Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / Texas TRAIGA

The Texas Responsible Artificial Intelligence Governance Act: the major cross-sector state AI law now in force.

The Texas Responsible Artificial Intelligence Governance Act, TRAIGA, enacted as HB 149 and signed on June 22, 2025, took effect on January 1, 2026. With Colorado having repealed its 2024 law before it operated, TRAIGA is a major cross-sector state AI statute in force in the United States, and it is built on a different legal theory than the Colorado model that dominated early discussion. This page explains what the statute prohibits, who it reaches, how it is enforced, and how framework compliance operates inside its defense structure.

The Statute at a Glance

TRAIGA (Texas HB 149)

  • Signed June 22, 2025; effective January 1, 2026
  • Intent-based prohibitions rather than an impact-based regime
  • Enforced by the Texas Attorney General, with no private right of action
  • A 60 day cure period before enforcement proceeds
  • Civil penalties that can reach $200,000 for uncurable violations
  • Framework compliance built into the statutory defense structure
Fundamentals

An intent-based statute, which changes what compliance means.

The single most important thing to understand about TRAIGA is the question it asks. The Colorado model that shaped early state AI debate was impact-based: it asked whether a high-risk AI system could produce algorithmic discrimination, regardless of what the deployer intended, and it obligated organizations to assess and manage that foreseeable risk. TRAIGA asks a different question: did the organization intentionally develop or deploy AI to cause a defined harm. The final statute is considerably narrower than its early drafts, focusing on a specific list of prohibited uses plus governance duties for Texas state agencies, rather than imposing a general high-risk management regime on private business.

The intent standard means most ordinary business AI use does not, by itself, create TRAIGA liability. What the statute changes for an ordinary organization is the value of being able to demonstrate what its AI systems are for and how they are governed, because intent disputes are resolved on records. An organization with a documented AI use inventory, stated intended uses, and a working AI use policy can show what it set out to do; an organization without them argues from recollection.

The Prohibitions

What the statute forbids and requires.

TRAIGA concentrates on uses the legislature judged categorically unacceptable, together with transparency duties for state government AI. The principal provisions group as follows.

01

Intentional harm and manipulation

Prohibits developing or deploying AI with the intent to incite or encourage self-harm, harm to others, or criminal activity, and AI intended to unlawfully manipulate the people it interacts with.

02

Intentional unlawful discrimination

Prohibits developing or deploying AI with the intent to unlawfully discriminate against protected classes. The intent qualifier is the dividing line from the impact-based Colorado approach: disparate outcomes alone, without intent, are addressed by existing civil rights law rather than by this statute.

03

Prohibited sexual content

Prohibits AI-generated child sexual abuse material and nonconsensual intimate deepfake imagery, aligning the statute with the deepfake laws most states have now enacted and with federal law in the same territory.

04

Government AI duties

Prohibits government social scoring and certain governmental biometric practices, and requires Texas state agencies to disclose to consumers when they are interacting with AI. The statute also establishes an AI regulatory sandbox program and a state AI council to oversee the field as it develops.

Enforcement belongs exclusively to the Texas Attorney General; there is no private right of action. An alleged violator receives notice and a 60 day period to cure before enforcement proceeds, and civil penalties scale with severity: $10,000 to $12,000 per curable violation or breach of a cure statement, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for continuing violations, with a rebuttable presumption that a person used reasonable care. The cure period rewards organizations that can demonstrate governance quickly, which is a records question before it is a legal one.
The Defense Structure

Where the NIST AI RMF sits in the statutory defense.

TRAIGA's most consequential feature for governance planning is where it places the NIST AI Risk Management Framework. Per the official bill analysis, a defendant may not be found liable where another person misused the AI system in a prohibited manner or where the defendant discovered the violation through recognized mechanisms, which the enacted text ties to good faith testing, audits, and internal review, with substantial compliance with the NIST AI RMF or another recognized risk management framework among the recognized bases. That is a discovery anchored defense rather than a blanket safe harbor: the statute protects the organization whose own governance process surfaced the problem, not the organization holding an unread framework binder. The distinction strengthens rather than weakens the case for framework work, because what earns the protection is a documented, operating process, and it sits alongside two further protections the statute provides separately: a 60 day cure period before the Attorney General may bring an action, and a rebuttable presumption that a person used reasonable care.

