TEXAS AI REPORT
Reference

AI Governance Glossary

Plain-English definitions of the terms that come up most in Texas and U.S. AI law.

AI system

Under TRAIGA (HB 149), any machine-based system that, for explicit or implicit objectives, infers from its inputs how to generate outputs — content, decisions, predictions, or recommendations — that can influence physical or virtual environments. Most enterprise AI deployments fit this definition.

AIGP

The IAPP AI Governance Professional certification — a professional credential in AI governance and compliance.

Civil Investigative Demand (CID)

A tool the Texas Attorney General can issue under TRAIGA (§ 552.103) requiring an entity to produce AI-system descriptions, intended use, training-data categories, inputs and outputs, performance metrics, known limitations, and monitoring records.

Colorado SB 26-189

Colorado’s repeal-and-replace AI law, signed May 14, 2026, that scrapped the original Colorado AI Act (SB 24-205). It uses a disclosure-and-consumer-rights model with no impact assessments, covers seven domains, and takes effect January 1, 2027.

Consequential decision

A decision that materially affects a person — in areas such as employment, lending, housing, insurance, healthcare, or government services. It is the trigger concept in disclosure-and-rights regimes such as Colorado’s SB 26-189.

Curable vs. uncurable violation

TRAIGA’s penalty tiers turn on this line: $10,000–$12,000 for curable violations versus $80,000–$200,000 for uncurable ones. The statute does not define the distinction — it will be drawn by early enforcement and common law.

Cure period

The 60-day window an entity has, after receiving a TRAIGA notice of violation, to fix the violation and submit a written explanation of the cure and any policy changes. In practice a violation notice can function like a cease-and-desist.

Developer vs. deployer

The common AI-law distinction between the entity that builds an AI system (developer) and the entity that puts it to use (deployer). TRAIGA includes a third-party-misuse carve-out: a developer or deployer is not liable simply because an end user uses a system for a prohibited purpose.

DIR regulatory sandbox

A TRAIGA program administered by the Texas Department of Information Resources allowing up to 36 months of AI development and testing without separate state licensing, with AG enforcement paused for waived requirements. TRAIGA’s four core prohibitions still apply during participation.

Disclosure duty

TRAIGA’s requirement to tell consumers when AI is involved. Government agencies must disclose before or at the time of interaction; healthcare providers must disclose AI use in treatment on the date of service. Private non-healthcare businesses carry no consumer-facing disclosure duty.

EU AI Act

The European Union’s risk-based, tiered AI regulation. In force since August 1, 2024 and phased in: prohibited practices since February 2, 2025; GPAI model rules since August 2, 2025; most high-risk obligations from August 2, 2026. Penalties reach €35 million or 7% of global annual turnover.

High-risk AI system

In risk-based regimes such as the EU AI Act, systems used in sensitive domains that face the strictest obligations (impact assessments, conformity assessments). Note: TRAIGA is not risk-tiered — it targets intent rather than risk category.

Intentional unlawful discrimination

Under TRAIGA, a discrimination violation requires intent. Disparate impact alone is insufficient — distinguishing TRAIGA from risk-based regimes that police discriminatory outcomes regardless of intent.

NIST AI RMF safe harbor

An explicit TRAIGA affirmative defense: an entity that conducts internal review under the NIST AI Risk Management Framework — alongside red-teaming, adversarial testing, or following state agency guidance — gains protection against enforcement.

Private right of action

The ability of individuals to sue directly under a statute. TRAIGA provides none; enforcement belongs exclusively to the Texas Attorney General. Colorado’s SB 26-189 and the EU AI Act likewise create no private right of action.

Prohibited use

TRAIGA’s universal bans, which apply to every covered entity: deploying AI with intent to manipulate users toward self-harm or crime, infringe constitutional rights, commit intentional unlawful discrimination, or generate unlawful deepfakes or child sexual content. Government entities face two more: AI social scoring and biometric identification without consent.

Texas Artificial Intelligence Council

A seven-member body appointed by the governor, lieutenant governor, and speaker of the House, administratively attached to DIR, that oversees the regulatory sandbox and AI policy recommendations.

TRAIGA

The Texas Responsible Artificial Intelligence Governance Act (House Bill 149) — Texas’s first comprehensive AI law. Signed June 22, 2025; effective January 1, 2026. It sets universal prohibited uses, layers disclosure duties on government agencies and healthcare providers, and gives the Texas Attorney General exclusive enforcement with penalties up to $200,000 per uncurable violation.


These definitions restate facts from our reporting and are analysis, not legal advice. See the TRAIGA Guide, the Texas AI Law Tracker, and the scope checker.