All articles
Regulations & StandardsJuly 30, 2026 · 3 min read · SafeAI for Business

Texas TRAIGA (HB 149): What SMEs Can and Cannot Do With AI

Texas TRAIGA takes effect 1 January 2026 with a prohibited-practices approach. It is simpler than Colorado's law, NIST compliance is a safe harbour, and fines run to $12,000 per violation.

The Texas Responsible AI Governance Act (TRAIGA, HB 149) takes effect on 1 January 2026. It regulates AI differently from Colorado, and for most SMEs the Texas approach is considerably easier to live with.

Colorado's AI Act asks what processes you have built. Texas asks a blunter question: did you do something prohibited?

A prohibited-practices law

TRAIGA works by naming things you must not do, rather than obligations you must discharge. That distinction is the single most useful thing to understand about it.

For developers, the law targets systems designed for:

  • Discrimination against protected groups.
  • Manipulation of human behaviour.
  • Infringement of rights.

For deployers — businesses putting AI into use — the duties are:

  • Disclose AI interactions so people know when they are dealing with a machine.
  • Do not deploy systems for the prohibited purposes above.

Penalties and defences

  • Fines run to $12,000 per violation.
  • NIST AI Risk Management Framework compliance operates as a safe harbour.
  • Red-team testing counts as a defence for developers.
  • Texas also operates a regulatory sandbox for testing AI systems under supervision.

That safe harbour is the headline for smaller businesses. Adopting a recognised framework converts an open-ended risk into a documented, defensible position.

Texas is a law about what you cannot do, not a checklist of what you must produce. For a small team, that is a far cheaper compliance posture than a process-heavy regime.

What SMEs should actually do

  • Adopt the NIST AI RMF. It is free, voluntary, and under TRAIGA it is your primary defence. It is also a safe harbour in Colorado, so the same work covers both states.
  • Add AI disclosure wherever customers interact with a bot or receive AI-generated output. This is cheap and removes an easy category of violation.
  • Review intent, not just outcomes. TRAIGA is concerned with systems designed for prohibited purposes. Document why you chose a tool and what you use it for.
  • Consider the sandbox if you are building something novel and want supervised room to test it.

What "adopting NIST" actually involves

The phrase sounds heavier than the work. The framework has four functions, and for a small business each maps to something modest:

  • Govern — a one-page AI policy and a named owner.
  • Map — a register of the AI you use, what it does, and what data it touches.
  • Measure — a simple risk rating per system, revisited quarterly.
  • Manage — a decision per risk (accept, mitigate, stop) and a route for reporting problems.

That is achievable in a fortnight for most SMEs. The value is that it converts an unbounded legal question into a documented position you can point at — in Texas, in Colorado, and in the next state to legislate.

The safe harbour is not a reward for buying software. It is a reward for being able to show your reasoning.

How this fits the wider US picture

There is still no comprehensive federal AI law. What exists is a patchwork — Colorado's process obligations, Texas's prohibitions, California's transparency rules, New York City's audit requirements — layered over a voluntary NIST framework.

The practical consequence for an SME is that NIST adoption is the highest-leverage single action available. It satisfies safe-harbour provisions in multiple states at once, and it is the benchmark enterprise buyers increasingly ask about.

Frequently asked questions

How is TRAIGA different from the Colorado AI Act?

Colorado tells you what you must do — impact assessments, risk programmes, consumer notices. Texas tells you what you cannot do. TRAIGA takes a prohibited-practices approach, which is generally simpler for a small business to comply with.

Does adopting the NIST AI RMF really help?

Yes. Under TRAIGA, NIST compliance functions as a safe harbour. Documented adoption of the framework is one of the strongest defensive positions a smaller business can take, and it also travels to other states.

Disclaimer: This article is educational guidance, not legal advice. Regulations change and apply differently by jurisdiction and sector — confirm decisions with qualified counsel.