Feature AI Risk
Texas's TRAIGA Has Been in Effect for Eight Months. If Your AI Touches Financial Decisions for Texas Residents, Here's What's Actually Required.
The Texas Responsible AI Governance Act (TRAIGA) took effect January 1, 2026. The final law is narrower than feared — but financial services firms using AI in credit, insurance, or banking decisions have real obligations. Here's what they are.
Table of Contents
TL;DR
- TRAIGA (Texas Responsible AI Governance Act, HB 149) took effect January 1, 2026 and applies to any company deploying AI that affects Texas residents, including financial services decisions.
- The final law is an intent-based liability framework — narrower than the original bill, but with real teeth for financial institutions using AI in credit, insurance, or banking decisions.
- The safe harbor is explicit: substantial compliance with the NIST AI Risk Management Framework is an affirmative defense. Documented AI governance that maps to NIST AI RMF protects you.
- Colorado’s SB 26-189 takes effect January 1, 2027, creating a different and more prescriptive framework. Firms in both states need both compliance programs running.
Eight Months In, and Most Financial Services Firms Haven’t Caught Up
When Governor Greg Abbott signed HB 149 — the Texas Responsible Artificial Intelligence Governance Act — into law on June 22, 2025, the initial reaction was relief. The final bill was significantly narrower than the original version, which had proposed mandatory risk assessments, annual impact assessments, and reporting obligations to the Attorney General.
The pared-back version passed. The headlines moved on. And a lot of financial services firms concluded that TRAIGA wasn’t really their problem.
That was the wrong read.
TRAIGA took effect January 1, 2026. If you’re a fintech, bank, insurer, or lender with AI systems that make or substantially factor into financial decisions affecting Texas residents — credit underwriting, insurance pricing, account eligibility, fraud decisioning — you have been subject to TRAIGA for eight months. The AG’s office has signaled enforcement interest. The 60-day cure period only applies if you’re notified before an action is filed, not after.
The question isn’t whether TRAIGA applies. It’s whether your AI governance program gives you the documentation to invoke the safe harbor when it matters.
Why Financial Services Firms Are Squarely in Scope
TRAIGA applies to two categories of actors: deployers (companies that use AI systems in products or services provided to consumers) and developers (companies that create AI systems). Financial institutions are deployers.
The trigger is straightforward: an AI system is high-risk under TRAIGA if it makes or is a substantial factor in consequential decisions affecting any of the following sectors: employment, education, healthcare, housing, insurance, financial services, and government services.
For financial services, that language captures a lot of ground:
- Credit underwriting models — any ML model that scores applications for personal loans, auto loans, credit cards, or BNPL products affecting Texas consumers
- Fraud detection and account decisioning — models that automatically freeze accounts, decline transactions, or flag activity for adverse action
- Insurance pricing algorithms — pricing or underwriting models for auto, home, or life insurance policies sold in Texas
- Customer service AI — chatbots that determine whether to escalate a dispute, approve a claim, or provide a specific product recommendation
The “substantial factor” language is important. It closes the gap between a fully automated decision and a “human reviews the model output” setup where the human consistently approves. If the AI output is a substantial input to the final decision, you’re in scope regardless of how many humans are in the loop.
What the Final TRAIGA Actually Requires — and What Was Cut
The original version of the Texas AI bill would have required mandatory algorithmic impact assessments, annual attestations to the Attorney General, and specific disclosures modeled on EU AI Act requirements. Industry pushed back hard on the implementation burden, particularly for the assessment and reporting requirements.
The final law that passed is significantly more targeted. What TRAIGA actually requires:
What it prohibits (the intent-based framework): TRAIGA prohibits the development or deployment of AI systems that are intentionally aimed at:
- Deceiving consumers about the nature of AI output
- Facilitating illegal discrimination
- Inciting or encouraging self-harm or criminal activity
“Intentionally” is the operative word. The Texas AG must establish that the prohibited outcome was the design goal of the AI system — not merely that it produced discriminatory outputs through model error or data bias. This is a meaningful limitation on enforcement scope compared to states that use disparate-impact standards.
What it requires for high-risk deployers:
- Consumer notice: consumers must be informed when high-risk AI is used to make consequential decisions
- Documentation: deployers must maintain documentation sufficient to demonstrate non-prohibited design intent
- Governance program: deployers of high-risk AI must implement an AI governance program with ongoing oversight
The safe harbor: TRAIGA provides an explicit affirmative defense for companies that substantially comply with the most recent NIST AI Risk Management Framework (including the Generative AI Profile). This safe harbor is the most important structural feature of TRAIGA for financial services compliance programs.
The Three Documentation Priorities TRAIGA Creates
1. AI Systems Inventory with Texas-Consumer Scope
You need to know which AI systems make or substantially factor into decisions affecting Texas residents. This isn’t a legal abstraction — it’s an operational question.
For a national lender, every credit model is potentially in scope. For a regional bank, TRAIGA applies to the subset of your AI decisions that touch Texas-based borrowers or customers. For an insurtech writing policies in 50 states, Texas is one of those states.
The inventory should capture, at a minimum:
- Model name and use case
- Whether it makes or substantially factors into consequential financial decisions
- Whether those decisions affect Texas residents (yes/no/partial)
- The human oversight process in the decision workflow
- Last review date
This is the same inventory structure that NIST AI RMF, the Treasury FS AI RMF, and the OCC’s 2026 model risk guidance require. TRAIGA adds the geographic scope filter.
2. Design Documentation Showing Non-Prohibited Intent
Under TRAIGA’s intent-based liability framework, contemporaneous design documentation is your primary evidence that an AI system wasn’t designed to deceive, discriminate, or cause harm.
“Contemporaneous” is key. If a model was deployed 18 months ago and your design documentation consists of a Confluence note from the ML engineer who built it, that’s not the evidence package that survives enforcement scrutiny.
The documentation should address:
- Intended use case and decision scope
- Training data sourcing and bias review conducted pre-deployment
- Known limitations and mitigations implemented
- Monitoring in place for drift and discriminatory output
- Who reviewed and approved the model before deployment
This isn’t new work if you have a model risk management program that covers pre-deployment review. It’s existing documentation that you need to organize and maintain against the specific models in TRAIGA scope.
3. Governance Program Records
TRAIGA requires that deployers of high-risk AI implement a governance program with ongoing oversight. The law doesn’t specify what the governance program must contain — but the NIST AI RMF safe harbor tells you exactly what “substantial compliance” looks like.
The four NIST AI RMF functions — GOVERN, MAP, MEASURE, MANAGE — provide the structure. A TRAIGA-compliant governance program for financial services should document:
- GOVERN: Who is responsible for AI risk decisions? What oversight committee reviews high-risk models?
- MAP: Which AI systems are in scope for TRAIGA? What’s their risk classification?
- MEASURE: How do you detect bias, drift, or unintended outputs in high-risk models?
- MANAGE: When a model produces an adverse outcome, what’s the escalation and remediation process?
The governance program records are also what you hand to the Texas AG if you get a notice letter. Having organized documentation of your AI governance framework — with records of model reviews, bias assessments, and oversight decisions — is what converts a potential enforcement action into a curable compliance gap.
TRAIGA vs. Colorado SB 26-189: Two Laws, Two Different Frameworks
If you’re reading this and thinking, “I just got through building a compliance program for Colorado’s AI law” — you need to verify that your Colorado program actually addresses TRAIGA’s different requirements. The laws are not interchangeable.
Colorado SB 26-189 (effective January 1, 2027):
- Requires post-adverse-outcome notices within 30 days in plain language
- Requires meaningful human review upon request (to the extent commercially reasonable)
- Requires three-year record retention
- Eliminated the financial institution exemption that existed in the prior Colorado law
- Colorado AG establishes sector-specific guidance (expected by January 1, 2027)
Texas TRAIGA (effective January 1, 2026):
- Intent-based liability framework — focus is on design intent, not adverse outcomes
- NIST AI RMF compliance is a complete affirmative defense
- Documentation of non-prohibited design intent is the primary compliance artifact
- No mandatory adverse-action notice process (unlike Colorado)
- 60-day cure period before civil enforcement
Texas is about what your AI was designed to do. Colorado is about what happens to consumers when your AI makes an adverse decision. Both matter if you operate in both states.
The state AI laws tracker for financial services provides the current status of all enacted state AI requirements — a useful reference for programs managing multi-state AI compliance obligations.
The Enforcement Signal to Watch
The Texas AG’s office has not publicly filed a TRAIGA enforcement action against a financial institution as of September 2026. The 60-day cure period is a meaningful buffer — most TRAIGA violations that are identified through normal compliance operations can be remediated before an action is filed.
But the enforcement signal to watch isn’t the AG’s complaint docket. It’s the examination process.
The OCC, FDIC, and state banking regulators have started incorporating TRAIGA compliance questions into examinations of Texas-chartered or Texas-operating institutions. The question isn’t “show me your TRAIGA filing.” It’s “walk me through your AI governance program for models in scope for Texas’s AI law.”
If the answer is “we have an AI use case inventory that covers our models, a pre-deployment review process, and a governance committee that reviews high-risk models quarterly” — you’re in good shape. If the answer is “we checked the TRAIGA website and didn’t think it applied to us” — that’s an MRA waiting to happen.
The Compliance Playbook for September 2026
Here’s where to focus your program effort in the time between now and the end of 2026:
By October 2026: Complete your AI systems inventory with TRAIGA scope flags. Every model that makes or substantially factors into financial decisions affecting Texas residents needs to be in the inventory with a documented assessment of TRAIGA applicability.
By November 2026: Conduct pre-deployment documentation review for any models deployed without contemporaneous design documentation. If your existing models lack bias review records, approval evidence, or use case documentation, produce them now before you’re under exam or facing a notice letter.
By December 2026: Run your AI governance program against the NIST AI RMF GOVERN function. Do you have assigned AI risk owners? An oversight committee? A monitoring process? These are the TRAIGA safe harbor elements you need to document before Colorado SB 26-189 takes effect on January 1, 2027.
January 2027: Dual compliance deadline. Colorado SB 26-189 goes live, adding the adverse-action notice requirement and meaningful human review obligation. By this point, you want both the TRAIGA documentation program (Texas) and the consumer-facing notice and human review process (Colorado) operational.
So What? The Practical Upshot for AI Governance Teams
TRAIGA is a lighter law than its original drafters intended. But “lighter” doesn’t mean “not applicable” — and for financial services firms using AI to make or substantially factor into credit, insurance, and banking decisions affecting Texas residents, it creates real compliance obligations that most programs haven’t formally addressed.
The good news: if you have an AI governance program that’s aligned with the NIST AI RMF — documented inventory, pre-deployment review, bias assessment, governance oversight — you have most of what TRAIGA’s safe harbor requires. The gap is usually documentation quality and completeness, not substantive program redesign.
The EU AI Act enforcement wave that started in August 2026 gave financial services firms operating in Europe a similar wake-up call: regulators are now asking to see the documentation, not just hear the verbal description of your AI governance program.
TRAIGA will get there. The question is whether your documentation is ready when the Texas AG’s office — or your bank examiner — asks for it.
For financial services AI governance programs that need a head start — AI use case inventory, pre-deployment risk assessment scorecard, bias evaluation tools, and a 30-day rollout plan — the AI Risk Assessment Template & Guide is built specifically for regulated financial institutions navigating NIST AI RMF, TRAIGA, Colorado SB 26-189, and the 2026 OCC model risk guidance simultaneously.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does TRAIGA apply to my fintech if we're not based in Texas?
What makes an AI system 'high-risk' under TRAIGA?
What does TRAIGA actually prohibit? Is it a list of banned practices?
Is there a safe harbor for TRAIGA compliance?
What penalties does TRAIGA impose?
How does TRAIGA compare to Colorado's SB 26-189 that takes effect January 2027?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.
The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.
Sep 12, 2026
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026