AI Governance, Risk & Red Teaming
Aware · M18 · lesson 18 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Texas TRAIGA HB 149 - Effective Jan 1, 2026
📖
now learning

Texas TRAIGA HB 149 - Effective Jan 1, 2026

15 min

On January 1, 2026, Texas became the second U.S. state with a comprehensive AI law on the books, and the first whose statute was so dramatically narrowed between draft and signature that compliance teams who built against the 2024-2025 drafts are now over-engineering for prohibitions that no longer exist. The Texas Responsible AI Governance Act (TRAIGA, HB 149), signed by Governor Greg Abbott in 2025 and effective January 1, 2026, lives in a small set of intent-based prohibitions, a state-agency and healthcare disclosure regime, an AI sandbox, and Attorney-General-only enforcement at $10K-$200K per violation. There is no algorithmic-discrimination cause of action on disparate impact alone. There is no private right of action. There is no comprehensive impact-assessment requirement of the kind that drove Colorado SB 24-205 into the federal court that stayed it on April 27, 2026. TRAIGA is the narrowed law that survived the 2025 lobbying cycle, and reading it correctly, alongside the unchanged federal Title VII / EEOC / FTC posture, the still-active NYC Local Law 144, and the EU AI Act Annex III §4 employment overlay that still binds any Texas employer with EU operations, is the operational discipline this lesson teaches.

From Draft to Statute - How TRAIGA Narrowed Between 2024 and Signature

Earlier drafts of TRAIGA (HB 1709 in 2023-2024; early HB 149 drafts in 2025) looked much more like Colorado SB 24-205: an algorithmic-discrimination cause of action triggered by disparate impact, comprehensive impact-assessment obligations for "high-risk" AI systems, deployer notice obligations, and either a private right of action or a broader civil-penalty enforcement regime. Between draft and signature, the bill was substantially narrowed under industry, civil-society, and intra-Republican-caucus pressure. The version Governor Abbott signed retains four intent-based prohibitions, two disclosure regimes (state agency and healthcare), and a regulatory sandbox, with AG-only enforcement and per-violation civil penalties. The disparate-impact theory of liability that was the centerpiece of the earlier drafts did not survive.

This matters operationally because three categories of organizations are now mis-tiered against TRAIGA in May 2026:

  • Programs that built their TRAIGA compliance against the 2024 drafts are running over-engineered impact-assessment workflows for hiring AI deployed in Texas, workflows that the statute does not require. The work is not wasted (Title VII and EEOC still drive disparate-impact analysis at the federal level, and the EU AI Act Article 27 FRIA still drives it at the EU level), but the Texas-specific rationale is incorrect.
  • Programs that assume TRAIGA = Colorado SB 24-205 are conflating two genuinely different statutes. Colorado's stayed law was broader (algorithmic-discrimination on a disparate-impact theory, private right of action contemplated in some versions, comprehensive impact-assessment obligations); Texas's enacted law is narrower (intent-based prohibitions only, AG-only enforcement, no private right of action). Cross-walking compliance posture from one to the other produces wrong answers in both directions.
  • Programs that assume "AG-only enforcement = no real risk" are under-reading the statute. The Texas AG's office has both investigative authority and the discretion to bring civil-penalty actions in the $10K-$200K per-violation range (or $2K-$40K per day for continuing violations). The first enforcement actions are expected in H2 2026 / 2027 as the AG's office stands up its investigative capacity. Limited 2026 enforcement is not the same as no future enforcement.

The correct read of TRAIGA in May 2026: a narrow but non-trivial statute with four intent-based prohibitions, a disclosure overlay for state agencies and healthcare providers, a regulatory sandbox, AG-only civil-penalty enforcement, and substantial residual obligation from federal anti-discrimination law that TRAIGA does not preempt. The compliance memo for a Texas operator should be roughly four to six pages, not the forty-page impact-assessment library the 2024 drafts would have required.

