Texas did not end up passing a Colorado-style AI law. It passed something different, and it has been enforced since January 1, 2026.
The bill that got most of the early attention, HB 1709, was closely modeled on Colorado's 2024 framework: risk management programs, impact assessments, the familiar deployer duties. It did not become law. What passed was HB 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), codified at Tex. Bus. & Com. Code chapters 551 to 553, and it takes a different approach.
What TRAIGA actually does
TRAIGA is intent-based. Rather than imposing process obligations on anyone deploying a high-risk system, it prohibits specific uses developed or deployed with a prohibited intent: intentional discrimination, intentional incitement of self-harm or crime, unlawful manipulation of behavior, certain biometric identification without consent, and government social scoring.
The distinction matters commercially. Colorado's reenacted law asks you to disclose. TRAIGA asks you not to do certain things on purpose. There is a disparate-impact clause providing that disparate impact alone is not sufficient to show intent to discriminate.
Penalties
| Violation type | Range |
|---|---|
| Curable violations | $10,000 to $12,000 |
| Uncurable violations | $80,000 to $200,000 |
| Continuing violations | $2,000 to $40,000 per day |
A 60-day cure period applies. Separately, a state licensing agency may sanction a person it licenses, registers, or certifies, including suspension, probation, or revocation plus a monetary penalty of up to $100,000, following a court finding and on the AG's recommendation.
The NIST safe harbor Texas kept
TRAIGA provides an affirmative defense for organizations that discover a violation through adversarial testing or red-teaming and that comply with the NIST AI Risk Management Framework.
This is worth stating plainly because it is now the opposite of Colorado. Colorado's NIST safe harbor was repealed by SB 26-189 in May 2026. Texas kept one. If you built a NIST-aligned program for Colorado reasons, it still has statutory value, but in Texas, not Colorado.
Enforcement so far
The Texas Attorney General has exclusive enforcement authority. The AG's Consumer AI Rights complaint page is live, with a statutory deadline of September 1, 2026. No TRAIGA enforcement actions have been filed as of this writing.
The Department of Information Resources is standing up the chapter 553 regulatory sandbox. Rules and the application process were still in development as of mid 2026, and DIR's public sandbox program covers state agencies rather than private entities, so confirm current DIR rules before assuming you can apply.
What this means if you operate in both states
The two regimes have diverged, and a single programme no longer covers both.
Colorado, effective January 1, 2027: pre-use notice, adverse-decision explanation, consumer rights to inspect and correct data and request human review, three-year recordkeeping. No impact assessment, no risk management program, no reasonable-care duty, no safe harbor. Enforcement currently stayed under *xAI v. Weiser*, including for the reenacted statute.
Texas, in force now: do not deploy AI with the prohibited intents, keep adversarial testing evidence, and maintain NIST alignment to preserve the affirmative defense.
Advice from 2025 that said "build to Colorado and you are ready for Texas" was reasonable when both were tracking the same model. It is not correct now.
What to do
- Stop treating Colorado as the template for US state AI compliance. It is now an outlier rather than the model.
- If you operate in Texas, keep your NIST AI RMF program and document your adversarial testing. That is where the defense lives.
- If you operate in Colorado, build the disclosure plumbing for January 1, 2027.
- Track both separately. They will keep diverging.
Resources
Regulations in this article
Regulome editors
The editorial desk covers AI and cyber regulation across the US, EU, and UK. Corrections and tips: editors@regulome.io
Not legal advice
This article is for information only. Consult qualified counsel before making compliance decisions. Run the free checker
