United States - Texas - AI Governance Act (HB 149)
Texas HB 149 — Texas Responsible Artificial Intelligence Governance Act (TRAIGA)
United States
RAI-US-TX-TH1TRXX-2025The Texas Responsible Artificial Intelligence Governance Act (HB 149), enacted by the Texas Legislature in 2025, regulates AI developers and deployers in the state by prohibiting harmful system uses and mandating disclosures for state agency AI tools. It took effect on January 1, 2026, and is enforced by the Texas Office of the Attorney General.
Summary
The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), enacted via HB 149 during the 89th Texas Legislative Session, is currently in force. Signed into law by Governor Greg Abbott on June 22, 2025, the Act officially entered into force on January 1, 2026.
TRAIGA regulates developers and deployers of artificial intelligence systems who conduct business in Texas, offer products or services consumed by Texas residents, or develop or deploy AI systems within the state. The statute contains explicit prohibitions against designing or deploying AI systems intended to incite physical self-harm or criminal activity, unlawfully discriminate against protected classes, infringe on constitutional rights, or produce sexually explicit material depicting children. Furthermore, government entities are barred from utilizing AI for social scoring or unconsented biometric identification that infringes upon legal rights.
The Act requires state agencies interacting with consumers via AI tools to provide clear and conspicuous consumer disclosures. TRAIGA also establishes the seven-member Texas Artificial Intelligence Advisory Council under the Department of Information Resources (DIR) to analyze AI governance, conduct agency training programs, and produce policy recommendations, without possessing binding rulemaking authority. In addition, DIR administers a 36-month regulatory sandbox program providing controlled conditions for testing AI innovations.
Exclusive enforcement authority under TRAIGA is granted to the Texas Office of the Attorney General. The Attorney General is empowered to conduct investigations, issue civil investigative demands, and seek civil monetary penalties against non-compliant developers or deployers. Prior to initiating enforcement, the Attorney General must issue a written notice of violation and afford alleged violators a 60-day cure period to correct non-compliance. Safe harbor defenses are available to entities demonstrating compliance with recognized AI frameworks such as the NIST AI Risk Management Framework or addressing third-party system misuse.
Full article
Read full text ↗Overview
The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), codified as HB 149, represents Texas's entry into comprehensive AI governance, making it the third US state after Colorado and Utah to enact such legislation. Signed by Governor Greg Abbott on June 22, 2025, with an effective date of January 1, 2026, the law underwent significant amendments from its original draft. The initial December 2024 version proposed a sweeping regulatory scheme modeled after the Colorado AI Act and EU AI Act, focusing on high-risk AI systems with substantial requirements for developers and deployers. However, March 2025 amendments significantly scaled back the scope, resulting in legislation that establishes foundational prohibitions and governance structures while avoiding prescriptive compliance mandates. This approach reflects Texas's traditionally business-friendly regulatory philosophy while addressing key AI safety concerns. The law applies broadly to parties conducting business in Texas, producing products used by Texas residents, or deploying AI systems within the state, creating significant reach for the nation's second-largest economy.
Definitions
TRAIGA establishes key definitions shaping regulatory scope. Artificial intelligence system means 'any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions or recommendations, that can influence physical or virtual environments.' This broad definition captures most modern AI technologies including generative AI, recommendation systems, and automated decision tools. Consumer means an individual who is a Texas resident 'acting only in an individual or household context,' explicitly excluding employment and commercial uses from consumer protection provisions. This limitation focuses the law on personal consumer interactions rather than workplace AI applications. The law does not extensively define 'high-risk AI systems' as originally proposed, instead focusing prohibitions on specific harmful applications regardless of risk categorization. Consequential decisions—central to the original draft—were largely removed from the enacted version, though healthcare provisions in companion legislation SB 1188 address AI in medical diagnosis contexts.
Governance and Institutional Framework
TRAIGA creates the Texas Artificial Intelligence Advisory Council as the primary governance body. The Council comprises seven qualified members: appointees from the governor, lieutenant governor, and speaker of the house of representatives. The Council's mandate includes conducting AI training programs for state agencies and local governments and issuing reports on AI-related topics including data privacy, security, AI ethics, and legal compliance. Critically, the Council is expressly prohibited from promulgating binding rules or regulations, establishing it as an advisory and educational body rather than a regulatory agency. This structural limitation distinguishes Texas's approach from states with more empowered AI governance bodies. The Texas Attorney General serves as the enforcement authority with power to investigate violations and impose civil penalties. Before initiating enforcement actions, the AG must provide written notice to alleged violators, who then have 60 days to respond. The Department of Information Resources (DIR) administers the 36-month regulatory sandbox in consultation with the AI Council, providing a controlled environment for AI innovation and experimentation. This sandbox model follows approaches used in financial services regulation, allowing developers to test AI applications with reduced regulatory burden.
Key Focus Areas
- Behavioral Manipulation Prohibition: AI systems cannot be developed or deployed to intentionally encourage any person to physically harm themselves or others.
- Anti-Discrimination Requirements: Prohibits deployment of systems intended to discriminate against protected classes including race, sex, and disability; clarifies that disparate impact alone does not establish intent.
- Child Protection: Bans AI systems producing child sexual abuse imagery, deepfake pornography, or engaging in text conversations simulating sexual content while impersonating children.
- Government Social Scoring Ban: Prohibits government entities from using AI for social scoring or biometric identification of specific individuals without consent.
- Consumer Interaction Disclosure: Government entities making AI systems available to consumers must provide clear notice that consumers are interacting with AI.
- Regulatory Sandbox: Establishes 36-month sandbox administered by DIR for controlled AI experimentation with reduced regulatory burden.
- Safe Harbor Provisions: Protects entities following NIST AI Risk Management Framework or similar recognized standards.
- Advisory Council: Creates seven-member council for training and reporting but without rulemaking authority.
- Healthcare AI Integration: Companion legislation SB 1188 addresses AI in medical diagnosis with Texas Medical Board oversight.
- Third-Party Misuse Protection: Entities not liable when third parties misuse AI in prohibited ways.
Implementation Framework
TRAIGA takes effect January 1, 2026, providing approximately six months for compliance preparation from the June 2025 signing. Unlike more prescriptive frameworks like Colorado's SB24-205, TRAIGA's streamlined structure requires less extensive implementation planning. Organizations must primarily ensure their AI systems do not fall within prohibited categories and that government-facing AI applications include required disclosures. The regulatory sandbox provides an alternative compliance pathway for experimental applications, with DIR developing participation criteria and oversight procedures. The AI Advisory Council will develop training programs for government agencies, though the timeline for these programs is not specified. Healthcare AI applications face additional requirements under SB 1188, effective September 1, 2025, requiring licensed practitioners to review AI-generated records according to Texas Medical Board standards. Organizations should evaluate whether they qualify for safe harbor protection through NIST AI RMF compliance or adoption of similar recognized standards. The 60-day notice and response period before AG enforcement actions provides opportunity for compliance remediation before penalties accrue.
Monitoring and Evaluation
TRAIGA does not establish extensive ongoing monitoring requirements comparable to Colorado's impact assessment mandates. The AI Advisory Council may issue reports on various AI topics, providing periodic evaluation of the regulatory landscape. Government entities using AI systems must maintain disclosure capabilities but face no formal reporting obligations to state authorities. The regulatory sandbox inherently includes monitoring of participating entities, with DIR oversight ensuring sandbox activities remain within permitted boundaries. The Attorney General's enforcement authority creates reactive monitoring through complaint investigation and compliance review. Private sector entities benefit from limited affirmative compliance monitoring, though they must maintain documentation sufficient to demonstrate safe harbor eligibility if challenged. Healthcare AI applications under SB 1188 fall under Texas Medical Board oversight, creating sector-specific monitoring for diagnostic AI uses. The Council's prohibition on binding rulemaking limits its ability to establish monitoring frameworks through regulatory action, leaving monitoring largely to AG enforcement discretion and sector-specific regulators.
Penalties, Liability, and Appeals
Enforcement authority rests exclusively with the Texas Attorney General, who may investigate violations and impose civil penalties. The pre-enforcement procedure requires the AG to send written notice of violation to alleged violators, who then have 60 days to respond before the AG can bring an enforcement action. This notice period provides opportunity for compliance remediation and distinguishes Texas's approach from immediate enforcement authority in other states. Civil penalty amounts are not specified in TRAIGA, leaving determination to AG discretion and judicial review. Safe harbors provide affirmative defenses in three circumstances: (1) when third parties misuse AI in ways TRAIGA prohibits; (2) when violations are discovered through testing or good faith audits; and (3) when entities substantially comply with NIST AI Risk Management Framework or similar recognized standards. These safe harbors incentivize proactive compliance efforts and self-monitoring. The third-party misuse protection is particularly significant for platform operators whose AI tools might be weaponized by users. Healthcare AI violations under SB 1188 fall under Texas Medical Board enforcement jurisdiction with profession-specific penalties. Appeals from AG enforcement actions follow standard administrative and judicial review procedures.
Relationship to Other Instruments
TRAIGA joins the emerging patchwork of US state AI legislation, with Colorado's SB24-205 and Utah's SB 149 providing the primary comparison points. Colorado's law is substantially more prescriptive, requiring impact assessments, consumer disclosures, and comprehensive documentation for high-risk AI systems. Utah's approach, like Texas's, is more permissive and innovation-oriented. TRAIGA's original draft closely followed the EU AI Act and Colorado model, but amendments produced a distinctly lighter-touch framework. The law explicitly accommodates federal standards through its safe harbor for NIST AI RMF compliance, creating alignment with federal AI governance direction. Texas companion legislation SB 1188 addresses healthcare AI specifically, integrating with existing Texas Medical Board authority rather than creating new AI-specific oversight. At the federal level, the potential 'One Big Beautiful Bill' moratorium on state AI laws, passed by the House in May 2025, could preempt TRAIGA if enacted, though Senate passage remains uncertain. TRAIGA's consumer focus distinguishes it from employment-focused state laws like Illinois's AI Video Interview Act and California's employment algorithmic decision proposals.
International Alignment
TRAIGA shows limited direct alignment with international AI frameworks, reflecting its scaled-back scope from the original EU AI Act-inspired draft. The European Union AI Act's risk-based categorization system influenced early TRAIGA drafts but was largely abandoned in final legislation. The prohibition on social scoring by government entities mirrors EU AI Act Article 5 prohibited practices, representing one area of transatlantic convergence. Consumer disclosure requirements align with emerging international transparency norms, though Texas's requirements apply only to government-deployed AI. The NIST AI RMF safe harbor creates indirect international alignment, as NIST standards inform and are informed by ISO/IEC AI governance standards used globally. Texas's sandbox approach follows international precedent from Singapore, UAE, and EU member states that have used regulatory sandboxes to foster AI innovation. The law's anti-discrimination provisions align with international human rights frameworks addressing AI bias, though the intent requirement (rather than disparate impact) represents a more permissive standard than some international approaches. Texas's market significance may drive international companies to consider TRAIGA compliance as part of US market access strategies.
Implementation Timeline
| Date | Milestone |
|---|---|
| December 2024 | Original HB 149 introduced with comprehensive EU-style requirements |
| March 2025 | Significant amendments scale back bill scope |
| May 2025 | House passes moratorium proposal potentially preempting state AI laws |
| June 20, 2025 | Companion healthcare AI bill SB 1188 signed |
| June 22, 2025 | Governor Abbott signs TRAIGA into law |
| September 1, 2025 | Healthcare AI provisions (SB 1188) take effect |
| January 1, 2026 | TRAIGA takes full effect |
| 2026-2029 | 36-month regulatory sandbox operational period |
Sources and References
| Source | Type |
|---|---|
| HB 149 Bill Page - Texas Legislature | Primary Source |
| HB 149 Bill Analysis | Primary Source |
| NIST AI Risk Management Framework | Safe Harbor Standard |
| Texas Attorney General | Enforcement Authority |
Read this article-by-article
Plain-English breakdown of 11 key articles, with cross-jurisdiction equivalents where applicable.
Requirements for a company
What an organisation has to do under United States - Texas - AI Governance Act (HB 149), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
2- Ensure licensed healthcare practitioners review AI-generated diagnostic records in compliance with Texas Medical Board standards.Healthcare providers and practitioners in Texas
- Provide clear notice to consumers when they are interacting with government-provided AI systems.Government entities in Texas providing AI to consumers
Must not do
4- Do not develop or deploy AI systems designed to intentionally encourage self-harm or physical harm to others.Entities developing or deploying AI systems in Texas
- Never create AI systems producing child sexual abuse material, deepfake pornography, or sexualized text conversations impersonating children.Entities developing or deploying AI systems in Texas
- Do not deploy AI systems intended to discriminate against protected classes including race, sex, or disability.Entities deploying AI systems in Texas
- Do not use AI for social scoring or non-consensual biometric identification of specific individuals.Government entities in Texas
Should do
2- Align AI governance practices with the NIST AI Risk Management Framework to qualify for statutory safe harbor protection.Entities developing or deploying AI systems in Texas
- Perform regular testing and good faith audits on AI systems to identify violations and secure safe harbor protection.Entities developing or deploying AI systems in Texas
Should not do
0Nothing in this category.
Who must do what
The obligations under United States - Texas - AI Governance Act (HB 149), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Entities developing or deploying AI systems in Texas | Do not develop or deploy AI systems designed to intentionally encourage self-harm or physical harm to others. “AI systems cannot be developed or deployed to intentionally encourage any person to physically harm themselves or others.” | Jan 1, 2026 | — | Critical |
| 2 | Entities developing or deploying AI systems in Texas | Never create AI systems producing child sexual abuse material, deepfake pornography, or sexualized text conversations impersonating children. “Bans AI systems producing child sexual abuse imagery, deepfake pornography, or engaging in text conversations simulating sexual content while impersonating children.” | Jan 1, 2026 | — | Critical |
| 3 | Entities deploying AI systems in Texas | Do not deploy AI systems intended to discriminate against protected classes including race, sex, or disability. “Prohibits deployment of systems intended to discriminate against protected classes including race, sex, and disability” | Jan 1, 2026 | — | Critical |
| 4 | Government entities in Texas | Do not use AI for social scoring or non-consensual biometric identification of specific individuals. “Prohibits government entities from using AI for social scoring or biometric identification of specific individuals without consent.” | Jan 1, 2026 | — | Critical |
| 5 | Healthcare providers and practitioners in Texas | Ensure licensed healthcare practitioners review AI-generated diagnostic records in compliance with Texas Medical Board standards. “requiring licensed practitioners to review AI-generated records according to Texas Medical Board standards.” | Sep 1, 2025 | — | Critical |
| 6 | Government entities in Texas providing AI to consumers | Provide clear notice to consumers when they are interacting with government-provided AI systems. “Government entities making AI systems available to consumers must provide clear notice that consumers are interacting with AI.” | Jan 1, 2026 | — | Important |
| 7 | Entities developing or deploying AI systems in Texas | Align AI governance practices with the NIST AI Risk Management Framework to qualify for statutory safe harbor protection. “when entities substantially comply with NIST AI Risk Management Framework or similar recognized standards.” | — | — | Recommended |
| 8 | Entities developing or deploying AI systems in Texas | Perform regular testing and good faith audits on AI systems to identify violations and secure safe harbor protection. “when violations are discovered through testing or good faith audits” | — | — | Recommended |
Related Regulations
United States - Texas - AI Advisory Council (HB 2060)
United States92% similar
United States - Utah - AI Policy Act (SB 149)
United States90% similar
Connecticut AI Responsibility and Transparency Act
United States89% similar
TRUMP AI Act (Federal AI Preemption)
United States89% similar
United States - Colorado - AI Consumer Protections (SB24-205)
United States89% similar
United States - Utah - AI Consumer Protection (SB 226)
United States88% similar
United States - New York - AI Safety Act (RAISE Act)
United States88% similar
United States - California - AI Transparency Act (SB 53)
United States88% similar
© Regulations.AI · reviewed against official sources on 09-Sep-2026 using Gemini 3.6 Flash