AI deployment review in Texas: what TRAIGA changes for buyers.
Published
Texas has had its own AI statute in force since January 1, 2026. The Texas Responsible Artificial Intelligence Governance Act (HB 149, usually called TRAIGA) does not require an assessment of every AI system, but its defenses are earned by documented internal review. This page explains what the law does and does not require, and where a buyer-side deployment review fits.
What TRAIGA covers.
Mayhem Shield is a buyer-side AI deployment assurance firm based in Frisco, Texas, serving the Dallas-Fort Worth area and enterprises across the state. We review AI tools as deployed in your environment, document what holds and what does not, and give approvers gate conditions before pilot expansion or production. We are paid only by buyers. We do not resell or implement the products we review.
HB 149 was signed on June 22, 2025 and took effect on January 1, 2026. It applies to any organization that does business in Texas, offers a product or service used by Texas residents, or develops or deploys an AI system in Texas. That reaches most enterprises with Texas operations or Texas customers, regardless of where they are headquartered.
The private-sector rules are narrower than the EU AI Act or Colorado's statute. They prohibit a short list of intentional uses. There is no general duty to run an impact assessment on every AI system. Enforcement belongs to the Texas Attorney General only; there is no private right of action. Penalties for violations that cannot be cured run up to $200,000 per violation, and continuing violations up to $40,000 per day.
What the statute prohibits, and what it rewards.
Prohibited practices
A short list of intentional uses. The test is intent, not outcome.
- AI developed or deployed with the intent to incite self-harm, harm to others, or criminal activity
- AI developed or deployed with the intent to unlawfully discriminate against a protected class
- AI developed or deployed with the intent to infringe constitutional rights
- Disparate impact alone is not a violation; private-sector liability is intent-based
Affirmative defenses and cure
What protects an organization when a violation is alleged. Each one depends on a review that actually ran and a record of what it found.
- The violation was discovered through the organization's own testing, including adversarial or red-team testing
- The violation was discovered through user feedback or applicable state-agency guidelines
- The organization substantially complied with the NIST AI Risk Management Framework, its Generative AI Profile, or another recognized AI risk-management framework as part of an internal review process
- Written notice from the Attorney General and 60 days to cure before any civil action
Two things follow. The defenses turn on a review that found the problem, not on a policy that says a review should happen. And the 60-day cure window is only usable if you can show what the deployment looked like before, what changed, and what controls are now in place. Both require a written record tied to the specific deployment.
This is not legal advice. We are not lawyers. Whether TRAIGA applies to a given system, and whether a defense holds, is a question for your counsel.
Where a deployment review fits.
A Mayhem Shieldreview produces the record the statute's defenses depend on. For one AI deployment we document:
- Data paths, identities, integrations, and workflows as built, with control points marked on a diagram
- A findings register where each finding is tied to evidence we examined and mapped to a NIST AI RMF 1.0 function (Govern, Map, Measure, Manage), with an OWASP Top 10 for LLM Applications ID where one fits
- The conditions that must close before the next approval gate (proof of concept, pilot, production), stated as go, conditional go, or no go
The public version of the framework, including the NIST AI RMF mapping, is on GitHub.
Who this is for in Texas.
Security, risk, audit, and compliance leaders at Texas enterprises who are approving an AI tool for production and want an independent read before they sign off. Typical cases: a Microsoft 365 Copilot or ChatGPT Enterprise rollout, an agentic tool with write access to enterprise systems, a customer-facing assistant that produces output under your name, or a vendor AI feature turned on inside software you already run.
Reviews start with a two-week Rapid Readiness Review of one tool, covering critical and high severity findings.
Discovery calls take twenty minutes.
We confirm deployment fit, outline review scope, and match you to the right packaged offer. No engagement starts until you decide to proceed.
