Compliance 13 min read

Who TRAIGA Binds: Texas AI Law's Two-Track Test

J

September 16, 2026

Texas's new AI statute reads like one law. It behaves like two.

If you're a private company building or using an AI system in Texas, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA) mostly leaves you alone unless you can be shown to have intended one of four narrow harms. If you're a state agency, TRAIGA doesn't care what you intended. You either disclosed, got consent, and skipped the social scoring, or you didn't.

That split is the whole architecture of the law, and in my view it's the reason TRAIGA has become the model other states are now copying instead of Colorado's. I want to walk through exactly who owes what, because "TRAIGA compliance" means something completely different depending on which side of that line you're standing on.

TRAIGA in one paragraph

House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, was signed by Governor Abbott on June 22, 2025, and took effect January 1, 2026. It's codified in Chapters 551 through 554 of the Texas Business and Commerce Code, and it also reaches into Chapter 503 (the state's biometric-identifier statute) and Chapter 541 (the Texas Data Privacy and Security Act) to fold AI processing into existing consumer-protection law. Chapter 551 defines terms and sets scope. Chapter 552 carries the actual prohibitions and the enforcement machinery. Chapter 553 sets up a regulatory sandbox. Chapter 554 creates the Texas Artificial Intelligence Council. Everything that matters for compliance purposes lives in Chapter 552, and Chapter 552 is where the two tracks separate.

The bill that finally passed is sometimes called TRAIGA 2.0, because the version originally filed looked much more like Colorado's AI Act: duty-of-care language, disparate-impact liability, algorithmic impact assessments for "high-risk" systems. The Legislature stripped almost all of that out before passage. What survived is narrower, and it's worth understanding why, because the narrowing is exactly what created the two-track structure this article is about.

Private developers, distributors, and deployers: the intent wall

If you build AI systems, sell them, or put them to use in your business, Chapter 551 calls you a developer, a distributor, or a deployer, and Chapter 552 imposes exactly four prohibitions on you. Not four categories of risk to manage. Four specific things you're barred from intending.

Self-harm, violence, or crime. Section 552.052 prohibits developing or deploying an AI system that intentionally aims to incite or encourage a person to commit physical self-harm, including suicide, to harm another person, or to engage in criminal activity.

Constitutional infringement. Section 552.055 prohibits developing or deploying a system with the sole intent of infringing, restricting, or otherwise impairing an individual's rights under the U.S. Constitution.

Unlawful discrimination. Section 552.056 prohibits developing or deploying a system with the intent to unlawfully discriminate against a protected class in violation of state or federal law.

Child exploitation material. Section 552.057 prohibits developing or distributing a system with the sole intent of producing child sexual abuse material or unlawful deepfakes, and separately prohibits systems intentionally built to simulate sexual conversation while impersonating a child.

Notice what's missing from that list. There's no duty to conduct an algorithmic impact assessment before deploying a hiring tool. No duty of reasonable care to avoid algorithmic discrimination. No requirement to document risk mitigation for a "high-risk" AI system, because TRAIGA never defines a "high-risk" category the way Colorado's original act did. The statute doesn't ask whether your system produced a discriminatory outcome. It asks whether you built or ran it for the purpose of producing one.

That's the wall, and it's a high one to climb for a plaintiff or the Attorney General. Section 552.056 requires proof of discriminatory intent, and the statute says plainly that disparate impact alone does not establish it. A hiring algorithm that screens out applicants over 40 at a disproportionate rate is a problem for Title VII and the ADEA, litigated the way employment discrimination has always been litigated. It is not, by itself, a TRAIGA violation, because TRAIGA was never written to police outcomes. It was written to police purpose.

I'd put the practical upshot bluntly: most companies using off-the-shelf AI tools in ordinary ways are not TRAIGA's target. The statute is aimed at the handful of systems built to do one of those four things on purpose. If your compliance program never asks why a system was built or deployed, though, you can't prove you're clear of the wall when someone asks.

Governmental entities: duties that don't wait for intent

Chapter 552 also contains a second set of rules, and these ones use different language on purpose. They don't say "a person." They say "a governmental entity" or "a governmental agency," and they don't require anyone to prove what the agency meant to do.

