Texas HB 149 — the Texas Responsible AI Governance Act, or TRAIGA — was signed in June 2025 and takes effect January 1, 2026. If your organization uses AI systems in Texas and the Attorney General's office sends written notice of an alleged violation, you have 60 days under Texas Business & Commerce Code § 552.104 to cure before civil penalties can attach. That window sounds workable until you understand what "cured" actually requires — and what the penalty exposure looks like if you miss it.
The statute draws a hard line between curable and uncurable violations. Under Texas Business & Commerce Code § 552.105(a), curable violations carry penalties in roughly the $10,000–$12,000 range; uncurable violations jump to roughly $80,000–$200,000, with continuing violations adding $2,000–$40,000 per day. (See law-firm analyses of the enacted statute by Baker Botts and Norton Rose Fulbright, both published following the June 2025 signing.) That penalty structure is the single most important thing to understand about the cure period. TRAIGA is explicit about which violations can and cannot be cured. Conflating them is expensive.
The second thing to understand: the 60-day period is a protection for companies that were already doing the work — not a starting gun for companies that weren't.
What Kind of Law TRAIGA Actually Is
This matters for cure readiness because a lot of guidance circulating about TRAIGA describes a different bill than the one that was signed.
Earlier drafts of the legislation followed a Colorado/EU AI Act template: developer and deployer tiers, mandatory impact assessments, ongoing risk management obligations, consumer disclosure rights. That structure did not survive to enactment. The final HB 149, as analyzed by Norton Rose Fulbright and Baker Botts, is an intent-based prohibited-practices statute. It prohibits specific AI-related conduct — deploying systems with the intent to discriminate, deceive, or manipulate — rather than imposing a general compliance framework of assessments and disclosures.
That distinction shapes everything about cure readiness. You are not building a compliance program to satisfy a checklist of affirmative obligations. You are building documentation that demonstrates your AI practices do not constitute prohibited conduct — and, when enforcement arrives, that you moved promptly to remedy whatever the AG's office identified.
There is one important safe harbor worth understanding: substantial alignment with the NIST AI Risk Management Framework (NIST AI RMF 1.0, published January 2023) functions as an affirmative defense under TRAIGA. The RMF is not a mandate imposed by the statute. It is a shield available to companies that can demonstrate they used it. That distinction — shield, not requirement — should drive how you invest your compliance resources.
Curable vs. Uncurable: The Distinction That Drives Everything
Before thinking about what to prepare, you need to know which category your potential exposure falls into — the three penalty tiers below come from Texas Business & Commerce Code § 552.105(a) — because the cure period only helps with one of them.
| Violation Type | Penalty Range | Cure Available? |
|---|---|---|
| Curable violations (e.g., operational deficiencies, missing procedures) | ~$10,000–$12,000 | Yes — 60-day cure period applies |
| Uncurable violations (e.g., intentional prohibited conduct) | ~$80,000–$200,000 | No |
| Continuing violations | +$2,000–$40,000/day | Stops accruing on cure for curable violations |
The cure period is specifically designed for situations where a business was doing something wrong operationally — not situations where the AG's office concludes the conduct was intentional prohibited behavior. If your AI system was deployed with the intent to discriminate or deceive, the 60-day window does not protect you. The penalty scale for uncurable violations reflects that.
This is why documentation of intent and governance matters so much. A company that can show it built governance processes around its AI systems, monitored them for disparate outcomes, and responded to problems when they emerged is in a fundamentally different position than one that cannot.
What the Cure Window Actually Requires You to Produce
Cure is not defined in general terms in the statute — under Texas Business & Commerce Code § 552.104(b), it is defined relative to the specific violation alleged in the AG's notice, and requires a written statement describing how the violation was cured, supporting documentation, and any policy changes made to prevent recurrence. If the notice identifies a deficiency in how your AI system operates, the cure means demonstrating that the deficiency has been corrected and that the practices producing it have changed. Both the symptom and the system that produced it have to be addressed.
That sets a high bar. Here is what being in a position to meet it looks like in practice.
An Honest Inventory of What AI Systems You Have
You cannot document compliance for systems you have not catalogued. Every AI system your organization deploys for decisions that touch Texas consumers needs to be identified and assessed for potential TRAIGA exposure — particularly systems involved in employment, financial services, healthcare, housing, or similar high-stakes domains. This inventory does not have to be elaborate. It has to be current, scoped correctly, and honest about what your systems actually do.
The inventory is foundational because it drives everything else. Companies that have one can update it and respond to a notice with specificity. Companies that have not built one are starting from scratch in a compressed window, while simultaneously trying to understand the notice they just received.
Documentation Showing AI Systems Are Not Being Used for Prohibited Purposes
Because TRAIGA is an intent-based statute, the most valuable documentation you can hold is evidence that your AI systems were deployed and monitored with legitimate, non-discriminatory, non-deceptive purposes — and that your governance structure would have caught and flagged prohibited conduct before it became a violation.
This means governance meeting records, documented review cycles, any bias or outcome audits you have run on your systems, escalation records for anomalies, and vendor representations about the systems you deploy but did not build. None of this is exotic. All of it takes time to build up. A company that starts this documentation in response to a notice is building a retrospective record that looks like what it is.
Evidence of NIST AI RMF Alignment (If You Want the Affirmative Defense)
The NIST AI RMF affirmative defense is genuinely valuable, but claiming it requires you to actually demonstrate alignment — not just gesture at it. The RMF's four core functions are Govern, Map, Measure, and Manage. Each has practices and outcomes that can be documented. If your organization is going to rely on this defense, you need artifacts showing real implementation: a governance structure (Govern), a documented understanding of your AI risks and context (Map), ongoing monitoring (Measure), and response procedures (Manage).
Organizations that implemented ISO 42001:2023 before TRAIGA took effect are well-positioned here. ISO 42001 clause 6.1.2 requires organizations to assess AI-related risks and determine appropriate responses. Clause 8.4 addresses AI system impact assessments. Clause 9.1 covers performance evaluation and monitoring. These are not one-to-one TRAIGA requirements, but companies with a functioning ISO 42001 management system have produced most of the documentation artifacts that NIST AI RMF alignment requires — which means they have the affirmative defense infrastructure largely in place. Certify Consulting's ISO 42001 gap assessment is designed to give organizations a clear read on where they actually stand before enforcement questions arise.
Vendor Contract Review
If you deploy AI systems built by third parties, your deployer exposure does not disappear because you did not write the model. TRAIGA applies to deployers, not just developers. That means your vendor contracts need to give you access to information about how the systems work, what their known limitations are, and how material changes will be communicated — because if a violation involves a system your vendor controls, your cure may require cooperation your contract does not guarantee. AI vendor contract review is one of the highest-leverage compliance activities you can do before enforcement begins.
A Pre-Notice Preparation Checklist
| Preparation Item | Lead Time Estimate | Why It Matters for Cure |
|---|---|---|
| AI system inventory (all systems touching Texas consumers) | 2–4 weeks | Foundation for all other documentation |
| Governance records (meeting notes, review cycles, escalations) | Ongoing; start immediately | Primary evidence against intent-based violations |
| Outcome and bias monitoring records | Ongoing | Demonstrates systems are being watched |
| NIST AI RMF alignment documentation (Govern/Map/Measure/Manage) | 6–12 weeks for substantive build-out | Affirmative defense infrastructure |
| AI vendor contract review | 2–4 weeks | Ensures access to information needed to cure |
| Training records | Ongoing | Shows governance is operational, not aspirational |
| Incident response records | Ongoing | Evidence of proactive management |
Lead times assume dedicated internal resources. Third-party AI deployments may require additional time for vendor cooperation.
What the Cure Period Cannot Fix
The cure window is real protection — but it is not a clean slate.
Cure applies to curable violations. If the AG's office concludes the conduct was intentional prohibited behavior, the 60-day period does not apply and the higher penalty range kicks in. Beyond that, even for curable violations, prospective cure does not automatically resolve questions about historical harm. The AG retains authority to pursue relief for consumers affected by past conduct.
The practical implication is that pre-notice preparation is risk mitigation, not procrastination insurance. A company with good documentation is in a position to respond to a notice by pointing to what already exists, identifying the specific gap the notice names, and using the 60 days to close it. A company starting from zero is trying to build a credible record of responsible AI governance — in 60 days — while simultaneously managing an enforcement inquiry. Those are very different problems.
How to Actually Use the Time Before a Notice Arrives
Start with the inventory. It is the only place to start, because everything else depends on knowing what systems you have.
From the inventory, think about which systems carry the most potential for TRAIGA exposure — systems that make or substantially influence consequential decisions for Texas consumers in sensitive domains. Concentrate initial governance documentation on those systems. The goal is not a perfectly comprehensive program on day one; it is getting your highest-exposure systems into a defensible position before the enforcement period matures.
Then build the governance record forward. Governance that exists in a policy document alone will not hold up as cure evidence. Governance that shows up in meeting records, review cycles, monitoring reports, and escalation logs is credible. The time to start building that record is now, not after a notice arrives.
If your organization is uncertain about where the gaps are, an honest gap assessment against TRAIGA's prohibited-practices structure — and against the NIST AI RMF safe harbor requirements — is the right starting point. That assessment tells you which documentation you already have, which needs to be built, and which systems need the most attention. Certify Consulting offers that kind of structured review through our ISO 42001 gap assessment service, which maps directly onto the documentation infrastructure TRAIGA cure readiness requires.
TRAIGA's cure period is a meaningful protection for businesses that take it seriously before they need it. The 60 days belong to companies that were already working on the problem.
Last updated: 2026-09-17
Frequently Asked Questions
What is TRAIGA's 60-day cure period?
Under Texas HB 149 (effective January 1, 2026), if the Texas Attorney General sends written notice of an alleged AI violation, the named business has 60 days to cure the violation before the AG may bring a civil action and civil penalties attach. The cure must address both the specific deficiency identified and the practices that produced it.
What is the difference between curable and uncurable TRAIGA violations?
TRAIGA explicitly distinguishes the two. Curable violations — typically operational deficiencies — carry penalties in roughly the $10,000–$12,000 range, and the 60-day cure period applies. Uncurable violations — associated with intentional prohibited conduct such as deploying AI with intent to discriminate or deceive — carry penalties of roughly $80,000–$200,000, and the cure period does not apply. Continuing violations add $2,000–$40,000 per day.
Does TRAIGA require mandatory impact assessments for AI deployers?
No. The enacted Texas HB 149 is an intent-based prohibited-practices statute, not an EU AI Act-style compliance framework. Freestanding impact-assessment mandates appear in earlier drafts of the bill that were not enacted. Assessment-like documentation is relevant primarily as evidence supporting the NIST AI RMF affirmative defense, not as a standalone statutory obligation.
What is the NIST AI RMF affirmative defense under TRAIGA?
Substantial alignment with the NIST AI Risk Management Framework (NIST AI RMF 1.0, published January 2023) functions as an affirmative defense in TRAIGA enforcement. It is not a mandate imposed by the statute — it is a shield available to companies that can demonstrate real implementation of the RMF's four core functions: Govern, Map, Measure, and Manage.
How does ISO 42001 certification help with TRAIGA cure readiness?
ISO 42001:2023 requires organizations to assess AI-related risks (clause 6.1.2), conduct AI system impact assessments (clause 8.4), and monitor and evaluate AI system performance (clause 9.1). These documentation artifacts closely align with what NIST AI RMF alignment requires, meaning ISO 42001-aligned organizations have most of the affirmative defense infrastructure already in place.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.