shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / TRAIGA / post · rnance
TRAIGATexas AI LawAI GovernanceFinancial Services

Texas TRAIGA for Banks and Fintechs: What HB 149 Requires

Texas HB 149, the Responsible AI Governance Act, took effect January 1, 2026 and is now enforceable statewide. What it requires of banks, captive finance arms, insurers, and fintechs, the financial-institution safe harbor, and the readiness sequence before an AG complaint arrives.

D
By the DSE practice team
Operator-led practice · how we research & review
September 24, 2026
11 min · 2,331 words

By the DSE practice team · published September 24, 2026 · reviewed September 24, 2026

Texas HB 149, the Responsible Artificial Intelligence Governance Act, took effect January 1, 2026 and now applies to any bank, captive finance arm, insurer, broker-dealer, RIA, or fintech that does business in Texas or serves Texas residents, whether or not the company is headquartered there. The statute prohibits developing or deploying AI with the intent to unlawfully discriminate against a protected class, gives federally insured financial institutions and regulated insurers a safe harbor tied to their existing banking or insurance compliance, and puts enforcement exclusively in the hands of the Texas Attorney General, who can now act on complaints through the consumer AI portal live by the law’s own September 1, 2026 deadline. There is no private right of action, but a curable violation still carries a $10,000 to $12,000 penalty and an uncurable one runs $80,000 to $200,000, so the safe harbor is worth confirming rather than assuming.

This guide is for the CCO, CRO, or Head of Model Risk at a bank, captive finance company, insurer, broker-dealer, RIA, or fintech evaluating Texas exposure for the first time or confirming a posture already underway. It covers who is in scope, how the financial-institution and insurance safe harbors work, what the Attorney General can now enforce, the sandbox fintechs use to pilot AI products, and a readiness sequence to run before a complaint arrives.

What TRAIGA requires and who it reaches

Governor Abbott signed HB 149 on June 22, 2025, and it took effect January 1, 2026, replacing an earlier, broader draft that drew heavy opposition from financial services and technology trade groups. The version that passed is narrower: instead of a general algorithmic-discrimination duty triggered by unequal outcomes, TRAIGA requires proof of intent. A company violates the statute only where it developed or deployed an AI system with the intent to unlawfully discriminate against a protected class under existing Texas and federal law: race, color, national origin, sex, age, religion, or disability. Disparate impact alone, without that intent, does not establish a violation.

Scope is broad even though the prohibition is narrow. TRAIGA reaches any person or entity that develops or deploys an AI system while conducting business in Texas, or that offers a product or AI-driven service used by Texas residents. A national bank, an out-of-state captive auto lender, or a fintech headquartered outside Texas is in scope the moment its AI-driven underwriting, servicing, or claims tool touches a Texas customer. There is no revenue threshold or headcount floor, so a smaller regional lender or a growth-stage fintech with a Texas customer base gets no size-based exemption.

TRAIGA also created the Texas Artificial Intelligence Council and layered a new AI-interaction disclosure duty onto state agencies. That disclosure duty binds government agencies, not private financial institutions: a bank’s own chatbot or AI-assisted call center does not inherit a Texas-law duty to announce itself as AI under TRAIGA, though FINRA’s Rule 2210 or a state consumer-protection statute may separately require it.

The financial-institution and insurance safe harbors, and where they end

TRAIGA gives two named industries a safe harbor from the discrimination prohibition, both framed the same way: compliance with your existing sector regulation counts as compliance with TRAIGA’s non-discrimination duty, not as a blanket exemption from the statute.

Sector Safe harbor condition What it does not cover
Federally insured banks, thrifts, and credit unions Adherence to applicable federal and state banking laws and regulations on fair lending and anti-discrimination AI systems or business lines the institution runs outside its chartered banking activity
Regulated insurance entities Adherence to state anti-discrimination, unfair-competition, and deceptive-practices law governing insurance Non-insurance AI use, such as marketing or claims-adjacent tools not governed by insurance regulation
Captive finance arms, non-bank lenders, broker-dealers, RIAs, fintechs No named safe harbor; the general intent-based discrimination prohibition applies directly The full statute, including the AG’s enforcement authority, applies without a sector-specific carve-out

The safe harbor is a bridge, not an exit. A bank already running fair-lending testing under ECOA and Regulation B, and documenting it for its own model risk program, has most of the evidence a TRAIGA safe-harbor claim needs. An institution that has never formalized that testing has a TRAIGA gap even though it holds a federal charter, because the safe harbor requires actual adherence to banking law, not the mere fact of being a bank. Captive finance arms are the segment most likely to misjudge their position: many operate under a parent’s banking relationships without being federally insured institutions themselves, so the safe harbor does not automatically extend to them the way it does to a bank-chartered affiliate.

How the Attorney General can act, and what a complaint looks like

TRAIGA vests enforcement exclusively in the Texas Attorney General. There is no private right of action, so a consumer cannot sue a bank or fintech directly under this statute the way some state privacy laws allow. What the consumer can do, as of the statute’s September 1, 2026 deadline, is file a complaint through the Attorney General’s consumer AI complaint intake, now the front door for a TRAIGA investigation.

Once a complaint or the AG’s own investigation identifies a potential violation, the institution gets a 60-day cure period after notice before a penalty attaches. A violation cured inside that window carries a civil penalty of $10,000 to $12,000. A violation the AG determines is not curable, or that goes uncured past the 60 days, carries a penalty of $80,000 to $200,000, and a continuing violation can add $2,000 to $40,000 per day on top of that. The cure period only helps an institution that can move fast: an AI inventory naming the system in the complaint, a fair-lending or non-discrimination testing record for it, and an owner authorized to execute a fix inside 60 days. Discovering the inventory for the first time after a complaint arrives burns much of the window on work that should already be done.

The regulatory sandbox and where fintechs use it

TRAIGA also established a regulatory sandbox, administered through the Texas Department of Information Resources, running up to 36 months per participant. An approved participant tests a new AI system with temporary relief from certain state licensing requirements. The sandbox does not suspend TRAIGA’s core prohibitions: manipulation, unlawful discrimination, and unlawful content generation remain enforceable against a participant exactly as they would outside it.

For a fintech piloting an AI-driven credit or insurance product that would otherwise trip a Texas licensing requirement before the product is proven, the sandbox is worth evaluating alongside, not instead of, the discrimination and safe-harbor analysis above. A bank or captive finance arm operating under an existing charter typically has less use for it, since the relief on offer targets products that would otherwise need a new state authorization to test.

How TRAIGA intersects with federal model risk guidance and other state AI laws

TRAIGA is a conduct statute aimed at discriminatory intent, not a model risk framework, and it does not replace SR 26-2, the April 2026 interagency guidance from the Federal Reserve, OCC, and FDIC that governs how banks develop, validate, and govern models, including the generative and agentic AI systems SR 26-2 excludes from its own scope. A bank’s SR 26-2 documentation and its TRAIGA safe-harbor posture answer different questions: one is about model governance rigor, the other about discriminatory intent and consumer complaint exposure in a specific state.

Texas is also not the only state to track. Colorado SB 26-189, effective January 1, 2027, imposes a consumer-notice and human-review regime on financial services AI that shares almost nothing with TRAIGA’s intent-based discrimination standard, and offers no comparable financial-institution safe harbor. An institution operating in both states needs two compliance postures layered on the same underlying AI inventory, not one national policy that assumes the laws match.

A readiness sequence before a complaint arrives

  1. Confirm which AI systems touch Texas residents. Credit, insurance, servicing, and claims systems used by any Texas customer are in scope regardless of where the institution is chartered.
  2. Establish the safe-harbor evidence, or confirm it does not apply. A federally insured institution or regulated insurer gathers the fair-lending or insurance anti-discrimination testing that supports the claim. A captive finance arm, non-bank lender, broker-dealer, or fintech without a named safe harbor builds the same testing record anyway, since it is the strongest evidence against a claim of discriminatory intent.
  3. Name an owner and a 60-day response process. Identify who receives a Texas AG notice, who can pull the relevant system’s testing and governance record on short notice, and who can implement a cure inside the statutory window.
  4. Decide whether the sandbox applies. For a fintech testing a new AI-driven product that would otherwise need Texas licensing to launch, evaluate the sandbox pathway before going to market.
  5. Fold Texas into the multi-state AI inventory. Track TRAIGA alongside Colorado SB 26-189 and any other state AI statute the institution’s footprint touches, in one inventory with a state-by-state compliance layer rather than parallel trackers.

What this guide is / What it is not

What it is: a practitioner orientation for banks, captive finance arms, insurers, broker-dealers, RIAs, and fintechs on what Texas HB 149 requires, how its financial-institution and insurance safe harbors work, and how Attorney General enforcement operates now that the statute is in force.

What it is not: legal advice, a compliance certification, or a guarantee of any regulatory or enforcement outcome. DSE prepares organizations for audit and examination; it does not certify, and it does not guarantee any regulatory result. Whether a specific AI system or safe-harbor claim satisfies TRAIGA is a legal determination for qualified Texas counsel, not a conclusion in this guide.

FAQ

Does TRAIGA apply to a bank headquartered outside Texas?

Yes. TRAIGA reaches any entity that conducts business in Texas or offers a product or AI-driven service used by Texas residents, regardless of headquarters location. A national bank, an out-of-state captive finance arm, or a fintech with Texas customers is in scope the moment its AI system touches one of them, with no size or revenue threshold to exempt a smaller institution.

Is a federally insured bank fully exempt from TRAIGA?

No. TRAIGA gives federally insured financial institutions a safe harbor from its non-discrimination prohibition, conditioned on actual adherence to applicable federal and state banking law on fair lending. It is not a blanket exemption from the statute, and it does not cover AI systems or business lines outside the institution’s chartered banking activity. A captive finance arm operating under a parent’s banking relationships without being federally insured itself does not automatically inherit the safe harbor.

Can a Texas consumer sue our institution directly under TRAIGA?

No. TRAIGA does not create a private right of action. Enforcement is exclusive to the Texas Attorney General, who acts on a complaint filed through the state’s consumer AI complaint intake or on the AG’s own investigation. That removes direct consumer litigation risk under this statute, but not AG investigation and penalty risk, which now runs through an active complaint channel.

What happens if the Attorney General finds a violation?

The institution gets a 60-day cure period after notice. A violation cured within that window carries a civil penalty of $10,000 to $12,000. An uncurable violation, or one left uncured past 60 days, carries a penalty of $80,000 to $200,000, with continuing violations adding $2,000 to $40,000 per day. Having an AI inventory and a testing record ready before a notice arrives is what makes the 60-day window usable rather than a scramble.

How does TRAIGA relate to SR 26-2 and our existing model risk program?

They answer different questions. SR 26-2 is federal supervisory guidance on model development, validation, and governance, and it explicitly excludes generative and agentic AI from its scope. TRAIGA is a state conduct statute focused on discriminatory intent and, for government agencies, AI-interaction transparency. A bank’s SR 26-2 documentation does not by itself establish a TRAIGA safe-harbor claim; the two programs should reference the same underlying AI inventory rather than run as separate efforts.

The Bottom Line

TRAIGA is in force, and as of September 2026 the Attorney General’s consumer AI complaint intake, the enforcement infrastructure behind it, is live. The discrimination prohibition is narrower than early drafts, requiring intent rather than disparate impact, and it gives federally insured banks and regulated insurers a safe harbor tied to compliance they should already be documenting. That safe harbor does not extend automatically to captive finance arms, non-bank lenders, broker-dealers, RIAs, or fintechs, who face the general prohibition directly and carry the full weight of AG enforcement, a 60-day cure window, and penalties up to $200,000 per uncurable violation.

The work is not building a new compliance regime from nothing. It is confirming which AI systems touch Texas residents, documenting the fair-lending or anti-discrimination testing that supports a safe-harbor claim or stands in for one where none applies, and naming an owner who can move inside 60 days if a notice arrives. Start with the AI governance checklist to structure that inventory work, and see the finserv compliance overview for how Texas exposure fits into the broader supervisory-framework-aligned program a bank, captive finance arm, insurer, broker-dealer, RIA, or fintech needs across every state it operates in.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly, or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter