Texas Bar Journal • September 2025

The Legislative Update

Technology Law

Written by Shawn Tuma and Christine Chasse

Texas Responsible Artificial Intelligence Governance Act (TRAIGA)

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), HB 149,1 is one of the most important bills from this legislative session. It establishes a comprehensive framework for the ethical development, deployment, and use of artificial intelligence (AI) systems in Texas. Effective January 1, 2026, the law seeks to balance responsible innovation with protections for individuals and groups against risks associated with AI technologies.

TRAIGA applies to individuals and entities that develop, deploy, or market AI systems in Texas or provide AI-powered products or services to Texans. However, certain entities are exempt, including financial institutions retaining voiceprint data, those using biometric data for non-identifying purposes, and entities employing AI for security, fraud prevention, or law enforcement purposes.

The law emphasizes transparency and accountability in AI use. It requires clear disclosures when consumers interact with AI systems and grants individuals the right to appeal AI-driven decisions that significantly impact health, safety, or basic rights. Developers and deployers must ensure their systems avoid manipulative outcomes, unlawful discrimination, and harm to individuals or groups.

TRAIGA prohibits several harmful uses of AI, including:

  • Government use of AI for social scoring or biometric surveillance without consent.

  • The creation or distribution of AI-generated child exploitation material or explicit deepfakes.

  • Developing or deploying an AI system with the intentional aim of inciting or encouraging a person to commit self-harm, criminal activity, or discrimination against protected classes.

TRAIGA introduces several innovative mechanisms to support ethical AI development while fostering innovation:

  1. Regulatory Sandbox Program: Entities can test AI systems under relaxed regulations for up to 36 months, allowing for experimentation and refinement without full compliance burdens. Participants must submit quarterly reports to the Department of Information Resources (DIR) detailing system performance, risk mitigation efforts, and stakeholder feedback.

  2. Texas Artificial Intelligence Council: This council will oversee AI ethics, public safety, and innovation, ensuring that AI governance aligns with the state’s broader policy goals.

  3. Enforcement and Penalties: The Office of the Texas Attorney General has exclusive enforcement authority under TRAIGA. Violations can result in penalties ranging from $10,000 to $200,000, depending on the severity of the infraction.

Cybersecurity Program Safe Harbor for Small Businesses

The Texas Cybersecurity Program Safe Harbor Law, SB 2610,2 limits the civil liability of small businesses in Texas in connection with data breaches if they comply with its requirements. Effective September 1, 2025, the law applies exclusively to businesses with fewer than 250 employees that own or license computerized data containing sensitive personal information. The law does not create a private cause of action or alter existing legal duties.

To qualify for protection, businesses must implement and maintain a cybersecurity program that meets specific requirements. These programs must include administrative, technical, and physical safeguards to protect sensitive personal information. They must also conform to recognized cybersecurity frameworks, such as the NIST Cybersecurity Framework, ISO/IEC 27000 standards, or other industry- recognized frameworks. The law scales requirements based on business size: businesses with fewer than 20 employees must adopt simplified measures like password policies and employee training, while those with 100 to 250 employees must comply with more comprehensive standards.

The law prohibits the recovery of exemplary damages in lawsuits related to data breaches if the business demonstrates compliance with its cybersecurity program at the time of the breach. However, it does not shield businesses from other forms of liability or damages.

Key features of the law include its focus on incentivizing small businesses to adopt robust cybersecurity measures, its alignment with industry standards, and its tiered approach to compliance based on business size. By providing a safe harbor from exemplary damages, the law encourages proactive cybersecurity practices while balancing the regulatory burden on small businesses.

Texas Cyber Command

A new state agency was also created through HB 150, which establishes the Texas Cyber Command (TCC),3 a state agency housed in San Antonio, to centralize cybersecurity oversight and incident response. Effective September 1, 2025, the TCC assumes responsibilities from the Texas Department of Information Resources (DIR), including threat detection, digital forensics, and training for state agencies, local governments, and critical infrastructure sectors like energy, healthcare, and finance. It will also maintain a 24/7 cyber incident hotline and leverage university research to enhance its mission.

AI Training for Public Sector Employees

The Texas Artificial Intelligence Training Act, HB 3512,4 effective September 1, 2025, mandates annual AI training for state and local government employees who use computers for at least 25% of their duties, including cybersecurity coordinators who must complete both AI and cybersecurity training. The law applies to state agencies, local governments, and school districts, requiring local governments to certify compliance to qualify for grants, with penalties for noncompliance. The Department of Information Resources (DIR) will certify AI training programs and publish an annual list of approved programs, ensuring training aligns with state standards and supports responsible AI use across public sector organizations.

AI Transparency and Risk Standards for Public Sector

In an effort to address concerns with AI use, SB 19645 introduces a comprehensive framework for the use and oversight of artificial intelligence (AI) by Texas state agencies and local governments. Effective September 1, 2025, the bill defines key AI terms and establishes a tiered classification system, including “heightened scrutiny” for AI systems that autonomously influence critical decisions, such as benefit eligibility or licensing.

State agencies must inventory their AI systems, assess associated risks, and include this information in IT strategic planning. Local governments must evaluate high-risk AI systems and share findings with DIR upon request. DIR, which gains rulemaking authority and 10 new employees, will oversee compliance and develop a state AI code of ethics.

App Store Parental Controls and Data Privacy for Minors aka the App Store Accountability Act

Regulations were also applied to minors making app store purchases. Effective January 1, 2026, SB 24206 creates a regulatory framework to protect minors from unauthorized digital purchases and inappropriate content. Mobile app stores must categorize users into four age groups (children under 13, younger teenagers 13 to 15, older teenagers 16 to 17, and adults 18 or older), implement age verification systems, and
obtain explicit parental consent for app downloads and in-app purchases by minors. Developers must disclose content ratings and data practices. While no government oversight agency is established, violations are classified as deceptive trade practices.

Creation of the Texas Strategic Bitcoin Reserve

A new reserve was created in Texas through SB 21,7 establishing the Texas Strategic Bitcoin Reserve, a state- managed fund overseen by the Texas Comptroller of Public Accounts. Effective June 20, 2025, the reserve is authorized to invest in cryptocurrencies with a market cap of at least $500 billion, effectively limiting investments to Bitcoin (and potentially Ethereum). Its purpose is to diversify the state’s financial portfolio and hedge against inflation and economic volatility. To ensure transparency, the comptroller must publish a biennial report detailing the reserve’s holdings, valuation changes, and administrative actions.

Regulating AI-Generated Explicit Content

Several bills address the growing threat of AI-generated sexually explicit content, particularly deepfakes:

  • Platform Takedown Requirements for Explicit Deepfake Content. HB 31338 requires social media platforms to establish complaint procedures for reporting AI-generated explicit deepfake content. The bill defines such material as visual material depicting real individuals in sexual scenarios or other conduct resulting in the exposure of the person’s intimate parts, created with intent to deceive. HB 3133 is effective September 1, 2025.

  • Criminal and Civil Penalties for AI-Generated Deepfake Pornography. SB 4419 expands criminal and civil liability for creating, distributing, or promoting AI- generated explicit content without consent. First-time offenses are Class A misdemeanors, with harsher penalties for repeat offenses or cases involving minors. SB 441 is effective September 1, 2025.

  • Age and Consent Verification for AI-Generated Sexual Content. HB 58110 addresses the growing threat of non-consensual, AI-generated sexually explicit material by mandating age and consent verification for websites or applications capable of generating AI-based explicit content, particularly deepfakes involving minors. HB 581 is effective September 1, 2025.

New Technology and Cybercrimes and Cyber Liabilities

Several bills address emerging cybercrimes and cyber liabilities:

  • Online impersonation. HB 78311 establishes civil liability for online impersonation, including using an individual’s name, voice, or likeness on social media without consent. For minors, guardian consent is required. HB 783 is effective September 1, 2025.

  • Doxxing Public Servants. HB 342512 criminalizes the unlawful disclosure of a public servant’s residence address or phone number, extending protections to their families and households. HB 3425 is effective September 1, 2025.

  • AI-Powered Phishing and Fraud. SB 237313 targets financial exploitation using AI-generated media or phishing communications. Offenses range from Class B misdemeanors to first-degree felonies. The law allows courts to award damages, including mental anguish and attorneys’ fees, and issue restraining orders to prevent further dissemination of harmful content. SB 2373 is effective September 1, 2025.

Notes

  1. Tex. Bus. & Comm. Code § 503.001.

  2. Tex. Bus. & Comm. Code Ch. 542.

  3. Tex. Gov’t Code § 2063.002.

  4. Tex. Educ. Code § 11.175 (h – 1).

  5. Tex. Gov’t Code § 2054.601.

  6. Tex. Bus. & Comm. Code § 121.

  7. Tex. Gov’t Code § 403.701.

  8. Tex. Bus. & Comm. Code § 120.1001.

  9. Tex. Penal Code §21.165.

  10. Tex. Civ. Prac. & Rem. Code §129B.001.

  11. Tex. Civ. Prac. & Rem. Code §98C.

  12. Tex. Penal Code §36.06(a-1) and (d).

  13. Tex. Penal Code §32.56.


shawn tumaSHAWN TUMA an attorney widely recognized in data, privacy, and cyber law, areas in which he has practiced for over two and a half decades. He is a past chair of the State Bar of Texas Computer & Technology Section and co-chair of the Cyber, Data, and AI Practice at Spencer Fane, where he is managing partner of the firm’s Collin County office.

christine chasseCHRISTINE CHASSE is a certified information privacy professional (CIPP/US) and AI governance professional (AIGP). She has also been a registered nurse since 2009. Chasse is an associate of Spencer Fane and member of both the Cyber, Data, and AI Practice and Healthcare Practice Groups, where she works primarily in the firm’s Collin County office.