Texas Data Privacy and Security Act
TRAIGA Is Now in Effect: What Texas's New AI Law Means for Your TDPSA Compliance Obligations
The Texas Responsible AI Governance Act took effect January 1, 2026, giving the Attorney General a second privacy statute to enforce against Texas businesses that develop or deploy AI systems.
The Texas Responsible Artificial Intelligence Governance Act, known as TRAIGA, took effect January 1, 2026, giving the Texas Attorney General a dedicated statute to enforce against any business that develops or deploys an artificial intelligence system reaching Texas residents, according to legal analyses from Norton Rose Fulbright and Baker Botts. TRAIGA now operates alongside the Texas Data Privacy and Security Act (TDPSA), and the same Attorney General's office enforces both. Since 2024 that office has used a mix of Texas privacy statutes, including the state's biometric-data law and its Deceptive Trade Practices Act, to secure the largest data privacy settlement obtained by a single state, a $1.4 billion recovery from Meta, according to the Texas Attorney General's office and CNBC. For commercial organizations that have treated AI adoption as a technology decision rather than a compliance one, an active AI-specific statute layered onto an aggressively enforced privacy enforcement office is worth a closer look now, not after the first inquiry letter arrives.
What TRAIGA Actually Requires
TRAIGA is not limited to companies that build AI products. The law's own language reaches anyone who "promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas," according to Norton Rose Fulbright's summary of the statute. That definition covers a business using an AI-driven chatbot for customer service, an AI tool that screens job applicants, an AI feature inside practice-management or accounting software, or a marketing platform that personalizes offers with machine learning, not only companies that train their own models.
The enforcement structure gives businesses room to fix problems, but only if they know a violation exists. The Texas Attorney General has exclusive authority to enforce TRAIGA, there is no private right of action, and the law provides a 60 day period to cure an alleged violation after notice, according to Norton Rose Fulbright, Baker Botts, and Wiley. A curable violation left uncured after that window can draw a civil penalty of $10,000 to $12,000, while a violation the statute treats as uncurable can draw $80,000 to $200,000, and a separate penalty of $2,000 to $40,000 per day applies to violations that continue, figures each firm cites directly from the statute's enforcement section. Those penalties apply on top of, not instead of, TDPSA's separate $7,500-per-violation exposure for mishandling the personal data an AI system relies on in the first place, a figure confirmed on the state's own Department of Information Resources TDPSA page and by Osano's TDPSA overview.
Why This Matters for Texas Businesses
Any business in Houston, Dallas, Spring, or Lufkin that has added an AI feature to a customer-facing product, HR process, or internal workflow in the last two years should treat this as applicable now, along with any company nationwide whose product or service reaches Texas customers. TDPSA's own applicability test does not use a revenue threshold. It reaches any entity that conducts business in Texas or serves Texas residents, processes or sells personal data, and does not qualify as a small business under U.S. Small Business Administration standards, according to Osano's summary of the statute, a bar that many mid-sized professional services firms clear without realizing it. TDPSA does carve out entity-level exemptions, including financial institutions regulated under the Gramm-Leach-Bliley Act and covered entities and business associates governed by HIPAA, so a business in a regulated industry should confirm its own exemption status with counsel rather than assume coverage or exemption either way.
What It Means for Your Obligations
Start with an honest inventory of every system in your business that uses artificial intelligence to make or influence a decision, including any embedded in software you did not build yourself, from applicant screening tools to AI features quietly added to a platform you already use.
Document the intended purpose of each AI system and the steps taken to avoid discriminatory or harmful outcomes. TRAIGA's civil penalties attach to intent-based prohibited conduct, which the Attorney General must establish to bring an enforcement action, and documented design decisions and testing records are the kind of evidence that can support your position if that question is ever raised, a point Norton Rose Fulbright and Baker Botts both stress in their analyses of the law.
Give customers, employees, and applicants clear notice when an AI system plays a meaningful role in a decision that affects them, in plain language and free of dark patterns. TRAIGA requires this kind of disclosure from government agencies, and in a more limited form from healthcare providers; extending the same practice to commercial use is a reasonable governance step consistent with the general notice obligations TDPSA already places on data processing.
Extend your vendor management program to every AI vendor with access to Texas consumer data, not only your core IT vendors. Ask what data the tool processes, whether it trains on your data, and how the vendor itself complies with TDPSA and TRAIGA before you sign or renew an agreement.
Maintain access controls and logging over the systems and data that feed your AI tools. TDPSA's consumer rights, including access, correction, and opt-out requests, only work if you can find, and reliably act on, the personal data behind them.
Build an incident and complaint response path that covers AI-specific issues, not only traditional data breaches, since the Attorney General is required to maintain an online mechanism for individuals to submit AI-related complaints under TRAIGA.
Train the employees who select, configure, or operate AI tools on what the law expects, since staff outside your security or legal team are often the ones who first turn on a new AI feature.
Retain the inventory, risk documentation, vendor assessments, and training records you produce. A dated compliance trail is what turns a 60 day cure period into a genuine opportunity to fix a problem instead of a scramble to reconstruct one.
The Bottom Line
Texas now enforces two statutes, TDPSA and TRAIGA, that reach the same underlying activity: how a business collects, uses, and automates decisions from Texas residents' data. An AI feature that reaches Texas customers is a compliance question the moment it goes live, not a hypothetical the first time the Attorney General's office asks about it. Businesses that can show a current inventory, documented AI governance, and a real vendor management program are the ones positioned to respond with evidence instead of a scramble. This brief is general security and compliance awareness, not legal advice, and Cyber One Solutions does not provide legal opinions on TDPSA or TRAIGA applicability; consult qualified Texas counsel for a determination specific to your business. Our compliance consulting services help build the governance, documentation, and vendor oversight evidence these laws expect, backed by IT and security assessments that inventory the systems and data an AI tool touches and managed cybersecurity that keeps access controls and logging in place around them. Businesses in the Houston area can start with a conversation about where their AI and data privacy exposure currently stands.
Sources
- Norton Rose Fulbright: The Texas Responsible AI Governance Act
- Baker Botts: Texas Enacts Responsible AI Governance Act
- Wiley: Texas Responsible AI Governance Act Enacted
- Texas Department of Information Resources: Texas Data Privacy and Security Act
- Osano: Texas Data Privacy and Security Act (TDPSA)
- Texas Attorney General: AG Paxton Secures $1.4 Billion Settlement with Meta
- CNBC: Google to pay Texas $1.4 billion in data privacy settlement
