MarketTexasSheet 26

Texas regulates AI now.

Houston first, and the wider United States.

The question in this market is no longer whether an institution will be asked to show its AI governance. It is whether the answer will survive a notice letter, and whether it can be assembled inside sixty days.

§ 01The dated obligation

TRAIGA, in force since 1 January 2026.

The Texas Responsible Artificial Intelligence Governance Act, House Bill 149, has been in force since 1 January 2026. It reaches those who develop or deploy AI systems in Texas and those who offer AI products and services to Texas residents, which means it binds organisations with no Texas entity at all.

Enforcement is exclusive to the Attorney General. There is no private right of action, and the Act preempts city and county AI ordinances, so the enforcement surface is single and statewide rather than a patchwork. Before an enforcement action the Attorney General must give notice and allow a sixty-day cure period.

The cure period is where governance either exists or does not. To cure, the developer or deployer must fix the violation within the sixty days and provide the Attorney General a written statement with evidence of how it was cured, notification to affected consumers where technically feasible, and the internal policy changes made to prevent recurrence. Penalties for a violation that is curable but not cured run $10,000 to $12,000, uncurable violations $80,000 to $200,000, and continuing violations $2,000 to $40,000 per day.

Read that requirement again as an engineering specification rather than a legal one. Producing evidence of remediation, identifying affected consumers, and demonstrating a policy change inside sixty days is only possible for an institution that already knows which systems it runs, what each was permitted to do, and where the decision record lives.

The Act also provides affirmative defences, and they reward exactly the work this practice does. A defendant may not be found liable where it substantially complies with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or with another nationally or internationally recognised risk management framework for AI systems. There is a further protection where a violation is discovered through the organisation’s own internal testing, including adversarial testing and red-team exercises.

That changes the economics of governance in this jurisdiction. Mapping to a recognised framework is not merely good practice that a regulator may look on kindly; it is a defence named in the statute, and finding your own faults through adversarial testing is protected rather than penalised. An institution that governs deliberately is buying a legal position, not just a tidier process.

§ 02The gap

Where the gap usually is.

Reach
The obligation follows the Texas resident, not the Texas address. Organisations without a Texas entity assume they are outside it.
Cure capacity
Sixty days is generous for a policy fix and short for reconstructing an evidence trail that was never designed to be produced.
Consumer identification
Notifying affected consumers where technically feasible presumes you can determine which decisions a failing system touched.
Inventory
The same first failure as everywhere: nobody has a current list of the AI systems actually in production.
§ 03The work

What I bring to it.

The AI Governance Teardown is scoped to exactly this question: a fixed two-week examination producing a gap report where every finding traces to evidence, plus a remediation roadmap ordered by severity. Underneath it sit the MESA Framework scored per layer, the Five-Gate Deployment Model, and a six-pillar model risk discipline. For Houston in particular the industrial and clinical work is where my architecture background carries most weight.

Houston is the focus: energy and industrial operations, and the hospital systems and payers concentrated in the medical corridor. Dallas and Austin are served on the same terms.

Energy and industrial operationsHospital systems, payers and health technologyBanking, insurance and financial servicesLogistics and supply chainTechnology and platform companies
How I work here

I am a Canadian independent consultant serving Texas clients, remotely and on site as an engagement requires. I am not a Texas-registered entity, I do not hold an office in Texas, and I do not provide legal advice. Nothing on this page is legal advice on TRAIGA; it is architecture and governance work that a client’s counsel should review.

§ 04Questions

What Houston clients ask.

Does TRAIGA apply to a company outside Texas?

It can. The Act reaches those who develop or deploy AI systems in Texas and those who offer AI products and services to Texas residents. The trigger follows the Texas resident rather than a Texas address, so an out-of-state or non-US organisation serving Texans can be in scope without holding any Texas entity.

Who enforces TRAIGA, and can we be sued by a consumer?

Enforcement is exclusive to the Texas Attorney General, and the Act provides no private right of action. It also preempts city and county AI ordinances, so the exposure is statewide and singular rather than a patchwork of local rules.

What actually has to happen inside the sixty-day cure period?

More than fixing the problem. The developer or deployer must cure the violation and give the Attorney General a written statement including evidence of how it was cured, notification to affected consumers where technically feasible, and the internal policy changes made to prevent recurrence. That is an evidence exercise, and it is why the cure period is best treated as a design constraint rather than a grace period.

What are the penalties?

Violations that are curable but not cured, or where a submitted cure statement is breached, run $10,000 to $12,000 per violation. Uncurable violations run $80,000 to $200,000 per violation. Continuing violations, or those persisting past the cure period without a statement, run $2,000 to $40,000 per day.

Is there a safe harbour or affirmative defence under TRAIGA?

Yes, and it is worth designing towards. A defendant may not be found liable where it substantially complies with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or with another nationally or internationally recognised risk management framework for AI systems. A separate protection applies where the organisation discovers a violation through its own internal testing, including adversarial testing and red-team exercises. Mapping to a recognised framework is therefore a defence named in the statute rather than merely good practice, which is a strong argument for doing the mapping deliberately and being able to evidence it. Your counsel should confirm how either defence applies to your facts.

Are you a Texas firm, and is this legal advice?

Neither. I am a Canadian independent consultant and architect serving Texas clients remotely and on site, with no Texas entity and no Texas office. This is architecture and governance work, not legal advice, and a client’s counsel should review any position taken on TRAIGA.

§ 05Start

Find the gap before someone else does.

The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.

Fin · Houston
Book a Fit Call →