Texas TRAIGA: What the AI Law Requires, What It Leaves Out, and What the Attorney General Uses Instead

Share Article

Table of Contents

Texas has the widest AI statute in the United States by scope and one of the narrowest by duty. The Texas Responsible Artificial Intelligence Governance Act reaches any company whose product or service is used by a Texas resident, with no revenue floor and no small-business exemption, and then asks that company for almost nothing.

TRAIGA’s combination of wide scope and thin duty produces a misreading worth correcting up front. The only AI enforcement the Texas Attorney General has actually run was opened on 18 August 2025, four and a half months before TRAIGA took effect, under general consumer protection law. Reading TRAIGA alone gives a false sense of how exposed an AI deployer in Texas really is.

Three things follow in order: what TRAIGA reaches and requires, what it conspicuously leaves out, and what the Attorney General reaches for instead.

Section 551.002 catches companies with no Texas presence at all

TRAIGA’s applicability provision comes before its duties and is short enough to quote whole.

“This subtitle applies only to a person who: (1) promotes, advertises, or conducts business in this state; (2) produces a product or service used by residents of this state; or (3) develops or deploys an artificial intelligence system in this state.”

The three limbs are disjunctive, so any one brings a person inside Chapters 551 to 554. Limb two is the one that travels: a company with no Texas office, no Texas employees and no Texas sale is caught if Texas residents use its product. Limb one reaches remote advertisers.

What is absent matters more. TRAIGA carries no revenue threshold, no headcount threshold, no processing-volume trigger and no small-business carve-out. The Texas Data Privacy and Security Act has one at section 541.002(a)(3), excluding businesses that qualify as small under the Small Business Administration definition. TRAIGA has no equivalent, which makes it broader in reach than the state’s own privacy law.

Scope is not duty, though. Three of the seven operative sections bind only governmental bodies, so most companies inside the statute owe nothing under most of it.

The definitions are broader than Brussels in one place and narrower in another

Three definitions decide how far the statute travels, and two of them are doing work nobody talks about.

Artificial intelligence system, at section 551.001(1), means “any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.”

Texas AI law took the European formula and cut two qualifiers out of it. The EU AI Act requires a system “designed to operate with varying levels of autonomy” that “may exhibit adaptiveness after deployment”. Neither phrase survives in Texas. Removing conditions widens the net, so a simple inference model that would struggle to qualify in Brussels qualifies in Austin. How the European definition works is set out in what the EU AI Act asks and when.

Consumer, at section 551.001(2), means “an individual who is a resident of this state acting only in an individual or household context. The term does not include an individual acting in a commercial or employment context.”

Excluding employment is load-bearing and almost never quoted. TRAIGA’s disclosure duty runs to consumers. An employee interacting with an HR chatbot, a candidate talking to a screening assistant, a contractor using an internal tool: none of them qualifies. Workplace AI sits outside the disclosure regime entirely.

Developer and deployer are defined at section 552.001, and here is the structural oddity. Neither term is used as the subject of any prohibition in Subchapter B. Every ban binds “a person” or “a governmental entity”. The two words appear operatively only in the investigative demand scope at 552.103(b)(7) and in the defence at 552.105(e)(2)(A). The developer-versus-deployer framing that dominates AI compliance writing is not how this statute is built.

Seven sections, seven different things the state has to establish

Chapter 552 Subchapter B carries one disclosure duty and six prohibitions. Each attaches a mental state, and the mental state decides whether the section has any practical reach.

SectionWho is boundConductWhat must be proved
552.051Governmental agencies; health care providersFailure to disclose AI interactionNothing. Strict duty
552.052Any personInciting self-harm, harm to others or crime“Intentionally aims to”
552.053Governmental entities onlySocial scoring“With the intent to calculate or assign a social score”
552.054Governmental entities, plus a private trapdoorBiometric identification and scraping“For the purpose of uniquely identifying”
552.055Any personInfringing constitutional rights“With the sole intent”
552.056Any personUnlawful discrimination“With the intent to unlawfully discriminate”
552.057Any personCSAM, deepfakes, child-impersonating sexual chat“Sole intent” for (1), “intentionally” for (2)

TRAIGA uses sole intent twice, and it means any lawful secondary purpose defeats the claim. A general-purpose model that can be misused has, by definition, other purposes. Sections 552.055 and 552.057(1) would be difficult to prove against a mainstream developer on the text alone.

TRAIGA’s discrimination liability turns on the same problem. Section 552.056(b) requires intent to unlawfully discriminate, and subsection (c) removes the route almost every discrimination case actually uses: “For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.” Subsection (d) then disapplies the section to insurance entities already regulated for unfair discrimination, and subsection (e) deems federally insured financial institutions compliant where they follow banking law. Credit scoring and insurance pricing, where the highest-volume automated decisioning sits, are largely outside it.

