TRAIGA has been in force since January 1, 2026. It reaches every business that operates in Texas or serves Texas residents, with no employee count or revenue floor. It bans 6 intentional AI uses instead of grading systems by risk tier. Private employers owe no AI disclosure to applicants. Healthcare providers owe one to patients. Penalties run $10,000 to $200,000 per violation, and documented NIST AI RMF alignment is an affirmative defense.
TRAIGA applies to any business that operates in Texas and uses AI, with no employee count or revenue threshold. It bans 6 specific intentional uses of AI, and the Texas Attorney General enforces it after a 60-day cure period.
Ask 10 Texas business owners whether the state AI law applies to them and you get 9 versions of the same answer. That gap is why AI governance and compliance stopped being a legal question this year and became an operational one. We are too small. We do not build AI. We just use Copilot. All 3 of those answers are wrong for the same reason. The Texas Responsible AI Governance Act was written around what you do with AI, not around how big you are or whether you wrote any of the code yourself.
House Bill 149 was signed on June 22, 2025 and took effect on January 1, 2026. The version that passed is far narrower than the one originally filed, which is why a great deal of the commentary written during the 2025 session now reads as flat wrong to anyone checking it against the enrolled text. Texas dropped the risk-tier structure Colorado adopted. What replaced it is a short list of intentional acts the state will punish, plus disclosure duties aimed at 2 specific groups.
We are an IT provider, not a law firm, so take the legal interpretation to your counsel. What follows is the operational read. Which systems count. What has to be written down. What happens if a notice arrives from the Attorney General.
What TRAIGA is, in plain terms
The Texas Responsible AI Governance Act is a state law that bans 6 intentional uses of artificial intelligence, requires AI disclosure from government agencies and healthcare providers, and gives the Texas Attorney General exclusive power to enforce it through civil penalties after a 60-day cure period.
The definition of an AI system is deliberately wide. Norton Rose Fulbright quotes it as any machine-based system that infers from the inputs it receives how to generate outputs, including content, decisions, predictions or recommendations. Copilot fits. So does the resume screener inside your applicant tracking system, the chatbot on your website, and the forecasting module your ERP vendor quietly shipped in a release note nobody on your team read. Nobody at your company had to call any of it AI for the law to treat it that way. The breadth is the point.
Most of the confusion comes from what the final bill left out, so here is the shape of it.
| What TRAIGA does | What TRAIGA does not do |
|---|---|
| Bans 6 intentional uses of AI under Subchapter B | Grade AI systems into risk tiers the way Colorado does |
| Requires AI disclosure by state agencies and healthcare providers | Require private employers to tell applicants that AI was used |
| Gives the Attorney General exclusive enforcement with a 60-day cure period | Create a private right of action for consumers or employees |
| Preempts city and county AI ordinances | Exempt small businesses by headcount or revenue |
| Offers an affirmative defense for documented NIST AI RMF alignment | Certify, approve, or license any vendor as TRAIGA compliant |
Does TRAIGA apply to a 25-person company in Texas?

Yes, if you use AI in the business. Section 551.002 sets 3 triggers, and meeting any one of them puts you in scope.
- You promote, advertise, or conduct business in Texas
- You produce a product or service used by Texas residents
- You develop or deploy an AI system in Texas
There is no fourth line about employee count. There is no revenue floor. The bill analysis published by the Texas Legislature states the scope in those 3 clauses and stops.
This catches owners off guard because the state privacy law works the other way around. The Texas Data Privacy and Security Act exempts businesses meeting the Small Business Administration definition of a small business, which across most industries lands near 500 employees or 8 million dollars in receipts. Companies that cleared that bar in 2024 assume the same shelter carries into 2026. It does not.
| Texas or federal law | Size threshold | Applies to a 30-person Houston firm |
|---|---|---|
| TRAIGA (HB 149) | None | Yes, if the firm uses AI in any form |
| Texas Data Privacy and Security Act | SBA small-business exemption | Usually no, though the ban on selling sensitive data without consent still applies |
| Title VII, ADEA, ADA | 15 or 20 employees depending on the statute | Yes for most firms at that size |
Worth saying plainly. Scope is not the same as exposure. A 25-person plumbing company using ChatGPT to write service descriptions is in scope and carries almost no realistic risk, because nothing that tool touches influences a decision the law cares about. A 25-person staffing agency running AI resume screening is in scope and carries real risk. Same headcount. Completely different position. The law reaches both. Only one of them needs a governance program this quarter.
It helps to know how common this actually is. As of December 2025, roughly 18 percent of U.S. firms reported adopting AI in the Census Bureau Business Trends and Outlook Survey, according to a Federal Reserve FEDS Note published April 3, 2026. That same note observes that adoption among the smallest firms runs stronger than firm size alone would predict, which is a polite way of saying the little guys are moving faster than the survey design expected them to. So the population of Texas SMBs newly inside TRAIGA scope is far larger than the vendor marketing implies and far smaller than the 75 percent adoption headlines imply. Both numbers are selling something.
The 6 things TRAIGA actually prohibits
Every prohibition in Subchapter B carries an intent requirement. That single word does more work than anything else in the statute. Intent is the hinge.
- Section 552.052. AI that intentionally aims to incite or encourage a person to commit physical self-harm, harm to another person, or criminal activity
- Section 552.053. Government use of AI for social scoring based on social behavior or personal characteristics
- Section 552.054. Government biometric identification without consent, including identifiers gathered from publicly available images
- Section 552.055. AI developed with the sole intent of infringing a constitutional right
- Section 552.056. AI developed or deployed with the intent to unlawfully discriminate against a protected class
- Section 552.057. AI that produces child sexual abuse material or sexual deepfakes of minors
Read that list again and notice where it points. Three of the 6 apply only to state and local agencies. For a private Texas business, one prohibition carries almost all of the weight. Just one.
The prohibition that reaches almost every business

Section 552.056 makes it unlawful to develop or deploy an AI system with the intent to unlawfully discriminate against a protected class. Duane Morris lists those classes as race, color, national origin, sex, age, religion, and disability. The statute then says something unusual for a discrimination law. Unequal outcomes alone do not establish intent.
That is a genuine break for employers and a trap at the same time. Disparate impact does not violate TRAIGA. Disparate impact absolutely violates Title VII, the ADEA, and the ADA, none of which changed on January 1. Duane Morris frames TRAIGA compliance as a floor, and that is the right way to hold it. A floor. Not a ceiling. Clearing the Texas bar does not clear the federal one.
There is a second-order problem with an intent standard that almost nobody flags early enough, and it catches careful companies as easily as careless ones. Disproving intent requires records. Baker Botts calls this the documentation imperative and notes that proving a lack of discriminatory or harmful intent effectively requires detailed documentation of AI purposes and design decisions. A company with no AI policy, no inventory, and no vendor paperwork is not innocent by default. It is simply unable to show anything.
Who has to disclose AI use and who does not
Healthcare providers
If you are licensed, registered, or certified to deliver health care services and you use an AI system in relation to that service or treatment, you have to tell the patient. Spencer Fane notes the disclosure must land no later than the date of service or treatment, or as soon as reasonably possible in an emergency. Plain language, clear and conspicuous.
The gap here is real, and it is not a drafting nitpick. The statute never defines what counts as using an AI system in relation to treatment. Your EHR vendor shipped ambient scribing last spring. Your billing platform runs AI coding suggestions. Does either trigger a disclosure? Nobody has a clean answer yet, and your practice will have to make that call before anyone at the state makes it for you. Ask the vendor in writing. If you are already working through the HIPAA IT compliance checklist, fold an AI inventory into the same review rather than running two projects that ask most of the same people most of the same questions.
Government agencies and the vendors who serve them
A state or local agency that puts an AI system in front of consumers must disclose it before or at the time of the interaction. Section 552.051 requires plain language, clear and conspicuous presentation, and no dark patterns. The duty holds even where it would be obvious to a reasonable person that they are talking to a bot.
That obligation sits on the agency, not on you. If you sell to Texas agencies, expect it to arrive as a contract clause anyway. It usually does.
Private employers
No disclosure duty at all. TRAIGA does not require you to tell job applicants or employees that AI touched a decision. That deserves stating clearly, because several widely circulated summaries published during 2025 said the opposite and are still sitting near the top of search results for anyone looking this up today. They were describing the originally filed bill, not the one that passed. Check the date on anything you read.
Illinois, Colorado, and New York City all take a different position on this, so a multi-state employer does not get to stop reading here.
How enforcement works, and why the 60-day cure period is the whole design

The Texas Attorney General holds exclusive enforcement authority. No consumer can sue you directly under TRAIGA and no plaintiff firm can assemble a class action out of it. Cities and counties cannot write their own AI rules either, since the statute preempts local ordinances, which spares multi-city operators the patchwork problem that makes California privacy compliance so miserable. One enforcer. One standard. Perkins Coie walks through the enforcement structure in more detail.
The Attorney General has to send written notice before filing anything. Then the clock starts. From that notice you get 60 days, and if you cure the violation inside the window, state in writing that you cured it, and identify the internal policy changes that will stop it from recurring, the penalty is zero.
| Violation type | Civil penalty per violation |
|---|---|
| Curable, cured inside the 60-day window | $0 |
| Curable, not cured | $10,000 to $12,000 |
| Uncurable | $80,000 to $200,000 |
| Continuing violation | $2,000 to $40,000 per day |
Those figures come from Section 552.105. The distance between $0 and $200,000 is the entire enforcement design. That gap is deliberate. Texas built a statute that wants remediation, not revenue.
One date belongs on your calendar. The Attorney General must have an online complaint mechanism operating by September 1, 2026. Until then complaints arrive through general consumer protection channels, and no formal TRAIGA enforcement action had been filed through the first half of 2026. Once the portal opens, complaint volume goes up. The 60-day clock does not get any longer.
Here is the part that decides outcomes. Curing a violation in 60 days means producing documentation you either had before the notice arrived or you did not, and there is no third option available to you once the letter is on your desk. Nobody writes a credible AI governance program in 8 weeks with an investigation already open. Preparation is the defense.
The NIST AI RMF defense and what it takes to claim it
TRAIGA gives you a rebuttable presumption of reasonable care plus 3 affirmative defenses. Norton Rose Fulbright summarizes them as third-party misuse of an otherwise compliant system, violations discovered through red-teaming or adversarial testing, and substantial compliance with a nationally recognized framework such as the NIST AI Risk Management Framework.
NIST AI RMF 1.0 runs on 4 functions. Govern, Map, Measure, and Manage. Stripped of the framework language, they translate into work that looks like this inside a real company.
| NIST function | What it means in a 50-person Texas business |
|---|---|
| Govern | One named person accountable for AI oversight, a written acceptable use policy, and a review cadence that actually happens |
| Map | A current inventory of every AI system in use, including the ones IT never approved, classified by the decisions each one influences |
| Measure | Testing on the systems that touch hiring, lending, pricing, or patient care, with results written down and dated |
| Manage | A documented response when a test fails, and evidence that the fix actually shipped |
One correction to something you will hear from vendors. NIST alignment is a defense, not immunity. It gives you a documented basis to argue you operated responsibly, which is genuinely valuable and also considerably less than the phrase safe harbor tends to suggest when a salesperson says it. It does not stop an investigation. It does not guarantee the argument wins. Anyone selling certification against TRAIGA is selling something the statute never created.
There is also a regulatory sandbox, run by the Texas Department of Information Resources with the Texas Artificial Intelligence Council. Approved participants get up to 36 months to test AI systems without standard state licensing, in exchange for quarterly reports on performance and risk. The American Bar Association published a clear breakdown of how it works. It was built for companies developing AI products, not for the accounting firm running Copilot, so most SMBs can skip it entirely.
A 30-day TRAIGA readiness plan for a Texas SMB

None of the first pass requires a consultant. Start with people, not software. This is the sequence we run with clients, compressed into 4 weeks.
- Week 1, inventory. List every AI system touching the business, including the free tools employees signed up for on their own. That last category is usually where the surprises live, and it is the reason the inventory has to come from people rather than from a software audit.
- Week 2, classify. Sort each system by the decisions it influences. Hiring, lending, pricing, clinical care, and tenant screening belong in the top tier. Meeting summaries and marketing drafts do not.
- Week 3, write the policy. Acceptable use, who approves new tools, which data may never be pasted into a public model, and who owns oversight by name rather than by committee. Our AI acceptable use policy template for Texas businesses covers the 9 sections that policy needs.
- Week 4, collect vendor documentation. Ask every AI vendor for their bias testing, their training data position, and their own compliance posture. Ask in writing. File the answers, including the non-answers.
That is a defensible starting position, not a finished program. It is enough to start. It is also the entire difference between having something to hand the Attorney General inside a 60-day window and having nothing but a promise that you meant well.
Two things worth folding in while you are already in there. Most SMB AI exposure sits inside Microsoft 365, so the 8 Microsoft 365 security settings Texas SMBs miss are the same controls that keep Copilot from surfacing files it should never touch. And if you have never mapped your permissions posture, an AI readiness assessment shows you what Copilot can actually reach before you write a policy describing what it should reach.
Where Texas SMBs are getting this wrong
Three patterns, in roughly the order we run into them.
The size assumption. Covered above. Most common, easiest to fix, and it usually takes about 30 seconds of reading Section 551.002 to correct.
Treating the intent standard as a shield. Owners hear that disparate impact does not violate TRAIGA and conclude their discrimination risk is handled. Federal law did not move. If an AI screening tool rejects applicants over 50 at twice the rate of everyone else, TRAIGA may not reach it, but the Age Discrimination in Employment Act does, and the EEOC has never once required anyone to prove intent to bring that claim.
Accepting the vendor answer. We hear this one constantly. Our software vendor says they are TRAIGA compliant. Vendor compliance describes the product. Your liability describes the deployment. Section 552.056 reaches the deployer, not only the developer, which means a perfectly compliant tool dropped into a workflow that screens people out on a protected characteristic is still entirely your problem to explain.
Uprite has supported Texas businesses for more than 25 years and has been named to the MSP 501 seven years running, but most of that history is a story about infrastructure. AI governance is a newer discipline and the honest position is that everybody is early, including us and including the law firms writing the client alerts. The companies handling it best right now are not the ones with the most sophisticated frameworks. They are the ones who wrote down what they are running. That is the whole trick.
Questions Texas business owners keep asking about TRAIGA
Does TRAIGA apply if we only use ChatGPT and Microsoft Copilot?
Yes. The statute covers deploying AI systems, not just building them, and general-purpose assistants meet the definition. Your obligations are lighter than a developer’s, but scope is scope. You still need an inventory, a written acceptable use policy, and a named owner for AI oversight.
Is there an employee count that exempts a small business from TRAIGA?
No. TRAIGA carries no headcount and no revenue threshold. That is the single biggest departure from the Texas Data Privacy and Security Act, which does exempt SBA-defined small businesses. Owners who lean on that privacy exemption often assume it carries across. It does not.
What is the penalty for a first TRAIGA violation?
Potentially nothing. Curable violations run $10,000 to $12,000, but only if you fail to fix the problem within 60 days of the Attorney General’s written notice. Cure it, document the policy change, and the penalty is zero. Uncurable violations run $80,000 to $200,000, and continuing violations add $2,000 to $40,000 per day.
Do we have to tell job applicants that AI screened their resume?
Not under Texas law. TRAIGA places no AI disclosure duty on private employers. Only state agencies and healthcare providers carry one. If you also hire in Illinois, Colorado, or New York City, those jurisdictions are stricter and their rules still apply to those roles.
Does following the NIST AI Risk Management Framework make us compliant?
It gives you an affirmative defense, which is not the same thing. Substantial compliance with NIST AI RMF lets you argue you exercised reasonable care. It does not prevent an investigation, and no framework makes a prohibited intentional act lawful.
Can a customer or employee sue us under TRAIGA?
Neither can. TRAIGA creates no private right of action and enforcement sits exclusively with the Texas Attorney General. Consumers may file complaints, and an online complaint mechanism must be operating by September 1, 2026, but the decision to pursue anything belongs to the state.
We are a medical practice. What does the AI disclosure actually require?
Tell the patient, in plain language, no later than the date of service, whenever an AI system is used in relation to their care. Emergencies allow disclosure as soon as reasonably possible afterward. The hard part is scoping it, because the statute never defines AI use in relation to treatment and most practices now run AI inside their EHR and billing platforms without ever labeling it that way.
Start with the inventory
TRAIGA is in force and the complaint mechanism opens September 1, 2026. If you cannot currently produce a list of every AI system your company runs, that is your gap. Two weeks. Not two quarters.
Uprite builds and manages that layer for Texas businesses. Managed AI services covers deployment and day-to-day administration, and AI governance and compliance covers the documentation, NIST AI RMF alignment, and the recurring reviews that keep a program defensible instead of stale. Start a conversation through our contact page or call (866) 570-3065.






