Texas TRAIGA: What HB 149 Requires of Healthcare Providers
House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, adding subtitle D, chapters 551 to 554, to title 11 of the Texas Business and Commerce Code
Last updated
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callRegulator
Texas Attorney General, with additional sanctions available to state licensing agencies
Who it applies to
- Any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas
- Providers of health care services or treatment, who owe the patient disclosure duty in section 552.051(f) whenever an AI system is used in relation to that service or treatment
- Health care practitioners using AI for diagnostic purposes, who owe the separate review and disclosure duties in Health and Safety Code section 183.005
- Governmental agencies and entities, which carry additional duties on consumer disclosure, social scoring and biometric identification that private organisations do not
- Insurance entities are excluded from the discrimination provision where they are subject to the applicable insurance statutes on unfair discrimination and unfair practices, and only the Department of Insurance may regulate the business of insurance under this chapter
- Biometric data collected, used or stored for health care treatment, payment or operations under HIPAA is outside the biometric provision
Penalties
The Attorney General has exclusive authority to enforce chapter 552, except for the additional agency sanctions in section 552.106, and the chapter expressly provides no basis for a private right of action. Before any action the Attorney General must give written notice identifying the provisions allegedly violated, and may not sue before the sixtieth day after that notice or at all if the person cures within it and provides a written statement showing how the violation was cured, with supporting documentation and any necessary changes to internal policies. Where a violation is not cured, civil penalties run from ten thousand to twelve thousand dollars for a curable violation or a breach of a cure statement, eighty thousand to two hundred thousand dollars for an uncurable violation, and two thousand to forty thousand dollars per day for a continuing violation. A state licensing agency may separately suspend, place on probation or revoke an authorisation and impose a monetary penalty of up to one hundred thousand dollars where the Attorney General has found a violation and recommended further enforcement. No penalty may be sought for an AI system that has not been deployed.
Deadlines
Dates that already bind, and dates still ahead.
| Date | What happens |
|---|---|
| SB 1188 was signed, adding Health and Safety Code section 183.005 on the use of artificial intelligence in diagnosis and in electronic health records. | |
| HB 149 was signed by the Governor. | |
| SB 1188 took effect, including the requirement that a practitioner using AI for diagnostic purposes review all records created with it and disclose that use to patients. | |
| TRAIGA took effect. The disclosure duty, the prohibited use provisions, the enforcement regime and the regulatory sandbox all became operative. | |
| Deadline for the Attorney General to post the public information and online complaint mechanism required by section 552.102. Complaints are the intended entry point for enforcement. |
What changed in 2026
Movement by year, newest first. Where nothing in the text moved, that is recorded too.
2026
TRAIGA became operative on January 1, 2026. The version that took effect is materially narrower than the bill first filed, which had a Colorado style high risk system framework with impact assessments. What survived is an intent based statute: with a small number of exceptions aimed at government, TRAIGA prohibits developing or deploying AI with a particular purpose rather than penalising a particular result.
The second half of 2026 is the enforcement runway. The Attorney General must post the public information and online complaint mechanism required by section 552.102 no later than September 1, 2026. That mechanism is how the statute expects to hear about violations, so the practical start of enforcement is later than the legal one.
2025
Texas passed two AI laws that matter to providers in the same session, and the smaller one binds sooner.
SB 1188, relating to electronic health record requirements, was signed on June 20, 2025 and took effect on September 1, 2025. It adds Health and Safety Code section 183.005. A health care practitioner may use AI for diagnostic purposes, including recommendations on a diagnosis or course of treatment based on a patient's medical record, subject to conditions, one of which is that the practitioner reviews all records created with AI in a manner consistent with medical records standards developed by the Texas Medical Board. A practitioner using AI for diagnostic purposes must disclose that use to patients.
HB 149 passed the Senate on May 23, 2025 and was signed on June 22, 2025 with a January 1, 2026 effective date. It preempts local ordinances and resolutions on AI use, which forecloses the city by city patchwork that some expected.
The pairing is worth noticing. TRAIGA governs conduct broadly and lightly. SB 1188 governs a specific clinical act narrowly and concretely. For most Texas practices, SB 1188 changes documentation workflow first and TRAIGA changes procurement paperwork second.
What does TRAIGA require of a private healthcare organisation?
Less than its name suggests, and one thing that is easy to miss.
TRAIGA applies to any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. That is a wide net, and it catches out of state vendors serving Texas patients as readily as it catches a Houston health system.
What it then requires of a private organisation is narrow. There is no risk assessment duty, no impact assessment, no registration, no algorithmic discrimination testing programme, and no consumer appeal right. The prohibitions in subchapter B are intent based, and several of them apply only to governmental entities. For a hospital or practice, the operative obligations reduce to three: disclose AI use to patients in the health care context, do not deploy AI with a prohibited intent, and be able to show reasonable care if asked.
That is a deliberately light regime, and it is the clearest example of the divergence in state AI law. Colorado regulates decisions and requires human review on request. California regulates communications and stops payers automating denials. Texas regulates purpose and asks you to tell the patient. Building to Texas alone would leave you badly short in the other two.
When must a Texas provider tell a patient AI is involved?
Section 552.051 is the provision to read carefully, because its structure misleads on a first pass.
Subsection (b) puts the general consumer disclosure duty on a governmental agency that makes available an AI system intended to interact with consumers. A private business is not covered by subsection (b) on its own terms.
Subsection (f) is where private healthcare comes in. If an AI system is used in relation to a health care service or treatment, the provider of the service or treatment must give the disclosure described in subsection (b) to the recipient of the service or treatment, or to their personal representative, not later than the date the service or treatment is first provided. In an emergency, the disclosure must be given as soon as reasonably possible.
Four details change how you implement it.
- The trigger is broad. Used in relation to a health care service or treatment, not used to communicate with the patient and not used to make a decision. An AI system involved in the care pathway is enough on the face of the text.
- The deadline is a date, not a moment. Not later than the date treatment is first provided. Unlike Utah, which demands disclosure at the start of the interaction, Texas lets you disclose at registration for care delivered later that day.
- Obviousness is irrelevant. Subsection (c) requires disclosure regardless of whether it would be obvious to a reasonable consumer that they are interacting with an AI system.
- Form is prescribed. Clear and conspicuous, written in plain language, and it may not use a dark pattern as defined in section 541.001. Subsection (e) expressly permits a hyperlink directing the consumer to a separate web page.
The hyperlink allowance is the practical gift. A single, well drafted, plain language page describing how AI is used across your services, linked from registration paperwork and the patient portal and delivered at or before first treatment, satisfies the Texas duty for the whole estate at once. That is a far cheaper design than per interaction disclosure, and it is worth building even if you also run per interaction disclosure for Utah and California.
What uses does TRAIGA actually prohibit?
Five prohibitions, of which two apply to everyone and three are aimed at government.
- Manipulation of human behaviour (552.052). No person may develop or deploy an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self harm including suicide, to harm another person, or to engage in criminal activity.
- Unlawful discrimination (552.056). No person may develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. Subsection (c) states plainly that a disparate impact is not sufficient by itself to demonstrate an intent to discriminate. Insurance entities subject to the applicable unfair discrimination statutes are excluded, and a federally insured financial institution complying with banking law is deemed compliant.
- Constitutional protection (552.055). A person may not develop an AI system with the sole intent of infringing, restricting or impairing rights guaranteed under the United States Constitution.
- Sexually explicit content and child exploitation material (552.057). Prohibited outright.
- Social scoring (552.053) and biometric identification (552.054). Both restricted to governmental entities. Note that the biometric provision expressly excludes information collected, used or stored for health care treatment, payment or operations under HIPAA, which keeps ordinary clinical voice and image data out of it.
The intent requirement is the whole design. A clinical model that performs worse for one patient group is a serious clinical governance failure and may well be a problem under federal civil rights law or under other regimes. On the face of section 552.056 it is not a TRAIGA violation without intent. Do not read that as permission. Read it as a statement that TRAIGA is not the statute that will catch your fairness problem, and that something else will.
What safe harbours does Texas offer, and how do you earn them?
Texas offers the most usable safe harbour in US state AI law, and it is the reason a Texas deployment is worth documenting well even though the duties are light.
Section 552.105(c) creates a rebuttable presumption that a person used reasonable care as required under the chapter. Subsection (e) then says a defendant may not be found liable if another person used the affiliated AI system in a prohibited manner, or if the defendant discovered a violation through any of four routes:
- Feedback from a developer, deployer or other person who believes a violation has occurred.
- Testing, including adversarial testing or red team testing.
- Following guidelines set by applicable state agencies.
- Substantial compliance with the most recent version of the NIST publication Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or another nationally or internationally recognised risk management framework for AI systems, together with an internal review process.
Two things follow. First, the framework named is the generative AI profile specifically, not the base AI Risk Management Framework, and the statute says most recent version, so a programme pinned to a 2023 document is not obviously substantial compliance in 2026. Second, the safe harbour requires an internal review process alongside the framework. Adopting the framework as a policy and never running a review does not qualify.
The commercial implication is straightforward. A NIST aligned governance programme with documented adversarial testing and a real internal review cycle is not overhead in Texas, it is a statutory defence. It is also directly reusable: the same artefacts answer Colorado's record keeping duty, California's CPPA risk assessment obligations and the diligence questions in any hospital procurement. Building that once is the core of our AI governance and compliance engagement.
Section 552.105(f) adds one more protection: the Attorney General may not bring an action to collect a civil penalty for an AI system that has not been deployed. Pilots and internal evaluations are outside the penalty regime.
What does SB 1188 add for clinicians using AI?
SB 1188 took effect on September 1, 2025, four months before TRAIGA, and for a practising clinician it is the more immediate rule.
It adds Health and Safety Code section 183.005. A health care practitioner may use AI for diagnostic purposes, including recommendations on a diagnosis or course of treatment based on a patient's medical record, where the statutory conditions are met. One of those conditions is that the practitioner reviews all records created with AI in a manner consistent with the medical records standards developed by the Texas Medical Board. Separately, a practitioner using AI for diagnostic purposes must disclose that use to patients.
Three practical consequences.
- Review is a records obligation, not a clinical courtesy. It is framed against Texas Medical Board records standards, which means it will be assessed like documentation is assessed, through the record itself. An ambient scribe workflow that allows an unreviewed draft to persist in the chart is a records problem in Texas before it is anything else.
- There are now two disclosure duties running in parallel. Section 183.005 requires disclosure of diagnostic AI use to patients. TRAIGA section 552.051(f) requires disclosure where an AI system is used in relation to health care service or treatment, no later than the date treatment is first provided. One well built disclosure can satisfy both, but only if it is drafted against both.
- Diagnostic use is the line. Documentation and administrative use sit outside section 183.005 and inside TRAIGA's broader trigger. Inbox triage that suggests a diagnostic direction, rather than merely routing a message, moves across that line.
What does enforcement look like, and what does it cost?
The route is complaint driven and the numbers are large, but the cure period is generous enough that a competent organisation should never reach the numbers.
The Attorney General has exclusive enforcement authority under section 552.101, and the chapter expressly provides no basis for a private right of action. Section 552.102 requires an online complaint mechanism, which the Attorney General must post by September 1, 2026. Section 552.103 gives the Attorney General a civil investigative demand power, and the categories it can reach are worth knowing in advance: the system's purpose and use, categories of training data, input and output categories, performance metrics, known limitations and post deployment monitoring. If you cannot produce those on request, you have a documentation problem regardless of whether you have a compliance problem.
Section 552.104 then requires written notice identifying the specific provisions allegedly violated, and bars an action before the sixtieth day after that notice. If the person cures within sixty days and provides a written statement that the violation is cured, with supporting documentation and any necessary changes to internal policies, the action cannot be brought at all.
Only if that fails do the penalties in section 552.105 apply: ten thousand to twelve thousand dollars for a curable violation or a breach of a cure statement, eighty thousand to two hundred thousand dollars for an uncurable violation, and two thousand to forty thousand dollars per day for a continuing violation, plus injunctive relief and the state's fees and investigative expenses. Section 552.106 lets a licensing agency add suspension, probation or revocation and a monetary penalty of up to one hundred thousand dollars where the Attorney General has found a violation and recommended further enforcement. For a licensed facility that agency exposure is the more serious of the two.
The realistic failure mode is not the penalty schedule. It is receiving a civil investigative demand and discovering that nobody can say which model version was in production on a given date, what it was trained on, or who reviewed its output. That is an inventory and logging problem, and it is solved before it is asked, or not at all.
Is the Texas AI sandbox useful to a health system?
Chapter 553 creates an artificial intelligence regulatory sandbox programme administered with the Department of Information Resources. A participant may test a system for up to thirty six months, extendable for good cause, without holding the licences or registrations that would otherwise be required, and with other laws and regulations set aside except for the prohibited use provisions in subchapter B, which are never waived. Participants file quarterly reports on performance metrics, risk mitigation and stakeholder feedback, and can be removed for undue risk to public safety or for violating state or federal law.
Chapter 554 establishes a seven member Texas Artificial Intelligence Council, appointed by the Governor, Lieutenant Governor and Speaker, which issues reports, conducts training, makes legislative recommendations and oversees the sandbox. It cannot adopt binding rules or override an agency.
Is it useful to a provider? Rarely, and for the same reason as the Utah learning laboratory: standard deployments do not need a rule waived. The sandbox matters if you are testing something that a Texas licensing requirement currently blocks, which is a developer's problem far more often than a health system's. It matters indirectly to everyone, because a vendor's participation is public information and tells you something about the maturity of what they are selling.
The council is worth tracking for a different reason. Its reports and training materials are the closest thing Texas will produce to agency guidance, and section 552.105(e)(2)(C) makes following guidelines set by applicable state agencies one of the routes into the safe harbour.
Should you build one AI governance programme or four?
One, built to the strictest requirement in each row rather than to the strictest state overall. No single state is strictest on everything, which is why the state by state project approach produces four incompatible programmes and a lot of duplicated evidence.
| Requirement | Strictest state | What that state demands | Build once as |
|---|---|---|---|
| Patient disclosure timing | Utah | Verbally at the start of a verbal interaction, in writing before a written one | Persistent AI identification at the start of every patient facing interaction |
| Disclosure content | California | Disclaimer plus instructions for reaching a human, placed by medium | One disclosure template with a route to a human, applied everywhere |
| Estate wide notice | Texas and Colorado | Notice before first treatment; general notice of advanced technologies | A single linked page describing AI use across services |
| Human review of adverse outcomes | Colorado | Trained reviewer with authority to override, who does not default to the output | One named review path with defined authority and training |
| Risk documentation | Texas and California | NIST generative AI profile plus internal review; CPPA risk assessments | One NIST aligned assessment per system, reviewed on a cycle |
| Record retention | Colorado and California | Three years after the decision; five years for risk assessments | Five year retention on system versions, decisions and assessments |
| Clinician record review | Texas | Review all records created with AI to Texas Medical Board standards | Attestation gate before any AI generated content enters the chart |
Read the right hand column as the actual specification. It has seven items and it satisfies all four states. Note also what is not in it: impact assessments as a standing obligation, algorithmic discrimination testing as a legal requirement, and consumer opt out rights outside California. Those either died with the original Colorado Act or never applied to HIPAA covered entities in the first place.
One caution on planning horizons. Proposals to preempt state AI regulation have surfaced repeatedly in Congress and in federal policy since 2025, and none has settled the question. Building to a preemption that has not arrived is a bet with no upside, because the seven item specification above is defensible practice regardless of who ends up enforcing it.
If you deploy agents in Texas, do these things
Six items, roughly in order of how quickly they pay back.
- Publish one AI use page and link it from registration. Section 552.051(e) expressly permits disclosure by hyperlink. Plain language, no dark patterns, delivered no later than the date treatment is first provided. This closes the main TRAIGA duty for the whole estate in one artefact.
- Gate AI generated content behind clinician attestation. SB 1188 requires review of all records created with AI to Texas Medical Board standards, and it has been in force since September 2025. If a draft can reach the chart unsigned, fix that before anything else on this list.
- Adopt the NIST generative AI profile and actually run the review. Substantial compliance plus an internal review process is a statutory defence under section 552.105(e). Half of it is not. Diarise the review, record the outputs, keep the versions.
- Run adversarial testing and write down what you found. Discovery through testing including red team testing is an independent route into the safe harbour. Testing that finds nothing and is not documented buys you nothing.
- Prepare the civil investigative demand answer in advance. System purpose and use, training data categories, input and output categories, performance metrics, known limitations, post deployment monitoring. One page per system, kept current, is the entire exercise.
- Check the vendor is inside scope with you. TRAIGA reaches anyone producing a product or service used by Texas residents, so your out of state vendor is covered too. Their documentation is what makes your safe harbour credible, so ask for it in the contract rather than after a notice arrives.
Texas rewards preparation more than it punishes error: there is a sixty day cure, a rebuttable presumption of reasonable care, a named framework you can comply with, and no private right of action. An organisation that has done items three through five has very little to fear from the statute. An organisation that has done none of them will spend the cure period building what it should already have had. If you want that programme designed once and mapped across Texas, Colorado, California and Utah, that is what our AI governance and compliance engagement delivers, and it usually starts with the estate inventory produced by an AI readiness audit.
Official sources
Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.
- StateHB 149, Responsible Artificial Intelligence Governance Act, Texas Legislature Online (opens in a new tab)
- StateHB 149 enrolled text, Texas Legislature Online (opens in a new tab)
- StateSB 1188, electronic health record requirements, Texas Legislature Online (opens in a new tab)
- StateTexas Attorney General (opens in a new tab)
- StateTexas Medical Board (opens in a new tab)
- NISTAI Risk Management Framework, NIST (opens in a new tab)
Questions we get asked
When did the Texas AI law take effect?
HB 149, the Texas Responsible Artificial Intelligence Governance Act, was signed on June 22, 2025 and took effect on January 1, 2026. The Attorney General's online complaint mechanism, which is the statute's intended enforcement entry point, was required to be posted no later than September 1, 2026. Texas SB 1188, covering AI in diagnosis and electronic health records, took effect earlier, on September 1, 2025.
Does TRAIGA require providers to tell patients about AI?
Yes. Section 552.051(f) requires that where an AI system is used in relation to a health care service or treatment, the provider gives the disclosure to the recipient or their personal representative no later than the date the service or treatment is first provided, and as soon as reasonably possible in an emergency. It must be clear, conspicuous, in plain language and free of dark patterns, and it may be delivered by hyperlink.
Does TRAIGA ban biased AI?
Only where there is intent. Section 552.056 prohibits developing or deploying an AI system with the intent to unlawfully discriminate against a protected class, and expressly states that a disparate impact is not sufficient by itself to demonstrate that intent. A biased clinical model may still create serious exposure under federal civil rights law and under your own clinical governance, but TRAIGA is not the statute that reaches it.
What is the NIST safe harbour under Texas law?
Under section 552.105(e), a defendant cannot be found liable where the violation was discovered through substantial compliance with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or another nationally or internationally recognised AI risk management framework, together with an internal review process. Feedback, adversarial testing and following state agency guidelines are three further independent routes.
What are the penalties under TRAIGA?
Ten thousand to twelve thousand dollars for a curable violation or a breach of a cure statement, eighty thousand to two hundred thousand dollars for an uncurable violation, and two thousand to forty thousand dollars per day for a continuing violation. A licensing agency may add suspension, probation or revocation plus up to one hundred thousand dollars. All of this follows a mandatory written notice and a sixty day opportunity to cure.
Can a patient sue under the Texas AI law?
No. Section 552.101(b) states that the chapter does not provide a basis for, and is not subject to, a private right of action. The Attorney General has exclusive enforcement authority except for the separate sanctions available to state licensing agencies under section 552.106. Other causes of action outside the chapter are unaffected.
Do out of state vendors have to comply with TRAIGA?
Yes, if they meet any of the three applicability tests in section 551.002: promoting, advertising or conducting business in Texas, producing a product or service used by Texas residents, or developing or deploying an AI system in Texas. A vendor serving your Texas patients from another state is inside the statute, which is a reasonable basis for asking them to produce the documentation your own safe harbour depends on.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion