# Texas TRAIGA (HB 149): Texas Responsible Artificial Intelligence Governance Act (H.B. 149, 89th Legislature)

Source: https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga
Last updated: Oct 5, 2026

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA, H.B. 149) was signed by the Governor on June 22, 2025 and took effect on January 1, 2026; it adds Subtitle D, Chapters 551–554, to Title 11 of the Business & Commerce Code. It prohibits developing or deploying AI with the intent to manipulate people into self-harm, harm to others or crime, to impair constitutional rights, to unlawfully discriminate against a protected class, or to produce child sexual abuse material and sexually explicit deepfakes, and only the Texas Attorney General can enforce it, after a 60-day notice-and-cure period, with civil penalties of up to $200,000 per uncurable violation. For banks the most important provision is Section 552.056(e): a federally insured financial institution is considered in compliance with the discrimination prohibition if it complies with all federal and state banking laws, and a disparate impact alone does not show intent to discriminate (Section 552.056(c)). The Act has no private right of action, no impact-assessment duty and no Attorney General rulemaking, and it creates a 36-month Department of Information Resources regulatory sandbox.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) |
| Type | Statute |
| Status | In force |
| Published | Jun 22, 2025 |
| Effective | Jan 1, 2026 |
| Applies to | Any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas (Section 551.002). Banks and credit unions are covered as deployers, but the Act contains a financial-institution provision: Section 552.056(e) treats a federally insured financial institution as in compliance with the unlawful-discrimination prohibition if it complies with all federal and state banking laws. The consumer-disclosure rule (Section 552.051), the social-scoring ban (Section 552.053) and the biometric-capture ban (Section 552.054) are written for governmental agencies and entities, and health care providers, not private banks |
| Official text | https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm |

## Key points

- Section 551.002 reaches a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas; Section 551.001(1) defines an artificial intelligence system as any machine-based system that, for any explicit or implicit objective, infers from its inputs how to generate outputs, including content, decisions, predictions or recommendations, that can influence physical or virtual environments.
- Section 552.056(b)–(c) and (e): no one may develop or deploy AI with the intent to unlawfully discriminate against a protected class in violation of state or federal law; disparate impact is not sufficient by itself to show intent; a federally insured financial institution is considered in compliance if it complies with all federal and state banking laws and regulations. Insurance entities subject to unfair-discrimination statutes are exempted separately in Section 552.056(d).
- Section 552.051(b): the duty to disclose to each consumer, before or at the time of interaction, that they are interacting with an AI system is imposed on a governmental agency, with Section 552.051(f) adding a duty on health care providers using AI in treatment. The disclosure must be clear and conspicuous, in plain language and free of dark patterns (Section 552.051(d)). A private bank's customer chatbot is not covered by the text.
- Sections 552.052, 552.055 and 552.057 apply to any person: no AI developed or deployed to intentionally incite or encourage self-harm, harm to another, or criminal activity; none developed or deployed with the sole intent to infringe rights guaranteed by the U.S. Constitution; none developed or distributed with the sole intent to produce child sexual abuse material or deepfakes in violation of Penal Code Section 21.165 or 43.26, or to simulate sexual conversations while imitating a child.
- Section 503.001 (Capture or Use of Biometric Identifier), as amended by Section 2 of the Act: an individual is not treated as having consented to biometric capture merely because an image exists on the internet (Subsection (b-1)); the section does not apply to voiceprint data retained by a financial institution or its affiliate, to training or storing biometric identifiers for AI unless used to uniquely identify an individual, or to AI developed or deployed to prevent, detect or respond to security incidents, identity theft, fraud or other illegal activity (Subsection (e)).
- Sections 552.101–552.105: the Attorney General has exclusive enforcement authority; no private right of action; a civil investigative demand may follow a complaint through the online mechanism; the Attorney General must give written notice and wait 60 days, during which the person may cure and certify the cure; civil penalties are $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation and $2,000–$40,000 per day for a continuing violation.
- Section 552.105(c) and (e): there is a rebuttable presumption of reasonable care, and a defendant is not liable where another person misuses the system or where the defendant found the violation through developer or user feedback, adversarial or red-team testing, state-agency guidelines, or an internal review process while substantially complying with the NIST AI Risk Management Framework: Generative AI Profile or another recognized AI risk-management framework.
- Section 552.106: a state agency may impose sanctions on a person it licenses, registers or certifies if the person has been found in violation under Section 552.105 and the Attorney General has recommended additional enforcement; sanctions may include suspension, probation or revocation and a monetary penalty not exceeding $100,000. Chapter 553 creates a Department of Information Resources sandbox of up to 36 months, and Section 552.003 preempts local AI ordinances.

