The Alerts Got the Emphasis Backwards

Here is the answer, up front. If you are a private Texas employer using AI to screen resumes, TRAIGA does not require you to disclose that to applicants, does not require a bias audit, does not require an impact assessment, and does not let an applicant sue you. Its discrimination provision requires intent, and the statute says outright that disparate impact alone is not enough to show it. Meanwhile Title VII, the ADA, the ADEA, and the Texas Commission on Human Rights Act all still apply exactly as they did in 2024, and those do reach disparate impact. Your AI hiring risk is real. It mostly is not TRAIGA.

I spent the back half of 2025 watching Texas employers get worked up about the wrong thing.

The alerts came fast after Governor Abbott signed HB 149 in June 2025. Most were written by very good lawyers for general counsel, and most were technically accurate. But they were written from the statute outward, which meant they catalogued every provision at roughly equal weight, and the reader — usually an HR director with eleven other things on the desk — came away with a general sense of alarm and no idea which drawer to open first.

Then January 1 came, the law took effect, and mostly nothing happened. Which produced the opposite error: a lot of Texas employers concluded the whole thing was noise.

Both readings are wrong, and the reason they are wrong is the same. TRAIGA is not a heavy law for private employers and is a meaningful law in two specific places most coverage buried. Let me sort it.

TRAIGA and Hiring: The Short Version
  • TRAIGA took effect January 1, 2026 and is codified at Business and Commerce Code Chapters 551 through 554.
  • It imposes no employment disclosure mandate, no bias audit, and no impact assessment on private Texas employers.
  • Its discrimination provision requires intent, and the statute states that disparate impact alone is not sufficient to prove it.
  • The provisions with real financial teeth are biometric, connecting to CUBI penalties of up to $25,000 per violation.
  • Texas cities carry more duties and less authority, including express preemption of local AI ordinances.
  • The attorney general's complaint portal is due by September 1, 2026. That is an intake channel, not a new compliance deadline.

What TRAIGA Actually Prohibits

Subchapter B of Chapter 552 contains the operative prohibitions. There are six, and it is worth seeing them together because the shape tells you something.

  • § 552.051 — Disclosure to consumers. A governmental agency making an AI system available to interact with consumers must disclose that fact, clearly, in plain language, with no dark patterns. Same duty attaches to health care services. Not to private employers generally.
  • § 552.052 — Manipulation of human behavior. No developing or deploying AI that intentionally aims to incite self-harm, harm to others, or criminal activity.
  • § 552.053 — Social scoring. Prohibited for governmental entities.
  • § 552.054 — Capture of biometric data. Prohibits a governmental entity from deploying AI to uniquely identify an individual using biometric data, or scraping images from public sources without consent, where that would infringe a constitutional or statutory right. A violation of § 503.001 is a violation of this section.
  • § 552.055 — Constitutional protection. No developing or deploying AI with the sole intent to infringe constitutional rights.
  • § 552.056 — Unlawful discrimination. The one you care about. Covered in detail below.

Notice the pattern. Four of the six are aimed at government or at genuinely extreme conduct. The statute reaches private employers in two places: the discrimination provision and, indirectly but importantly, biometrics.

Source reference: Texas Legislature, C.S.H.B. 149 bill analysis (89R)

The Employment Provision, and Why It Is Narrower Than You Were Told

Section 552.056(b) prohibits a person from developing or deploying an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law.

Then subsection (c) does something unusual, and it is the single most important sentence in this statute for HR purposes:

"For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate."

— Tex. Bus. & Com. Code § 552.056(c)

Sit with that for a second, because it is the opposite of what most people assume an AI discrimination law does.

The entire policy anxiety around hiring algorithms is a disparate impact anxiety. Nobody seriously worries that an employer buys a resume screener intending to exclude women. The worry is that a tool trained on twenty years of a company's own hiring data learns that company's historical preferences and reproduces them at scale, with nobody intending anything at all. That is the textbook disparate impact scenario, and TRAIGA's discrimination provision expressly declines to reach it on impact evidence alone.

So TRAIGA is not your AI hiring compliance framework. Which raises the obvious question.

Then what is your actual exposure?

Everything that was already there. Title VII's disparate impact framework did not change on January 1. Neither did the ADA's rules on medical inquiry and accommodation, which is where video-interview and game-based assessment tools live dangerously. Neither did the ADEA. Neither did the Texas Commission on Human Rights Act. The EEOC has taken the position for years that an employer is responsible for a selection procedure it uses, including one a vendor built.

Here is how I put it to clients, and I will put it to you the same way: TRAIGA changed almost nothing about your AI hiring risk. It just made everyone look at it for the first time. That attention is the useful part. Do not waste it on the wrong statute.

The question that actually matters

Forget the statute for a moment. If an applicant's attorney asked you to explain the job-related basis for rejecting their client, could you? Not "the system scored them low." The job-related basis. If the honest answer is that nobody at your organization can explain what the tool measured or why it correlates with performance in that role, you have a problem that predates TRAIGA by about sixty years and will outlive it.

Where the Teeth Actually Are: Biometrics

This is the part the employment-focused coverage mostly skipped, and it is where I would spend your first hour.

TRAIGA did not just create new chapters. Section 2 of HB 149 amended CUBI — the Capture or Use of Biometric Identifier Act at Business & Commerce Code § 503.001 — and CUBI has real money attached: a civil penalty of up to $25,000 per violation, enforced by the attorney general.

Two amendments matter operationally.

First, the "it was on the internet" defense is dead. New subsection (b-1) provides that an individual has not consented to capture or storage of a biometric identifier based solely on the existence of an image containing it on the internet or another publicly available source — unless that individual is the one who made it public. If a vendor tells you their identity-verification model was trained on publicly available images, that sentence is now directly relevant to them.

Second, there is a training carve-out with a trapdoor. Amended subsection (e) exempts biometric identifiers involved in developing or training AI models — unless the system is used or deployed to uniquely identify a specific individual. And new subsection (f) provides that if a biometric identifier captured for training purposes is later used for a commercial purpose outside that carve-out, the possessor becomes subject to CUBI's possession, destruction, and penalty provisions.

Now put that next to what is actually in your building. Fingerprint or hand-geometry time clocks. Facial recognition on door access. Voiceprint authentication in a call center. Video interview platforms doing facial analysis. Body-worn cameras with any analytic layer. Every one of those touches biometric identifiers, and biometric consent is where I find the most unmanaged exposure when I audit a Texas employer.

Source reference: Texas Attorney General, Biometric Identifier Act

If You Are a City: More Duties, Less Authority

Public employers get a different deal, and it runs in both directions.

More duties. The disclosure obligation in § 552.051, the social scoring prohibition in § 552.053, and the biometric identification prohibition in § 552.054 are all aimed at government. If your city has deployed a chatbot on the utility billing page, a resident-facing 311 assistant, or an AI intake tool at the permit counter, the disclosure question is live for you in a way it is not for the private employer across the street. And the statute is explicit that disclosure is required even if it would be obvious to a reasonable person that they are talking to a machine.

Less authority. Section 552.003 provides that the chapter supersedes and preempts any ordinance, resolution, rule, or other regulation adopted by a political subdivision regarding the use of AI systems. A Texas city cannot pass its own AI ordinance. You can and absolutely should adopt internal administrative policy governing your own use — that is management of your operation, not regulation of the public — but the local-regulation door is closed.

An ambiguity worth asking your city attorney about

Section 552.051(b) imposes the disclosure duty on a "governmental agency." Sections 552.053 and 552.054 use "governmental entity," a term that conventionally reaches political subdivisions. Meanwhile the construction section at § 551.003 describes a purpose of providing notice regarding AI use "by state agencies." Whether the consumer disclosure duty reaches municipalities as cleanly as the social scoring and biometric prohibitions do is a question I am not going to answer for you in a blog post. Ask your city attorney, and in the meantime, disclose. The cost of a plain-language notice on your chatbot is approximately zero.

One more thing for cities, and it is a genuine benefit: § 554.102 requires the new Texas Artificial Intelligence Council to conduct training programs for state agencies and local governments on AI use. That is a resource your city is entitled to. Very few have asked for it.

How Enforcement Actually Works — and What September 1 Means

The mechanics matter more than the prohibitions, because they tell you what a bad day actually looks like.

  • The AG has exclusive enforcement authority (§ 552.101(a)), with a narrow role for licensing agencies under § 552.106.
  • There is no private right of action (§ 552.101(b)). No class actions, no plaintiff's bar, no parallel suits.
  • Complaints drive investigations. Under § 552.103, the AG's civil investigative demand authority is triggered by a complaint received through the online mechanism.
  • That mechanism is due by September 1, 2026 under Section 8 of the bill.
  • 60-day notice and cure (§ 552.104) before the AG may bring an action.
  • Rebuttable presumption of reasonable care (§ 552.105(c)), plus a defense where another person misused your system (§ 552.105(e)) and no penalty for a system never deployed (§ 552.105(f)).

So here is what September 1 is and is not. It is not a compliance deadline. TRAIGA has bound you since January 1. Anyone selling you a September 1 deadline is selling you something.

What it is: the date the statute gets a front door. For eight months there has been a law with no intake channel, which is why the AG had not filed a formal TRAIGA enforcement action as of mid-2026. Investigative authority under § 552.103 keys off complaints arriving through the portal. Build the portal, and the complaints have somewhere to land.

The cure period is not the safety net people think it is

"There's a 60-day cure" has been doing a lot of soothing in conference rooms, and it deserves a harder look. Section 552.104(b)(2) requires four things to avoid an action:

  • Actually cure the identified violation;
  • Give the AG a written statement that you cured it;
  • Provide supporting documentation showing the manner in which you cured it; and
  • Make any necessary changes to internal policies to reasonably prevent further violation.

Items three and four are the trap. An organization with no AI inventory, no written policy, and no documentation of who reviewed what cannot produce supporting documentation or demonstrate a policy change — because there was no policy to change. You will spend the 60 days building from zero the thing you should have built in an afternoon last year, under a clock, while a state agency waits.

That is the same lesson as everything else I write about documentation. The paperwork is not the point. The paperwork is the evidence that a system existed.

The TRAIGA Exposure Map

Find your row. Most Texas employers have exposure in exactly two of these and none in the rest.

The TRAIGA Exposure Map. Faulkner HR Solutions. Original framework, 2026. Cite as: Faulkner, T.W. (2026). The TRAIGA Exposure Map. Faulkner HR Solutions.

What you are doing TRAIGA exposure Your bigger exposure What to do about it
AI screens or ranks resumes Low — intent required; disparate impact excluded Title VII, ADA, ADEA, TCHRA disparate impact Document the job-related basis; keep a human decision-maker who can override and explain
AI-scored video or game-based assessment Low under § 552.056 ADA — disability screen-out and accommodation Publish an alternative-format path; get vendor validation evidence in writing
Biometric time clock, door access, voiceprint High — § 552.054 and amended CUBI CUBI, up to $25,000 per violation Written notice and consent before capture; a documented retention and destruction schedule
Facial recognition or image scraping High for governmental entities CUBI § 503.001(b-1) — public availability is not consent Get the vendor's training-data provenance in writing before renewal
Public-facing chatbot (city or health care) Moderate — § 552.051 disclosure Reputational and open-records exposure Clear, plain-language disclosure at or before interaction. No dark patterns.
AI drafting discipline or performance documentation None directly Every wrongful termination theory there is Supervisors verify facts before signing. AI drafts; humans attest.
Staff pasting employee data into public AI tools None directly Confidentiality, PIA exposure, and Ch. 541 data duties Written acceptable-use policy and a sanctioned tool
City considering a local AI ordinance Preempted — § 552.003 Wasted council time Adopt internal administrative policy instead. That is not preempted.

The Operational Version: Five Things, One Afternoon

This is the part the law firm alerts do not write, because it is not legal advice — it is HR operations. None of it requires a lawyer, and all of it is what you would need to satisfy items three and four of the cure provision if the letter ever comes.

  • Inventory what you actually have. Not what you bought — what is running. The AI features your existing vendors switched on without asking are the ones nobody has looked at. Name, vendor, department, internal owner, whether a human reviews the output.
  • Send your ATS vendor three questions in writing. Does the system score, rank, or filter applicants, and on what features? Has it been validated for job-relatedness, and can you produce the study? What biometric data, if any, does it capture or process, and what is the training-data provenance? Get the answers in email. The email is the documentation.
  • Fix biometric consent first. Of everything on this list, the time clock is most likely to be non-compliant and carries the clearest per-violation penalty. Written notice, written consent, documented retention and destruction.
  • Write one page of AI acceptable-use policy. What tools are sanctioned, what data may never be entered, who reviews AI output before it becomes a decision, and the rule that a human signs every employment action. One page beats no pages by an enormous margin.
  • Put a human decision standard in writing for every AI-influenced employment decision. This is the one that protects you under the statutes that actually reach you, which are the federal ones.

If you want a structured version of this, we publish a TRAIGA readiness checklist that walks the same ground — tool inventory, use-case classification, human review and decision authority, employment and HR risk, biometrics. It is free, it takes about twenty minutes, and it is a first-pass review tool rather than a substitute for legal advice.

And I will say the quiet part, as usual. Most of the organizations that call me about AI compliance do not have an AI problem. They have a documentation problem that AI made visible by scaling it. The tool did not create the inability to explain why a decision was made. It just produced enough decisions fast enough that the inability became impossible to ignore.

Before the Portal Opens
Know What You're Running, and Who Signs Off
Faulkner HR Solutions helps Texas employers and municipalities inventory AI use, fix biometric consent, and put a defensible human decision standard behind every AI-influenced employment action.

Frequently Asked Questions

No. TRAIGA's consumer disclosure duty under Section 552.051 applies to governmental agencies and to health care services, not to private employers in the employment context. There is no TRAIGA requirement that a private Texas employer tell applicants an AI system screened their resume. This is one of the largest differences between TRAIGA and the earlier HB 1709 draft.

No. TRAIGA as enacted contains no bias audit mandate, no algorithmic impact assessment requirement, and no use-case inventory obligation for private employers. Those provisions appeared in the earlier HB 1709 draft and did not survive into HB 149.

Section 552.056 prohibits developing or deploying an AI system with the intent to unlawfully discriminate against a protected class. Subsection (c) states expressly that a disparate impact is not sufficient by itself to demonstrate intent. That makes TRAIGA's discrimination provision considerably narrower than federal employment law, which does reach disparate impact under Title VII.

HB 149 requires the attorney general to post the online complaint mechanism no later than September 1, 2026. That is not a new compliance deadline — TRAIGA has been in effect since January 1, 2026. It is the date the statute acquires a functioning intake channel, because the AG's investigative authority under Section 552.103 is triggered by complaints received through that mechanism.

For violations the court determines to be curable, not less than $10,000 and not more than $12,000 per violation. For uncurable violations, not less than $80,000 and not more than $200,000. For a continuing violation, $2,000 to $40,000 for each day it continues. Licensing agencies may separately impose sanctions up to $100,000 following an AG recommendation.

No. Section 552.101(b) states that the chapter does not provide a basis for, and is not subject to, a private right of action. The attorney general has exclusive enforcement authority, subject to a limited role for licensing agencies. Applicants and employees retain every claim they already had under Title VII, the ADA, the ADEA, and the Texas Commission on Human Rights Act.

No. Section 552.003 provides that the chapter supersedes and preempts any ordinance, resolution, rule, or other regulation adopted by a political subdivision regarding the use of artificial intelligence systems. Cities can and should adopt internal administrative policies governing their own AI use, but they cannot regulate AI use by others within their jurisdiction.

Less than people assume. Curing requires four things under Section 552.104(b)(2): actually curing the violation, giving the AG a written statement that you cured it, providing supporting documentation showing how, and making necessary changes to internal policies to reasonably prevent recurrence. An organization with no documentation and no written AI policy cannot satisfy the third and fourth requirements on a 60-day clock.

A necessary note. I am an HR and organizational consultant, not an attorney, and this article is general information rather than legal advice. Statutory descriptions are drawn from the enrolled text and bill analysis of C.S.H.B. 149, 89th Legislature, and reflect the law as of August 2026. AI regulation is moving quickly at both the state and federal level — verify current status before relying on any of it, and route specific questions to your employment counsel or city attorney. What I can tell you is which drawers to open first.

About the Author
Dr. Thomas W. Faulkner
Principal Consultant & Founder, Faulkner HR Solutions

Dr. Faulkner brings over 15 years of strategic HR experience to Texas municipalities, nonprofits, and growing businesses. A U.S. Army veteran, his doctoral research focused on professional development frameworks in public sector organizations. He holds the SPHR, Lean Six Sigma Black Belt, and dual master's degrees in Business Administration and Leadership.

SPHR Certified Doctorate — Org. Leadership Lean Six Sigma Black Belt U.S. Army Veteran
AI Made the Gap Visible
Fix the Decision System, Not Just the Software
Faulkner HR Solutions helps Texas employers build the documentation and human decision standards that hold up under any statute — the ones that existed before TRAIGA and will outlast it.