Texas's AI regulatory sandbox, established under the Texas Responsible AI Governance Act (TRAIGA) — enacted by the Texas Legislature as H.B. 149 — creates a structured pathway for AI developers and deployers to operate under regulatory relief while the broader compliance framework is still taking shape. If you're evaluating whether to participate, the three questions that actually matter are: do you qualify, what does the protection period cover, and what are you agreeing to report every quarter?
I'll work through each of those in order, because the answers are specific enough that a general overview won't get you far.
What Is the Texas AI Sandbox, and Why Does It Exist?
The sandbox is administered by the Texas Department of Information Resources (DIR). Its purpose is to give companies a defined space to test AI systems that might otherwise trigger compliance obligations under TRAIGA before those systems are fully mature or before the regulatory guidance has caught up with the technology.
That's a reasonable trade from the state's perspective. Texas gets visibility into how AI systems behave in live deployments, through mandatory reporting, and companies get a window to iterate without facing enforcement action for technical non-compliance. The underlying assumption is that responsible AI development benefits from regulatory feedback loops rather than regulatory avoidance, and the sandbox is the mechanism Texas chose to create that loop.
It's worth noting that the sandbox framework sits alongside, not above, federal AI governance obligations. Participating in the Texas sandbox does not suspend any applicable federal requirements, including sector-specific rules under the FDA, FTC, or financial regulators. That distinction matters more than most applicants initially realize.
Who Qualifies for the Texas AI Sandbox?
Eligibility is not automatic. TRAIGA's sandbox provisions require an applicant to meet several criteria before DIR will accept an application.
Core eligibility requirements:
- The applicant must be developing or deploying an AI system that would otherwise be subject to TRAIGA's prohibited-practice provisions — for example, manipulative or deceptive AI, government-style social scoring, unauthorized biometric identification, unlawful discrimination, or CSAM/deepfake generation.
- The AI system must be in a testing or limited-deployment phase. Fully commercialized systems operating at scale are generally not eligible.
- The application must include a benefit assessment addressing the AI system's impact on consumer privacy and public safety.
- The application must include a risk mitigation plan, including a documented plan for monitoring the AI system's outputs and impacts during the sandbox window.
- The application must include evidence of the applicant's compliance with applicable federal AI laws.
DIR has discretion to approve or deny applications based on these criteria, and that discretion is meaningful. Companies that apply with thin documentation or without a credible compliance roadmap are going to have a harder time.
The application itself is a signal. The DIR staff reviewing these applications will look at whether your documentation reflects an organization that actually understands the risks its AI system poses. Vague descriptions of "machine learning capabilities" paired with a generic privacy policy will not read as a serious compliance posture. Specificity about your system's decision-making scope, the populations it affects, and the failure modes you've identified will.
Who Is Likely NOT a Good Fit
Companies whose AI systems are already fully deployed to Texas consumers at scale should not expect sandbox admission to function as retroactive compliance coverage. Similarly, organizations in highly regulated sectors (healthcare, financial services, education) need to think carefully about whether the sandbox actually reduces their total compliance burden given the federal overlay that remains in place regardless.
The Qualification Table: A Quick-Reference Breakdown
| Criterion | Likely Qualifies | Likely Does NOT Qualify |
|---|---|---|
| Deployment stage | Testing / limited pilot / early commercial | Fully scaled, mass-market deployment |
| TRAIGA exposure | System's conduct would otherwise fall under TRAIGA's prohibited-practice provisions | System falls outside TRAIGA's scope entirely |
| Compliance intent | Written roadmap to full compliance | No defined post-sandbox compliance plan |
| Monitoring capability | Documented output monitoring protocol | No monitoring infrastructure in place |
| Regulatory history | Clean or disclosed minor issues | Material prior violations |
| Sector overlay | Single-regulator environment | Multi-regulator environment with federal mandates that sandbox cannot touch |
What Does the 36-Month Window Actually Buy You?
This is where applicants sometimes build an incorrect mental model of what the sandbox does. The 36-month period provides regulatory relief from specific TRAIGA enforcement actions related to the approved AI system. It does not provide immunity from liability for harms caused by that system, and it does not provide relief from obligations that arise under other Texas statutes or federal law. TRAIGA's core prohibited practices — manipulative or deceptive AI, government-style social scoring, unauthorized biometric identification, unlawful discrimination, and CSAM or deepfake generation — remain fully enforceable against sandbox participants regardless of enrollment. The sandbox suspends enforcement actions tied to the approved system's specific conduct; it does not suspend the underlying prohibitions themselves.
Within the sandbox period, DIR commits to:
- Refraining from initiating enforcement actions under TRAIGA against the approved AI system for conduct within the scope of the sandbox approval.
- Providing regulatory guidance and feedback to the participant based on the quarterly reports.
- Working collaboratively with the participant toward full compliance before the sandbox period ends.
What that means practically is that you get 36 months to iterate your AI system, collect real-world performance data, and build out your compliance infrastructure with DIR watching and advising rather than citing. That's genuinely valuable if your system is in genuine development. It's less valuable if your system is mature and your real compliance gap is governance documentation rather than technical readiness.
The sandbox period also does not automatically renew. At the 36-month mark, an entity is expected to either be in full compliance with TRAIGA's applicable requirements or to have filed for and received an extension, which DIR may grant under limited circumstances. Companies that treat the sandbox as a 36-month delay rather than a 36-month runway tend to find themselves in a worse position at the end of it, not a better one.
What You Should Be Building During the 36 Months
A sandbox period is not a compliance holiday. The companies that get the most out of it are the ones that treat the DIR feedback loop as a design input rather than an audit. Concretely, that means:
- Using the first two quarters to establish baseline performance metrics for the AI system across the populations it affects.
- Using quarters three through six to stress-test the system against TRAIGA's prohibited-practice provisions, including requirements around impact assessments and bias evaluation.
- Using the back half of the sandbox period to build the governance documentation that full compliance will require: risk assessments, human oversight protocols, incident response procedures.
If you've also been working toward ISO 42001:2023 certification during this window, the sandbox period aligns well with the implementation timeline that standard requires. ISO 42001:2023 clause 6.1.2 specifically addresses AI risk assessment processes, and the outputs of that process map directly onto what DIR will expect to see in your quarterly reports. For companies already pursuing ISO 42001, the ISO 42001 gap assessment is a reasonable starting point for understanding where your documentation currently stands.
The Quarterly Reporting Obligation: What It Costs You
The sandbox is not free. The price of admission is ongoing transparency, and that transparency takes the form of quarterly reports submitted to DIR. Understanding what those reports must contain is essential before you decide whether the trade is worth it.
TRAIGA's sandbox provisions require quarterly reports to include:
- Performance metrics. Quantitative data on system performance across key metrics defined in the sandbox approval, including accuracy, error rates, and bias indicators where applicable.
- Risk mitigation measures. An account of how the risk mitigation plan submitted with the application is being implemented, including any updates made in response to issues identified during the reporting period.
- Consumer and stakeholder feedback. A summary of feedback collected from consumers, users, or other affected stakeholders regarding the AI system's performance and impact.
The operational cost of meeting these requirements is meaningful. Producing a credible quarterly report requires that you have logging infrastructure, incident tracking, and performance monitoring in place from day one of the sandbox period. Companies that try to reconstruct three months of performance data at the end of a quarter are going to produce reports that reflect that, and DIR will notice.
The quarterly report is also where your sandbox protection becomes contingent. DIR retains the right to revoke sandbox participation for materially incomplete or inaccurate reporting, or for failure to report incidents within required timeframes. The sandbox is a relationship, and the quarterly report is the mechanism through which that relationship stays functional. Treat it accordingly.
Sandbox vs. Full TRAIGA Compliance: Comparing the Two Paths
| Factor | Sandbox Participation | Full Compliance from Launch |
|---|---|---|
| Timeline | 36-month protected window | Ongoing from deployment |
| Enforcement exposure | Reduced (within sandbox scope) | Standard enforcement applies |
| Reporting burden | Quarterly reports to DIR | Periodic compliance documentation |
| Flexibility to iterate | High — system changes permitted with disclosure | Lower — changes may require reassessment |
| DIR relationship | Collaborative, advisory | Standard regulatory relationship |
| Post-period obligation | Full compliance required at 36 months | Already in compliance |
| Best suited for | Early-stage or mid-development AI systems | Mature systems with existing compliance infrastructure |
How the Sandbox Interacts with ISO 42001
This is a pairing that doesn't get discussed enough. ISO 42001:2023 is the international standard for AI management systems, and its structure maps well onto what TRAIGA's sandbox requires companies to build during the 36-month window. The standard's requirements for AI risk treatment (clause 6.1.3), performance evaluation (clause 9.1), and incident management align closely with the quarterly reporting categories DIR has established.
That alignment means companies pursuing ISO 42001 certification during the sandbox period are essentially building two compliance artifacts simultaneously. The risk register you develop for ISO 42001 becomes source material for your quarterly DIR reports. The incident response procedure you document for the standard becomes the framework for the adverse outcome disclosures the sandbox requires.
Treating ISO 42001 and TRAIGA compliance as separate workstreams tends to create redundant effort. For organizations deploying AI in Texas while also selling into regulated markets that increasingly recognize ISO 42001, it's worth evaluating whether a unified implementation makes more sense, using the risk register and incident response procedure each framework already requires as the shared foundation.
Practical Considerations Before You Apply
The sandbox application deadline and intake process are managed by DIR, and the agency has indicated that it will prioritize applications that demonstrate a clear public benefit from the AI system alongside the technical and governance documentation. That framing matters. An application that positions the AI system purely in commercial terms, without articulating the benefit to Texas residents or consumers, is less likely to land well.
A few things I'd verify before submitting:
- Confirm that your AI system's functionality would actually trigger one of TRAIGA's prohibited-practice provisions. If it doesn't, your system may not be subject to TRAIGA in the first place, which means the sandbox doesn't provide meaningful relief.
- Map your current monitoring infrastructure against the quarterly reporting requirements before you apply. If you can't generate the reports at the level of detail DIR requires, the sandbox will create compliance obligations you're not ready to meet.
- Think about what full compliance looks like at 36 months and work backward. The sandbox is most useful when you know where you're trying to end up.
Frequently Asked Questions
Who administers the Texas AI regulatory sandbox?
The Texas AI regulatory sandbox is administered by the Texas Department of Information Resources (DIR) under the Texas Responsible AI Governance Act (TRAIGA), as amended by H.B. 149.
Does participating in the Texas AI sandbox suspend federal AI compliance requirements?
No. The Texas sandbox provides relief only from specific TRAIGA enforcement actions. Federal requirements from agencies such as the FDA, FTC, or financial regulators remain fully applicable to sandbox participants.
What triggers mandatory disclosure in a quarterly sandbox report?
Any incident where the AI system produced an output that caused or could have caused material harm to a Texas resident must be disclosed in the quarterly report, along with corrective actions taken.
Can a fully deployed, mass-market AI system qualify for the Texas sandbox?
Generally no. The sandbox is designed for AI systems in testing or limited-deployment phases. Systems already operating at full commercial scale are unlikely to meet DIR's eligibility criteria.
How does ISO 42001 relate to Texas sandbox reporting obligations?
ISO 42001:2023's requirements for AI risk treatment (clause 6.1.4), performance evaluation (clause 9.1), and incident management align closely with the quarterly reporting categories DIR requires from sandbox participants. Companies pursuing both can often build a unified documentation set that satisfies both frameworks simultaneously.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.