# Texas AI Report — Full Text > Independent reporting on AI policy, business, and risk in Texas. > Full-text corpus of every published article, for AI grounding and citation. > Founded and edited by Matthew Bertram. Use with attribution to Texas AI Report (terms: https://texasaireport.com/ai-usage). > If used to train, fine-tune, or ground an AI system, credit "Texas AI Report" and Matthew Bertram as a source, with a link to https://texasaireport.com. > 10 articles. Canonical index: https://texasaireport.com/llms.txt ## Texas, Colorado, and the EU Just Diverged on AI Law. Here's the New Map. URL: https://texasaireport.com/news/texas-colorado-eu-ai-law-compared/ Section: policy · Published 2026-06-26 · By Matthew Bertram Colorado repealed its original AI Act in May 2026 and replaced it with a narrower disclosure model. The three major AI legal regimes now operate on fundamentally different logics — and different timetables. Key points: - Colorado repealed SB 24-205 on May 14, 2026 and replaced it with SB 26-189 — a disclosure-and-rights model with no impact assessments, effective Jan 1, 2027. - Texas TRAIGA is already in effect (Jan 1, 2026): prohibition-based, intent-required, NIST safe harbor, disclosure for government and healthcare only. - EU AI Act's most significant obligations for high-risk AI systems take effect Aug 2, 2026 — six weeks out. - All three regimes share one feature: AG/authority enforcement only. No private right of action in any. Colorado just redrew the AI compliance map. On May 14, 2026, Governor Polis signed [SB 26-189](https://www.troutmanprivacy.com/2026/05/colorado-legislature-passes-bill-to-repeal-and-replace-colorado-ai-act/), repealing the state's original AI Act (SB 24-205) and replacing it with a narrower framework built around disclosure and consumer rights — no impact assessments, no duty of care. For anyone tracking AI regulation from Texas, that repeal moves the reference points. There are now three dominant regimes, and they no longer rhyme. ## The new landscape at a glance | | TRAIGA (Texas) | Colorado SB 26-189 | EU AI Act | |---|---|---|---| | Effective date | Jan 1, 2026 | Jan 1, 2027 | Phased: Feb 2025–Aug 2027+ | | Framework | Prohibition-based (intent required) | Disclosure + consumer rights | Risk-based tiered | | Enforcer | TX AG exclusively | CO AG exclusively | National authorities + EU AI Office | | Disclosure duties | Gov agencies + healthcare providers only | All covered ADMT in 7 domains | Varies by risk tier | | Impact assessments | No | No (eliminated) | Yes (high-risk systems) | | Max penalty | $200,000/violation (uncurable) | Not yet specified | EUR 35M or 7% global revenue | | NIST safe harbor | Yes (explicit) | No | No | ## What changed, and why Colorado pivoted The original SB 24-205 mirrored the EU's risk-tiered model, with deployer impact assessments and a duty-of-care standard. It was delayed twice, then stayed by a federal court in April 2026 after xAI sued and the DOJ intervened — a challenge fed in part by a December 2025 White House executive order that singled out Colorado's approach. SB 26-189 passed 34–1 in the Colorado Senate and 57–6 in the House. What survives: consumer notice at the point of AI interaction, post-adverse-outcome notice within 30 days, consumer rights to access data and request human review, and AG enforcement with a 60-day cure period. What was dropped: impact assessments, deployer risk-management programs, and the algorithmic discrimination duty of care. Seven sectors remain in scope — education, employment, housing, financial services, insurance, healthcare, and government services — but the compliance burden is much lighter than before. ## Where Texas stands TRAIGA has been in effect since January 1, 2026, and its logic differs from both Colorado and the EU: it targets intent, not risk tiers. The core prohibitions — behavioral manipulation designed to incite self-harm, constitutional-rights infringement, intentional unlawful discrimination (disparate impact alone is not enough), and child sexual content — apply to any entity. Government agencies must disclose AI interactions to consumers before or at the time of contact. Healthcare providers must disclose AI use in treatment on the date of service. Private non-healthcare businesses face no disclosure requirement at all. Penalties run in tiers: $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable ones, and $2,000–$40,000 per day for continuing ones. An explicit NIST AI RMF safe harbor is available. As of May 2026, no TRAIGA enforcement actions had been publicly reported. ## The EU's next deadline: August 2 Most high-risk obligations under the [EU AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689) — Annex III systems, transparency rules — take effect August 2, 2026. That is six weeks out. Prohibited AI practices have been enforceable since February 2025; GPAI model rules since August 2025. A political agreement to streamline certain obligations was reached May 7, 2026, but formal EU Parliament and Council adoption had not been confirmed as of publication. For Texas-based companies with EU operations or EU customers, August 2 is a live deadline, not a distant one. ## Three regimes, three theories of harm Strip away the detail and the divergence is clean. Texas prohibits bad intent. Colorado mandates disclosure and consumer rights in defined sectors. The EU imposes tiered conformity obligations by risk. None of the three creates a private right of action; all three rely on government enforcement with a cure window before penalties attach. The practical problem is that a compliance posture built around any one of them leaves gaps in the other two. Which is why the starting point hasn't changed since the day TRAIGA passed: know exactly which AI systems you run, and where they touch people. Frequently asked questions: Q: Why did Colorado repeal its original AI Act rather than simply amend it? A: The original SB 24-205 faced compounding opposition: a December 2025 White House executive order criticized Colorado's risk-tiered approach, the DOJ stood up an AI Litigation Task Force in January 2026, xAI sued the state, and a federal magistrate stayed the law on April 27, 2026. The replacement, SB 26-189, then cleared the Colorado Senate 34-1 and the House 57-6 — margins that read less like a patch than a decision to start over. Q: Does Colorado's new SB 26-189 require impact assessments the way the original law did? A: No. Impact assessments, deployer risk-management programs, and the algorithmic-discrimination duty of care were all dropped. SB 26-189, effective January 1, 2027, relies instead on consumer notice at the point of interaction, post-adverse-outcome notice within 30 days, and consumer rights to access data and request human review — a substantially lighter structure than its predecessor. Sources: - Carpe Datum Law — Colorado's AI Reset (May 18, 2026): https://www.carpedatumlaw.com/2026/05/colorados-ai-reset-two-weeks-a-white-house-callout-and-a-pivot-away-from-the-eu-model/ - Troutman Privacy — Colorado Repeal and Replace (May 2026): https://www.troutmanprivacy.com/2026/05/colorado-legislature-passes-bill-to-repeal-and-replace-colorado-ai-act/ - Norton Rose Fulbright — The Texas Responsible AI Governance Act (March 30, 2026): https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act - European Commission — EU AI Act regulatory framework (updated May 11, 2026): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai --- ## TRAIGA Is Six Months Old. No Enforcement Actions — But the Machinery Is Being Built. URL: https://texasaireport.com/news/traiga-enforcement-six-months-in/ Section: policy · Published 2026-06-26 · By Matthew Bertram There are no publicly reported TRAIGA enforcement actions yet, but AG Paxton's office has been building its enforcement infrastructure since the law was signed. September 1 is the next inflection point. Key points: - No publicly reported TRAIGA enforcement actions or civil investigative demands as of late May 2026 — six months after the law took effect. - The AG's enforcement process runs: consumer complaint → civil investigative demand → notice of violation → 60-day cure → civil penalties in court. - Penalties are tiered: curable violations $10,000–$12,000; uncurable $80,000–$200,000; continuing $2,000–$40,000 per day. - AG Paxton launched investigations into Character.AI, Reddit, Instagram, and Discord in 2024 — a signal of appetite for AI-adjacent enforcement. Six months after TRAIGA took effect, there are no publicly reported enforcement actions. But quiet is not the same as dormant. The Texas Attorney General's office has been building its TRAIGA enforcement infrastructure since the law was signed in June 2025 — staffing up, developing technical capacity, and training state-agency personnel on disclosure obligations. The statute requires the AG's public complaint portal to be live by September 1, 2026 — and it may already be accepting complaints — so the quiet period could be brief. ## How enforcement actually works The path from consumer grievance to civil penalty has five steps. A consumer files a complaint through the AG's online portal. The AG may then issue a civil investigative demand (CID), requiring the company to hand over AI system descriptions, training-data categories, performance metrics, known limitations, and post-deployment monitoring records. If the AG finds a violation, the entity gets a notice and a 60-day window to cure it and submit a written explanation. If that window closes without resolution, the AG seeks civil penalties in court. There's a catch in those 60 days. Norton Rose Fulbright attorneys Marc Collier and Ethan Glenn noted in March 2026 that the period "may be insufficient time to 'cure' a violation of TRAIGA, particularly because a 'cure' might mean that the party must substantially modify an AI system." In practice, a notice of violation can land like a cease-and-desist. ## The penalty tiers TRAIGA's civil penalties are tiered, not flat. Curable violations carry $10,000–$12,000 each. Uncurable ones jump to $80,000–$200,000. Continuing violations accrue at $2,000–$40,000 per day. What separates curable from uncurable isn't settled. The statute doesn't define it; Norton Rose Fulbright expects the line to be "developed by experts, the courts and the resulting common law." That uncertainty cuts both ways — companies have less guidance, but so does the AG. ## Paxton's pre-TRAIGA track record AG Ken Paxton is not new to AI-adjacent enforcement. In 2024, his office [launched investigations into Character.AI, Reddit, Instagram, and Discord](https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-launches-investigations-characterai-reddit-instagram-discord-and-other) over children's privacy and safety concerns, and stood up a specialized data-privacy enforcement team. That history suggests both the appetite and the infrastructure to act. Whether TRAIGA enforcement opens with a high-profile target or a quiet CID to a lesser-known company is anyone's guess — but the portal opening this fall hands consumers a direct channel to the AG's desk. DIR rulemaking under TRAIGA, meanwhile, is still developing; no formal agency guidance has been confirmed as published. Frequently asked questions: Q: Can the Texas AG bring a TRAIGA enforcement action against a company for an AI system it is still testing and has not launched? A: No. TRAIGA bars the AG from bringing a civil-penalty action over an AI system that has not yet been deployed. Under Tex. Bus. & Comm. Code 552.105(f), enforcement reach begins at deployment — pre-launch development and testing sit outside the AG's penalty authority. Q: What is a Civil Investigative Demand under TRAIGA, and how does it differ from a lawsuit? A: A CID is an investigative tool the AG can use before filing any court action. Under Tex. Bus. & Comm. Code 552.103, it can compel a company to produce AI system descriptions, training-data categories, inputs and outputs, performance metrics, known limitations, post-deployment monitoring records, and user-safeguard measures, plus anything else the AG deems reasonably necessary. A CID is not itself a penalty; it's the information-gathering step that precedes a notice of violation and, ultimately, civil litigation. Sources: - traiga.news — AG Enforcement Update (March 29, 2026): https://traiga.news/traiga-enforcement-what-the-texas-ag-has-and-has-not-done-and-what-comes-next/ - Duane Morris — TRAIGA Employer Alert (May 27, 2026): https://www.duanemorris.com/alerts/texas_new_ai_law_is_now_in_effect_what_employers_need_to_know_about_traiga2_0526.html - Norton Rose Fulbright — TRAIGA Deep Dive (March 30, 2026): https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act - Texas AG — Character.AI and Platform Investigations: https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-launches-investigations-characterai-reddit-instagram-discord-and-other --- ## What Texas Companies Get Wrong About TRAIGA Readiness URL: https://texasaireport.com/news/what-texas-companies-get-wrong-traiga-readiness/ Section: policy · Published 2026-06-26 · By Matthew Bertram The biggest TRAIGA risk isn't the headline penalties. It's process: no AI inventory, no paper trail, no time to re-engineer a system inside a 60-day cure window. Key points: - Most TRAIGA exposure is process-related: no written AI policy, incomplete AI inventory, and no documentation trail if the AG comes calling. - TRAIGA's intent standard pulls product and engineering teams into the compliance program — legal alone cannot carry it. - The 60-day cure period may be too short to re-engineer a non-compliant system; in practice, a violation notice can function as a cease-and-desist. - The statute requires the AG's complaint portal to be live by September 1, 2026 — it may already be open — the moment consumer complaints start flowing directly to enforcement. TRAIGA has been in effect since January 1, 2026, and no enforcement actions have been reported. Some Texas companies are reading that silence as permission to wait. It isn't. The headline penalties — up to $200,000 per