AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·AI Compliance7 min read

Texas TRAIGA: The Safe Harbor Is About Discovery, Not Compliance

Most summaries call Section 552.105(e) a safe harbor for NIST AI RMF compliance. The text conditions it on how you found the problem, not on having a framework, and it names the Generative AI Profile rather than AI RMF 1.0. If discovery is the trigger, the capability that earns the shield is detection.

S
Sofia Reyes
Head of Compliance
Sep 30, 2026

Texas has had an AI statute in force since 1 January 2026, and the part worth your attention is not the prohibitions. It is Section 552.105(e), the provision that says when a defendant cannot be found liable. Most summaries describe it as a safe harbor for NIST AI RMF compliance. Read the text and it is narrower than that, and more interesting.

The shield is conditioned on how you found the problem. Not on having a framework. On having found it yourself.

That distinction changes what you build.

What TRAIGA actually prohibits

The Texas Responsible Artificial Intelligence Governance Act, House Bill 149, was signed on 22 June 2025 and took effect on 1 January 2026. It adds Subtitle D to Title 11 of the Business and Commerce Code, creating Chapters 551, 552 and 553.

The bill that passed is substantially narrower than the bill that was introduced. The original followed the Colorado model, with duties of care and algorithmic impact assessments for anyone deploying consequential AI. What survived is a set of intent-based prohibitions. Section 552.052 reaches systems that intentionally aim to incite or encourage certain harms. Section 552.056(b) reaches development or deployment with the intent to unlawfully discriminate. Sections 552.055 and 552.057 use a sole intent standard.

Intent standards matter enormously for ordinary enterprises. An employer whose screening model produces a disparate outcome has a serious problem under federal employment law and under the Illinois statute, and probably not under TRAIGA, because TRAIGA asks what the system was built or deployed to do. Disparate impact without intent is outside the prohibition as written.

So if you deploy AI for ordinary commercial purposes in Texas, your direct exposure under these prohibitions is low. Anyone telling you otherwise is selling urgency. The penalties are real where they attach: Section 552.105(a) sets $10,000 to $12,000 for curable violations, $80,000 to $200,000 for uncurable ones, and $2,000 to $40,000 per day for continuing violations. Enforcement is exclusively the Attorney General's under Section 552.101, there is no private right of action, and Section 552.104(b) gives you 60 days from notice to cure.

A 60-day cure period and no private right of action is a mild enforcement posture. That is the context for the safe harbor, and it is why the safe harbor is the part that earns attention rather than the threat.

The provision, and what it actually says

Here is Section 552.105(e) in full. A defendant may not be found liable if (1) another person uses the AI system affiliated with the defendant in a prohibited manner, or (2) the defendant discovers a violation through:

  • (A) feedback from a developer, deployer or other person who believes a violation has occurred;
  • (B) testing, including adversarial testing or red-team testing;
  • (C) following guidelines set by applicable state agencies; or
  • (D) if the defendant substantially complies with the most recent version of the "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" published by the National Institute of Standards and Technology, or another nationally or internationally recognized risk management framework for artificial intelligence systems, an internal review process.

Three things in that text differ from how it is usually reported.

The trigger is discovery, not compliance. Subsection (e)(2) opens with "the defendant discovers a violation through," and every item under it is a route to discovery. On this reading, running a framework is not itself the shield. Finding the problem through a process run under that framework is. A company with an immaculate NIST-aligned program that learns of a violation from a journalist has not met (e)(2) by its terms.

The named document is the Generative AI Profile, not AI RMF 1.0. Several widely cited summaries say the defense attaches to the NIST AI Risk Management Framework generally. The statute names the Generative AI Profile specifically, then broadens to "another nationally or internationally recognized risk management framework." The general AI RMF would almost certainly qualify under that second clause, as would ISO/IEC 42001. But the document Texas chose to name is the generative profile, and it says "the most recent version," which means the target moves when NIST revises it.

