I have filed exactly one complaint with a government agency in my life. It concerned a utility company, it took about forty minutes, and I never heard anything back — not a rejection, not an update, nothing. I assumed at the time that the form existed to absorb my annoyance rather than to do anything with it, and I have been quietly cynical about complaint portals ever since.
So when I learned that Texas had built one for artificial intelligence, my instinct was to file it under theater. That instinct turned out to be wrong, but not in the direction I expected. The page is not decorative. Under the Texas statute it is closer to an ignition switch — and what it starts is a machine with some very particular limits built into it.
The page, and the sentence that makes it matter
The Texas attorney general's office now runs a page called Consumer AI Rights, sitting inside its consumer-protection section, ending in a button marked File An AI Complaint. It explains that as of January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act — TRAIGA — "governs entities deploying artificial intelligence ('AI') in Texas."
That page exists because a legislature said it had to. Section 8 of the enrolled bill is blunt: "Not later than September 1, 2026, the attorney general shall post on the attorney general's Internet website the information and online mechanism required by Section 552.102." A deadline, written into statute, for building a web page. Legislatures do not usually bother unless they think the page is load-bearing.
And in this law, it is. The provision creating the mechanism is one sentence long: the attorney general "shall create and maintain an online mechanism … through which a consumer may submit a complaint under this chapter." The next section is the one to read twice. Section 552.103 opens: "If the attorney general receives a complaint through the online mechanism under Section 552.102 alleging a violation of this chapter, the attorney general may issue a civil investigative demand."
If. Within this chapter, the investigative power does not exist until somebody files. The office can then demand serious things — including "a description of the type of data used to program or train the artificial intelligence system" and "any known limitations" of it. But the chapter contains no other route to that power. Texas built a law whose enforcement engine will not turn over until a member of the public turns the key.
I want to be precise, because this is easy to overstate and I nearly did. The attorney general is not powerless without your complaint in general — the office's authority under the Deceptive Trade Practices Act runs on entirely separate rails. What is true is narrower and still remarkable: TRAIGA's own investigative machinery is switched on by a complaint from someone like you.
So the button matters. Now look at what it can reach.
Everything turns on the word "intent"
Here is the part that reorganized my thinking about this whole statute.
Section 552.056 says a person "may not develop or deploy an artificial intelligence system with the intent to unlawfully discriminate against a protected class." And then, in case anyone thought to prove that the ordinary way, subsection (c): "For purposes of this section, a disparate impact is not sufficient by itself to demonstrate an intent to discriminate."
Read that second sentence for what it forecloses. The standard method of showing algorithmic discrimination is to demonstrate that a system produces systematically worse outcomes for a protected group. Texas has said that evidence, standing alone, does not get you where you need to go.
It is not confined to the discrimination section either. The prohibition on behavioral manipulation reaches systems deployed "in a manner that intentionally aims to incite or encourage" self-harm. Two other prohibitions require sole intent — a person may not deploy a system "with the sole intent" of infringing constitutional rights, or "with the sole intent of producing" certain unlawful material. A system with a mixed purpose, or a merely reckless one, sits outside them.
Then the belt and braces. There is a rebuttable presumption "that a person used reasonable care." There is a defense for substantially complying with the National Institute of Standards and Technology's generative-AI risk framework. The attorney general may not sue for sixty days after notifying you, so you can cure. And the penalties, when they land, are tiered: $10,000 to $12,000 for a curable violation, $80,000 to $200,000 for an uncurable one, and $2,000 to $40,000 for each day a violation continues.
Finally, the clause that decides who is allowed to care: TRAIGA "does not provide a basis for, and is not subject to, a private right of action." If the attorney general does not act, nobody does. An employment-law firm put the practical upshot about as plainly as it can be put — an AI hiring tool that produces skewed outcomes but was not designed to do so does not violate this law, though it may still run afoul of federal statutes like Title VII, which do allow claims based on unequal outcomes.
The question the definitions raise
Now something the law does not announce, and which I have not seen discussed anywhere.
The complaint mechanism is open to "a consumer." That word is defined in the subtitle's definitions section as "an individual who is a resident of this state acting only in an individual or household context" — and then, expressly: "The term does not include an individual acting in a commercial or employment context."
Sit with that against the most common way an ordinary person actually meets a consequential AI: a résumé screen. On a plain reading of these two provisions together, the person likeliest to be sorted by an algorithm may not be the kind of person the complaint portal was built for.
I am not going to tell you that is settled, because it is not. It is a reading of two definitions sitting next to each other, not a court holding, and I would be glad to be told I have it wrong. But it is the first question I would want a Texas legislator asked, and the answer should not require a lawsuit to discover — particularly since nobody can bring one.
One more thing before you file. The page you file from says it in a heading: Your Complaint Is Public. The text underneath — "Know that under Texas law your complaint is open to the public" — comes from the Consumer Protection Division's own practice under the state's open-records law, not from TRAIGA, which says nothing about disclosure. The office's FAQ hedges it slightly: complaints are "records generally open to the public," meaning any member of the public may request a copy. Nobody publishes your complaint. Somebody can ask for it. If you are complaining about your employer's software, that distinction is worth understanding before you type your name.
So Texas gutted it. Right?
That is the piece I expected to write, and the evidence would not let me.
Because there is a serious argument for this design, and it is not a fig leaf — it is a documented, pre-registered position. In 2021 the U.S. Chamber of Commerce's litigation-reform arm published a five-point critique of Illinois' biometric privacy law, listing what a biometric-privacy statute ought to do instead: preclude private rights of action, vest exclusive enforcement in the attorney general, cap damages, establish notice-and-cure periods, and offer safe harbors.
TRAIGA does all five. Every one. Texas did not stumble into this shape; it implemented a business-side blueprint with precision.
And here is the part that genuinely complicated my view. The obvious retort — that attorney-general-only enforcement means no enforcement — has a Texas-sized counterexample sitting in the state's own record. Texas's biometric statute is also AG-only, with no private right of action, and in 2024 it produced a $1.4 billion settlement with Meta — described by the office as the largest privacy settlement any attorney general has ever obtained. Illinois' private-right-of-action statute, by contrast, produced a celebrated $650 million settlement from Facebook, which worked out to at least $345 each for 1.6 million residents.
One prosecutor with subpoena power recovered more than 1.6 million plaintiffs did. If your model of enforcement is "private suits are strong, regulators are weak," that pair of numbers should cost you some sleep.
The bill's author defends the cure period on similar practical grounds. Representative Giovanni Capriglione told the IAPP that the law was written to stop businesses knowingly deploying harmful systems, and that the cure window "is a benefit to the business, which is as long as they fix the problem, they'll avoid penalties." That is a coherent theory of regulation: you want the harm stopped, not the company destroyed.
So the honest position is not that Texas built a fake law. It is that Texas built a law optimized for a particular kind of wrongdoer — the one who meant it — and that this is a real choice with real trade-offs, made in the open.
Meanwhile, in Illinois, the opposite bet is eighteen years old
Illinois ran the other experiment, and it has been running long enough to have results.
Its Biometric Information Privacy Act does precisely what TRAIGA withholds. Section 20 gives "any person aggrieved by a violation of this Act" a right of action, with liquidated damages of $1,000 for negligent violations, $5,000 for reckless or intentional ones, plus attorneys' fees. No attorney general required.
And in 2019 the Illinois Supreme Court explained why that architecture was deliberate. In Rosenbach v. Six Flags, holding that a plaintiff need not show any injury beyond the violation itself, the court wrote: "Other than the private right of action authorized in section 20 of the Act, no other enforcement mechanism is available." Because of that, "those entities have the strongest possible incentive to conform to the law and prevent problems before they occur and cannot be undone."
That is Texas's design read backwards in a mirror. Illinois built deterrence out of the certainty that thousands of people can sue you. Texas built it out of the possibility that one official might.
Now the honest half, because Illinois is not a happy ending. By the defense firm Duane Morris's count, 427 BIPA suits were filed in 2024, against 57 in 2017 — and different trackers give materially different series, so treat any single number as one firm's methodology rather than a fact about the world. The Chamber of Progress — a tech-industry-backed group, which is worth knowing before you weigh the finding — reported that across eight consumer settlements, plaintiffs' lawyers averaged $11.5 million per firm per case while individuals averaged $506, and that the overwhelming majority of suits were employer-employee disputes about fingerprint time clocks — not the surveillance dystopia the law was written for. The Illinois Policy Institute wants the statute reformed or repealed. And in 2024 Illinois itself pulled back, amending BIPA so that repeated scans of the same person by the same method yield at most one recovery.
Two states, two coherent theories, and a lopsided evidence base: Illinois has eighteen years of results to argue about and Texas has eight months, which is its own reason for humility. Neither model is obviously winning. That is the actual state of play, and anyone selling you certainty about it is selling something.
Run it forward
Here is the version of 2029 I find most plausible, and it is not dramatic.
The portal works exactly as designed. Complaints arrive — some serious, most not, because that is what public complaint channels receive. The office triages them with the twelve new full-time staff the fiscal note anticipated. Occasionally one describes a system whose designers left behind evidence of what they meant to do: a Slack message, a product spec, a marketing deck promising exactly the sort of filtering the law forbids. Those cases proceed, and some of them are genuinely important.
Everything else fails not because it lacks merit but because it lacks a smoking gun. A screening model that quietly downranks candidates from certain zip codes, built by people who never discussed race and would be horrified to be accused of it, produces the disparate impact the statute says is not enough by itself. The complaint is closed. Nobody did anything wrong under Texas law, and the applicants never learn there was anything to complain about.
Which is not a failure of the portal. It is the statute working precisely as written — and it is why the intent standard, not the button, is the thing to argue about.
What the people who study this are saying
The sharpest version of the objection comes from the academy, and it is about capability rather than politics. Writing in the Stanford Law Review Online, Keith Swisher, a law professor at the University of Arizona, makes the point in seven words: "An algorithm, after all, has no intent." Intent-based doctrines, he argues, are "essentially useless in the algorithmic context because the 'decisionmaker' is a statistical optimization process that has no intent at all" — building classifications out of thousands of features that "bear no obvious relationship to race, sex, or other prohibited grounds."
From the consumer side, EPIC argues that where "Attorneys General have sole enforcement authority, we have seen little enforcement of (and compliance with) privacy laws," and quotes the privacy scholar Woodrow Hartzog making the uncomfortable structural point: "Regulators are more predictable than plaintiffs and are vulnerable to political pressure."
There is also a good rebuttal to the "intent is normal in consumer protection" defense, and it is empirical. The National Consumer Law Center's 2018 survey of state deceptive-practices statutes found that most states do not require proof of intent, that the handful which do are treated as having undercut their own enforcement, and that "proving intent or knowledge can be extremely difficult." Texas knows this: its own Deceptive Trade Practices Act has a private right of action and no intent element, and gives the attorney general seven days' notice before suing rather than sixty.
And from the limited-government right, Texas Policy Research urged legislators to vote no on HB 149 unless it were amended, pricing the machinery at a projected $25.06 million through August 2027. This law had critics on both flanks, which is usually a sign that something real was being decided.
What does this mean for you?
If you live in Texas, this is unusually actionable. Most of what I write about is not.
The button is real, and using it is the whole mechanism. TRAIGA's investigative power is triggered by complaints arriving through that page. If you have a genuine one, filing it is not a gesture — within this statute, it is the only thing that starts anything.
Write down what somebody meant to do, not just what happened to you. The law reaches deliberate harm. A complaint that says "this system rejected me and people like me" is weaker, under this statute, than one that can point to what the deployer knew, was told, or advertised. Save the marketing copy, the emails, the support chat where someone explained how it works.
Assume your complaint can be requested. The office says complaints are records generally open to the public. Nobody publishes them; anyone can ask. Decide what to put in the box accordingly.
If it happened at work or while job-hunting, get advice before relying on this law. The definition of "consumer" excludes people acting in an employment context, and the portal is open to consumers. Federal employment law does reach unequal outcomes, and that may be the better door.
Ask your legislator one question. Not "do you support AI regulation" — everyone says yes. Ask: why does the discrimination provision require intent, and does the complaint portal cover job applicants? Those two answers tell you more than any press release.
The button and the lock
I came into this expecting to find a suggestion box and found something more interesting: a real key, cut to fit a lock with very specific wards.
The page works. The statutory trigger is genuine, the investigative demand it unlocks has teeth, and the penalties are not trivial. Texas has also, in the same act, required that the harm be meant, foreclosed the standard proof of algorithmic discrimination, presumed the deployer careful, granted two months to fix it, and reserved the right to complain to a category of person that may not include the job applicant.
None of that is hidden. It is all in a chapter you can read on a state website in twenty minutes, which I would gently suggest is more transparency than most laws about you offer.
My vote? Use the button anyway. Not because I think most complaints will succeed — on this statute's terms, most will not. But every complaint that arrives is a fact on a public record about what these systems are doing to people, and a legislature that wrote a deadline for building the page can be shown what came through it. The intent standard is a choice, and choices made in one session get revisited in the next. The people who show up with evidence are the ones who get to argue for the revision.
Somebody you know is job-hunting in Texas right now, or running a company that just bought a screening tool. Send this to them — the button is genuinely useful and the fine print genuinely matters, and neither travels well as a headline. Everything the HAIA Foundation publishes is over here, and it gets around because readers pass it on.