Only three duties in TRAIGA run to governmental entities by name: the AI-interaction disclosure in Section 552.051, the ban on government social scoring in Section 552.053, and the biometric-identification consent requirement in Section 552.054. All three are strict — met or not met, with no intent element to argue about.

Disclosure. Section 552.051 requires a governmental agency that makes an AI system available to interact with a consumer to disclose, before or at the time of that interaction, that the consumer is interacting with an AI system. Section 552.051(d) specifies the disclosure has to be clear and conspicuous and written in plain language. A state agency chatbot that quietly answers questions without ever saying "I'm an AI assistant" is non-compliant the moment a consumer engages it, full stop. Nobody has to show the agency meant to deceive anyone.

No social scoring. Section 552.053 bars a governmental entity from deploying an AI system that evaluates or classifies people based on social behavior or personal characteristics and assigns a social score or similar categorical estimation resulting in detrimental or unfavorable treatment. This is the closest thing in American state law to the EU AI Act's social-scoring ban, and Texas put it on government only. A private company can build a "trust score" product; a state agency using one to determine benefit eligibility on that basis runs straight into 552.053.

Biometric consent. Section 552.054(b) prohibits a governmental entity from developing or deploying a system for the purpose of uniquely identifying a specific individual using biometric data without that individual's consent. Pair this with the Chapter 503 amendments and Texas has built a fairly tight biometric perimeter specifically around government use of AI-driven identification, tighter than what it demands of private industry doing the same thing.

The design logic here isn't subtle once you see it. Private actors get the benefit of the doubt because the Legislature decided the market and existing sectoral law (employment, credit, health) would catch most of the bad outcomes; state agencies get no benefit of the doubt because the citizen dealing with a government AI system usually has no alternative vendor to walk to. You can't shop around for a different DMV.

Who owes what, at a glance

Obligation Who it binds Trigger Statute
No AI built/deployed to incite self-harm, harm to others, or crime Developer, distributor, deployer Intent Sec. 552.052
No AI built/deployed with sole intent to infringe constitutional rights Developer, distributor, deployer Intent Sec. 552.055
No AI built/deployed with intent to unlawfully discriminate Developer, distributor, deployer Intent (disparate impact alone insufficient) Sec. 552.056
No AI built/distributed to produce CSAM or unlawful deepfakes Developer, distributor Intent Sec. 552.057
Disclose AI interaction before or during use Governmental agency Strict — no intent element Sec. 552.051
No social scoring resulting in detrimental treatment Governmental entity Strict — no intent element Sec. 552.053
No biometric identification without consent Governmental entity Strict — no intent element Sec. 552.054

Read the right-hand column and the pattern holds every time: intent is the trigger for private parties, and its absence is exactly what makes the government column strict.

Why Texas built it this way, and why Colorado's bet just collapsed

Texas didn't narrow TRAIGA in a vacuum. Colorado had already tried the other approach, and by the time Texas's substitute bill passed, Colorado's was already coming apart.

Colorado's SB 24-205 built its AI Act around a duty of care to avoid "algorithmic discrimination," backed by mandatory impact assessments and disclosure obligations for developers and deployers of "high-risk" systems, closer to the EU AI Act's risk-tiered model. It was originally set to take effect February 1, 2026. Colorado's own Legislature delayed it once, to June 30, 2026, after a special session failed to produce agreed amendments. Then, on April 27, 2026, a federal magistrate judge in the District of Colorado blocked the state from enforcing SB 205 after xAI sued on constitutional grounds and the Department of Justice intervened on xAI's side. Three weeks later, on May 14, 2026, Governor Polis signed SB 189, which stripped out the duty of care, the impact assessments, and most of the deployer risk-management obligations, and pushed the effective date again, to January 1, 2027. What's left of Colorado's law now looks a lot more like disclosure-and-transparency rules than the comprehensive risk-management regime it started as.

I don't think that's a coincidence, and I don't think it's just litigation risk. It's a design lesson. A statute that asks a court to referee "was the outcome discriminatory" invites exactly the kind of open-ended liability that draws a constitutional challenge and scares a legislature into rewriting its own law twice in one year. A statute that asks "did you intend this narrow, named harm" gives a regulator a much smaller, much more defensible thing to prove. Texas bet on the narrower question. So far, that's the bet that's still standing.