The Four Prohibitions - Texas's Article 5 Analog

TRAIGA's substantive obligations sit in a small set of prohibitions that read like a narrower version of the EU AI Act's Article 5 unacceptable-risk list. The four prohibited uses:

Prohibition 1 - Manipulation Toward Self-Harm

TRAIGA prohibits the deployment of an AI system that manipulates a person toward self-harm. This is the closest TRAIGA analog to EU AI Act Article 5(1)(a), which prohibits AI systems that deploy subliminal techniques or purposefully manipulative or deceptive techniques to materially distort behavior in a manner that causes significant harm. The Texas version is narrower, scoped to self-harm, but captures a recognized harm pattern that has been the subject of multiple high-profile lawsuits against consumer-facing chatbot vendors in 2024-2025 (Character.AI, Replika, others).

Operationally, the prohibition affects any organization deploying a consumer-facing conversational AI to Texas users. The compliance posture is:

  • Self-harm content filters at both the input layer (user expressing self-harm ideation) and the output layer (model recommending or describing self-harm methods). The OWASP LLM Top 10 LLM06 (Sensitive Information Disclosure) and LLM09 (Misinformation) probes cover this attack surface.
  • Escalation pathways to crisis-line resources (988 Suicide and Crisis Lifeline integration is the default U.S. baseline).
  • Logged evidence of the safety-tuning regime (system-prompt content, RLHF safety training, evaluation results from suites like Garak, PyRIT, or Promptfoo). The evidence pack supports both TRAIGA defensibility and the parallel EU Article 5(1)(a) analysis for any EU-deployed surface.
  • Incident reporting infrastructure that triggers on detected self-harm content emission. The Article 73 EU AI Act incident-reporting infrastructure can be reused here for Texas reporting purposes, with the AG as the relevant U.S. recipient.

Prohibition 2 - Intent to Discriminate

This is the prohibition that defines TRAIGA's narrowed scope. TRAIGA prohibits the deployment of an AI system with the intent to discriminate on the basis of a protected class. Disparate impact alone, that is, statistically unequal outcomes across protected classes absent intentional design, is not sufficient to trigger the TRAIGA violation. This is materially narrower than:

  • Federal Title VII / EEOC AI guidance, which captures both disparate treatment (intentional) and disparate impact (statistical) theories of liability for employment AI. EEOC's 2023 technical assistance document on AI in hiring explicitly applies the four-fifths rule to AI-driven selection outcomes.
  • NYC Local Law 144 AEDT, which mandates annual independent bias audits applying the four-fifths rule regardless of deployer intent.
  • Colorado SB 24-205 (stayed), which contemplated an "algorithmic discrimination" theory that captured disparate-impact patterns without an intent requirement.
  • EU AI Act Article 10, which requires high-risk system providers to examine training datasets for bias and to put in place mitigation measures, disparate-impact testing is the standard methodology.

The intent narrowing has a sharp operational implication: a hiring tool that produces statistically unequal selection outcomes across protected classes in Texas, absent evidence of intentional design to discriminate, is not a TRAIGA violation. But that same hiring tool is still:

  • Subject to EEOC scrutiny under Title VII disparate impact (federal law, not preempted by TRAIGA).
  • Subject to NYC LL 144 if any candidate is screened in NYC (city law, separate jurisdiction).
  • Subject to EU AI Act Annex III §4 if any candidate is screened in the EU (FRIA + bias-testing + Article 10 data-governance obligations).
  • Potentially subject to state attorney-general unfair-and-deceptive-trade-practice actions and to state-specific anti-discrimination law.

The defensible Texas compliance posture for any potentially-discriminatory AI deployment is therefore: document the intent analysis explicitly. The documentation should establish (a) that the system was designed without discriminatory intent; (b) that the deployer is aware of disparate-impact monitoring at the federal Title VII / NYC LL 144 / EU AI Act levels; (c) that the system has been reviewed against the four-fifths rule as a defensive matter; and (d) that the deployer has not knowingly continued deployment after disparate-impact patterns were identified, because continued knowing deployment after pattern identification could itself constitute evidence of intent under some readings.

This last point is the crucial Texas-specific drafting tip. The statute requires intent, but the line between "we did not intend to discriminate" and "we knew the system was producing disparate impact and continued to deploy it anyway" is the line that aggressive AG investigation could probe. The defensible posture is to monitor for disparate impact, document remediation steps when patterns are identified, and not continue deployment of a known-discriminatory system without explicit intent analysis and remediation evidence.

Prohibition 3 - CSAM Generation

TRAIGA prohibits the deployment of an AI system that generates child sexual abuse material (CSAM). This conduct is already criminal under Texas Penal Code §43.26, federal 18 U.S.C. §2252, and the 2003 PROTECT Act and subsequent amendments (which expressly cover computer-generated CSAM indistinguishable from real depictions). TRAIGA adds an AI-specific civil-penalty layer on top of the existing criminal regime.

The compliance posture for any organization deploying a generative AI system to Texas users:

  • CSAM content filters at the output layer using established detection technology (PhotoDNA, Microsoft's commercial offerings, NCMEC-coordinated hash-matching infrastructure).
  • Refusal patterns at the input layer when prompts seek to elicit CSAM. The OWASP LLM Top 10 LLM06 + LLM10 (Unbounded Consumption, including misuse for content generation) probe coverage applies.
  • Reporting infrastructure compliant with the federal NCMEC reporting obligation under 18 U.S.C. §2258A (electronic communication service providers must report apparent CSAM to NCMEC).
  • Documentation of the safety-tuning and refusal-pattern regime, both for TRAIGA defensibility and for the parallel federal criminal-defense posture and the EU AI Act Article 5 analysis.

Prohibition 4 - Constitutional-Rights Infringement

TRAIGA prohibits deployment of an AI system that infringes upon constitutional rights. This is the prohibition with the least precise operational scope: "constitutional rights" includes First Amendment speech, Second Amendment, Fourth Amendment search-and-seizure, Fifth and Fourteenth Amendment due process, and Texas Constitution analogs. The breadth makes the prohibition somewhat aspirational; the AG's office will develop interpretive guidance through enforcement actions, unlikely before 2027.

The provisionally defensible compliance posture in 2026 is:

  • For state-government or state-contractor AI deployments, explicit due-process and equal-protection analysis where the system makes or substantively informs a government decision affecting an individual.
  • For surveillance-adjacent AI (facial recognition, location tracking, communication monitoring), Fourth Amendment analysis where the system supports a government function. Private-sector facial recognition for facility access is less likely to implicate constitutional concerns directly, but the analysis should be documented.
  • For content-moderation AI affecting expression, First Amendment analysis where the system supports a state-actor function. Private-sector content moderation is generally not state action and therefore generally outside Constitutional-rights analysis, but the line can blur where private platforms are operating under significant government partnership (a doctrine the Supreme Court continues to develop in cases like Murthy v. Missouri).

The realistic 2026-2027 posture for most private-sector deployers is to document a brief Constitutional-rights analysis as part of the broader AI risk assessment, note the absence of state-actor or state-contractor status where applicable, and revisit as AG enforcement guidance emerges.

AG-Only Enforcement, Penalty Tiers, and What 2026 Enforcement Looks Like

TRAIGA enforcement vests exclusively in the Texas Attorney General. There is no private right of action. Individuals harmed cannot sue under TRAIGA itself; they can still pursue claims under separate state-law theories (deceptive trade practices, common-law torts, state anti-discrimination statutes) and federal law (Title VII, ADA, ADEA, FCRA, ECOA, FHA, etc.). The AG-only structure is a substantive narrowing relative to statutes contemplating private rights of action.

The civil-penalty range:

  • $10,000 to $200,000 per violation for a single TRAIGA violation. The lower end captures less-severe or first-occurrence violations; the upper end captures more-severe or repeat violations. The AG has prosecutorial discretion within the range.
  • $2,000 to $40,000 per day for continuing violations. This is the structure that allows penalties to escalate where a deployer has been notified of a violation and continues the deploying conduct. A 90-day continuing violation at the upper end is $3.6M in penalties.

These numbers are substantial but not in the EU AI Act Article 99(2) tier (€35M / 7% worldwide turnover for Article 5 violations) or the Article 99(3) tier (€15M / 3% for most provider failures). They are roughly comparable to the upper end of FTC Section 5 civil-penalty exposure. For Fortune-500 deployers, upper-end TRAIGA penalties are meaningful but not existential; for startups they can be material.

