Texas TRAIGA and the NIST AI RMF Safe Harbour: What an AI Sales Team Should Actually Document
Quick answer: The Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature) took effect on 1 January 2026 as Chapters 551–554 of the Texas Business & Commerce Code. It bans a short list of intentional AI harms, puts the consumer-disclosure duty on governmental agencies and health care providers rather than private sellers, gives the Attorney General exclusive enforcement with a 60-day cure window, and offers a documentation-based defence tied to the NIST AI Risk Management Framework.
This is general information about published statutes and standards, not legal advice. It reflects the enrolled bill text as read on 26 August 2026. Get Texas counsel before relying on it.
Two things happen when a US state passes an AI law: vendors email to say you are now non-compliant, and summaries appear that merge it with whichever other law came out the same session. TRAIGA has attracted both. This piece is built from the enrolled text of HB 149 published by the Texas Legislature, cross-checked against the Texas Attorney General’s Consumer AI Rights page.
What TRAIGA actually is
Section 10 of the enrolled bill reads: “This Act takes effect January 1, 2026.” It adds Subtitle D, “Artificial Intelligence Protection,” to Title 11 of the Business & Commerce Code — Chapter 551 (general provisions), Chapter 552 (the prohibitions and enforcement), Chapter 553 (a regulatory sandbox) and Chapter 554 (the Texas Artificial Intelligence Council).
Applicability is broad. Section 551.002 applies the subtitle to a person who “promotes, advertises, or conducts business in this state,” “produces a product or service used by residents of this state,” or “develops or deploys an artificial intelligence system in this state.” An Australian vendor selling into Texas is inside that net; there is no revenue floor or headcount threshold.
The obligations are narrow and keyed to intent. Section 552.052 prohibits developing or deploying an AI system “in a manner that intentionally aims to incite or encourage” self-harm, harm to another, or criminal activity. Section 552.056 prohibits deploying a system “with the intent to unlawfully discriminate against a protected class,” adding at subsection (c) that “a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.” Section 552.055 catches systems built with the “sole intent” of impairing constitutional rights. Sections 552.053 (social scoring) and 552.054 (biometric capture) bind governmental entities only.
That is a different design from a risk-tier regime. The EU AI Act asks what your system does; TRAIGA asks what you were trying to do.
The disclosure duty is not on you (probably)
This is the most commonly mangled part. Section 552.051(b) reads: “A governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an artificial intelligence system.” Subsection (f) extends the duty to providers of health care services or treatment. The Attorney General’s summary lists exactly those two, and a private B2B sales team is in neither. A second limit sits on top: Section 551.001(2) defines “consumer” as a resident “acting only in an individual or household context,” and says the term “does not include an individual acting in a commercial or employment context.”
Do not read that as licence to hide the robot. Disclosure duties for AI callers into the US come from other instruments — the TCPA’s artificial-voice consent regime, the identification rules at 47 CFR §64.1200(b), and a handful of genuine state AI-disclosure statutes, mapped separately in The US State AI Call-Disclosure Patchwork. TRAIGA is not one of them for private sellers.
TRAIGA is not Texas SB 140
Both are Texas, both 89th Legislature, both amend the Business & Commerce Code, and both get filed under “the Texas AI law” in vendor decks. They are unrelated. SB 140 is captioned “relating to certain definitions relating to the regulation of and private rights of action arising from certain solicitation-related communications”: it widens “telephone solicitation” to cover “a transmission of a text or graphic message or of an image,” makes Chapter 304 and 305 violations deceptive trade practices, and took effect 1 September 2025. It never mentions artificial intelligence.
| TRAIGA (HB 149) | SB 140 | |
|---|---|---|
| Subject | Development and deployment of AI systems | Telephone and text solicitation |
| Where codified | Bus. & Com. Code ch. 551–554 | Bus. & Com. Code ch. 302, 304, 305 |
| Effective | 1 January 2026 | 1 September 2025 |
| Trigger | Prohibited intent | Sending a solicitation, AI or not |
| Who sues | Attorney General (exclusive under §552.101(a), except as provided by §552.106); §552.101(b) states the chapter “does not provide a basis for” a private right of action | Expressly enables private DTPA remedies |
If you run SMS or voice outreach into Texas, SB 140 is the one that can produce a plaintiff. TRAIGA is the one that can produce a civil investigative demand.
The safe harbour, read literally
Three protections sit in Section 552.105. Subsection (c): “There is a rebuttable presumption that a person used reasonable care as required under this chapter.” Subsection (f) bars a penalty action over a system “that has not been deployed.” Subsection (e) is the one everyone calls the NIST safe harbour, and the summaries flatten it. It says a defendant “may not be found liable if” either another person misused the system, or “the defendant discovers a violation of this chapter through” one of four routes: feedback from a developer, deployer or other person; “testing, including adversarial testing or red-team testing”; following applicable state agency guidelines; or — at (e)(2)(D) — “if the defendant substantially complies with the most recent version of the ‘Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile’ published by the National Institute of Standards and Technology or another nationally or internationally recognized risk management framework for artificial intelligence systems, an internal review process.”
Two consequences. First, the NIST hook is not “adopt the framework and you are immune”. It qualifies an internal review process through which you find the problem yourself. The framework is what makes your self-discovery count. Second, the statute names a specific document: NIST AI 600-1, the Generative AI Profile, published 26 July 2024, a cross-sectoral companion to AI RMF 1.0 (NIST AI 100-1, January 2023) naming 12 risks unique to or exacerbated by generative AI. As at 26 August 2026 that July 2024 edition is still the published version — but the statute says “most recent version,” so re-check each audit cycle.
The real documentation spec is Section 552.103(b)
Here is the underused part of the statute. Section 552.103(b) lists what the Attorney General may request under a civil investigative demand. That list is, in effect, the file you should already have: the system’s “purpose, intended use, deployment context, and associated benefits”; training-data types; input categories; outputs; “any metrics the person uses to evaluate the performance”; “any known limitations”; and post-deployment monitoring and safeguards, “including, if the person is a deployer, the oversight, use, and learning process established by the person to address issues arising from the system’s deployment.”
Those items map onto the four AI RMF functions. NIST describes GOVERN as “a cross-cutting function that is infused throughout AI risk management,” MEASURE as employing “quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk,” and MANAGE as “allocating risk resources to mapped and measured risks on a regular basis.” Build the file once and it answers both.
The checklist: obligation, framework, artefact
| Obligation area | What TRAIGA requires | What the NIST AI RMF suggests | Artefact you keep on file |
|---|---|---|---|
| Intended use and scope | Nothing proactive; §552.103(b)(1) lets the AG demand “purpose, intended use, deployment context” | MAP 1.1: intended purposes, context-specific laws, norms and prospective settings “are understood and documented” | One-page intended-use statement per agent: audience, channels, jurisdictions, out-of-scope tasks |
| Consumer disclosure | Required of governmental agencies (§552.051(b)) and health care providers (§552.051(f)) — clear and conspicuous, plain language, no dark patterns | MEASURE 2.8: transparency and accountability risks “are examined and documented” | Approved disclosure scripts per channel and language, versioned, with the date each went live |
| Consent and data | Biometric prohibition binds governmental entities (§552.054); training and input data are demandable under §552.103(b)(2)–(3) | GOVERN 1.1: legal and regulatory requirements involving AI “are understood, managed, and documented” | Consent records tied to contact ID and timestamp; voice-clone authorisations; data-source register |
| Non-discrimination | Intent to unlawfully discriminate is prohibited (§552.056(b)); disparate impact alone is not proof of intent (§552.056(c)) | MEASURE function: testing before deployment and regularly in operation | Pre-launch and periodic test logs: prompts run, subgroup results, who signed off, what changed |
| Known limitations | Demandable under §552.103(b)(5)–(6): evaluation metrics and known limitations | MAP 3.4: operator and practitioner proficiency processes “are defined, assessed, and documented” | A living limitations register, plus the operator training record for the humans behind the agent |
| Human oversight | Demandable under §552.103(b)(7): the “oversight, use, and learning process” | MANAGE 4.1: post-deployment monitoring including “appeal and override, decommissioning, incident response, recovery, and change management” | Escalation design doc: confidence thresholds, hard-stop topics, handoff path, override log |
| Incidents | Discovery through feedback or red-team testing supports the §552.105(e)(2) defence | MANAGE 2.3 and MANAGE 4.3: respond to and recover from previously unknown risks; processes for “tracking, responding to, and recovering from incidents and errors” followed and documented | Dated incident register: what surfaced it, containment, fix, policy change |
| Cure readiness | §552.104(b)(2): cure within 60 days and give the AG written confirmation with supporting documentation and internal-policy changes | GOVERN 1.4: the risk management process and its outcomes “are established through transparent policies, procedures, and other controls” | A pre-drafted cure-response runbook and named owner, so that day one of sixty is not spent finding the files |
Retention deserves its own line. The statute sets no retention period, so borrow one from your existing records policy and write it down. An artefact you cannot produce inside a 60-day cure window is an artefact you do not have.
