Inventory your AI systems
List every AI system you develop or deploy that touches Texans, and flag any involved in consequential decisions: employment, healthcare, housing, insurance, financial services, or government services.
Texas has its own AI statute, and it is already in force. What the Texas Responsible AI Governance Act prohibits, who enforces it, and the compliance checklist for anyone deploying AI in the state.
AI governance is how an organization keeps its AI systems lawful, safe, and accountable: inventories, risk assessment, human oversight, testing, and clear ownership. In Texas it stopped being optional on January 1, 2026, when TRAIGA took effect as one of the first comprehensive state AI laws in the country.
Texas chose a different path from the EU's sweeping AI Act and from heavier state proposals elsewhere: TRAIGA targets a specific list of prohibited uses, hinges most liability on intent, gives companies a 60-day cure window, and rewards good-faith testing. The result is a law that Texas businesses can realistically comply with, and that AI builders should understand before shipping anything consumer-facing in the state.
TRAIGA (House Bill 149) prohibits AI built to manipulate people into harm, intentionally discriminate, generate CSAM, or run government social scoring and non-consensual biometric identification. The Texas Attorney General enforces it exclusively, with penalties up to $200,000 per uncurable violation.
| Provision | What it means |
|---|---|
| What it is | The Texas Responsible AI Governance Act (TRAIGA, House Bill 149), signed June 22, 2025 |
| Effective date | January 1, 2026 — already in force |
| Who it covers | Developers and deployers of AI systems doing business in Texas, plus government agencies |
| Core prohibitions | AI designed to manipulate behavior into harm, intentional unlawful discrimination, CSAM generation, government social scoring, and government biometric identification without consent |
| Enforcement | Texas Attorney General only (no private lawsuits); up to $200,000 per uncurable violation and $40,000 per day for continuing violations, with a 60-day cure period |
| Safe harbor | Substantial compliance with a recognized framework such as the NIST AI Risk Management Framework |
| Sandbox | A 36-month regulatory sandbox for testing AI systems with reduced regulatory exposure |
This is an editorial summary, not legal advice. For anything consequential, put the statute and Texas counsel in the loop; the primary sources are linked below.
Five steps cover most Texas companies: inventory your AI systems, screen them against the prohibited uses, align with the NIST AI Risk Management Framework (the statute's explicit safe harbor), document testing and intent, and assign a named owner.
List every AI system you develop or deploy that touches Texans, and flag any involved in consequential decisions: employment, healthcare, housing, insurance, financial services, or government services.
Verify nothing you ship could be characterized as behavioral manipulation causing harm, intentional discrimination, or (for public entities) social scoring or non-consensual biometric identification.
Substantial compliance with NIST AI RMF is TRAIGA's explicit safe harbor. Map your practices to it and document the mapping.
TRAIGA's prohibitions largely hinge on intent, and good-faith testing that uncovers issues supports a defense. Keep records of red-teaming, audits, and fixes.
Governance fails without a named owner. Enforcement guidance will come from the Texas Attorney General's office; assign someone to track it.
Building the systems this governance wraps around? See enterprise AI in Texas for the deployment side, and AI ethics in Texas for the research and principles the law grew out of.
AI governance software catalogs your models, maps your controls to frameworks like NIST AI RMF, and monitors for bias, drift, and shadow AI. The major platforms are IBM watsonx.governance, Microsoft Purview, Credo AI, and OneTrust, and several of the biggest vendors run their operations from Texas.
| Platform | Focus | Texas footprint |
|---|---|---|
| IBM watsonx.governance | ML lifecycle management and model risk tracking | Major Austin campus, plus Houston and Dallas offices |
| Microsoft Purview | Data lineage, classification, and security controls for Azure-centric stacks | Large hubs in Austin, Irving, and Houston |
| Credo AI | Policy-driven compliance mapping across models, apps, and agents | Bay Area HQ; distributed/remote team in Texas |
| OneTrust AI Governance | Privacy-first AI asset inventory and lifecycle approval workflows | Atlanta HQ; remote sales and engineering across Texas metros |
| CrowdStrike | AI security: protecting LLM environments, shadow-AI detection, agentic AI defense | Headquartered in Austin |
| Trend Micro | Enterprise AI cybersecurity, risk monitoring, and data compliance | US headquarters in Irving |
Two buying notes for Texas companies. First, weight the NIST AI RMF mapping heavily: substantial compliance with NIST is TRAIGA's safe harbor, so a platform that documents that mapping is doing your legal homework. Second, governance platforms and AI security platforms (CrowdStrike, Trend Micro) solve different halves of the problem — policy and lifecycle on one side, protecting models and detecting unsanctioned AI use on the other. Mature programs run both.
Texas government entities face the strictest TRAIGA provisions: bans on social scoring and non-consensual biometric identification, plus disclosure duties when residents interact with AI systems.
Public-sector AI is also where Texas research meets policy in practice. UT Austin's Good Systems initiative has advised the City of Austin on AI governance, and the state's cyber-and-government AI capacity is concentrated in San Antonio, home to the largest government security cluster outside Washington DC. For agencies and their vendors, the compliance bar is higher and the scrutiny earlier.
AI governance is the set of policies, processes, and accountability structures an organization uses to make sure its AI systems are lawful, safe, and aligned with its goals: system inventories, risk assessments, human oversight of consequential decisions, testing and audit trails, and clear ownership. In Texas, governance moved from best practice to legal necessity when TRAIGA took effect on January 1, 2026.
TRAIGA is the Texas Responsible Artificial Intelligence Governance Act (House Bill 149), signed June 22, 2025 and effective January 1, 2026. It prohibits AI systems designed to manipulate behavior into harm, intentionally discriminate, generate CSAM, or (for government) run social scoring or non-consensual biometric identification. It is enforced exclusively by the Texas Attorney General, with penalties up to $200,000 per uncurable violation.
If you develop or deploy AI systems and do business in Texas, most likely yes — the law is not limited to companies headquartered in the state. Obligations differ for developers, deployers, and government entities, and consumer-facing government AI carries disclosure duties. When in doubt, have Texas counsel map your systems against the statute.
The practical path: inventory your AI systems, screen them against the prohibited uses, align your program with the NIST AI Risk Management Framework (TRAIGA's explicit safe harbor), document testing and intent, and assign a named governance owner. The 60-day cure period and good-faith-testing protections reward companies that find and fix issues themselves.
AI governance software is a category of platforms that catalog, monitor, and manage AI models and their risk. Core capabilities: an inventory/registry of models, datasets, agents, and vendors; policy and compliance workflows that map controls to frameworks like NIST AI RMF and the EU AI Act; and monitoring for bias, drift, and security issues. Leading platforms include IBM watsonx.governance, Microsoft Purview, Credo AI, and OneTrust AI Governance — and for Texas buyers, the NIST-mapping capability matters most, since NIST alignment is TRAIGA's safe harbor.
TRAIGA creates a 36-month regulatory sandbox that lets companies test innovative AI systems with reduced regulatory exposure. For Texas AI startups, it is a genuine advantage: a legal pathway to experiment that most states do not offer.
Yes. Texas government entities face additional TRAIGA restrictions, including bans on social scoring and on biometric identification without consent, plus disclosure requirements when consumers interact with AI systems. Public-sector AI in Texas also draws on research partnerships like UT Austin's Good Systems initiative, which has advised the City of Austin on AI policy.