AI Regulation Tracker · Texas AG · Statute

What does Texas TRAIGA (HB 149) say about AI in banking?

Published Jun 22, 2025 · Last reviewed Oct 5, 2026

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA, H.B. 149) was signed by the Governor on June 22, 2025 and took effect on January 1, 2026; it adds Subtitle D, Chapters 551–554, to Title 11 of the Business & Commerce Code. It prohibits developing or deploying AI with the intent to manipulate people into self-harm, harm to others or crime, to impair constitutional rights, to unlawfully discriminate against a protected class, or to produce child sexual abuse material and sexually explicit deepfakes, and only the Texas Attorney General can enforce it, after a 60-day notice-and-cure period, with civil penalties of up to $200,000 per uncurable violation. For banks the most important provision is Section 552.056(e): a federally insured financial institution is considered in compliance with the discrimination prohibition if it complies with all federal and state banking laws, and a disparate impact alone does not show intent to discriminate (Section 552.056(c)). The Act has no private right of action, no impact-assessment duty and no Attorney General rulemaking, and it creates a 36-month Department of Information Resources regulatory sandbox.

OFFICIAL TEXT: capitol.texas.gov ↗ · IN FORCE · TEXAS AG

DocumentTexas TRAIGA (HB 149) — Texas Responsible Artificial Intelligence Governance Act (H.B. 149, 89th Legislature)
Issued byTexas — Office of the Attorney General (exclusive enforcer of the Texas Responsible Artificial Intelligence Governance Act, HB 149), with the Department of Information Resources (regulatory sandbox) and the Texas Artificial Intelligence Council
TypeStatute
StatusIn force
PublishedJun 22, 2025
EffectiveJan 1, 2026
Applies toAny person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas (Section 551.002). Banks and credit unions are covered as deployers, but the Act contains a financial-institution provision: Section 552.056(e) treats a federally insured financial institution as in compliance with the unlawful-discrimination prohibition if it complies with all federal and state banking laws. The consumer-disclosure rule (Section 552.051), the social-scoring ban (Section 552.053) and the biometric-capture ban (Section 552.054) are written for governmental agencies and entities, and health care providers, not private banks
Official sourcecapitol.texas.gov ↗
Use casesAI governance (general) · Fair lending & discrimination · Customer-facing chatbots · Generative & agentic AI · Data & privacy

What are the key points of Texas TRAIGA (HB 149)?

  • Section 551.002 reaches a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas; Section 551.001(1) defines an artificial intelligence system as any machine-based system that, for any explicit or implicit objective, infers from its inputs how to generate outputs, including content, decisions, predictions or recommendations, that can influence physical or virtual environments.
  • Section 552.056(b)–(c) and (e): no one may develop or deploy AI with the intent to unlawfully discriminate against a protected class in violation of state or federal law; disparate impact is not sufficient by itself to show intent; a federally insured financial institution is considered in compliance if it complies with all federal and state banking laws and regulations. Insurance entities subject to unfair-discrimination statutes are exempted separately in Section 552.056(d).
  • Section 552.051(b): the duty to disclose to each consumer, before or at the time of interaction, that they are interacting with an AI system is imposed on a governmental agency, with Section 552.051(f) adding a duty on health care providers using AI in treatment. The disclosure must be clear and conspicuous, in plain language and free of dark patterns (Section 552.051(d)). A private bank's customer chatbot is not covered by the text.
  • Sections 552.052, 552.055 and 552.057 apply to any person: no AI developed or deployed to intentionally incite or encourage self-harm, harm to another, or criminal activity; none developed or deployed with the sole intent to infringe rights guaranteed by the U.S. Constitution; none developed or distributed with the sole intent to produce child sexual abuse material or deepfakes in violation of Penal Code Section 21.165 or 43.26, or to simulate sexual conversations while imitating a child.
  • Section 503.001 (Capture or Use of Biometric Identifier), as amended by Section 2 of the Act: an individual is not treated as having consented to biometric capture merely because an image exists on the internet (Subsection (b-1)); the section does not apply to voiceprint data retained by a financial institution or its affiliate, to training or storing biometric identifiers for AI unless used to uniquely identify an individual, or to AI developed or deployed to prevent, detect or respond to security incidents, identity theft, fraud or other illegal activity (Subsection (e)).
  • Sections 552.101–552.105: the Attorney General has exclusive enforcement authority; no private right of action; a civil investigative demand may follow a complaint through the online mechanism; the Attorney General must give written notice and wait 60 days, during which the person may cure and certify the cure; civil penalties are $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation and $2,000–$40,000 per day for a continuing violation.
  • Section 552.105(c) and (e): there is a rebuttable presumption of reasonable care, and a defendant is not liable where another person misuses the system or where the defendant found the violation through developer or user feedback, adversarial or red-team testing, state-agency guidelines, or an internal review process while substantially complying with the NIST AI Risk Management Framework: Generative AI Profile or another recognized AI risk-management framework.
  • Section 552.106: a state agency may impose sanctions on a person it licenses, registers or certifies if the person has been found in violation under Section 552.105 and the Attorney General has recommended additional enforcement; sanctions may include suspension, probation or revocation and a monetary penalty not exceeding $100,000. Chapter 553 creates a Department of Information Resources sandbox of up to 36 months, and Section 552.003 preempts local AI ordinances.

