Policy Guide · TRAIGA

AI Governance in Texas: The TRAIGA Era

Texas has its own AI statute, and it is already in force. What the Texas Responsible AI Governance Act prohibits, who enforces it, and the compliance checklist for anyone deploying AI in the state.

What is AI governance, and why does Texas have its own rules?

AI governance is how an organization keeps its AI systems lawful, safe, and accountable: inventories, risk assessment, human oversight, testing, and clear ownership. In Texas it stopped being optional on January 1, 2026, when TRAIGA took effect as one of the first comprehensive state AI laws in the country.

Texas chose a different path from the EU's sweeping AI Act and from heavier state proposals elsewhere: TRAIGA targets a specific list of prohibited uses, hinges most liability on intent, gives companies a 60-day cure window, and rewards good-faith testing. The result is a law that Texas businesses can realistically comply with, and that AI builders should understand before shipping anything consumer-facing in the state.

What does TRAIGA actually say?

TRAIGA (House Bill 149) prohibits AI built to manipulate people into harm, intentionally discriminate, generate CSAM, or run government social scoring and non-consensual biometric identification. The Texas Attorney General enforces it exclusively, with penalties up to $200,000 per uncurable violation.

TRAIGA at a glance
Provision What it means
What it is The Texas Responsible AI Governance Act (TRAIGA, House Bill 149), signed June 22, 2025
Effective date January 1, 2026 — already in force
Who it covers Developers and deployers of AI systems doing business in Texas, plus government agencies
Core prohibitions AI designed to manipulate behavior into harm, intentional unlawful discrimination, CSAM generation, government social scoring, and government biometric identification without consent
Enforcement Texas Attorney General only (no private lawsuits); up to $200,000 per uncurable violation and $40,000 per day for continuing violations, with a 60-day cure period
Safe harbor Substantial compliance with a recognized framework such as the NIST AI Risk Management Framework
Sandbox A 36-month regulatory sandbox for testing AI systems with reduced regulatory exposure

This is an editorial summary, not legal advice. For anything consequential, put the statute and Texas counsel in the loop; the primary sources are linked below.

How do you build TRAIGA-ready AI governance?

Five steps cover most Texas companies: inventory your AI systems, screen them against the prohibited uses, align with the NIST AI Risk Management Framework (the statute's explicit safe harbor), document testing and intent, and assign a named owner.

Step 1

Inventory your AI systems

List every AI system you develop or deploy that touches Texans, and flag any involved in consequential decisions: employment, healthcare, housing, insurance, financial services, or government services.

Step 2

Screen against the prohibited uses

Verify nothing you ship could be characterized as behavioral manipulation causing harm, intentional discrimination, or (for public entities) social scoring or non-consensual biometric identification.

Step 3

Adopt the NIST AI Risk Management Framework

Substantial compliance with NIST AI RMF is TRAIGA's explicit safe harbor. Map your practices to it and document the mapping.

Step 4

Document intent and testing

TRAIGA's prohibitions largely hinge on intent, and good-faith testing that uncovers issues supports a defense. Keep records of red-teaming, audits, and fixes.

Step 5

Assign an owner and watch the AG

Governance fails without a named owner. Enforcement guidance will come from the Texas Attorney General's office; assign someone to track it.

Building the systems this governance wraps around? See enterprise AI in Texas for the deployment side, and AI ethics in Texas for the research and principles the law grew out of.

What software runs AI governance?

AI governance software catalogs your models, maps your controls to frameworks like NIST AI RMF, and monitors for bias, drift, and shadow AI. The major platforms are IBM watsonx.governance, Microsoft Purview, Credo AI, and OneTrust, and several of the biggest vendors run their operations from Texas.

