The question in this market is no longer whether an institution will be asked to show its AI governance. It is whether the answer will survive a notice letter, and whether it can be assembled inside sixty days.
The Texas Responsible Artificial Intelligence Governance Act, House Bill 149, has been in force since 1 January 2026. It reaches those who develop or deploy AI systems in Texas and those who offer AI products and services to Texas residents, which means it binds organisations with no Texas entity at all.
Enforcement is exclusive to the Attorney General. There is no private right of action, and the Act preempts city and county AI ordinances, so the enforcement surface is single and statewide rather than a patchwork. Before an enforcement action the Attorney General must give notice and allow a sixty-day cure period.
The cure period is where governance either exists or does not. To cure, the developer or deployer must fix the violation within the sixty days and provide the Attorney General a written statement with evidence of how it was cured, notification to affected consumers where technically feasible, and the internal policy changes made to prevent recurrence. Penalties for a violation that is curable but not cured run $10,000 to $12,000, uncurable violations $80,000 to $200,000, and continuing violations $2,000 to $40,000 per day.
Read that requirement again as an engineering specification rather than a legal one. Producing evidence of remediation, identifying affected consumers, and demonstrating a policy change inside sixty days is only possible for an institution that already knows which systems it runs, what each was permitted to do, and where the decision record lives.
The Act also provides affirmative defences, and they reward exactly the work this practice does. A defendant may not be found liable where it substantially complies with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or with another nationally or internationally recognised risk management framework for AI systems. There is a further protection where a violation is discovered through the organisation’s own internal testing, including adversarial testing and red-team exercises.
That changes the economics of governance in this jurisdiction. Mapping to a recognised framework is not merely good practice that a regulator may look on kindly; it is a defence named in the statute, and finding your own faults through adversarial testing is protected rather than penalised. An institution that governs deliberately is buying a legal position, not just a tidier process.
The AI Governance Teardown is scoped to exactly this question: a fixed two-week examination producing a gap report where every finding traces to evidence, plus a remediation roadmap ordered by severity. Underneath it sit the MESA Framework scored per layer, the Five-Gate Deployment Model, and a six-pillar model risk discipline. For Houston in particular the industrial and clinical work is where my architecture background carries most weight.
Houston is the focus: energy and industrial operations, and the hospital systems and payers concentrated in the medical corridor. Dallas and Austin are served on the same terms.
I am a Canadian independent consultant serving Texas clients, remotely and on site as an engagement requires. I am not a Texas-registered entity, I do not hold an office in Texas, and I do not provide legal advice. Nothing on this page is legal advice on TRAIGA; it is architecture and governance work that a client’s counsel should review.
It can. The Act reaches those who develop or deploy AI systems in Texas and those who offer AI products and services to Texas residents. The trigger follows the Texas resident rather than a Texas address, so an out-of-state or non-US organisation serving Texans can be in scope without holding any Texas entity.
Enforcement is exclusive to the Texas Attorney General, and the Act provides no private right of action. It also preempts city and county AI ordinances, so the exposure is statewide and singular rather than a patchwork of local rules.
More than fixing the problem. The developer or deployer must cure the violation and give the Attorney General a written statement including evidence of how it was cured, notification to affected consumers where technically feasible, and the internal policy changes made to prevent recurrence. That is an evidence exercise, and it is why the cure period is best treated as a design constraint rather than a grace period.
Violations that are curable but not cured, or where a submitted cure statement is breached, run $10,000 to $12,000 per violation. Uncurable violations run $80,000 to $200,000 per violation. Continuing violations, or those persisting past the cure period without a statement, run $2,000 to $40,000 per day.
Yes, and it is worth designing towards. A defendant may not be found liable where it substantially complies with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or with another nationally or internationally recognised risk management framework for AI systems. A separate protection applies where the organisation discovers a violation through its own internal testing, including adversarial testing and red-team exercises. Mapping to a recognised framework is therefore a defence named in the statute rather than merely good practice, which is a strong argument for doing the mapping deliberately and being able to evidence it. Your counsel should confirm how either defence applies to your facts.
Neither. I am a Canadian independent consultant and architect serving Texas clients remotely and on site, with no Texas entity and no Texas office. This is architecture and governance work, not legal advice, and a client’s counsel should review any position taken on TRAIGA.
The first conversation is a free thirty-minute fit call that qualifies the work in both directions. If it does not fit, you leave with a clearer read on where your governance stands and no cost. If you would rather start on your own, the Readiness Self-Assessment is twelve questions and the result is not gated behind a form.