← Back to Sia website
Sia RegAI  /  Blog  /  Texas TRAIGA
Analysis · US state AI law

Texas TRAIGA: what the effective law actually requires.

Published July 26, 2026Reviewed July 26, 20264-minute readBy Cyril Sayada

Texas HB149 took effect on 1 January 2026. The enacted Texas Responsible Artificial Intelligence Governance Act is narrower than many summaries of earlier versions: it uses targeted disclosure and prohibited-use rules, Attorney General enforcement, sector boundaries and a state sandbox rather than a universal impact-assessment regime.

Direct answer: inventory Texas-facing AI, but do not assume every private deployer owes a general chatbot disclosure. The enacted consumer-interaction disclosure is targeted to governmental agencies and providers using AI in relation to health-care services or treatment. Separate that duty from the law's broader prohibitions, biometric amendments and enforcement information requests.

Regulatory snapshot

ItemPosition
StatusEnacted; effective 1 January 2026.
Primary enforcerTexas Attorney General, with specified state-agency sanctions following a violation.
Private right of actionThe AI chapter does not create one.
Local rulesThe chapter pre-empts local political-subdivision regulation of AI use.

Who has a consumer disclosure duty?

A governmental agency making an AI system available to interact with consumers must disclose that the consumer is interacting with AI before or at the time of interaction. The disclosure must be clear, conspicuous, in plain language and free of dark patterns.

When AI is used in relation to health-care service or treatment, the provider must disclose the use to the recipient or representative no later than the first service or treatment, subject to the emergency timing rule. For an enterprise inventory, distinguish:

  • governmental consumer interaction;
  • health-care service or treatment;
  • other private-sector interaction not covered by this particular disclosure section; and
  • separate contractual, sector or consumer-protection disclosures that may still apply.

Prohibited development and deployment

The enacted law targets defined conduct rather than imposing a general “responsible AI” standard. Prohibitions address intentional encouragement of self-harm, harm to others or criminal activity; governmental social scoring; certain biometric identification practices; intentional impairment of constitutional rights; intentional unlawful discrimination against protected classes; and specified sexually explicit or child-exploitative content.

Intent matters in several provisions. The law states that disparate impact alone is not enough to show intent under its unlawful-discrimination section. That does not remove obligations under other discrimination laws, and it should not be treated as permission to ignore outcome testing.

Insurance and financial-services boundaries

The AI chapter does not authorise an agency other than the Texas Department of Insurance to regulate the business of insurance. Its unlawful-discrimination section also has an insurance boundary for entities already subject to laws governing unfair discrimination and unfair or deceptive insurance practices. A federally insured financial institution is treated as compliant with that section when it complies with applicable federal and state banking laws and regulations.

These provisions are routing rules, not a conclusion that insurance or banking AI is unregulated. Record which regulator, statute and control framework governs each use case.

Enforcement evidence

The Attorney General may request a high-level description of purpose, intended use and deployment context; data used for programming or training; input categories; outputs; performance metrics; known limitations; and post-deployment monitoring and safeguards. That request list is a useful minimum evidence pack even before a complaint arrives.

The act provides a 60-day notice-and-cure sequence before the Attorney General brings an action under the AI chapter. State licensing agencies can impose additional sanctions after the statutory conditions are met.

The Texas AI sandbox

HB149 establishes a regulatory sandbox administered by the Department of Information Resources in consultation with the Texas Artificial Intelligence Council. Approved participants may test for a limited period and limited scope while specified licensing or regulatory requirements are waived or suspended. Core prohibited-use requirements are not waivable. An application must describe the system and intended use, assess benefits and consumer, privacy and public-safety impacts, and explain mitigation of adverse consequences.

An operating checklist

  1. Identify AI systems developed, offered or deployed in Texas.
  2. Separate government, health-care, insurance, banking and general commercial contexts.
  3. Map each system to disclosure and prohibited-use provisions.
  4. Document purpose, data, outputs, metrics, limits and monitoring.
  5. Review biometric training, identification and commercial-use workflows.
  6. Confirm which sector regulator and existing statute controls.
  7. Assess sandbox eligibility only for a defined, controlled test.
  8. Track Attorney General and Department of Information Resources implementation.

How Sia RegAI can support the workflow

RegReview can monitor HB149 implementation alongside insurance, banking, privacy and sector sources so the applicable rule is routed to the correct owner. RegMatcher can map each provision to the Texas AI inventory, notices, biometric controls, model documentation and monitoring evidence, while preserving the reason a sector boundary or exception was applied. Counsel and accountable business owners make the final scope and intent determinations.

Primary sources

This analysis is general information, not legal advice. Review the enacted text, implementing rules and applicable sector law for the specific system.

Build a Texas AI perimeter that respects sector boundaries.

Connect each system to the right source, owner, control and monitoring evidence.