Texas's AI Complaint Portal Went Live Today. The Public Record Starts Before Any Verdict.
By Yuri Bobbert
On September 1, 2026, the Texas Attorney General's online complaint portal under the Texas Responsible AI Governance Act (TRAIGA, House Bill 149) went live. The mechanism is simple: a job applicant who thinks an algorithm screened them out, a tenant who believes an AI system rejected their application, or a customer who suspects an AI tool denied them service can file a complaint from any browser. No lawyer required, no dollar threshold to clear.
TRAIGA gives Texans no private right of action. They cannot sue an AI operator directly under this law, a point confirmed both in the Transparency Coalition's line by line analysis of the bill and in TXAIMS' compliance breakdown of the enacted law. Several compliance teams read that fact as a reason to rank Texas below states with tougher liability exposure. The portal is the reason that reading is already outdated.
What actually changes today
TRAIGA gives the Texas Attorney General exclusive enforcement authority to open an investigation, issue a civil demand for records and risk assessments, and pursue penalties on the state's own initiative. The complaint portal is the intake mechanism that feeds that authority: a low friction channel through which any member of the public can flag a system for review, with no need to first prove standing or damages.
The detail that changes the calculus for legal and compliance teams is what happens to a complaint the moment it is filed. Under Texas's open records law, a filed complaint becomes a public record, discoverable well before the Attorney General decides whether to investigate, let alone before any finding is made. A company does not need to lose a case to have a complaint about its AI system sitting in the public record. It only needs someone to file one.
The law behind the portal, in plain terms
TRAIGA started life in late 2024 as a much broader bill covering any "high-risk" AI system and requiring annual impact assessments, a risk mitigation policy, and detailed consumer disclosures. As the Transparency Coalition documented in its guide to the revised bill, tech industry pushback in early 2025 led its own author to strip most of those affirmative duties out before it passed. What survived and was signed into law on September 1, 2025, taking full effect on January 1, 2026, is a narrower, intent based statute, as TXAIMS lays out in its rundown of what HB 149 actually requires.
In practice that means TRAIGA defines seven prohibited AI practices, among them subliminal manipulation, exploitation of a person's vulnerabilities, government social scoring, real time biometric surveillance, intentional unlawful discrimination, infringement of constitutional rights, and generation of child sexual abuse material, rather than regulating AI systems by risk category. Disparate impact alone is not enough to establish a violation; intent has to be shown. Documented alignment with the NIST AI Risk Management Framework acts as an affirmative defense, effectively a safe harbor for companies that can show their governance work. The Attorney General must give 60 days' notice before enforcement and a further 60 days to cure a violation before penalties apply, and those penalties range from $10,000 to $12,000 per general violation, $80,000 to $200,000 for a prohibited use, and $2,000 to $40,000 per day a violation continues uncorrected.
Why this should worry compliance teams more than the fines
For GRC and AI risk professionals, the shift is about where discovery risk now originates. Most AI governance programs are built to respond to a regulator's request or a litigation hold. This portal creates a third trigger: a member of the public, with no legal training and no obligation to be right, initiating a record that a journalist, a plaintiff's lawyer in an unrelated case, or a competitor can pull the moment it exists. A risk register that only tracks formal investigations is now missing the step where exposure actually begins.
For Entrepreneurs and Tech Founders operating any product that screens, scores, or ranks people in Texas, hiring tools, tenant screening, lending, insurance pricing, customer service triage, the practical question changes from "could we be sued" to "could someone file a complaint we would need to explain publicly." The second question has a much lower bar, and it arrives much sooner in a product's life.
A company does not need to lose a case to have a complaint about its AI system sitting in the public record. It only needs someone to file one.
TRAIGA against the EU AI Act: two different bets on how to regulate AI
Set side by side, TRAIGA and the EU AI Act make almost opposite wagers on what actually reduces AI harm.
- Regulatory logic: Texas prohibits a defined list of intentional bad uses. The EU classifies systems into risk tiers and imposes affirmative obligations, conformity assessments, technical documentation, human oversight, and post-market monitoring on anything that lands in the high-risk category, regardless of intent.
- Trigger for liability: under TRAIGA, disparate impact alone does not establish a violation; intent has to be shown. Under the EU AI Act, a system's classification and characteristics trigger obligations whether or not anyone intended the outcome.
- Pre-deployment duties: Texas stripped out its impact assessment and risk mitigation policy requirements before the bill passed. The EU requires both, plus a technical file, before a high risk system can be placed on the market.
- Safe harbor: TRAIGA gives companies an affirmative defense for documented alignment with the NIST AI Risk Management Framework. The EU AI Act instead offers a presumption of conformity for following harmonized technical standards, a narrower and more prescriptive route to the same idea.
- Enforcement architecture: Texas centralizes enforcement in a single Attorney General with a mandatory 60-day cure period before any penalty. The EU splits enforcement between the AI Office for general-purpose and frontier models and national market surveillance authorities across 27 member states, with no universal cure period.
- Penalties: TRAIGA tops out at $200,000 per violation, plus $2,000 to $40,000 per day of continued noncompliance. The EU AI Act reaches up to €35 million or 7 percent of global annual turnover for banned practices.
- Public discovery: Texas's new portal turns any complaint into a public record the moment it is filed. The EU AI Act gives regulators investigative and information request powers, but no equivalent pipeline that turns a member of the public's complaint into a citable record before an investigation opens.
What the EU could learn from Texas
Not everything in TRAIGA is worth copying, an intent standard that lets disparate impact alone go unpunished trades away real protection for people affected by biased systems. But a few design choices are worth Brussels's attention.
A single, clearly defined safe harbor tied to a recognized framework gives compliance teams a concrete finish line rather than an open ended list of documentation duties. The EU AI Act's harmonized standards route is meant to do something similar, but it remains slow to publish and hard for smaller companies to navigate; a NIST-style affirmative defense that companies can point to today, not once a standard is finalized years from now, would close that gap faster.
A mandatory cure period before financial penalties rewards a company for fixing a problem rather than simply having had one. That does not need to replace the AI Act's fine structure, but it could sit alongside it for lower severity findings, reducing the number of enforcement actions that turn into disputes over an outcome the company was already correcting.
A single enforcement authority per question reduces coordination cost. The EU's own ongoing effort to clarify which matters sit with the AI Office and which sit with national authorities suggests this is already a recognized gap, and Texas's one Attorney General, one portal model is a simpler reference point than anything currently on offer in Europe.
A dedicated public complaint channel for AI systems, separate from general consumer protection portals, would give the EU an early signal of where enforcement attention is needed, the same function TRAIGA's portal now performs for Texas, without waiting for a formal market surveillance investigation to surface the issue.
What it would mean for companies if the EU had written a law like this
Imagine, for a moment, that Brussels had passed a TRAIGA-style statute instead of, or alongside, the current AI Act. The practical effect on a company operating across the EU would cut in more than one direction.
The scope of day to day duty would shrink for most deployments. Instead of classifying every AI system, assessing its risk tier, and maintaining a technical file and quality management system for anything in the high risk category, most companies would only need to screen their systems against a short, defined list of prohibited practices. For the large share of AI use cases that never touch those categories, compliance overhead would fall sharply.
The bar for liability would rise just as sharply. Intent is hard to prove. A company facing a discrimination complaint about a hiring or lending algorithm today, under the EU AI Act's outcome based approach, would face materially lower enforcement risk if intent could not be demonstrated, an easier position for the company, a harder one for the person affected by a biased outcome the law was designed to catch.
Cost and time to market would likely fall. Without a mandatory conformity assessment or CE-marking-style process for high risk systems, deployment could move faster, at the cost of losing the specific, documented market access certainty that a completed conformity assessment currently provides to a buyer or investor doing diligence.
Legal exposure would shift in character, not just in size. A Texas-style complaint portal at EU scale would mean facing reputational and discovery risk earlier and more often, since a complaint becomes a public record whether or not it has merit, a different kind of risk to manage than a market surveillance authority's request for technical documentation, and one that a company cannot always predict or control.
Tail risk would likely fall, and so would predictability of protection. EU-wide fines would probably be lower on average and slower to land given a cure period, but a single-authority model spread across 27 member states with different enforcement cultures could reproduce exactly the kind of fragmented, unpredictable patchwork the AI Act was written to avoid in the first place, unless paired with the same kind of centralized guidance Texas gets from having one Attorney General and one portal.
The pattern behind the story
Texas is not acting alone. It joins a fast growing list of jurisdictions where the binding rule sits at the state or local level rather than in a single federal statute, a pattern we mapped in detail when we counted 109 separate AI laws already in force across the United States. TRAIGA's portal adds a new kind of obligation: the evidence a company needs is no longer just the ability to defend a decision after a regulator asks. It is the ability to explain, on short notice and in public, why an AI system made the call it made, before anyone in government has even opened a file.
That is a continuous governance problem, not a periodic one, whether the underlying law is intent based like TRAIGA or risk based like the EU AI Act. A risk assessment completed at launch and revisited once a year will not help a team asked to respond to a complaint six months later about a model that has since been retrained, and a NIST-style safe harbor is only worth as much as the evidence behind it. This is the gap insAIght is built to close: keeping an inventory of AI systems, their purpose, and their risk controls current and audit-ready at all times, so a complaint or a regulator's request, wherever it originates, is met with an answer instead of a scramble.
Learn more
- insAIght: continuous AI governance and risk mapping
- There Is No AI Law in the United States. There Are 109.
- Transparency Coalition: The revised guide to TRAIGA 2.0
- TXAIMS: Has Texas HB 1481 Passed? What You're Actually Looking For
- Duane Morris: Texas' AI Law Is Now in Effect
See how insAIght keeps your AI risk evidence ready before a complaint is ever filed, on either side of the Atlantic. Book a demo.