LIVE NOW · Effective January 1, 2026
Texas TRAIGA
(HB 149)
The Texas Responsible AI Governance Act is in force. It includes prohibited-use, disclosure, enforcement, cure, and affirmative-defense provisions. Penalty and defense analysis depends on the provision and facts; operational records may support that analysis but do not establish the legal result.
What the law says
TRAIGA is narrower than the argument around it suggests. It bans a short list of uses outright, and it puts disclosure duties on government agencies and on healthcare providers. Most private companies are left with no general obligation to announce that AI is in the room, which is where Texas parts company with Colorado and the EU.
Prohibited AI practices
- • Behavioral manipulation: AI that incites self-harm, harm to others, or criminal activity (applies to all entities)
- • Social scoring: government AI that classifies persons based on social behavior (government entities only)
- • Discrimination: AI used to intentionally discriminate against protected classes
- • Unauthorized biometrics: government capture without consent
- • Constitutional infringement: AI designed to infringe constitutional rights
- • CSAM: AI-generated sexually explicit content involving minors
Disclosure requirements
- • Government agencies: Must disclose AI use before or at the time of consumer interaction. The disclosure has to be clear and conspicuous, written in plain language, and free of dark patterns
- • Healthcare providers: Must disclose AI use no later than when service is first provided; in emergencies, as soon as reasonably possible
- • Private companies: No general disclosure obligation (unlike Colorado/EU)
Companion bill SB 1188 adds human oversight requirements for AI in medical decisions; our healthcare page covers the runtime evidence behind that oversight.
Employment uses can raise TRAIGA and other discrimination questions, but scope and liability are fact-specific. See how bounded operational records can support review of a configured hiring workflow on our hiring AI page.
Penalties (Section 552.105)
AG enforcement with injunctive relief + attorney’s fees. Licensed professionals face additional sanctions up to $100K (Section 552.106). 60-day notice and cure period before AG action (Section 552.104).
Five affirmative defense grounds (Section 552.105(e))
TRAIGA identifies affirmative-defense and rebuttable-presumption provisions. Their availability and effect depend on the current statutory text and facts; framework mapping or a signed record does not activate a defense by itself:
1. Third-party misuse: not liable if another person uses the AI system in a prohibited manner
2. Discovery through feedback: violation discovered via feedback from developers, deployers, or other persons
3. Discovery through testing: including adversarial and red-team testing
4. Agency guidelines: following guidelines set by applicable state agencies
5. Framework compliance: substantial compliance with NIST AI RMF (AI 600-1) or another nationally/internationally recognized framework
Connect policy to the configured workflow
GLACIS can preserve signed reports from selected control paths and map them to a broader review package. Those records may support factual diligence; counsel and the relevant authority determine whether a statutory defense applies.
1. Assess your gaps
We map one named AI workflow against TRAIGA requirements and NIST AI RMF controls.
2. Continuous attestation
Route in-scope AI decisions through the configured path. SDK or self-hosted receipts may be operator-signed; receipts minted through the Glacis portal may add a Glacis service-operated witness countersignature and inclusion proof. Covered payload fields can be excluded.
3. Activate your defense
Assemble bounded records that may be relevant to selected affirmative-defense elements under Section 552.105(e). The records do not establish that every element is met or that the defense will be accepted.
A signed record preserves the presented claim and signer attribution for covered fields. It does not establish complete coverage, framework adherence, reasonable care, or a legal defense.