
Short answer: yes, the Texas AI law is in force. The Texas Responsible Artificial Intelligence Governance Act, called TRAIGA, is House Bill (H.B.) 149 of the 89th Legislature (see the bill page). It took effect on January 1, 2026. It is mostly a list of banned uses, such as building AI to push people toward self-harm or to unlawfully discriminate on purpose. Only the Texas attorney general (the AG) can enforce it, apart from license sanctions (penalties on a professional or business license) by other state agencies after an AG referral. A business gets 60 days to fix a problem after a written notice. This is not legal advice. Ask a lawyer whether it applies to you.
TL;DR
- Status on October 5, 2026: in force since January 1, 2026. I checked the official Texas code that day and found no later change. A search of news and law-firm alerts on that date turned up no court order stopping it.
- Who: anyone who does business in Texas, makes a product Texans use, or builds or deploys AI in Texas.
- What: bans on intentional misuse for everyone. Disclosure and social scoring rules for government. Disclosure rules for health care providers.
- Enforcement: the AG only, with a 60-day cure window (time to fix a problem before a lawsuit). The statute says it creates no private lawsuit.
- Versus Colorado: Texas asks businesses to avoid listed bad intent. It sets no duty for them to write an impact assessment (a written risk review) or to notify customers.
The dates, in order
On October 5, 2026, I read the enrolled act (the final text both chambers passed), the legislature's bill page and the codified text (the act as filed in the state's code).
- March 14, 2025: H.B. 149 filed.
- April 23, 2025: passed the House.
- May 23, 2025: passed the Senate with amendments.
- May 30, 2025: the House agreed to the Senate changes.
- June 22, 2025: signed by the governor.
- January 1, 2026: the effective date, set by section 10 of the act.
- September 1, 2026: the deadline in section 8 for the AG to post an online complaint form. The AG's Consumer AI Rights page now carries a "File An AI Complaint" link.
The legislature's bill page lists these steps. The act became Subtitle D of Title 11 of the Texas Business and Commerce Code, chapters 551 to 554, titled "Artificial Intelligence Protection." A subtitle is a group of chapters in a code. The codified text ends each section with a history line that reads "Added by Acts 2025, 89th Leg., R.S., Ch. 1174 (H.B. 149)." That means the 89th Legislature, Regular Session, chapter 1174. No later amendment is listed there. For why a law exists in two forms, see what a session law is.
Who it applies to
Section 551.002 says the subtitle "applies only to a person who" does one of three things. The person promotes, advertises or conducts business in Texas. Or the person produces a product or service used by Texas residents. Or the person develops or deploys an AI system in Texas. That reaches a company outside Texas whose product Texans use.
Section 551.001 defines an "artificial intelligence system" as a "machine-based system" that "infers from the inputs the system receives how to generate outputs." Outputs include "content, decisions, predictions, or recommendations."
A developer builds a system that is sold or offered in Texas. A deployer puts one to use in Texas. Section 552.001 defines both. A consumer is a Texas resident "acting only in an individual or household context." An employee at work is not a consumer under this law.
A governmental entity means a state or local government body. It does not include hospital districts or public colleges and universities.
What it bans and requires
Most readers are surprised by how little it asks of a private business. The text has no impact assessment duty. It has no general customer notice duty.
| Duty | Who it applies to | Where in the statute |
|---|---|---|
| Do not build or use AI that "intentionally aims to incite or encourage" self-harm, harm to others or crime | Any person | § 552.052 |
| Do not use AI to impair constitutional rights, if that is the "sole intent" | Any person | § 552.055 |
| Do not build or use AI "with the intent to unlawfully discriminate against a protected class" (a group the civil rights laws protect, such as race, sex, age, religion or disability) | Any person, with exceptions for insurers and banks | § 552.056 |
| Do not build or share AI made to produce illegal child images, unlawful deepfakes (fake images or video made with AI), or sexual chat that imitates a child | Any person | § 552.057 |
| Tell people they are dealing with AI, before or at the time of use | A governmental agency offering a consumer-facing system | § 552.051(b) |
| Tell patients AI is used in their care, no later than the first service | A health care provider | § 552.051(f) |
| No social scoring that leads to unjustified treatment | Government only | § 552.053 |
| No identifying people by biometrics (fingerprints, voiceprints, iris scans) or scraping their images without consent, if it infringes rights | Government only | § 552.054 |
| Tell people and get their consent before capturing a face or fingerprint for commercial use | Any person | § 503.001 |
Two points in the table need care.
Intent is the test. Section 552.056(c) says "a disparate impact is not sufficient by itself to demonstrate an intent to discriminate." A disparate impact is a bad result that falls harder on one group. A biased result alone does not prove a violation.
The notice rule is narrow. Section 552.051(b) says a "governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose" this to each consumer "before or at the time of interaction." That is a duty for government. A private chatbot owner has no general duty under TRAIGA. The one private-sector notice is for health care, in section 552.051(f). Some summaries online get this wrong.
Section 503.001 is an older biometric law that TRAIGA amended. It sits outside chapter 552, and the same AG can enforce it. A face image found online does not count as consent unless the person posted it. Training data gets some exceptions. A violation of that section carries a civil penalty of up to $25,000 for each violation.
Limits and exemptions
- Section 552.056(d) exempts insurers already covered by insurance anti-bias laws from the discrimination ban.
- Under section 552.056(e), a federally insured bank "is considered to be in compliance" if it follows banking law.
- Section 552.002 says the chapter cannot be read to limit free speech. It also keeps insurance oversight with the Department of Insurance.
- The AG cannot seek a penalty over an AI system "that has not been deployed" (section 552.105(f)).
- Section 552.003 overrides any city or county rule on AI. That is called preemption, meaning the state law blocks local rules.
Who enforces it, and what it costs
Section 552.101(a) gives the AG "exclusive authority to enforce this chapter," except for licensing sanctions by other agencies. Section 552.101(b) adds: "This chapter does not provide a basis for, and is not subject to, a private right of action for a violation of this chapter or any other law." A private right of action is a person's right to sue directly.
A case moves in these steps. A civil penalty is a money penalty paid to the state.
- A consumer files a complaint through the AG's web form (§ 552.102).
- The AG may issue a civil investigative demand, a written order to hand over information (§ 552.103). It can ask for the system's purpose, training data types, outputs, metrics, known limits and safeguards.
- If the AG finds a violation, it must send written notice naming the provisions (§ 552.104(a)).
- The AG may not sue before day 60. It also may not sue if, within 60 days, you cure the violation and send a written statement with proof and policy changes (§ 552.104(b)).
- If you do not cure, the penalties in § 552.105 apply.
| Kind of violation (a court decides if it is curable or uncurable, meaning fixable or not) | Civil penalty (§ 552.105(a)) |
|---|---|
| Curable, or breaking a promise made in a cure statement | $10,000 to $12,000 each |
| Uncurable | $80,000 to $200,000 each |
| Continuing | $2,000 to $40,000 per day |
The AG can also seek an injunction, which is a court order to stop the conduct, plus fees and costs. Section 552.106 lets a licensing agency sanction a licensee it oversees, with a license suspension or a fine of up to $100,000. That needs a court finding and an AG recommendation first.
The law helps defendants too. Section 552.105(c) sets "a rebuttable presumption that a person used reasonable care." That means a court starts by assuming you were careful unless the state proves otherwise. Under subsection (e), you are not liable if someone else misuses your system. You are also protected if you find a problem through red-team testing, which is testing where staff try to break the system. So do agency guidance and an internal review that follows a known framework, such as the AI Risk Management Framework from the National Institute of Standards and Technology.
The test program and the council
Chapter 553 sets up a regulatory sandbox, which is a program that lets a firm test an AI system under state watch without the usual license. The Department of Information Resources runs it. Tests can last up to 36 months. The AG cannot bring charges over a waived rule during the test. The ban list in Subchapter B of chapter 552 cannot be waived (§ 553.051(e)). Applicants need approval and must file quarterly reports. On October 5, 2026, I checked the statute, the Department of Information Resources' AI pages and the Texas administrative rules. I found no published application form or rule for this sandbox.
Chapter 554 creates the Texas Artificial Intelligence Council, with seven members. It advises the legislature. Section 554.103 bars it from adopting "rules or guidance that is binding for any entity."
How it differs from Colorado
Colorado's law starts January 1, 2027. It covers tools that help decide jobs, loans, housing and similar matters. Under sections 6-1-1702 and 6-1-1704 of the Colorado code, developers share documents and users send notices and 30-day letters. Texas has no such duties. Texas bans listed bad purposes and leans on proof of intent. Both give enforcement to the AG alone, both offer a 60-day cure window, and both say they create no new private lawsuit. Texas also lists penalty amounts. Colorado points to its Consumer Protection Act.