uncurable violation — are real enough. But the practitioners advising Texas companies right now keep landing on the same point: the actual exposure isn't mostly about what your AI does. It's about whether you can prove, on short notice, that you knew what your AI was doing. ## The process gaps that create real risk Start with shadow AI. In [one 2026 estimate cited by managed-IT firm CTTS](https://www.cttsonline.com/2026/06/23/managed-it-services-texas-making-traiga-compliance-workable-for-your-business-in-2026/), 57% of employees use consumer generative AI at work, roughly a third paste sensitive company data into those tools, and shadow-AI incidents add an average of about $670,000 in breach costs. Treat the specific figures as directional rather than gospel — but the structural problem they point at is real: most companies are surprised by how many AI tools are quietly running across hiring platforms, document workflows, email, and analytics, tools they never formally deployed and can't currently inventory. That inventory gap compounds fast. On investigation, the Texas AG can issue a Civil Investigative Demand requiring comprehensive documentation — AI system descriptions, training-data categories, inputs and outputs, performance metrics, known limitations, and post-deployment monitoring records. A company that can't respond faces exposure on top of whatever triggered the inquiry. The second gap is organizational. TRAIGA's liability standard turns on intent — whether a system was developed or deployed *with the intent* to harm, manipulate, or discriminate. That sounds like a high bar until you realize the flip side: demonstrating intent-to-comply requires documented design decisions. And documented design decisions live with the product and engineering teams, not with legal. Treat TRAIGA as a legal-department problem and you leave the people who actually build and configure the AI outside the compliance perimeter. The third gap is vendor documentation. If your HR platform, contract-review tool, or customer-service chatbot runs AI under the hood, TRAIGA's obligations attach to you as the deployer. A vendor that can't produce documentation of its system's purpose, training data, and safeguards on short notice is a direct compliance gap — one a CID will expose. ## The 60-day cure period is shorter than it looks TRAIGA gives companies 60 days to cure a violation after notice from the AG. Plenty of compliance programs treat that window as a safety net. It may not be one. Norton Rose Fulbright's Marc Collier and Ethan Glenn wrote in March 2026: "given the complexity of AI systems, 60 days may be insufficient time to 'cure' a violation of TRAIGA, particularly because a 'cure' might mean that the party must substantially modify an AI system... If this 60-day window is not sufficient time to alter an AI system's programming or functionality, then a notice of violation will effectively function as a cease and desist order." The statute also never defines what makes a violation "curable" versus "uncurable" — the line between a $10,000–$12,000 penalty and an $80,000–$200,000 one. As Norton Rose Fulbright put it, that will be "developed by experts, the courts and the resulting common law." Early enforcement writes those rules. The first companies to receive violation notices become the case law. ## What to do before September 1 The complaint portal must be live by September 1, 2026 — and may already be open — so consumer complaints could be reaching enforcement now. The quiet period is ending. Five things matter most: 1. **Run a complete AI inventory.** Every tool, every platform, every workflow — not just the ones IT sanctioned. Shadow AI belongs on the list. 2. **Write and distribute an AI policy.** As CTTS observed, "common exposure for most owners is process related rather than substantive: not having a written policy, not knowing which employees are using which tools, and not being able to show a paper trail if an investigation begins." 3. **Align with the NIST AI Risk Management Framework.** TRAIGA provides an explicit safe harbor for a documented NIST AI RMF review — one of four affirmative defenses, and the one most directly in your control. 4. **Document red-team and adversarial testing.** The safe harbor also covers violations discovered through adversarial testing. Dated records of testing and remediation are the paper trail that makes a regulatory response defensible. 5. **Audit your vendors.** Review every material AI vendor relationship. If a vendor can't produce documentation of its system's inputs, outputs, and safeguards, escalate — or replace it. The enforcement calendar is no longer abstract. September 1 is nine weeks out. Frequently asked questions: Q: If a vendor's AI tool causes a TRAIGA violation, does liability fall on the vendor or the company that deployed it? A: TRAIGA's third-party misuse carveout means a developer or deployer can't be held liable simply because an end user or other third party uses an AI system for a prohibited purpose. But that carveout doesn't shield a deployer from liability for its own choice to use a vendor's system. If the deploying company's configuration or use of a vendor tool results in prohibited conduct, the deployer carries the exposure — which is why vendor documentation of purpose, training data, inputs, outputs, and safeguards is a compliance requirement, not optional due diligence. Q: Is a spreadsheet enough to track TRAIGA compliance? A: It's a weak foundation. A spreadsheet can't demonstrate the systematic implementation of the NIST AI Risk Management Framework — one of TRAIGA's four explicit statutory affirmative defenses. The NIST safe harbor turns on showing a documented, structured review process, and an ad hoc spreadsheet inventory is unlikely to satisfy that standard when the AG issues a Civil Investigative Demand. Sources: - Norton Rose Fulbright — TRAIGA Deep Dive: https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act - CTTS — Making TRAIGA Compliance Workable (June 2026): https://www.cttsonline.com/2026/06/23/managed-it-services-texas-making-traiga-compliance-workable-for-your-business-in-2026/ - Baker Botts — What Companies Need to Know: https://www.bakerbotts.com/thought-leadership/publications/2025/july/texas-enacts-responsible-ai-governance-act-what-companies-need-to-know - Duane Morris — TRAIGA and Employers (May 2026): https://www.duanemorris.com/alerts/texas_new_ai_law_is_now_in_effect_what_employers_need_to_know_about_traiga2_0526.html --- ## Does TRAIGA Apply to Your Business? A Scope Guide. URL: https://texasaireport.com/news/does-traiga-apply-to-your-business/ Section: policy · Published 2026-06-25 · By Matthew Bertram TRAIGA's reach is wider than most Texas companies realize — but its duties are narrower, and exemptions carve out specific industries and interactions. Key points: - TRAIGA covers any entity that does business in Texas, offers products or services to Texas residents, or develops AI in Texas — regardless of where it is headquartered. - Consumer-AI disclosure duties