Divergence from Colorado is deliberate here. Colorado built its 2024 framework on a duty of reasonable care testable by outcome; Texas requires proof of purpose. What Colorado asks for now is in the SB 26-189 checklist.

Two duties do land on private business, and both are narrow

The statute imposes almost nothing on an ordinary commercial deployer. Two exceptions are worth finding.

Health care disclosure. Section 552.051(b) imposes the general AI-interaction disclosure duty on “a governmental agency“, not on business. Subsection (f) carves private providers back in: where an AI system is used in relation to health care service or treatment, the provider must disclose to the patient or their representative no later than the date treatment is first provided, with an emergency exception allowing disclosure as soon as reasonably possible. Texas providers using AI in triage, diagnosis support or treatment scheduling are inside this.

Two drafting problems sit in that one section. “Governmental agency” appears exactly once in the entire chapter and is nowhere defined; the defined term is “governmental entity” at section 552.001(3), used in sections 552.053 and 552.054, and it expressly excludes hospital districts and institutions of higher education. Whether “agency” is narrower or wider than “entity” is unresolved. Separately, subsection (c) opens “A person is required to make the disclosure under Subsection (b)”, which reads as though the duty runs to everyone; the better view is that (c) is parasitic on (b) and only removes an obviousness defence, since a subsection cannot create a duty the operative subsection withholds. No court and no Attorney General opinion has addressed either point.

The biometric trapdoor. TRAIGA addresses section 552.054(b) to governmental entities. Subsection (c) is one sentence and changes who is exposed: “A violation of Section 503.001 is a violation of this section.” Section 503.001 is the Capture or Use of Biometric Identifier Act, which binds private persons capturing biometric identifiers for a commercial purpose. A CUBI breach therefore becomes a Chapter 552 breach, exposed to the Chapter 552 penalty bands on top of CUBI’s own penalty of up to 25,000 dollars per violation.

Read that trapdoor against the statutory definition before budgeting for it. Section 552.054(a) defines biometric data to exclude photographs, data derived from photographs, audio and video recordings, and HIPAA treatment, payment and operations data. Much of retail video analytics falls outside. Voiceprint and faceprint template systems do not.

What TRAIGA does not require, which is most of what a programme normally does

Listing TRAIGA’s absences is the fastest way to understand it.

No AI system inventory. No impact assessment of any kind. No bias audit. No consumer notice from a private business outside health care. No record-retention duty. No registration. No conformity assessment. No human review right. No appeal route. No annual reporting. No duty to inform workers. No data governance standard.

Texas AI law asks for none of that. Colorado requires notice, a 30-day explanation, meaningful human review and three years of records from 1 January 2027. The EU AI Act requires technical documentation, a quality management system and conformity assessment for Annex III systems from 2 December 2027. Neither duty set has a Texas equivalent for a private deployer at any date. The comparison across jurisdictions sits in the global regulation tracker.

Four shields narrow the remaining surface further

TRAIGA carries more defensive provisions than any comparable American AI law.

A cure right with no sunset. Section 552.104 requires written notice identifying the specific provisions allegedly violated and bars action for 60 days. Curing inside the window, with a written statement, supporting documentation and evidence of internal policy changes, ends the matter. Unlike the Texas Data Privacy and Security Act, and unlike Colorado’s cure right which expires on 1 January 2030, this one is permanent. Curing carries its own trap: the written statement becomes an enforceable representation, and breaching it is separately penalised under section 552.105(a)(1).

A presumption of reasonable care. Section 552.105(c) provides in a single line that “There is a rebuttable presumption that a person used reasonable care as required under this chapter.”

Misuse by another person. Section 552.105(e)(1) bars liability outright where “another person uses the artificial intelligence system affiliated with the defendant in a manner prohibited by this chapter.”

A framework-based defence that is not what it looks like. Section 552.105(e)(2) protects a defendant who discovers a violation through feedback, through testing including adversarial or red-team testing, through following state agency guidelines, or through an internal review process where the defendant “substantially complies with the most recent version of the ‘Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile'” published by NIST “or another nationally or internationally recognized risk management framework”.

The named instrument is NIST AI 600-1, the Generative AI Profile, not the AI RMF 1.0 that commentary reflexively cites, and ISO/IEC 42001 falls inside the alternative. More importantly the defence attaches to how a violation was discovered, not to whether an organisation complies. Adopting the framework and finding nothing is not literally within the subsection. A documented discovery route through red-teaming, feedback intake and internal review is what converts framework adoption into something usable in court.

