Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
US-TXDEEP coverage

Texas Responsible AI Governance Act (TRAIGA / HB 149): AI Compliance Requirements

Texas HB 149 (TRAIGA), signed June 22, 2025 and codified as Tex. Bus. & Com. Code Title 11, Subtitle D (ch. 551–552, with a ch. 553 regulatory sandbox and a ch. 554 Texas AI Council), prohibits specific harmful AI practices and imposes disclosure obligations. The Act focuses on intent-based liability. Subchapter B contains exactly seven prohibition/disclosure sections (§§ 552.051–552.057, verified against the enrolled text — there is no § 552.058): consumer and health-care AI disclosure (§ 552.051), manipulation of human behaviour (§ 552.052), government social scoring (§ 552.053), government capture of biometric data or untargeted scraping of images (§ 552.054), sole-intent infringement of federal constitutional rights (§ 552.055 — binding on any person), unlawful discrimination against a protected class (§ 552.056), and certain sexually explicit content and child pornography (§ 552.057). Healthcare providers must disclose AI use to patients. Government entities must disclose AI-driven interactions.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2026

Maximum Penalty

$10,000–$12,000 per curable violation; $80,000–$200,000 per violation a court determines uncurable; $2,000–$40,000 per day for continuing violations (Tex. Bus. & Com. Code § 552.105(a)); state licensing agencies may add license suspension/probation/revocation or up to $100,000 on AG recommendation (§ 552.106). TX AG exclusive enforcement, no private right of action (§ 552.101), mandatory 60-day cure (§ 552.104)

What Your Business Must Do

7 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Prohibited AI Practices Compliance

Critical

Ensure no AI system you develop or deploy is intentionally designed to: incite or encourage a person to commit physical self-harm (including suicide), to harm another, or to engage in criminal activity (§ 552.052 reaches a system that "intentionally aims to incite or encourage" those acts); infringe, restrict, or otherwise impair an individual's rights guaranteed under the United States Constitution where that is the system's SOLE intent (§ 552.055(a); § 552.055(b) makes the section remedial only and creates or expands no constitutional right); UNLAWFULLY discriminate against a protected class (§ 552.056(b) requires INTENT to unlawfully discriminate in violation of state or federal law, and § 552.056(c) states that "a disparate impact is not sufficient by itself to demonstrate an intent to discriminate"; "protected class" is defined at § 552.056(a)(3) and includes race, color, national origin, sex, age, religion, or disability); produce visual material in violation of Penal Code § 43.26 or deep fake videos or images in violation of Penal Code § 21.165 — where that is the system's sole intent — or intentionally develop or distribute a system that engages in text-based conversations simulating or describing sexual conduct while impersonating or imitating a child younger than 18 (§ 552.057). GOVERNMENTAL ENTITIES ONLY: assigning social scores based on social behavior or personal characteristics that cause detrimental treatment, disproportionate consequences, or infringement of constitutional rights (§ 552.053), and developing or deploying an AI system to uniquely identify a specific individual using biometric data, or to gather images or other media from the Internet or any other publicly available source (targeted or untargeted) without consent, where the gathering would infringe a right under the U.S. Constitution, the Texas Constitution, or state or federal law (§ 552.054(b)) — and § 552.054(c) provides that "a violation of Section 503.001 is a violation of this section."

Deadline: January 1, 2026

Tex. Bus. & Com. Code §§ 552.052, 552.053, 552.054, 552.055, 552.056, 552.057

Healthcare AI Patient Disclosure

High Priority

Health care providers using AI in a patient's diagnosis or treatment must disclose that use to the patient (or the patient's personal representative) no later than the date the service or treatment is first provided — except in an emergency, where the disclosure must be made as soon as reasonably possible (§ 552.051(f)). The disclosure must be clear and conspicuous, written in plain language, and must not use a dark pattern (§ 552.051(d)); it may be provided by hyperlink (§ 552.051(e)).

Deadline: January 1, 2026

Tex. Bus. & Com. Code § 552.051(d), (f)

Government Consumer AI Disclosure

High Priority

Governmental agencies that make available an AI system intended to interact with consumers must disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an AI system (§ 552.051(b)) — regardless of whether it would be obvious to a reasonable consumer (§ 552.051(c)). The disclosure must be clear and conspicuous, in plain language, and free of dark patterns (§ 552.051(d)).

