Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / Texas TRAIGA

The Texas Responsible Artificial Intelligence Governance Act: the comprehensive state AI law now in force.

The Texas Responsible Artificial Intelligence Governance Act, TRAIGA, enacted as HB 149 and signed on June 22, 2025, took effect on January 1, 2026. With Colorado having repealed its 2024 law before it operated, TRAIGA is the comprehensive state AI statute actually in force in the United States, and it is built on a different legal theory than the Colorado model that dominated early discussion. This page explains what the statute prohibits, who it reaches, how it is enforced, and why its NIST AI RMF safe harbor changes the value of framework alignment.

The Statute at a Glance

TRAIGA (Texas HB 149)

  • Signed June 22, 2025; effective January 1, 2026
  • Intent-based prohibitions rather than an impact-based regime
  • Enforced by the Texas Attorney General, with no private right of action
  • A 60 day cure period before enforcement proceeds
  • Civil penalties that can reach $200,000 for uncurable violations
  • Substantial compliance with the NIST AI RMF recognized as a defense
Fundamentals

An intent-based statute, which changes what compliance means.

The single most important thing to understand about TRAIGA is the question it asks. The Colorado model that shaped early state AI debate was impact-based: it asked whether a high-risk AI system could produce algorithmic discrimination, regardless of what the deployer intended, and it obligated organizations to assess and manage that foreseeable risk. TRAIGA asks a different question: did the organization intentionally develop or deploy AI to cause a defined harm. The final statute is considerably narrower than its early drafts, focusing on a specific list of prohibited uses plus governance duties for Texas state agencies, rather than imposing a general high-risk management regime on private business.

The intent standard means most ordinary business AI use does not, by itself, create TRAIGA liability. What the statute changes for an ordinary organization is the value of being able to demonstrate what its AI systems are for and how they are governed, because intent disputes are resolved on records. An organization with a documented AI use inventory, stated intended uses, and a working AI use policy can show what it set out to do; an organization without them argues from recollection.

The Prohibitions

What the statute forbids and requires.

TRAIGA concentrates on uses the legislature judged categorically unacceptable, together with transparency duties for state government AI. The principal provisions group as follows.

01

Intentional harm and manipulation

Prohibits developing or deploying AI with the intent to incite or encourage self-harm, harm to others, or criminal activity, and AI intended to unlawfully manipulate the people it interacts with.

02

Intentional unlawful discrimination

Prohibits developing or deploying AI with the intent to unlawfully discriminate against protected classes. The intent qualifier is the dividing line from the impact-based Colorado approach: disparate outcomes alone, without intent, are addressed by existing civil rights law rather than by this statute.

03

Prohibited sexual content

Prohibits AI-generated child sexual abuse material and nonconsensual intimate deepfake imagery, aligning the statute with the deepfake laws most states have now enacted and with federal law in the same territory.

04

Government AI duties

Prohibits government social scoring and certain governmental biometric practices, and requires Texas state agencies to disclose to consumers when they are interacting with AI. The statute also establishes an AI regulatory sandbox program and a state AI council to oversee the field as it develops.

Enforcement belongs exclusively to the Texas Attorney General; there is no private right of action. An alleged violator receives notice and a 60 day period to cure before enforcement proceeds, and civil penalties scale with severity, reaching $200,000 for uncurable violations, with additional daily amounts for continuing ones. The cure period rewards organizations that can demonstrate governance quickly, which is a records question before it is a legal one.
The Safe Harbor

Substantial compliance with the NIST AI RMF as a defense.

TRAIGA's most consequential feature for governance planning is its treatment of the NIST AI Risk Management Framework: substantial compliance with the framework is recognized as a defense. This is the first time a binding American statute has converted the voluntary framework into concrete legal value, and it validates the framework-based approach to AI governance directly. An organization that aligns to the AI RMF, and holds the records that demonstrate it, has built its Texas defense as a byproduct of ordinary governance work.

The counterpoint is instructive. Colorado's original 2024 statute contained a comparable framework-based defense, and when that law was repealed and replaced in 2026, the defense did not survive into the successor. Statutes and their incentives churn; the framework has remained the stable reference underneath them. The planning conclusion drawn across this cluster follows: govern to the framework, hold the records, and let statute-specific analysis sit on top, as the state AI laws page develops across the full patchwork.

Who It Reaches

Location of the organization is not the test.

TRAIGA reaches entities that develop or deploy AI systems in Texas or whose systems affect Texans. As with the other state statutes, the attachment runs through the people a system touches rather than through the deployer's address: an organization headquartered elsewhere whose chatbot serves Texas consumers, whose hiring tool screens Texas applicants, or whose AI-assisted decisions affect Texas residents should treat itself as inside the statute's reach. Texas is the second largest state economy in the country, which makes incidental reach into it the norm rather than the exception for any organization with a national customer base, applicant pool, or remote workforce. The boundary analysis on the state law page develops the point across jurisdictions; the operational answer is the same everywhere: the AI use inventory must record whose residents each system can reach.

What Compliance Looks Like

For most organizations, TRAIGA compliance is documentation of purpose.

Because the statute is intent-based and its prohibitions target deliberate misuse, an ordinary organization does not build a TRAIGA program the way a Colorado-style regime would have demanded. What it builds is the ability to demonstrate purpose and governance: the inventory that shows which AI systems exist and what each is for, the intended use documentation that the NIST AI RMF's Map function produces in the ordinary course, the use policy that shows the organization decided what its people may do, and the framework alignment that constitutes the statutory defense. Every element serves the organization's other obligations at the same time, from customer questionnaires to insurance applications, which is why the Texas statute functions in practice less as a new compliance burden than as a legislature putting a price on governance work the organization had reason to do anyway.

Common Questions

TRAIGA, answered briefly.

What is TRAIGA?

The Texas Responsible Artificial Intelligence Governance Act, HB 149, signed June 22, 2025 and effective January 1, 2026. It prohibits a defined list of intentionally harmful AI uses, sets disclosure and governance duties for Texas state agencies, establishes a regulatory sandbox and an AI council, and is enforced by the Texas Attorney General.

Who does it apply to?

Entities that develop or deploy AI in Texas or whose systems affect Texans, regardless of where the organization sits. Reach follows the residents affected, not the deployer's location.

How does the NIST AI RMF safe harbor work?

Substantial compliance with the NIST AI Risk Management Framework is recognized as a defense under the statute. The practical consequence is that framework alignment, with the records to demonstrate it, carries direct legal value in Texas in addition to its commercial value everywhere else. The NIST AI RMF page covers the framework itself.

How is TRAIGA different from Colorado's law?

TRAIGA is intent-based and targets deliberate misuse; Colorado's 2024 law was impact-based and regulated high-risk systems for foreseeable discrimination regardless of intent. Colorado repealed that law in 2026 before it operated and replaced it with a narrower transparency statute taking effect in 2027, covered on the state AI laws page.

Get In Touch

Discuss TRAIGA and Your AI Governance Position

Inquiries may involve whether your systems reach Texas, building the inventory and intended use records that an intent-based statute rewards, or structuring NIST AI RMF alignment so it also constitutes the Texas defense. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is whether TRAIGA reaches your organization, what records would demonstrate purpose and governance if the question were ever asked, or how the safe harbor changes your framework planning, the first conversation carries no commitment and no pitch.

Discuss an Assessment →