Penalties, when reached, run from 10,000 to 12,000 dollars for a curable violation or breach of a cure statement, 80,000 to 200,000 dollars for an uncurable one, and 2,000 to 40,000 dollars for each day a violation continues, plus attorney’s fees, court costs and investigative expenses under section 552.105(b). Neither curable nor uncurable is defined, leaving the classification to the court. Section 552.105(f) puts undeployed systems outside the penalty regime entirely.

For anyone holding a state licence, TRAIGA’s section 552.106 matters more than the fine. A licensing agency may suspend, place on probation or revoke a licence and add up to 100,000 dollars, but only after a court has found a violation under 552.105 and the Attorney General has recommended further enforcement. Both conditions are cumulative.

Enforcement under TRAIGA waits for a complaint. The Attorney General does not

Reading TRAIGA alone misleads at exactly this point.

Section 552.101 gives the Attorney General exclusive enforcement authority and bars private suits in terms broad enough to block bootstrapping: TRAIGA “does not provide a basis for, and is not subject to, a private right of action for a violation of this chapter or any other law.”

Section 552.102 required an online complaint mechanism by 1 September 2026. Texas has the page live, with a “File An AI Complaint” route into the consumer complaint portal, and it was in place ahead of that deadline. No launch announcement appears in the Attorney General’s newsroom, so no precise go-live date is on the public record.

Complaint intake matters because of what TRAIGA allows next. Section 552.103(a) provides that “If the attorney general receives a complaint through the online mechanism under Section 552.102 alleging a violation of this chapter, the attorney general may issue a civil investigative demand.” A portal complaint is the predicate. TRAIGA enforcement is reactive by design.

What a TRAIGA demand can compel is bounded too. Section 552.103(b) lists seven categories plus a catch-all, and four of the seven are capped at a “high-level description”: purpose, intended use and deployment context; input data categories; outputs; and post-deployment monitoring and safeguards. Also compellable are training data types, performance metrics and known limitations. Model weights and source code are not listed. Paragraph (8), “any other relevant documentation reasonably necessary”, is where that protection softens.

None of that constrains the Attorney General’s powers outside TRAIGA. On 18 August 2025, months before TRAIGA existed as live law, the office opened investigations into Meta AI Studio and Character.AI over chatbots presented as mental health tools, alleging impersonation of licensed professionals, fabricated credentials and misrepresented confidentiality. The authority used was Texas consumer protection law, with the SCOPE Act in the Character.AI matter, and the instrument was a civil investigative demand issued without any TRAIGA complaint.

The practical conclusion for a Texas deployer is straightforward, and it is not about TRAIGA. TRAIGA sets a narrow, intent-based, complaint-gated regime. The Deceptive Trade Practices Act sets a wide, outcome-based, self-starting one. Marketing claims about an AI product are governed by the second, not the first.

The institutions: one rulemaker, one advisory council, and a name collision

Chapter 553 creates an AI regulatory sandbox administered by the Texas Department of Information Resources in consultation with the Council, with sign-off also required from whichever agency would otherwise license the activity. Participants may test for up to 36 months, extendable on a finding of good cause with no stated cap, and report quarterly on performance metrics, risk mitigation and stakeholder feedback, with the Department obliged to protect intellectual property.

Section 553.051(e) sets the boundary: the sandbox waives licensing and registration requirements, not the Subchapter B prohibitions, which stay live throughout. Section 553.052 is also the Act’s only rulemaking grant, directing the Department to prescribe the application form by rule. No such rule appears in the Texas Register, so the programme does not yet appear to be open, and no participants have been reported.

Chapter 554 creates the Texas Artificial Intelligence Council: seven public members, three appointed by the Governor, two by the Lieutenant Governor and two by the Speaker, administratively attached to the Department. Section 554.103 forecloses the obvious question. The Council “may not adopt rules or promulgate guidance that is binding for any entity”. Its only mandatory duty, under section 554.102, is conducting training for state agencies and local governments.

Two of the Council’s listed purposes read unusually for an AI statute: evaluating “potential instances of regulatory capture, including undue influence by technology companies or disproportionate burdens on smaller innovators”, and evaluating “the influence of technology companies on other companies” including “tools or processes designed to censor competitors or users”. TRAIGA is partly an antitrust and speech instrument wearing AI clothing.

One caution on names. The Artificial Intelligence Advisory Council whose members the Governor appointed in February 2024 is a different body, created by House Bill 2060 in 2023 to study AI used by state agencies. Guidance that treats those appointments as filling the Chapter 554 Council is wrong.

TRAIGA cannot be amended before the 90th Legislature convenes on 12 January 2027, because no Texas legislative session sat at any point during 2026. The codified text carries no amendment credit.

What a Texas programme should hold anyway

Narrow liability is not the same as no work, and the statute tells you exactly what to keep.

TRAIGA’s seven categories at section 552.103(b) are a specification in disguise. Purpose, intended use and deployment context. Training data types. Input categories. Outputs. Performance metrics. Known limitations. Post-deployment monitoring and the oversight and learning process. An organisation that can produce those seven on request has answered the investigation before it starts, and the same seven satisfy most of Annex IV of the EU AI Act and most of a Colorado developer pack.

Two more records earn their place. Evidence of how a problem was found, because section 552.105(e)(2) turns on discovery rather than compliance. And substantiation for every public claim made about an AI product, because that is what the Deceptive Trade Practices Act actually tests.

Adoption data explains the urgency. The United States Census Bureau reported in May 2026 that 17 to 20 percent of American businesses were using AI, with 20 to 23 percent expecting to adopt within six months. Among firms with 250 or more employees the figure reached 37 percent, in Information 39.7 percent and in Finance and Insurance 33.9 percent. Complaints are most likely to arrive from exactly those sectors.

Where the Texas records live

Two questions decide a TRAIGA outcome: can you answer a demand quickly, and can you prove how you found the problem. Both are records problems before they are legal ones.

Govern365 holds each covered system once in the AI System Registry with its purpose, deployment context, owner and known limitations, which answers four of the seven demand categories before anyone asks. The Audit Evidence Manager attaches red-team findings, testing results and internal review records to the system and the date they were produced, which is what makes the section 552.105(e)(2) discovery defence provable rather than asserted. Governance Workflows carry the 60-day cure process, with notice, remediation, documentation and policy change in one trail, so the written statement to the Attorney General is backed by evidence. Continuous Monitoring keeps performance metrics and post-deployment safeguards current. All four sit in one platform at govern365.ai, and the route from intake to an approved, evidenced system is shown on where these approvals are tracked. Which record answers which obligation across regimes is worked out in the records that prove conformity.

Frequently asked questions

Who does Texas AI law apply to?

Section 551.002 reaches any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. The limbs are disjunctive, and there is no revenue, headcount or volume threshold and no small-business exemption.

Does TRAIGA require businesses to disclose that customers are talking to AI?

Not generally. TRAIGA puts the duty at section 552.051(b) on governmental agencies. The one private-sector duty is subsection (f), requiring health care providers to disclose AI use in service or treatment no later than the date treatment is first provided. The disclosure also runs only to “consumers”, and section 551.001(2) excludes anyone acting in a commercial or employment context, so workplace AI sits outside it.

Is a biased algorithm a violation of TRAIGA?

Not on its own. Section 552.056 requires intent to unlawfully discriminate, and subsection (c) states that disparate impact is not sufficient by itself to demonstrate that intent. Insurance entities and federally insured financial institutions are further carved out. Federal civil rights law still applies on disparate impact.

Can a company be sued under Texas AI law?

No. TRAIGA gives the Attorney General exclusive authority at section 552.101 and states the chapter “does not provide a basis for, and is not subject to, a private right of action for a violation of this chapter or any other law”.

How does a TRAIGA investigation start, and is that the only AI risk in Texas?

A TRAIGA civil investigative demand requires a complaint through the Attorney General’s online mechanism first, under section 552.103(a). Other risk sits outside the statute. In August 2025 the Attorney General opened AI investigations into Meta and Character.AI under general consumer protection law and the SCOPE Act, with no TRAIGA complaint involved.

Does following the NIST framework protect us?

Partly, and not as most summaries describe. TRAIGA protects at section 552.105(e)(2) a defendant who discovers a violation through feedback, testing, agency guidelines, or internal review conducted in substantial compliance with NIST AI 600-1, the Generative AI Profile, or another recognised framework such as ISO/IEC 42001. The defence attaches to the discovery route, so documented red-teaming and review records are what make it usable.

Is the Texas AI regulatory sandbox open?

Not visibly. Chapter 553 directs the Department of Information Resources to prescribe the application form by rule, and no such rule appears in the Texas Register. No participants have been reported. The sandbox waives licensing and registration requirements only, never the Subchapter B prohibitions.

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

us-ai-laws-california-ai-laws

California AI Laws: What Binds You Today, What Is Signed but Dormant, and What Is Still on the Governor’s Desk

Most California AI law coverage collapses three different things into one list: law that binds

Read More →
ai-regulations

Global AI Regulation Tracker: Which Countries Have Binding AI Law in 2026

Five claims about global AI regulation are repeated so widely that they have stopped being

Read More →
ai-evidence

AI Compliance Evidence: The Records That Prove an AI Obligation Was Met

AI compliance evidence is the set of dated, attributable records that show an AI obligation

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.