Texas Opened Its AI Complaint Portal Early. Here Is What Actually Lands in It.

Executive Summary

  • The Texas Responsible Artificial Intelligence Governance Act required the Texas Attorney General to publish a public AI complaint mechanism no later than September 1, 2026. The office moved ahead of that deadline. The page is already live, and the complaint portal behind it accepts submissions in under 15 minutes.
  • TRAIGA reaches far beyond Texas borders. It applies to any person who promotes, advertises, or conducts business in Texas, or who produces a product or service used by Texas residents, with no revenue floor and no employee count threshold.
  • The prohibitions on private business are narrower than most coverage suggests. Social scoring and biometric identification bans apply only to governmental entities, and the discrimination prohibition requires proven intent because the statute says disparate impact alone is not enough.
  • Penalties run from $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for continuing violations, after a 60 day cure period.
  • The statute names substantial compliance with the NIST AI Risk Management Framework Generative AI Profile as a path to avoiding liability. That defense only works if your documentation exists before the complaint arrives.

1. What September 1, 2026 actually changes

September 1, 2026 is the statutory deadline by which the Texas Attorney General had to publish a public online mechanism for any Texas consumer to file a complaint about an artificial intelligence system, and the office met it early. The requirement comes from Section 8 of House Bill 149, which directs the attorney general, not later than September 1, 2026, to post the information and online mechanism required by Section 552.102 of the Business and Commerce Code.

The Texas Responsible Artificial Intelligence Governance Act, known as TRAIGA, is the Texas AI statute that took effect January 1, 2026. It sets prohibitions on AI use, disclosure duties for government agencies and health care providers, and an enforcement scheme run by the attorney general. Civil penalties reach $200,000 per uncurable violation, and there is no private right of action.

The attorney general did not wait for the deadline. The office has already published a Consumer AI Rights page that walks Texas residents through every prohibition in the statute in plain language, defines the key terms, lists the penalty tiers, and ends with a button labeled File An AI Complaint. That button routes to the Texas Consumer Complaint Portal, which tells the user that submitting online usually takes less than 15 minutes.

That is the shift worth paying attention to, and it is worth being precise about what the date does and does not mean. September 1 is a publication deadline, not a new effective date and not the first day the mechanism works. TRAIGA has been enforceable since January 1, and the complaint channel appears to have gone live before the deadline arrived. What the deadline does is formalize a dedicated public intake route for TRAIGA complaints, sitting on a consumer facing government website next to Learn Your Privacy Rights and Learn Your A.I. Rights.

GOVERNANCE INSIGHT

A complaint channel changes your risk profile even when the law does not change

TRAIGA has been enforceable since January 1, 2026. Nothing about the prohibitions changes on September 1. What changes is the volume and the origin of the signals reaching the attorney general. Regulators act on what lands in the inbox, and a purpose built intake form produces far more inbound than a general consumer complaint category ever did.

2. Does TRAIGA apply to your business?

TRAIGA applies to you if you promote, advertise, or conduct business in Texas, produce a product or service used by Texas residents, or develop or deploy an AI system in Texas. That three part test comes from Section 551.002 and contains no revenue threshold, no employee count minimum, and no small business carve out.

Compare that to Illinois SB 315, which reaches only frontier developers above a large revenue floor. TRAIGA has no such gate. A 12 person agency in Ohio with three Texas clients meets prong two of the test. So does a SaaS product with any meaningful Texas user base.

The definition of an artificial intelligence system is similarly broad. The statute defines it as any machine based system that, for any explicit or implicit objective, infers from the inputs it receives how to generate outputs including content, decisions, predictions, or recommendations that can influence physical or virtual environments. As Norton Rose Fulbright points out in its analysis, that language captures recommendation algorithms, facial recognition, and scoring models, not only generative AI chatbots.

The word consumer is doing a lot of work

There is a limit on the complaint channel that most summaries miss. TRAIGA defines a consumer as an individual who is a resident of Texas acting only in an individual or household context, and expressly excludes an individual acting in a commercial or employment context.

That matters because the single largest category of AI complaint in the country right now is employment screening. A rejected job applicant acting in an employment context generally is not a consumer for purposes of this complaint mechanism, which narrows this particular route considerably.

Do not over read that limit. It constrains one intake channel, not your overall exposure. The attorney general can still learn about an AI hiring system from another source, and the substantive prohibition on intentional discrimination in Section 552.056 is not written to apply only to conduct reported by consumers. Federal law and other states remain fully in play. Our guide to Colorado’s employer AI obligations covers where much of that exposure actually lives.

3. What TRAIGA actually prohibits, and what it does not

TRAIGA contains six prohibitions, and only four of them apply to private businesses at all. Two of the most widely reported bans, social scoring and biometric identification, apply exclusively to governmental entities. Reading the statute carefully changes the compliance picture substantially for a small or medium sized business.

Section 552.052 bars any person from developing or deploying an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self harm, harm another person, or engage in criminal activity. Section 552.055 bars any person from deploying an AI system with the sole intent to infringe, restrict, or impair rights guaranteed under the United States Constitution. Section 552.057 bars AI systems built to produce child sexual abuse material, unlawful deep fake imagery, or text based sexual conversations impersonating minors.

Section 552.056 is the one that matters most for ordinary commercial operations. It prohibits developing or deploying an AI system with the intent to unlawfully discriminate against a protected class. The next sentence of the statute is the one to internalize: a disparate impact is not sufficient by itself to demonstrate an intent to discriminate.

That is a materially different standard from the risk based frameworks in Colorado and the European Union. Norton Rose Fulbright reads it the same way, noting that evidence of disparate impact is not enough to demonstrate intent. Section 552.056 also exempts insurance entities regulated under unfair discrimination statutes, and treats a federally insured financial institution as compliant if it follows applicable federal and state banking law.

Sections 552.053 and 552.054, covering social scoring and biometric identification of individuals, are written to apply to governmental entities. A private company that runs a customer scoring model or a face matching feature is not reached by those two sections of TRAIGA. Private sector biometric use in Texas continues to be governed separately under Chapter 503 of the Business and Commerce Code.

4. The two disclosure duties, and which one reaches private business

TRAIGA creates one general AI disclosure duty that binds only governmental agencies and one sector specific duty that binds health care providers whether public or private. Both live inside Section 552.051. There is no general obligation for an ordinary private business to tell a customer that they are talking to a chatbot.

Section 552.051(b) requires a governmental agency that makes an AI system available to interact with consumers to disclose, before or at the time of interaction, that the consumer is interacting with an AI system. Subsection (c) adds that the disclosure is required even where it would be obvious to a reasonable consumer, and subsection (d) requires it to be clear, conspicuous, in plain language, and free of dark patterns. The definition of governmental entity excludes some hospital districts and institutions of higher education.

Section 552.051(f) is the subsection that reaches private practices. Where an AI system is used in relation to a health care service or treatment, the provider of that service or treatment must give the subsection (b) disclosure to the recipient or the recipient’s personal representative no later than the date the service or treatment is first provided. In an emergency, the disclosure must follow as soon as reasonably possible.

The statute defines health care services as services related to human health, or to the diagnosis, prevention, or treatment of human disease or impairment, provided by an individual licensed, registered, or certified under applicable law. Spencer Fane flags the practical ambiguity here, noting the statute gives no detailed guidance on what counts as using an AI system in relation to a health care service or treatment. A practice running an ambient scribe, an intake triage tool, or an AI assisted imaging read should assess whether that tool is used in relation to a service or treatment rather than assume either answer. No rules or enforcement actions have defined the phrase yet, so where the connection to care is material, disclosing is the more defensible call. Our analysis of patient intake chatbot compliance covers how that intersects with HIPAA obligations.

GOVERNANCE INSIGHT

Texas health care practices carry a disclosure duty that most other Texas businesses do not

If you run a licensed clinical practice in Texas and AI is used in relation to diagnosis, prevention, or treatment, Section 552.051(f) puts a disclosure duty on you at or before first service. If you run almost any other kind of Texas business, TRAIGA imposes no equivalent duty. Do not let generic AI disclosure advice push you into obligations the statute never created, and do not let it obscure the one that genuinely applies.

5. What happens after a consumer files a complaint

A TRAIGA complaint routes to the attorney general, who holds exclusive enforcement authority under Section 552.101 and may respond by issuing a civil investigative demand before any lawsuit exists. That is the mechanism a small business needs to understand, because the investigative burden arrives long before any finding of liability.

Section 552.103 lets the attorney general demand documentation covering the purpose and intended use of the system, the types of data used to train it, descriptions of its inputs and outputs, performance metrics, known limitations, and post deployment monitoring. Read that list again as an operator rather than a lawyer. Every item on it is documentation, not a technical control. If your organization cannot produce those artifacts on request, the response cost alone is significant regardless of the merits.

If the attorney general determines a violation has occurred, Section 552.104 requires written notice identifying the specific provisions alleged to have been violated. The attorney general may not bring an action before the 60th day after that notice, and may not bring an action at all if the person cures the identified violation within that window and provides the required written statement.

That 60 day cure period is genuinely protective, and it is the reason documentation matters more than perfection. A business that can demonstrate what a system does, show it reviewed the system, and correct a defect inside 60 days is in a fundamentally different position from one that receives the notice and starts building a governance program from zero.

6. What a TRAIGA violation costs

TRAIGA civil penalties run in three tiers under Section 552.105, ranging from $10,000 for a curable violation to $200,000 for an uncurable one, with continuing violations accruing up to $40,000 per day. The attorney general may also seek injunctive relief, attorney’s fees, court costs, and investigative expenses.

Violation type Civil penalty range What triggers this tier
Curable violation $10,000 to $12,000 A violation the court determines can be cured, or a breach of a written statement submitted to the attorney general during the cure process
Uncurable violation $80,000 to $200,000 A violation the court determines cannot be cured
Continued violation $2,000 to $40,000 per day Each day the violation continues after the cure window closes

The gap between the curable tier and the uncurable tier is roughly sixteen fold at the low end. Nothing in the statute defines in advance which category a given violation falls into, so that determination is made by a court after the fact. TRAIGA is new enough that there is no enforcement precedent to look to, and the classification will likely turn on the facts, the nature of the conduct, and how feasible remediation was. That uncertainty is itself a reason to write design decisions down while they are being made, because a contemporaneous record of what you intended is the evidence most likely to matter.

7. The affirmative defenses, and why NIST is named in the statute

TRAIGA gives defendants a set of paths to avoid liability entirely, and one of them is substantial compliance with a recognized AI risk management framework. Section 552.105(e) states that a defendant may not be found liable if another person used the affiliated AI system in a prohibited manner, or if the defendant discovered the violation through one of several routes.

Those routes are worth listing precisely. They are feedback from a developer, deployer, or other person who believes a violation occurred; testing, including adversarial or red team testing; following guidelines set by applicable state agencies; or an internal review process where the defendant substantially complies with the most recent version of the Artificial Intelligence Risk Management Framework Generative Artificial Intelligence Profile published by the National Institute of Standards and Technology, or another nationally or internationally recognized AI risk management framework.

The named document is NIST AI 600-1, published July 26, 2024. Texas wrote a specific federal framework into the text of a state liability shield. That is unusual, and it is a strong signal about what the attorney general expects a defensible AI program to look like.

Here is the operational point. A framework based defense is only as strong as the record behind it. It will hold up where you can show the review process existed before the alleged violation, actually ran, and generated records of risk assessment, testing, monitoring, and remediation. You cannot adopt the NIST AI RMF in week three of an investigation and claim substantial compliance for a system you deployed last year. The same logic applies to red team testing, which only helps if the test happened and the results were recorded and acted on.

The statute also extends the defense to another nationally or internationally recognized AI risk management framework. An ISO/IEC 42001 aligned management system is a credible candidate, though the statute does not name it and whether a given implementation demonstrates substantial compliance would be decided on the facts. Treat it as support for the defense rather than an automatic substitute for the NIST profile. For businesses already pursuing certification for enterprise procurement reasons, that work does double duty.

Getting your AI governance in order

Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.

Start the free AI maturity self assessment

8. How TRAIGA compares to Colorado, Illinois, and California

TRAIGA is the most business friendly of the four major state AI regimes because it requires proven intent rather than risk management outcomes, but it is also the only one with a live consumer complaint portal built into the statute. The four states have taken meaningfully different approaches, and a business operating nationally needs to hold all four in view.

State law Key date Liability standard Who it reaches
Texas TRAIGA (HB 149) Effective January 1, 2026. Complaint mechanism due September 1, 2026 Intent required. Disparate impact alone is expressly insufficient Any person doing business in Texas or serving Texas residents. No size threshold
Colorado SB 26-189 Effective January 1, 2027. AG rules due by January 1, 2027 Risk and process based, with duties around consequential decisions Developers and deployers of covered systems, including out of state employers
Illinois SB 315 Signed July 6, 2026. Obligations begin January 1, 2028 Safety framework publication and annual independent third party audits Large frontier developers only, above $500 million in annual revenue and a 10^26 FLOP training threshold
California AI Transparency Act (SB 942, amended by AB 853) Covered provider duties operative August 2, 2026. Platform duties January 1, 2027. Capture devices January 1, 2028 Provenance, disclosure, and free detection tooling Covered generative AI providers above one million monthly users, plus large online platforms, hosting platforms, and later capture device manufacturers

Colorado is the most instructive contrast because its rulemaking is happening right now. The Colorado Attorney General filed proposed draft rules with the Secretary of State on August 11, 2026, opening a formal comment period that runs until October 26, 2026, ahead of the January 1, 2027 effective date. Colorado is building a regulatory apparatus. Texas built a complaint form. Both produce enforcement risk, on different timelines and through different doors.

The California row deserves one clarification, because it is widely misread. The AI Transparency Act does not put a disclosure duty on every business that publishes AI generated content. As Morgan Lewis lays out, it reaches covered generative AI providers above one million monthly users starting August 2, 2026, then large online platforms and hosting platforms on January 1, 2027, then capture device manufacturers on January 1, 2028. If you are a small business using someone else’s generative AI tool, you are on the consuming side of that regime, not the regulated side. Our breakdown of the California AI disclosure regime covers what that means downstream.

9. The sandbox and the Texas AI Council

TRAIGA created a regulatory sandbox that lets approved participants test an AI system for up to 36 months with specified legal requirements waived, and a seven member Texas Artificial Intelligence Council that explicitly cannot issue binding rules. Both are relevant to how enforcement will actually develop.

The sandbox is administered by the Texas Department of Information Resources in consultation with the council. During the testing period, the attorney general may not file or pursue charges against a participant for violation of a law or regulation that was waived under the program. Read that protection narrowly. It attaches to the requirements actually waived in the participant’s approval terms, not to everything the company does for 36 months, and it does not extend to laws outside the waiver. For a company building something genuinely novel with regulatory uncertainty attached it is still a meaningful asset, but the value depends entirely on what the approval covers.

The council is composed of seven members serving staggered four year terms, with three appointed by the governor, two by the lieutenant governor, and two by the speaker of the house. Its authority is deliberately constrained. The statute says the council may not adopt rules or promulgate guidance that is binding on any entity, may not interfere with or override the operation of a state agency, and may not exercise powers the chapter does not grant.

That constraint has a practical consequence. Unlike Colorado, where a formal rulemaking will produce detailed compliance guidance before enforcement begins, Texas has no binding rulemaking body standing behind TRAIGA. Absent binding council rules, the statute’s practical meaning is likely to emerge through attorney general guidance and advisory materials, investigations and enforcement actions, and eventually court decisions. There is no rule book coming to tell you what using an AI system in relation to a health care service means. That ambiguity resolves case by case.

10. Your 30 day plan before the complaints start

The highest value work in the next 30 days is documentation, not remediation, because every affirmative defense in TRAIGA depends on records that must already exist when a complaint arrives. Adoption is running well ahead of governance. The U.S. Chamber of Commerce Empowering Small Business report found 58 percent of small businesses using generative AI, up from 40 percent in 2024 and 23 percent in 2023. Very few of those businesses can produce a system inventory.

Start with an inventory. List every AI system your organization develops or deploys that touches a Texas resident, including embedded features your vendors switched on inside tools you already licensed. For each one, capture the purpose, the categories of training or input data, a plain description of outputs, known limitations, and who owns it internally. That list maps directly onto the civil investigative demand categories in Section 552.103.

Second, confirm your actual exposure rather than the exposure in the headlines. Determine whether you are a health care provider subject to the Section 552.051(f) disclosure duty, whether any of your systems could plausibly be characterized as intentionally discriminating against a protected class, and whether your Texas facing activity is consumer directed or employment and commercial. Most businesses will find their real TRAIGA surface is smaller than they feared and their documentation gap is larger.

Third, stand up the internal review process the statute rewards. Adopt the NIST AI RMF Generative AI Profile or an ISO/IEC 42001 aligned management system, run at least one documented review of your highest risk system, record what you tested and what you found, and set a recurring cadence. The defense in Section 552.105(e) is available only to organizations that can show the process ran.

Fourth, write down your escalation path. Decide now who receives a civil investigative demand, who assembles the documentation, who has authority to implement a cure, and what your 60 day clock looks like operationally. The cure period is the most valuable protection in the statute and it is the easiest to squander.

Talk to Ross about your AI governance needs

Every business has different AI governance requirements. Let us talk about yours.

Contact Dynamic Comply

Frequently Asked Questions

Does TRAIGA apply to my business if I am not located in Texas?

Yes, if you promote, advertise, or conduct business in Texas, or produce a product or service used by Texas residents. Section 551.002 sets that three part test with no revenue floor and no employee count threshold, so a small out of state company with Texas customers is covered the same way a Texas company is.

What can a consumer actually complain about under TRAIGA?

A consumer can complain about any of the statute’s prohibitions, but only as a consumer, which TRAIGA defines as a Texas resident acting in an individual or household context. Individuals acting in a commercial or employment context are expressly excluded, so a rejected job applicant does not have a TRAIGA consumer complaint.

What are the penalties for violating TRAIGA?

Civil penalties are $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 for each day a violation continues. The attorney general may also seek injunctive relief, attorney’s fees, court costs, and investigative expenses. There is a 60 day cure period after written notice.

Does TRAIGA require me to tell customers they are talking to AI?

Only if you are a governmental agency or a health care provider. Section 552.051(b) places the general disclosure duty on governmental agencies, and Section 552.051(f) requires providers of health care services or treatment to disclose AI use to the patient no later than the date service is first provided. Ordinary private businesses have no general AI disclosure duty under TRAIGA.

How is TRAIGA different from the Colorado AI law?

TRAIGA requires proven intent and states that disparate impact alone is not sufficient to demonstrate intent to discriminate, while Colorado SB 26-189 imposes risk and process based duties around consequential decisions. TRAIGA has been effective since January 1, 2026, while Colorado takes effect January 1, 2027 with attorney general rules due by that date.

What should a small business do before the complaint portal opens?

Build an AI system inventory that captures purpose, input data categories, outputs, known limitations, and owner for each system, because those are the exact categories the attorney general can demand under Section 552.103. Then stand up a documented internal review process aligned to the NIST AI RMF Generative AI Profile, which Section 552.105(e) names as a route to avoiding liability.

About the author

Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.

This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *