Justin McKelvey

Justin McKelvey

Fractional CTO · 15 years, 50+ products shipped

• AI for Business • 9 min read •

TRAIGA: What the Texas Responsible AI Governance Act Actually Requires of a Business (2026)

The short answer

TRAIGA is the Texas Responsible Artificial Intelligence Governance Act (House Bill 149). It took effect January 1, 2026 and covers any business that operates in Texas, with no small-business exemption. For a private company it does three things: it bans building or deploying AI that is meant to manipulate people into harm, to unlawfully discriminate, to violate constitutional rights, or to produce certain sexual content; it makes health care providers disclose AI use to patients; and it lets the attorney general fine you $10,000 to $200,000 per violation after a 60-day chance to fix it.

That is a much smaller law than the one most summaries describe, and I can show you why. I work from Austin, so this is my state's law too. I'm not a lawyer and this is not legal advice. It is the bill text, read line by line, with the parts that touch a normal company pulled out.

Most TRAIGA summaries describe a bill that did not pass

Two bills carried the name "Texas Responsible Artificial Intelligence Governance Act" in the 2025 session. House Bill 1709 was filed on December 23, 2024. The Texas Legislature's site shows its last action as a committee referral on March 14, 2025. It never became law. House Bill 149 is the one that passed: 146 to 3 in the House, 31 to 0 in the Senate, signed June 22, 2025.

I counted the terms in both texts on September 30, 2026:

Term HB 1709 (filed, stalled) HB 149 (the law)
"high-risk" 75 times 0 times
"impact assessment" 14 times 0 times
"small business" carved out, by SBA definition 0 times (no carve-out)

So if a vendor or a consultant tells you TRAIGA requires annual impact assessments for "high-risk AI systems," they are quoting the bill that stalled. The law on the books has no high-risk category and no assessment duty for private companies. It also has no size exemption, which the stalled bill did have. You are covered at 5 employees. There just isn't much to do.

Who the law covers

Section 551.002 applies the Act to a person who does any one of three things: "promotes, advertises, or conducts business in this state," "produces a product or service used by residents of this state," or "develops or deploys an artificial intelligence system in this state." An out-of-state company with Texas customers is in.

The definition of an AI system is broad: "any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations." ChatGPT, a website chatbot, an AI phone agent and a resume-screening tool all fit.

One definition narrows the disclosure rule. A "consumer" is a Texas resident "acting only in an individual or household context." Someone acting "in a commercial or employment context" is not a consumer under the Act.

What each section says, and who it binds

Section Binds What the text says
552.051 Disclosure Government agencies; health care providers Tell the consumer they are interacting with AI, clearly and in plain language. Providers disclose "not later than the date the service or treatment is first provided."
552.052 Manipulation Everyone No AI developed or deployed "in a manner that intentionally aims to incite or encourage" self-harm, harm to another person, or criminal activity.
552.053 Social scoring Government only No AI that assigns people a social score leading to unfair treatment.
552.054 Biometric identification Government only No AI that identifies a specific person from biometric data or scraped images without consent, where that infringes a legal right.
552.055 Constitutional rights Everyone No AI developed or deployed "with the sole intent" to infringe a person's federal constitutional rights.
552.056 Discrimination Everyone No AI developed or deployed "with the intent to unlawfully discriminate against a protected class." The text adds: "a disparate impact is not sufficient by itself to demonstrate an intent to discriminate."
552.057 Sexual content Everyone No AI built with the sole intent of producing child sexual abuse material or unlawful deepfakes, or to hold sexual conversations while imitating a minor.

Read the right-hand column again and look for the word that repeats: intent. Every rule that binds a private business is about what you built the system to do. None of them is a paperwork duty.

Two carve-outs sit inside the discrimination section. It does not apply to insurers already covered by insurance anti-discrimination statutes, and a federally insured bank "is considered to be in compliance" if it follows federal and state banking law.

The Act also amends the existing Texas biometric law (Business and Commerce Code 503.001), which does bind private companies. A photo of someone that exists online is not consent to capture their biometric identifier unless that person made it public themselves. Training an AI model on biometric data is exempt unless the system is used to identify a specific individual.

The fines, and what 30 uncured days costs

Section 552.105 sets three penalty bands:

  • $10,000 to $12,000 for each violation the court finds curable.
  • $80,000 to $200,000 for each violation the court finds uncurable.
  • $2,000 to $40,000 per day for a continued violation.

Here is the arithmetic on one curable violation that a company ignores for 30 days after the cure window closes. The base penalty is $10,000 to $12,000. Thirty days at the daily rate is $60,000 to $1,200,000. Added together that is $70,000 at the statutory floor and $1,212,000 at the ceiling, before attorney's fees, which the state can also recover. Whether a court stacks them that way is a question for your lawyer. The point is that the daily number, not the headline number, is the one that gets large.

If you hold a state license (contractors, real estate, health professions), Section 552.106 lets your licensing agency add a penalty of up to $100,000 and suspend or revoke the license, but only after you have been found in violation and the attorney general recommends it.

How enforcement actually works

  1. A complaint. The attorney general had to post an online complaint mechanism by September 1, 2026. It is live: the consumer complaint page now lists an "AI complaint form."
  2. A civil investigative demand. After a complaint, the attorney general can demand documents about the AI system.
  3. A written notice naming the sections you allegedly violated.
  4. 60 days to cure. No action can be filed during those 60 days, or at all if you fix the problem and send a written statement saying how, with documentation and any policy changes.
  5. A lawsuit by the state if you don't.

There is no private lawsuit. The text says the chapter "does not provide a basis for, and is not subject to, a private right of action." Cities can't add their own AI rules either: the Act preempts local ordinances on AI use.

The eight things the attorney general can ask for

This is the most useful part of the bill for an owner, and almost nobody writes about it. Section 552.103(b) lists what a civil investigative demand can request. Turn it around and it is the record you want to already have for every AI system you run:

The statute asks for What to write down now
1. Purpose, intended use, deployment context, benefits One sentence: what this tool is for and who uses it.
2. The type of data used to program or train it For a bought tool: the vendor's statement. For your own: your data sources.
3. Categories of data processed as inputs What your people put in: customer names, call audio, resumes, financials.
4. The outputs it produces Drafts, scores, decisions, booked appointments.
5. Metrics used to evaluate performance How you check it: spot checks, error counts, review rate.
6. Known limitations What it gets wrong and what it is not allowed to do.
7. Post-deployment monitoring and user safeguards Who reviews the output, and how a problem gets reported.
8. Other relevant documentation Your policy, vendor contracts, training records.

Seven rows per tool. For a company with five AI tools that is a one-page spreadsheet. It is also the inventory step in any AI governance framework, which matters because of the next section.

The defenses, including the NIST one

The Act starts from a "rebuttable presumption that a person used reasonable care." On top of that, a defendant "may not be found liable" in two situations. First, when another person used the defendant's AI system in a prohibited way. Second, when the defendant found the violation itself through one of four routes: feedback from a developer, deployer or other person; testing, "including adversarial testing or red-team testing"; following guidelines set by state agencies; or an internal review process, if the defendant "substantially complies" with NIST's Generative AI Profile "or another nationally or internationally recognized risk management framework."

Plain version: the company that looks for its own problems and writes down what it found is in a far better position than the one that waits for a complaint. A short written AI acceptable use policy, the inventory above and a quarterly check are what "an internal review process" looks like at 30 people.

Three Texas businesses, read against the text

These are made-up companies, to show how the sections land.

  • A 25-person HVAC contractor with a website chatbot and an AI phone agent. No disclosure duty under TRAIGA: it is neither a government agency nor a health care provider. The intent prohibitions apply, and none is likely to be triggered by booking service calls. The licensing-agency sanction in 552.106 is the part to know about.
  • A dental practice using AI to read X-rays or draft treatment notes. This one has an affirmative duty. When AI is "used in relation to health care service or treatment," the provider must disclose it to the patient no later than the date of service. Add a line to the intake paperwork.
  • A staffing firm using AI to rank resumes. The discrimination section applies. It requires intent, and disparate impact alone is not enough under this Act. Federal and state employment law still apply on their own terms, so this is the tool where the monitoring row in the table above should not be blank.

Texas next to Colorado

If you sell in both states, do not assume they match. Colorado's legislature describes its law (Senate Bill 24-205) as requiring a deployer of a "high-risk" system to implement a risk management policy and program, complete an impact assessment, review each deployment annually, notify consumers about consequential decisions and offer an appeal. It also requires any business with consumer-facing AI to disclose it. A 2025 special-session bill (Senate Bill 25B-004) extended the effective date to June 30, 2026. Colorado has moved that date once already, so check the legislature's page before you rely on it.

Texas asks for none of those things from a private business. The same company can be fully fine in Austin and out of compliance in Denver.

What else the Act created

  • A regulatory sandbox. The Department of Information Resources can approve a company to test an AI system for up to 36 months with certain licensing rules waived. Participants report quarterly. The prohibitions in the table above cannot be waived.
  • The Texas Artificial Intelligence Council. Seven public members appointed by the governor, lieutenant governor and House speaker. It studies and recommends. The Act says it may not "adopt rules or promulgate guidance that is binding for any entity."

What I'd do this week

Open a spreadsheet. List every AI tool your company uses down the left side and the first seven rows of the attorney general's list across the top. Fill in what you can in 30 minutes and mark what you can't. If you run a health care practice, add the AI disclosure line to your intake forms today.

If the blanks in that sheet worry you, that is what an AI audit is for. If you are deciding whether to bring in outside help, read what to ask an AI consultant first. And if you want the inventory, the risk map and a written plan done for you, my AI Readiness Assessment produces exactly that ($2,500, delivered in two weeks).

Sources

  • Texas Legislature Online, H.B. 149 enrolled text (89th Regular Session), read September 30, 2026: every section number, quote and penalty amount above.
  • Texas Legislature Online, bill history for H.B. 149 (signed June 22, 2025) and for H.B. 1709 (filed December 23, 2024; last action March 14, 2025), plus the introduced text of H.B. 1709, read September 30, 2026.
  • Office of the Texas Attorney General, "File a Consumer Complaint" and "Consumer AI Rights" pages, read September 30, 2026: the AI complaint form.
  • Colorado General Assembly, bill pages for SB24-205 and SB25B-004, read September 30, 2026. Later Colorado changes were not checked.
Free Resource Justin McKelvey

Get the Free AI Content Toolkit

The exact system I use to turn one idea into a month of content — atomization framework, voice template, prompt library, weekly system.

Frequently Asked Questions

What is TRAIGA?
TRAIGA is the Texas Responsible Artificial Intelligence Governance Act, passed as House Bill 149 and signed on June 22, 2025. It took effect January 1, 2026. It bans a short list of intentional AI misuses, requires state agencies and health care providers to disclose AI use, gives the Texas attorney general sole enforcement power, and creates a regulatory sandbox and a seven-member Texas Artificial Intelligence Council.
Does TRAIGA apply to small businesses?
Yes. The enacted text has no revenue or headcount exemption. It applies to any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. What keeps the burden small is the content, not an exemption: for a private business the Act is mostly a list of things you may not build or deploy AI to do on purpose.
Does TRAIGA require my business to disclose that a customer is talking to AI?
Only in two cases written into the Act. A governmental agency must disclose AI that is intended to interact with consumers, and a health care provider must disclose when an AI system is used in relation to a health care service or treatment, no later than the date the service is first provided. The Act puts no general chatbot-disclosure duty on other private businesses.
What are the penalties under TRAIGA?
Civil penalties of $10,000 to $12,000 for each violation a court finds curable, $80,000 to $200,000 for each violation found uncurable, and $2,000 to $40,000 for each day a violation continues. A state licensing agency can add sanctions up to $100,000 and suspend or revoke a license if the attorney general recommends it. Penalties only apply to a violation that was not cured in the 60-day window.
Can a customer or employee sue my company under TRAIGA?
No. The Act says it does not provide a basis for a private right of action, and the attorney general has exclusive authority to enforce it. A consumer can file a complaint through the attorney general's online AI complaint form, which can lead to a civil investigative demand.
Is there a safe harbor in TRAIGA?
There are several defenses. The Act presumes a person used reasonable care unless shown otherwise. A defendant cannot be found liable when someone else misused its AI system, or when it found the violation itself through user feedback, testing such as red-teaming, following state agency guidelines, or an internal review process while substantially complying with NIST's Generative AI Profile or another recognized AI risk management framework.

More on AI for Business

ChatGPT Business vs Plus (2026): Which One a Small Business Should Actually Pay For

ChatGPT Plus vs Business, as of September 2026: Plus is $20 a month for one person and OpenAI may train on your chats unless you opt out; Business is $20 a seat billed annually or $25 monthly, two seats minimum, with no training by default, admin controls, shared projects for groups, and the Company Knowledge plugin. The side-by-side from OpenAI's pages, and three owner scenarios with a verdict each.

6 min

ChatGPT for Customer Service (2026): What Works, What Breaks, and What It Costs a Small Business

ChatGPT for customer service, as of September 2026: it drafts replies, answers policy questions from your own documents, and triages an inbox for $20 to $25 a seat a month on ChatGPT Business. It can't look up an order, issue a refund, or remember a customer unless you connect the system that holds them. The honest capability line, the plan you need, a setup in six steps, the failure modes, and the point where a real agent takes over.

7 min

ChatGPT Pulse (2026): What It Was, Why OpenAI Retired It, and How to Get the Morning Brief for Your Business

ChatGPT Pulse, the daily research cards OpenAI previewed for Pro users in September 2025, was sunset on June 17, 2026 with a 14-day wind-down. What it did, which plans ever had it, why scheduled tasks replaced it, and how an owner rebuilds the morning brief on a Plus or Business seat without handing ChatGPT the wrong things.

7 min

Claude for Nonprofits (2026): The $8 Team Plan Seat, Who Qualifies, and What a 10-Person Team Actually Pays

Claude for Nonprofits, as of September 2026: Anthropic lists Claude Team at $8 per user per month for verified nonprofits, against $20 to $25 on the standard plan, and $3 for nonprofits in low- and middle-income countries. Minimum 2 seats. Under 20 people you verify through Goodstack in a few minutes; above that, it's a sales call. Who qualifies, what's included, and the math.

4 min
Justin McKelvey, Fractional CTO and AI consultant in Austin, TX

Written by

Justin McKelvey

Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI — without hiring a full-time executive team.

Work with me

If this was useful, here are two ways I can help: