← Blog

Texas TRAIGA AI Controls Mapping: Requirement, Owner, Test and Evidence

Texas TRAIGA took effect on 1 January 2026 and combines targeted use prohibitions with complaint-driven Attorney General enforcement. This mapping connects enacted HB 149 requirements to control objectives, accountable owners, implementation points, tests and evidence. It marks HTTP gateway coverage as full, partial or outside scope and keeps legal intent, notices, training data and metrics with their proper owners.

ByParminder Singh· Founder & CEO, DeepInspect Inc.
Compliance & Regulationcomplianceregulationai-complianceai-governancepolicy-enforcementai-security
Texas TRAIGA AI Controls Mapping: Requirement, Owner, Test and Evidence

Texas House Bill 149 took effect on 1 January 2026. The enacted Texas Responsible Artificial Intelligence Governance Act creates targeted disclosure and prohibited-use provisions, then gives the Attorney General a complaint-driven investigation and cure path.

I use seven fields for this Texas TRAIGA AI controls mapping: provision, objective, owner, implementation, test, evidence and coverage. Coverage describes controls at the authenticated HTTP user-or-agent-to-LLM boundary. It never grades the adjacent legal, product, IAM or platform work required to complete the statutory duty.

Scope and role control

Business & Commerce Code § 551.002 covers specified Texas business, resident-use, development and deployment connections. Chapter 552 defines a developer as a person developing an AI system provided in Texas and a deployer as a person deploying one for use in Texas.

Legal owns the nexus and role analysis. Product operations maintains the system inventory, deployment state and version. The test selects one Texas-facing product and traces its legal entity, system, developer-or-deployer role and production status. Evidence includes the signed scope sheet and architecture record.

Coverage sits outside the gateway for legal classification. Observed HTTP routes can reveal an omitted system or model endpoint, providing partial inventory evidence after legal has defined the scope.

Consumer-disclosure control

Business & Commerce Code § 552.051 requires a governmental agency making an AI system available to interact with consumers to disclose the AI interaction before or at the time it begins. The notice must be clear, conspicuous, written in plain language and free of dark patterns. The provision also specifies timing where AI is used in relation to health care service or treatment.

Legal determines applicability, product presents the notice and the service owner retains proof. The test opens a clean consumer session and checks timing, text and placement against the approved version. Evidence is the approval, dated interface capture and interaction sample.

Coverage is outside the HTTP AI gateway for presentation. An application can pass a notice-version value into a request record, but that supports correlation rather than proving the consumer saw the notice.

Harm and criminal-activity control

Business & Commerce Code § 552.052 prohibits developing or deploying an AI system in a manner that intentionally aims to incite or encourage physical self-harm, harm to another person or criminal activity.

Product and legal own design intent. Trust or safety writes the policy, and security testing runs adversarial cases. The test set includes explicit harmful requests, indirect prompts and benign nearby cases, each tied to the model and policy version. Evidence connects product requirements, system instructions, observed outputs, findings and retests.

Gateway coverage remains partial because inline request and response policy can refuse specified content on routed HTTP LLM traffic and preserve evidence. The control cannot determine legal intent or cover offline model behaviour and direct routes outside the enforcement point.

Government social-scoring and biometric controls

Business & Commerce Code § 552.053 restricts a governmental entity's use of social scoring that produces listed forms of detrimental treatment or rights infringement. The biometric provision in § 552.054 addresses specified governmental identification using targeted or untargeted gathering from public sources without consent where rights would be infringed. The same provision connects a violation of Business & Commerce Code § 503.001.

The governmental entity and legal team own use classification, consent and rights analysis. Data governance controls source and purpose. A test follows one biometric or scoring data flow through collection, model input, output and downstream decision. Evidence includes purpose approval, source record, consent where applicable and decision workflow.

Gateway coverage remains partial for data-class and route policy. Collection, consent, governmental authority and downstream treatment sit outside the LLM request path.

Constitutional-rights and discrimination controls

Business & Commerce Code § 552.055 uses a sole-intent threshold for constitutional impairment. The discrimination provision in § 552.056 prohibits development or deployment with intent to unlawfully discriminate against a protected class and states that disparate impact alone is insufficient to show intent.

Legal owns statutory analysis, while product owns design purpose and business operations owns the downstream decision. Testing compares protected and control cohorts under an approved evaluation plan. Evidence includes requirements, feature review, performance analysis, approval history, individual case files and remediation.

Gateway coverage is partial for enforcing approved data-class, route and response rules. A request record can show inputs, model route and policy outcome. It cannot decide statutory intent, prove fairness across a population or govern the downstream business action.

Specified sexual-content control

Business & Commerce Code § 552.057 addresses development or distribution with sole intent involving specified unlawful visual material, deepfake videos or images, and intentional systems that impersonate or imitate a child in text-based sexual conversations.

Legal and trust or safety own the control definition. Product limits the use case, and model evaluation tests representative inputs and outputs. Evidence includes design approvals, blocked cases, reviewer decisions, model or policy changes and clean retests.

Coverage is partial on routed HTTP LLM traffic because inline policy can inspect requests and responses and stop defined classes. Distribution channels, local generation, training choices and legal intent need application, model-governance and legal controls.

Attorney General information control

The investigative provision in Business & Commerce Code § 552.103 permits a civil investigative demand after a complaint. Its eight information categories cover purpose and use; programming or training data; input categories; outputs; performance metrics; known limitations; post-deployment monitoring and safeguards; and other relevant documentation reasonably necessary for the investigation.

The legal team coordinates the response across product, data science, AI platform and security owners who hold the source artifacts. The test selects one deployed system and assembles all eight folders with owners, versions and approval dates. Evidence is the indexed response file plus the reconciliation record tying high-level descriptions to technical sources.

Gateway coverage remains partial because runtime records support input and output descriptions, observed routes, monitoring and safeguards. Training data, performance metrics, known limitations and the legal response package remain outside the gateway.

Testing and internal-review control

Business & Commerce Code § 552.105 recognizes feedback, adversarial testing and red-team testing among the routes through which a defendant may discover a violation. It also refers to substantial compliance with the current NIST Generative AI Profile or another recognized framework alongside an internal review process.

The security-testing team owns execution while product owns remediation and legal reviews the statutory effect. Each test captures objective, version, input, observed output, reviewer, severity, correction and retest. Evidence retains failed cases and the internal-review decision.

Coverage can be full for executing and recording an HTTP request-path policy test. The wider statutory effect is partial because framework alignment and legal applicability extend beyond the traffic boundary.

Post-deployment monitoring control

The seventh information category in § 552.103 expressly reaches post-deployment monitoring and user safeguards. For deployers it includes the oversight, use and learning process established to address deployment issues.

Product operations owns the process and security owns technical alerts. A seeded case moves through detection, triage, correction and retest. Evidence joins user reports, alert data, affected request IDs, policy changes and closure approval.

Gateway coverage is full for monitoring policy decisions on routed HTTP LLM traffic and partial for the complete oversight process. User reporting, business review and model-performance monitoring require adjacent systems.

Complaint and cure control

Business & Commerce Code § 552.102 establishes an Attorney General complaint mechanism. The cure provision in § 552.104 requires written notice of an alleged violation and provides a 60-day path requiring cure, a written statement, supporting documentation and necessary internal-policy changes aimed at reasonably preventing recurrence.

The legal team owns the cure response while the affected product or control owner implements correction and security validates the retest. A tabletop begins with a mock written notice and ends with a signed statement, deployment evidence, policy revision and clean test. The case timeline is the evidence.

Gateway coverage remains partial because per-decision records can identify affected requests and prove a policy correction. The written statement, legal position, product change and Attorney General communication remain outside the traffic path.

Consolidated mapping

  • Scope under §§ 551.002 and 552.001: Legal and product own the Texas system trace. Route inventory provides partial evidence.
  • Disclosure under § 552.051: Legal and product own the clean consumer-session test. Gateway coverage is outside scope.
  • Harm and crime under § 552.052: Product, legal and safety run adversarial cases against request and response policy, giving partial coverage at the gateway.
  • Government scoring and biometric use under §§ 552.053 and 552.054: Government and legal owners trace data source through decision. Data-class and route policy provide partial coverage.
  • Rights and discrimination under §§ 552.055 and 552.056: Legal and operations own cohort and case review. Approved input and route policy provide partial coverage.
  • Specified content under § 552.057: Legal and safety test defined content classes. Request and response inspection provide partial coverage.
  • Information under § 552.103: Legal and system owners run the eight-folder tabletop. Runtime input and output records provide partial evidence.
  • Testing under § 552.105: Security and product run adversarial tests and retests. Versioned policy decisions provide partial statutory coverage.
  • Monitoring under § 552.103: Product operations and security run a seeded issue lifecycle. Decision monitoring provides partial coverage.
  • Cure under § 552.104: Legal and the control owner run a 60-day exercise. Affected-request and retest data provide partial evidence.

The consolidated mapping contains no blanket Full verdict because TRAIGA combines legal intent, interface design, model governance and operational evidence. My opinion is that a map filled with green gateway cells would be a warning sign. The grey cells preserve accountability.

Put the mapping on one screen and a sampled Texas deployment on another. Every Partial row should link the runtime artifact to the legal, product or operational artifact that completes it. The Texas TRAIGA audit evidence guide shows how those paired artifacts fit into the investigation package.

DeepInspect

DeepInspect implements the HTTP request-path portions of this mapping for authenticated users or agents calling LLM endpoints. It evaluates identity context supplied by the application, request classification, destination and policy before transmission, then creates a signed, tamper-evident per-decision record outside the calling application's write path.

That supplies a testable point for data-class, route, request and response rules. The resulting records support input-output descriptions, monitoring, affected-request searches and cure retests. Legal intent, consumer notices, training-data records, performance metrics, fairness evaluation and Attorney General submissions retain their named owners. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

What does Partial coverage mean in this mapping?

Partial means an authenticated HTTP AI control can implement or evidence one part of the objective. Another owner must complete the duty through legal analysis, product design, model evaluation, IAM, workflow or regulator communication.

Which TRAIGA control should a company test first?

The strongest first test uses the information file described in Business & Commerce Code § 552.103. Building its eight folders forces the legal scope, system version, input-output taxonomy, metrics, limitations and monitoring owners into one exercise. Missing artifacts become named gaps.

Can a gateway determine unlawful discriminatory intent?

A gateway can apply approved policy to request data, destination and response content and preserve the decision record. Legal intent and population-level fairness analysis require product records, evaluation data, downstream outcomes and legal judgment.

Does the NIST reference create a mandatory framework control?

Business & Commerce Code § 552.105 places substantial compliance with the current NIST Generative AI Profile or another recognized framework inside a liability provision that also refers to internal review. It stops short of imposing universal framework adoption.

Which evidence supports the 60-day cure path?

Use the written notice, affected system and request scope, containment, permanent correction, policy revision, deployment approval, retest and signed statement. Each artifact should carry a date, owner and system or policy version.