United States - Texas - AI Governance Act (HB 149)

Texas HB 149 — Texas Responsible Artificial Intelligence Governance Act (TRAIGA)

United States

RAI-US-TX-TH1TRXX-2025
Effective: January 1, 2026
In Force(In Force)
ActGovernance and OversightFundamental Rights
Export PDF

The Texas Responsible AI Governance Act (TRAIGA), signed June 22, 2025, makes Texas the third US state with comprehensive AI legislation. The law prohibits AI systems designed to manipulate behavior causing harm, discriminate based on protected characteristics, produce child sexual abuse material, or enable social scoring by government. It creates an AI Advisory Council and a 36-month regulatory sandbox.

Overview

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), codified as HB 149, represents Texas's entry into comprehensive AI governance, making it the third US state after Colorado and Utah to enact such legislation. Signed by Governor Greg Abbott on June 22, 2025, with an effective date of January 1, 2026, the law underwent significant amendments from its original draft. The initial December 2024 version proposed a sweeping regulatory scheme modeled after the Colorado AI Act and EU AI Act, focusing on high-risk AI systems with substantial requirements for developers and deployers. However, March 2025 amendments significantly scaled back the scope, resulting in legislation that establishes foundational prohibitions and governance structures while avoiding prescriptive compliance mandates. This approach reflects Texas's traditionally business-friendly regulatory philosophy while addressing key AI safety concerns. The law applies broadly to parties conducting business in Texas, producing products used by Texas residents, or deploying AI systems within the state, creating significant reach for the nation's second-largest economy.

Definitions

TRAIGA establishes key definitions shaping regulatory scope. Artificial intelligence system means 'any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions or recommendations, that can influence physical or virtual environments.' This broad definition captures most modern AI technologies including generative AI, recommendation systems, and automated decision tools. Consumer means an individual who is a Texas resident 'acting only in an individual or household context,' explicitly excluding employment and commercial uses from consumer protection provisions. This limitation focuses the law on personal consumer interactions rather than workplace AI applications. The law does not extensively define 'high-risk AI systems' as originally proposed, instead focusing prohibitions on specific harmful applications regardless of risk categorization. Consequential decisions—central to the original draft—were largely removed from the enacted version, though healthcare provisions in companion legislation SB 1188 address AI in medical diagnosis contexts.

Governance and Institutional Framework

TRAIGA creates the Texas Artificial Intelligence Advisory Council as the primary governance body. The Council comprises seven qualified members: appointees from the governor, lieutenant governor, and speaker of the house of representatives. The Council's mandate includes conducting AI training programs for state agencies and local governments and issuing reports on AI-related topics including data privacy, security, AI ethics, and legal compliance. Critically, the Council is expressly prohibited from promulgating binding rules or regulations, establishing it as an advisory and educational body rather than a regulatory agency. This structural limitation distinguishes Texas's approach from states with more empowered AI governance bodies. The Texas Attorney General serves as the enforcement authority with power to investigate violations and impose civil penalties. Before initiating enforcement actions, the AG must provide written notice to alleged violators, who then have 60 days to respond. The Department of Information Resources (DIR) administers the 36-month regulatory sandbox in consultation with the AI Council, providing a controlled environment for AI innovation and experimentation. This sandbox model follows approaches used in financial services regulation, allowing developers to test AI applications with reduced regulatory burden.