fall only on government agencies and healthcare providers — not on private non-healthcare businesses. - B2B and employment-context AI interactions are explicitly out of scope. - Insurers under existing state insurance law and federally-insured banks have a compliance-deemed exemption from the anti-discrimination provision; hospital districts and higher-ed institutions are exempt from the government disclosure requirement. Start with geography, because that is where TRAIGA reaches furthest. Any individual or entity that promotes, advertises, or conducts business in Texas; produces products or services used by Texas residents; or develops or deploys an AI system in Texas falls under the law — no matter where it is headquartered. The language sweeps in out-of-state companies whose AI tools simply reach Texas users. The statute defines "[AI system](https://capitol.texas.gov/tlodocs/89R/billtext/pdf/HB00149F.pdf)" broadly: any machine-based system that infers from inputs how to generate outputs — content, decisions, predictions, or recommendations — that can influence physical or virtual environments. Most enterprise AI deployments fit that description. ## What duties actually apply Who you are, and the context you deploy AI in, determines which rules bite. **Government agencies** must disclose AI interaction to consumers before or at the time of the interaction. The notice has to be clear, conspicuous, written in plain English, and free of dark patterns. No consumer consent is required — just disclosure. **Healthcare providers** carry a separate requirement: disclose AI use in treatment on the date of service, or as soon as reasonably possible in emergencies. That notice can be embedded in standard intake forms. **Private non-healthcare businesses** face no consumer-AI disclosure duty. That provision was stripped out of the final bill. What applies universally — to every entity, private or public — is TRAIGA's set of prohibited uses: no AI system may be deployed with the intent to incite self-harm or criminal activity, infringe constitutional rights, commit intentional unlawful discrimination, or generate child sexual content or deepfakes. **B2B and employment contexts are out of scope.** TRAIGA imposes no disclosure, notice, or nondiscrimination requirements for employee or commercial interactions. As Moore & Van Allen put it: "businesses do not need to provide notices or meet specific transparency or nondiscrimination requirements with respect to individuals acting in an employment or B2B context." ## Key exemptions and carve-outs Several industries have explicit carve-outs from the anti-discrimination provision. **Insurers** already subject to state insurance laws that prohibit unfair discrimination are exempt from TRAIGA's parallel anti-discrimination rule. **Federally-insured financial institutions** complying with applicable federal and state banking law are deemed compliant with that same provision. **Hospital districts and institutions of higher education** are excluded from the definition of "government agency" for the AI disclosure requirement — so they do not carry the real-time consumer-disclosure duty that other state and local government entities do. **Biometric data** used for fraud prevention and cybersecurity training is carved out. And [TRAIGA preempts any city or county AI ordinance](https://www.bakerbotts.com/thought-leadership/publications/2025/july/texas-enacts-responsible-ai-governance-act-what-companies-need-to-know), setting one statewide compliance standard instead of a patchwork of local rules. ## For most private companies, it's lighter than the headline For a private Texas company outside healthcare, the day-one burden is smaller than the law's reputation suggests — no disclosure obligation, no impact assessments, no B2B or employment requirements. What every covered entity does carry is the universal prohibition set and exposure to Attorney General investigation if a consumer AI system is alleged to have caused harm. The AG's complaint portal is required by statute to open by September 1, 2026. That is the date most compliance attorneys have circled as the real enforcement inflection point. Frequently asked questions: Q: Does TRAIGA apply to AI tools a company uses only for internal HR functions such as resume screening or scheduling? A: No. TRAIGA excludes employment and B2B contexts from its disclosure, notice, and nondiscrimination requirements. As Moore & Van Allen put it, businesses do not need to provide notices or meet specific transparency or nondiscrimination requirements for individuals acting in an employment or B2B context. The universal prohibited-use rules — against behavioral manipulation, constitutional-rights infringement, intentional unlawful discrimination, and child sexual content — still apply everywhere, but a purely internal tool carries no affirmative disclosure or nondiscrimination duty. Q: Are Texas universities and hospital districts required to give TRAIGA's AI-interaction disclosure to students or patients? A: No. Hospital districts and institutions of higher education are excluded from the definition of "government agency" for purposes of TRAIGA's AI disclosure requirement under Tex. Bus. & Comm. Code 552.001(1)-(2). They do not carry the real-time consumer-disclosure obligation that other state and local government entities do. Sources: - Norton Rose Fulbright — TRAIGA deep dive: https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act - Morgan Lewis — TRAIGA scope: https://www.morganlewis.com/pubs/2025/07/texas-joins-the-emerging-landscape-of-state-level-ai-governance - Moore & Van Allen — TRAIGA analysis: https://www.mvalaw.com/data-points/a-red-state-model-for-comprehensive-ai-laws-texas-enacts-the-responsible-artificial-intelligence-governance-act - Baker Botts — TRAIGA overview: https://www.bakerbotts.com/thought-leadership/publications/2025/july/texas-enacts-responsible-ai-governance-act-what-companies-need-to-know --- ## Texas Is Pulling Serious AI Capital — Three Deals Make the Case URL: https://texasaireport.com/news/texas-ai-funding-apptronik-saronic-stargate/ Section: business · Published 2026-06-25 · By Matthew Bertram Apptronik, Saronic, and Stargate mark Austin and West Texas as priority destinations for AI investment. Austin startups raised a record $7.19B in 2025. Key points: - Austin-based Apptronik closed over $935M in Series A funding at a valuation over $5B; new investors include AT&T Ventures, John Deere, and Qatar's sovereign wealth fund. - Saronic Technologies raised a $1.75B Series D at a $9.25B valuation to scale autonomous naval vessels from its Austin base. - The Stargate data center in Abilene — the flagship site of OpenAI and Oracle's $500B national AI infrastructure push — houses Nvidia Blackwell chips across roughly 0.3 GW of live capacity. - Austin startups raised a record $7.19B in 2025, up 65% from 2024, driven by AI, robotics, and defense. Three big capital events landed inside a five-month window, and together they put hard numbers on what used to be mostly