What did Texas TRAIGA (HB 149) change for banks?

TRAIGA is an intent-based statute: it has no high-risk system categories, impact assessments or mandatory consumer notices for private businesses. For banks the change is narrow but real: a statutory ban on intentionally discriminatory AI that expressly defers to federal and state banking law for federally insured institutions, an Attorney General enforcement channel with a mandatory cure period, a possible licensing-agency sanction channel, and a safe-harbor-style defense for firms that follow the NIST AI RMF Generative AI Profile. The Act also added AI-specific text to the Texas Data Privacy and Security Act (Section 541.104(a)) so that processors help controllers with the security of personal data held in an AI system.

What does the Texas Responsible AI Governance Act (TRAIGA) require of banks?

TRAIGA, signed June 22, 2025 and in force since January 1, 2026, asks little of a bank that its existing compliance program does not already cover. It prohibits developing or deploying AI with the intent to unlawfully discriminate against a protected class, but says a disparate impact is not enough to show intent (Section 552.056(c)) and deems a federally insured financial institution compliant if it complies with all federal and state banking laws (Section 552.056(e)). It also bans, for any person, AI built to incite self-harm, harm to others or crime, to impair constitutional rights, or to produce child sexual abuse material and sexually explicit deepfakes (Sections 552.052, 552.055, 552.057). The Act's consumer-disclosure, social-scoring and biometric-capture rules are addressed to governmental bodies and health care providers. The Attorney General alone enforces the Act, after a 60-day notice-and-cure period, with penalties up to $200,000 per uncurable violation; a bank that keeps a documented review process aligned to the NIST AI Risk Management Framework: Generative AI Profile has a statutory defense (Section 552.105(e)).

RuleAuthorityWhat it requiresApplies
Section 551.002 — ApplicabilityTexas AGThe subtitle applies to a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas.In force since January 1, 2026
Section 552.056(b), (c), (e) — Unlawful discriminationTexas AGNo development or deployment of AI with the intent to unlawfully discriminate against a protected class; disparate impact alone is insufficient; a federally insured financial institution is considered in compliance if it complies with all federal and state banking laws and regulations.In force since January 1, 2026
Sections 552.052, 552.055, 552.057 — Prohibited purposesTexas AGNo AI intentionally aimed at inciting self-harm, harm to others or crime; none built with the sole intent to infringe constitutional rights; none developed or distributed with the sole intent to produce child sexual abuse material or unlawful sexually explicit deepfakes.In force since January 1, 2026
Section 552.051 — Disclosure to consumersTexas AGA governmental agency that makes available an AI system intended to interact with consumers must disclose, clearly and in plain language, that the consumer is interacting with AI; health care providers using AI in treatment must disclose by first service. The text does not impose the duty on private banks.In force since January 1, 2026
Sections 552.053–552.054 — Social scoring and biometric identificationTexas AGA governmental entity may not use AI to assign social scores that cause unrelated or disproportionate detrimental treatment, or to uniquely identify individuals from biometric data or scraped images without consent where that would infringe a legal right.In force since January 1, 2026
Section 503.001(b-1), (e), (f) — Biometric identifiers and AITexas AGPublic images are not consent to capture biometric identifiers; exempt are voiceprint data retained by a financial institution or its affiliate and AI used to prevent, detect or respond to security incidents, identity theft or fraud; training data later used commercially outside the exemptions carries the section's possession, destruction and penalty provisions.In force since January 1, 2026
Sections 552.103–552.105(a) — Investigation, cure and penaltiesTexas AGThe Attorney General may issue civil investigative demands on complaints, must give 60 days' written notice and accept a documented cure, and may seek $10,000–$12,000 (curable), $80,000–$200,000 (uncurable) and $2,000–$40,000 per day (continuing).Complaint mechanism due September 1, 2026
Section 552.105(c), (e) — Presumption and defensesTexas AGA rebuttable presumption of reasonable care applies; liability is excluded where another person misuses the system or where the defendant found the violation through feedback, adversarial testing, state-agency guidelines or an internal review while substantially complying with the NIST AI RMF Generative AI Profile or a recognized equivalent.In force since January 1, 2026
Section 552.106 — Licensing-agency sanctionsTexas AGA state agency may suspend, put on probation or revoke a licensee's authorization and impose a penalty up to $100,000 after a Section 552.105 finding and an Attorney General recommendation.In force since January 1, 2026
Chapter 553 — Regulatory sandboxTexas AGThe Department of Information Resources may approve participants, with any applicable agency, to test AI for up to 36 months with certain state requirements waived; the Subchapter B prohibitions in Chapter 552 may not be waived.Application form by DIR rule

TRAIGA is best read as an enforcement statute with a short list of intent-based prohibitions, not as a governance framework for AI in credit. It does not create high-risk categories, risk-management programs, impact assessments, or consumer notices for private businesses; the enrolled bill does not contain them. The discrimination prohibition illustrates the approach: it requires intent, says a disparate impact is not enough, and defers entirely to federal and state banking law for federally insured institutions. Fair-lending exposure under ECOA, Regulation B and the Fair Housing Act is therefore governed by those laws and their regulators, not by TRAIGA.

Enforcement runs through the Attorney General. A consumer files a complaint using the online mechanism that Section 552.102 required the Attorney General to post by September 1, 2026; the Attorney General may then issue a civil investigative demand for descriptions of the system's purpose, training data, inputs, outputs, performance metrics, limitations and post-deployment safeguards (Section 552.103(b)), and must give notice and 60 days to cure before suing (Section 552.104). The statute's defenses reward documented governance: substantial compliance with the NIST AI RMF Generative AI Profile or another recognized framework, adversarial testing and internal review all appear in Section 552.105(e). A bank that already maintains SR 26-2 or OCC Bulletin 2026-13 model-risk documentation, and an AI inventory, will have most of what a civil investigative demand would ask for.

The second channel is licensing. Section 552.106 lets a state agency sanction a licensee, including by suspension or revocation, after an Attorney General recommendation, and Chapter 553's sandbox treats finance as a named sector (Section 553.051(b)(1)). Both make the state banking agency a stakeholder for state-chartered institutions, although the text does not name a particular agency. Section 552.003 preempts local ordinances on AI. The Texas Artificial Intelligence Council may study and report but may not adopt binding rules or guidance (Section 554.103), so the content of the regime will come from the Attorney General's choices and from any amendment by the Legislature, which next meets in regular session in January 2027.

WHAT THIS MEANS IN PRACTICE

  • Map where AI touches intent-sensitive uses at the bank — marketing, collections scripts, customer-facing agents — and confirm the design documentation shows none is built to manipulate customers into harm or to discriminate; intent is the statutory test, so design records matter.
  • Record the Section 552.056(e) position: for a federally insured institution, evidence of compliance with federal and state banking laws (fair-lending testing, model validation) is the safe path, and a TRAIGA response should be able to point to it.
  • Align the AI governance documentation to the NIST AI RMF Generative AI Profile; Section 552.105(e)(2)(D) makes substantial compliance a defense, and an internal review process and adversarial testing are listed as ways a defendant can discover and cure violations.
  • Prepare a response playbook for a civil investigative demand: Section 552.103(b) lists the eight categories of information, so keep a current inventory entry per system with purpose, data, outputs, metrics, limitations and monitoring.
  • Treat the 60-day cure window as an operational deadline: the cure requires a written statement with supporting documentation and changes to internal policies (Section 552.104(b)(2)), so draft the template now.
  • Do not assume customer chatbots are exempt from other Texas and federal disclosure and deception rules; Section 552.051 does not reach private banks, but the Texas Deceptive Trade Practices Act, UDAAP and CFPB guidance on chatbots continue to apply.

Does the Texas Responsible AI Governance Act (TRAIGA) apply to banks?

Yes, but narrowly. TRAIGA applies to any person doing business in Texas or deploying AI there (Section 551.002), so banks are covered, but its operative prohibitions require intent. For discrimination, Section 552.056(e) treats a federally insured financial institution as compliant if it complies with all federal and state banking laws. The consumer AI-disclosure duty in Section 552.051 is written for governmental agencies and health care providers, not private banks.

When does TRAIGA take effect?

TRAIGA (H.B. 149) was signed by the Governor on June 22, 2025 and took effect January 1, 2026 (Section 10 of the Act). The Attorney General had until September 1, 2026 to post the information and online complaint mechanism required by Section 552.102 (Section 8 of the Act).

What are the penalties under TRAIGA?

After written notice and a 60-day cure period, a court may impose $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation and $2,000–$40,000 per day for a continuing violation (Section 552.105(a)), plus injunctive relief, attorney's fees and investigative costs. A licensing agency may add sanctions of up to $100,000 and license action if the Attorney General recommends it (Section 552.106).

Is TRAIGA binding, and can individuals sue under it?

It is a binding state statute. Only the Attorney General can enforce it (Section 552.101(a)), and Section 552.101(b) states the chapter does not provide a basis for, and is not subject to, a private right of action. The Texas Artificial Intelligence Council created by Chapter 554 may not adopt binding rules or guidance (Section 554.103).

How does TRAIGA compare with the EU AI Act for banks?

The EU AI Act (Regulation (EU) 2024/1689) classifies AI for creditworthiness assessment as high-risk and imposes conformity, governance and oversight duties; TRAIGA has no risk tiers and no system-level duties for private businesses, and instead prohibits specific intentional harms, backed by a cure period and Attorney General enforcement. TRAIGA's discrimination rule requires intent and defers to banking law for insured institutions, while fair-lending law under ECOA and Regulation B is applied separately by the federal agencies.

DateDocumentStatus
Sep 30, 2026SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act)Final
Sep 30, 2026Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew BaileyFinal
Sep 28, 2026AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act)Final
Sep 10, 2026Atkins remarks at Investor Advisory Committee (Sep 2026) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information EcosystemFinal
Sep 2, 2026FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber ResilienceIn force
Aug 31, 2026FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence modelsFinal

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning