Compliance 15 min read

TRAIGA vs. Colorado vs. the EU AI Act: What Applies to You

J

September 21, 2026

Say you run a mid-sized company: engineering and support out of Austin, customers in Denver and Düsseldorf, and an AI feature in your product that screens job applicants or scores loan applications. Which law governs that feature? The honest answer is probably all three of the ones in this article's title, at once, each triggered by a different fact and each defining "AI system" and "risk" in its own way.

That's the trap in multi-state AI compliance right now. Nobody wrote these laws to work together. Texas wrote a narrow, intent-based statute. Colorado wrote a broad one, gutted it twice, and replaced it with something narrower. The EU wrote the most comprehensive AI law in the world and then delayed its hardest parts by more than a year. None of them coordinated with each other, and none of them coordinated with the federal government, which is separately trying to preempt all of them. I want to walk through what each one actually requires, when it actually applies, and how to tell which pieces bind your company specifically — because "comply with AI regulation" isn't a real instruction. Comply with which one, triggered by what, is.

Three Laws, Three Definitions of "AI Risk"

The fastest way to see how differently these three regimes are built is side by side. Notice that the trigger for coverage — the fact that pulls your company into scope — is different in all three columns.

Texas TRAIGA Colorado SB 26-189 EU AI Act
What triggers coverage Developing or deploying AI that affects Texas residents, or a government entity using AI Deploying automated decision-making technology (ADMT) that makes a "consequential decision" about a Colorado resident Placing an AI system on the EU market, or having its output used in the EU — regardless of where the company is based
Core obligation Don't engage in specific prohibited uses (manipulation, unlawful discrimination by intent, government social scoring, CSAM) Notify users of AI interaction; disclose adverse ADMT outcomes within 30 days; allow correction and human review Risk-tiered duties: banned practices, transparency labeling, and (for high-risk systems) provider/deployer obligations under Articles 9–17 and 26
Impact assessments required? No No — dropped from the original 2024 law Yes, for high-risk systems once those provisions apply
Enforcement Texas Attorney General only, with a 60-day cure period Colorado Attorney General National competent authorities in each EU member state, plus the EU AI Office for GPAI
Penalties $10,000–$12,000 per curable violation; $80,000–$200,000 per uncurable violation; $2,000–$40,000 per day for continuing violations Set by the Colorado Consumer Protection Act framework Up to €35 million or 7% of global annual turnover for banned-practice violations
Recognized safe harbor Affirmative defense for substantial compliance with NIST AI RMF (including the Generative AI Profile) or a comparable framework like ISO/IEC 42001:2023 None specified Presumption of conformity for high-risk systems certified to relevant harmonized standards
Effective date January 1, 2026 January 1, 2027 Phased: Feb. 2, 2025 (banned practices) → Aug. 2, 2025 (GPAI) → Aug. 2, 2026 (transparency) → Dec. 2, 2027 (Annex III high-risk, deferred)

Everything after this table is the "why" behind those rows, and the "so what" for a company that has to answer to more than one of them.

Texas TRAIGA: Narrow on Purpose

Governor Abbott signed HB 149, the Texas Responsible Artificial Intelligence Governance Act, on June 22, 2025, and it took effect January 1, 2026. It's worth knowing that TRAIGA is the pared-back survivor of an earlier, much heavier bill that would have looked a lot more like Colorado's original law. The legislature killed that version and replaced it with something built around intent rather than outcomes.

That distinction matters more than almost anything else in the statute. TRAIGA doesn't require impact assessments, doesn't require a registry of high-risk systems, and doesn't impose a general duty of reasonable care. It bans four categories of conduct:

  • Developing or deploying AI intended to incite self-harm, physical harm, or criminal activity
  • Using AI to unlawfully discriminate against a protected class with intent
  • Government use of AI for social scoring, or for biometric identification of individuals from publicly available sources without consent
  • AI-generated child sexual abuse material

If your AI system isn't doing one of those specific things, TRAIGA's prohibitions largely don't reach it, however sophisticated the system is.

Two features are worth building into a compliance calendar:

  • Enforcement is narrow. It sits exclusively with the Texas Attorney General — there's no private right of action — and the AG must give 60 days' notice and a chance to cure before pursuing a curable violation.
  • There's an actual affirmative defense. Under § 552.105(e)(2)(D), substantial compliance with the NIST AI Risk Management Framework's Generative AI Profile (NIST-AI-600-1), or with "another nationally or internationally recognized risk management framework for artificial intelligence systems," is a complete defense. ISO/IEC 42001:2023, the AI management system standard, is the kind of certifiable framework that argument is built for.

Texas also runs a 36-month regulatory sandbox through the Department of Information Resources, though it can waive licensing requirements, not the Subchapter B prohibitions themselves.

The practical read: TRAIGA is a floor, not a ceiling. If your only AI exposure is Texas customers, you have real but limited obligations. If you also sell into Colorado or the EU, TRAIGA is the easiest box to check and the least likely to be where your actual work is.

Colorado's Reset: From Impact Assessments to Disclosure Duties

Colorado's story is the messiest of the three, and it's not finished. The original Colorado AI Act, SB 24-205, was the country's first comprehensive high-risk AI statute — closer in spirit to the EU model than to Texas's. It would have required developers and deployers of "high-risk" systems to conduct impact assessments, maintain risk management programs, and exercise reasonable care to prevent algorithmic discrimination, with a rebuttable presumption of compliance for companies following NIST AI RMF or a comparable framework.

It never actually took effect. Originally set for February 1, 2026, the legislature pushed it to June 30, 2026, when Governor Polis signed SB 25B-004 on August 28, 2025, following a special session that couldn't agree on a full rewrite. Then, on April 27, 2026, a federal court paused enforcement outright while the law's scope was being reconsidered. Three weeks later, on May 14, 2026, Polis signed its actual replacement: SB 26-189, which repeals the original framework entirely.

What survived the rewrite is narrower and more mechanical. SB 26-189 drops risk management programs, impact assessments, and the general duty of reasonable care — the three heaviest obligations in the original bill are simply gone. In their place, it builds a framework around "automated decision-making technology" used to make "consequential decisions" about a consumer (things like employment, housing, credit, healthcare, or education outcomes), and imposes four operational duties:

  • Notify the person when they're interacting with an AI system.
  • Disclose to them within 30 days if an ADMT-driven decision produced an adverse outcome.
  • Correct inaccurate personal data on request.
  • Provide a path to meaningful human review.

It takes effect January 1, 2027, and applies to decisions made on or after that date.

If you're tracking Colorado for compliance purposes, the operative fact is that nothing is currently enforceable — the original law is dead, and the replacement isn't live until 2027. That's a real planning window, not a reason to ignore it; disclosure and human-review workflows take longer to build than most teams expect, and 2027 will arrive during whatever your next product cycle is.

The EU AI Act: Delayed, Not Dead

The EU AI Act entered into force on August 1, 2024, and it's still the most comprehensive framework of the three by a wide margin, even after this year's changes softened its timeline. Its structure is risk-tiered: Article 5's banned practices (things like social scoring and manipulative subliminal techniques) became applicable February 2, 2025. Obligations for general-purpose AI models under Articles 51–56 became applicable August 2, 2025. The heavy provider and deployer obligations for high-risk systems — Articles 9 through 17 for providers, Article 26 for deployers — were originally set for August 2, 2026.

They're not anymore, at least not for the largest category. On May 7, 2026, EU negotiators reached a provisional agreement on the Digital Omnibus on AI, the first substantive amendment package since the Act's adoption. That agreement was formally adopted as Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026, and has been in force since July 27, 2026 — this is now binding law, not a pending proposal. It pushes the high-risk obligations for Annex III systems — the "use-based" category covering things like employment screening, credit scoring, and law enforcement tools — from August 2, 2026 to December 2, 2027, a sixteen-month deferral. Annex I systems, the category embedded in already-regulated products like medical devices and lifts, moves from August 2, 2027 to August 2, 2028.

What the deferral didn't touch: Article 50's transparency duties, which require labeling AI-generated content and disclosing when a person is interacting with a chatbot or emotion-recognition system, still land on their original date of August 2, 2026. If your product talks to EU users or generates content EU users will see, that obligation is a matter of months away regardless of what happened to the high-risk timeline.

The provision that surprises the most American companies is territorial scope. Under Article 2(1)(c), the Act reaches providers and deployers established outside the EU whenever the AI system's output is used in the EU. There's no intent or targeting requirement, and no EU subsidiary is needed to be in scope. A Texas company running a résumé-screening model on servers in Dallas is inside the Act's reach the moment that model's output is used to make a decision about a candidate in Munich, even without an EU office or an EU customer contract of its own.

The Federal Wildcard: Preemption Isn't Law Yet

No conversation about multi-state AI compliance in September 2026 is complete without the preemption fight, because it's the reason none of this has settled down. Congress tried twice to short-circuit the whole state patchwork and failed both times: the House's 2025 reconciliation bill included a ten-year moratorium on state AI enforcement, and the Senate stripped it by a 99-1 vote before final passage. The 2026 NDAA, which some expected to carry a similar provision, dropped it too.

Having lost in Congress, the executive branch tried a different lever. In December 2025, the President signed an executive order creating an AI Litigation Task Force inside the Department of Justice, directing it to begin challenging state AI laws — on theories that they unconstitutionally burden interstate commerce or are preempted by federal authority — starting January 10, 2026. That task force is active. It has not, as of this writing, produced a court ruling that displaces TRAIGA, Colorado's new law, or the EU AI Act's reach into US companies.

I'd treat this the way I'd treat any pending litigation risk: real, worth watching, and not a reason to delay building the compliance program you actually need today. A task force with a mandate is not a statute. Until something with the force of law actually preempts these regimes, they bind you exactly as written.

Which Obligations Actually Bind Your Company

Run each of the three through a simple nexus test rather than trying to answer "am I regulated" in the abstract:

  • Texas: Does your AI system get developed or deployed in Texas, or does it affect a Texas resident, or is a government entity using it? If yes, you're inside TRAIGA's prohibited-use rules and the healthcare AI disclosure duty, but nothing resembling an impact assessment.
  • Colorado: Does an automated decision-making system you deploy make a "consequential decision" — employment, credit, housing, healthcare, education — about a Colorado resident? If yes, and if you're still operating after January 1, 2027, you owe notice, adverse-outcome disclosure, correction rights, and human review. Before that date, there's nothing live to comply with, though building the workflow now avoids a scramble later.
  • EU: Does your AI system's output get used by anyone in the EU, in any capacity, regardless of where you're incorporated or where your servers sit? If yes, Article 50's transparency duties bind you by August 2, 2026, and the high-risk provider or deployer obligations bind you by December 2, 2027 if your use case falls in Annex III.

The uncomfortable finding for most companies that run this test honestly: they're inside all three, just on different obligations and different clocks. A single HR-tech product selling into Texas, Colorado, and a European customer base is not choosing which law to comply with. It's stacking three sets of duties that happen to share a subject.

Building One Program That Satisfies All Three

The good news, if there is one, is that these three regimes reward the same underlying discipline even though they demand different documents. TRAIGA's affirmative defense is built around a recognized AI risk management framework. Colorado's original law offered the same kind of presumption before it was replaced, and disclosure/human-review duties are much easier to operationalize if you already have a governance structure that tracks decisions and their outcomes. The EU AI Act's high-risk obligations are essentially a formalized risk management system with documentation requirements attached.

That convergence is why an increasing number of companies build one AI governance program, mapped to ISO/IEC 42001:2023, and then layer jurisdiction-specific obligations on top of it rather than building three parallel compliance tracks. The standard gives you a documented risk management process, a system of internal controls, and an audit trail — exactly the substance TRAIGA's safe harbor rewards, exactly the infrastructure Colorado's human-review duty needs, and a meaningful head start on the EU's provider obligations once your product lands in Annex III. Starting with an ISO 42001 gap assessment tells you concretely which of the three regimes' requirements your current documentation already satisfies and which ones are actually missing, instead of guessing.

If you're earlier in the process and trying to figure out whether you need a certified management system at all or just a set of documented controls, that's a conversation worth having with an ISO 42001 consultant before you build anything, because the answer depends on how many of these three jurisdictions you're actually exposed to and how fast your product roadmap is pushing you toward Annex III territory.

FAQ

Does TRAIGA apply to companies outside Texas?

Yes. TRAIGA applies based on where the AI system is deployed or who it affects, not where the company is headquartered. A California company whose AI product is used by a Texas resident, or by a Texas government entity, falls within its scope.

Is the Colorado AI Act currently in effect?

No. The original Colorado AI Act (SB 24-205) never took effect — a federal court paused its enforcement on April 27, 2026, and it was formally repealed and replaced by SB 26-189 on May 14, 2026. The replacement law takes effect January 1, 2027.

Do I need to comply with the EU AI Act if my company has no EU office?

Possibly, yes. Under Article 2(1)(c), the EU AI Act applies to providers and deployers outside the EU whenever the AI system's output is used in the EU. No EU subsidiary, EU customer contract, or intent to target the EU market is required.

What is TRAIGA's safe harbor, and does ISO 42001 qualify?

TRAIGA's affirmative defense, at § 552.105(e)(2)(D), applies to companies that substantially comply with the NIST AI RMF Generative AI Profile or another recognized AI risk management framework. ISO/IEC 42001:2023, as a certifiable AI management system standard, fits the description of a comparable recognized framework.

When do the EU AI Act's high-risk obligations actually take effect now?

For Annex III (use-based) high-risk systems, the deadline moved from August 2, 2026 to December 2, 2027, under the Digital Omnibus on AI, agreed provisionally on May 7, 2026 and formally adopted as Regulation (EU) 2026/1744, in force since July 27, 2026. Annex I (product-embedded) obligations moved from August 2, 2027 to August 2, 2028. Article 50's transparency and disclosure duties were not affected and still apply from August 2, 2026.

Will a federal law preempt these state AI laws?

Not yet. Congress removed a proposed ten-year moratorium on state AI enforcement from the 2025 reconciliation bill by a 99-1 Senate vote, and it did not appear in the 2026 NDAA. A December 2025 executive order created a DOJ task force to challenge state AI laws in court starting January 10, 2026, but as of this writing no ruling or statute has actually preempted TRAIGA, Colorado's law, or any comparable state statute.

Last updated: 2026-09-21

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.