Atlantic Health Strategies

TRAIGA Section 552.052: What Texas’s AI Behavioral Manipulation Ban Means for Behavioral Health Operators

Table of Contents

Ready to See Results?

From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.

The short answer, and why the clock started January 1

If you operate a treatment center in Texas, license a digital intake tool, or contract with a vendor whose chatbot reaches a Texas resident, the Texas Attorney General can now investigate you under TRAIGA. Effective January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act governs entities deploying artificial intelligence in Texas and establishes requirements for those deploying AI systems and prohibitions on certain types of AI uses.

The penalty math is not theoretical. Per the Texas Attorney General’s own consumer page, civil penalties may range from $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 for each day a violation continues. Sixty-day cure window after AG notice. That is the whole answer. The rest is documentation.

The statutory language on behavioral manipulation is unusually short. Section 552.052 prohibits a person from developing or deploying an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self-harm (including suicide), harm another person, or engage in criminal activity. Norton Rose Fulbright’s team reads the word “harm” liberally: “harm” under this section may be interpreted liberally, particularly since “harm” is a separate sub-section from criminal activity, which could indicate that it includes harm in the civil context; in other words, TRAIGA’s prohibition on “harm” could be quite broad and apply to many different “harmful” outcomes (for example, monetary harm). Read it liberally. A Texas court likely will.

The reach is wider than most treatment center CEOs assume. TRAIGA applies to anyone who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas. If your alumni app engages a former patient who moved to Fort Worth, the statute reaches you, even if your headquarters sits in Tennessee or Florida.

The penalty math and who enforces it

The Texas Attorney General has exclusive authority to enforce TRAIGA, unless the AG has recommended additional enforcement by another state agency, and may issue civil investigative demands, seek civil penalties, injunctive relief, attorney’s fees, and reasonable court costs or investigative expenses. There is no private right of action. Good news? Not really. It concentrates power in a single office and speeds decisions.

Skadden’s team adds the sanction stack for licensed operators: following an enforcement action by the attorney general, other state agencies may impose additional sanctions on licensed, registered or certified persons, including fines up to $100,000 and suspending or revoking their authorization to conduct business activities. For a Texas treatment center, the Texas Health and Human Services Commission (HHSC) and the Texas Medical Board can stack sanctions on top of the AG action. One AI-driven incident can therefore accumulate three ways: an AG civil penalty up to $200,000, an agency license penalty up to $100,000, and continuing daily penalties up to $40,000 until cured.

One structural point operators miss: TRAIGA does not require an AI system to have been built for a harmful purpose to be worth scrutinizing. Intent is the legal standard. Capability is the investigative trigger. If the Texas Attorney General receives a complaint through TRAIGA’s online reporting mechanism, TRAIGA allows the AG to issue (without also requiring it to issue a notice of violation) a civil investigative demand to determine if a violation has occurred, which can require a company to provide AI system descriptions (including intended use, purpose and training data), input data details, outputs, performance metrics and known limitations, and post-deployment monitoring and user safeguard measures. That portal, and the CID that follows it, is your practical deadline.

Why this hits behavioral health harder than other sectors

Conversational AI, symptom-triage bots, peer-support companions, and EHR-embedded clinical decision support all sit inside TRAIGA’s definition. The Texas AG defines the term this way: “artificial intelligence system” means any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations. That captures the predictive risk-stratification tool your EHR vendor bolted on last quarter.

Federal regulators are already moving on the underlying harm pattern. On September 11, 2025, the FTC issued 6(b) orders to seven companies that operate consumer-facing AI chatbots, seeking information on how these firms measure, test, and monitor potentially negative impacts of this technology on children and teens. FTC Chairman Andrew Ferguson framed it plainly: “As AI technologies evolve, it is important to consider the effects chatbots can have on children”. The order letters went to Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap, and xAI.

Consumer-facing volume is not slowing. Common Sense Media’s research, based on a nationally representative survey of 1,060 teens aged 13 to 17 conducted in April and May 2025, found that 72% of teens have used AI companions at least once, and over half (52%) qualify as regular users. Reporting on the same dataset noted that Character.AI is being sued over a teen’s suicide in Florida and for promoting violence in Texas. Volume up. Scrutiny up. Civil discovery record being built in real time.

For Texas residential programs, PHP (an outpatient level of care), and IOP operators, the implication is direct. If your patient engagement platform sends automated check-ins, if your intake bot screens for suicidal ideation, if your alumni app uses an LLM to respond to cravings or crisis disclosures, then the Texas AG, HHSC, the Texas Medical Board, and CMS surveyors reviewing Conditions of Participation can all ask how you documented the safeguards. Joint Commission and CARF surveyors will pull the same thread during accreditation review.

What operators should do before the first enforcement action lands

TRAIGA gives compliance officers something they rarely get: a written safe harbor. The American Bar Association’s Business Law Today analysis confirms that safe-harbor provisions incentivize businesses to document compliance with frameworks like the NIST AI Risk Management Framework, conduct adversarial testing, and preserve audit trails, strengthening defenses against algorithmic bias and intentional-use allegations. Operators who documented their framework alignment on January 1 are already inside the safe harbor. Everyone else is exposed.

AHS recommends the following to behavioral health clients operating in Texas:

  • Inventory every AI touchpoint. Intake, EHR modules, marketing chatbots, alumni apps, payer-facing utilization management automations. If it infers and generates, it counts.
  • Document intent for each system. Write the legitimate clinical or operational purpose. Write what the tool is not designed to do. Date it. File it. Baker Botts frames the practical result: while TRAIGA doesn’t explicitly mandate extensive record-keeping, proving lack of discriminatory or harmful intent effectively requires organizations to maintain detailed documentation of AI system purposes, design decisions, and intended use cases; companies should consider documenting their legitimate business purposes for AI systems, testing protocols that demonstrate efforts to prevent prohibited uses, and clear policies restricting system deployment to lawful purposes.
  • Map escalation pathways for self-harm language. Every conversational system should hand off to a human clinician on detection, and the handoff should be logged. Align the logic with SAMHSA’s 988 protocols where applicable.
  • Update vendor MSAs. Add TRAIGA-specific representations, audit rights, and indemnification. Vendor assurance letters are not a defense.
  • Align governance with the NIST AI RMF. That is the affirmative defense the statute names by category.
  • Confirm healthcare disclosure compliance. Ropes & Gray notes that in healthcare, providers must disclose AI use to patients or their representatives before or at the time of service, except in emergencies, where disclosure must occur as soon as reasonably possible. Layer that on top of HIPAA and 42 CFR Part 2 obligations enforced by HHS OCR and SAMHSA.

Compliance officers should have documentation defensible by the date the AG publishes the complaint portal, not by some later date the AG chooses to investigate.

The bigger picture for multi-state operators

Texas joined Colorado as one of the first states to enact broad AI legislation. TRAIGA also preempts local regulations, so Texas cities and counties cannot impose their own AI rules. Other states are watching, and enforcement patterns will diverge. Multi-state operators running facilities in Florida, Texas, and Tennessee cannot rely on one AI governance policy and assume it travels.

Colorado uses a risk-based standard. Texas took the opposite path. As Baker Botts summarized, TRAIGA’s most significant innovation lies in its intent-based liability framework; unlike impact-focused regulations that create strict liability for discriminatory outcomes, Texas requires proof of intentional misconduct, which provides businesses with clearer compliance guidelines while maintaining consumer protections against deliberate abuse. That is a governance design difference, not a semantic one.

CEOs and compliance officers should treat TRAIGA as a live enforcement regime. Pull the AI inventory this quarter. Get the documentation defensible before the AG’s complaint portal goes live. The penalty math is too steep, and the reputational exposure for a behavioral health operator tied to an AI-induced harm allegation will outlast the fine by years, especially if CMS, the DEA, or a Joint Commission surveyor cross-references the finding during a separate review.

AHS works with treatment center operators on AI governance reviews, vendor MSA updates, and NIST AI RMF alignment. If you run a facility in Texas and you have not inventoried your AI touchpoints, that is the first call to make this month.

Frequently asked questions

When did TRAIGA take effect and who does it apply to?

TRAIGA took effect January 1, 2026. Per Norton Rose Fulbright, it applies to anyone who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. Out-of-state behavioral health operators whose AI tools reach Texas residents are within scope.

What are the civil penalties under TRAIGA Section 552.052?

Per the Texas Attorney General, civil penalties range from $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for continuing violations, with a 60-day cure period after AG notice. The AG holds exclusive enforcement authority and may also seek injunctive relief, attorney’s fees, and investigative expenses. There is no private right of action. For licensed persons, state agencies may separately impose sanctions including license suspension or revocation and fines up to $100,000 (Skadden).

Does Section 552.052 apply to clinical chatbots and patient engagement tools used by treatment centers?

Yes, if the system could be interpreted as intentionally inciting or encouraging self-harm, harm to others, or criminal activity. TRAIGA’s AI system definition is broad enough to cover symptom-triage bots, peer-support companions, alumni engagement apps, and EHR-embedded clinical decision support. The FTC’s September 11, 2025 Section 6(b) orders to seven consumer-facing AI chatbot companies (Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap, and xAI) and Common Sense Media’s 2025 study finding that 72% of 1,060 surveyed U.S. Teens ages 13–17 have used AI companions at least once are widening the underlying evidentiary record on chatbot harm to minors.

What is the safest compliance posture for a Texas behavioral health operator?

Substantial adherence to the NIST AI Risk Management Framework, combined with internal audits and adversarial or red-team testing, functions as an affirmative defense against TRAIGA enforcement (per the ABA’s Business Law Today analysis). Operators should inventory every AI touchpoint, document intent and design decisions for each system, log self-harm escalation pathways aligned with SAMHSA’s 988 protocols, update vendor MSAs with TRAIGA-specific representations and audit rights, and confirm healthcare AI-use disclosures on top of HIPAA and 42 CFR Part 2 obligations.

Request a Free Consultation

Scroll to Top