The Texas Responsible AI Governance Act took effect on January 1, 2026. Almost everything written about it since has been aimed at enterprises with in-house counsel and a governance office. The companies most exposed are the ones nobody is writing for: mid-sized Texas businesses that adopted AI tool by tool, without an inventory, a policy, or an owner.
The short version
TRAIGA sets obligations for organizations that develop or deploy AI systems in Texas. The details matter and counsel should read them against your specific use, but the practical shape is familiar to anyone who lived through early privacy law. Know what AI you use. Know what it decides. Be able to explain it. Have a human accountable for it. Do not use it to do prohibited things.
That list sounds manageable until you try to produce it. In my work with leadership teams, the first request that breaks is the simplest one. Show me one inventory of the AI in this company. Most mid-sized firms cannot, because most of their AI arrived without an announcement. Employees adopted tools on their own. Vendors quietly added AI features to software the company already ran. IBM's 2025 research put the average cost of a breach involving shadow AI at $4.63M, and shadow AI is exactly what an unwritten inventory looks like from the inside.
Why mid-sized companies are the exposed middle
Enterprises have governance teams. Ten-person shops fly under most thresholds and most scrutiny. The exposed band is the middle. Enough employees to have real shadow AI, enough customers for AI decisions to matter, enough revenue to be worth a complaint, and no one whose job is governance.
The uncomfortable part is that the gap is rarely technical. It is organizational. When I ask who owns AI decisions, including the decision not to deploy something, the room usually looks at the CIO, the CIO looks at legal, and legal looks back at the room. An unowned obligation is an unmet obligation.
The five questions your board should ask this quarter
Directors do not need to read the statute. They need to ask questions management cannot answer with confidence unless the work is done.
One. Do we have a single inventory of the AI systems, vendors, and features in use across the company? Two. Which of those systems make or influence decisions about people, money, or safety? Three. Can we explain, in plain language, how each of those systems reaches its result? Four. Who is the named owner of AI governance here, and what did they change last quarter? Five. If a regulator or a plaintiff asked for our AI records tomorrow, what would we actually be able to produce?
If those five come back solid, TRAIGA is mostly paperwork. If two or more come back as silence, you have found your exposure, and it existed before the law did. The law just gave it a docket number.
What to do about it
Start with the inventory, because everything else depends on it. Then assign the owner, write the plain-language policy for employee AI use, and put a human review step in front of any AI output that touches customers. None of this requires new software. It requires a decision that someone owns it.
A scored readiness review compresses this into two to four weeks and gives your board a number instead of a shrug. Whether you do it with me or on your own, do it before the first demand letter does it for you.
This article is not legal advice. Read the act with counsel. But do not wait for counsel to build the inventory. That part is just management.