Skip to content
RiskTemplates · The Daily Brief Tuesday, September 15, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature AI Risk

Texas's TRAIGA Has Been in Effect for Eight Months. If Your AI Touches Financial Decisions for Texas Residents, Here's What's Actually Required.

The Texas Responsible AI Governance Act (TRAIGA) took effect January 1, 2026. The final law is narrower than feared — but financial services firms using AI in credit, insurance, or banking decisions have real obligations. Here's what they are.

By Rebecca Leung · September 11, 2026 ·
Table of Contents

TL;DR

  • TRAIGA (Texas Responsible AI Governance Act, HB 149) took effect January 1, 2026 and applies to any company deploying AI that affects Texas residents, including financial services decisions.
  • The final law is an intent-based liability framework — narrower than the original bill, but with real teeth for financial institutions using AI in credit, insurance, or banking decisions.
  • The safe harbor is explicit: substantial compliance with the NIST AI Risk Management Framework is an affirmative defense. Documented AI governance that maps to NIST AI RMF protects you.
  • Colorado’s SB 26-189 takes effect January 1, 2027, creating a different and more prescriptive framework. Firms in both states need both compliance programs running.

Eight Months In, and Most Financial Services Firms Haven’t Caught Up

When Governor Greg Abbott signed HB 149 — the Texas Responsible Artificial Intelligence Governance Act — into law on June 22, 2025, the initial reaction was relief. The final bill was significantly narrower than the original version, which had proposed mandatory risk assessments, annual impact assessments, and reporting obligations to the Attorney General.

The pared-back version passed. The headlines moved on. And a lot of financial services firms concluded that TRAIGA wasn’t really their problem.

That was the wrong read.

TRAIGA took effect January 1, 2026. If you’re a fintech, bank, insurer, or lender with AI systems that make or substantially factor into financial decisions affecting Texas residents — credit underwriting, insurance pricing, account eligibility, fraud decisioning — you have been subject to TRAIGA for eight months. The AG’s office has signaled enforcement interest. The 60-day cure period only applies if you’re notified before an action is filed, not after.

The question isn’t whether TRAIGA applies. It’s whether your AI governance program gives you the documentation to invoke the safe harbor when it matters.


Why Financial Services Firms Are Squarely in Scope

TRAIGA applies to two categories of actors: deployers (companies that use AI systems in products or services provided to consumers) and developers (companies that create AI systems). Financial institutions are deployers.

The trigger is straightforward: an AI system is high-risk under TRAIGA if it makes or is a substantial factor in consequential decisions affecting any of the following sectors: employment, education, healthcare, housing, insurance, financial services, and government services.

For financial services, that language captures a lot of ground:

  • Credit underwriting models — any ML model that scores applications for personal loans, auto loans, credit cards, or BNPL products affecting Texas consumers
  • Fraud detection and account decisioning — models that automatically freeze accounts, decline transactions, or flag activity for adverse action
  • Insurance pricing algorithms — pricing or underwriting models for auto, home, or life insurance policies sold in Texas
  • Customer service AI — chatbots that determine whether to escalate a dispute, approve a claim, or provide a specific product recommendation

The “substantial factor” language is important. It closes the gap between a fully automated decision and a “human reviews the model output” setup where the human consistently approves. If the AI output is a substantial input to the final decision, you’re in scope regardless of how many humans are in the loop.


What the Final TRAIGA Actually Requires — and What Was Cut

The original version of the Texas AI bill would have required mandatory algorithmic impact assessments, annual attestations to the Attorney General, and specific disclosures modeled on EU AI Act requirements. Industry pushed back hard on the implementation burden, particularly for the assessment and reporting requirements.

The final law that passed is significantly more targeted. What TRAIGA actually requires:

What it prohibits (the intent-based framework): TRAIGA prohibits the development or deployment of AI systems that are intentionally aimed at:

  1. Deceiving consumers about the nature of AI output
  2. Facilitating illegal discrimination
  3. Inciting or encouraging self-harm or criminal activity

“Intentionally” is the operative word. The Texas AG must establish that the prohibited outcome was the design goal of the AI system — not merely that it produced discriminatory outputs through model error or data bias. This is a meaningful limitation on enforcement scope compared to states that use disparate-impact standards.

What it requires for high-risk deployers:

  • Consumer notice: consumers must be informed when high-risk AI is used to make consequential decisions
  • Documentation: deployers must maintain documentation sufficient to demonstrate non-prohibited design intent
  • Governance program: deployers of high-risk AI must implement an AI governance program with ongoing oversight

The safe harbor: TRAIGA provides an explicit affirmative defense for companies that substantially comply with the most recent NIST AI Risk Management Framework (including the Generative AI Profile). This safe harbor is the most important structural feature of TRAIGA for financial services compliance programs.