Deadline: January 1, 2026

Tex. Bus. & Com. Code § 552.051(b)–(d)

CUBI Biometric Safe Harbor for AI Training — Conditions, Snap-Back & Consent

High Priority

TRAIGA (HB 149) also amended the Texas Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code §503.001), effective January 1, 2026. New §503.001(e)(2) exempts the training, processing, or storage of biometric identifiers involved in developing, training, evaluating, disseminating, or otherwise offering an AI model or system from CUBI's notice-and-consent and retention requirements — UNLESS the AI system is used or deployed for the purpose of uniquely identifying a specific individual, which revives full CUBI coverage. A parallel exemption (§503.001(e)(3)) covers developing or deploying an AI system to prevent, detect, protect against, or respond to a security incident, identity theft, fraud, harassment, malicious or deceptive activity, or other illegal activity. SNAP-BACK: if a biometric identifier captured under the AI-training exemption is later used for a commercial purpose, the possessor becomes subject to CUBI's existing possession-and-destruction duties and civil penalties (enforced exclusively by the Texas Attorney General; no private right of action). CONSENT CLARIFICATION: an individual is not deemed to have consented to the capture or storage of their biometric identifiers merely because an image or other media containing them is on the internet or otherwise publicly available, unless that individual themselves made it publicly available. Action: if you train or operate AI on biometric data (faces, voice, fingerprints) touching Texans, document whether each system is within the (e)(2)/(e)(3) exemptions or is used for unique identification, and apply CUBI possession/destruction controls to any biometric data repurposed for a commercial use.

Deadline: January 1, 2026

Tex. Bus. & Com. Code § 503.001(a), (b), (b-1), (c)–(c-2), (d), (e)(2)–(3), (f), as amended by HB 149 § 2

AI Governance Policy

Medium Priority

Document your AI governance practices demonstrating that deployed AI systems comply with TRAIGA prohibitions, and maintain an internal review process. This is not a free-standing statutory mandate — its value is the statutory SAFE HARBOR: a defendant is not liable if it discovers a violation through feedback, adversarial/red-team testing, following applicable state-agency guidelines, or — where it substantially complies with the most recent NIST "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" or another nationally/internationally recognized AI risk framework — an internal review process (§ 552.105(e)(2)). A separate limb of the same subsection bars liability where ANOTHER person uses the AI system affiliated with the defendant in a manner prohibited by the chapter (§ 552.105(e)(1)) — so contractual and technical controls over downstream use are themselves safe-harbor evidence. A defendant who believes in good faith it has not violated the chapter may also seek an expedited hearing or declaratory judgment (§ 552.105(d)). Keep the framework mapping and review records as safe-harbor evidence.

Tex. Bus. & Com. Code § 552.105(e)

TRAIGA Cure Period Readiness

Medium Priority

TRAIGA gives every alleged violator written AG notice and a 60-day cure window before any enforcement action (§ 552.104). To stop the action, within the 60 days you must BOTH cure the identified violation AND provide the AG a written statement that you cured it, with supporting documentation showing how, plus any internal-policy changes made to reasonably prevent recurrence (§ 552.104(b)). Establish that response workflow now: a designated owner, a documented complaint-response process, and evidence of AI system review. Note the statute does not pre-classify violations as curable or uncurable — a court makes that determination at the penalty stage (§ 552.105(a)).

Tex. Bus. & Com. Code §§ 552.104–552.106

AI Documentation Package for an AG Civil Investigative Demand

Medium Priority

TRAIGA gives the Texas Attorney General a civil investigative demand (CID) power that fires on a consumer complaint: if the AG receives a complaint through the online mechanism it must maintain under § 552.102, it may issue a CID to determine whether a violation has occurred (§ 552.103(a)). § 552.103(b) names exactly what the AG may request, and it is the practical documentation spec for any AI system touching Texans: (1) a high-level description of the purpose, intended use, deployment context, and associated benefits; (2) a description of the type of data used to program or train the system; (3) a high-level description of the categories of data processed as inputs; (4) a high-level description of the outputs produced; (5) any metrics used to evaluate performance; (6) any known limitations of the system; (7) a high-level description of post-deployment monitoring and user safeguards; and (8) any other relevant documentation reasonably necessary. Assemble and version these eight items per AI system now — the CID arrives on a complaint, and § 552.104's 60-day cure clock is a separate, later step that does not buy time to author them.