a talking point: Texas has become a destination for AI investment, not just AI adoption. The backdrop is the topline. Austin startups raised $7.19 billion in 2025 — an all-time high and a 64.8% jump from 2024's $4.37 billion, according to Crunchbase News. AI, robotics, and defense-tech carried most of that weight. ## Humanoid robots: Apptronik closes over $935M Apptronik, an Austin-based humanoid robotics company with UT Austin roots, closed a $520 million Series A extension in February 2026, bringing its total Series A to over $935 million. The round values the company at over $5 billion — roughly triple where it stood when the Series A began. The company's Apollo robot targets manufacturing and logistics work. New investors in the extension include AT&T Ventures, John Deere, and the Qatar Investment Authority; Google, Mercedes-Benz, B Capital, and PEAK6 had backed the initial raise. Apptronik says the capital goes toward expanding Apollo production, building out robot training facilities, and debuting a new model later in 2026. ## Autonomous defense vessels: Saronic at $9.25B Saronic Technologies, also headquartered in Austin, closed a $1.75 billion Series D in March 2026 at a $9.25 billion valuation — more than double the roughly $4 billion it carried after its $600 million Series C in 2025. Kleiner Perkins led the round; Andreessen Horowitz, Bessemer, Advent International, and Franklin Templeton also took part. Saronic builds AI-driven autonomous surface vessels for U.S. military customers. It is expanding its Austin footprint past 500,000 square feet and standing up a next-generation shipyard, Port Alpha, with a target of 20-plus ships per year by 2027. A $300 million shipyard expansion in Franklin, Louisiana is already underway. ## AI infrastructure: Stargate in Abilene The third data point sits 180 miles northwest of Austin, in Abilene. The Stargate project — a $500 billion national AI infrastructure initiative anchored by OpenAI, Oracle, and SoftBank — picked Abilene as its flagship first site. The campus covers more than 1,000 acres and 4 million square feet, with a $3.5 billion investment and an 85% property-tax exemption negotiated with the city and Taylor County. As of March 2026, roughly four of eight planned buildings were operational at about 0.3 GW of capacity, housing Nvidia Blackwell chips, with full-site completion expected by the end of 2026. The first data center opened in September 2025. A scale correction is worth making, because early headlines overshot. Oracle and OpenAI dropped plans to expand Abilene to 2.1 GW; the campus is large, but it is not the 2.1 GW build-out some coverage described. A Microsoft-affiliated 900 MW adjacent site has been reported, though the details were unresolved as of March 2026. ## The common thread "Talent density in venture categories such as software, fintech, health tech, defense and robotics has reached a critical mass," Silverton Partners managing partner Morgan Flager told Crunchbase News in March 2026. The three deals sit in different sectors — physical robotics, maritime defense, and cloud infrastructure — but they share a Texas address and one underlying bet: AI moving out of software and into the physical world. That kind of build tends to be capital-intensive and hard to relocate once it's planted, which is exactly why landing it matters for the state. Sources: - TechCrunch — Apptronik $935M Series A: https://techcrunch.com/2026/02/11/humanoid-robot-startup-apptronik-has-now-raised-935m-at-a-5b-valuation/ - PR Newswire — Saronic Series D: https://www.prnewswire.com/news-releases/saronic-closes-1-75b-series-d-at-9-25b-valuation-to-accelerate-a-new-era-of-maritime-autonomy-302729298.html - Texas Standard — Stargate Abilene: https://texasstandard.org/stories/stargate-data-center-abilene-texas-construction-ai-artificial-intelligence/ - Crunchbase News — Austin 2025 funding record: https://news.crunchbase.com/venture/all-time-high-funding-to-austin-startups-2025-ai-robotics-manufacturing/ --- ## What Texas's AI Regulatory Sandbox Offers Builders URL: https://texasaireport.com/news/texas-ai-regulatory-sandbox-explained/ Section: business · Published 2026-06-25 · By Matthew Bertram TRAIGA created a formal testing lane for AI companies: up to 36 months of development without separate licensing, with AG enforcement paused during participation. The catch: TRAIGA's core prohibitions still apply. Key points: - Texas DIR administers up to 36-month sandbox periods; the AG cannot bring enforcement actions while a company participates. - Applicants must submit a system description, benefit assessment, risk-mitigation plan, and proof of federal compliance. - Participants file quarterly reports on performance metrics, risk updates, and stakeholder feedback. - The sandbox does not waive TRAIGA's four core prohibitions — behavioral manipulation, constitutional-rights violations, intentional discrimination, and child sexual content bans remain in force. TRAIGA does something most state AI laws don't: it builds in a sanctioned testing lane. The law, effective January 1, 2026, authorizes the [Texas Department of Information Resources](https://dir.texas.gov/) to run an AI regulatory sandbox — a formal program that lets builders develop and test AI systems without first clearing separate state licensing or regulatory-authorization hurdles. ## What the sandbox actually provides Participants get two concrete protections during the testing period. First, the Attorney General cannot file enforcement charges for violations of state laws that are waived for sandbox purposes. Second, state agencies cannot impose fines or suspend licenses for those same waived requirements while testing is active. The period runs up to 36 months, and DIR can extend it for good cause. Oversight sits with the [Texas Artificial Intelligence Council](https://www.americanbar.org/groups/business_law/resources/business-law-today/2025-july/texas-enters-ai-sandbox-with-traiga-implications-business-trials/), a seven-member body appointed by the governor, lieutenant governor, and speaker of the House, and administratively attached to DIR. The Council — or any applicable agency — can recommend removing a participant whose AI poses undue risk to public safety, violates federal law, or violates non-waived state law. DIR keeps trade secrets and other sensitive submissions confidential. ## What applicants must show There is no lightweight path in. Applicants submit four things: a detailed description of the AI system and its intended use; a benefit assessment covering consumer impact, privacy, and public safety; a plan for mitigating adverse consequences during testing; and proof of compliance with applicable federal AI laws and regulations. Once accepted, participants file quarterly reports on performance metrics, risk-mitigation updates, and feedback from users and stakeholders. DIR, in turn, reports to the legislature each year with sandbox outcomes and policy recommendations. ## The caveat that matters The sandbox does not suspend TRAIGA's core prohibitions. A company inside it still cannot deploy AI designed to manipulate users into self-harm or criminal activity, infringe constitutional rights, engage in intentional unlawful discrimination, or generate child sexual content or deepfakes. Those apply no matter your testing status. As of June 2026, the sandbox is authorized by law and in effect. Whether DIR has published application forms or begun accepting participants hasn't been confirmed — builders who want to apply should check directly with DIR at dir.texas.gov. Frequently asked questions: Q: What can trigger removal from the TRAIGA sandbox once a company is accepted? A: The Texas Artificial Intelligence Council, or any applicable state agency, can recommend removing a participant if the AI system poses undue risk to public safety, violates federal law, or violates a state law that was not waived as part of participation. Removal is not automatic — it takes a recommendation from the Council or the relevant agency. Q: Does sandbox participation excuse a company from TRAIGA's core prohibitions? A: No. The sandbox waives separate licensing and regulatory-authorization requirements, but TRAIGA's four core prohibitions stay in force regardless of participation. A sandboxed company still cannot deploy AI designed to manipulate users into self-harm or criminal activity, infringe constitutional rights, engage in intentional unlawful discrimination, or generate child sexual content or non-consensual deepfakes. Q: Who sits on the Texas Artificial Intelligence Council that oversees the sandbox? A: The Council has seven members appointed across three offices — the governor, the lieutenant governor, and the speaker of the House. It is administratively attached to DIR and submits annual reports to the legislature with sandbox outcomes and policy recommendations. Sources: - ABA Business Law Today — Texas Enters AI Sandbox with TRAIGA: https://www.americanbar.org/groups/business_law/resources/business-law-today/2025-july/texas-enters-ai-sandbox-with-traiga-implications-business-trials/ - Baker Botts — Texas Enacts TRAIGA: https://www.bakerbotts.com/thought-leadership/publications/2025/july/texas-enacts-responsible-ai-governance-act-what-companies-need-to-know - Latham & Watkins — Texas Signs Responsible AI Governance Act: https://www.lw.com/en/insights/texas-signs-responsible-ai-governance-act-into-law - Norton Rose Fulbright — The Texas Responsible AI Governance Act: https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act --- ## UT Austin Hosts 600-Person AI Symposium as Texas Universities Claim Research Spotlight URL: https://texasaireport.com/news/texas-universities-ai-research/ Section: research · Published 2026-06-25 · By Matthew Bertram The inaugural Texas Symposium on Machine Learning, Responsible AI, and Robotics drew more than 600 attendees in March 2026 — a signal that Texas is staking out a serious role in the national AI research conversation. Key points: - UT Austin's Texas Robotics, Machine Learning Lab, and Good Systems co-organized the first-ever Texas Symposium on Machine Learning, Responsible AI, and Robotics in early March 2026. - More than 600 people attended — spanning academia, industry, government, and nonprofits. - Sessions covered agentic AI and the workforce, robotic surgery, harmful AI companions, fair data, and generative AI in music. - UT Austin and Rice University both appeared on Forbes' 2026 'New Ivies' list, cited for producing AI-ready graduates. In early March 2026, more than 600 researchers, engineers, policymakers, and community members gathered on the UT Austin campus for the inaugural Texas Symposium on Machine Learning, Responsible AI, and Robotics. Co-organized by Texas Robotics, the Machine Learning Lab, and Good Systems: Ethical AI at UT Austin, it was the first time the university's three leading AI research programs formally convened under one roof. ## What the symposium said about Texas AI The session list was essentially a tour of the field's hard problems: agentic AI and the workforce, robotics in healthcare settings, harmful AI companions, speech generation, robotic surgery, fair and transparent data collection, and generative AI in music. The breadth was the point. "There's never been a more important time to question — what _should_ we do?" said Ken Fleischmann of Good Systems, framing the responsible-AI thread that ran through the event. CS department chair Peter Stone was blunt about the stakes: "We have the opportunity to choose what technology we build and also try to shape it in a way that the positives will outweigh the negatives." Adam Klivans of the Machine Learning Lab pointed to what academic openness makes possible: "We'll be able to train close to frontier-size models and try out" ideas that closed-source labs use but don't publish. And in one of the more concrete sessions, Alice Xiang of Sony AI introduced the FHIBE dataset, built with ethical data-collection standards including contributor consent and compensation. ## The institutional moment The symposium arrived just as outside rankings started catching up to what insiders had argued for years. Forbes' 2026 "New Ivies" list named both UT Austin and Rice University, singling out each for producing AI-ready graduates. That recognition matters for how Texas positions itself in the AI talent pipeline — and for whether the research institutions here can anchor a durable ecosystem instead of exporting talent to the coasts. With 600 people in the room from academia, industry, government, and the broader Austin community, the clustering already looks underway. Sources: - UT Austin News — AI Symposium recap: https://news.utexas.edu/2026/03/20/leaders-in-ai-robotics-and-ethical-innovation-come-together-at-ut-austin/ - Fox 7 Austin — Forbes New Ivies: https://www.fox7austin.com/news/texas-universities-forbes-new-ivies-ai-careers --- ## TRAIGA Compliance Checklist for Texas General Counsel URL: https://texasaireport.com/news/traiga-compliance-checklist-texas-general-counsel/ Section: policy · Published 2026-06-25 · By Matthew Bertram TRAIGA has been in effect since January 1. The AG's complaint portal opens September 1. Here's what GCs and compliance owners need to do now — before the first CID lands. Key points: - Build an AI inventory first — shadow AI across hiring platforms, chatbots, and document review is the most common compliance gap. - Disclosure duties under TRAIGA fall only on government agencies and healthcare providers, not on private non-healthcare businesses. - A documented NIST AI Risk Management Framework review is an explicit statutory affirmative defense. - The 60-day cure period may be too short to modify an AI system — making a notice of violation functionally a cease-and-desist. The Texas AG's complaint portal has a September 1, 2026 statutory deadline. Once it opens, consumers can file TRAIGA complaints directly, and the enforcement clock starts moving faster. A GC who hasn't run a compliance baseline yet is already behind. Here's the work, in the order that matters. ## Step 1: Build an AI inventory The first enforcement exposure isn't a prohibited use — it's not knowing what AI you're running. TRAIGA applies to any entity that develops, deploys, or promotes AI products to Texas consumers, and the statutory definition of "AI system" is broad: any machine-based system that infers from inputs to generate content, decisions, predictions, or recommendations. In practice, the footprint surprises people. Hiring platforms, document-review tools, email scheduling assistants, and chatbots all qualify. Audit your stack, vendor SaaS included. For each tool, two threshold questions drive everything downstream: Is it consumer-facing? Is it making or influencing a decision? **One caution on disclosure:** if your entity is a private non-healthcare company, TRAIGA imposes no consumer-facing AI disclosure requirement. Disclosure obligations fall separately on government agencies (before or at the time of AI interaction, in plain English, no dark patterns) and on healthcare providers (at the time of service, or as soon as practicable). Don't conflate the two, and don't take on private-sector disclosure costs you don't owe. ## Step 2: Lean on the NIST safe harbor — and document it TRAIGA provides explicit affirmative defenses, and the most accessible is an internal review conducted using the NIST AI Risk Management Framework. This isn't boilerplate. Run it, date it, file it. The other defenses — red-teaming or adversarial testing, compliance with state-agency guidance, and acting on stakeholder feedback — work the same way: they only help if there's a paper trail. Build that trail now, not in response to a civil investigative demand. A CID under [§ 552.103](https://capitol.texas.gov/tlodocs/89R/billtext/pdf/HB00149F.pdf) can require AI system descriptions, intended-use documentation, training-data categories, performance metrics, known limitations, post-deployment monitoring records, and user-safeguard measures — plus anything else the AG deems relevant. If you can't produce that on short notice, the gap itself becomes the exposure. ## Step 3: Understand the penalty tiers and the cure problem Penalties are tiered, not flat: - **Curable violations:** $10,000–$12,000 per violation - **Uncurable violations:** $80,000–$200,000 per violation - **Continuing violations:** $2,000–$40,000 per day The statute never defines what makes a violation curable versus uncurable. Per Norton Rose Fulbright's Marc Collier and Ethan Glenn, that distinction "will be developed by experts, the courts and the resulting common law." For now, you're operating without a clear line. More pressing: the 60-day cure period after a notice of violation may not be enough time to materially change an AI system. As Collier and Glenn put it, "a notice of violation will effectively function as a cease and desist order" when the cure requires reprogramming. That is the argument for pre-enforcement compliance over reactive scrambling. There is no private right of action under TRAIGA; the AG has exclusive enforcement authority. But the AG's data-privacy enforcement team is already built out, and the complaint pipeline opens in September. ## The September 1 inflection point The complaint portal is expected to open by September 1, 2026 — the statutory deadline under Section 8 of HB 149. No publicly reported TRAIGA enforcement actions had been filed as of late June 2026, but the office has been assembling enforcement infrastructure since the law was signed. The window to close documentation gaps is before the portal opens, not after the first complaint triggers a CID. Frequently asked questions: Q: If an end user or employee misuses an AI tool in a way that causes harm, is the company that deployed it liable under TRAIGA? A: Not automatically. TRAIGA includes a third-party misuse carveout: a developer or deployer cannot be held liable simply because an end user or other third party uses an AI system for a prohibited purpose. Liability turns on the intent behind how the system was developed or deployed, not on downstream misuse by others. The carveout does not, however, relieve the deployer of having documented the system's intended safeguards. Q: Does TRAIGA require companies to use the NIST AI Risk Management Framework? A: No — the NIST AI RMF is not mandatory. But conducting a documented internal review using it is one of TRAIGA's explicit statutory affirmative defenses. A company that can show it ran that review has a defense against enforcement even if a violation occurred. The other affirmative defenses are red-teaming or adversarial testing, compliance with state-agency guidance, and acting on feedback from developers, deployers, or stakeholders. Sources: - Norton Rose Fulbright — TRAIGA Deep Dive: https://www.nortonrosefulbright.com/en/knowledge/publications/c6c60e0c/the-texas-responsible-ai-governance-act - Baker Botts — TRAIGA: What Companies Need to Know: https://www.bakerbotts.com/thought-leadership/publications/2025/july/texas-enacts-responsible-ai-governance-act-what-companies-need-to-know - Latham & Watkins — Texas Signs TRAIGA: https://www.lw.com/en/insights/texas-signs-responsible-ai-governance-act-into-law - CTTS — Making TRAIGA Compliance Workable: https://www.cttsonline.com/2026/06/23/managed-it-services-texas-making-traiga-compliance-workable-for-your-business-in-2026/ --- ## TxDOT Has Saved 22,000 Staff Hours a Year With AI. Here's How. URL: https://texasaireport.com/news/txdot-government-ai-model/ Section: government · Published 2026-06-25 · By Matthew Bertram The Texas Department of Transportation has quietly built one of the most mature public-sector AI programs in the state — 200+ use cases identified, 30+ active initiatives, and a firm rule that humans stay in the loop. Key points: - TxDOT's invoice-workflow automation saves an estimated 22,000 staff hours per year, according to GovTech. - Microsoft 365 Copilot is deployed to more than 940 TxDOT staff; the agency has identified more than 200 AI use cases. - A 'Human-Led, AI-Supported' standard requires human validation of every AI-assisted output. - Three Texas laws effective September 1, 2025 — SB 1964, HB 2818, and HB 3512 — now require state agencies to inventory AI systems, stand up an AI division in DIR, and mandate AI training for government employees. The Texas Department of Transportation has saved an estimated 22,000 staff hours a year by automating invoice workflows — and that's one of more than 30 completed or active AI initiatives the agency was running as of January 2026, according to GovTech reporting. The number makes TxDOT an outlier in state government, and a useful benchmark now that Texas law requires every agency to catch up. ## What TxDOT has built TxDOT has identified more than 200 AI use cases internally, with another 20-plus projects in development. It has deployed Microsoft 365 Copilot to more than 940 staff. Its Enterprise Data Platform connects 51 data sources to feed AI-driven analysis. Completed deployments include invoice-processing automation (the source of the 22,000-hour figure), onboarding