Texas TRAIGA Complaint Portal Is Live: What Changes for AI Teams Now
For eight months, Texas had an AI law with teeth on paper and no way for anyone to actually pull the trigger. The Responsible AI Governance Act (TRAIGA, HB 149) took effect January 1, 2026, but the statute also gave the attorney general a separate deadline, September 1, 2026, to stand up a public complaint mechanism. That deadline has now passed. The portal is live.
TL;DR: The Texas Attorney General's statutory deadline to launch a public TRAIGA complaint mechanism was September 1, 2026, and the portal is now live under the Consumer AI Rights page. Texas residents (acting in an individual or household context) can now file complaints against any AI developer or deployer they believe violated the Responsible AI Governance Act. A complaint can trigger a civil investigative demand for your records, followed by written notice, a 60-day cure window, and penalties of $10K-$12K per curable violation up to $80K-$200K per uncurable one. Until now, TRAIGA had no live intake mechanism, so enforcement was theoretical. It no longer is.
This matters more than another compliance-deadline headline. TRAIGA has been enforceable since January, but enforcement needs a starting point, and for eight months that starting point did not exist. The AG's office spent that window building enforcement infrastructure rather than investigating anyone: standing up sandbox program rules through the Texas Department of Information Resources, staffing an enforcement team, and training state agency staff on AI disclosure obligations. No formal actions, no public civil investigative demands, no notices of violation. That was the calm part of the timeline. The portal opening is the part where it stops being calm.
What the portal actually is
The complaint mechanism lives on the Texas Attorney General's Consumer Protection division, under a Consumer AI Rights page. It is a plain-language overview of TRAIGA's prohibitions with a "file an AI complaint" route into the office's standard complaint intake.
| Element | Detail |
|---|---|
| Statutory deadline | September 1, 2026 |
| Statute section | Tex. Bus. & Comm. Code Section 552.102 (mechanism requirement) |
| Location | Texas AG Consumer Protection, Consumer AI Rights page |
| Who can file | Individuals, acting in an individual or household context |
| Who cannot use this route | Commercial or employment-context complainants (competitors, employees) |
| What filing triggers | Discretionary civil investigative demand under Section 552.103 |
The narrow "individual or household context" language matters for small teams building B2B or B2C products differently. A consumer who feels manipulated by your chatbot, discriminated against by your screening tool, or targeted by a deepfake of themselves can file directly. A business partner who thinks your vendor disclosures are inadequate, or an employee who thinks your internal AI use violates their rights, cannot use this specific channel, though the AG retains authority to open an investigation on its own initiative regardless of how a lead reaches the office.
What happens after a complaint is filed
A complaint landing in the portal is not a lawsuit and is not even automatically an investigation. Here is the actual sequence, as the statute lays it out:
- Complaint intake. The complaint enters the AG's standard Consumer Protection queue alongside every other consumer complaint the office handles.
- Discretionary civil investigative demand (CID). Under Section 552.103(a), the attorney general may issue a CID to determine whether a violation occurred. This is a records request, not a court filing, issued under the CID procedures in Chapter 15.10 of the Business and Commerce Code. It can ask for system documentation, risk assessments, internal policies, and communications relevant to the complaint.
- Written notice of violation. If the AG concludes a violation likely occurred, it must issue written notice before it can sue.
- 60-day cure window. From the date of written notice, you have 60 days to cure the violation, document what you fixed, and describe the policy changes that prevent recurrence. Cure a violation properly within that window and the AG cannot sue over it.
- Penalty exposure if uncured, or for uncurable violations. Penalties run $10,000 to $12,000 per curable violation not cured, the same range for a false statement about how a violation was cured, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for a continuing violation. These figures come from Tex. Bus. & Comm. Code Section 552.105(a).
There is no private right of action anywhere in this chain. Every step runs through the attorney general's office. That concentration is exactly why the portal opening matters: before September 1, the AG's own complaint volume was effectively zero because there was no formal channel for consumers to reach it about AI specifically. Now there is one, and Texas is the eighth-largest economy in the world. A dormant law with a live intake page is a different risk posture than a dormant law with no intake page at all.
Why this is not the same story as the law taking effect
It is tempting to file this under "Texas AI law, already covered" and move on. Two things are genuinely new as of this week that were not true in January.
First, the enforcement funnel now has an entry point. A statute with an intent standard, a narrow set of prohibited uses, and no private right of action is, in practice, only as active as its complaint pipeline. For eight months, TRAIGA's pipeline had no public inlet. Complaints could only reach the AG through channels the office built itself, referrals, or whatever informal tips came in. A dedicated, publicized "file an AI complaint" page changes the volume math, because it is now something a frustrated customer can find by searching, not something they have to know to ask for.
Second, the AG's own public messaging changed with the launch. The Consumer AI Rights page frames TRAIGA in plain language for ordinary consumers, not just compliance professionals. That framing is itself a signal: the office built a page designed to be found and used, not a bureaucratic form buried three clicks deep. Offices that want low complaint volume do not optimize their intake pages for consumer discovery.
Neither of these changes what TRAIGA prohibits. The prohibited-use list (behavioral manipulation toward self-harm or criminal activity, unlawful discrimination, non-consensual deepfakes of identifiable people, CSAM, constitutional-rights violations by government actors) is unchanged, and the intent standard that limits liability to designed misuse rather than accidental harm is unchanged too. What changed is the odds that someone who believes you crossed one of those lines now has a fast, visible way to say so.
The complaint-response runbook
Most small AI teams have never had to respond to a state AG civil investigative demand. Waiting until one arrives to figure out the process costs you days you do not have inside a 60-day cure window. Build this now.
Step 1: Assign an owner before you need one. Name a single person, general counsel, a compliance lead, or the founder if you have neither, who is responsible for coordinating a response if a CID arrives. Not a committee. One person who knows the clock starts the day notice is received.
Step 2: Keep a standing AI system inventory. List every AI system you develop or deploy that touches Texas residents, what it does, and who owns it internally. A CID response starts with "which system is this even about," and that should take minutes, not a week of internal archaeology.
Step 3: Document your prohibited-use review, not just your outcome. If you have already reviewed your systems against TRAIGA's prohibited-use list, keep the review notes, not just the conclusion that you passed. "We are compliant" is not evidence. "Here is the review we ran on [date], here is what we checked, here is who signed off" is evidence, and it is what a cure statement needs to look like if you ever have to file one.
Step 4: If you are pursuing the NIST AI RMF safe harbor, keep the paper trail current. Substantial, documented compliance with the NIST AI Risk Management Framework is an affirmative defense under TRAIGA. Citing the framework's name in a policy document is not the same as having GOVERN, MAP, MEASURE, and MANAGE records the AG can actually review. If a complaint arrives, the strength of your defense is the strength of your existing documentation, not what you can produce after the fact.
Step 5: Write a 60-day cure checklist now, before you are inside one. A basic version covers: stop the violating conduct immediately, document the fix with dates and responsible owners, update the internal policy that failed to prevent it, and draft the written statement to the AG describing all three. Teams with no governance documentation cannot move fast enough inside 60 days because they cannot show what changed from what baseline. Teams with a baseline can.
Step 6: Monitor for your own complaint exposure, not just your compliance status. The categories most likely to generate a consumer complaint are the ones a consumer can actually notice: a chatbot that manipulates rather than assists, a hiring or lending tool that produces a discriminatory outcome someone can point to, a deepfake of a real person. Internal documentation gaps rarely trigger complaints on their own, because consumers do not see your paperwork. They see outcomes. Prioritize review of the systems where a bad outcome is visible to the person it happens to.
What this does not change
Federal preemption has still not arrived. The Trump administration's December 2025 executive order directed work toward a federal AI framework that would preempt inconsistent state laws, but as of this writing no statute implementing that preemption has passed Congress. TRAIGA is in force, the Texas AG now has a working intake mechanism for it, and treating federal preemption as a live shield is premature.
TRAIGA also still does not impose the developer-to-deployer documentation packages, mandatory impact assessments, or consumer notice requirements that appeared in the earlier draft (HB 1709) and were stripped before passage. If a vendor or compliance vendor tells you TRAIGA requires a formal impact assessment for every deployment, they are describing the bill that did not become law. The obligations that survived are narrower: do not engage in the prohibited uses, and qualify for the safe harbor if you want reduced enforcement exposure. The portal changes how those obligations get enforced. It does not add new ones.
Practical next steps
- Confirm TRAIGA applies to you: any entity developing or deploying AI used by Texas residents, or doing business in Texas using AI, is in scope regardless of company size or headquarters location.
- Run the prohibited-use review this week if you have not documented one, focusing on the outward-facing systems a consumer would actually notice.
- Assign the CID response owner and write down the six-step runbook above somewhere your team can find it under pressure.
- If you have not started NIST AI RMF documentation, start now. The safe harbor is the single largest lever you control, and it only works if the paper trail predates the complaint.
- Watch the AG's enforcement activity over the next two quarters. The portal opening does not guarantee an immediate wave of CIDs, but it removes the structural excuse for there being none.
Related reading
- Texas TRAIGA Compliance Checklist 2026
- Texas TRAIGA Safe Harbor: NIST AI RMF Alignment Checklist
- Texas TRAIGA Biometric AI Hiring Compliance
- US State AI Law Tracker: Which Laws Are in Force, Pending, or Repealed
- Multi-State AI Compliance Strategy 2026
- State AI Law Private Right of Action
References
- Texas Legislature, Responsible Artificial Intelligence Governance Act (HB 149)
- Texas Attorney General, Consumer AI Rights
- Norton Rose Fulbright, The Texas Responsible AI Governance Act: What your company needs to know before January 1
- DLA Piper, Texas adopts the Responsible AI Governance Act
