The AI Law That Won by Doing Less
Seven months in force, a live complaint portal, and no announced enforcement action. TRAIGA is not the clampdown the headlines described. It is the lightest comprehensive AI statute in America — and it is becoming the template.
The Texas Responsible AI Governance Act has been in force since 1 January 2026. The attorney general's complaint channel is already online — a "Consumer AI Rights" page inside the office's consumer-complaint system, launched ahead of the statute's 1 September deadline. And as of this writing, no enforcement action under the law has been publicly announced, though an absence of announced cases does not rule out investigations, which are not public.
Nearly seven months is enough to say what Texas actually built, and it is close to the opposite of what much of the coverage described. TRAIGA was reported as comprehensive AI regulation, sometimes as a clampdown. Read the enacted text and you find something else: a statute with broad jurisdiction and remarkably narrow obligations, wrapped in one of the most generous defence suites in American consumer law. The claim of this piece is that TRAIGA matters not for what it demands — it demands almost nothing of private firms — but for what it signals. The deliberately light, intent-based model has captured the institutional momentum in the contest over America's AI regulatory default: for the first time, the light-touch camp has both a state template and the federal government's machinery behind it. And that shift has sharper consequences for European firms than any Texas compliance cost ever would.
What the statute actually says

TRAIGA applies to anyone who does business in Texas or whose AI systems reach Texas residents, so its jurisdiction is broad even though its obligations are not.
For every person, public or private, the law prohibits developing or deploying an AI system for four purposes: intentionally inciting or encouraging self-harm, harm to others, or criminal activity; unlawfully discriminating against a protected class, with the express caveat that disparate impact alone does not establish the required intent; infringing constitutional rights, where the statute demands sole intent; and producing or distributing child sexual abuse material or unlawful sexually explicit deepfakes. Every prohibition hinges on intent or purpose, not on outcome.
Government entities carry the additional duties. They must disclose to consumers, clearly and before or at the point of interaction, that they are dealing with an AI system; they are barred from AI-driven social scoring, in a provision that reads like Article 5 of the EU AI Act; and they are restricted from using AI to identify specific individuals through biometric data gathered without consent where that gathering would infringe a constitutional or statutory right. Healthcare providers carry one of the few private-sector disclosure duties: they must clearly and conspicuously tell patients when AI is used in their care.
Two institutions round it out: the Texas Artificial Intelligence Council, a seven-member advisory body with no rulemaking power, and a 36-month regulatory sandbox. And one definition quietly narrows the law's main channel: "consumer" excludes people acting in employment or commercial contexts. That sharply narrows the statute-specific complaint funnel for B2B activity — the business most European AI vendors are actually in — although it does not exempt B2B developers and deployers from the law's general prohibitions.
Built to be survivable
The defence architecture is where the law's real character shows.
There is no private right of action; enforcement belongs exclusively to the attorney general. Before penalties, a firm gets written notice and a 60-day cure period. Substantial compliance with the NIST AI Risk Management Framework is a recognised defence, and so is discovering a violation through internal testing, red-teaming, or documented feedback processes. A developer is protected when a third party misuses its system. No civil penalty attaches to an AI system that has not been deployed. And the statute pre-empts local AI ordinances, so there is one rulebook in Texas rather than one per city.
The penalties are real on paper — per Ogletree's analysis, $10,000 to $12,000 per curable violation, $80,000 to $200,000 for uncurable ones, and $2,000 to $40,000 per day for continuing violations — but the path to them is deliberately narrow. To reach a discrimination penalty, the state must prove the system was developed or deployed with the intent to discriminate. Uneven outcomes are not enough. In practice that makes discrimination cases materially harder to prove, particularly without internal evidence showing discriminatory purpose, and it makes enforcement selective and case-driven by design.

So the honest criticisms of TRAIGA run in the opposite direction from the one I expected when I started reading it. This is not a law that overburdens business. It is a law that may underprotect consumers: an intent threshold that impact evidence alone cannot cross, and every ounce of enforcement discretion concentrated in a single elected office. That discretion is the one genuine private-sector exposure worth naming. A consumer complaint can give the attorney general a basis to issue civil investigative demands and seek information from the person reported — and because TRAIGA reaches certain out-of-state businesses whose systems are used in Texas, that scrutiny need not stop with the local deployer. This particular office built a specialised data-privacy enforcement team in 2024 and reached what it described as a first-of-its-kind AI consumer-protection settlement, with a healthcare AI company, before TRAIGA existed. But discretion is a risk you price, not a compliance program you build. It is not a barrier to entry.
The two-statute confusion

If you read that TRAIGA requires risk assessments, impact documentation, or controls on consequential decisions, you read a merger of two different laws — and much of the coverage made exactly that merger.
Governor Greg Abbott signed a second statute, SB 1964, two days before HB 149. It governs the state's own use of AI, took effect on 1 September 2025, and the Department of Information Resources' implementing rules followed in early 2026. That is the law with the machinery — a DIR-maintained inventory of agency AI systems, a NIST-aligned code of ethics for state and local government, and a "heightened scrutiny" tier for systems that influence consequential decisions. Agencies bound by those rules pass the expectations through procurement to their vendors. So a firm selling into Texas government workflows does face a documentation regime — but its source is SB 1964 and the DIR rules, not TRAIGA. A firm that never touches the public sector faces almost nothing at all.
That distinction is not pedantry. It is the difference between "Texas regulates AI heavily" and the truth:
Texas regulates its own government's AI and asks the private market to avoid a short list of intentional harms.
The template has the momentum

TRAIGA's significance is upstream of its text. An earlier TRAIGA proposal, HB 1709, filed in December 2024, borrowed heavily from the Colorado and European approach — high-risk classifications, impact assessments, duties to address foreseeable harms. The enacted HB 149, introduced in March 2025, abandoned most of that architecture; contemporaneous coverage documented months of negotiation and industry lobbying narrowing the bill's scope, and its sponsor pitched the result explicitly as a model for red-state AI legislation. "Template" here does not mean other states copying the statute section by section. It means a regulatory philosophy: reactive rather than preventive, intent-focused rather than impact-focused, enforcement after harm rather than architecture before it.
The question was always whether that philosophy or Colorado's would become the American default, and the last eight months have reshaped the contest. Follow the chronology.
On 11 December 2025, Executive Order 14365 declared excessive state regulation an obstacle to a "minimally burdensome" national AI framework. It directed the attorney general to create an AI Litigation Task Force to challenge state AI laws, ordered the Commerce Department to identify conflicting statutes, contemplated withholding discretionary broadband funding from non-aligned states, and requested a legislative proposal for federal pre-emption. An executive order does not itself erase state law — the Task Force was formally established on 9 January 2026 and, notably, has not yet filed a case of its own. Its power operates earlier: through litigation exposure, funding leverage, and the threat of pre-emption.
Colorado shows how that works. Its 2024 law — the first comprehensive state AI statute, built on high-risk systems and algorithmic-discrimination duties — never took effect. Its original February 2026 start date was pushed to 30 June. Before that date arrived, xAI sued Colorado over the law's constitutionality in April 2026, and the US Department of Justice intervened in support of the challenge; the federal court entered a temporary stay of enforcement while the case proceeded — a procedural pause, not a ruling on the merits. On 14 May 2026, Colorado repealed and re-enacted the law as SB 26-189, dropping its three heaviest obligations — risk management programs, impact assessments, and the duty of reasonable care against algorithmic discrimination — in favour of a materially lighter framework for automated decision-making technology, effective January 2027.
The sequence supports a precise conclusion, and it is an inference worth stating as one. Washington did not pre-empt Colorado: no court ruled on the merits, no federal statute passed. But Washington increased the legal and political cost of maintaining the original regime — and Colorado retreated before that regime ever applied to anyone.
Texas did not defeat Colorado. The American incentive structure did.
That is how regulatory power operates now: before any final judgment, through the price of holding a position.
Two qualifications keep this honest. Colorado did not become Texas: its replacement still covers automated systems in consequential decisions and grants consumers procedural rights TRAIGA never provides — disclosure after adverse decisions, data correction, human review. And the contest is not settled. California's Transparency in Frontier Artificial Intelligence Act took effect on 1 January 2026, and New York signed its RAISE Act eight days after the executive order, then aligned it with California in March; from January 2027 it will require large frontier developers to publish safety frameworks and report incidents within 72 hours. The heavy, preventive model is in retreat at the broad-obligations end, but a second front — frontier-model transparency — remains open, and the two largest state economies are holding it.
So the calibrated claim is this: for the first time, the light-touch camp has both a state template and the federal government's coercive machinery behind it. That is not victory. It is momentum — and momentum moves markets before laws do.
The asymmetry that should worry Europe

The standard European comfort about all this used to have two halves: the EU's rules are heavier, but at least they are harmonised; the US market is lighter, but fragmented. The first half still holds. The second is eroding — not toward zero regulation, but toward a substantially lower ex ante compliance burden, with Washington working to make reactive enforcement, rather than preventive governance, the American default.
Be precise about what the asymmetry is, because it is not "European firms regulated, American firms free." The EU AI Act applies by market activity, not nationality: an American company placing models or systems on the European market falls inside it exactly as a European one does. The real dividing line runs between firms that build one global governance architecture around the European baseline and firms able to segment — keeping their US products, models, and processes outside that baseline until the day they choose to enter Europe. A European company tends to build the compliance in from the start, because maintaining two architectures is operationally unattractive, and then carries that cost into a US market that never asked for it. A US-first company defers the cost until Europe becomes worth entering. The advantage is not American nationality. It is time — and the regulatory advantage increasingly belongs to whoever can stay outside the European baseline longest.
The measured precedent for why this matters is GDPR. Johnson, Shriver and Goldberg's study in Management Science tracked the technology vendors used by more than 27,000 top websites and found vendor use fell 15% for EU users in the week after enforcement began, while market concentration rose 17% — with the relative gains going predominantly to Google- and Facebook-owned vendors, because fixed compliance costs sort markets by who can absorb them. The study's own limitation belongs in the record: the aggregate effects faded by the end of 2018, although the concentration effect persisted in the advertising-vendor category most closely scrutinised by regulators. The result does not prove that every compliance regime permanently entrenches incumbents, but it demonstrates the mechanism — fixed regulatory costs shift demand toward providers already equipped to absorb them. For years, Europeans could tell themselves that mechanism protected the home market. In a transatlantic race where one side is suppressing its most demanding rules, it prices European products instead.
And Europe is responding — which is itself the tell. In June 2026, the EU formally adopted its AI omnibus amendments: the European Parliament approved the package on 16 June and the Council gave its final green light on 29 June. The new timetable moves obligations for stand-alone high-risk systems from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to 2 August 2028. Brussels is lightening its framework while keeping it — a window I have argued firms should use deliberately rather than gratefully. So the honest picture is not a static contrast between a regulated Europe and a deregulated America. It is a race between two systems under the same competitive pressure: the US pushing its most demanding state laws down, Europe stretching its timeline out — and the question underneath is whether one demanding rulebook remains an advantage when your largest rival is working to make demanding rulebooks politically untenable.
What to do with this
- European SMEs: the marginal cost of entering Texas is a scoping memo, not a compliance program. Reserve the real budget for Colorado's automated-decision rules from January 2027, frontier-transparency duties in California and New York if they apply to you, and sector regulation in health, finance, and employment, which persists whatever general AI statutes do. If you sell into Texas government workflows, SB 1964 and the DIR rules are your checklist — not TRAIGA.
- Investors: reprice the assumption that US expansion carries EU-style compliance cost. For TRAIGA itself, the principal risk to underwrite is enforcement discretion in the attorney general's office, not a standing documentation mandate.
- Policymakers: every year of EU implementation cost is now a competitiveness variable measured against a converging-light American market, not against a fragmented one. The harmonisation premium Europe charges only pays if the alternative stays chaotic.
- Everyone: watch the federal pre-emption fight. It decides whether any state framework — light or heavy — survives at all.
Regulation as market structure, inverted
In Europe, the compliance layer is a moat — it protects whoever has already paid for it. In the emerging American settlement, the moat is the absence of that layer: the advantage goes to whoever can build and deploy fastest while the rules stay thin, and to whichever jurisdiction can credibly promise they will stay that way. Texas did not build the wall its early proposals contemplated. It declined to build one — and dared other jurisdictions to keep theirs.
I often write that regulation is market structure. The first thesis I tested here was that TRAIGA operated as a barrier to entry. It was plausible enough to structure an entire argument around—and doubtful enough that I kept pushing against it. The closer I read the statute, the less the claim held. For most private companies, its obligations are too limited for compliance costs to be the main story. The market-structure thesis did not disappear. It inverted—and became sharper.
The contest Texas opened is not over who can afford the rules. It is over who can move while the rules stay thin — and over how long anyone can afford to keep theirs thick.
If you want analysis like this each week, subscribe to ELECTE's Newsletter. I write about AI as power: who controls it, who captures the value, and what regulation, procurement, labour, and competition look like once the headlines fade.
Sources
- Texas Attorney General, Consumer AI Rights complaint page
- Texas legislative analysis of HB 149: provisions, pre-emption, and the complaint-mechanism deadline
- Ogletree on TRAIGA penalties and intent-based discrimination liability
- Baker Botts on TRAIGA's prohibited practices and government obligations
- Perkins Coie on the healthcare disclosure requirement
- Ropes & Gray on TRAIGA's defences, exemptions, and the 36-month sandbox
- Duane Morris on TRAIGA in force and the consumer-definition carve-out
- TechPolicy.Press on civil investigative demands and TRAIGA's enforcement design
- MultiState on the narrowing from HB 1709 to HB 149
- Biometric Update on the negotiation and lobbying that narrowed TRAIGA's scope
- Jackson Walker overview of the Texas 89th Legislature's AI bills, including SB 1964
- GovTech on the DIR board's adoption of the SB 1964 implementing rules
- Holland & Knight on Colorado SB 26-189, the executive order, and the xAI challenge
- Crowell & Moring on the obligations Colorado's rewrite dropped
- Colorado General Assembly, SB 26-189
- Chambers, Artificial Intelligence 2026 — Texas, on the attorney general's enforcement record
- White House, Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence"
- White & Case on EO 14365, the Task Force, and California's frontier transparency law
- Wiley on the final New York RAISE Act
- DLA Piper on the EU AI omnibus: Parliament and Council adoption and the deferred deadlines
- Johnson, Shriver & Goldberg, "Privacy and Market Concentration," Management Science (2023)
Fabio Lauria
CEO & Founder, ELECTE
Every week, we explore AI without the hype — using data, analysis and an independent perspective.

Comments ()