## What changed for banks

TRAIGA is an intent-based statute: it has no high-risk system categories, impact assessments or mandatory consumer notices for private businesses. For banks the change is narrow but real: a statutory ban on intentionally discriminatory AI that expressly defers to federal and state banking law for federally insured institutions, an Attorney General enforcement channel with a mandatory cure period, a possible licensing-agency sanction channel, and a safe-harbor-style defense for firms that follow the NIST AI RMF Generative AI Profile. The Act also added AI-specific text to the Texas Data Privacy and Security Act (Section 541.104(a)) so that processors help controllers with the security of personal data held in an AI system.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Fair lending & discrimination](https://www.bankingnewsai.com/ai-regulation/by-use-case#fair-lending)
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)

## What does the Texas Responsible AI Governance Act (TRAIGA) require of banks?

TRAIGA, signed June 22, 2025 and in force since January 1, 2026, asks little of a bank that its existing compliance program does not already cover. It prohibits developing or deploying AI with the intent to unlawfully discriminate against a protected class, but says a disparate impact is not enough to show intent (Section 552.056(c)) and deems a federally insured financial institution compliant if it complies with all federal and state banking laws (Section 552.056(e)). It also bans, for any person, AI built to incite self-harm, harm to others or crime, to impair constitutional rights, or to produce child sexual abuse material and sexually explicit deepfakes (Sections 552.052, 552.055, 552.057). The Act's consumer-disclosure, social-scoring and biometric-capture rules are addressed to governmental bodies and health care providers. The Attorney General alone enforces the Act, after a 60-day notice-and-cure period, with penalties up to $200,000 per uncurable violation; a bank that keeps a documented review process aligned to the NIST AI Risk Management Framework: Generative AI Profile has a statutory defense (Section 552.105(e)).

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Section 551.002 — Applicability | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | The subtitle applies to a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Section 552.056(b), (c), (e) — Unlawful discrimination | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | No development or deployment of AI with the intent to unlawfully discriminate against a protected class; disparate impact alone is insufficient; a federally insured financial institution is considered in compliance if it complies with all federal and state banking laws and regulations. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Sections 552.052, 552.055, 552.057 — Prohibited purposes | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | No AI intentionally aimed at inciting self-harm, harm to others or crime; none built with the sole intent to infringe constitutional rights; none developed or distributed with the sole intent to produce child sexual abuse material or unlawful sexually explicit deepfakes. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Section 552.051 — Disclosure to consumers | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | A governmental agency that makes available an AI system intended to interact with consumers must disclose, clearly and in plain language, that the consumer is interacting with AI; health care providers using AI in treatment must disclose by first service. The text does not impose the duty on private banks. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Sections 552.053–552.054 — Social scoring and biometric identification | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | A governmental entity may not use AI to assign social scores that cause unrelated or disproportionate detrimental treatment, or to uniquely identify individuals from biometric data or scraped images without consent where that would infringe a legal right. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Section 503.001(b-1), (e), (f) — Biometric identifiers and AI | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | Public images are not consent to capture biometric identifiers; exempt are voiceprint data retained by a financial institution or its affiliate and AI used to prevent, detect or respond to security incidents, identity theft or fraud; training data later used commercially outside the exemptions carries the section's possession, destruction and penalty provisions. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Sections 552.103–552.105(a) — Investigation, cure and penalties | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | The Attorney General may issue civil investigative demands on complaints, must give 60 days' written notice and accept a documented cure, and may seek $10,000–$12,000 (curable), $80,000–$200,000 (uncurable) and $2,000–$40,000 per day (continuing). | Complaint mechanism due September 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Section 552.105(c), (e) — Presumption and defenses | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | A rebuttable presumption of reasonable care applies; liability is excluded where another person misuses the system or where the defendant found the violation through feedback, adversarial testing, state-agency guidelines or an internal review while substantially complying with the NIST AI RMF Generative AI Profile or a recognized equivalent. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Section 552.106 — Licensing-agency sanctions | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | A state agency may suspend, put on probation or revoke a licensee's authorization and impose a penalty up to $100,000 after a Section 552.105 finding and an Attorney General recommendation. | In force since January 1, 2026 | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |
| Chapter 553 — Regulatory sandbox | [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | The Department of Information Resources may approve participants, with any applicable agency, to test AI for up to 36 months with certain state requirements waived; the Subchapter B prohibitions in Chapter 552 may not be waived. | Application form by DIR rule | [Texas TRAIGA (HB 149)](https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga) |

TRAIGA is best read as an enforcement statute with a short list of intent-based prohibitions, not as a governance framework for AI in credit. It does not create high-risk categories, risk-management programs, impact assessments, or consumer notices for private businesses; the enrolled bill does not contain them. The discrimination prohibition illustrates the approach: it requires intent, says a disparate impact is not enough, and defers entirely to federal and state banking law for federally insured institutions. Fair-lending exposure under ECOA, Regulation B and the Fair Housing Act is therefore governed by those laws and their regulators, not by TRAIGA.

Enforcement runs through the Attorney General. A consumer files a complaint using the online mechanism that Section 552.102 required the Attorney General to post by September 1, 2026; the Attorney General may then issue a civil investigative demand for descriptions of the system's purpose, training data, inputs, outputs, performance metrics, limitations and post-deployment safeguards (Section 552.103(b)), and must give notice and 60 days to cure before suing (Section 552.104). The statute's defenses reward documented governance: substantial compliance with the NIST AI RMF Generative AI Profile or another recognized framework, adversarial testing and internal review all appear in Section 552.105(e). A bank that already maintains SR 26-2 or OCC Bulletin 2026-13 model-risk documentation, and an AI inventory, will have most of what a civil investigative demand would ask for.

The second channel is licensing. Section 552.106 lets a state agency sanction a licensee, including by suspension or revocation, after an Attorney General recommendation, and Chapter 553's sandbox treats finance as a named sector (Section 553.051(b)(1)). Both make the state banking agency a stakeholder for state-chartered institutions, although the text does not name a particular agency. Section 552.003 preempts local ordinances on AI. The Texas Artificial Intelligence Council may study and report but may not adopt binding rules or guidance (Section 554.103), so the content of the regime will come from the Attorney General's choices and from any amendment by the Legislature, which next meets in regular session in January 2027.

### What this means in practice

- Map where AI touches intent-sensitive uses at the bank — marketing, collections scripts, customer-facing agents — and confirm the design documentation shows none is built to manipulate customers into harm or to discriminate; intent is the statutory test, so design records matter.
- Record the Section 552.056(e) position: for a federally insured institution, evidence of compliance with federal and state banking laws (fair-lending testing, model validation) is the safe path, and a TRAIGA response should be able to point to it.
- Align the AI governance documentation to the NIST AI RMF Generative AI Profile; Section 552.105(e)(2)(D) makes substantial compliance a defense, and an internal review process and adversarial testing are listed as ways a defendant can discover and cure violations.
- Prepare a response playbook for a civil investigative demand: Section 552.103(b) lists the eight categories of information, so keep a current inventory entry per system with purpose, data, outputs, metrics, limitations and monitoring.
- Treat the 60-day cure window as an operational deadline: the cure requires a written statement with supporting documentation and changes to internal policies (Section 552.104(b)(2)), so draft the template now.
- Do not assume customer chatbots are exempt from other Texas and federal disclosure and deception rules; Section 552.051 does not reach private banks, but the Texas Deceptive Trade Practices Act, UDAAP and CFPB guidance on chatbots continue to apply.

## FAQ

### Does the Texas Responsible AI Governance Act (TRAIGA) apply to banks?

Yes, but narrowly. TRAIGA applies to any person doing business in Texas or deploying AI there (Section 551.002), so banks are covered, but its operative prohibitions require intent. For discrimination, Section 552.056(e) treats a federally insured financial institution as compliant if it complies with all federal and state banking laws. The consumer AI-disclosure duty in Section 552.051 is written for governmental agencies and health care providers, not private banks.

### When does TRAIGA take effect?

TRAIGA (H.B. 149) was signed by the Governor on June 22, 2025 and took effect January 1, 2026 (Section 10 of the Act). The Attorney General had until September 1, 2026 to post the information and online complaint mechanism required by Section 552.102 (Section 8 of the Act).

### What are the penalties under TRAIGA?

After written notice and a 60-day cure period, a court may impose $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation and $2,000–$40,000 per day for a continuing violation (Section 552.105(a)), plus injunctive relief, attorney's fees and investigative costs. A licensing agency may add sanctions of up to $100,000 and license action if the Attorney General recommends it (Section 552.106).

### Is TRAIGA binding, and can individuals sue under it?

It is a binding state statute. Only the Attorney General can enforce it (Section 552.101(a)), and Section 552.101(b) states the chapter does not provide a basis for, and is not subject to, a private right of action. The Texas Artificial Intelligence Council created by Chapter 554 may not adopt binding rules or guidance (Section 554.103).

### How does TRAIGA compare with the EU AI Act for banks?

The EU AI Act (Regulation (EU) 2024/1689) classifies AI for creditworthiness assessment as high-risk and imposes conformity, governance and oversight duties; TRAIGA has no risk tiers and no system-level duties for private businesses, and instead prohibits specific intentional harms, backed by a cure period and Attorney General enforcement. TRAIGA's discrimination rule requires intent and defers to banking law for insured institutions, while fair-lending law under ECOA and Regulation B is applied separately by the federal agencies.

## Related documents

- [SB 947](https://www.bankingnewsai.com/ai-regulation/documents/ca-sb-947-2026) — Employment: Automated Decision Systems (No Robo Bosses Act) (Sep 30, 2026)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [AB 1609](https://www.bankingnewsai.com/ai-regulation/documents/ca-ab-1609-2026) — Customer Service Chatbots (Right to Human Customer Service Act) (Sep 28, 2026)
- [Atkins remarks at Investor Advisory Committee (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/sec-atkins-iac-ai-disclosure-remarks-2026-09) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information Ecosystem (Sep 10, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [FSB Chair's letter to G20 (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-chair-letter-g20-august-2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models (Aug 31, 2026)
- [Colorado AG proposed ADMT rules](https://www.bankingnewsai.com/ai-regulation/documents/co-ag-admt-proposed-rules-2026) — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) (Aug 11, 2026)
- [Responses to FSB AI sound practices consultation (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-responses-2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI) (Aug 6, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/tx-hb-149-traiga
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
