.
- Developing or deploying an AI system that infringes a person's constitutionally protected rights.
- Developing or deploying an AI system with the sole intent to produce child sexual abuse material or other unlawful visual material depicting a minor.
Two additional prohibitions apply only to government entities, not private companies — a distinction that trips people up because the surrounding coverage of TRAIGA rarely says so explicitly:
- A government entity may not develop or deploy an AI system to assign a "social score" to individuals or groups based on their social behavior or personal characteristics.
- A government entity may not develop or deploy an AI system to capture biometric data for the purpose of identifying a specific individual without that person's consent.
A private company building a biometric-matching or behavior-scoring product isn't automatically caught by these last two — it would need to run into one of the other four, universal prohibitions instead, or into a different statute (Texas's existing biometric and privacy law still applies independently).
A worked example
Take Brazos Lending Analytics, a hypothetical fintech that sells a credit-underwriting model to Texas-based lenders. The model weighs dozens of signals, and a post-launch audit finds that applicants from a handful of majority-minority zip codes are approved at a measurably lower rate than the overall pool. Under Colorado's reasonable-care standard, that disparity alone could support a claim — the statute asks whether the company managed a foreseeable discrimination risk, and a measurable disparity is itself evidence worth scrutinizing.
Under TRAIGA, that same audit finding doesn't get Brazos to a violation by itself. The statute says disparate impact alone doesn't establish liability — the Texas Attorney General would need evidence that Brazos built or tuned the model with the sole intent to discriminate against applicants based on a protected characteristic, not merely that the outcome turned out uneven. If Brazos can show the disparity traces to a legitimate underwriting variable correlated with geography, rather than to a feature or training choice aimed at the protected characteristic itself, intent becomes very hard to prove. That doesn't mean the disparity is a non-issue — it's still a real underwriting and fair-lending exposure under other law, and a reasonable compliance team fixes it regardless — but it does mean TRAIGA specifically isn't the statute doing the enforcing in that scenario.
Enforcement, the cure period, and penalties
Enforcement runs through one channel only: the Texas Attorney General. There's no private right of action, so an individual harmed by an AI system can't bring a TRAIGA claim directly — any civil suit would have to rest on a different legal theory entirely.
Before the AG can impose a penalty, the statute builds in a cure period: written notice of the alleged violation, followed by 60 days for the company to cure it and document that the cure actually happened. Only after that window closes without a cure can the AG pursue penalties. Multiple independent law firm alerts and compliance trackers report consistent numbers for what those penalties look like: roughly $10,000 to $12,000 per violation that was curable but wasn't cured in time, $80,000 to $200,000 per violation the AG establishes was uncurable, and $2,000 to $40,000 per day for a violation that continues uncorrected. The statute doesn't spell out a bright-line test for what makes a violation curable versus not, so companies should treat the cure period less as a formality and more as the real opportunity it's designed to be — document the fix, don't just make it.
The regulatory sandbox option
TRAIGA also creates a regulatory sandbox, administered by the Texas Department of Information Resources in consultation with the Texas Artificial Intelligence Council. A company building a system it's genuinely uncertain about can apply to participate, and approved participants get reduced regulatory friction for up to 36 months, with quarterly reporting back to the state. The sandbox doesn't suspend the law's core prohibitions — the ban on intentionally discriminatory, manipulative, or otherwise harmful systems still applies inside it — but it's a real, usable pathway for a company developing a higher-risk system who wants a documented, good-faith relationship with the state while it works through open questions, rather than building in isolation and hoping an eventual AG inquiry goes well.
TRAIGA vs. Colorado's AI Act
The comparison that matters most isn't jurisdiction size or enforcement history — it's which standard a given system actually has to clear. Colorado's statute asks whether developers and deployers exercised reasonable care against foreseeable algorithmic discrimination risk, built around the idea of a consequential decision affecting employment, credit, housing, healthcare, or similar high-stakes categories. TRAIGA asks a narrower question: was this specific system built or used with the intent to cause one of a short list of defined harms. A company operating in both states can't treat one compliance program as covering both — satisfying Colorado's documentation and impact-assessment obligations doesn't establish anything about intent under TRAIGA, and clearing TRAIGA's narrower bar says nothing about whether reasonable care was exercised under Colorado's broader one. See our full Colorado AI Act breakdown for the mechanics of that separate standard, and our California coverage if your compliance footprint spans a third, differently-structured state.
