Article-by-article breakdown
Texas HB 149 (TRAIGA)
Texas HB 149 — Texas Responsible Artificial Intelligence Governance Act (TRAIGA)
Section 1: Scope and Key Definitions — Scope of Application and Core Definitions
Applies to
- ›Entities conducting business in Texas
- ›Entities producing products used by Texas residents
- ›Entities deploying AI systems within Texas
Plain English
The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) applies broadly to any entity operating in Texas, creating products for Texas residents, or deploying AI systems within the state. This gives the law significant reach across the nation's second-largest economy.
The law defines an 'artificial intelligence system' broadly as any machine-based system that infers from inputs to generate outputs (content, decisions, predictions, recommendations) that can influence physical or virtual environments. This encompasses most modern AI technologies, including generative AI and automated decision tools.
Crucially, 'consumer' is defined as a Texas resident acting 'only in an individual or household context,' explicitly excluding employment and commercial uses from the law's consumer protection provisions. This narrows the focus of certain aspects of the law to personal consumer interactions.
Key points
- •Broad jurisdictional reach covering operations, products, and deployments in Texas.
- •Wide definition of 'artificial intelligence system' covers most AI technologies.
- •Consumer protections are limited to individual/household contexts, excluding employment and commercial uses.
What you need to do
- 1.Assess if your organization's AI activities fall under Texas's broad jurisdictional scope.
- 2.Review your AI systems against the broad definition to determine applicability.
- 3.Understand the distinction between consumer and commercial/employment uses for compliance.
Cross-jurisdiction equivalents
Section 2: Texas Artificial Intelligence Advisory Council — Establishment and Role of the AI Advisory Council
Applies to
- ›Texas state agencies
- ›Local governments
- ›AI developers and deployers (indirectly, through guidance)
Plain English
TRAIGA establishes the Texas Artificial Intelligence Advisory Council, a seven-member body appointed by the governor, lieutenant governor, and speaker of the house. This Council serves as the primary governance body for AI in Texas.
The Council's main responsibilities include developing and conducting AI training programs for state agencies and local governments. It is also tasked with issuing reports on various AI-related topics, such as data privacy, security, AI ethics, and legal compliance. These reports are intended to inform the public and government on best practices and emerging issues.
Significantly, the Council is expressly prohibited from promulgating binding rules or regulations. This structural limitation means the Council acts purely as an advisory and educational body, distinguishing Texas's approach from jurisdictions where AI governance bodies have direct regulatory authority.
Key points
- •Creates a seven-member AI Advisory Council.
- •Mandated to conduct AI training for government entities and issue reports on AI topics.
- •Expressly prohibited from creating binding rules or regulations, serving an advisory role only.
What you need to do
- 1.Monitor reports and guidance issued by the Council for insights into Texas's AI policy direction.
- 2.Understand that direct regulatory mandates will not originate from this Council.
- 3.State and local government agencies should prepare for potential AI training programs.
Cross-jurisdiction equivalents
Section 3: Regulatory Sandbox — AI Regulatory Sandbox for Innovation
Applies to
- ›AI developers
- ›AI deployers
Plain English
TRAIGA establishes a 36-month regulatory sandbox, administered by the Department of Information Resources (DIR) in consultation with the AI Advisory Council. This sandbox provides a controlled environment designed to foster AI innovation and experimentation.
The purpose of the sandbox is to allow developers and deployers to test new AI applications with a reduced regulatory burden. This approach aims to encourage technological advancement while still providing a framework for oversight.
DIR will be responsible for developing the specific criteria for participation and the oversight procedures for entities operating within the sandbox. This model is similar to those used in financial services regulation, offering a pathway for novel AI solutions to be developed and tested.
Key points
- •Establishes a 36-month regulatory sandbox for AI innovation.
- •Administered by the Department of Information Resources (DIR).
- •Allows for controlled AI experimentation with reduced regulatory burden.
What you need to do
- 1.Evaluate whether your experimental AI applications could benefit from participation in the regulatory sandbox.
- 2.Monitor DIR for the release of participation criteria and oversight procedures.
- 3.Consider the sandbox as an alternative compliance pathway for novel AI solutions.
Cross-jurisdiction equivalents
Section 4: Prohibited Uses - Behavioral Manipulation — Prohibition on AI for Harmful Behavioral Manipulation
Applies to
- ›AI developers
- ›AI deployers
Plain English
TRAIGA explicitly prohibits the development or deployment of AI systems designed to intentionally encourage any person to physically harm themselves or others. This provision targets AI applications that could be used to manipulate individuals into dangerous actions.
The focus is on the 'intentional' aspect of encouragement, meaning the system's design or purpose must be to provoke such harmful behavior. This is a direct prohibition against AI systems that could be weaponized for psychological manipulation leading to physical harm.
This prohibition underscores a fundamental ethical boundary for AI development and deployment in Texas, prioritizing public safety and individual well-being.
Key points
- •Prohibits AI systems designed to intentionally encourage self-harm.
- •Also prohibits AI systems designed to intentionally encourage harm to others.
- •Applies to both the development and deployment phases of AI systems.
What you need to do
- 1.Conduct thorough design reviews and risk assessments to ensure AI systems cannot be intentionally misused for harmful behavioral manipulation.
- 2.Implement safeguards and ethical guidelines during the development process to prevent such capabilities.
- 3.Ensure terms of service and acceptable use policies explicitly forbid such applications by users.
Cross-jurisdiction equivalents
Section 5: Prohibited Uses - Anti-Discrimination — Prohibition on Intentional Discrimination
Applies to
- ›AI developers
- ›AI deployers
Plain English
The Act prohibits the deployment of AI systems intended to discriminate against protected classes, including race, sex, and disability. This provision aims to prevent AI from being used as a tool for targeted prejudice.
An important clarification in the law is that disparate impact alone does not establish intent to discriminate. This means that if an AI system's output unintentionally leads to different outcomes for protected groups, it does not automatically constitute a violation, unless discriminatory intent can be proven.
This focus on 'intent' sets a higher bar for proving a violation compared to some other anti-discrimination laws that consider disparate impact sufficient for a finding of discrimination.
Key points
- •Prohibits deployment of AI systems with the intent to discriminate.
- •Covers protected characteristics such as race, sex, and disability.
- •Clarifies that disparate impact (unequal outcomes) alone is not sufficient to prove discriminatory intent.
What you need to do
- 1.Implement robust bias detection and mitigation strategies during AI development and deployment.
- 2.Document design choices and ethical considerations to demonstrate a lack of discriminatory intent.
- 3.Regularly audit AI systems for fairness and equitable outcomes, even if disparate impact isn't a direct violation.
Cross-jurisdiction equivalents
Section 6: Prohibited Uses - Child Protection — Prohibition on AI for Child Sexual Abuse Material and Impersonation
Applies to
- ›AI developers
- ›AI deployers
Plain English
TRAIGA enacts strict prohibitions against AI systems involved in child sexual abuse material (CSAM). Specifically, it bans AI systems that produce child sexual abuse imagery or deepfake pornography.
Furthermore, the law prohibits AI systems from engaging in text conversations that simulate sexual content while impersonating children. This targets generative AI models that could be used to create harmful and exploitative interactions.
These provisions reflect a strong stance on protecting children from online exploitation facilitated by AI, aligning with broader efforts to combat child abuse material.
Key points
- •Bans AI systems that produce child sexual abuse imagery.
- •Prohibits AI systems generating deepfake pornography.
- •Forbids AI systems from simulating sexual content in text while impersonating children.
What you need to do
- 1.Implement robust content moderation and safety filters in all AI systems, especially generative models.
- 2.Train AI models to prevent the generation of any prohibited content related to child exploitation.
- 3.Regularly review and update safety protocols to address evolving methods of misuse.
Cross-jurisdiction equivalents
Section 8: Government Consumer Interaction Disclosure — Disclosure for Government-Deployed AI Interacting with Consumers
Applies to
- ›Government entities (Texas)
Plain English
This provision mandates that any Texas government entity making an AI system available to consumers must provide clear notice that consumers are interacting with an AI. This ensures transparency in interactions between the public and automated government services.
The requirement applies specifically when a consumer, defined as an individual acting in a personal or household context, is engaging with a government-deployed AI system. This could include chatbots on government websites, automated phone systems, or other AI-powered interfaces.
The goal is to inform individuals when they are not communicating with a human, allowing them to adjust their expectations and interactions accordingly.
Key points
- •Requires Texas government entities to disclose when consumers are interacting with AI.
- •Applies to AI systems made available to consumers (individuals/households).
- •Aims to ensure transparency in government-citizen interactions involving AI.
What you need to do
- 1.Texas government agencies must implement clear and conspicuous notices for all public-facing AI systems.
- 2.Review all AI-powered interfaces that interact with the public to ensure compliance with disclosure requirements.
- 3.Train personnel on when and how to provide these disclosures to consumers.
Cross-jurisdiction equivalents
Section 9: Enforcement and Penalties — Enforcement Authority and Civil Penalties
Applies to
- ›AI developers
- ›AI deployers
- ›Government entities (Texas)
Plain English
Enforcement authority for TRAIGA rests exclusively with the Texas Attorney General (AG). The AG is empowered to investigate alleged violations of the Act and impose civil penalties.
Before initiating any enforcement action, the AG is required to provide written notice to the alleged violator. This notice triggers a 60-day period during which the entity can respond to the allegations. This pre-enforcement procedure offers a crucial opportunity for remediation and dialogue before formal legal action is taken.
While the Act grants the AG the power to impose civil penalties, the specific amounts of these penalties are not detailed within TRAIGA itself. This leaves the determination of penalty amounts to the AG's discretion and potential judicial review.
Key points
- •Texas Attorney General holds exclusive enforcement authority.
- •Requires a 60-day written notice period before the AG can bring an enforcement action.
- •Civil penalties can be imposed, but specific amounts are not defined in the Act.
What you need to do
- 1.Establish internal processes for promptly responding to any written notices from the Texas AG.
- 2.Be prepared to demonstrate compliance and, if necessary, remediate issues within the 60-day notice period.
- 3.Understand that penalty amounts will be determined by the AG and potentially through judicial processes.
Cross-jurisdiction equivalents
Section 10: Safe Harbor Provisions — Affirmative Defenses and Safe Harbors
Applies to
- ›AI developers
- ›AI deployers
Plain English
TRAIGA includes important safe harbor provisions that offer affirmative defenses against enforcement actions. These provisions incentivize proactive compliance and responsible AI practices.
There are three main circumstances for safe harbor: first, when third parties misuse an AI system in ways prohibited by TRAIGA, protecting the original developer/deployer from liability. Second, if violations are discovered through good faith testing or audits, demonstrating a commitment to self-correction. Third, substantial compliance with the NIST AI Risk Management Framework (AI RMF) or similar recognized standards provides a defense.
These safe harbors are particularly significant for platform operators and developers, as they offer protection when users or external factors lead to non-compliance, provided the entity has taken reasonable steps to ensure responsible use and adherence to recognized standards.
Key points
- •Protects entities from liability when third parties misuse AI in prohibited ways.
- •Provides a defense if violations are discovered through good faith testing or audits.
- •Offers safe harbor for substantial compliance with the NIST AI Risk Management Framework or similar standards.
What you need to do
- 1.Consider adopting the NIST AI RMF or a similar recognized framework to qualify for safe harbor protection.
- 2.Implement robust internal testing and auditing protocols to proactively identify and address potential violations.
- 3.Review and update terms of service and acceptable use policies to clearly prohibit third-party misuse of your AI systems.
Cross-jurisdiction equivalents
Section 11: Healthcare AI Integration (SB 1188) — Specific Requirements for AI in Healthcare
Applies to
- ›Healthcare providers using AI for diagnosis
- ›AI developers for healthcare applications
Plain English
While TRAIGA provides general AI governance, companion legislation, Senate Bill 1188 (SB 1188), specifically addresses the integration of AI in healthcare within Texas. This bill focuses on AI systems used in medical diagnosis.
SB 1188 mandates that licensed practitioners must review AI-generated records. This ensures that human oversight remains central to diagnostic processes, even when AI tools are utilized. The oversight and standards for this review fall under the jurisdiction of the Texas Medical Board.
This sector-specific legislation highlights the critical nature of AI applications in healthcare and ensures that existing medical regulatory bodies maintain authority over the use of AI in patient care.
Key points
- •Companion legislation (SB 1188) specifically governs AI in medical diagnosis.
- •Requires licensed practitioners to review AI-generated medical records.
- •Oversight and standards are managed by the Texas Medical Board.
What you need to do
- 1.If developing or deploying AI for medical diagnosis in Texas, ensure compliance with SB 1188 and Texas Medical Board standards.
- 2.Integrate human oversight and review processes for all AI-generated diagnostic outputs.
- 3.Collaborate with healthcare professionals to ensure AI tools support, rather than replace, clinical judgment.
Cross-jurisdiction equivalents
Need help applying this to your case?
The wizard takes 60 seconds and tells you which articles you actually need to worry about based on your jurisdictions, use case, and data.
Start the wizard →