The Three Documentation Priorities TRAIGA Creates

1. AI Systems Inventory with Texas-Consumer Scope

You need to know which AI systems make or substantially factor into decisions affecting Texas residents. This isn’t a legal abstraction — it’s an operational question.

For a national lender, every credit model is potentially in scope. For a regional bank, TRAIGA applies to the subset of your AI decisions that touch Texas-based borrowers or customers. For an insurtech writing policies in 50 states, Texas is one of those states.

The inventory should capture, at a minimum:

  • Model name and use case
  • Whether it makes or substantially factors into consequential financial decisions
  • Whether those decisions affect Texas residents (yes/no/partial)
  • The human oversight process in the decision workflow
  • Last review date

This is the same inventory structure that NIST AI RMF, the Treasury FS AI RMF, and the OCC’s 2026 model risk guidance require. TRAIGA adds the geographic scope filter.

2. Design Documentation Showing Non-Prohibited Intent

Under TRAIGA’s intent-based liability framework, contemporaneous design documentation is your primary evidence that an AI system wasn’t designed to deceive, discriminate, or cause harm.

“Contemporaneous” is key. If a model was deployed 18 months ago and your design documentation consists of a Confluence note from the ML engineer who built it, that’s not the evidence package that survives enforcement scrutiny.

The documentation should address:

  • Intended use case and decision scope
  • Training data sourcing and bias review conducted pre-deployment
  • Known limitations and mitigations implemented
  • Monitoring in place for drift and discriminatory output
  • Who reviewed and approved the model before deployment

This isn’t new work if you have a model risk management program that covers pre-deployment review. It’s existing documentation that you need to organize and maintain against the specific models in TRAIGA scope.

3. Governance Program Records

TRAIGA requires that deployers of high-risk AI implement a governance program with ongoing oversight. The law doesn’t specify what the governance program must contain — but the NIST AI RMF safe harbor tells you exactly what “substantial compliance” looks like.

The four NIST AI RMF functions — GOVERN, MAP, MEASURE, MANAGE — provide the structure. A TRAIGA-compliant governance program for financial services should document:

  • GOVERN: Who is responsible for AI risk decisions? What oversight committee reviews high-risk models?
  • MAP: Which AI systems are in scope for TRAIGA? What’s their risk classification?
  • MEASURE: How do you detect bias, drift, or unintended outputs in high-risk models?
  • MANAGE: When a model produces an adverse outcome, what’s the escalation and remediation process?

The governance program records are also what you hand to the Texas AG if you get a notice letter. Having organized documentation of your AI governance framework — with records of model reviews, bias assessments, and oversight decisions — is what converts a potential enforcement action into a curable compliance gap.


TRAIGA vs. Colorado SB 26-189: Two Laws, Two Different Frameworks

If you’re reading this and thinking, “I just got through building a compliance program for Colorado’s AI law” — you need to verify that your Colorado program actually addresses TRAIGA’s different requirements. The laws are not interchangeable.

Colorado SB 26-189 (effective January 1, 2027):

  • Requires post-adverse-outcome notices within 30 days in plain language
  • Requires meaningful human review upon request (to the extent commercially reasonable)
  • Requires three-year record retention
  • Eliminated the financial institution exemption that existed in the prior Colorado law
  • Colorado AG establishes sector-specific guidance (expected by January 1, 2027)

Texas TRAIGA (effective January 1, 2026):

  • Intent-based liability framework — focus is on design intent, not adverse outcomes
  • NIST AI RMF compliance is a complete affirmative defense
  • Documentation of non-prohibited design intent is the primary compliance artifact
  • No mandatory adverse-action notice process (unlike Colorado)
  • 60-day cure period before civil enforcement

Texas is about what your AI was designed to do. Colorado is about what happens to consumers when your AI makes an adverse decision. Both matter if you operate in both states.

The state AI laws tracker for financial services provides the current status of all enacted state AI requirements — a useful reference for programs managing multi-state AI compliance obligations.


The Enforcement Signal to Watch

The Texas AG’s office has not publicly filed a TRAIGA enforcement action against a financial institution as of September 2026. The 60-day cure period is a meaningful buffer — most TRAIGA violations that are identified through normal compliance operations can be remediated before an action is filed.

But the enforcement signal to watch isn’t the AG’s complaint docket. It’s the examination process.

The OCC, FDIC, and state banking regulators have started incorporating TRAIGA compliance questions into examinations of Texas-chartered or Texas-operating institutions. The question isn’t “show me your TRAIGA filing.” It’s “walk me through your AI governance program for models in scope for Texas’s AI law.”

If the answer is “we have an AI use case inventory that covers our models, a pre-deployment review process, and a governance committee that reviews high-risk models quarterly” — you’re in good shape. If the answer is “we checked the TRAIGA website and didn’t think it applied to us” — that’s an MRA waiting to happen.


The Compliance Playbook for September 2026

Here’s where to focus your program effort in the time between now and the end of 2026:

By October 2026: Complete your AI systems inventory with TRAIGA scope flags. Every model that makes or substantially factors into financial decisions affecting Texas residents needs to be in the inventory with a documented assessment of TRAIGA applicability.

By November 2026: Conduct pre-deployment documentation review for any models deployed without contemporaneous design documentation. If your existing models lack bias review records, approval evidence, or use case documentation, produce them now before you’re under exam or facing a notice letter.

By December 2026: Run your AI governance program against the NIST AI RMF GOVERN function. Do you have assigned AI risk owners? An oversight committee? A monitoring process? These are the TRAIGA safe harbor elements you need to document before Colorado SB 26-189 takes effect on January 1, 2027.

January 2027: Dual compliance deadline. Colorado SB 26-189 goes live, adding the adverse-action notice requirement and meaningful human review obligation. By this point, you want both the TRAIGA documentation program (Texas) and the consumer-facing notice and human review process (Colorado) operational.


So What? The Practical Upshot for AI Governance Teams

TRAIGA is a lighter law than its original drafters intended. But “lighter” doesn’t mean “not applicable” — and for financial services firms using AI to make or substantially factor into credit, insurance, and banking decisions affecting Texas residents, it creates real compliance obligations that most programs haven’t formally addressed.

The good news: if you have an AI governance program that’s aligned with the NIST AI RMF — documented inventory, pre-deployment review, bias assessment, governance oversight — you have most of what TRAIGA’s safe harbor requires. The gap is usually documentation quality and completeness, not substantive program redesign.

The EU AI Act enforcement wave that started in August 2026 gave financial services firms operating in Europe a similar wake-up call: regulators are now asking to see the documentation, not just hear the verbal description of your AI governance program.

TRAIGA will get there. The question is whether your documentation is ready when the Texas AG’s office — or your bank examiner — asks for it.


For financial services AI governance programs that need a head start — AI use case inventory, pre-deployment risk assessment scorecard, bias evaluation tools, and a 30-day rollout plan — the AI Risk Assessment Template & Guide is built specifically for regulated financial institutions navigating NIST AI RMF, TRAIGA, Colorado SB 26-189, and the 2026 OCC model risk guidance simultaneously.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does TRAIGA apply to my fintech if we're not based in Texas?
Yes. TRAIGA applies to any company that conducts business in Texas, produces products used by Texas residents, or deploys AI systems within the state. Geographic presence isn't the trigger — reach into Texas consumers is. If your credit model, underwriting system, or customer-facing AI makes decisions affecting Texas residents, you're covered.
What makes an AI system 'high-risk' under TRAIGA?
Under TRAIGA, an AI system is high-risk if it makes or is a substantial factor in consequential decisions affecting employment, education, healthcare, housing, insurance, financial services, or government services. For financial institutions, this covers credit underwriting models, insurance pricing algorithms, fraud decisioning, and account eligibility determinations. The 'substantial factor' language means you can't avoid scope by having a human rubber-stamp the output.
What does TRAIGA actually prohibit? Is it a list of banned practices?
The final TRAIGA is an intent-based liability framework, not a checklist of banned AI features. It prohibits the intentional development or deployment of AI systems designed to deceive consumers, facilitate illegal discrimination, or incite self-harm or criminal activity. 'Intentional' is the pivotal word. The Texas AG must establish that a prohibited outcome was the design goal — not that it accidentally occurred. That said, contemporaneous design documentation is your primary evidence of non-prohibited intent.
Is there a safe harbor for TRAIGA compliance?
Yes. TRAIGA provides an affirmative defense if you substantially comply with the most recent NIST AI Risk Management Framework (including the Generative AI Profile), conduct and document impact assessments, and follow guidelines from applicable Texas state agencies. If the Texas AG brings an enforcement action, substantial NIST AI RMF compliance is a complete affirmative defense. This is the clearest path to structured TRAIGA compliance for financial services firms.
What penalties does TRAIGA impose?
The Texas Attorney General holds exclusive enforcement authority. Before filing a civil action, the AG must provide written notice and allow a 60-day cure period. If violations aren't cured, civil penalties can reach $200,000 per violation. There is no private right of action — consumers cannot sue directly. The AG's office has signaled enforcement interest but no financial services cases have been publicly filed as of September 2026.
How does TRAIGA compare to Colorado's SB 26-189 that takes effect January 2027?
The two laws take different approaches. TRAIGA (effective January 1, 2026) is intent-based and prohibitive — it focuses on what you can't do and provides an affirmative defense for NIST AI RMF compliance. Colorado's SB 26-189 (effective January 1, 2027) is more prescriptive — it requires post-adverse-outcome notices within 30 days, meaningful human review upon request, and three-year record retention. If you operate in both states, you need both frameworks. Texas is the earlier deadline; Colorado is the harder operational lift.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.