August 19, 2026

9 min read

What TRAIGA Actually Requires From AI Buyers and Vendors in Texas

What TRAIGA Is, and Why It's Already in Effect

The Texas Responsible Artificial Intelligence Governance Act, better known as TRAIGA or House Bill 149, has been enforceable law since January 1, 2026. Governor Greg Abbott signed it on June 22, 2025 (DLA Piper), and the Texas Attorney General now holds exclusive authority to enforce it against companies that develop or deploy AI systems touching Texas consumers, employees, or government agencies (Texas AG, Consumer AI Rights). Most companies subject to it don't know that yet. As of May 2026, Duane Morris reported that the AG's office was still building out its formal complaint infrastructure, months after the law took effect (Duane Morris). That's a strange but common pattern with state AI law: the statute goes live quietly, enforcement machinery lags, and companies assume they have more runway than they actually do. If you're selling into Texas, employing people there, or running AI systems that make decisions about Texas residents, the runway is already gone. This matters because TRAIGA is not a distant compliance deadline you can schedule around, the way you might with the EU AI Act's phased rollout (we cover that timeline in what the EU AI Act's August 2026 deadline means for US and Singapore companies). It's live now, with an AG who can already open an investigation.

Does TRAIGA Apply to Your Company?

TRAIGA applies if you develop or deploy an AI system that interacts with Texas consumers, employees, or state government entities, regardless of where your company is headquartered. There's no revenue threshold that exempts a mid-market company, and there's no carve-out for using a third-party vendor's model instead of building your own.

The law distinguishes between "developers" (companies that build or substantially modify an AI system) and "deployers" (companies that put an AI system into use, including SaaS customers who configure a vendor tool for their own workflows). Both roles carry obligations, though developers carry more. If you're a $20M revenue operations company using a vendor's AI-powered applicant screening tool to filter candidates for Texas roles, you're a deployer under this law even though you didn't write a line of the underlying model. That single fact catches a lot of operators off guard, because the instinct is to assume "we bought this off the shelf, so it's the vendor's problem." Under TRAIGA, it's yours too.

What TRAIGA Actually Prohibits

TRAIGA does not require a broad risk-management program or algorithmic impact assessments the way Colorado's law does. It bans five specific practices, and everything else is, in effect, permitted. That's the core design choice that separates it from most state AI legislation, and it's worth sitting with because it changes what "compliant" actually means.

The five prohibited practices, per Greenberg Traurig's provision breakdown (GT Law), are:

  • Building or deploying an AI system with the intent to unlawfully discriminate against a protected class. Critically, disparate impact alone does not establish intent under TRAIGA. A model that produces statistically uneven outcomes across a protected class isn't automatically a violation; the AG has to show the system was built or used with discriminatory intent.

  • Government use of AI for social-scoring systems that result in unfavorable treatment of individuals based on that score.

  • AI systems designed to incite self-harm, violence, or criminal activity.

  • Capturing biometric identifiers through AI without consent, including untargeted scraping of faceprints or voiceprints.

  • Using AI to generate unlawful deepfakes or to impersonate minors, including in child sexual abuse material contexts.

The "intent" standard on the discrimination ban is the single most consequential detail in the entire law, and it's the part general-counsel client alerts explain accurately but don't translate into an operational answer. Intent is proven or disproven largely through documentation: what your team knew when it built or configured a decision system, what testing it ran, what it changed in response to findings. A company that never tested its hiring model for adverse impact and has no record of that testing is in a worse position defending an intent claim than a company that tested, found a gap, and can show it acted. Ironically, doing the disparate-impact analysis Colorado would require you to do anyway is also your best defense under Texas's narrower, intent-based standard.

How TRAIGA Differs from Colorado's AI Act

TRAIGA and Colorado's AI Act solve the same political problem with almost opposite mechanisms, and if your company operates in both states, understanding that difference is what keeps you from building two redundant compliance programs. Colorado's law (SB 205) requires developers and deployers of "high-risk AI systems" involved in "consequential decisions" (employment, lending, housing, healthcare, insurance, legal services) to run a documented risk-management program and impact assessments before and after deployment. It's a broad, ongoing governance obligation. We break down that model in detail in our Colorado AI Act compliance guide, including why its effective date has moved more than once.

TRAIGA takes the opposite approach: no mandatory risk-management program, no impact assessments required by statute, just a short list of banned practices with an intent-based standard. Ogletree's analysis confirms Texas is only the second state after Colorado to pass comprehensive AI legislation, and the contrast in design is deliberate (Ogletree). Texas lawmakers explicitly narrowed an earlier, broader draft of the bill (referred to in some alerts as "TRAIGA 2.0") before passage, trading breadth for a lighter, prohibition-only touch.

For a multi-state company, the practical takeaway is this: build to Colorado's standard, because it's the stricter bar, and TRAIGA compliance mostly falls out of it. A documented risk-management process, testing records, and impact assessments satisfy Colorado's affirmative requirements and simultaneously give you the paper trail that defeats a TRAIGA intent claim. Building to TRAIGA's minimum and hoping it covers Colorado does not work in reverse.

Who Enforces TRAIGA and What Happens If You Violate It

Enforcement sits exclusively with the Texas Attorney General; there is no private right of action, so individual consumers cannot sue your company directly under this statute (Texas AG). Several law-firm alerts reference a cure period before civil penalties apply, giving companies a window to fix a violation once notified rather than facing immediate liability. Given that specific penalty dollar amounts and the exact cure-period length vary across secondary sources, verify the current figures directly against the bill text at capitol.texas.gov or a recent law-firm summary before you rely on a specific number in a board memo.

The law also includes a regulatory sandbox program, letting companies test AI systems under state oversight with some liability protection, structured similarly to fintech regulatory sandboxes. If you're building something genuinely novel and Texas-facing, that's worth investigating before you assume you need to slow down or avoid the state entirely.

What This Means for Your AI Vendor Contracts and Build-vs-Buy Decisions

A black-box vendor tool makes the intent defense harder, not easier, because you can't produce documentation you never had access to. If your applicant-screening vendor won't tell you how their model weighs inputs, or won't let you run your own testing against your own applicant data, you're stuck defending an intent claim with someone else's evidence, or with no evidence at all. That's the opposite of where you want to be if the AG ever opens an inquiry.

This is where we'd push back on the instinct to just buy a compliance-branded SaaS layer and call it done. Owning your AI architecture, or at minimum having contractual rights to your vendor's testing data and model documentation, is what lets you actually answer an intent question when it's asked. We built the full AI stack for a PropTech client, Flow Intelligence, after two previous vendor relationships failed to deliver something the client could inspect or control (case study); the client now owns 100% of that IP, which means they also own the documentation trail if a regulator ever asks how a decision was made. That's not a TRAIGA-specific argument. It's the same reason we tell clients to be wary of any AI vendor contract that treats model logic as a trade secret you're not allowed to see.

Before you sign anything with a new AI vendor for a Texas-facing workflow, get answers to what data trained or fine-tuned the system, what testing the vendor ran for disparate outcomes across protected classes, whether you have contractual rights to that testing data, and who owns liability if the AG opens an inquiry. Our AI vendor risk assessment checklist walks through the fuller version of this before-you-sign conversation, and it applies whether the trigger is TRAIGA, Colorado, or a customer contract that requires SOC 2.

A Practical Compliance Checklist for Companies Deploying AI in Texas

Skip the twelve-page policy document. Here's the version an operations or compliance lead can actually work through this week:

  1. Inventory every AI system touching Texas consumers, employees, or applicants, including vendor tools your team configured but didn't build.

  2. For each system involved in a consequential decision (hiring, lending, insurance, healthcare, legal outcomes), document what testing has been run for discriminatory outcomes and when.

  3. Get in writing, from every AI vendor, what data trained the model and what disparate-impact testing they've done, and whether you have audit rights.

  4. Check your biometric data practices specifically: any facial recognition, voiceprint, or fingerprint capture needs documented consent, not just a line buried in a terms-of-service page.

  5. Set up a documented process for what happens when someone flags a concerning output, who reviews it, what gets fixed, and how that fix gets recorded. This is your intent defense if it's ever needed.

  6. If you operate in both Texas and Colorado, build your governance program to Colorado's stricter risk-management standard first; treat TRAIGA compliance as a byproduct, not a separate workstream.

  7. Loop in whoever owns AI governance internally, or borrow the structure from the enterprise AI agent governance framework we use with clients, even if you don't have a dedicated AI team yet.

None of this requires hiring outside counsel to get started, though counsel should review anything before you rely on it in a dispute. What it requires is someone in the company actually owning the answer to "can we prove what this system does and why," before the AG's office asks.

If you're weighing whether to build this governance layer in-house, retrofit it onto a vendor relationship, or rethink the underlying architecture entirely, that's precisely the kind of diagnosis we run before recommending anything, and our enterprise AI work usually starts there, not with a build recommendation.

Frequently asked questions

What are the new AI laws in Texas?

The main one is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, House Bill 149), signed June 22, 2025 and effective since January 1, 2026. It bans five specific practices, including intentional discrimination by AI systems, government social scoring, self-harm-inciting AI, unauthorized biometric capture, and unlawful deepfakes, with enforcement handled exclusively by the Texas Attorney General.

What are the changes in Texas' AI law in 2026?

TRAIGA became enforceable on January 1, 2026, after being signed the previous June. The Attorney General's complaint infrastructure was still being finalized months after that date, per Duane Morris, meaning many companies already subject to the law may not realize enforcement is active now rather than pending.

Does TRAIGA apply to my company if we're not based in Texas?

Yes, if your AI system interacts with Texas consumers, employees, or government agencies. Headquarters location doesn't matter. If you use a vendor's AI tool configured for Texas-facing hiring, lending, or customer decisions, you're a "deployer" under the law even if you didn't build the underlying model.

What's the difference between TRAIGA and Colorado's AI Act?

Colorado requires an ongoing risk-management program and impact assessments for high-risk AI systems making consequential decisions. TRAIGA bans a narrow list of specific practices instead, using an intent-based standard for its discrimination ban rather than requiring proactive risk assessments. Building to Colorado's standard generally satisfies TRAIGA; the reverse isn't true.

Is there a private right of action under TRAIGA, or can only the state sue?

Only the Texas Attorney General can enforce TRAIGA. There is no private right of action, so individual consumers can't bring a lawsuit directly against your company under this statute, though a cure period reportedly applies before civil penalties attach once the AG notifies a company of a violation.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

August 19, 2026

9 min read

What TRAIGA Actually Requires From AI Buyers and Vendors in Texas

What TRAIGA Is, and Why It's Already in Effect

The Texas Responsible Artificial Intelligence Governance Act, better known as TRAIGA or House Bill 149, has been enforceable law since January 1, 2026. Governor Greg Abbott signed it on June 22, 2025 (DLA Piper), and the Texas Attorney General now holds exclusive authority to enforce it against companies that develop or deploy AI systems touching Texas consumers, employees, or government agencies (Texas AG, Consumer AI Rights). Most companies subject to it don't know that yet. As of May 2026, Duane Morris reported that the AG's office was still building out its formal complaint infrastructure, months after the law took effect (Duane Morris). That's a strange but common pattern with state AI law: the statute goes live quietly, enforcement machinery lags, and companies assume they have more runway than they actually do. If you're selling into Texas, employing people there, or running AI systems that make decisions about Texas residents, the runway is already gone. This matters because TRAIGA is not a distant compliance deadline you can schedule around, the way you might with the EU AI Act's phased rollout (we cover that timeline in what the EU AI Act's August 2026 deadline means for US and Singapore companies). It's live now, with an AG who can already open an investigation.

Does TRAIGA Apply to Your Company?

TRAIGA applies if you develop or deploy an AI system that interacts with Texas consumers, employees, or state government entities, regardless of where your company is headquartered. There's no revenue threshold that exempts a mid-market company, and there's no carve-out for using a third-party vendor's model instead of building your own.

The law distinguishes between "developers" (companies that build or substantially modify an AI system) and "deployers" (companies that put an AI system into use, including SaaS customers who configure a vendor tool for their own workflows). Both roles carry obligations, though developers carry more. If you're a $20M revenue operations company using a vendor's AI-powered applicant screening tool to filter candidates for Texas roles, you're a deployer under this law even though you didn't write a line of the underlying model. That single fact catches a lot of operators off guard, because the instinct is to assume "we bought this off the shelf, so it's the vendor's problem." Under TRAIGA, it's yours too.

What TRAIGA Actually Prohibits

TRAIGA does not require a broad risk-management program or algorithmic impact assessments the way Colorado's law does. It bans five specific practices, and everything else is, in effect, permitted. That's the core design choice that separates it from most state AI legislation, and it's worth sitting with because it changes what "compliant" actually means.

The five prohibited practices, per Greenberg Traurig's provision breakdown (GT Law), are:

  • Building or deploying an AI system with the intent to unlawfully discriminate against a protected class. Critically, disparate impact alone does not establish intent under TRAIGA. A model that produces statistically uneven outcomes across a protected class isn't automatically a violation; the AG has to show the system was built or used with discriminatory intent.

  • Government use of AI for social-scoring systems that result in unfavorable treatment of individuals based on that score.

  • AI systems designed to incite self-harm, violence, or criminal activity.

  • Capturing biometric identifiers through AI without consent, including untargeted scraping of faceprints or voiceprints.

  • Using AI to generate unlawful deepfakes or to impersonate minors, including in child sexual abuse material contexts.

The "intent" standard on the discrimination ban is the single most consequential detail in the entire law, and it's the part general-counsel client alerts explain accurately but don't translate into an operational answer. Intent is proven or disproven largely through documentation: what your team knew when it built or configured a decision system, what testing it ran, what it changed in response to findings. A company that never tested its hiring model for adverse impact and has no record of that testing is in a worse position defending an intent claim than a company that tested, found a gap, and can show it acted. Ironically, doing the disparate-impact analysis Colorado would require you to do anyway is also your best defense under Texas's narrower, intent-based standard.

How TRAIGA Differs from Colorado's AI Act

TRAIGA and Colorado's AI Act solve the same political problem with almost opposite mechanisms, and if your company operates in both states, understanding that difference is what keeps you from building two redundant compliance programs. Colorado's law (SB 205) requires developers and deployers of "high-risk AI systems" involved in "consequential decisions" (employment, lending, housing, healthcare, insurance, legal services) to run a documented risk-management program and impact assessments before and after deployment. It's a broad, ongoing governance obligation. We break down that model in detail in our Colorado AI Act compliance guide, including why its effective date has moved more than once.

TRAIGA takes the opposite approach: no mandatory risk-management program, no impact assessments required by statute, just a short list of banned practices with an intent-based standard. Ogletree's analysis confirms Texas is only the second state after Colorado to pass comprehensive AI legislation, and the contrast in design is deliberate (Ogletree). Texas lawmakers explicitly narrowed an earlier, broader draft of the bill (referred to in some alerts as "TRAIGA 2.0") before passage, trading breadth for a lighter, prohibition-only touch.

For a multi-state company, the practical takeaway is this: build to Colorado's standard, because it's the stricter bar, and TRAIGA compliance mostly falls out of it. A documented risk-management process, testing records, and impact assessments satisfy Colorado's affirmative requirements and simultaneously give you the paper trail that defeats a TRAIGA intent claim. Building to TRAIGA's minimum and hoping it covers Colorado does not work in reverse.

Who Enforces TRAIGA and What Happens If You Violate It

Enforcement sits exclusively with the Texas Attorney General; there is no private right of action, so individual consumers cannot sue your company directly under this statute (Texas AG). Several law-firm alerts reference a cure period before civil penalties apply, giving companies a window to fix a violation once notified rather than facing immediate liability. Given that specific penalty dollar amounts and the exact cure-period length vary across secondary sources, verify the current figures directly against the bill text at capitol.texas.gov or a recent law-firm summary before you rely on a specific number in a board memo.

The law also includes a regulatory sandbox program, letting companies test AI systems under state oversight with some liability protection, structured similarly to fintech regulatory sandboxes. If you're building something genuinely novel and Texas-facing, that's worth investigating before you assume you need to slow down or avoid the state entirely.

What This Means for Your AI Vendor Contracts and Build-vs-Buy Decisions

A black-box vendor tool makes the intent defense harder, not easier, because you can't produce documentation you never had access to. If your applicant-screening vendor won't tell you how their model weighs inputs, or won't let you run your own testing against your own applicant data, you're stuck defending an intent claim with someone else's evidence, or with no evidence at all. That's the opposite of where you want to be if the AG ever opens an inquiry.

This is where we'd push back on the instinct to just buy a compliance-branded SaaS layer and call it done. Owning your AI architecture, or at minimum having contractual rights to your vendor's testing data and model documentation, is what lets you actually answer an intent question when it's asked. We built the full AI stack for a PropTech client, Flow Intelligence, after two previous vendor relationships failed to deliver something the client could inspect or control (case study); the client now owns 100% of that IP, which means they also own the documentation trail if a regulator ever asks how a decision was made. That's not a TRAIGA-specific argument. It's the same reason we tell clients to be wary of any AI vendor contract that treats model logic as a trade secret you're not allowed to see.

Before you sign anything with a new AI vendor for a Texas-facing workflow, get answers to what data trained or fine-tuned the system, what testing the vendor ran for disparate outcomes across protected classes, whether you have contractual rights to that testing data, and who owns liability if the AG opens an inquiry. Our AI vendor risk assessment checklist walks through the fuller version of this before-you-sign conversation, and it applies whether the trigger is TRAIGA, Colorado, or a customer contract that requires SOC 2.

A Practical Compliance Checklist for Companies Deploying AI in Texas

Skip the twelve-page policy document. Here's the version an operations or compliance lead can actually work through this week:

  1. Inventory every AI system touching Texas consumers, employees, or applicants, including vendor tools your team configured but didn't build.

  2. For each system involved in a consequential decision (hiring, lending, insurance, healthcare, legal outcomes), document what testing has been run for discriminatory outcomes and when.

  3. Get in writing, from every AI vendor, what data trained the model and what disparate-impact testing they've done, and whether you have audit rights.

  4. Check your biometric data practices specifically: any facial recognition, voiceprint, or fingerprint capture needs documented consent, not just a line buried in a terms-of-service page.

  5. Set up a documented process for what happens when someone flags a concerning output, who reviews it, what gets fixed, and how that fix gets recorded. This is your intent defense if it's ever needed.

  6. If you operate in both Texas and Colorado, build your governance program to Colorado's stricter risk-management standard first; treat TRAIGA compliance as a byproduct, not a separate workstream.

  7. Loop in whoever owns AI governance internally, or borrow the structure from the enterprise AI agent governance framework we use with clients, even if you don't have a dedicated AI team yet.

None of this requires hiring outside counsel to get started, though counsel should review anything before you rely on it in a dispute. What it requires is someone in the company actually owning the answer to "can we prove what this system does and why," before the AG's office asks.

If you're weighing whether to build this governance layer in-house, retrofit it onto a vendor relationship, or rethink the underlying architecture entirely, that's precisely the kind of diagnosis we run before recommending anything, and our enterprise AI work usually starts there, not with a build recommendation.

Frequently asked questions

What are the new AI laws in Texas?

The main one is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, House Bill 149), signed June 22, 2025 and effective since January 1, 2026. It bans five specific practices, including intentional discrimination by AI systems, government social scoring, self-harm-inciting AI, unauthorized biometric capture, and unlawful deepfakes, with enforcement handled exclusively by the Texas Attorney General.

What are the changes in Texas' AI law in 2026?

TRAIGA became enforceable on January 1, 2026, after being signed the previous June. The Attorney General's complaint infrastructure was still being finalized months after that date, per Duane Morris, meaning many companies already subject to the law may not realize enforcement is active now rather than pending.

Does TRAIGA apply to my company if we're not based in Texas?

Yes, if your AI system interacts with Texas consumers, employees, or government agencies. Headquarters location doesn't matter. If you use a vendor's AI tool configured for Texas-facing hiring, lending, or customer decisions, you're a "deployer" under the law even if you didn't build the underlying model.

What's the difference between TRAIGA and Colorado's AI Act?

Colorado requires an ongoing risk-management program and impact assessments for high-risk AI systems making consequential decisions. TRAIGA bans a narrow list of specific practices instead, using an intent-based standard for its discrimination ban rather than requiring proactive risk assessments. Building to Colorado's standard generally satisfies TRAIGA; the reverse isn't true.

Is there a private right of action under TRAIGA, or can only the state sue?

Only the Texas Attorney General can enforce TRAIGA. There is no private right of action, so individual consumers can't bring a lawsuit directly against your company under this statute, though a cure period reportedly applies before civil penalties attach once the AG notifies a company of a violation.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

August 19, 2026

9 min read

What TRAIGA Actually Requires From AI Buyers and Vendors in Texas

What TRAIGA Is, and Why It's Already in Effect

The Texas Responsible Artificial Intelligence Governance Act, better known as TRAIGA or House Bill 149, has been enforceable law since January 1, 2026. Governor Greg Abbott signed it on June 22, 2025 (DLA Piper), and the Texas Attorney General now holds exclusive authority to enforce it against companies that develop or deploy AI systems touching Texas consumers, employees, or government agencies (Texas AG, Consumer AI Rights). Most companies subject to it don't know that yet. As of May 2026, Duane Morris reported that the AG's office was still building out its formal complaint infrastructure, months after the law took effect (Duane Morris). That's a strange but common pattern with state AI law: the statute goes live quietly, enforcement machinery lags, and companies assume they have more runway than they actually do. If you're selling into Texas, employing people there, or running AI systems that make decisions about Texas residents, the runway is already gone. This matters because TRAIGA is not a distant compliance deadline you can schedule around, the way you might with the EU AI Act's phased rollout (we cover that timeline in what the EU AI Act's August 2026 deadline means for US and Singapore companies). It's live now, with an AG who can already open an investigation.

Does TRAIGA Apply to Your Company?

TRAIGA applies if you develop or deploy an AI system that interacts with Texas consumers, employees, or state government entities, regardless of where your company is headquartered. There's no revenue threshold that exempts a mid-market company, and there's no carve-out for using a third-party vendor's model instead of building your own.

The law distinguishes between "developers" (companies that build or substantially modify an AI system) and "deployers" (companies that put an AI system into use, including SaaS customers who configure a vendor tool for their own workflows). Both roles carry obligations, though developers carry more. If you're a $20M revenue operations company using a vendor's AI-powered applicant screening tool to filter candidates for Texas roles, you're a deployer under this law even though you didn't write a line of the underlying model. That single fact catches a lot of operators off guard, because the instinct is to assume "we bought this off the shelf, so it's the vendor's problem." Under TRAIGA, it's yours too.

What TRAIGA Actually Prohibits

TRAIGA does not require a broad risk-management program or algorithmic impact assessments the way Colorado's law does. It bans five specific practices, and everything else is, in effect, permitted. That's the core design choice that separates it from most state AI legislation, and it's worth sitting with because it changes what "compliant" actually means.

The five prohibited practices, per Greenberg Traurig's provision breakdown (GT Law), are:

  • Building or deploying an AI system with the intent to unlawfully discriminate against a protected class. Critically, disparate impact alone does not establish intent under TRAIGA. A model that produces statistically uneven outcomes across a protected class isn't automatically a violation; the AG has to show the system was built or used with discriminatory intent.

  • Government use of AI for social-scoring systems that result in unfavorable treatment of individuals based on that score.

  • AI systems designed to incite self-harm, violence, or criminal activity.

  • Capturing biometric identifiers through AI without consent, including untargeted scraping of faceprints or voiceprints.

  • Using AI to generate unlawful deepfakes or to impersonate minors, including in child sexual abuse material contexts.

The "intent" standard on the discrimination ban is the single most consequential detail in the entire law, and it's the part general-counsel client alerts explain accurately but don't translate into an operational answer. Intent is proven or disproven largely through documentation: what your team knew when it built or configured a decision system, what testing it ran, what it changed in response to findings. A company that never tested its hiring model for adverse impact and has no record of that testing is in a worse position defending an intent claim than a company that tested, found a gap, and can show it acted. Ironically, doing the disparate-impact analysis Colorado would require you to do anyway is also your best defense under Texas's narrower, intent-based standard.

How TRAIGA Differs from Colorado's AI Act

TRAIGA and Colorado's AI Act solve the same political problem with almost opposite mechanisms, and if your company operates in both states, understanding that difference is what keeps you from building two redundant compliance programs. Colorado's law (SB 205) requires developers and deployers of "high-risk AI systems" involved in "consequential decisions" (employment, lending, housing, healthcare, insurance, legal services) to run a documented risk-management program and impact assessments before and after deployment. It's a broad, ongoing governance obligation. We break down that model in detail in our Colorado AI Act compliance guide, including why its effective date has moved more than once.

TRAIGA takes the opposite approach: no mandatory risk-management program, no impact assessments required by statute, just a short list of banned practices with an intent-based standard. Ogletree's analysis confirms Texas is only the second state after Colorado to pass comprehensive AI legislation, and the contrast in design is deliberate (Ogletree). Texas lawmakers explicitly narrowed an earlier, broader draft of the bill (referred to in some alerts as "TRAIGA 2.0") before passage, trading breadth for a lighter, prohibition-only touch.

For a multi-state company, the practical takeaway is this: build to Colorado's standard, because it's the stricter bar, and TRAIGA compliance mostly falls out of it. A documented risk-management process, testing records, and impact assessments satisfy Colorado's affirmative requirements and simultaneously give you the paper trail that defeats a TRAIGA intent claim. Building to TRAIGA's minimum and hoping it covers Colorado does not work in reverse.

Who Enforces TRAIGA and What Happens If You Violate It

Enforcement sits exclusively with the Texas Attorney General; there is no private right of action, so individual consumers cannot sue your company directly under this statute (Texas AG). Several law-firm alerts reference a cure period before civil penalties apply, giving companies a window to fix a violation once notified rather than facing immediate liability. Given that specific penalty dollar amounts and the exact cure-period length vary across secondary sources, verify the current figures directly against the bill text at capitol.texas.gov or a recent law-firm summary before you rely on a specific number in a board memo.

The law also includes a regulatory sandbox program, letting companies test AI systems under state oversight with some liability protection, structured similarly to fintech regulatory sandboxes. If you're building something genuinely novel and Texas-facing, that's worth investigating before you assume you need to slow down or avoid the state entirely.

What This Means for Your AI Vendor Contracts and Build-vs-Buy Decisions

A black-box vendor tool makes the intent defense harder, not easier, because you can't produce documentation you never had access to. If your applicant-screening vendor won't tell you how their model weighs inputs, or won't let you run your own testing against your own applicant data, you're stuck defending an intent claim with someone else's evidence, or with no evidence at all. That's the opposite of where you want to be if the AG ever opens an inquiry.

This is where we'd push back on the instinct to just buy a compliance-branded SaaS layer and call it done. Owning your AI architecture, or at minimum having contractual rights to your vendor's testing data and model documentation, is what lets you actually answer an intent question when it's asked. We built the full AI stack for a PropTech client, Flow Intelligence, after two previous vendor relationships failed to deliver something the client could inspect or control (case study); the client now owns 100% of that IP, which means they also own the documentation trail if a regulator ever asks how a decision was made. That's not a TRAIGA-specific argument. It's the same reason we tell clients to be wary of any AI vendor contract that treats model logic as a trade secret you're not allowed to see.

Before you sign anything with a new AI vendor for a Texas-facing workflow, get answers to what data trained or fine-tuned the system, what testing the vendor ran for disparate outcomes across protected classes, whether you have contractual rights to that testing data, and who owns liability if the AG opens an inquiry. Our AI vendor risk assessment checklist walks through the fuller version of this before-you-sign conversation, and it applies whether the trigger is TRAIGA, Colorado, or a customer contract that requires SOC 2.

A Practical Compliance Checklist for Companies Deploying AI in Texas

Skip the twelve-page policy document. Here's the version an operations or compliance lead can actually work through this week:

  1. Inventory every AI system touching Texas consumers, employees, or applicants, including vendor tools your team configured but didn't build.

  2. For each system involved in a consequential decision (hiring, lending, insurance, healthcare, legal outcomes), document what testing has been run for discriminatory outcomes and when.

  3. Get in writing, from every AI vendor, what data trained the model and what disparate-impact testing they've done, and whether you have audit rights.

  4. Check your biometric data practices specifically: any facial recognition, voiceprint, or fingerprint capture needs documented consent, not just a line buried in a terms-of-service page.

  5. Set up a documented process for what happens when someone flags a concerning output, who reviews it, what gets fixed, and how that fix gets recorded. This is your intent defense if it's ever needed.

  6. If you operate in both Texas and Colorado, build your governance program to Colorado's stricter risk-management standard first; treat TRAIGA compliance as a byproduct, not a separate workstream.

  7. Loop in whoever owns AI governance internally, or borrow the structure from the enterprise AI agent governance framework we use with clients, even if you don't have a dedicated AI team yet.

None of this requires hiring outside counsel to get started, though counsel should review anything before you rely on it in a dispute. What it requires is someone in the company actually owning the answer to "can we prove what this system does and why," before the AG's office asks.

If you're weighing whether to build this governance layer in-house, retrofit it onto a vendor relationship, or rethink the underlying architecture entirely, that's precisely the kind of diagnosis we run before recommending anything, and our enterprise AI work usually starts there, not with a build recommendation.

Frequently asked questions

What are the new AI laws in Texas?

The main one is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, House Bill 149), signed June 22, 2025 and effective since January 1, 2026. It bans five specific practices, including intentional discrimination by AI systems, government social scoring, self-harm-inciting AI, unauthorized biometric capture, and unlawful deepfakes, with enforcement handled exclusively by the Texas Attorney General.

What are the changes in Texas' AI law in 2026?

TRAIGA became enforceable on January 1, 2026, after being signed the previous June. The Attorney General's complaint infrastructure was still being finalized months after that date, per Duane Morris, meaning many companies already subject to the law may not realize enforcement is active now rather than pending.

Does TRAIGA apply to my company if we're not based in Texas?

Yes, if your AI system interacts with Texas consumers, employees, or government agencies. Headquarters location doesn't matter. If you use a vendor's AI tool configured for Texas-facing hiring, lending, or customer decisions, you're a "deployer" under the law even if you didn't build the underlying model.

What's the difference between TRAIGA and Colorado's AI Act?

Colorado requires an ongoing risk-management program and impact assessments for high-risk AI systems making consequential decisions. TRAIGA bans a narrow list of specific practices instead, using an intent-based standard for its discrimination ban rather than requiring proactive risk assessments. Building to Colorado's standard generally satisfies TRAIGA; the reverse isn't true.

Is there a private right of action under TRAIGA, or can only the state sue?

Only the Texas Attorney General can enforce TRAIGA. There is no private right of action, so individual consumers can't bring a lawsuit directly against your company under this statute, though a cure period reportedly applies before civil penalties attach once the AG notifies a company of a violation.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.

Tell us where the manual work hurts

We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.