Texas HR team building an AI tool inventory on a whiteboard for TRAIGA compliance

A Practical Breakdown of What Texas’s New AI Law Actually Requires From Employers

Texas’s new AI law, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), took effect January 1, 2026. If you’ve read a summary online that says Texas now requires AI disclosure notices, mandatory risk assessments, or a written AI policy before you can use hiring software, most of that isn’t accurate for private employers. Lawmakers stripped those requirements out of the bill before Governor Greg Abbott signed it. What’s left is narrower, but it still changes how Texas employers should handle AI in hiring, promotions, and performance decisions. Here’s what the law actually says, what it doesn’t, and what HR teams should do about it.

HR professional reviewing AI-flagged hiring results on a laptop under a Texas TRAIGA compliance policy
Texas employers using AI to screen candidates now fall under TRAIGA’s intent-based discrimination standard.

What TRAIGA Is and When It Took Effect

Governor Abbott signed House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, into law on June 22, 2025. It took effect January 1, 2026, making Texas the third state with a comprehensive AI law on the books. TRAIGA applies broadly: it covers anyone who develops or deploys an AI system in Texas, or who advertises, promotes, or does business in the state, including out-of-state employers with Texas workers. The law defines an “artificial intelligence system” as any machine-based system that generates outputs like content, decisions, predictions, or recommendations from the data it receives, a definition wide enough to cover applicant tracking software, resume screening tools, and AI-assisted performance review platforms. Most Texas employers fall into the law’s “deployer” category, meaning they put an AI system into use rather than build one from scratch, and TRAIGA’s obligations for deployers are lighter than what it asks of developers who create these tools in the first place.

What TRAIGA Does Not Require (This Surprises Most Employers)

TRAIGA started out as a much bigger bill. The original 2024 proposal would have required companies to disclose AI use to job applicants, run impact assessments to check for algorithmic bias, and maintain a formal risk management policy, an approach similar to Colorado’s AI law. Lawmakers cut nearly all of that before the final version passed, and the text of House Bill 149 as enrolled reflects the narrower version.

No Disclosure Requirement for Employers

Under the law as signed, private employers don’t have to tell job applicants or employees when an AI tool is involved in a hiring or personnel decision. TRAIGA’s disclosure rule applies to state agencies and to healthcare providers using AI in treatment, not to private-sector HR departments. The law’s definition of “consumer” specifically excludes anyone acting in a commercial or employment context.

No Mandatory Risk Assessments or AI Policy

The original bill would have required developers and deployers to complete algorithmic impact assessments before using AI for consequential decisions. That requirement didn’t survive. According to K&L Gates’ analysis of the signed law, TRAIGA does not force Texas employers to complete a formal risk assessment or adopt a written AI policy as a legal prerequisite to using AI in HR.

That last point comes with an important caveat, covered below: not being required to have a policy isn’t the same as it being a bad idea to skip one.

What TRAIGA Actually Prohibits

Instead of broad disclosure and assessment mandates, TRAIGA takes a narrower, intent-based approach. It prohibits developing or deploying an AI system with the intent to unlawfully discriminate against someone based on a protected class, like race, sex, age, or disability. The key word is intent. Under TRAIGA, a hiring algorithm that produces a discriminatory outcome isn’t automatically a violation. The state has to show the system was built or used with the intent to discriminate. Disparate impact alone, meaning a pattern where an AI tool disadvantages a protected group even without anyone intending it, isn’t enough on its own to trigger liability under this law.

Printed AI vendor contract with a discrimination safeguard clause highlighted during a TRAIGA compliance review
Reviewing vendor contracts for discrimination safeguards is a practical first step under TRAIGA’s intent-based standard.

TRAIGA also bans AI systems intentionally designed to push someone toward self-harm, violence, or criminal activity, and separately prohibits AI used to create child sexual abuse material or deepfake pornography involving minors. Those provisions apply to any developer or deployer, not just employers, and they sit alongside, not instead of, existing federal protections like Title VII, the ADA, and the ADEA, which still apply to AI-assisted employment decisions in Texas regardless of what TRAIGA does or doesn’t require.

How Texas Enforces TRAIGA

Only the Texas Attorney General can bring a TRAIGA enforcement action. There’s no private right of action, so employees can’t sue directly under this law, though they can still file a complaint with the AG’s office or pursue a claim under federal or state anti-discrimination law separately. Before the AG can penalize a violation, the office has to send written notice and give the employer 60 days to fix the problem.

Penalties scale with how serious, and how fixable, the violation is:

Violation type Civil penalty
Curable, fixed within the 60-day notice period No penalty
Curable, not fixed in time $10,000 to $12,000
Uncurable $80,000 to $200,000
Continuing violation $2,000 to $40,000 per day

A single mishandled AI hiring complaint isn’t going to trigger the top end of that range on its own, but a pattern of intentional discrimination that an employer ignores after AG notice could.

Why Texas Employers Should Build an AI Policy Anyway

Not being legally required to have an AI policy is different from it being a smart move to skip one. TRAIGA includes safe harbor provisions that protect employers who can show good-faith compliance efforts, and the easiest way to document that effort is through a policy you can point to later.

Safe Harbors That Protect Compliant Employers

According to Baker Botts’ summary of TRAIGA’s safe harbor provisions, an employer isn’t liable if it discovers a violation through its own internal testing, including adversarial or red-team testing, substantially complies with a recognized framework like the NIST AI Risk Management Framework, follows applicable state agency guidance, or gets hit by third-party misuse of a system it didn’t cause. Each of those defenses works better with a paper trail. If the Texas AG ever opens an inquiry, “we had a policy, we trained on it, and we can show our testing” is a very different conversation than starting from zero.

What a Basic AI Policy Should Cover

A workable policy doesn’t need to be complicated. At minimum, it should name which HR functions use AI, such as screening, scheduling, or performance scoring, spell out who reviews AI-flagged decisions before they’re final, require vendors to confirm their tools don’t intentionally discriminate, and set a schedule for periodic testing. Document the legitimate business purpose for each AI tool in writing, since that documentation is what would back up an intent-based defense if a complaint is ever filed.

Practical Steps for Texas HR Teams Right Now

Most Texas employers don’t need a compliance overhaul. They need a short list of actions that match TRAIGA’s actual scope:

Texas HR team building an AI tool inventory on a whiteboard for TRAIGA compliance
Most TRAIGA compliance work starts with a simple inventory of every AI tool touching HR decisions.
  • Inventory every AI tool touching HR decisions. Applicant tracking systems, resume-screening software, scheduling algorithms, and performance-review platforms all count.
  • Ask vendors directly about intentional discrimination safeguards. Get it in writing, not just a sales pitch.
  • Write a short AI use policy. It isn’t mandatory, but it should cover what tools are used, who reviews flagged decisions, and how often the system gets tested.
  • Train HR staff and hiring managers on what the policy says and why it matters if the AG ever asks.
  • Keep records of legitimate business purpose for each AI system, since that’s the core of an intent-based defense.
  • Watch for Texas AG guidance, since the office is expected to issue interpretive guidance as complaints start coming in.

None of this requires a legal department the size of a Fortune 500 company. A short written policy and a habit of asking vendors the right questions covers most of what TRAIGA actually asks for.

How TRAIGA Compares to Other States Regulating AI in HR

Texas’s approach stands out for being narrower than most. Colorado’s AI Act, in effect February 1, 2026, uses an impact-based model that requires businesses to conduct algorithmic impact assessments and notify people when AI plays a significant role in an employment decision, regardless of intent. Utah’s AI Policy Act, already in effect, sticks to minimal disclosure requirements. California’s automated decision-making rules under the CCPA lean toward consumer privacy rights and opt-outs. TRAIGA’s intent-based standard, safe harbors, and lack of a disclosure mandate make it more forgiving for employers, but that only covers AI use inside Texas. A Texas-based company with employees or applicants in Colorado, California, or elsewhere still has to meet those states’ stricter rules for that part of its workforce, which means a single national AI hiring tool may need different guardrails depending on where the candidate is located.

The Texas AI Regulatory Sandbox (Probably Not Relevant to Most Employers)

TRAIGA also creates a regulatory sandbox, administered by the Texas Department of Information Resources, that lets approved participants test new AI systems for up to 36 months without obtaining standard state licenses. Participants submit quarterly reports and still have to follow TRAIGA’s core prohibitions during the testing period. This provision matters mainly to AI developers building new products, not to a typical Texas employer buying an off-the-shelf applicant tracking system. It’s worth knowing it exists mostly so you’re not confused if a vendor mentions being part of it.

FAQs about TRAIGA and Texas AI Hiring Law

Do Texas employers have to tell job applicants when AI is used in hiring?

No. TRAIGA’s disclosure requirement applies to state agencies and healthcare providers, not private employers. The law’s definition of “consumer” specifically leaves out anyone in a commercial or employment context, so job applicants and employees fall outside that disclosure rule.

Is TRAIGA the same as Colorado’s AI law?

No. Colorado’s AI Act uses an impact-based standard that requires disclosure and impact assessments regardless of intent. TRAIGA only applies when a system is developed or deployed with the intent to discriminate, which is a much higher bar for the state to prove.

Can an employee sue their employer directly under TRAIGA?

No. TRAIGA gives exclusive enforcement authority to the Texas Attorney General and doesn’t create a private right of action. An employee who believes an AI system discriminated against them can still pursue a claim under federal or state anti-discrimination law, or file a complaint with the AG’s office.

What counts as an “AI system” under TRAIGA?

The law defines it broadly as any machine-based system that generates outputs like decisions, predictions, or recommendations from the data it’s given. That covers most modern applicant tracking systems, resume screeners, and AI-assisted scheduling or performance tools, even if a vendor doesn’t market the product as “AI.”

Does TRAIGA replace federal anti-discrimination law?

No. Title VII, the ADA, and the ADEA still apply to AI-assisted employment decisions in Texas exactly as they did before TRAIGA. TRAIGA adds a state-level, intent-based standard on top of those existing protections, it doesn’t replace them.

What happens if the Texas Attorney General finds a TRAIGA violation?

The AG’s office has to send written notice and give the employer 60 days to fix the issue before pursuing penalties. Curable violations that get fixed in time avoid a civil penalty altogether; violations that go uncorrected or can’t be cured carry penalties ranging from $10,000 up to $200,000, with continuing violations adding daily fines.

Do out-of-state employers with Texas employees have to comply with TRAIGA?

Yes, if they develop or deploy an AI system in Texas, advertise or do business in the state, or offer a product or service used by Texas residents. Physical presence in Texas isn’t required for the law to apply.

Is an employer automatically liable if a third-party AI vendor’s tool causes a problem?

Not automatically. TRAIGA includes a safe harbor for employers hit by third-party misuse of an AI system they didn’t design or control. That protection works best when the employer can show it vetted the vendor and asked reasonable questions about how the tool works, rather than deploying it without any review.

What Texas Employers Should Do Before Their Next AI-Assisted Hiring Decision

TRAIGA gives Texas employers more breathing room than early coverage of the bill suggested, but not being legally required to act isn’t the same as having no risk. The practical move is the same one good HR teams were already doing before TRAIGA existed: know what AI tools are actually running in your hiring process, confirm they aren’t built or used in a way that could look like intentional discrimination, and keep the documentation that proves it. That combination, more than any single form or notice, is what protects an employer if the Texas Attorney General’s office ever comes asking.

The bigger risk usually comes from treating an AI hiring tool like any other software purchase, without asking how it makes decisions or who’s checking its work. TRAIGA gives Texas employers room to move quickly on AI, but that room only works in your favor if you can show, later, that quick didn’t mean careless.

Leave a Reply

Your email address will not be published. Required fields are marked *