Texas TRAIGA, Utah’s disclosure regime, and New York’s RAISE Act

Lesson 5 of 6 in State AI Laws in Depth: Colorado, California, Texas, Illinois, NYC, and Beyond.

Three more regimes complete the map, and they could hardly be more different from each other: Texas built a prohibition law, Utah built a disclosure law, and New York built a frontier-safety law.

Texas TRAIGA (HB 149) — signed June 22, 2025, effective January 1, 2026 — is the red-state answer to Colorado. Instead of duty-of-care obligations on high-risk systems, it prohibits a short list of uses, and — the load-bearing word — most prohibitions require intent: developing or deploying AI with intent to manipulate human behavior into self-harm or crime, or with intent to unlawfully discriminate against protected classes. The statute says expressly that disparate impact alone does not establish intent — a direct repudiation of the disparate-impact logic in Illinois and the original Colorado act. Government-specific bans (social scoring, biometric identification without consent) and prohibitions on unlawful sexual deepfakes and child-exploitation content round out the list. Government agencies must disclose when consumers interact with AI; healthcare providers must disclose AI use in treatment contexts.

TRAIGA’s enforcement design became a template: AG-exclusive enforcement, a 60-day cure period, tiered civil penalties (larger for uncurable or intentional violations), no private right of action — and, critically for this domain, a substantial-compliance defense keyed to the NIST AI RMF: a defendant whose program substantially complies with the RMF (or a documented internal equivalent) has a defense to enforcement. Add a 36-month regulatory sandbox run with the new Texas AI Council, plus amendments tightening the state biometric (CUBI) and privacy (TDPSA) laws, and you have the most innovation-forward comprehensive state law — one that still manages to make the voluntary RMF legally valuable.

Utah’s AI Policy Act (SB 149) was first, quietly: effective May 1, 2024, the first state GenAI disclosure statute. If you use generative AI in an activity covered by consumer-protection law, you must disclose it when asked; regulated occupations (doctors, lawyers, therapists…) must disclose prominently and proactively. The Office of AI Policy runs a Learning Laboratory that can grant participating companies regulatory mitigation agreements — reduced penalties in exchange for supervised innovation. 2025 amendments narrowed the disclosure triggers (SB 226), extended the sunset to July 1, 2027 (SB 332), and added mental-health chatbot rules (HB 452).

New York closed 2025 with the RAISE Act (signed December 19, 2025, effective January 1, 2027) — the East Coast counterpart to SB 53: frontier-model developers must adopt safety protocols and report safety incidents. Alongside it, the LOADinG Act governs state-agency use of automated decision systems. When RAISE goes live in 2027, a frontier developer will answer to two overlapping state safety regimes plus whatever the federal voluntary framework asks — the exact multiplicity EO 14365 was written to attack.

Texas: prohibit

Theory: ban the worst uses, require intent, leave everything else alone. Hook for practitioners: the NIST RMF substantial-compliance defense — the strongest legal payoff for RMF adoption anywhere in US law. Enforcement: AG only, 60-day cure, tiered penalties, sandbox.

Utah: disclose

Theory: people are entitled to know when they are talking to a machine; regulated professionals must volunteer it. Hook: the Learning Laboratory’s regulatory mitigation agreements — negotiated, supervised flexibility. Enforcement: Division of Consumer Protection; statute sunsets July 1, 2027 unless renewed.

New York: frontier safety

Theory: catastrophic risk from frontier models is a state consumer-protection concern when Washington will not act. Hook: from January 1, 2027, safety protocols and incident reporting for frontier developers — read it together with California SB 53, because most covered developers will owe both. Enforcement: AG; LOADinG Act separately constrains state-agency automated decisions.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.