If your company uses a chatbot to field customer inquiries, an algorithm to screen job applicants, or a software tool that generates recommendations — you are deploying artificial intelligence. And as of January 1, 2026, Texas has a law with teeth that applies to you.
The Texas Responsible AI Governance Act, known as TRAIGA, is now in effect. Signed by Governor Greg Abbott on June 22, 2025, it creates a comprehensive compliance framework for businesses that develop or deploy AI systems in Texas — or whose AI-powered products are used by Texas residents. The penalties for getting it wrong range from $10,000 to $200,000 per violation. This is not a law you want to discover after the fact.
Who Does TRAIGA Apply To?
The scope of TRAIGA is intentionally broad. The law applies to any person or entity that conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas.
Notably, a company does not need to be physically located in Texas to be covered. If you sell software, provide services, or operate a platform that Texas residents interact with — and that platform uses AI — TRAIGA likely reaches you. Both developers of AI systems (the companies that build the tools) and deployers (the businesses that use them) are covered under the statute.
The law defines an “AI system” as “any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations that can influence physical or virtual environments.” That definition is broad enough to encompass most modern enterprise software that incorporates machine learning or predictive analytics — not just the large language models making headlines.
What Does TRAIGA Actually Prohibit?
The law establishes a core set of prohibited uses. No covered business may develop or deploy an AI system with the intent to engage in behavioral manipulation that subverts a person’s decision-making through deceptive or coercive means; discriminate against a protected class under federal or state law (though the statute requires proof of discriminatory intent, not merely disparate impact); create or distribute child sexual abuse material or unlawful deepfakes; or infringe the constitutional rights of Texas residents.
For most businesses deploying standard commercial AI tools — customer service chatbots, analytics platforms, HR screening software — the prohibited-use provisions are less likely to be the central compliance concern. The more immediate challenge is building the governance infrastructure TRAIGA expects you to have in place.
What Compliance Actually Looks Like: A 5-Step Framework
1. Inventory Every AI System You Use
Before you can manage risk under TRAIGA, you need a complete picture of your AI footprint. That means cataloging every AI tool deployed across your organization — hiring platforms, customer-facing chatbots, document review software, predictive analytics tools, recommendation engines, even AI-powered email and scheduling tools. Many businesses are surprised by how many they have. Document the purpose of each system, the data it ingests, and the decisions or outputs it generates. This inventory becomes the foundation for everything else in your compliance program.
2. Establish an AI Governance Function
TRAIGA implicitly rewards companies with organized oversight. Designate an internal owner — whether that is your General Counsel, Chief Compliance Officer, or a cross-functional AI governance committee — who is accountable for monitoring the use of AI systems and ensuring ongoing compliance. This person or team should have visibility into what AI tools are being adopted across business units, not just those approved by IT. Shadow AI adoption — teams deploying their own tools without central review — is one of the most common compliance gaps we see.
3. Document Your Legitimate Business Purpose
For each AI system in your inventory, document the legitimate business reason for its use. This documentation serves two purposes: it focuses your internal team on intentional, purpose-driven deployment, and it creates a contemporaneous record that can be produced to regulators if the Texas Attorney General ever initiates an inquiry. The documentation should reflect that the system is not being deployed for any of TRAIGA’s prohibited purposes and should describe the controls you have in place to prevent prohibited use.
4. Implement Testing and Audit Procedures
TRAIGA creates an affirmative defense for businesses that discover and self-remediate violations through their own testing, internal audits, or third-party reviews. This is the statute’s way of encouraging proactive governance. Practically, that means building red-team testing or adversarial testing protocols into your AI deployment lifecycle, and conducting periodic audits to assess whether your systems are performing as intended. A testing program that catches a problem and documents remediation is a powerful shield against regulatory penalty.
5. Align With the NIST AI Risk Management Framework
TRAIGA’s safe harbor expressly recognizes nationally recognized AI risk management frameworks — and the NIST AI Risk Management Framework (AI RMF) is the primary standard the statute and regulators reference. A company that substantially complies with the NIST AI RMF has a meaningful affirmative defense available if a violation is alleged. If your organization has not already mapped its AI governance practices to a recognized framework, now is the time to do so. This is not merely a best practice under TRAIGA; it is direct statutory protection.
Understanding the Penalty Structure
TRAIGA enforcement is the exclusive province of the Texas Attorney General — there is no private right of action, meaning individual plaintiffs cannot sue your business directly under the statute. That is meaningful protection compared to some other state AI laws, but it does not eliminate regulatory risk. When the AG identifies a violation, the business receives written notice and a 60-day cure period. For violations that can be remediated, civil penalties range from $10,000 to $12,000. If the violation cannot be cured, penalties jump to $80,000–$200,000 per violation. Continuing violations can generate $2,000 to $40,000 per day in additional fines. For businesses with multiple AI systems, the per-violation structure means exposure can compound quickly across a single enforcement action.
A Note for Government Contractors and Public-Facing Platforms
If your company provides AI-powered tools on behalf of Texas government agencies, TRAIGA imposes additional transparency requirements: users must receive clear and conspicuous notice when they are interacting with an automated system rather than a human. Businesses serving Texas public-sector clients should review their contracts and interface disclosures carefully in light of this requirement, and should ensure that any government-facing AI deployments include appropriate disclosure language.
The Strategic Bottom Line
TRAIGA is not the most stringent AI law in the country — Colorado’s AI Act, for example, imposes more granular requirements for high-risk AI systems — but it is in effect in Texas today, and the enforcement mechanism is operational. The businesses most at risk are not necessarily those using the most sophisticated AI. They are the companies that have not thought deliberately about how their AI tools are governed, documented, and tested.
The good news is that TRAIGA structurally rewards organizations that get ahead of the problem. A thorough inventory, a documented governance program, and alignment with the NIST AI RMF put you in a strong defensive position. That work also builds compliance equity that extends beyond Texas: it positions your organization for the next generation of AI regulation at the state and federal level, which is accelerating regardless of the federal political environment.
We advise Texas businesses on AI governance, commercial contracts, and regulatory compliance. If you would like a practical assessment of what TRAIGA requires of your business and a roadmap for building a defensible compliance program, contact us to schedule a consultation.
⚠ REVIEW NEEDED — Attorney Verification Required Before Publishing
- Penalty ranges: Verify current civil penalty figures ($10,000–$12,000 curable / $80,000–$200,000 uncurable / $2,000–$40,000/day continuing) against the enrolled text of HB 149 from the 89th Texas Legislature. These figures are drawn from secondary sources.
- Effective date: Confirm January 1, 2026 is the operative effective date for private-sector deployers and that no agency rulemaking delayed implementation.
- NIST AI RMF safe harbor language: Confirm whether the statute expressly names the NIST AI RMF or refers generically to “nationally recognized AI risk management frameworks” — the post states the latter, which appears accurate but needs verification against the statute text.
- No private right of action: Confirm this is unqualified and that no subsequent implementing rules created hybrid enforcement provisions.
- Developer vs. deployer obligations: Confirm the post accurately characterizes whether TRAIGA creates meaningfully different compliance obligations for AI developers versus deployers. If so, the post should be revised to reflect that distinction for the reader’s benefit.
- Colorado AI Act comparison: Verify the characterization of Colorado’s AI Act as imposing “more granular requirements for high-risk AI” is accurate as of the publication date.
- Texas bar advertising compliance: Review the call-to-action under Texas Disciplinary Rules of Professional Conduct Rule 7.02. The post does not promise outcomes, but the CTA language and overall framing should be reviewed by the responsible attorney before publishing.