Skip to main content

What TRAIGA Actually Requires (and What It Doesn't)

Most vendors and blog posts overstate TRAIGA. Here is what HB 149's enacted text actually says, section by section — the obligations it imposes, the mandates it does not, and the safe harbor it rewards.

Jan 1, 2026
in force
$200K
max penalty per uncurable violation
1
private-sector disclosure duty (§ 552.051(f), healthcare)
1
named safe harbor: NIST AI RMF

What TRAIGA Does NOT Require of Private Companies

The enacted text of HB 149 imposes no inventory, assessment, training, or reporting mandates on private deployers — and exactly one disclosure duty, limited to health care providers (§ 552.051(f)). Yet each of the following myths keeps circulating. Here is what Chapter 552 actually says.

  • Myth: TRAIGA requires an AI inventory.Reality: HB 149 contains no inventory mandate for private companies. SB 1964 does mandate one — but only for Texas governmental entities. A maintained AI register is still prime evidence of substantial compliance with the NIST AI RMF, the § 552.105(e) safe harbor.
  • Myth: TRAIGA requires algorithmic impact assessments.Reality: The enacted text contains no impact-assessment requirement for private deployers. A documented assessment program is voluntary — and useful safe-harbor evidence — but it is not a mandate.
  • Myth: TRAIGA has 72-hour incident reporting.Reality: HB 149 contains no incident-reporting duty at all — not 72 hours, not annual, none.
  • Myth: Private deployers must disclose AI interaction to consumers.Reality: The § 552.051 disclosure duty binds government agencies (a definition that excludes hospital districts and institutions of higher education). 'Consumer' means a Texas resident acting in an individual or household context — employment and commercial uses are out of scope. The one true private-sector exception: a provider of health care services or treatment who uses AI in relation to that care must disclose it to the patient no later than the first service (§ 552.051(f); emergencies: as soon as reasonably possible).
  • Myth: TRAIGA requires annual audits or registration fees.Reality: There is no audit mandate, no registration, and no fee anywhere in Chapter 552.

What TRAIGA Actually Does

TRAIGA takes an intent-based, prohibited-use approach rather than a paperwork approach. Its operative provisions are:

  • Prohibited Uses (§§ 552.052–.057)AI that incites or encourages self-harm, crime, or violence (§ 552.052); governmental social scoring (§ 552.053); governmental biometric identification without consent (§ 552.054); AI developed or deployed with the sole intent to infringe constitutional rights (§ 552.055); AI developed or deployed with intent to unlawfully discriminate against a protected class (§ 552.056); and sexually explicit content and CSAM, including deep fakes (§ 552.057).
  • Intent Standardthe discrimination prohibition turns on intent, and § 552.056(c) states expressly that disparate impact alone is not sufficient to show intent. Regulated insurance entities are carved out (§ 552.056(d)), and federally insured financial institutions complying with banking laws are deemed compliant (§ 552.056(e)).
  • Disclosure Duties (§ 552.051)government agencies (excluding hospital districts and higher education) must disclose AI interaction to consumers: clear and conspicuous, plain language, no dark patterns, hyperlink permitted (§ 552.051(b)–(e)). Health care providers using AI in relation to a service or treatment must give the same disclosure to the patient by the first service; in an emergency, as soon as reasonably possible (§ 552.051(f)).
  • Enforcementthe Texas Attorney General has exclusive enforcement authority; there is no private right of action. The AG must give 60 days' notice and an opportunity to cure. Penalties: $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for ongoing violations. State licensing agencies may add sanctions up to $100,000 after a finding and AG recommendation (§ 552.106).
  • Safe Harbors and Protections (§ 552.105)a rebuttable presumption of reasonable care (§ 552.105(c)); no civil penalties for systems that have not been deployed (§ 552.105(f)); and defenses where a violation stems from third-party misuse, was discovered through your own testing or a good-faith audit, or where you show substantial compliance with the most recent NIST AI RMF Generative AI Profile or another nationally or internationally recognized AI risk framework (§ 552.105(e)).
  • Supporting InstitutionsHB 149 also creates a 36-month regulatory sandbox program (Chapter 553; note the Subchapter B prohibitions and disclosure duties are never waived, § 553.051(e)) and the Texas AI Council (Chapter 554). The Attorney General must stand up an online complaint mechanism by September 1, 2026 (§ 552.102).

So What Should a Texas Company Actually Do?

Because TRAIGA imposes no paperwork mandates on private companies, the rational strategy is a defensible posture: avoid the prohibited uses, and build the evidence that wins the safe harbor if a use is ever questioned.

Risk Meridian generates each element of that posture:

  • Prohibited-use screeningevery AI system is screened against the §§ 552.052–.057 categories, with documented results.
  • Intent documentationrecorded purpose, design decisions, and deployment rationale that speak to the § 552.056 intent standard.
  • NIST AI RMF alignment with evidencea substantial-compliance evidence pack mapped to the Govern, Map, Measure, and Manage functions for the § 552.105(e) safe harbor.
  • Incident and cure readinessa structured incident log and remediation workflow tuned to the 60-day notice-and-cure window, so a cure is documented and demonstrable.

Frequently asked questions

Does TRAIGA apply to my employment AI?

TRAIGA's prohibited-use provisions apply to developers and deployers generally, but its disclosure duties do not reach employment AI: § 552.051(b) binds government agencies and § 552.051(f) binds health care providers, and 'consumer' means a Texas resident acting in an individual or household context — employment and commercial uses are out of scope. Private employment AI faces the intent-based prohibitions, not disclosure or assessment mandates.

Do hospital districts follow TRAIGA's government rules?

No. Hospital districts are excluded from TRAIGA's government-agency definition, so the § 552.051 consumer-disclosure duty does not attach. They remain covered persons for the person-level prohibitions (§§ 552.052–.057), and SB 1964 — which does include hospital districts — is their governmental AI framework.

Is disparate impact enough for TRAIGA liability?

No. § 552.056 prohibits AI developed or deployed with intent to unlawfully discriminate against a protected class, and § 552.056(c) states that disparate impact alone is not sufficient to show intent.

What is the fastest path to a TRAIGA safe harbor?

Documented substantial compliance with the NIST AI RMF (§ 552.105(e)). The other recognized defenses — third-party misuse and discovery through your own testing or good-faith audits — also depend on documentation you build before any AG inquiry.

Can I be sued privately under TRAIGA?

No. Enforcement is exclusive to the Texas Attorney General; there is no private right of action. The AG must give 60 days' notice and an opportunity to cure before enforcement.

Start your AI governance program today

Risk Meridian is the fastest path to an audit-ready AI governance program — inventory, risk reviews, controls, disclosures, and board-ready reports in one place.

✓ No credit card ✓ Full platform access ✓ Cancel anytime

This platform provides tools to assist organizations in implementing AI governance programs aligned with the Texas Responsible AI Governance Act (TRAIGA). Use of the platform does not constitute legal advice or guarantee regulatory compliance. © 2026 Risk Meridian.