Where this lands for an AI sales team
Zian AI builds autonomous phone, SMS, email and WhatsApp agents, so this documentation burden is our design problem before it is a customer’s compliance problem. Most of the artefacts above are by-products of running agents properly: PrecisionPitch AI’s continuous split-testing of scripts is a test log if you keep the results, and a confidence threshold that escalates to a human is an oversight record if you log the handoff. Zian is in waitlist and partnership beta, so if a completed third-party audit trail is a hard procurement gate this quarter, an established vendor is the better fit today.
FAQ
Does TRAIGA require my AI sales agent to announce itself on a call in Texas?
Not under TRAIGA. Section 552.051(b) puts the disclosure duty on a “governmental agency,” and subsection (f) on health care providers. Other laws may still require it — see our state-by-state disclosure map.
Can a customer sue us under TRAIGA?
No. Section 552.101(b) states the chapter “does not provide a basis for, and is not subject to, a private right of action for a violation of this chapter or any other law.” Enforcement sits with the Attorney General — exclusive under Section 552.101(a), except that Section 552.106 lets a licensing agency add sanctions after an AG finding and recommendation. Under Section 552.102 the Attorney General must maintain an online complaint mechanism — the Consumer AI Rights page is where that lives.
What are the penalties?
Section 552.105(a) sets civil penalties of $10,000 to $12,000 for each curable violation or breach of a cure statement; $80,000 to $200,000 for each uncurable violation; and $2,000 to $40,000 per day for a continued violation.
Which NIST document does the statute actually name?
Section 552.105(e)(2)(D) names the “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile” — that is NIST AI 600-1, published July 2024, a cross-sectoral profile of AI RMF 1.0 offering “suggested actions to help organizations govern, map, measure, and manage” generative-AI risks. The statute also accepts “another nationally or internationally recognized risk management framework.”
We already did EU AI Act Article 50 work. Does any of it carry over?
The artefacts do, even though the duties differ. Article 50 imposes a transparency obligation TRAIGA does not put on private deployers, but the disclosure scripts, consent records and oversight design you built for it slot straight into the table above. Our EU AI Act Article 50 checklist covers that side.
Does the sandbox exempt us from TRAIGA?
Not from the prohibitions. Section 553.051(e) says that notwithstanding the enforcement relief given to participants, “the requirements of Subchapter B, Chapter 552, may not be waived,” and the Attorney General or a state agency may still act against a participant who violates that subchapter.
Sources
Every section number and quotation above comes from the Texas Legislature’s enrolled texts of HB 149 and SB 140, the Texas Attorney General’s Consumer AI Rights page, and NIST’s AI 600-1 Generative AI Profile (July 2024) and AI RMF 1.0 (January 2023).
If you want that evidence trail built in from the first call rather than reconstructed under a 60-day cure notice, then Apply For Partnership.