Texas Responsible Artificial Intelligence Governance Act
A narrowed governance statute focused on state-agency AI use, with bans on AI designed for behavioural manipulation, unlawful discrimination, or producing unlawful deepfake content, and a regulatory sandbox.
Overview
Duties turn on intent rather than on risk classes or impact assessments: the discrimination prohibition requires intent to unlawfully discriminate, and the statute states outright that disparate impact is not sufficient by itself to demonstrate that intent, which is the clearest drafting difference from Colorado-style or EU-style AI rules. Reach is broad on paper, covering any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in the state, yet the affirmative disclosure duty lands on governmental agencies and healthcare providers, and 'consumer' is defined to exclude individuals acting in a commercial or employment context, which keeps most workplace AI outside it. Enforcement is a single channel: a consumer complaint through an Attorney General portal, then a civil investigative demand, then written notice identifying the provisions breached and a 60 day window in which curing the violation, documenting the cure and changing internal policies blocks any action. Penalties are tiered by whether the court finds the violation curable, from $10,000 to $12,000 for curable breaches up to $80,000 to $200,000 for uncurable ones, with a rebuttable presumption of reasonable care and defences for third-party misuse and for substantial compliance with the NIST Generative AI Profile. There is no private right of action, and the chapter preempts local AI ordinances.
Key dates
- Jun 22, 2025Signed into law
- Jan 1, 2026In force
Risk areas addressed
Who it applies to
The subtitle applies to any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in the state, with no headcount, revenue or sector threshold (§ 551.002). Consumer disclosure, social scoring and biometric identification provisions bind governmental entities and agencies, with 'governmental entity' defined to exclude hospital districts created under the Health and Safety Code or Article IX of the Texas Constitution and institutions of higher education (§ 552.001(3)); providers of health care services carry their own patient-facing disclosure duty. Insurance entities regulated under unfair discrimination and unfair practices statutes are carved out of the discrimination section, and a federally insured financial institution that complies with all federal and state banking law is deemed compliant with it (§ 552.056(d) and (e)).
Key obligations
- As a governmental agency making an AI system available to interact with consumers, disclose before or at the time of interaction that the consumer is interacting with an AI system, in clear and conspicuous plain language, with no dark pattern, and regardless of whether the fact would be obvious to a reasonable consumer (§ 552.051(b), (c) and (d)).
- Where AI is used in relation to a health care service or treatment, give that disclosure to the recipient or their personal representative no later than the date the service or treatment is first provided, or as soon as reasonably possible in an emergency (§ 552.051(f)).
- Do not develop or deploy an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self-harm including suicide, to harm another person, or to engage in criminal activity (§ 552.052).
- As a governmental entity, do not use or deploy an AI system that assigns a social score or similar categorical valuation from social behaviour or personal characteristics where the result may be detrimental treatment in an unrelated context, treatment disproportionate to the behaviour observed, or infringement of a constitutional or statutory right (§ 552.053).
- Governmental entities must not develop or deploy an AI system to uniquely identify a specific individual from biometric data, or to gather images or other media from the internet or other public sources without consent, where that gathering would infringe an individual's rights under the US or Texas Constitution or state or federal law (§ 552.054(b)).
- Do not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law, noting that race, colour, national origin, sex, age, religion and disability are named and that disparate impact alone does not establish the required intent (§ 552.056(b) and (c)).
- Do not develop or distribute an AI system with the sole intent of producing or aiding unlawful visual material under Penal Code § 43.26 or unlawful deep fake videos or images under Penal Code § 21.165, and do not intentionally develop or distribute a system that holds text-based conversations simulating or describing sexual conduct while impersonating a child under 18 (§ 552.057).
- Be able to produce on a civil investigative demand a high-level description of each system's purpose, intended use, deployment context and benefits, the types of training data, the categories of input and output, your performance metrics, known limitations, and your post-deployment monitoring and user safeguards (§ 552.103(b)).
How to prepare
- Map which Texas-facing AI systems interact with consumers in an individual or household context, and separate out employment and business-to-business uses, which fall outside the statutory definition of consumer and therefore outside the disclosure rule.
- Add the AI interaction disclosure to chatbots, voice systems and intake tools operated by or for a Texas governmental agency, and to any AI touching a health care service or treatment, then check the wording against the plain language and dark pattern conditions.
- Run an intent review across development and deployment decisions: record the documented purpose of each system, retain design rationale where protected characteristics or proxies are involved, and remove features that could be read as aiming at manipulation, social scoring or biometric identification.
- Adopt the NIST Artificial Intelligence Risk Management Framework Generative AI Profile, or another recognised AI risk framework, and evidence substantial compliance through a documented internal review process plus adversarial or red-team testing, since these are the statutory defences in § 552.105(e).
- Assemble a civil investigative demand response pack per system in advance, holding the eight § 552.103(b) items, so that a 60 day cure window is spent fixing the problem and drafting the cure statement rather than gathering documents.
- If you intend to test a novel system, apply to the Department of Information Resources sandbox for a period of up to 36 months, remembering that Subchapter B duties and prohibitions cannot be waived and that quarterly performance and risk mitigation reports are required.
Penalties & enforcement
Civil penalties per violation; cure period; AG exclusive enforcement.
Enforced by: Texas Attorney General
Texas TRAIGA is enforced by Texas Attorney General. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope across every sector you operate in, holding assessments that speak to bias & discrimination, safety & robustness and synthetic media & deepfakes, and being able to produce that evidence on request.