What this means for a compliance program
The practical mistake to avoid is importing a Colorado or EU AI Act mental model into Texas and assuming the paperwork burden is similar. It isn't — TRAIGA doesn't require an annual impact assessment or a pre-use consumer notice the way Colorado's statute does. What it requires instead is making sure no system is built, tuned, or deployed in a way that creates evidence of intent to discriminate, manipulate, or cause the other listed harms, and keeping records that would support a cure if the Attorney General ever comes calling. That's a materially different risk to manage: less about structured ongoing compliance paperwork, more about what a system's design choices and internal communications would look like if a regulator ever went looking for intent. Companies operating nationally should also keep an eye on how the broader fight over state AI law authority is playing out — nothing currently in effect displaces TRAIGA, but it's one more state statute sitting inside a legal landscape that's still actively being contested at the federal level.
Frequently asked questions
- Does TRAIGA apply to a company headquartered outside Texas?
- Yes. TRAIGA's trigger is conduct, not incorporation: it reaches anyone who promotes, advertises, or conducts business in Texas, or whose AI-powered product or service is used by Texas residents. A company based in Delaware or California with Texas customers is in scope the same way a Texas-headquartered company is. There's also no revenue or size threshold — an earlier draft bill had a small-business carve-out, but the enacted version doesn't.
- Is there a private right of action under TRAIGA?
- No. Enforcement is exclusive to the Texas Attorney General. A consumer who believes an AI system violated TRAIGA can't bring their own lawsuit under the statute — they'd need to pursue a claim under some other legal theory, or wait for the AG to act.
- What's the actual difference between TRAIGA's standard and Colorado's?
- TRAIGA requires proof that an AI system was developed or deployed with the sole intent to discriminate against a protected class, manipulate someone's behavior against their interest, or cause one of the statute's other listed harms — and it explicitly says disparate impact alone doesn't establish a violation. A reasonable-care, foreseeability-based standard like the one Colorado built its AI Act around doesn't require proving what anyone intended; it asks whether a known or foreseeable risk went unaddressed. Intent is a materially harder thing for a regulator to prove than foreseeability, which is the whole point of writing the statute that way.
- What happens if a company doesn't cure a violation within 60 days?
- The Attorney General can file a civil enforcement action and seek penalties. Multiple independent compliance trackers and law firm client alerts report consistent penalty ranges: roughly $10,000 to $12,000 per violation that was curable but not cured in time, $80,000 to $200,000 per violation found to be uncurable, and $2,000 to $40,000 per day for a continuing violation. The statute's own curable/uncurable distinction isn't spelled out in granular detail, so treat these as the ranges reported consistently across secondary sources rather than a verbatim statutory table.
- Can a Texas government agency use AI for social scoring or biometric tracking?
- No, not under TRAIGA's prohibited-practices list — developing or deploying AI to socially score individuals, or to capture biometric data to identify someone without consent, is banned specifically for government entities. That's narrower than it looks at first read: those two prohibitions don't extend to private companies, which remain governed by TRAIGA's other, universally-applicable prohibitions instead.
Sources & references
- Official source
- Texas HB 149 (89th Legislature, Regular Session, 2025) — bill text and legislative history
- K&L Gates — Pared Back Version of the Texas Responsible Artificial Intelligence Governance Act Signed Into Law
- Baker Botts — Texas Enacts Responsible AI Governance Act: What Companies Need to Know
- American Bar Association, Business Law Today — Texas Enters the AI Sandbox with TRAIGA
Suggested next reading
regulations us colorado
Colorado AI Act (SB 205)
regulations us california