Texas AI Legislation in 2026
Texas enacted the Texas Responsible AI Governance Act (TRAIGA, HB 149), signed June 22, 2025 and in force since January 1, 2026, alongside a cluster of bills on health records, government AI use, and deepfakes. Texas chose an intent-based liability model over Colorado's risk-based one, putting the heaviest duties on government and offering industry a sandbox and a NIST-aligned safe harbor.
The Texas Picture
Texas in 2026 has staked out a distinctly different position from the other early movers in state AI regulation, and the contrast is most visible when you set TRAIGA against the Colorado AI Act. Colorado built its framework around risk and outcomes. A deployer of a high-risk system there can face liability for algorithmic discrimination measured by disparate impact, regardless of whether anyone intended a harmful result. Texas, through HB 149, deliberately rejected that model. TRAIGA is intent-based. The statute reaches the intentional deployment of AI to discriminate, to incite harm, to facilitate crime, or to produce illegal content, and it expressly declines to treat a disparate outcome, on its own, as a violation. That single design choice changes the compliance calculus for almost every commercial actor in the state.
The second defining feature is that the heaviest obligations fall on government, not industry. The most prescriptive parts of TRAIGA govern state agencies and local governments: disclosure of AI use to the public, a prohibition on AI-driven social scoring, and a ban on biometric identification drawn from public sources without informed consent. For private builders and businesses, the law functions more as a set of bright-line prohibitions on bad-faith conduct than as a sweeping operational mandate. That posture is consistent with the broader Texas legislative instinct, which is to constrain the state's own use of powerful technology more tightly than it constrains the market.
Enforcement and innovation are handled in parallel, and I think this is the part executives should pay closest attention to. Enforcement is centralized entirely in the Texas Attorney General. There is no private right of action, there is a 60-day cure period for violations that can be cured, and penalties scale from modest curable amounts up to the $200,000 range for serious uncurable violations, plus daily penalties for continuing conduct. The Attorney General is also required to operate a public complaint portal, so the real-world enforcement signal will come from how aggressively that office prioritizes referrals. On the other side of the ledger sits the DIR-run regulatory sandbox, which lets approved entities test systems for up to 36 months with reduced exposure, and a meaningful safe harbor for organizations that substantially align with the NIST AI Risk Management Framework, including its Generative AI Profile.
For builders and businesses, the practical takeaway is straightforward. If you are operating in good faith, documenting your risk processes, mapping to NIST, and avoiding the enumerated prohibited uses, your TRAIGA exposure is manageable and far lighter than a Colorado-style obligation. The strategic risk is not accidental disparate impact, it is conduct that an Attorney General could characterize as intentional misuse, plus the biometric and consumer-disclosure rules that now have teeth. Looking ahead, I expect the Texas model, intent-based, innovation-friendly, and AG-enforced, to become a reference point for other Republican-led states drafting their own AI statutes in the 2026 and 2027 sessions, sharpening the national split between Texas-style and Colorado-style frameworks while federal action remains unsettled.
Tracked Texas AI Bills
Texas Responsible AI Governance Act (TRAIGA)
Signed by Governor Abbott on June 22, 2025, in force since January 1, 2026. Prohibits the intentional development or deployment of AI to incite harm, facilitate crime, unlawfully discriminate against a protected class, produce CSAM, or infringe constitutional rights. Liability turns on intent, not disparate impact. Government use carries the heaviest obligations.
Key Provisions
- Intent-based liability, disparate impact alone is not a violation
- Bans government social scoring and biometric identification from public sources without consent
- Exclusive Attorney General enforcement, no private right of action, 60-day cure period
- Civil penalties up to roughly $200,000 for uncurable violations plus daily penalties
- DIR-run regulatory sandbox for up to 36 months of testing
- Safe harbor for substantial alignment with the NIST AI Risk Management Framework
AI in Electronic Health Records
Signed June 20, 2025. Governs the use of AI in creating medical records, requires provider review of AI-generated records per Texas Medical Board standards, and requires covered entities to store electronic health records within the United States.
Key Provisions
- Provider review of AI-generated medical records
- US-based storage requirement for electronic health records
- Patient notification regarding AI use in diagnostics
State Agency Use of AI
Signed June 20, 2025. Directs the Department of Information Resources to maintain an inventory of AI systems used by state agencies and to create an AI code of ethics for state and local government.
Key Provisions
- DIR inventory of state-agency AI systems
- AI code of ethics covering oversight, fairness, transparency, privacy, and accountability
AI-Generated Intimate Deepfakes
Signed June 20, 2025. Criminalizes knowingly producing or distributing nonconsensual AI-generated intimate imagery, with felony treatment where a minor is depicted.
Key Provisions
- Criminalizes nonconsensual AI-generated intimate imagery
- Felony where a minor is depicted
Download The AI Law Brief of All 50 States
A formatted PDF covering every tracked AI bill across all 50 states, with status, effective dates, and key provisions. Useful for compliance teams and board packs.
* You will also be subscribed to my newsletter.
Brief sent. Check your inbox.