Skip to main content

TRAIGA Compliance: The Complete Guide

The Texas Responsible AI Governance Act prohibits specific AI uses, gives the Texas Attorney General exclusive enforcement with penalties up to $200K per uncurable violation, and recognizes substantial compliance with the NIST AI RMF as a safe-harbor defense. Here is everything you need to comply.

Jan 1, 2026
TRAIGA effective date
Chapter 552
prohibited uses + safe harbors
2 roles
developer, deployer
Auto
disclosures generated by TRAIGA

What Is TRAIGA?

The Texas Responsible AI Governance Act (TRAIGA, HB 149) is Texas state legislation, effective January 1, 2026, that prohibits specific harmful uses of artificial intelligence, requires government agencies to disclose AI interaction to consumers, and gives the Texas Attorney General exclusive enforcement authority — with no private right of action.

Unlike the Colorado Artificial Intelligence Act, TRAIGA imposes no inventory, assessment, training, or incident-reporting mandates on private deployers, and exactly one private-sector disclosure duty: providers of health care services or treatment who use AI in relation to that care must disclose it to the patient (§ 552.051(f)). It otherwise takes an intent-based, prohibited-use approach — and rewards documented governance through a safe harbor for substantial compliance with the NIST AI RMF or a similar recognized framework (§ 552.105(e)).

Who Does TRAIGA Apply To?

TRAIGA distinguishes between two roles, plus a separate disclosure duty for government agencies:

  • Developersorganizations that develop AI systems offered, sold, leased, or provided in Texas. Developers are subject to the prohibited-use provisions of Chapter 552.
  • Deployersorganizations that put AI systems into service in Texas. Deployers are subject to the same prohibited-use provisions, with an intent standard for the discrimination prohibition (§ 552.056).
  • Government Agenciesadditionally required by § 552.051 to disclose to consumers that they are interacting with AI. The statutory definition excludes hospital districts and institutions of higher education. The duty does not extend to private deployers generally — with one exception: any provider of health care services or treatment who uses AI in relation to that care must give the disclosure to the patient or their personal representative (§ 552.051(f)).

Key TRAIGA Provisions

TRAIGA imposes no inventory, assessment, or reporting mandates on private deployers. Its core provisions are:

  • Prohibited Uses (§§ 552.052–.057)AI intended to manipulate or incite self-harm, criminal activity, or violence (§ 552.052); government social scoring (§ 552.053); government biometric identification without consent (§ 552.054); infringement of constitutional rights (§ 552.055); intentional unlawful discrimination against a protected class (§ 552.056) — disparate impact alone is not sufficient to show intent (§ 552.056(c)); and explicit deep fakes and CSAM (§ 552.057).
  • Government-Agency Consumer Disclosure (§ 552.051)government agencies must disclose to consumers, clearly and conspicuously in plain language (no dark patterns; a hyperlink is permitted), that they are interacting with AI. This duty does NOT apply to private deployers generally, hospital districts, institutions of higher education, or employment and commercial contexts. EXCEPTION (§ 552.051(f)): any provider of health care services or treatment who uses AI in relation to that care must give the disclosure to the recipient or their personal representative no later than the date the service is first provided — or, in an emergency, as soon as reasonably possible.
  • NIST AI RMF Safe Harbor (§ 552.105(e))an affirmative defense against liability where a violation stems from third-party misuse, was discovered through your own testing or a good-faith audit, or where you can show substantial compliance with the most recent NIST ‘AI Risk Management Framework: Generative Artificial Intelligence Profile’ — or another nationally or internationally recognized AI risk framework (NIST AI RMF 1.0 qualifies under that clause). Documented governance is your defense posture.
  • 60-Day Notice-and-Cure (§ 552.104)the Texas Attorney General (the exclusive enforcer; there is no private right of action) must give 60 days' notice before enforcement. Curing requires fixing the violation, documenting the fix, and updating internal policies. Penalties: $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable violations, and $2,000–$40,000 per day for ongoing violations.
  • Litigation Posture (§ 552.105(c), (f))there is a rebuttable presumption that a person used reasonable care, and the Attorney General may not seek civil penalties for an AI system that has not been deployed — pre-deployment testing is penalty-free.
  • Safe-Harbor-Supporting Best Practices (not TRAIGA mandates)a documented AI governance program, employee AI training, and vendor due diligence are not required by TRAIGA, but they build the substantial-compliance evidence the § 552.105(e) safe harbor rewards.

How TRAIGA the Platform Automates TRAIGA Compliance

TRAIGA was designed from the ground up around TRAIGA's real Chapter 552 provisions. Every feature maps to a prohibited-use risk, a safe-harbor factor, or cure readiness — reducing the time from 'zero to defensible' from months of manual work to days.

The platform screens every AI system against the §§ 552.052–.057 prohibited-use categories, assembles a NIST AI RMF safe-harbor evidence pack, documents intent and design decisions for the § 552.056 discrimination standard, runs an incident-and-cure workflow tuned to the 60-day notice-and-cure window, and produces audit-ready governance documentation.

Frequently asked questions

When does TRAIGA go into effect?

TRAIGA (HB 149) takes effect on January 1, 2026. Its substantive provisions — prohibited uses, government-agency disclosure, safe harbors, and Attorney General enforcement — are codified in Chapter 552.

What is a 'consequential decision' under TRAIGA?

Early drafts of TRAIGA followed the Colorado model of regulating 'consequential decisions,' but the enacted law does not impose obligations on private deployers based on consequential decisions. Instead, it prohibits specific AI uses (§§ 552.052–.057) under an intent standard and provides safe harbors that reward documented governance.

What disclosures does TRAIGA require?

Two disclosures. Government agencies must disclose to consumers that they are interacting with AI (§ 552.051(b)) — clearly, conspicuously, in plain language, no dark patterns, hyperlink permitted. And any provider of health care services or treatment who uses AI in relation to that care must give the same disclosure to the patient or their personal representative no later than the first service (§ 552.051(f); emergencies: as soon as reasonably possible). Beyond those, private deployers have no TRAIGA disclosure mandate, and employment and commercial uses are out of scope of the consumer duty.

What is an algorithmic impact assessment under TRAIGA?

TRAIGA does not mandate algorithmic impact assessments. An AIA is a structured analysis of an AI system's potential for disparate impact, its data inputs, accuracy, and mitigation measures — and a documented AIA program is strong evidence of substantial compliance with the NIST AI RMF, which TRAIGA recognizes as a safe harbor (§ 552.105(e)).

Does TRAIGA apply to AI systems from third-party vendors?

TRAIGA's prohibited-use provisions apply to developers and deployers of AI systems used in Texas, including procured systems. Notably, § 552.105(e) provides a safe harbor where a violation results from third-party misuse of your system — and documented vendor due diligence strengthens that defense.

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.