Services About Insights Schedule Consultation

Sometime around the first of September, without a press release, the Texas Attorney General’s office switched on a web page that changes the compliance math for anyone running AI in or around Texas. The AG’s Consumer AI Rights page now carries a live “File An AI Complaint Online” mechanism — the intake channel the Texas Responsible AI Governance Act required the office to have running by the statute’s September 1, 2026 deadline. Independent trackers verified the portal live on August 31; the AG’s office posted no launch announcement (Texas AI Report).

If that sounds like administrative housekeeping, it isn’t. TRAIGA — House Bill 149 — has been in effect since January 1, 2026, but for eight months its enforcement machinery had no intake channel. Nobody could file a complaint, so the pipeline from complaint to civil investigative demand to penalty existed on paper only (Norton Rose Fulbright). That changed this month. Tex. Bus. & Comm. Code § 552.103(a) reads: “If the attorney general receives a complaint through the online mechanism under Section 552.102 alleging a violation of this chapter, the attorney general may issue a civil investigative demand to determine if a violation has occurred” (HB 149 enrolled text).

Read that with an operator’s eye. A consumer web form is now the statutory trigger for the entire enforcement chain. No enforcement action had been publicly reported as of mid-September 2026 — but the intake channel is open, civil investigative demands are investigative instruments companies rarely publicize, and silence in the trade press is not evidence of quiet at the AG’s office.

So for a mid-market fintech, crypto firm, or B2B SaaS company, the practical question has shifted. It is no longer “does this law apply to us.” It is “if someone files a complaint about one of our systems tomorrow, what do we hand the Attorney General?”

The enforcement chain, exactly as the statute draws it

TRAIGA’s enforcement design is unusual enough that it deserves a careful walk-through, because each step rewards preparation and punishes improvisation.

First, the AG must maintain an online complaint mechanism (§ 552.102), and Section 8 of the Act set September 1, 2026 as the deadline for posting it (bill text). A single complaint through that mechanism authorizes a civil investigative demand — no lawsuit, no severity threshold, no minimum number of affected consumers. One unhappy user of your underwriting model, your support chatbot, or your AI-drafted outreach is enough to open a file.

If the investigation concludes a violation occurred, § 552.104 requires the AG to give written notice identifying the specific provisions allegedly violated, and the statute bars suit before the 60th day after that notice. A company that cures the violation within the window — fixes the problem, provides the required written statement, and makes the relevant policy changes — avoids penalties (bill text). Norton Rose Fulbright’s analysis flags the squeeze in that design: sixty days is rarely enough to re-engineer an AI system, the line between curable and uncurable violations is unsettled, and a notice of violation can function like a cease-and-desist (Norton Rose Fulbright).

If the matter reaches penalties, § 552.105(a) sets the tiers: $10,000 to $12,000 per curable violation (or for breaching a cure-period statement), $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for a continuing violation. The AG’s own page describes the same numbers (bill text; AG Consumer AI Rights page).

Two structural features matter as much as the dollar figures. Enforcement is AG-exclusive: § 552.101(a) gives the attorney general sole authority, and § 552.101(b) provides no private right of action (bill text). Your customers cannot sue you under TRAIGA — but they can file the complaint that starts everything, which is why a free web form belongs on your risk register. And for licensed entities, § 552.106 allows a state agency to impose additional sanctions on a licensee, including license suspension and a monetary penalty of up to $100,000, after an AG finding and an AG recommendation. That is not a second, independently triggered enforcement path, but a licensed money transmitter or lender should assume its regulator reads the AG’s mail (bill text).

What a CID actually demands

The civil investigative demand is where theory becomes an evidence request. Section 552.103(b) lets the AG require, for the system under complaint:

None of that is exotic. These are the standard artifacts of a NIST-aligned AI program: intended-use statements, model documentation, evaluation results, monitoring plans, escalation records. A company with a real governance program will find that the CID asks for things it already has. A company with thin documentation will have nothing to hand over — and the response window is the wrong time to discover that the answers live in four tools, two wikis, and a departed engineer’s laptop.

A readiness checklist you can actually run

You don’t need a legal department the size of the AG’s consumer protection division to get defensibly ahead of this. Five steps, roughly in order.

1. Build the AI inventory first. Every CID answer has to survive one upstream question: what systems do you actually run? Inventory them — including the AI embedded in vendor products you didn’t build and the tools individual teams adopted on their own. We’ve covered how to build that inventory and surface shadow AI before; it is the right first step for TRAIGA, because an unanswered inventory question contaminates everything downstream of it.

2. Screen prohibited uses against the statutory sections, not a vendor summary. TRAIGA’s prohibited practices sit in §§ 552.052 through 552.057, and secondary sources group them differently — so work from the statutory text, section by section, rather than from a compressed checklist. The unlawful-discrimination prohibition in § 552.056 deserves particular attention for anyone running underwriting, pricing, or eligibility models (bill text). One recent analysis specifically flagged AI-powered sales and outreach tools as in scope (Record of Record) — a category most mid-market companies don’t associate with “AI compliance” at all.

3. Fix your intent-and-documentation posture. Some prohibitions turn on what the deployer intended as much as on what the system did. Intent is defended with contemporaneous records: the intended-use statement written at deployment, the review that approved the use case, the decision log for features that were declined. Documentation reconstructed after a complaint arrives reads exactly like what it is.

4. Align the program to the NIST AI RMF and its Generative AI Profile. This is the provision most teams overlook. Under § 552.105(e), penalties are barred for violations a company discovers and corrects through internal review, provided it complies with nationally recognized AI risk-management frameworks — the NIST AI RMF and its Generative AI Profile (NIST-AI-600-1) — or finds issues through red-teaming, adversarial testing, or stakeholder feedback (bill text). The CSA’s analysis of the portal launch makes the same point: this language converts governance investment into direct legal protection (CSA Lab Space). A program mapped to the NIST AI RMF isn’t just good practice under TRAIGA — it is the difference between a self-corrected finding and a penalty negotiation.

5. Write the complaint-response runbook before the complaint. Who receives AG correspondence, who can invoke counsel, who assembles the § 552.103(b) package, and who decides — quickly — whether a noticed violation is curable inside 60 days. A written, owned AI governance policy makes that runbook an extension of existing process rather than an improvisation. The cure window rewards companies that can move; it punishes companies that spend the first three weeks finding an owner.

The fintech carve-out reality

TRAIGA’s applicability is geography-based. Under § 551.002, it reaches anyone who advertises, promotes, or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys AI in the state. There is no revenue threshold and no size floor (bill text).

The financial-services carve-outs are narrower than most fintech executives assume. Section 552.056(e) deems federally insured financial institutions compliant with the discrimination prohibition so long as they follow banking laws, and extends related treatment to insurance entities regulated under existing unfair-discrimination statutes. Separately, § 552.054(e) exempts voiceprint data held by financial institutions and their affiliates, per the federal definition at 15 U.S.C. § 6809 (bill text).

“Federally insured” is doing the work in that carve-out. A state-licensed money transmitter is not a federally insured financial institution. Neither is an MSB, a non-bank lender, a crypto exchange, a payments platform, or a B2B SaaS product serving Texas users. Non-bank fintechs get none of these carve-outs and remain fully in scope for every prohibition, including the discrimination provisions (bill text). The carve-out is easy to misread as “fintech exemption” — the statute says no such thing.

This is a home-state statute for us. NTD is Dallas-based, and our Texas fractional CISO and Dallas fractional CISO pages exist because geography-based statutes like TRAIGA are precisely the obligations mid-market companies need scoped, not theorized.

What to watch

Three developments worth tracking over the next two quarters:

None of this is an argument for panic. TRAIGA’s enforcement design gives prepared companies a genuine exit — cure, document, align to NIST — and it prices unpreparedness per day. A web form started the clock.

For multi-state context, see our related piece on California’s AI audit law — state AI enforcement mechanics are converging faster than most compliance calendars assume.

If you’re unsure whether your AI systems touch Texas consumers, or how your team would answer a CID, NTD’s fractional CISO team builds TRAIGA-ready AI governance programs mapped to the NIST AI RMF.

Need a second set of eyes before your SOC 2 audit?

NTD Consulting offers a free 30-minute readiness assessment. No pitch, no pressure — just direct feedback on where your program is likely to get pushed back.

Schedule a 30-Minute Consultation