The Texas AG's office is standing up AI investigative capacity in 2026. No dedicated AI unit has been announced at the scale of California AG's privacy enforcement unit, but several assistant attorneys general with consumer-protection and civil-rights backgrounds have been reassigned to AI matters. First enforcement actions are widely expected in H2 2026 / 2027; likely initial targets:

  • Consumer-facing chatbot vendors with documented self-harm-manipulation incidents (Prohibition 1).
  • CSAM-generation incidents that escape filtering (Prohibition 3), likely brought in coordination with federal prosecutors.
  • High-profile hiring AI vendors with documented intent-to-discriminate evidence (e.g., training data explicitly curated to exclude protected classes, or internal communications indicating discriminatory design intent).
  • State-agency or healthcare-provider deployers who failed the disclosure obligations (the easier-to-establish administrative violations are likely to be the earlier-frequency enforcement targets).

The strategic implication for compliance teams: 2026-2027 is the period to ensure that (a) the four prohibitions are documented as not applicable or as actively mitigated; (b) the disclosure obligations for state-agency and healthcare deployments are operationally implemented; and (c) the documentation pack would survive an AG investigative request. Limited 2026 enforcement should not be read as deferred risk.

State-Agency and Healthcare Disclosure Requirements

TRAIGA includes two specific disclosure regimes that operate independently of the prohibitions:

State-Agency Disclosure

Texas state agencies, and contractors operating state-agency AI on the agency's behalf, must disclose to a citizen when AI is used in an interaction. The disclosure is concise (notification of AI use, plus typically a human-mediated alternative pathway) and applies regardless of whether the system is one of the four prohibited categories. Functionally analogous to EU AI Act Article 50(1) but limited to state-government contexts.

The Texas Department of Information Resources (DIR) is expected to publish implementation guidance during 2026. Pending the guidance, the defensible interim posture for state-agency-adjacent vendors is:

  • A standardized disclosure banner or modal for any citizen-facing AI surface: chatbots, intake forms, eligibility-determination interfaces, benefits-application assistants, document-review AI used in state administrative proceedings.
  • Documentation of the disclosure in the vendor's contract with the state agency, including the responsibility for delivering the disclosure (typically the agency, but the vendor may operate the disclosure surface on the agency's behalf).
  • Plain-language disclosure (avoid legalese), with reading level appropriate for the citizen population the agency serves.
  • A human-mediated alternative pathway where feasible (e.g., a phone-line or in-person alternative for the AI-handled intake function).

The disclosure obligation does not exempt the agency from federal law that may require additional notice, the federal Privacy Act of 1974 applies to federal agencies; HIPAA applies to health-services interactions; the Americans with Disabilities Act applies to accessibility of the disclosure surface itself.

Healthcare-Provider Disclosure

Healthcare providers using AI in healthcare decisions must disclose AI use to patients. Scope is broader than state-agency: including private-sector physicians, hospitals, clinics, and other licensed providers operating in Texas. "Healthcare decisions" captures clinical-decision-support AI, AI-assisted diagnostic tools, AI-driven imaging analysis, AI-assisted treatment-recommendation systems, AI-driven prior-authorization by insurers, and AI in claims adjudication affecting patient care.

The disclosure regime parallels and partly overlaps several other Texas-specific healthcare regimes:

  • Texas SB 1188 (separate companion legislation in the 2025 cycle) imposes additional AI-governance obligations on Texas state-government AI use, requires AI literacy components in K-12 education (forthcoming guidance), and addresses healthcare-provider AI disclosure with overlapping requirements.
  • The Texas Medical Board has indicated it will issue interpretive guidance on the licensure-implications of AI-assisted clinical decisions in 2026-2027.
  • The Texas Department of Insurance has parallel oversight authority over insurer use of AI in claims-adjudication and prior-authorization workflows, which interacts with TRAIGA Prohibition 2 (intent to discriminate) where claims-adjudication AI produces disparate outcomes across protected classes.

Compliance posture for a Texas healthcare provider deploying clinical-decision-support AI:

  • Patient-facing disclosure at the point of care that AI is informing the clinical decision. The form-factor of the disclosure can vary, a notation in the intake paperwork, a verbal disclosure by the clinician, a written notation in the after-visit summary, but it must be reasonably calculated to inform the patient.
  • Documentation of the disclosure pathway in the provider's compliance file, alongside the existing HIPAA and informed-consent documentation.
  • Coordination with the EHR vendor or AI-tool vendor on the disclosure copy and the form-factor. Vendors selling clinical-decision-support AI to Texas providers should expect to be asked to deliver disclosure-ready vendor packages.
  • The disclosure does not substitute for informed consent under existing Texas informed-consent law for the underlying clinical procedure or treatment. It is an additional, AI-specific notice.

For insurance deployers using AI in claims adjudication or prior authorization affecting Texas-resident patients, the disclosure interacts with EOB (Explanation of Benefits) language and the prior-authorization notice. Defensible interim posture: add AI-disclosure language to both EOBs and prior-authorization decisions where AI materially informed the decision.

The AI Sandbox - Texas's Innovation-Friendly Provision

TRAIGA establishes a regulatory sandbox for AI developers to test products in Texas with limited liability exposure. The sandbox is modeled on the Texas Department of Banking's financial-services regulatory sandbox (SB 600, 2017) and the Arizona Corporation Commission's broader regulatory sandbox precedent. The TRAIGA AI sandbox is:

  • Opt-in, A developer affirmatively applies for sandbox status; it is not the default posture. The application includes a description of the AI system, the intended test surface, the expected duration of the test, and the user-protection mechanisms in place.
  • AG-approved, The Texas Attorney General reviews and approves sandbox applications. Approval grants temporary relief from certain Texas regulatory requirements during the test period. The relief does not extend to federal law, to criminal prohibitions (including CSAM and the consumer-protection criminal regime), or to fundamental rights.
  • Time-limited, Sandbox approvals are for a defined period (typically 24 months, with possible extension). After the period concludes, the developer must come into full compliance or exit the Texas market for the relevant product.
  • User-protection requirements: Sandbox participants must implement specified user-protection mechanisms, including disclosure to test users that they are interacting with a sandbox product, complaint-handling infrastructure, and (typically) some form of consumer-restitution mechanism if harm occurs.
  • Reporting: Sandbox participants report periodically to the AG's office on incidents, complaints, and material changes to the AI system.

The AI sandbox is genuinely innovation-friendly and distinguishes TRAIGA from the European-style approach (which has narrower regulatory-sandbox provisions in EU AI Act Article 57). For a Texas-headquartered AI startup or an out-of-state developer planning Texas market entry with an innovative use case, the sandbox is a real option. Trade-offs:

  • The sandbox does not provide federal-law cover. A sandbox-approved hiring AI is still subject to Title VII and EEOC enforcement; a sandbox-approved healthcare AI is still subject to FDA oversight where the device-classification threshold is crossed; a sandbox-approved financial-services AI is still subject to ECOA, FCRA, UDAAP, and state insurance / banking regulation.
  • The sandbox does not exempt from the four core TRAIGA prohibitions (self-harm manipulation, intent-to-discriminate, CSAM, constitutional-rights). The sandbox provides relief from secondary regulatory requirements, not from the core conduct prohibitions.
  • The reporting and user-protection requirements create their own operational overhead, so the sandbox is best for developers who are already committed to robust testing infrastructure.

The decision tree for a Texas operator considering sandbox application:

  1. Is the AI system novel enough that prospective regulatory uncertainty is material? (If "this is just another conventional ML model," sandbox is overkill.)
  2. Is the deployment Texas-only or Texas-primary? (Sandbox protections are state-specific; multi-state deployment requires multi-state strategy.)
  3. Is the developer able to commit to the reporting and user-protection obligations? (Smaller startups may find the overhead exceeds the benefit.)
  4. Does the developer have a clear post-sandbox compliance path? (Sandbox is time-limited; exit-from-sandbox planning should be in place at entry.)

Multi-Jurisdiction Operational Overlay - Texas + EU + NYC + Colorado

For most enterprise deployers, the operational challenge is not TRAIGA in isolation but TRAIGA in combination with the broader 2026 U.S. and EU regulatory stack. A representative case: a Fortune-500 employer headquartered in Texas, with EU subsidiaries, with hiring activity in New York City, and with operations across the U.S. The hiring AI deployed to screen Texas + NYC + EU candidates must address:

  • Texas TRAIGA, Prohibition 2 intent analysis (documented absence of discriminatory intent; monitoring for disparate impact as a defensive matter; no continued deployment after known-pattern identification without remediation evidence). State-agency or healthcare-provider disclosure if the use is in those contexts.
  • NYC Local Law 144 AEDT: Annual independent bias audit, 10-business-day candidate notice, public bias-audit summary, four-fifths-rule analysis, alternative-assessment offer. Post-Comptroller-audit enforcement (Dec 2025) means more rigorous DCWP enforcement in 2026.
  • EU AI Act Annex III §4 employment: Article 27 FRIA (in process toward the Dec 2, 2027 stand-alone Annex III applicability), Article 10 data governance, Article 14 human oversight, Article 15 robustness, Article 26 deployer obligations, Article 50(1) candidate-facing disclosure where applicable.
  • Federal EEOC Title VII, Disparate-impact analysis under the four-fifths rule (federal floor; not preempted by TRAIGA or by any state law).
  • Colorado SB 24-205: Federally stayed (Apr 27, 2026, U.S. District Court of Colorado). SB 189 replacement notice-and-transparency framework passed May 7-9, 2026 (effective Jan 1, 2027 if signed by Governor Polis; enforcement contingent on AG rulemaking). Colorado-resident candidates are currently not subject to the SB 24-205 algorithmic-discrimination framework but may be subject to the SB 189 transparency regime in 2027 if the bill becomes effective.
  • FTC Section 5, Unfair or deceptive AI practices in hiring tools, particularly tools sold across state lines. The FTC has signaled enforcement interest in AI-driven hiring tools that make unsupported claims about bias-free outcomes.
  • FCRA, Where a hiring AI uses consumer-report data, FCRA disclosure and adverse-action notice obligations apply.
  • State-specific anti-discrimination law: Illinois, California, Washington, Colorado, Maryland, and several other states have their own anti-discrimination overlays that may or may not capture AI-driven decisions depending on state-specific interpretation.

The operational challenge for the L3 risk practitioner running this portfolio is evidence reconciliation across the jurisdictional stack. The NYC LL 144 bias audit, the EU Article 27 FRIA, the Texas intent-analysis memo, the EEOC defensibility pack, and the FTC marketing-claim documentation should be designed to draw from a common evidence base, common training-data documentation, common bias-testing methodology, common human-oversight evidence, with jurisdiction-specific artifact wrappers that meet each regime's documentation expectations. Programs that build separate evidence bases for each jurisdiction quickly become operationally unsustainable and inconsistent. Programs that build a common evidence base with reconciliation layers are sustainable and defensible.

The common evidence base for a hiring AI should include:

  • Model card (Mitchell et al. 2019 schema) with training-data composition, fairness-testing methodology, performance-by-protected-class disaggregation, and known limitations.
  • Datasheet (Gebru et al. 2018 schema) for the training and evaluation datasets.
  • Disparate-impact testing report applying the four-fifths rule, with subgroup analysis for the relevant protected classes (race, ethnicity, gender, age 40+, disability status, and applicable state-specific protected classes).
  • Bias-mitigation log documenting any preprocessing, in-processing, or post-processing fairness interventions and the rationale for each.
  • Human-oversight design documentation (Article 14 EU AI Act analog) including the qualifications and authorities of the human reviewers, the cases triggering human review, and the documentation pattern for human override.
  • Incident log with all reported issues, complaints, AG inquiries, candidate disputes, and remediation actions.
  • Vendor-documentation pack (where the AI is third-party) including the vendor's model card, SOC 2 or ISO 27001 evidence, ML-BOM under CycloneDX 1.7 if available, and contractual representations.

From this common evidence base, the jurisdiction-specific artifacts (NYC LL 144 bias-audit summary; EU FRIA template under Article 27; Texas intent-analysis memo; EEOC defensibility pack) are constructed. The reconciliation layer is the L3 practitioner's principal deliverable for cross-jurisdiction deployments.

Texas SB 1188 and Companion Legislation - The Broader Texas AI Stack

TRAIGA does not sit alone in the Texas 2025 legislative cycle. Several companion bills address AI in adjacent contexts:

  • Texas SB 1188: additional AI-governance obligations on Texas state-government AI use (procurement standards, agency-level AI inventory requirements, governance committee at the agency level), AI literacy components in K-12 education (forthcoming Texas Education Agency guidance), and healthcare-provider AI disclosure that overlaps partially with TRAIGA. SB 1188 also contains a study and reporting requirement for the Texas Department of Information Resources to monitor AI use across state government.
  • Texas Data Privacy and Security Act (TDPSA), Texas's comprehensive consumer privacy law (effective July 1, 2024) interacts with AI deployments that process personal data. The TDPSA's profiling provisions overlap with TRAIGA's intent-to-discriminate prohibition, and the data-protection assessment requirement under TDPSA can satisfy part of an AI-system risk-assessment workflow.
  • Texas Department of Insurance bulletins on AI in insurance underwriting and claims adjudication, TDI has indicated bulletin-level guidance is forthcoming in 2026-2027 addressing insurer use of AI, including the intersection with TRAIGA Prohibition 2 (intent to discriminate) and the healthcare-provider disclosure regime.
  • Texas Medical Board guidance on physician use of AI in clinical decision-making: TMB has signaled interpretive guidance is forthcoming in 2026-2027, addressing licensure-implications, documentation expectations, and the disclosure regime.
  • Texas Workforce Commission guidance on AI in hiring and workforce-management, TWC has not signaled formal guidance yet, but enforcement coordination with EEOC and Texas Workforce Commission Civil Rights Division is plausible.

The cumulative effect: a Texas employer in healthcare or insurance deploying AI is subject to TRAIGA + TDPSA + sector-specific TDI / TMB guidance + federal EEOC / Title VII / HIPAA / FTC. The TRAIGA-specific compliance memo is one piece of a broader multi-statute, multi-regulator stack. The L4 governance lead's portfolio mapping for a Texas-headquartered enterprise should capture all of this in a single artifact.

L1 Deliverable, Common Mistakes, and the Sandbox Decision Tree

The L1 deliverable for this lesson is a Texas TRAIGA compliance memo, a 4-6 page artifact for each AI deployment that affects Texas-resident users. The memo structure:

  1. System summary: Name, deployer entity, vendor, deployment surface, Texas-resident user count (approximate).
  2. Four-prohibition analysis, Per-prohibition row: applicable / not applicable / partially applicable, with rationale. For applicable prohibitions, the mitigation-evidence reference.
  3. Intent analysis (for systems implicating Prohibition 2) - Explicit documentation that the system was not designed with discriminatory intent; reference to bias-monitoring infrastructure; reference to remediation log if disparate-impact patterns have been identified.
  4. Disclosure analysis, Whether the deployment falls within the state-agency disclosure regime (and the disclosure mechanism), and whether it falls within the healthcare-provider disclosure regime (and the patient-facing disclosure mechanism).
  5. Sandbox decision, Whether the deployment is a candidate for the AI sandbox (and the rationale for opting in or staying out).
  6. Adjacent-statute overlay: TDPSA, sector-specific (TDI, TMB), federal (EEOC, Title VII, ADA, FCRA, ECOA, HIPAA), other state law (NYC LL 144, EU AI Act, etc.) that applies in parallel to TRAIGA.
  7. Refresh cadence: Quarterly review for substantive change; triggered review for vendor model upgrades, scope expansion, AG enforcement guidance, or incident occurrence.

The most common TRAIGA mistakes in May 2026:

Mistake 1 - Confusing TRAIGA with Colorado SB 24-205

Colorado SB 24-205 is federally stayed (April 27, 2026) and was broader in scope. Texas TRAIGA is active (January 1, 2026) and is narrower. Compliance posture cannot be cross-walked from one to the other. The most common confusion is assuming that disparate-impact testing satisfies TRAIGA (it does not, TRAIGA requires intent analysis) or assuming that TRAIGA contemplates impact assessments (it does not, there is no comprehensive impact-assessment requirement in the enacted version).

Mistake 2 - Assuming Disparate-Impact Protection

TRAIGA requires intent. Disparate impact alone is not a TRAIGA violation. But Title VII, NYC LL 144, EU AI Act Article 10, ECOA, and FHA still apply. A Texas employer deploying hiring AI that produces statistically unequal outcomes across protected classes is not safe simply because TRAIGA-intent is absent, federal disparate-impact liability is alive and well. The defensible posture is to monitor for disparate impact, remediate, and document, not to abandon disparate-impact testing because TRAIGA does not require it.

Mistake 3 - Over-Relying on AG-Only Enforcement

AG-only enforcement means no private right of action under TRAIGA. It does not mean no enforcement. It does not preempt federal regulator action. It does not preclude state-law claims under other statutes. The 2026 enforcement posture is limited; the 2027+ posture is expected to be more active. Compliance built on the assumption that AG-only enforcement equals deferred risk is mis-calibrated.

Mistake 4 - Ignoring State-Agency or Healthcare Disclosure

The administrative-violation enforcement targets (failure-to-disclose by state agencies, contractors, or healthcare providers) are likely to be among the earlier 2026-2027 AG actions because they are easier to establish than intent-based discrimination cases. Operational implementation of the disclosure regimes (banner, modal, patient notice, EOB language) is straightforward and should not be deferred.

Mistake 5 - Missing the AI Sandbox Opportunity

For Texas-headquartered or Texas-primary deployments of genuinely novel AI products, the AI sandbox is a real regulatory-relief option. Many compliance teams default to the conservative "treat everything as fully regulated" posture and miss the sandbox option. The sandbox decision tree should be a standing line item on the L1 compliance memo for each Texas deployment.

Mistake 6 - Skipping the Constitutional-Rights Analysis

Prohibition 4 (constitutional-rights infringement) is the broadest and least operationally precise of the four prohibitions. Compliance teams often skip the constitutional-rights analysis on the assumption that it is too vague to address. The defensible posture is the opposite: document a brief analysis explicitly, note the absence of state-actor or state-contractor status where applicable, and revisit as AG enforcement guidance emerges. The documentation is the defensibility.

Key Takeaways

  • Texas TRAIGA (HB 149) took effect January 1, 2026. The enacted version is materially narrower than the 2024 drafts: intent-based prohibitions only, no comprehensive impact-assessment requirement, AG-only enforcement, no private right of action.
  • Four prohibitions structure the substantive obligations: manipulation toward self-harm (Prohibition 1; analogous to EU Article 5(1)(a)); intent to discriminate (Prohibition 2; the narrowing that defines TRAIGA's scope, disparate impact alone is INSUFFICIENT); CSAM generation (Prohibition 3; layered on existing state and federal criminal law); constitutional-rights infringement (Prohibition 4; broadest and least operationally precise).
  • Intent-based discrimination is materially narrower than disparate-impact theories. Federal Title VII / EEOC, NYC LL 144, Colorado SB 24-205, and EU AI Act Article 10 all use disparate-impact methodologies. A hiring tool causing disparate impact without intentional discrimination is NOT a TRAIGA violation but remains subject to those other regimes. Document the intent analysis explicitly.
  • Penalties are $10,000-$200,000 per violation or $2,000-$40,000 per day for continuing violations. Substantial but not in the EU AI Act Article 99(2) €35M/7% tier. AG has prosecutorial discretion within the ranges.
  • AG-only enforcement is not no-risk. The Texas AG's office is standing up AI investigative capacity in 2026; first enforcement actions are expected in H2 2026 / 2027. Limited 2026 enforcement is not deferred risk.
  • State-agency and healthcare-provider disclosure obligations operate independently of the four prohibitions. State agencies and contractors must disclose AI use to citizens; healthcare providers using AI in clinical decisions must disclose to patients. Administrative-violation enforcement is likely to be among the earlier AG actions.
  • The AI sandbox is opt-in, AG-approved, time-limited, and provides relief from Texas regulatory requirements (not federal law, not the four core prohibitions). A genuine innovation-friendly provision for Texas-headquartered or Texas-primary novel deployments. The sandbox decision tree should be standing in the L1 compliance memo.
  • The multi-jurisdiction overlay is the operational center of gravity. Texas TRAIGA + NYC LL 144 + EU AI Act Article 27 FRIA + federal EEOC Title VII + FTC Section 5 + FCRA + Colorado SB 189 (forthcoming) all run in parallel. Build a common evidence base with jurisdiction-specific reconciliation layers; do not build separate evidence bases per jurisdiction.
  • Texas SB 1188 and adjacent state regulator guidance (TDI, TMB, TDPSA, TWC) extend the Texas AI stack beyond TRAIGA alone. A Texas healthcare or insurance deployer is subject to multiple Texas-specific regimes; the TRAIGA compliance memo is one component of a broader portfolio.
  • The L1 deliverable is a 4-6 page TRAIGA compliance memo per Texas deployment. Four-prohibition analysis, intent analysis where applicable, disclosure analysis, sandbox decision, adjacent-statute overlay, refresh cadence. The memo is the artifact that anchors L3 risk-practitioner work and L4 governance reporting.