Do not mix it up with S.B. 1964
A separate 2025 law, Senate Bill 1964, added rules for state agencies' own AI use in Government Code chapter 2054, effective September 1, 2025. It requires impact assessments for "heightened scrutiny" systems, meaning AI built to make or control a major decision about a person. It is not part of TRAIGA, and it binds public bodies.
A worked example
A Texas telehealth clinic adds an AI assistant that answers patient questions. Section 552.051(f) says the provider must tell the patient AI is used, no later than the first service. The clinic adds that notice to its intake form. Months later, a patient complains through the AG's web form. The office sends a demand for the system's purpose, data types and safeguards. The clinic's test logs and review notes now matter. If the office finds a violation, the clinic gets a written notice and 60 days. It fixes the issue, files its written statement, and the office cannot sue.
TRAIGA compliance checklist for a business
- Work out which role you hold: developer, deployer, health care provider, collector of faces or fingerprints, or none of these. Then list where your AI touches Texans, including products sold from out of state.
- Look for any use that could be read as pushing self-harm, crime or intentional bias. Write down your purpose for each system.
- If you are a health care provider, add the disclosure before the first service.
- If you capture faces or fingerprints, get clear consent first.
- Keep test and review records. They are a defense under § 552.105(e).
- Pick a person to answer an AG notice inside 60 days.
What goes wrong
The first error is using a Colorado checklist. A Texas business that builds impact assessments is solving the wrong problem. The second is treating a vendor's chatbot notice as a TRAIGA duty. The third is ignoring the 60-day clock. Miss it and the chance to cure is gone.
Federal action has not changed this. Executive Order 14365, signed December 11, 2025, calls for a review of state AI laws, and the Federal Register prints it at volume 90, page 58499. Its text names Colorado's law and says nothing about Texas. An executive order is a presidential directive to federal agencies, and it cannot repeal a state statute.
How to check the current text
Open the statute on the legislature's site. Read the history line under each section. It lists every act that changed it. Texas holds regular sessions in odd years, so check again after January 2027. This guide is part of US Law Data: The Complete Guide. To cite Texas law, see how to find and cite Texas law.
FAQ
Is the Texas AI law in effect? Yes. TRAIGA took effect on January 1, 2026. I found no amendment since.
What does TRAIGA actually prohibit? It bans building or using AI with a bad aim. The listed aims are pushing people toward self-harm, harm or crime, impairing constitutional rights, unlawful bias, and making child pornography or unlawful deepfakes. Government also may not use social scoring, or identify people by biometrics without consent.
Does my business have to tell customers they are talking to AI? Not under TRAIGA, unless you are a governmental agency or a health care provider. Other laws may still require it.
Can I be sued by a customer under TRAIGA? The statute says it creates no private right of action. Only the AG can enforce it. Claims under other laws are separate.
What are the penalties? Civil penalties under section 552.105 run $10,000 to $12,000 for a curable violation and $80,000 to $200,000 for an uncurable one, plus $2,000 to $40,000 per day for a continuing one. The AG can also seek an injunction and fees, and a licensing agency can add sanctions.
Do I get a chance to fix a violation? Yes. The AG must give written notice and wait 60 days. If you cure and report in writing, no suit may follow.
Is there a Texas AI sandbox? The statute creates one with tests of up to 36 months. I could not find a published application process yet. Check the Department of Information Resources' AI pages at dir.texas.gov.
Where do I read the official text? The Texas statutes site on capitol.texas.gov has chapter 552. The legislature's bill page for H.B. 149 has the enrolled act.
If you build or buy tools that need statute text and its amendment history behind guides like this, start with the US primary law API.
New legal AI guides, weekly.
Further Reading
California AI Laws Explained: SB 53 and the Rest
Read postNew York RAISE Act Explained: Who It Covers and When It Starts
Read postUtah AI Law Explained From the Statute: What Is in Force Now
Read postTexas Attorney General Opinions: How to Find, Read and Cite Them
Read postColorado AI Law Explained From the Statute (SB 24-205 and SB 26-189)
Read postFederal vs State Law: Which One Applies to You?
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.