The counterpoint is instructive. Colorado's original 2024 statute contained its own framework-based defense, and when that law was repealed and reenacted in 2026, the defense did not carry forward into the successor. Statutes and their incentives churn; the framework has remained the stable reference underneath them. The planning conclusion drawn across this cluster follows: govern to the framework, hold the records, and let statute-specific analysis sit on top, as the state AI laws page develops across the full patchwork.

Who It Reaches

Location of the organization is not the test.

TRAIGA reaches entities that develop or deploy AI systems in Texas or whose systems affect Texans. As with the other state statutes, the attachment runs through the people a system touches rather than through the deployer's address: an organization headquartered elsewhere whose chatbot serves Texas consumers, whose hiring tool screens Texas applicants, or whose AI-assisted decisions affect Texas residents should treat itself as inside the statute's reach. Texas is the second largest state economy in the country, which makes incidental reach into it the norm rather than the exception for any organization with a national customer base, applicant pool, or remote workforce. The boundary analysis on the state law page develops the point across jurisdictions; the operational answer is the same everywhere: the AI use inventory must record whose residents each system can reach.

What Compliance Looks Like

For most organizations, TRAIGA compliance is documentation of purpose.

Because the statute is intent-based and its prohibitions target deliberate misuse, an ordinary organization does not build a TRAIGA program the way a Colorado-style regime would have demanded. What it builds is the ability to demonstrate purpose and governance: the inventory that shows which AI systems exist and what each is for, the intended use documentation that the NIST AI RMF's Map function produces in the ordinary course, the use policy that shows the organization decided what its people may do, and the framework alignment that supports the statutory defense described above. Every element serves the organization's other obligations at the same time, from customer questionnaires to insurance applications, which is why the Texas statute functions in practice less as a new compliance burden than as a legislature putting a price on governance work the organization had reason to do anyway.

Common Questions

TRAIGA, answered briefly.

What is TRAIGA?

The Texas Responsible Artificial Intelligence Governance Act, HB 149, signed June 22, 2025 and effective January 1, 2026. It prohibits a defined list of intentionally harmful AI uses, sets disclosure and governance duties for Texas state agencies, establishes a regulatory sandbox and an AI council, and is enforced by the Texas Attorney General.

Who does it apply to?

Entities that develop or deploy AI in Texas or whose systems affect Texans, regardless of where the organization sits. Reach follows the residents affected, not the deployer's location.

How does the NIST AI RMF defense work?

The statute's defense is discovery anchored: a defendant may avoid liability where a third party misused the system or where the defendant discovered the violation through recognized mechanisms such as good faith testing, audits, or internal review, with substantial compliance with the NIST AI RMF or another recognized framework among the recognized bases. Framework alignment with operating records therefore carries direct legal value in Texas, earned through the process rather than the paperwork. The NIST AI RMF page covers the framework itself.

How is TRAIGA different from Colorado's law?

TRAIGA is intent-based and targets deliberate misuse; Colorado's 2024 law was impact-based and regulated high-risk systems for foreseeable discrimination regardless of intent. Colorado repealed and reenacted that law in 2026, before it operated, as a narrower transparency statute taking effect in 2027, covered on the state AI laws page.

Get In Touch

Discuss TRAIGA and Your AI Governance Position

Inquiries may involve whether your systems reach Texas, building the inventory and intended use records that an intent-based statute rewards, or structuring NIST AI RMF alignment so it also constitutes the Texas defense. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is whether TRAIGA reaches your organization, what records would demonstrate purpose and governance if the question were ever asked, or how the defense structure changes your framework planning, the first conversation carries no commitment and no pitch.

Discuss an Assessment →