Skip to content
Securafy AI Lab by Securafy
AI Lab

TRAIGA Is Live and Colorado Rewrote Its AI Law: What Regulated Businesses Should Do Now

Texas's AI law took effect this year with a built-in reward for companies that document their governance work, while Colorado tore up its own AI law and started over before enforcement even began. This piece walks through what changed in both states, how insurance regulators are layering on their own AI rules, and why chasing each new statute is a losing strategy for compliance and sales teams alike. It closes with the specific program elements a regulated business needs in place regardless of which law is currently in force.

In this article

Texas's AI law took effect January 1 and rewards companies that can document alignment with a federal risk framework. Colorado spent the first half of 2026 delaying, then rewriting, its own AI law before it ever took hold. If your business sells into or operates inside a regulated industry, the answer is not tracking fifty separate statutes. It is one governance program built to hold up no matter which state law is live this quarter.

What does Texas's AI law actually require now that it is in effect?

The Texas Responsible AI Governance Act, known as TRAIGA, took effect on January 1, 2026, and it applies to any business that develops or deploys an AI system in Texas, sells a product or service used by Texas residents, or otherwise does business in the state. That scope reaches far past Texas borders. A healthcare group in Cincinnati or a regional bank in Columbus with Texas customers or Texas-facing tools falls under it just as squarely as a company headquartered in Austin.

TRAIGA bars specific intentional misuses of AI, including systems built to manipulate someone into self-harm or violence, to unlawfully discriminate, or to generate certain deceptive content. Enforcement sits exclusively with the Texas Attorney General, who can seek civil penalties up to 200,000 dollars per violation, though the law gives companies a 60-day window to cure a violation before that penalty attaches. The detail that matters most for regulated businesses sits inside the enforcement mechanics rather than the prohibitions themselves.

TRAIGA treats documented alignment with the NIST AI Risk Management Framework as evidence that a company acted reasonably and in good faith when a dispute arises. That is not a checkbox. It rewards a company that already runs a real AI governance program on the four functions NIST defines: Govern, Map, Measure, and Manage. Businesses that can produce documentation, testing records, and audit trails tied to that framework enter an enforcement conversation from a fundamentally different position than one that cannot.

Why did Colorado rewrite its AI law before it ever took effect?

Colorado passed a sweeping AI Act in 2024 built around a duty of care, mandatory impact assessments, and deployer risk management programs for anything classified as a high-risk AI system. Governor Jared Polis delayed the original February 2026 effective date to June 30, 2026, then, after lawmakers could not agree on amendments during a special session, signed SB 26-189 on May 14, 2026, replacing the law entirely and pushing the new effective date to January 1, 2027.

The replacement law abandons the original risk-based structure. It drops the duty of care, the deployer risk management programs, and most of the impact assessment requirements, and it narrows the target from broad "high-risk AI systems" to a more specific category of automated decision-making technology used in decisions like hiring, lending, and housing. Businesses that spent 2025 and early 2026 building compliance programs mapped to Colorado's original framework now have to reassess what actually survives into 2027.

That whiplash is the real lesson for compliance and operations leaders. A company that built its AI governance around Colorado's specific statutory language spent months of work on requirements that no longer exist. A company that built its governance around a framework like NIST's, and treated Colorado's law as one state-specific overlay on top of it, lost far less when the underlying statute changed shape.

How does insurance-specific regulation add another layer on top of state AI law?

Insurance carriers and agencies face a second, sector-specific track. The National Association of Insurance Commissioners issued a Model Bulletin on insurers' use of AI systems, and by the spring 2026 NAIC national meeting roughly two dozen states plus the District of Columbia had adopted it, with several more states, including California, Colorado, New York, and Texas, running their own insurance-specific AI rules instead. The bulletin expects insurers to maintain a written AI governance program, document testing for unfair discrimination, and extend that oversight to third-party AI vendors and models the carrier did not build itself.

Regulators are not stopping at bulletins. State insurance departments launched a multistate pilot of the NAIC's AI Systems Evaluation Tool in 2026, built specifically to assess an insurer's AI governance, risk management, and model oversight during examinations. An insurance business operating across several states is now answering to its home regulator's version of the bulletin, any state-specific insurance AI law where it writes business, and TRAIGA or a similar general-purpose statute wherever its policyholders or vendors sit in Texas.

Is a federal AI law about to replace this patchwork?

Not yet, and businesses should not plan around the assumption that it will. Congress considered a ten-year moratorium on state AI regulation inside a 2025 reconciliation bill, and the Senate stripped it by a 99 to 1 vote. A similar attempt to attach a moratorium to the National Defense Authorization Act also failed to pass.

President Trump signed an executive order on December 11, 2025, titled Ensuring a National Policy Framework for Artificial Intelligence, directing the Commerce Department to review state AI laws and creating an AI Litigation Task Force at the Justice Department to challenge statutes it considers unduly burdensome. The White House followed in March 2026 with legislative recommendations for a national framework. An executive order carries no statutory force on its own, and Congress has not passed the legislation the order calls for. States kept legislating regardless: by July 1, 2026, states had enacted 109 new AI laws for the year, close to the prior year's pace. Betting your compliance posture on federal preemption arriving on any predictable timeline is not a strategy a regulated business can defend to an examiner or a board.

What a defensible AI governance program actually looks like

Every one of the developments above points to the same practical conclusion. Build your program around a framework that regulators already treat as a credible baseline, then layer state and sector-specific requirements on top of it as they change. A program built this way typically includes:

  • A written inventory of every AI system in use, including vendor tools and embedded features, mapped to the business processes and data they touch, matching the Govern and Map functions of the NIST framework.
  • Documented testing for accuracy, bias, and unintended output before deployment and on a recurring schedule after, matching the Measure function.
  • Defined incident response and correction procedures when an AI system produces a harmful or discriminatory result, matching the Manage function.
  • Vendor oversight language in contracts requiring AI suppliers to disclose testing, training data sourcing, and known limitations.
  • An audit trail that a regulator, an insurer, or an enterprise customer's procurement team can review without a scramble.

That last point is where compliance stops being a defensive cost and starts affecting revenue. Enterprise buyers in healthcare, financial services, and insurance increasingly put AI governance questions directly into vendor security questionnaires and cyber insurance renewals. A sales team that can point to a documented, NIST-aligned program closes those reviews in days. A team scrambling to answer for the first time during a renewal or an RFP loses the deal to the timeline, not to the answer itself.

Building the program instead of chasing the next headline

None of this requires waiting for the next state legislature to act or the next executive order to clarify anything. Leadership teams that treat AI governance as a standing operational discipline, not a reaction to whichever state law made the news this month, are the ones still standing when Colorado rewrites its statute again or Texas regulators issue their first round of TRAIGA enforcement actions. Structured learning paths through Securafy AI Lab's AI governance certifications give compliance, operations, and sales leadership a shared, documented baseline to build that program on, rather than each department improvising its own interpretation of the rules.

Before building anything new, it helps to know where the gaps actually sit. A structured AI readiness assessment maps your current AI use against exactly the categories regulators and enterprise buyers are asking about: system inventory, testing history, vendor oversight, and incident response. Teams that want the deeper context behind why frameworks like NIST's keep showing up as the common reference point across state law can start with Securafy AI Lab's AI University, which walks through the reasoning regulators and courts are applying as this area of law keeps moving.

The state AI law landscape will keep shifting through 2027 and past it. Texas will start bringing enforcement actions under a law that is now nine months old. Colorado's replacement law takes effect at the start of 2027, and few expect it to be the final version. Federal preemption remains a stated goal without a passed statute behind it. None of that changes what a regulated business needs to do this quarter, which is build a documented, testable AI governance program now, tied to a framework that outlasts any single state's legislative session.

Your next step

If your team is still treating AI governance as a list of state laws to track rather than a program to run, that gap is the one worth closing first. Book a strategy call with Securafy AI Lab to walk through where your current AI use stands against the frameworks regulators, insurers, and enterprise buyers are already asking about.

Ric Hall
Ric Hall

Ric Hall is the Chief Revenue Officer at Securafy, with decades of experience in enterprise infrastructure, cloud technology, sales leadership, and business strategy.

He writes for leaders trying to make sense of big technology decisions without getting trapped in vague promises or polished sales language. His articles cover provider selection, IT budgeting, co-managed services, cybersecurity investments, modernization, and the questions businesses should ask before signing a contract.

Ric’s strength is connecting technical decisions to business outcomes, helping leaders understand not just what they are buying, but why it matters and whether it will still make sense 3 years from now.

Writes about: IT budgeting, provider evaluation, cybersecurity ROI, co-managed IT, cloud modernization, vendor selection, technology strategy

More from Ric Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.