Article-by-article breakdown

Texas HB 149 (TRAIGA)

Texas HB 149 — Texas Responsible Artificial Intelligence Governance Act (TRAIGA)

Section 1: Scope and Key DefinitionsScope of Application and Core Definitions

Applies from: 2026-01-01

Applies to

  • Entities conducting business in Texas
  • Entities producing products used by Texas residents
  • Entities deploying AI systems within Texas

Plain English

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) applies broadly to any entity operating in Texas, creating products for Texas residents, or deploying AI systems within the state. This gives the law significant reach across the nation's second-largest economy.

The law defines an 'artificial intelligence system' broadly as any machine-based system that infers from inputs to generate outputs (content, decisions, predictions, recommendations) that can influence physical or virtual environments. This encompasses most modern AI technologies, including generative AI and automated decision tools.

Crucially, 'consumer' is defined as a Texas resident acting 'only in an individual or household context,' explicitly excluding employment and commercial uses from the law's consumer protection provisions. This narrows the focus of certain aspects of the law to personal consumer interactions.

Key points

  • Broad jurisdictional reach covering operations, products, and deployments in Texas.
  • Wide definition of 'artificial intelligence system' covers most AI technologies.
  • Consumer protections are limited to individual/household contexts, excluding employment and commercial uses.

What you need to do

  1. 1.Assess if your organization's AI activities fall under Texas's broad jurisdictional scope.
  2. 2.Review your AI systems against the broad definition to determine applicability.
  3. 3.Understand the distinction between consumer and commercial/employment uses for compliance.

Cross-jurisdiction equivalents

EUEU AI Act, Article 3The EU AI Act also provides a broad definition of 'AI system' but then categorizes systems by risk, which TRAIGA largely avoids.

Section 2: Texas Artificial Intelligence Advisory CouncilEstablishment and Role of the AI Advisory Council

Applies from: 2026-01-01

Applies to

  • Texas state agencies
  • Local governments
  • AI developers and deployers (indirectly, through guidance)

Plain English

TRAIGA establishes the Texas Artificial Intelligence Advisory Council, a seven-member body appointed by the governor, lieutenant governor, and speaker of the house. This Council serves as the primary governance body for AI in Texas.

The Council's main responsibilities include developing and conducting AI training programs for state agencies and local governments. It is also tasked with issuing reports on various AI-related topics, such as data privacy, security, AI ethics, and legal compliance. These reports are intended to inform the public and government on best practices and emerging issues.

Significantly, the Council is expressly prohibited from promulgating binding rules or regulations. This structural limitation means the Council acts purely as an advisory and educational body, distinguishing Texas's approach from jurisdictions where AI governance bodies have direct regulatory authority.

Key points

  • Creates a seven-member AI Advisory Council.
  • Mandated to conduct AI training for government entities and issue reports on AI topics.
  • Expressly prohibited from creating binding rules or regulations, serving an advisory role only.

What you need to do

  1. 1.Monitor reports and guidance issued by the Council for insights into Texas's AI policy direction.
  2. 2.Understand that direct regulatory mandates will not originate from this Council.
  3. 3.State and local government agencies should prepare for potential AI training programs.

Cross-jurisdiction equivalents

UKAI CouncilSimilar to the UK's AI Council, the Texas body is advisory, focusing on guidance and expertise rather than direct rulemaking.

Section 3: Regulatory SandboxAI Regulatory Sandbox for Innovation

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers

Plain English

TRAIGA establishes a 36-month regulatory sandbox, administered by the Department of Information Resources (DIR) in consultation with the AI Advisory Council. This sandbox provides a controlled environment designed to foster AI innovation and experimentation.

The purpose of the sandbox is to allow developers and deployers to test new AI applications with a reduced regulatory burden. This approach aims to encourage technological advancement while still providing a framework for oversight.

DIR will be responsible for developing the specific criteria for participation and the oversight procedures for entities operating within the sandbox. This model is similar to those used in financial services regulation, offering a pathway for novel AI solutions to be developed and tested.

Key points

  • Establishes a 36-month regulatory sandbox for AI innovation.
  • Administered by the Department of Information Resources (DIR).
  • Allows for controlled AI experimentation with reduced regulatory burden.

What you need to do

  1. 1.Evaluate whether your experimental AI applications could benefit from participation in the regulatory sandbox.
  2. 2.Monitor DIR for the release of participation criteria and oversight procedures.
  3. 3.Consider the sandbox as an alternative compliance pathway for novel AI solutions.

Cross-jurisdiction equivalents

SingaporeFinTech Regulatory SandboxMany jurisdictions, including Singapore, have implemented regulatory sandboxes to encourage innovation in emerging technologies like AI and FinTech.

Section 4: Prohibited Uses - Behavioral ManipulationProhibition on AI for Harmful Behavioral Manipulation

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers

Plain English

TRAIGA explicitly prohibits the development or deployment of AI systems designed to intentionally encourage any person to physically harm themselves or others. This provision targets AI applications that could be used to manipulate individuals into dangerous actions.

The focus is on the 'intentional' aspect of encouragement, meaning the system's design or purpose must be to provoke such harmful behavior. This is a direct prohibition against AI systems that could be weaponized for psychological manipulation leading to physical harm.

This prohibition underscores a fundamental ethical boundary for AI development and deployment in Texas, prioritizing public safety and individual well-being.

Key points

  • Prohibits AI systems designed to intentionally encourage self-harm.
  • Also prohibits AI systems designed to intentionally encourage harm to others.
  • Applies to both the development and deployment phases of AI systems.

What you need to do

  1. 1.Conduct thorough design reviews and risk assessments to ensure AI systems cannot be intentionally misused for harmful behavioral manipulation.
  2. 2.Implement safeguards and ethical guidelines during the development process to prevent such capabilities.
  3. 3.Ensure terms of service and acceptable use policies explicitly forbid such applications by users.

Cross-jurisdiction equivalents

EUEU AI Act, Article 5(1)(a)The EU AI Act also prohibits AI systems that deploy subliminal techniques or intentionally manipulative techniques that cause physical or psychological harm.

Section 5: Prohibited Uses - Anti-DiscriminationProhibition on Intentional Discrimination

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers

Plain English

The Act prohibits the deployment of AI systems intended to discriminate against protected classes, including race, sex, and disability. This provision aims to prevent AI from being used as a tool for targeted prejudice.

An important clarification in the law is that disparate impact alone does not establish intent to discriminate. This means that if an AI system's output unintentionally leads to different outcomes for protected groups, it does not automatically constitute a violation, unless discriminatory intent can be proven.

This focus on 'intent' sets a higher bar for proving a violation compared to some other anti-discrimination laws that consider disparate impact sufficient for a finding of discrimination.

Key points

  • Prohibits deployment of AI systems with the intent to discriminate.
  • Covers protected characteristics such as race, sex, and disability.
  • Clarifies that disparate impact (unequal outcomes) alone is not sufficient to prove discriminatory intent.

What you need to do

  1. 1.Implement robust bias detection and mitigation strategies during AI development and deployment.
  2. 2.Document design choices and ethical considerations to demonstrate a lack of discriminatory intent.
  3. 3.Regularly audit AI systems for fairness and equitable outcomes, even if disparate impact isn't a direct violation.

Cross-jurisdiction equivalents

EUEU AI Act, Article 5(1)(c)The EU AI Act prohibits AI systems that exploit vulnerabilities leading to harm, including discrimination, but does not explicitly require 'intent' in the same way as TRAIGA.

Section 6: Prohibited Uses - Child ProtectionProhibition on AI for Child Sexual Abuse Material and Impersonation

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers

Plain English

TRAIGA enacts strict prohibitions against AI systems involved in child sexual abuse material (CSAM). Specifically, it bans AI systems that produce child sexual abuse imagery or deepfake pornography.

Furthermore, the law prohibits AI systems from engaging in text conversations that simulate sexual content while impersonating children. This targets generative AI models that could be used to create harmful and exploitative interactions.

These provisions reflect a strong stance on protecting children from online exploitation facilitated by AI, aligning with broader efforts to combat child abuse material.

Key points

  • Bans AI systems that produce child sexual abuse imagery.
  • Prohibits AI systems generating deepfake pornography.
  • Forbids AI systems from simulating sexual content in text while impersonating children.

What you need to do

  1. 1.Implement robust content moderation and safety filters in all AI systems, especially generative models.
  2. 2.Train AI models to prevent the generation of any prohibited content related to child exploitation.
  3. 3.Regularly review and update safety protocols to address evolving methods of misuse.

Cross-jurisdiction equivalents

UKOnline Safety ActThe UK's Online Safety Act also includes stringent provisions against the creation and dissemination of child sexual abuse material, including AI-generated content.

Section 7: Prohibited Uses - Government Social ScoringProhibition on Government Social Scoring and Biometric Identification

Applies from: 2026-01-01

Applies to

  • Government entities (Texas)

Plain English

TRAIGA prohibits government entities within Texas from using AI for social scoring. Social scoring typically involves evaluating or classifying individuals based on their social behavior, economic status, or personal characteristics, often leading to discriminatory outcomes or restrictions on rights.

Additionally, the law bans government entities from using AI for biometric identification of specific individuals without their explicit consent. This ensures that biometric data, such as facial recognition or fingerprints, is not used by the government for identification purposes without the individual's knowledge and agreement.

These prohibitions aim to safeguard individual liberties and prevent the misuse of powerful AI technologies by state and local government bodies.

Key points

  • Prohibits Texas government entities from using AI for social scoring.
  • Bans government use of AI for biometric identification of individuals without consent.
  • Focuses on protecting individual liberties from government AI misuse.

What you need to do

  1. 1.Texas government agencies must review all AI systems to ensure they are not engaged in social scoring.
  2. 2.Implement clear consent mechanisms for any AI-driven biometric identification systems used by government.
  3. 3.Ensure compliance with privacy and data protection principles when deploying AI.

Cross-jurisdiction equivalents

EUEU AI Act, Article 5(1)(b)The EU AI Act also includes a prohibition on social scoring by public authorities, reflecting a global concern over this practice.

Section 8: Government Consumer Interaction DisclosureDisclosure for Government-Deployed AI Interacting with Consumers

Applies from: 2026-01-01

Applies to

  • Government entities (Texas)

Plain English

This provision mandates that any Texas government entity making an AI system available to consumers must provide clear notice that consumers are interacting with an AI. This ensures transparency in interactions between the public and automated government services.

The requirement applies specifically when a consumer, defined as an individual acting in a personal or household context, is engaging with a government-deployed AI system. This could include chatbots on government websites, automated phone systems, or other AI-powered interfaces.

The goal is to inform individuals when they are not communicating with a human, allowing them to adjust their expectations and interactions accordingly.

Key points

  • Requires Texas government entities to disclose when consumers are interacting with AI.
  • Applies to AI systems made available to consumers (individuals/households).
  • Aims to ensure transparency in government-citizen interactions involving AI.

What you need to do

  1. 1.Texas government agencies must implement clear and conspicuous notices for all public-facing AI systems.
  2. 2.Review all AI-powered interfaces that interact with the public to ensure compliance with disclosure requirements.
  3. 3.Train personnel on when and how to provide these disclosures to consumers.

Cross-jurisdiction equivalents

US (Federal)NIST AI Risk Management FrameworkWhile not a direct legal equivalent, the NIST AI RMF emphasizes transparency and explainability, aligning with the spirit of disclosure requirements.

Section 9: Enforcement and PenaltiesEnforcement Authority and Civil Penalties

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers
  • Government entities (Texas)

Plain English

Enforcement authority for TRAIGA rests exclusively with the Texas Attorney General (AG). The AG is empowered to investigate alleged violations of the Act and impose civil penalties.

Before initiating any enforcement action, the AG is required to provide written notice to the alleged violator. This notice triggers a 60-day period during which the entity can respond to the allegations. This pre-enforcement procedure offers a crucial opportunity for remediation and dialogue before formal legal action is taken.

While the Act grants the AG the power to impose civil penalties, the specific amounts of these penalties are not detailed within TRAIGA itself. This leaves the determination of penalty amounts to the AG's discretion and potential judicial review.

Key points

  • Texas Attorney General holds exclusive enforcement authority.
  • Requires a 60-day written notice period before the AG can bring an enforcement action.
  • Civil penalties can be imposed, but specific amounts are not defined in the Act.

What you need to do

  1. 1.Establish internal processes for promptly responding to any written notices from the Texas AG.
  2. 2.Be prepared to demonstrate compliance and, if necessary, remediate issues within the 60-day notice period.
  3. 3.Understand that penalty amounts will be determined by the AG and potentially through judicial processes.

Cross-jurisdiction equivalents

US (Colorado)Colorado AI Act (SB24-205)The Colorado AI Act also designates the state Attorney General as the enforcement authority, but without the explicit 60-day notice period for remediation.

Section 10: Safe Harbor ProvisionsAffirmative Defenses and Safe Harbors

Applies from: 2026-01-01

Applies to

  • AI developers
  • AI deployers

Plain English

TRAIGA includes important safe harbor provisions that offer affirmative defenses against enforcement actions. These provisions incentivize proactive compliance and responsible AI practices.

There are three main circumstances for safe harbor: first, when third parties misuse an AI system in ways prohibited by TRAIGA, protecting the original developer/deployer from liability. Second, if violations are discovered through good faith testing or audits, demonstrating a commitment to self-correction. Third, substantial compliance with the NIST AI Risk Management Framework (AI RMF) or similar recognized standards provides a defense.

These safe harbors are particularly significant for platform operators and developers, as they offer protection when users or external factors lead to non-compliance, provided the entity has taken reasonable steps to ensure responsible use and adherence to recognized standards.

Key points

  • Protects entities from liability when third parties misuse AI in prohibited ways.
  • Provides a defense if violations are discovered through good faith testing or audits.
  • Offers safe harbor for substantial compliance with the NIST AI Risk Management Framework or similar standards.

What you need to do

  1. 1.Consider adopting the NIST AI RMF or a similar recognized framework to qualify for safe harbor protection.
  2. 2.Implement robust internal testing and auditing protocols to proactively identify and address potential violations.
  3. 3.Review and update terms of service and acceptable use policies to clearly prohibit third-party misuse of your AI systems.

Cross-jurisdiction equivalents

US (Federal)NIST AI Risk Management FrameworkThe NIST AI RMF is a widely recognized federal standard, and its inclusion as a safe harbor aligns Texas with broader national AI governance efforts.

Section 11: Healthcare AI Integration (SB 1188)Specific Requirements for AI in Healthcare

Applies from: 2025-09-01

Applies to

  • Healthcare providers using AI for diagnosis
  • AI developers for healthcare applications

Plain English

While TRAIGA provides general AI governance, companion legislation, Senate Bill 1188 (SB 1188), specifically addresses the integration of AI in healthcare within Texas. This bill focuses on AI systems used in medical diagnosis.

SB 1188 mandates that licensed practitioners must review AI-generated records. This ensures that human oversight remains central to diagnostic processes, even when AI tools are utilized. The oversight and standards for this review fall under the jurisdiction of the Texas Medical Board.

This sector-specific legislation highlights the critical nature of AI applications in healthcare and ensures that existing medical regulatory bodies maintain authority over the use of AI in patient care.

Key points

  • Companion legislation (SB 1188) specifically governs AI in medical diagnosis.
  • Requires licensed practitioners to review AI-generated medical records.
  • Oversight and standards are managed by the Texas Medical Board.

What you need to do

  1. 1.If developing or deploying AI for medical diagnosis in Texas, ensure compliance with SB 1188 and Texas Medical Board standards.
  2. 2.Integrate human oversight and review processes for all AI-generated diagnostic outputs.
  3. 3.Collaborate with healthcare professionals to ensure AI tools support, rather than replace, clinical judgment.

Cross-jurisdiction equivalents

US (Federal)FDA Guidance for AI/ML-Based Medical DevicesThe FDA provides guidance for AI/ML in medical devices, reflecting a similar focus on human oversight and regulatory review for AI in healthcare.

Need help applying this to your case?

The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.

Start the wizard →