Deadline: January 1, 2026

Tex. Bus. & Com. Code §§ 552.102, 552.103(a)–(b)

Who Does This Apply To?

Applies to any person or entity that: (1) develops an AI system intended to interact with or make decisions about Texas residents; OR (2) deploys an AI system in Texas or to serve Texas residents. Unlike Colorado SB23-169, TRAIGA does not include a minimum consumer threshold — it applies regardless of company size. Scope is intent-based: prohibitions only apply to AI systems "intentionally designed" to cause harm, and for the discrimination prohibition specifically the enacted Act requires INTENT to UNLAWFULLY discriminate against a protected class — a disparate impact alone is statutorily insufficient to establish that intent. No affirmative duty to conduct impact assessments (unlike Colorado) — TRAIGA is primarily a prohibited-practices and disclosure law. Healthcare and government entities have additional sector-specific disclosure obligations. Separately, HB 149 also amended the Texas biometric statute (CUBI, Tex. Bus. & Com. Code §503.001) — adding an AI-training/processing/storage exemption (lost if the system is used to uniquely identify a specific individual), a security/fraud-response exemption, a snap-back to CUBI possession/destruction duties and penalties when training biometrics are later used commercially, and a clarification that an image being publicly available online is not consent unless the individual made it public.

Recent Regulatory Guidance

opinion2025-06-22

Governor Abbott Signing Statement — TRAIGA

Governor Greg Abbott signed HB 149 on June 22, 2025, with a statement emphasizing that TRAIGA is intentionally narrower than European AI regulation and Colorado SB23-169: it focuses on "bad actors" (AI designed to cause harm) rather than imposing blanket impact assessment requirements on all AI developers. Signing statement indicated the TX AG will prioritize enforcement of the CSAM, manipulation, and discrimination prohibitions, not disclosure technicalities.

Source

Quarterly Enforcement Digest

Q2 2026: TRAIGA took effect January 1, 2026. As of mid-2026 the Texas AG has published NO formal TRAIGA guidance and filed NO TRAIGA enforcement action. The AG's office appears to have already stood up a "Consumer AI Rights" complaint page in practice (CYCLE 23, 2026-08-23 — see the deadlineCalendar entry for sourcing/caveats), well ahead of the September 1, 2026 statutory deadline for that mechanism to be operational; no filed enforcement action has resulted from it as of this cycle either way. (Separately and pre-TRAIGA: AG Paxton opened a December 2024 investigation into Character.AI and Meta AI under the SCOPE Act, the Texas Data Privacy and Security Act, and the DTPA over minors' privacy and allegedly deceptive marketing of chatbots as mental-health tools — that matter is NOT a TRAIGA action, and TRAIGA was not yet in force.) Healthcare AI disclosure is the broadest practical obligation for most businesses: any SaaS platform used by Texas healthcare providers for clinical AI must ensure patient disclosure. Unlike Colorado SB23-169, TRAIGA has NO impact assessment or risk documentation requirement — a pure disclosure + prohibition law, and a disparate impact alone is statutorily insufficient to show the intent its discrimination prohibition requires. Businesses operating in both TX and CO should note: Colorado requires proactive impact assessments while Texas only prohibits intentional harm.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-25.

Industry Playbooks covering Texas Responsible AI Governance Act (TRAIGA / HB 149)

These industry playbooks include jurisdiction-specific checklist items and guidance for Texas Responsible AI Governance Act (TRAIGA / HB 149).

Frequently Asked Questions

Does Texas Responsible AI Governance Act (TRAIGA / HB 149) apply to my business?

Texas HB 149 (TRAIGA), signed June 22, 2025 and codified as Tex. Bus. & Com. Code Title 11, Subtitle D (ch. 551–552, with a ch. 553 regulatory sandbox and a ch. 554 Texas AI Council), prohibits specific harmful AI practices and imposes disclosure… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Texas Responsible AI Governance Act (TRAIGA / HB 149) is: $10,000–$12,000 per curable violation; $80,000–$200,000 per violation a court determines uncurable; $2,000–$40,000 per day for continuing violations (Tex. Bus. & Com. Code § 552.105(a)); state licensing agencies may add license suspension/probation/revocation or up to $100,000 on AG recommendation (§ 552.106). TX AG exclusive enforcement, no private right of action (§ 552.101), mandatory 60-day cure (§ 552.104). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Texas Responsible AI Governance Act (TRAIGA / HB 149)?

The 7 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan