Skip to main content
Statute-Accurate · Myth vs. Reality

What TRAIGA actually requires (and what it doesn't)

Plain-English and statute-accurate. Most vendors overstate the Texas Responsible AI Governance Act (TRAIGA / HB 149) to sell you a checklist. The truth is narrower: for private deployers, TRAIGA is an intent-based prohibition statute with an affirmative defense you have to evidence — not a mandate to inventory, tier, disclose, or register your AI.

Intent-based prohibitionAG-only enforcement60-day cure periodNo private right of actionNIST AI RMF safe harbor

Myth vs. Reality

The most common misconceptions about TRAIGA — and what the enacted statute actually says. When in doubt, confirm specifics with counsel.

Myth

TRAIGA forces private companies to build an AI inventory, run formal risk assessments, publish disclosures, and file board reports.

Reality

It does not impose any of those affirmative mandates on private deployers. Enacted TRAIGA (HB 149) is an intent-based prohibition statute — it bars certain intentional harmful uses of AI, not a documentation or reporting regime. An inventory, risk assessments, and oversight are excellent best practices (and help you evidence good faith), but the law does not require them of private businesses.

Myth

There is a mandatory incident-reporting clock — if something goes wrong you must notify the state within a fixed window.

Reality

There is no general incident-reporting duty for private deployers under TRAIGA. The statute does not create a breach-style notification clock for private companies. The only cure-related clock is the 60-day period the Attorney General must give you to fix an alleged violation before penalties can attach.

Myth

TRAIGA sets up statutory risk tiers — like the EU AI Act — that classify your systems as minimal, limited, high, or unacceptable risk.

Reality

There is no statutory risk-tier system in TRAIGA. Unlike the EU AI Act, Texas did not create legal risk categories with tier-specific obligations. Any risk score you see in a governance product — including Risk Meridian's — is that vendor's own classification methodology, not a statutory TRAIGA tier.

Myth

If your AI harms someone, they can sue you directly under TRAIGA.

Reality

There is no private right of action under TRAIGA. It is enforced exclusively by the Texas Attorney General, and only after a 60-day cure period in which you can remedy the alleged violation. Individuals cannot bring a TRAIGA claim against you themselves.

Myth

You must register your AI systems with a Texas agency before you can deploy them.

Reality

There is no registration requirement in TRAIGA. You do not file or license your AI systems with the state to use them. (Texas does offer a voluntary 36-month DIR regulatory sandbox for testing — that is an opt-in program, not a registration mandate.)

What TRAIGA actually does

Here is the real substance of the enacted law (HB 149, in force January 1, 2026) and the disclosure duties it places on the public sector and healthcare providers.

Four intent-based prohibitions

TRAIGA prohibits developing or deploying AI with the intent to: incite or encourage self-harm, harm to others, or criminal activity; (as the sole intent) infringe constitutional rights; unlawfully discriminate against a protected class; or produce unlawful sexual content involving minors or unlawful deepfake sexual material (§§ 552.052, 552.055–552.057). Liability turns on intent — a disparate impact alone is not enough (§ 552.056(c)).

Government agency disclosure duties

Government agencies that make an AI system available to interact with consumers must disclose that (§ 552.051(b)). Related public-sector laws (SB 1964 and HB 3512) add data-management, procurement, advisory-board, and AI-training obligations for state agencies and local governments.

Healthcare provider disclosure duty

Healthcare providers must disclose the use of AI in a patient's treatment, no later than the date treatment is first provided (emergency exception aside) (§ 552.051(f)). This dovetails with SB 1188 (effective September 1, 2025), which adds provider-review standards for AI-generated records, EMR-offshoring limits, and patient-notification rules for AI used in treatment and healthcare services.

AG-only enforcement, 60-day cure, penalty bands

Enforcement is exclusively by the Texas Attorney General, with a mandatory 60-day cure period and no private right of action (§§ 552.101, 552.104). Separately, for a licensed or certified professional, a licensing agency may add sanctions — up to suspension or revocation of a license and a penalty up to $100,000 — but only after a violation finding and an AG recommendation (§ 552.106). Civil penalties run roughly $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable violations, and $2,000–$40,000 per day for continuing violations.

NIST AI RMF safe harbor (and others)

Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense (§ 552.105(e)). Other recognized safe harbors include internal, adversarial, or red-team testing; following state-agency guidance; and third-party misuse of your system. The whole statute rewards evidenced good faith.

A rebuttable presumption of reasonable care

TRAIGA starts from a rebuttable presumption that a person used reasonable care (§ 552.105(c)). It can be challenged — so the practical goal is to keep a current, credible record of how your AI is used, tested, and overseen. That documented record is what preserves the presumption if the Attorney General ever pushes back.

What the AG can actually demand (§ 552.103)

If the Attorney General investigates a complaint, a civil investigative demand can require a high-level description of the system's purpose, intended use, and benefits; the type of training data; input-data categories; outputs; performance metrics; known limitations; and your post-deployment monitoring and oversight process. A maintained governance record answers exactly this — it is the file you will want if the AG calls.

36-month DIR sandbox + local preemption

TRAIGA establishes a voluntary 36-month regulatory sandbox administered by the Texas Department of Information Resources (DIR) for testing AI systems, and it preempts conflicting local AI ordinances so the rules are set at the state level.

So what should you actually do?

Because TRAIGA liability is intent-based, the winning move is to document intent, testing, and oversight — so you can evidence good faith and qualify for the safe harbors. That is exactly what Risk Meridian is built for.

Screen for the prohibited intentional uses

Because liability is intent-based, start by clearing your systems against the four prohibited purposes and keeping a record of that clearance. Risk Meridian's prohibited-practice screening produces exactly this clearance record.

Build NIST AI RMF safe-harbor evidence

Map your controls to Govern / Map / Measure / Manage and assemble a Safe Harbor Evidence Pack. Substantial NIST alignment is the affirmative defense the statute names — so it is worth documenting deliberately.

Document intent, not just impact

Capture per-system intended-purpose and non-discriminatory-intent statements — signed and versioned. TRAIGA is intent-based, so evidence of your intent is the record that matters most if the AG ever asks.

Stay ready for the 60-day cure

Keep a cure-readiness posture: know which systems could draw scrutiny, who owns remediation, and how fast you can produce evidence. Risk Meridian's 60-day cure workflow tracks the deadline, milestones, and cure-evidence export.

What TRAIGA requires — FAQs

Straight answers for founders, compliance leads, and counsel trying to separate the statute from the hype.

So what does TRAIGA actually require of a private company?
For private deployers, TRAIGA is primarily a set of prohibitions rather than affirmative mandates. It requires that you not develop or deploy AI with the intent to incite self-harm, harm, or crime; to (solely) infringe constitutional rights; to unlawfully discriminate against a protected class; or to produce unlawful sexual content involving minors or unlawful deepfake sexual material. It does not require an AI inventory, statutory risk tiers, public disclosures, incident reporting, executive certification, or registration. Those are best practices that help you demonstrate good faith — not legal mandates.
Does TRAIGA require an AI inventory or risk assessments?
No. Enacted TRAIGA does not impose an inventory or risk-assessment mandate on private deployers. Maintaining an inventory and assessing risk are strongly recommended practices — and they make it far easier to evidence good faith and qualify for the NIST AI RMF safe harbor — but the statute itself does not compel them for private companies.
Can an individual sue us under TRAIGA?
No. TRAIGA creates no private right of action. It is enforced exclusively by the Texas Attorney General, and only after a mandatory 60-day cure period during which you can remedy an alleged violation before civil penalties attach.
Does TRAIGA have risk tiers like the EU AI Act?
No. TRAIGA does not establish statutory risk tiers. The EU AI Act uses legal risk categories with tier-specific obligations; Texas took a different approach and built an intent-based prohibition statute instead. Any risk score in a governance tool — including Risk Meridian's Compliance Health Score — is that vendor's own classification, not a statutory tier.
How does NIST AI RMF fit in?
Substantial compliance with the NIST AI Risk Management Framework is an explicit affirmative defense under TRAIGA. In practice, aligning your governance to NIST's Govern, Map, Measure, and Manage functions and keeping the evidence is one of the most valuable things you can do — it is a named safe harbor, alongside red-team testing, following state-agency guidance, and third-party misuse.
If almost nothing is mandated, why use a governance platform?
Because the defense has to be evidenced. TRAIGA gives you affirmative defenses and safe harbors, but you only benefit from them if you can produce the record — prohibited-practice clearance, NIST alignment, intent documentation, and cure readiness. Risk Meridian is built to help you assemble that defensible record so you are ready if the Attorney General ever comes calling.

Evidence your TRAIGA defense — not a checklist you don't owe

Screen for prohibited uses, build your NIST AI RMF safe-harbor evidence, document intent, and stay cure-ready. Audit-ready in under an hour.

No credit card required.

Prohibited-practice screening with a clearance record

NIST AI RMF Safe Harbor Evidence Pack

60-day cure workflow, always ready