AI governance software platforms, their focus, and Texas footprint
Platform Focus Texas footprint
IBM watsonx.governance ML lifecycle management and model risk tracking Major Austin campus, plus Houston and Dallas offices
Microsoft Purview Data lineage, classification, and security controls for Azure-centric stacks Large hubs in Austin, Irving, and Houston
Credo AI Policy-driven compliance mapping across models, apps, and agents Bay Area HQ; distributed/remote team in Texas
OneTrust AI Governance Privacy-first AI asset inventory and lifecycle approval workflows Atlanta HQ; remote sales and engineering across Texas metros
CrowdStrike AI security: protecting LLM environments, shadow-AI detection, agentic AI defense Headquartered in Austin
Trend Micro Enterprise AI cybersecurity, risk monitoring, and data compliance US headquarters in Irving

Two buying notes for Texas companies. First, weight the NIST AI RMF mapping heavily: substantial compliance with NIST is TRAIGA's safe harbor, so a platform that documents that mapping is doing your legal homework. Second, governance platforms and AI security platforms (CrowdStrike, Trend Micro) solve different halves of the problem — policy and lifecycle on one side, protecting models and detecting unsanctioned AI use on the other. Mature programs run both.

What about government AI in Texas?

Texas government entities face the strictest TRAIGA provisions: bans on social scoring and non-consensual biometric identification, plus disclosure duties when residents interact with AI systems.

Public-sector AI is also where Texas research meets policy in practice. UT Austin's Good Systems initiative has advised the City of Austin on AI governance, and the state's cyber-and-government AI capacity is concentrated in San Antonio, home to the largest government security cluster outside Washington DC. For agencies and their vendors, the compliance bar is higher and the scrutiny earlier.

AI Governance & TRAIGA: FAQ

What is AI governance?

AI governance is the set of policies, processes, and accountability structures an organization uses to make sure its AI systems are lawful, safe, and aligned with its goals: system inventories, risk assessments, human oversight of consequential decisions, testing and audit trails, and clear ownership. In Texas, governance moved from best practice to legal necessity when TRAIGA took effect on January 1, 2026.

What is TRAIGA, the Texas AI law?

TRAIGA is the Texas Responsible Artificial Intelligence Governance Act (House Bill 149), signed June 22, 2025 and effective January 1, 2026. It prohibits AI systems designed to manipulate behavior into harm, intentionally discriminate, generate CSAM, or (for government) run social scoring or non-consensual biometric identification. It is enforced exclusively by the Texas Attorney General, with penalties up to $200,000 per uncurable violation.

Does TRAIGA apply to my company?

If you develop or deploy AI systems and do business in Texas, most likely yes — the law is not limited to companies headquartered in the state. Obligations differ for developers, deployers, and government entities, and consumer-facing government AI carries disclosure duties. When in doubt, have Texas counsel map your systems against the statute.

How do I comply with TRAIGA?

The practical path: inventory your AI systems, screen them against the prohibited uses, align your program with the NIST AI Risk Management Framework (TRAIGA's explicit safe harbor), document testing and intent, and assign a named governance owner. The 60-day cure period and good-faith-testing protections reward companies that find and fix issues themselves.

What is AI governance software?

AI governance software is a category of platforms that catalog, monitor, and manage AI models and their risk. Core capabilities: an inventory/registry of models, datasets, agents, and vendors; policy and compliance workflows that map controls to frameworks like NIST AI RMF and the EU AI Act; and monitoring for bias, drift, and security issues. Leading platforms include IBM watsonx.governance, Microsoft Purview, Credo AI, and OneTrust AI Governance — and for Texas buyers, the NIST-mapping capability matters most, since NIST alignment is TRAIGA's safe harbor.

What is the TRAIGA regulatory sandbox?

TRAIGA creates a 36-month regulatory sandbox that lets companies test innovative AI systems with reduced regulatory exposure. For Texas AI startups, it is a genuine advantage: a legal pathway to experiment that most states do not offer.

Is AI governance different for government agencies in Texas?

Yes. Texas government entities face additional TRAIGA restrictions, including bans on social scoring and on biometric identification without consent, plus disclosure requirements when consumers interact with AI systems. Public-sector AI in Texas also draws on research partnerships like UT Austin's Good Systems initiative, which has advised the City of Austin on AI policy.