The drafting is awkward and reasonable readings differ. Subparagraph (D) ends with the words "an internal review process" dangling after the framework clause, which is not clean statutory English. One reading makes the internal review process the discovery mechanism, qualified by substantial compliance with a recognized framework. Another treats substantial compliance as sufficient on its own. We think the first reading is better supported by the "discovers a violation through" stem that governs the whole list, and we are a security company rather than a law firm. Get your counsel's view before you rely on either one.

Why the discovery reading changes your architecture

If the shield depends on self-discovery, then the capability that earns it is detection. Policy documents do not discover anything.

Look again at the four routes. Feedback, in (A), means a channel exists and someone monitors it. Testing, in (B), means adversarial and red-team exercises that are scheduled and recorded, not a one-off before launch. Agency guidelines, in (C), is a watching brief. The internal review process in (D) is the one that has to run continuously, because a review that happens annually discovers annual problems.

Each of those needs a record. "We discovered this ourselves on 14 March through our internal review process" is a claim, and the thing that makes it a defense rather than an assertion is a timestamped trail showing the detection, who saw it, what they did, and when. If the record is reconstructed after the Attorney General's notice arrives, it is worth very little.

This is the same argument the EU AI Act makes through its logging obligations and ISO/IEC 42001 makes through control A.6.2.8, arrived at from a different direction. Texas is not asking for logs. Texas is offering a liability shield that is hard to claim without them.

Two practical consequences. First, your detection coverage has to extend to the places where prohibited use would actually happen, which for most enterprises is employee and agent use of AI systems rather than a model you trained. Second, the trail has to be tamper-evident, because its evidentiary value is the point. We went through the mechanics of both in AI audit trails and SIEM integration and what belongs in an AI agent audit log.

What substantial compliance plausibly requires

TRAIGA does not define substantial compliance, and no Texas court has construed Section 552.105(e) yet. Nobody can tell you where the line is. What we can say is what the named document asks for, because the Generative AI Profile is public.

The profile organizes risk actions against the four AI RMF functions, Govern, Map, Measure and Manage, and the Measure and Manage functions are where generative risks get operational: monitoring deployed systems, tracking incidents, maintaining feedback channels, and acting on what comes back. A program that has written Govern and Map but never implemented Measure would be a weak candidate for substantial compliance, and it would also fail the discovery test, for the same underlying reason.

If you already map to NIST AI RMF, you are most of the way there, and the gap is usually the generative-specific monitoring rather than the governance scaffolding. We laid the framework mappings side by side in the unified compliance crosswalk, which is the fastest way to see what your existing program already satisfies.

The sandbox, and who it is for

Chapter 553 creates an Artificial Intelligence Regulatory Sandbox Program, established under Section 553.051. It lets participants test systems with regulatory relief for a defined period under state oversight.

Be realistic about this. Sandboxes suit organizations developing novel AI products that bump into existing Texas regulation, and they come with reporting obligations and visibility you may not want. For an enterprise deploying commercial AI tools internally, the sandbox is not the relevant provision. Section 552.105(e) is.

What to do with this

The honest summary is that TRAIGA is a low-exposure statute with a high-value option attached, and the option costs almost nothing extra if you are already building AI governance for the EU AI Act or ISO 42001.

Four steps, in order. Confirm whether any of your AI use could touch the intent-based prohibitions, which for most enterprises takes one meeting and ends in no. Pick your framework and write down which one you are claiming substantial compliance with, because an unstated claim is not a claim. Make sure the Measure and Manage half is actually running, not just documented. Then verify that your detection produces a trail you would be willing to put in front of a regulator, including the timestamps.

Texas is also the beginning of a pattern rather than an exception. Four state AI laws took effect on 1 January 2026 and Colorado's replacement statute arrives on 1 January 2027, with obligations that fall on different parties in each. We put the deployer and developer split in one place in the US state AI law tracker.

If you want the policy groundwork that the framework claim rests on, our AI acceptable use policy template is the document most of these provisions assume you already have.

None of this is legal advice. Section 552.105(e) has not been tested, our reading of subparagraph (D) is one of at least two available, and the difference between them could matter. Have counsel read the text before you build a compliance position on it.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoRun the free assessment

15 enterprises secured · under 38ms p99 · live on your own estate in 72 hours