Enforcement: the Attorney General, the clock, and the bill

TRAIGA is not privately enforceable. There is no cause of action for an individual consumer to bring against a developer, distributor, or deployer, or against a governmental entity, for a Chapter 552 violation. The Texas Attorney General holds exclusive enforcement authority under Section 552.101, and Section 552.104 requires 60 days' written notice and a chance to cure before any penalty attaches. If you fix the problem and document the fix inside that window, the Attorney General cannot collect a penalty for it.

If the violation goes uncured, or can't be cured, the numbers in Section 552.105 are the ones that matter:

Violation type Penalty range
Curable, cured within the notice period No penalty
Curable, not cured $10,000–$12,000 per violation
Uncurable $80,000–$200,000 per violation
Continuing violation $2,000–$40,000 per day

That 60-day cure window is, in practical terms, the most useful compliance asset TRAIGA hands you. It means the highest-value thing a private company can do isn't a defensive legal memo arguing why its AI system doesn't fall under Section 552.056. It's a documented process for responding to a notice fast enough to cure it before day 60. For a governmental agency, where the disclosure and biometric-consent duties are strict, cure usually just means turning the disclosure on, which is why those violations tend to be more embarrassing than expensive.

The sandbox and the council

Chapter 553 sets up an AI regulatory sandbox administered through the Texas Department of Information Resources, letting a participant test a system for up to 36 months under a supervised waiver of some regulatory requirements. It does not waive the Chapter 552 prohibitions themselves; the intent-based bans and the government duties apply inside the sandbox exactly as they do outside it. Chapter 554 creates the Texas Artificial Intelligence Council, seven members appointed by the governor, the lieutenant governor, and the House speaker, tasked with studying AI use and issuing recommendations. The Council doesn't have binding rulemaking authority. It's an advisory body, and right now it's the most likely source of interpretive guidance on where the intent line actually falls in practice, since the statute itself doesn't spell out how the Attorney General will prove intent in a contested case.

What this means for your compliance program

For a private developer, distributor, or deployer, the compliance question TRAIGA actually asks is narrower than most AI governance vendors will tell you. You don't need a Colorado-style impact assessment for every model. You need to be able to show, if the Attorney General ever asks, that nothing in your development or deployment process was built or run for one of those four prohibited purposes. That's a documentation problem, not a testing problem: design records, use-case approval, and a paper trail showing your system's purpose from the intake stage forward. A structured AI management system built against a real standard, rather than an internal policy nobody follows, is the cleanest way I've seen to generate that trail without slowing product work down. That's the conversation we have with clients building out an ISO 42001 AI management system, and it usually starts with a gap assessment against where the documentation already stands.

For a state agency, or a vendor building AI tools for one, the job is simpler to describe and less forgiving to get wrong. Turn the disclosure on, get consent before biometric identification, and make sure nothing in your scoring model resembles a social score. There's no cure for "we didn't mean to." The statute doesn't ask.

FAQ

Does TRAIGA apply to a business that just uses an off-the-shelf AI tool? Yes, using an AI system in your business makes you a "deployer" under Chapter 551, but the four prohibitions in Chapter 552 only reach you if you deployed the tool with the intent to cause one of the four named harms. Ordinary use of a mainstream AI product for its intended purpose isn't what the statute targets.

Do I have to prove I didn't intend discrimination, or does the state have to prove I did? The Attorney General has to prove intent under Section 552.056. The statute specifically states that a disparate impact alone doesn't establish the discriminatory intent required for a violation, which is a meaningfully different standard than Colorado's original duty-of-care approach.

Do state agencies have to disclose every AI chatbot to citizens? Yes. Section 552.051 requires a governmental agency to disclose, clearly and in plain language, before or at the time of interaction, that a consumer is interacting with an AI system. There's no intent element and no minimum-use threshold in the statute.

What happens during TRAIGA's 60-day cure period? After the Attorney General provides written notice of a violation under Section 552.104, the recipient has 60 days to cure the violation and document the cure. If cured in that window, no civil penalty attaches for that violation.

Can a consumer sue a company directly under TRAIGA? No. Section 552.101(b) creates no private right of action. Enforcement runs exclusively through the Texas Attorney General.

Last updated: 2026-09-16

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.