Texas took a light-touch, intent-based approach — heavy duties for government, narrow prohibitions for everyone. Here is what applies from January 1, 2026.
This article is educational guidance, not legal advice. AI law in the United States is changing quickly and varies by state and sector. Confirm current statutory text, effective dates, and rulemaking with primary sources and qualified counsel before making compliance decisions.The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), enacted as HB 149, took effect January 1, 2026. The version that became law is far narrower than the sweeping, EU-style draft first introduced. It centers on a short list of intent-based prohibitions that apply to everyone, a heavier set of duties for government agencies, an AI regulatory sandbox, and exclusive enforcement by the Texas Attorney General. A companion law, SB 1188, addresses AI in health records.
For most private businesses, TRAIGA is closer to a set of guardrails than a compliance program. This article explains its scope, the prohibited uses, the government-versus-private split, and the enforcement mechanics.
Scope: who and what is covered
TRAIGA defines an “artificial intelligence system” broadly — a machine-based system that infers, from the inputs it receives, how to generate outputs that can influence physical or virtual environments. The Act reaches a person or entity that:
- Promotes, advertises, or conducts business in Texas;
- Produces a product or service used by Texas residents; or
- Develops or deploys an AI system in the state.
Crucially, the final law abandoned the draft's broad “high-risk AI” duties, impact assessments, and disparate-impact discrimination theory for the private sector. What remains for private actors is a set of narrow prohibitions tied to intent.
Prohibited uses (apply to everyone)
TRAIGA prohibits developing or deploying an AI system with the intent to:
- Incite or encourage a person to commit physical self-harm, harm another person, or engage in criminal activity;
- Unlawfully discriminate against a protected class — and the statute makes clear that a disparate impact, by itself, is not sufficient to prove the required intent;
- Produce or distribute child sexual abuse material, or unlawful sexually explicit deepfakes, including content that impersonates a minor in sexual contexts;
- Infringe or restrict constitutional rights, or unlawfully capture/use biometric identifiers without consent (interacting with Texas's existing biometric law).
The intent requirement is the heart of TRAIGA. Unlike Colorado's original reasonable-care model, TRAIGA generally does not penalize unintended discriminatory outcomes — the AG must show the system was designed or deployed with a prohibited purpose. That makes ordinary, good-faith AI product use much lower risk under this statute.Government-specific duties
State and local government agencies carry obligations that private businesses do not:
- Consumer disclosure: government agencies must clearly disclose to a person when they are interacting with an AI system, before or at the time of interaction.
- Health care: providers using AI in patient treatment must inform patients of that use (reinforced by companion law SB 1188 on AI and health records).
- No government social scoring: government entities may not use AI to assign social scores that evaluate or classify people based on behavior or personal characteristics in ways that produce detrimental treatment.
- Biometric constraints on government use of AI-driven identification.
The AI regulatory sandbox
TRAIGA creates a state AI regulatory sandbox program that lets approved participants test AI systems for a limited period without full licensing or certain regulatory authorizations, under state oversight. The goal is to encourage innovation while keeping a supervisory line of sight into novel systems. The Act also establishes a Texas Artificial Intelligence Council to advise on policy and monitor the sandbox.
Enforcement and penalties
Enforcement is exclusive to the Texas Attorney General — there is no private right of action. The AG must generally provide notice and a cure opportunity before penalties for curable violations. Penalty ranges reported for the enacted law:
| Violation type | Civil penalty range |
|---|---|
| Curable violation | $10,000 – $12,000 |
| Uncurable violation | $80,000 – $200,000 |
| Continuing violation | $2,000 – $40,000 per day |
TRAIGA also preempts local (city and county) AI-specific ordinances, creating a single statewide standard rather than a patchwork within Texas.
How TRAIGA compares to Colorado and California
| Dimension | Texas TRAIGA | Colorado SB 26-189 | California (stack) |
|---|---|---|---|
| Core theory | Intent-based prohibitions | Transparency + consumer rights for ADMT | Frontier safety + GenAI transparency + privacy ADMT |
| Private-sector burden | Low | Moderate | Varies by law; can be high |
| Discrimination standard | Intentional only | No standalone duty of care | Sector/privacy rules |
| Enforcement | AG only, no private action | AG only, no private action | AG (SB 53); UCL private exposure (AB 2013) |
| Effective | Jan 1, 2026 | Jan 1, 2027 | Rolling 2026–2027 |
What Texas-operating teams should do
- Confirm none of your AI features could be read as designed to enable a prohibited use (self-harm/criminal incitement, unlawful biometric capture, CSAM/deepfake sexual content, intentional discrimination).
- If you are a government agency or a vendor to one, implement AI-interaction disclosures and patient/health notices, and avoid any social-scoring functionality.
- Review biometric data flows against Texas's biometric consent requirements, which TRAIGA reinforces.
- Consider the sandbox if you are piloting a novel AI system in Texas and want supervised regulatory relief.
TRAIGA's low private-sector burden should not be read as “no US AI compliance needed.” Teams operating in multiple states still face Colorado's ADMT duties, California's transparency stack, and sector rules (EEOC, FCRA, HIPAA). Treat TRAIGA as one layer, not the whole picture.