Texas
Texas AI Laws and Regulation (2026)
Independently fact-checked against primary sources (last audited August 20, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 20, 2026. · 7 primary sources cited on this page. How we verify our legal content

Texas regulates AI primarily through the Texas Responsible AI Governance Act (TRAIGA), which took effect January 1, 2026. TRAIGA prohibits harmful AI uses, applies an intent-based liability standard, and grants the Texas Attorney General exclusive enforcement authority with civil penalties up to $200,000 per violation.
Overview of Texas AI Laws
Texas has established itself as a major force in state-level artificial intelligence regulation. During the 89th Legislative Session in 2025, the Texas Legislature passed a comprehensive suite of AI laws that address everything from broad AI governance to healthcare-specific requirements, deepfake protections, and government AI oversight.
The centerpiece of Texas's AI regulatory framework is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), signed by Governor Greg Abbott on June 22, 2025. TRAIGA makes Texas the second state, after Colorado, to enact comprehensive AI legislation. However, Texas took a distinctly different approach from Colorado by focusing on intent-based liability rather than strict liability for discriminatory outcomes.
Texas's approach reflects the state's traditionally business-friendly regulatory philosophy. TRAIGA provides multiple safe harbor provisions, creates a regulatory sandbox for innovation, and vests enforcement authority exclusively in the Attorney General rather than creating private rights of action. At the same time, the state has enacted aggressive protections against deepfakes, imposed healthcare AI disclosure requirements, and established government AI oversight mechanisms.
This article covers all enacted and pending Texas AI legislation, including TRAIGA, healthcare AI laws, deepfake protections, and government AI regulations. This information is current as of March 2026, but you should consult a licensed Texas attorney for advice specific to your situation.
Texas Responsible AI Governance Act (TRAIGA): HB 149
The Texas Responsible Artificial Intelligence Governance Act, enacted as HB 149, is the most significant AI law passed by the Texas Legislature. Governor Abbott signed the bill on June 22, 2025, and it took effect on January 1, 2026.
Scope and Definitions
TRAIGA defines an "artificial intelligence system" as any machine-based system that, for any explicit or implicit objective, infers from its inputs how to generate outputs including content, decisions, predictions, or recommendations that can influence physical or virtual environments. This broad definition captures most modern AI tools, from large language models to automated decision-making systems.
The law applies to any entity that develops or deploys an AI system in Texas, advertises or promotes products or services in the state, conducts business in Texas, or offers products or services used by Texas residents.
Prohibited AI Practices
TRAIGA prohibits several categories of AI use. Under the law, it is illegal to develop or deploy AI systems that:
- Are intentionally aimed at inciting or encouraging self-harm or criminal activity
- Produce child sexual abuse material (CSAM) or deepfake pornography
- Engage in text-based conversations that simulate or describe sexual content while impersonating a child
- Use "social scoring" by government entities to categorize individuals for detrimental treatment
- Intentionally discriminate against protected classes under federal or state law
- Are developed or deployed by a governmental entity to uniquely identify a specific individual using biometric data, or to gather images or other media from the internet or another publicly available source without the individual's consent, where the gathering would infringe a right under the United States Constitution, the Texas Constitution, or state or federal law
The self-harm, CSAM, impersonation, and discrimination prohibitions apply to any developer or deployer. The social scoring and biometric provisions, Sections 552.053 and 552.054, bind governmental entities only. Private-sector biometric capture is governed separately by Business and Commerce Code Chapter 503, and Section 552.054(c) provides that a violation of Section 503.001 is also a violation of the TRAIGA biometric section.
Intent-Based Liability Framework
TRAIGA's most significant distinction from other state AI laws is its intent-based liability framework. Unlike Colorado's AI Act, which creates liability based on discriminatory outcomes (disparate impact), Texas requires proof of intentional misconduct. A company that inadvertently produces biased results through its AI system would not automatically violate TRAIGA, as long as there was no intent to discriminate.
This approach gives businesses clearer compliance guidelines. As long as a company acts in good faith and does not deliberately design or use AI systems to cause harm, it faces lower legal risk under TRAIGA compared to impact-focused regulations.
Enforcement and Penalties
TRAIGA does not create a private cause of action. Only the Texas Attorney General can enforce the law, and Business and Commerce Code Section 552.105 sets three separate penalty tiers rather than one continuous range. A violation the court determines to be curable, or a breach of the written cure statement submitted to the Attorney General, carries not less than $10,000 and not more than $12,000. A violation the court determines to be uncurable carries not less than $80,000 and not more than $200,000. A continuing violation carries not less than $2,000 and not more than $40,000 for each day it continues. There is no penalty amount between $12,000 and $80,000 under the statute.
Section 552.106 adds a second layer for regulated businesses. Once a person has been found in violation under Section 552.105 and the Attorney General recommends further enforcement, the state agency that licenses, registers, or certifies that person may suspend, place on probation, or revoke the authorization and may impose a monetary penalty of up to $100,000.
Before initiating enforcement action, the Attorney General must provide written notice to the alleged violator, giving the company 60 days to cure the violation and implement policy changes necessary to prevent further violations. This cure period provides companies with an opportunity to correct issues before facing penalties.
| Enforcement Detail | Requirement |
|---|---|
| Enforcement authority | Texas Attorney General (exclusive) |
| Curable violation | Not less than $10,000, not more than $12,000 each |
| Uncurable violation | Not less than $80,000, not more than $200,000 each |
| Continuing violation | Not less than $2,000, not more than $40,000 for each day |
| Additional agency sanction | Up to $100,000 plus license action against a licensee |
| Notice requirement | Written notice before action |
| Cure period | 60 days to fix and prevent recurrence |
| Private right of action | None |
Texas AI Council
TRAIGA creates the Texas Artificial Intelligence Council, a seven-member advisory body tasked with studying AI-related issues, making policy recommendations, and overseeing the regulatory sandbox program. The Council may issue non-binding reports and guidance but does not have rulemaking authority.
The Council's responsibilities include monitoring AI technology developments, advising state agencies on AI policy, evaluating the effectiveness of TRAIGA's provisions, and recommending legislative updates as the technology evolves. The advisory nature of the Council reflects Texas's preference for limited government intervention in technology markets.
Regulatory Sandbox Program
One of TRAIGA's most innovative features is the regulatory sandbox program, administered by the Texas Department of Information Resources (DIR) in consultation with the AI Council.
How the Sandbox Works
The sandbox allows approved participants to develop and test AI systems in a controlled environment, temporarily exempt from certain state licensing and regulatory requirements, for up to 36 months. This creates a structured pathway for businesses to experiment with novel AI applications without the immediate risk of regulatory penalties.
Key features of the sandbox include:
- Duration: Up to 36 months of regulatory flexibility
- Oversight: Administered by DIR with AI Council consultation
- Protections retained: Prohibitions on manipulation, discrimination, and unlawful content remain in force even within the sandbox
- Innovation focus: Designed to let companies test AI applications that might otherwise be impractical under existing regulatory frameworks
Limitations
The sandbox does not exempt participants from TRAIGA's core prohibitions. Companies operating in the sandbox must still comply with bans on discriminatory AI, CSAM generation, and other prohibited uses. The sandbox applies only to certain licensing and regulatory requirements that might otherwise prevent testing of innovative AI applications.
NIST Safe Harbor Provisions
TRAIGA provides multiple safe harbor provisions that incentivize companies to adopt responsible AI practices. Under Section 552.105(e), a defendant may not be found liable if either of the following applies:
- Third-party misuse: Another person uses the AI system affiliated with the defendant in a manner the chapter prohibits
- Discovery through a listed route: The defendant discovers the violation through feedback from a developer, deployer, or other person who believes a violation has occurred; through testing, including adversarial testing or red-team testing; by following guidelines set by applicable state agencies; or through an internal review process, where the defendant substantially complies with the most recent version of the NIST "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" or another nationally or internationally recognized risk management framework for AI systems
The NIST reference is not a standalone immunity. Framework compliance appears in the statute as the condition that qualifies an internal review process as a discovery route, so a company still has to actually find the violation and be able to show how it found it. Documented framework adherence, adversarial testing, and audit trails matter because they are what makes that showing possible. The statute also creates a rebuttable presumption that a person used reasonable care.
What NIST Compliance Requires
The framework the statute names is the NIST "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" (NIST AI 600-1), not the general AI RMF 1.0, though the statute also accepts another nationally or internationally recognized AI risk management framework. An internal review process built on that framework should include:
- Regular risk assessments of AI systems
- Documentation of AI system design decisions and known limitations
- Ongoing monitoring for bias, accuracy, and safety
- Stakeholder engagement and transparency reporting
- Incident response procedures for AI failures

Healthcare AI: SB 1188
Senate Bill 1188, signed by Governor Abbott on June 20, 2025, with an effective date of September 1, 2025, introduces specific requirements for healthcare providers using AI in diagnostic contexts.
Disclosure Requirements
Healthcare practitioners who use AI for diagnostic purposes, including AI-powered recommendations for diagnosis or treatment based on patient medical records, must disclose their use of AI to patients. The disclosure can be verbal or written but must clearly inform patients that AI is being used for care-related purposes.
Conditions for AI Use in Healthcare
Healthcare practitioners may use AI for diagnostic purposes only if they meet all of the following conditions:
- The practitioner discloses their use of AI to patients
- The practitioner uses AI within the scope of their license, certification, or authorization
- The use of AI is not otherwise restricted or prohibited by applicable state or federal law
- The practitioner reviews all records created with AI in a manner consistent with medical records standards developed by the Texas Medical Board
Electronic Health Record Protections
SB 1188 also prohibits the physical offshoring of electronic medical records, requiring that patient health data remain within the United States. This provision addresses growing concerns about AI companies processing medical data through overseas servers.
Penalties
The Texas Attorney General may seek injunctive relief and civil penalties against a covered entity. Health and Safety Code Section 183.011(b) sets culpability-keyed maximums rather than a floor-to-ceiling range. A civil penalty may not exceed $5,000 for each violation committed negligently that occurs in a single year, $25,000 for each violation committed knowingly or intentionally that occurs in a single year, in both cases regardless of how long the violation continues during that year, or $250,000 for each violation in which the covered entity knowingly or intentionally used protected health information for financial gain.
| Healthcare AI Requirement | Detail |
|---|---|
| Patient disclosure | Required before AI-assisted diagnosis |
| Scope limitation | Must be within practitioner's license |
| Record review | AI-created records must be reviewed per TMB standards |
| Data localization | EHRs cannot be offshored |
| Penalty maximums | $5,000 negligent, $25,000 knowing or intentional, $250,000 for knowing or intentional use of PHI for financial gain |
Deepfake Laws

Texas has been a pioneer in deepfake legislation, and the 89th Legislative Session significantly expanded the state's deepfake protections.
Sexually Explicit Deepfakes: Penal Code Section 21.165
Under Texas Penal Code Section 21.165, it is illegal to knowingly produce or distribute deepfake media depicting a person with visible intimate parts or engaging in sexual conduct without their effective consent.
| Offense | Classification | Maximum Penalty |
|---|---|---|
| Production or distribution without consent | Class A misdemeanor | Up to 1 year jail, $4,000 fine |
| Prior conviction or victim under 18 | Third-degree felony | 2 to 10 years prison |
| Threatening to produce or distribute | Class B misdemeanor | Up to 180 days jail |
| Threats involving victim under 18 | Class A misdemeanor | Up to 1 year jail |
SB 441: Expanded Civil Liability for Intimate Deepfakes
Senate Bill 441, signed by Governor Abbott on June 20, 2025, with an effective date of September 1, 2025, creates comprehensive civil liability for nonconsensual intimate deepfakes. The law allows victims to seek civil damages against:
- Individuals who create nonconsensual intimate deepfakes
- Websites that host such content
- Payment processors that manage payment systems for sites hosting nonconsensual deepfake content
SB 441 also strengthens requirements for obtaining consent before creating intimate visual material, ensuring that consent is documented and informed.
HB 3133: Platform Removal Requirements
House Bill 3133, signed on June 20, 2025, requires social media platforms to provide easily accessible and timely complaint systems for reporting alleged sexually explicit deepfakes and mechanisms for removing such material. Platforms that fail to comply face enforcement under Texas consumer protection laws.
HB 581: Age Verification for AI Sexual Content Tools
House Bill 581, signed on June 20, 2025, requires operators of websites with publicly available tools capable of creating "artificial sexual material harmful to minors" to implement reasonable age verification methods. This provision targets AI image generators that could be used to create harmful content involving minors.
Political Deepfakes: Election Code and HB 366
Texas was the first state in the nation to enact legislation restricting deepfakes in campaign advertisements. The original 2019 law made it illegal to create a deepfake video with intent to injure a candidate or influence an election result within 30 days of an election. Violations carry up to one year in county jail and a $4,000 fine.
However, the original law had significant limitations: it applied only to video content, required proof of intent, and was restricted to the 30-day pre-election window. It also covered only state-level races, not federal contests.
House Bill 366, sponsored by former House Speaker Dade Phelan, addressed these gaps. The bill passed both chambers and requires any political advertising that uses altered images, audio, or video, including AI-generated content, to include a disclosure stating the content did not occur in reality. The requirement applies to officeholders, candidates, or political committees that spend more than $100 on political advertising.
Failure to include the required disclosure is a Class A misdemeanor, punishable by up to one year in jail and a fine of up to $4,000. The Texas Ethics Commission determines the specific rules for disclosure format, including font size, color, and placement.
Government AI Regulation: SB 1964
Senate Bill 1964, signed by Governor Abbott on June 20, 2025, with an effective date of September 1, 2025, establishes a comprehensive framework for government use of AI in Texas.
Key Requirements
SB 1964 requires the Department of Information Resources (DIR) to maintain an inventory of AI systems used by state agencies and to create an AI code of ethics for state and local governments. The code of ethics must address:
- Human oversight of AI decision-making
- Fairness and non-discrimination
- Transparency in AI operations
- Data privacy protections
- Accountability mechanisms
- Regular evaluation of AI system performance
Heightened Scrutiny Classification
The bill establishes a tiered classification system for government AI, including a "heightened scrutiny" category for AI systems that autonomously influence consequential decisions such as benefit eligibility, licensing, or other government actions that significantly affect individuals.
Advisory Board
An eight-member advisory board assists state agencies with AI development and deployment, providing guidance on responsible AI use within government operations.
AI and Employment in Texas

TRAIGA applies to AI systems used in employment contexts, but Texas's approach differs significantly from states like Illinois and New York City that have enacted specific AI hiring regulations.
What TRAIGA Requires for Employers
TRAIGA prohibits developing or deploying an AI system with the intent to discriminate against a protected class under federal or state law. However, disparate impact alone, without evidence of intentional discrimination, does not violate TRAIGA.
The law does not require:
- Disclosure to job applicants or employees about AI use in hiring
- Mandatory bias audits of AI hiring tools
- Impact assessments for automated employment decision tools
Only state agencies and healthcare providers have mandatory AI disclosure obligations under Texas law. Private employers using AI for hiring, screening, or performance evaluation have no specific disclosure requirements under TRAIGA.
Practical Compliance for Employers
While not legally required, Texas employers should consider implementing AI policies and auditing their AI hiring tools. The Attorney General's enforcement authority means companies should retain meaningful human oversight over AI outputs that influence employment decisions and periodically reassess tools for bias or unintended discriminatory effects.
Federal AI Policy and Texas
Executive Order 14365
President Trump's Executive Order 14365, signed December 11, 2025, aims to establish a national AI policy framework and reduce diverging state regulations. The order creates a DOJ AI Litigation Task Force empowered to challenge state AI laws on constitutional grounds, including arguments based on the Commerce Clause and federal preemption.
Texas's Position
Texas's TRAIGA was designed with potential federal preemption challenges in mind. The law's business-friendly approach, intent-based liability standard, and lack of private right of action align with the federal government's stated preference for minimally burdensome AI regulation.
TRAIGA's safe harbor provisions, particularly the NIST framework compliance defense, also align with federal standards, making the law less likely to be challenged as imposing conflicting or duplicative requirements.
Protected Categories
The executive order exempts several categories of state laws from potential preemption challenges, including child safety protections and state government AI procurement. Texas's deepfake laws protecting minors (HB 581, SB 441) and government AI oversight (SB 1964) fall within these protected categories.
Looking Ahead: Texas AI Regulatory Future
Texas's 89th Legislative Session produced an unprecedented volume of AI legislation, establishing the state as a leader in AI governance. TRAIGA's January 1, 2026 effective date means businesses are now actively implementing compliance programs.
Key developments to watch include:
- The Texas AI Council's initial guidance and recommendations
- The regulatory sandbox program's first participants and outcomes
- Attorney General enforcement priorities under TRAIGA
- Potential federal preemption challenges to state AI laws
- Whether Texas will expand employer AI disclosure requirements in future sessions
The tension between Texas's pro-business philosophy and the need for consumer protection will continue to shape the state's AI regulatory trajectory. TRAIGA's intent-based framework may prove influential as other states consider their own comprehensive AI legislation.
More Texas Laws
Explore other Texas law topics on Recording Law:
Frequently Asked Questions
What is the Texas Responsible AI Governance Act (TRAIGA)?
TRAIGA (HB 149) is Texas's comprehensive AI governance law, signed by Governor Abbott on June 22, 2025, and effective January 1, 2026. It prohibits developing or deploying AI for harmful purposes including discrimination, CSAM generation, and behavioral manipulation. It creates the Texas AI Council, establishes a regulatory sandbox, and provides NIST-based safe harbor protections. The Texas Attorney General enforces the law with tiered civil penalties of $10,000 to $12,000 for a curable violation, $80,000 to $200,000 for an uncurable violation, and $2,000 to $40,000 for each day a violation continues.
What are the penalties for creating AI deepfakes in Texas?
Texas has multiple deepfake laws with escalating penalties. Under Penal Code Section 21.165, producing or distributing sexually explicit deepfakes without consent is a Class A misdemeanor (up to 1 year jail, $4,000 fine), escalating to a third-degree felony (2 to 10 years) if the victim is under 18 or the offender has a prior conviction. SB 441 adds civil liability, allowing victims to sue creators, hosting platforms, and payment processors. For political deepfakes, HB 366 makes undisclosed AI content in political ads a Class A misdemeanor.
Do Texas healthcare providers have to disclose AI use to patients?
Yes. Under SB 1188 (effective September 1, 2025), healthcare practitioners who use AI for diagnostic purposes, including AI-powered recommendations for diagnosis or treatment, must disclose their use of AI to patients. The disclosure can be verbal or written. Practitioners must also use AI within their license scope and review all AI-created records per Texas Medical Board standards. Civil penalties are capped at $5,000 for each negligent violation in a year, $25,000 for each knowing or intentional violation in a year, and $250,000 where a covered entity knowingly or intentionally used protected health information for financial gain.
How does the TRAIGA regulatory sandbox work?
TRAIGA's regulatory sandbox, administered by the Texas Department of Information Resources, allows approved participants to develop and test AI systems for up to 36 months while temporarily exempt from certain state licensing and regulatory requirements. Core TRAIGA prohibitions on discrimination, CSAM, and manipulation still apply within the sandbox. The program is designed to encourage AI innovation by providing a structured testing environment with reduced regulatory risk.
Does Texas regulate AI in hiring and employment?
TRAIGA prohibits intentional discrimination through AI in employment, but unlike New York City (Local Law 144) or Illinois, Texas does not require bias audits, impact assessments, or mandatory disclosure to job applicants about AI use. Disparate impact alone does not violate TRAIGA without evidence of discriminatory intent. However, employers must still comply with federal anti-discrimination laws, and the Attorney General can enforce TRAIGA against companies that intentionally use AI to discriminate in hiring.
Updates
Corrected the TRAIGA and SB 1188 penalty figures to the statutes' actual tiers and maximums, limited the biometric prohibition to governmental entities as the statute does, and corrected the NIST safe harbor, which requires discovery of the violation through an internal review process rather than framework compliance alone.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Texas Business & Commerce Code
§ 552.056UNLAWFUL DISCRIMINATIONIn force
(a) In this section: (1) "Financial institution" has the meaning assigned by Section 201.101, Finance Code. (2) "Insurance entity" means: (A) an entity described by Section 82.002(a), Insurance Code; (B) a fraternal benefit society regulated under Chapter 885, Insurance Code; or (C) the developer of an artificial intelligence system used by an entity described by Paragraph (A) or (B). (3) "Protected class" means a group or class of persons with a characteristic, quality, belief, or status protected from discrimination by state or federal civil rights laws, and includes race, color, national origin, sex, age, religion, or disability. (b) A person may not develop or deploy an artificial intelligence system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. (c) For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- HB 149 Bill Text - Texas Responsible AI Governance Act(capitol.texas.gov).gov
- HB 149 Bill History - Texas Legislature(capitol.texas.gov).gov
- SB 1964 Bill Analysis - Government AI Regulation(capitol.texas.gov).gov
- Texas Department of Information Resources - Technology Legislation(dir.texas.gov).gov
- SB 441 Deepfake Civil Liability - Texas Senate News(senate.texas.gov).gov
- HB 3133 Bill Text - Platform Deepfake Removal(capitol.texas.gov).gov
- SB 441 Bill Text - Intimate Deepfake Liability(capitol.texas.gov).gov
- Texas Responsible AI Governance Act - Norton Rose Fulbright(nortonrosefulbright.com)
- Texas Enacts Responsible AI Governance Act - Baker Botts(bakerbotts.com)
- TRAIGA Key Provisions - Greenberg Traurig(gtlaw.com)
- Navigating TRAIGA - Ropes and Gray(ropesgray.com)
- Texas AI Sandbox - American Bar Association(americanbar.org)
- HB 366 Political Ad AI Disclosure - Texas Tribune(texastribune.org)
- Texas Healthcare AI Disclosure - Texas Medical Association(texmed.org)
- New Texas AI Healthcare Laws - SB 1188 Compliance(tafp.org)
- Texas AI Employment Law - Berkshire Associates(berkshireassociates.com)
- 89th Legislature AI Bills - Jackson Walker(jw.com)
- TRAIGA Pared Back Version - K&L Gates(klgates.com)
- SB 1188 Enrolled Bill Text - Health and Safety Code Chapter 183 (AI in electronic health records; civil penalties)(capitol.texas.gov)
- HB 149 Enrolled Bill Text - TRAIGA, Business and Commerce Code Chapter 552 (prohibitions, safe harbors, civil penalties)(capitol.texas.gov)