Key Focus Areas

  • Behavioral Manipulation Prohibition: AI systems cannot be developed or deployed to intentionally encourage any person to physically harm themselves or others.
  • Anti-Discrimination Requirements: Prohibits deployment of systems intended to discriminate against protected classes including race, sex, and disability; clarifies that disparate impact alone does not establish intent.
  • Child Protection: Bans AI systems producing child sexual abuse imagery, deepfake pornography, or engaging in text conversations simulating sexual content while impersonating children.
  • Government Social Scoring Ban: Prohibits government entities from using AI for social scoring or biometric identification of specific individuals without consent.
  • Consumer Interaction Disclosure: Government entities making AI systems available to consumers must provide clear notice that consumers are interacting with AI.
  • Regulatory Sandbox: Establishes 36-month sandbox administered by DIR for controlled AI experimentation with reduced regulatory burden.
  • Safe Harbor Provisions: Protects entities following NIST AI Risk Management Framework or similar recognized standards.
  • Advisory Council: Creates seven-member council for training and reporting but without rulemaking authority.
  • Healthcare AI Integration: Companion legislation SB 1188 addresses AI in medical diagnosis with Texas Medical Board oversight.
  • Third-Party Misuse Protection: Entities not liable when third parties misuse AI in prohibited ways.

Implementation Framework

TRAIGA takes effect January 1, 2026, providing approximately six months for compliance preparation from the June 2025 signing. Unlike more prescriptive frameworks like Colorado's SB24-205, TRAIGA's streamlined structure requires less extensive implementation planning. Organizations must primarily ensure their AI systems do not fall within prohibited categories and that government-facing AI applications include required disclosures. The regulatory sandbox provides an alternative compliance pathway for experimental applications, with DIR developing participation criteria and oversight procedures. The AI Advisory Council will develop training programs for government agencies, though the timeline for these programs is not specified. Healthcare AI applications face additional requirements under SB 1188, effective September 1, 2025, requiring licensed practitioners to review AI-generated records according to Texas Medical Board standards. Organizations should evaluate whether they qualify for safe harbor protection through NIST AI RMF compliance or adoption of similar recognized standards. The 60-day notice and response period before AG enforcement actions provides opportunity for compliance remediation before penalties accrue.

Monitoring and Evaluation

TRAIGA does not establish extensive ongoing monitoring requirements comparable to Colorado's impact assessment mandates. The AI Advisory Council may issue reports on various AI topics, providing periodic evaluation of the regulatory landscape. Government entities using AI systems must maintain disclosure capabilities but face no formal reporting obligations to state authorities. The regulatory sandbox inherently includes monitoring of participating entities, with DIR oversight ensuring sandbox activities remain within permitted boundaries. The Attorney General's enforcement authority creates reactive monitoring through complaint investigation and compliance review. Private sector entities benefit from limited affirmative compliance monitoring, though they must maintain documentation sufficient to demonstrate safe harbor eligibility if challenged. Healthcare AI applications under SB 1188 fall under Texas Medical Board oversight, creating sector-specific monitoring for diagnostic AI uses. The Council's prohibition on binding rulemaking limits its ability to establish monitoring frameworks through regulatory action, leaving monitoring largely to AG enforcement discretion and sector-specific regulators.

Penalties, Liability, and Appeals

Enforcement authority rests exclusively with the Texas Attorney General, who may investigate violations and impose civil penalties. The pre-enforcement procedure requires the AG to send written notice of violation to alleged violators, who then have 60 days to respond before the AG can bring an enforcement action. This notice period provides opportunity for compliance remediation and distinguishes Texas's approach from immediate enforcement authority in other states. Civil penalty amounts are not specified in TRAIGA, leaving determination to AG discretion and judicial review. Safe harbors provide affirmative defenses in three circumstances: (1) when third parties misuse AI in ways TRAIGA prohibits; (2) when violations are discovered through testing or good faith audits; and (3) when entities substantially comply with NIST AI Risk Management Framework or similar recognized standards. These safe harbors incentivize proactive compliance efforts and self-monitoring. The third-party misuse protection is particularly significant for platform operators whose AI tools might be weaponized by users. Healthcare AI violations under SB 1188 fall under Texas Medical Board enforcement jurisdiction with profession-specific penalties. Appeals from AG enforcement actions follow standard administrative and judicial review procedures.

Relationship to Other Instruments

TRAIGA joins the emerging patchwork of US state AI legislation, with Colorado's SB24-205 and Utah's SB 149 providing the primary comparison points. Colorado's law is substantially more prescriptive, requiring impact assessments, consumer disclosures, and comprehensive documentation for high-risk AI systems. Utah's approach, like Texas's, is more permissive and innovation-oriented. TRAIGA's original draft closely followed the EU AI Act and Colorado model, but amendments produced a distinctly lighter-touch framework. The law explicitly accommodates federal standards through its safe harbor for NIST AI RMF compliance, creating alignment with federal AI governance direction. Texas companion legislation SB 1188 addresses healthcare AI specifically, integrating with existing Texas Medical Board authority rather than creating new AI-specific oversight. At the federal level, the potential 'One Big Beautiful Bill' moratorium on state AI laws, passed by the House in May 2025, could preempt TRAIGA if enacted, though Senate passage remains uncertain. TRAIGA's consumer focus distinguishes it from employment-focused state laws like Illinois's AI Video Interview Act and California's employment algorithmic decision proposals.

International Alignment

TRAIGA shows limited direct alignment with international AI frameworks, reflecting its scaled-back scope from the original EU AI Act-inspired draft. The European Union AI Act's risk-based categorization system influenced early TRAIGA drafts but was largely abandoned in final legislation. The prohibition on social scoring by government entities mirrors EU AI Act Article 5 prohibited practices, representing one area of transatlantic convergence. Consumer disclosure requirements align with emerging international transparency norms, though Texas's requirements apply only to government-deployed AI. The NIST AI RMF safe harbor creates indirect international alignment, as NIST standards inform and are informed by ISO/IEC AI governance standards used globally. Texas's sandbox approach follows international precedent from Singapore, UAE, and EU member states that have used regulatory sandboxes to foster AI innovation. The law's anti-discrimination provisions align with international human rights frameworks addressing AI bias, though the intent requirement (rather than disparate impact) represents a more permissive standard than some international approaches. Texas's market significance may drive international companies to consider TRAIGA compliance as part of US market access strategies.

Implementation Timeline

DateMilestone
December 2024Original HB 149 introduced with comprehensive EU-style requirements
March 2025Significant amendments scale back bill scope
May 2025House passes moratorium proposal potentially preempting state AI laws
June 20, 2025Companion healthcare AI bill SB 1188 signed
June 22, 2025Governor Abbott signs TRAIGA into law
September 1, 2025Healthcare AI provisions (SB 1188) take effect
January 1, 2026TRAIGA takes full effect
2026-202936-month regulatory sandbox operational period

Compliance Checklist

RequirementDetails
Review Prohibited UsesEnsure AI systems are not designed for behavioral manipulation causing harm, discrimination, CSAM generation, or child-impersonating sexual content
Assess Government ApplicationsIf providing AI to government entities, ensure consumer interaction disclosures are implemented
Evaluate Safe Harbor EligibilityConsider adopting NIST AI RMF or similar recognized framework for compliance defense
Implement Testing ProtocolsEstablish good faith audit and testing procedures to identify potential violations
Review Third-Party Use TermsUpdate terms of service to prohibit third-party misuse enabling safe harbor protection
Consider Sandbox ParticipationEvaluate whether experimental AI applications qualify for regulatory sandbox participation
Healthcare AI ComplianceIf developing diagnostic AI, ensure compliance with SB 1188 and Texas Medical Board requirements
Document Compliance EffortsMaintain records demonstrating reasonable compliance measures for potential AG inquiries
Monitor Federal DevelopmentsTrack federal moratorium proposal that could preempt TRAIGA if enacted
Train PersonnelEducate staff on prohibited AI applications and compliance requirements

Sources and References

SourceType
HB 149 Bill Page - Texas LegislaturePrimary Source
HB 149 Bill AnalysisPrimary Source
NIST AI Risk Management FrameworkSafe Harbor Standard
Texas Attorney GeneralEnforcement Authority
Plain English

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) establishes foundational prohibitions and governance structures for artificial intelligence systems, applying broadly to businesses operating in Texas, creating products for Texas residents, or deploying AI within the state.

Signed into law in June 2025, TRAIGA takes effect on January 1, 2026. It represents a significant, yet scaled-back, approach to AI regulation compared to earlier drafts. The law primarily focuses on banning specific harmful uses of AI, rather than imposing broad compliance mandates for "high-risk" systems.

Key prohibitions include: - Developing or deploying AI to intentionally encourage self-harm or harm to others. - Using AI systems with the intent to discriminate against protected classes like race, sex, or disability. Notably, simply causing a disparate impact without intent does not constitute a violation. - Creating AI systems that produce child sexual abuse material, deepfake pornography, or simulate sexual conversations while impersonating children. - Government entities using AI for social scoring or biometric identification of individuals without consent.

Additionally, government bodies making AI systems available to the public must clearly disclose that consumers are interacting with AI.

Enforcement falls to the Texas Attorney General, who can investigate violations and impose civil penalties. Before taking action, the AG must notify alleged violators, providing a 60-day window to respond and potentially remedy the issue. While specific penalty amounts are not defined, the law offers "safe harbor" protections. Businesses can avoid liability if: - Third parties misuse their AI in prohibited ways. - Violations are discovered through good-faith testing or audits. - They substantially comply with recognized standards like the NIST AI Risk Management Framework.

A practical surprise for many is how much TRAIGA differs from more prescriptive laws in other states or the EU. Texas opted for a lighter touch, focusing on clear "red lines" rather than extensive regulatory burdens, making the safe harbor provisions a crucial aspect for compliance.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

Read this article-by-article

Plain-English breakdown of 11 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under United States - Texas - AI Governance Act (HB 149). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJan 1, 2026

    Applies to: Developers and deployers of AI systems in Texas.

    AI systems cannot be developed or deployed to intentionally encourage any person to physically harm themselves or others.
  2. #2CriticalJan 1, 2026

    Applies to: Deployers of AI systems in Texas.

    Prohibits deployment of systems intended to discriminate against protected classes including race, sex, and disability.
  3. #3CriticalJan 1, 2026

    Applies to: Developers and deployers of AI systems in Texas.

    Bans AI systems producing child sexual abuse imagery, deepfake pornography, or engaging in text conversations simulating sexual content while impersonating children.
  4. #4CriticalJan 1, 2026

    Applies to: Government entities in Texas.

    Prohibits government entities from using AI for social scoring or biometric identification of specific individuals without consent.
  5. #5ImportantJan 1, 2026

    Applies to: Government entities making AI systems available to consumers.

    Government entities making AI systems available to consumers must provide clear notice that consumers are interacting with AI.
  6. #6ImportantSep 1, 2025

    Applies to: Healthcare providers using AI for medical diagnosis in Texas.

    requiring licensed practitioners to review AI-generated records according to Texas Medical Board standards.
  7. #7Important

    Applies to: Entities developing or deploying AI systems in Texas.

    maintain documentation sufficient to demonstrate safe harbor eligibility if challenged.
  8. #8Recommended

    Applies to: Entities developing or deploying AI systems in Texas.

    when entities substantially comply with NIST AI Risk Management Framework or similar recognized standards.
  9. #9Recommended

    Applies to: Entities developing or deploying AI systems in Texas.

    when violations are discovered through testing or good faith audits
  10. #10Recommended

    Applies to: Providers of AI systems in Texas.

    Entities not liable when third parties misuse AI in prohibited ways.
  11. #11Recommended

    Applies to: Entities developing or deploying AI systems in Texas.

    Organizations must primarily ensure their AI systems do not fall within prohibited categories.
  12. #12Recommended

    Applies to: Developers of AI systems in Texas.

    providing a controlled environment for AI innovation and experimentation.

© Regulations.AI — created on 12-Jun-2026