If you've been tracking US state AI laws through the lens of the EU AI Act — risk tiers, mandatory impact assessments, conformity requirements — Texas will surprise you. The Texas Responsible AI Governance Act (TRAIGA, HB 149) took effect January 1, 2026, and it deliberately rejected that model. Understanding why matters, because TRAIGA is now the second-largest state economy's answer to AI regulation, and its structure is likely to influence how other states legislate going forward.
Texas's TRAIGA took effect January 1, 2026. Unlike the EU AI Act or Colorado's original law, it's an intent-based prohibition model, not a risk-tier system — and it gives an explicit legal safe harbor to organizations that substantially comply with the NIST AI Risk Management Framework.
From EU-Style Draft to Intent-Based Law
TRAIGA's original December 2024 draft looked a lot like Colorado's original SB 24-205 and the EU AI Act: a "high-risk AI system" classification, mandatory algorithmic impact assessments, and a duty-of-care standard. By the time Governor Abbott signed the final version on June 22, 2025, the bill had been substantially rewritten. The enacted law scraps the risk-tier framework entirely and instead prohibits specific harmful intents behind AI development and deployment. If you see a summary describing TRAIGA as a "high-risk system" law with mandatory impact assessments, it's very likely describing the original bill, not what actually passed — this mix-up is common enough in secondary coverage that it's worth double-checking against the enacted text before you build a compliance program around it.
This is the second time in two years a US state has walked back an EU-style AI framework before or shortly after enactment. Texas rewrote its bill before passage; Colorado passed SB 24-205, then repealed it entirely in May 2026 in favor of a narrower disclosure model. Treat any "EU AI Act, but for [state]" characterization as provisional until the final text is signed.
What TRAIGA Actually Prohibits
Rather than classifying systems by risk level, TRAIGA prohibits developing or deploying an AI system with the specific intent to:
- Manipulate human behavior in a way intentionally aimed at inciting self-harm, harm to others, or criminal activity.
- Discriminate against a protected class in violation of state or federal civil rights law — critically, disparate impact alone does not establish intent under TRAIGA. This is the law's central departure from EU/Colorado-style frameworks, which regulate discriminatory outcomes regardless of intent.
- Produce or distribute child sexual abuse material or certain unlawful deepfake sexual content.
- Infringe constitutional rights guaranteed under the US Constitution.
Two additional restrictions apply specifically to government entities: a prohibition on AI-driven "social scoring," and restrictions on using AI to identify individuals via biometric data scraped from public sources without consent. Government agencies also carry a disclosure duty — they must tell consumers when they're interacting with an AI system, though affirmative consent isn't required to continue the interaction. Healthcare providers face a parallel, narrower disclosure duty to patients regarding AI use in their care.
The NIST Safe Harbor — TRAIGA's Most Underrated Provision
TRAIGA builds in an affirmative defense that many summaries underplay: organizations that substantially comply with the current NIST AI Risk Management Framework — including the Generative AI Profile (NIST AI 600-1) — have a defense against enforcement. The same protection extends to organizations that discover violations through internal or adversarial red-team testing, or that follow guidance issued by applicable state agencies. In practice, this means documented alignment with NIST's Govern, Map, Measure, and Manage functions isn't just good practice under TRAIGA — it's a legal shield.
Enforcement and Penalties
| Violation Type | Penalty |
|---|---|
| Curable violation | $10,000 – $12,000 per violation |
| Uncurable violation | $80,000 – $200,000 per violation |
| Continuing violation | $2,000 – $40,000 per day |
The Texas Attorney General holds exclusive enforcement authority — there's no private right of action, so individuals can't sue directly, though consumers can file complaints through an AG-maintained online portal. A 60-day cure period applies before most enforcement actions proceed. TRAIGA also preempts local AI ordinances statewide, so cities and counties can't layer additional AI-specific rules on top.
The Regulatory Sandbox
TRAIGA establishes a 36-month regulatory sandbox administered by the Texas Department of Information Resources. Approved participants can test AI systems without standard state licensing or registration requirements, though the core prohibitions — manipulation, discrimination, harmful content — still apply inside the sandbox. A parallel Texas Artificial Intelligence Advisory Council was created to study AI policy and advise the legislature and state agencies, but it has no rulemaking authority of its own.
Who Actually Needs to Care About TRAIGA
TRAIGA's scope is broad by design: it covers anyone who develops or deploys an AI system in Texas, conducts business or advertises in the state, or offers a product or service used by Texas residents. Given Texas's population and economic footprint, most companies operating AI systems at any national scale will find themselves in scope even if Texas isn't their headquarters state. The "AI system" definition itself is intentionally wide — any machine-based system that infers from inputs how to generate outputs, decisions, predictions, or recommendations — so customer-facing chatbots, hiring tools, fraud detection, and recommendation engines are all plausibly covered, even though most won't touch the law's specific prohibitions in ordinary operation.
How TRAIGA Compares to Colorado and California
The three most-discussed comprehensive state AI laws now sit on genuinely different foundations:
- Texas (TRAIGA): Intent-based prohibitions on specific harmful uses. No general risk-assessment requirement. NIST AI RMF is an explicit safe harbor.
- Colorado (SB 26-189): Disclosure and notice obligations for ADMT in five consequential-decision domains. No NIST/ISO affirmative defense — that existed under the repealed SB 24-205 but didn't carry over.
- California (SB 942 / CPPA ADMT rules): Built on the state's existing privacy law architecture rather than a standalone AI statute.
None of the three replicate the EU AI Act's conformity-assessment, CE-marking-style framework. If your compliance program was designed primarily around EU-style risk classification, none of these three US laws will map onto it cleanly — each requires its own control set, even where the underlying governance work (documentation, testing, human oversight) overlaps.
What to Do Before Your Next Audit
- Inventory AI systems touching Texas residents and flag any that plausibly intersect the four prohibited-intent categories, particularly employment and lending tools where discriminatory-intent claims are most likely to surface.
- Formalize NIST AI RMF alignment, including the Generative AI Profile where applicable, and keep dated documentation — this is your safe harbor, and it only works if it's demonstrable.
- Build red-team testing into your release process and document it; self-discovered violations through adversarial testing carry their own affirmative defense under the statute.
- Don't assume TRAIGA compliance satisfies Colorado or California — the three frameworks solve different problems and require separate mapping.
Frequently Asked Questions
When did the Texas Responsible AI Governance Act (TRAIGA) take effect?
January 1, 2026. It was signed into law by Governor Abbott on June 22, 2025, as HB 149.
Is TRAIGA a risk-based law like the EU AI Act or Colorado's original AI Act?
No. TRAIGA's enacted version uses an intent-based prohibition model — it requires proof of intentional misconduct rather than classifying systems by risk tier. Its own original December 2024 draft did use a risk-based model, but that was rewritten before passage.
Does NIST AI RMF compliance protect against TRAIGA enforcement?
Yes. Substantial compliance with the current NIST AI Risk Management Framework, including the Generative AI Profile, is an explicit affirmative defense under the statute.
Who enforces TRAIGA and what are the penalties?
The Texas Attorney General has exclusive enforcement authority, with no private right of action. Penalties range from $10,000–$12,000 for curable violations up to $80,000–$200,000 for uncurable ones, plus $2,000–$40,000 per day for continuing violations.
Related reading: what NIST's Generative AI Profile actually requires, Colorado's SB 26-189, and how AIGP compares to other 2026 AI governance certifications.