automation, and traffic-incident detection. On deck: a statewide incident-detection rollout, predictive-maintenance expansion, AI-assisted permitting reviews, and mandatory annual AI training starting this year. The agency's CIO, Anh Selissen, sits on the state's Public Sector AI Systems Advisory Board — a sign that TxDOT's work is feeding broader Texas government strategy rather than sitting siloed in one department. ## The governance rule that makes it work One policy underpins the whole operation: a "Human-Led, AI-Supported" standard that requires human validation of every AI-assisted output before it takes effect. It's simple enough to state in a sentence and consequential enough to head off the failure mode — automated decisions with no review — that tends to do the most institutional damage. That principle now has statutory backing. Three laws signed June 20, 2025 and effective September 1, 2025 set new floors for AI governance across all Texas state agencies: - **SB 1964** requires the Texas Department of Information Resources (DIR) to maintain an inventory of state AI systems, develop an ethics code, and mandate disclosure and risk assessments for high-stakes "Heightened Scrutiny AI Systems." - **HB 2818** creates a dedicated Artificial Intelligence Division within DIR to help agencies modernize legacy systems using generative AI. - **HB 3512** makes AI and cybersecurity training mandatory for state and local government employees, with DIR certifying approved programs. TxDOT was already operating ahead of those requirements. Most agencies are now building toward them. ## The benchmark worth tracking Our review turned up no other Texas agency with a public AI deployment profile as detailed as TxDOT's. That gap reflects where most of state government sits right now: the statutory framework is in place, the inventory and training mandates are live, and the AI Division at DIR has its mandate — but the operational depth TxDOT has accumulated takes years to replicate. The 22,000-hour figure is the concrete number to watch. If even a handful of agencies match TxDOT's invoice-automation savings in their own back-office workflows, the aggregate effect on state capacity would be hard to ignore. The September 2025 legislative package was built to make that possible; whether it happens is now an execution question, not a legal one. Sources: - GovTech — TxDOT AI Strategic Plan Update: https://www.govtech.com/artificial-intelligence/texas-department-of-transportation-updates-ai-strategic-plan - Jackson Walker — Texas 89th Legislature AI Package: https://www.jw.com/news/insights-texas-89th-legislature-ai/ --- ## Texas Enacts One of the Nation's First Comprehensive AI Laws URL: https://texasaireport.com/news/traiga-takes-effect/ Section: policy · Published 2025-06-22 · By Matthew Bertram Gov. Abbott signed HB 149 on June 22, 2025. TRAIGA takes effect January 1, 2026 — and it brings disclosure mandates, prohibited-use rules, and tiered civil penalties reaching $200,000 per violation for the most serious cases. Key points: - Texas is among the first states to enact a comprehensive AI governance law. - Government agencies must disclose AI interactions to consumers; healthcare providers must disclose AI use to patients. - Civil penalties are tiered: roughly $10,000–$12,000 for curable violations and $80,000–$200,000 for uncurable ones, enforced by the Texas Attorney General. - The law bans AI systems designed to incite self-harm or facilitate criminal activity. Texas Governor Greg Abbott signed [House Bill 149](https://legiscan.com/TX/bill/HB149/2025) — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA) — into law on June 22, 2025. The law takes effect January 1, 2026, putting Texas among the first states with a comprehensive AI statute on the books. ## What the law does TRAIGA runs on two tracks: disclosure and prohibition. **Disclosure mandates.** State and local government agencies must tell consumers when they're interacting with an AI system rather than a human. Healthcare providers face a parallel duty: patients must be told when AI is used in their care. **Prohibited uses.** The law bars deploying AI systems specifically designed to incite self-harm or facilitate criminal activity, along with systems built to infringe constitutional rights or to intentionally and unlawfully discriminate. The principles are broad; the enforcement contours will be drawn through Attorney General guidance and the first wave of enforcement actions. ## Enforcement The [Texas Attorney General](https://iapp.org/news/a/governor-signs-texas-responsible-artificial-intelligence-governance-act) holds exclusive enforcement authority. Civil penalties are tiered: roughly $10,000 to $12,000 for curable violations, $80,000 to $200,000 for uncurable ones, and $2,000 to $40,000 per day for continuing violations — a structure meant to separate good-faith stumbles from deliberate bad actors. ## Why Texas GCs and CISOs should act now The effective date is January 1, 2026 — six months from signing. For organizations that interact with Texas government entities or provide AI-assisted healthcare in the state, that window is tighter than it sounds. Compliance work usually means an AI system inventory, a disclosure-design sprint, and legal sign-off before go-live. TRAIGA establishes no private right of action, which limits litigation exposure but does nothing to reduce regulatory risk: the Attorney General's office has broad investigative authority and can move before a violation ever becomes public. Organizations that already keep NIST-style AI documentation and disclosure practices will start with a head start on the rest. Frequently asked questions: Q: What specific uses of AI does TRAIGA prohibit for every entity — public and private? A: TRAIGA's universal prohibitions apply to any developer or deployer regardless of industry: no AI system may be built with the sole intent to manipulate users into self-harm or criminal activity, to infringe constitutional rights, to engage in intentional unlawful discrimination, or to generate child sexual content or non-consensual deepfakes. Government agencies face two additional prohibitions that private entities do not: social-scoring systems and biometric identification without consent. Q: Does TRAIGA preempt local city or county AI ordinances in Texas? A: Yes. Under Tex. Bus. & Comm. Code 552.003, TRAIGA supersedes and preempts any city or county ordinance that regulates AI, setting one statewide compliance standard. A company operating in Dallas, Houston, or Austin faces no additional municipal AI rules on top of the state law. Q: Can a Texas company be penalized under TRAIGA for an AI system it has not yet deployed? A: No. The statute explicitly bars the AG from bringing a civil-penalty action over an AI system that has not yet been deployed. Pre-deployment testing and development sit outside the AG's enforcement reach under Tex. Bus. & Comm. Code 552.105(f). Sources: - HB 149 — Texas Legislature (LegiScan): https://legiscan.com/TX/bill/HB149/2025