AIセキュリティ

Intent vs Scale — Texas TRAIGA and New York RAISE Act: Two State AI Laws with Opposite Philosophies

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

Texas HB 149 TRAIGA (in force January 2026) punishes intent; New York RAISE Act (January 2027) punishes scale. Same "state AI law" label, opposite design.

Intent vs Scale — Texas TRAIGA and New York RAISE Act: Two State AI Laws with Opposite Philosophies
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

On 1 January 2026, Texas put HB 149 (TRAIGA) into force. Among the fastest US state AI timelines: six months after Governor Greg Abbott signed. That same month, New York's Governor Kathy Hochul locked in a chapter amendment to the RAISE Act, with force set for January 2027.

Press often pairs these two laws. Their design philosophies point opposite ways. Texas punishes intent; New York punishes scale (capability). Treat them as one "state AI regulation" bucket and Japanese compliance design will miss.

As the third and fourth forces after California and Colorado, both deserve a careful read. I keep coming back to the same board question: which state's logic does our product actually sit under?

TL;DR

  • TRAIGA: in force January 2026. Punishes malicious intent, outcome-focused. Applies if you serve one Texas resident; max roughly USD 200k per violation plus daily USD 40k
  • RAISE Act: force January 2027. Frontier developers only (USD 500M+ revenue × 10²⁶ FLOPs+); core duties are safety-protocol publication and 72-hour incident reporting
  • RAISE penalties sharply reduced by amendment: original USD 30M → amended max USD 3M (first violation USD 1M). Watch outdated press
  • Japanese impact is completely asymmetric: TRAIGA already hits many Japanese SaaS; RAISE is effectively zero today
  • Philosophy contrast: common-law tort model (TX) vs regulatory-state supervision (NY)

TRAIGA — outcome-focused liability for malicious intent

TRAIGA (Texas Responsible AI Governance Act, HB 149) passed as a pared-back 31-page bill on 31 May 2025 (signed 22 June), down from a 43-page December 2024 draft.

That cut tells the story. The original was a risk-based framework like the EU AI Act and Colorado: high-risk AI, developer/deployer duties of care, impact assessments, risk policies, employer disclosure. A close Colorado copy.

After the Republican triple win in November 2024 (White House and both chambers), HB 149 was reintroduced in March 2025. High-risk AI, impact assessments, duties of care, and risk policies vanished. What remained was a list of prohibited AI practices: five for private and government actors, two government-only.

Scope Prohibited practices
Private and government Self-harm inducing AI / unlawful discrimination AI / political-viewpoint discrimination AI (new conservative-values clause) / CSAM and illegal deepfake AI / constitutional-rights infringing AI
Government only Social scoring / biometric ID without consent

The philosophy in one line: liability turns on the intent of the creator or distributor, not end-user misuse; statistical disparate impact alone is not enough to prove intent.

That is closer to intentional torts than structural-discrimination doctrine. Classic liberal legislation: punish only intentional wrongdoers; leave good-faith innovators free.

Penalties are outcome-focused:

  • Curable violations: USD 10k–12k per instance
  • Incurable violations: USD 80k–200k per instance
  • Continuing violations: USD 2k–40k per day
  • 60-day cure period after AG notice
  • Preemption of city/county AI ordinances

The 60-day cure means good-faith violations can be fixed. Incurable cases still carry real deterrence up to USD 200k per instance.

I read this as a conservative-state minimal-regulation solution. Not comprehensive like the EU or Colorado, but limited to malicious harm. It aligns with Trump-era innovation priority; Florida, South Carolina, and peers may follow the Texas Model.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

RAISE Act — continuous supervision for frontier models only

New York's RAISE Act (Responsible AI Safety and Education Act) is extremely narrow: Large Frontier Developers only.

Amended definition: prior-year total revenue over USD 500M × frontier model over 10²⁶ FLOPs developed or operated in New York. In practice OpenAI, Anthropic, Google DeepMind, Meta, Microsoft, xAI and peers. Not Japanese AI startups. Not even SoftBank–Sony–Honda–NEC coalitions today.

Four core duties:

  1. Create and publish a frontier AI safety framework (protocol)
  2. 72-hour safety incident reporting to DHSES
  3. Within 24 hours to appropriate law enforcement / public safety if imminent severe physical harm
  4. Periodic public document updates

"Safety Incident" needs precision. Beyond Critical Harm (100+ deaths/injuries, or USD 1B+ rights/property/monetary damage), four types with demonstrable evidence of elevated risk:

  • Frontier model acts autonomously beyond user request
  • Model-weight theft, misuse, malicious use, careless release, unauthorized access, or "escape"
  • Critical failure of technical/administrative controls limiting model modification
  • Unauthorized use of a frontier model

Penalties were cut sharply. This is still the most common press error:

Violation Original (Dec 2025) Amended (from Mar 2026)
First Up to USD 10M Up to USD 1M
Subsequent Up to USD 30M Up to USD 3M

When you see "USD 30 million," check the 27 March 2026 chapter amendment to USD 3 million max.1 That changes board-level impact math.

Enforcement is exclusive AG power plus ongoing oversight inside DFS. A financial-style continuous supervision model applied to AI.

OpenAI and Anthropic supported RAISE. I read that as (a) raising barriers for smaller rivals and (b) publicizing existing safety commitments. Regulated parties inviting regulation is unusual in AI policy. Worth noticing, even if you never enter the threshold yourself.

Intent vs scale — one comparison table

Item Texas TRAIGA New York RAISE Act
Party politics Republican governor, Republican legislature Democratic governor, Democratic legislature
Philosophy Intent-based liability Capability-based responsibility
Who is covered Anyone serving Texas residents USD 500M+ × 10²⁶ FLOPs+ frontier developers only
Model Was EU/Colorado-like → cut to outcome-focused Same framework family as CA SB 53
Core duties Ban development/deployment with malicious intent Publish safety protocols; 72-hour incident report
Incident reporting (no explicit duty) 72 hours (24 hours if imminent harm)
Penalties USD 10k–200k per instance + daily USD 2k–40k First max USD 1M; subsequent max USD 3M
Private right of action No No
Local preemption Yes No explicit provision
Sandbox 36 months (DIR) None
Force 1 Jan 2026 (already live) 1 Jan 2027

Texas punishes bad acts; New York supervises large actors. If you know the EU AI Act: TRAIGA is "Annex III only, rest discarded"; RAISE is "GPAI systemic-risk only, rest discarded."

Completely asymmetric impact on Japanese companies

TRAIGA already covers many Japanese firms. Serving Texas residents is enough. Japanese IT services, HR tech, and generative-AI startups with US SaaS are generally in. Force since January 2026 means no real grace. Priorities:

  • Inventory prohibited-practice AI: political-viewpoint discrimination filters, self-harm risk in mental-health bots, unlawful discrimination in HR screening and credit scoring
  • Operationalize the 60-day cure: US counsel/PR intake that can receive AG notice; engineering that can remediate in 60 days
  • Local ordinances are preempted: Austin-style city AI rules yield to TRAIGA

Japanese firms in RAISE scope: effectively zero as of May 2026. A SoftBank–Sony–Honda–NEC frontier model operated in NY could change that years out.

Do not ignore RAISE entirely. Its 72-hour incident reporting will become a reference standard for global AI governance design. I would rather over-prepare for that clock than pretend the threshold will never move.

Implementing 72-hour incident reporting

Triggers run from when you reasonably believe learning or a safety incident occurred, not from confirmation. Doubt starts the clock.

Five implementation must-haves:

  1. Detection: real-time watch for the four incident types. MLOps + security monitoring fused
  2. Escalation criteria: engineering to legal/compliance within 24 hours (first ~48h investigate, last ~24h decide to report)
  3. Cross-border: 14-hour NY–Tokyo gap; 24/7 or at least clear Friday-to-Monday ownership
  4. GDPR / APPI alignment: pre-protocolized cross-border user data in reports
  5. Record preservation: full decision trail for later AG inquiry

Compared with California SB 53's 15 days (24 hours if imminent), 72 hours is very tight. The blind spot: RAISE includes demonstrable evidence of elevated Critical Harm risk, not only realized Critical Harm.

Honestly, this is the part that still gets messy in practice. Detection criteria look clean on a slide; Sunday-night Japan time is where they break.

Board decisions at the fork — WARP SECURITY

TRAIGA and RAISE show that US AI regulation's philosophical split is no longer academic. It is a compliance design problem. Texas service needs intent-based filters; NY frontier work needs capability-based supervision. Same company's AI governance runs on different logic by state.

TIMEWELL's WARP SECURITY is a two-day program where leadership and operators work the fork hands-on: Texas prohibited-practice inventory, NY 72-hour reporting flow, and one unified internal AI governance policy, in the same room.

Five tabletop incidents, including "Texas AG 60-day cure notice arrives Friday evening" and "NY DHSES 72-hour clock lands Japan-time Sunday night." Role-play, not slideware.

Intent states and scale states. Building an organization that can face both needs more than lectures.

Staggered application of the EU AI Act — what starts on 2 August 2026, and what does not

While US state philosophies diverge, the EU AI Act (Regulation (EU) 2024/1689) is rolling out in stages. This is where coverage most often goes wrong, so it is worth stating article by article.

2 August 2026 is the general date of application (Art.113, second paragraph). What starts on that date includes:

  • Chapter IV — transparency obligations (Art.50): disclosing AI interaction, machine-readable marking of synthetic content, deepfake disclosure
  • Chapter III Section 5 (Art.40–49) — harmonised standards, conformity assessment, CE marking, registration
  • Art.101 — the Commission's power to impose fines on GPAI model providers
  • Chapter VI and Chapters VIII–XI

Penalty levels sit in Art.99: up to €35 million or 7% of worldwide turnover (whichever is higher) for Art.5 prohibited practices, and up to €15 million or 3% (whichever is higher) for GPAI-related and other breaches. The penalty provisions themselves (Chapter XII, Art.99 and 100) have applied since 2 August 2025; what 2 August 2026 adds is Art.101.

What does not start on that date is the substantive high-risk regime. Under the amending act Regulation (EU) 2026/1744 (Digital Omnibus) — adopted 8 July 2026, published in the OJ on 24 July 2026, in force from 27 July 2026 — Chapter III Sections 1–3 now apply to high-risk AI on these dates:

Category Applies from
Annex III high-risk AI (Art.6(2)) 2 December 2027
Annex I high-risk AI (Art.6(1), embedded in products) 2 August 2028

Art.22 (authorised representatives), Art.25 (value-chain responsibilities), Art.26 (deployer obligations) and Art.27 (fundamental rights impact assessment) switch on with the same schedule. The transitional rule for systems already placed on the market (Art.111(2)) is no longer tied to a fixed date either: it now bites only where significant changes in their designs are made on or after the Chapter III application date.

A second marker falls on 2 December 2026. New prohibited practices begin — Art.5(1)(ba) (non-consensual sexual deepfakes), Art.5(1)(bb) (generation of child sexual abuse material), plus Art.5(1a) and (1b). The same date is the deadline under the new Art.111(4) for providers of synthetic-content-generating AI placed on the market before 2 August 2026 to comply with Art.50(2). The transparency obligations themselves (Art.50(1)–(6)) still apply from 2 August 2026; Regulation 2026/1744 amended only Art.50(7) on codes of practice.

That is a third axis, distinct from TRAIGA's intent and RAISE's scale: the EU bundles model capability and use-case risk on separate clocks. For Japanese firms it means tracking the EU schedule at article level alongside state-by-state reading. Japan's personal information protection law reform also matters for 72-hour reporting and data-transfer design.

Summary

If I had to pick one Monday-morning action for a Japanese product team with US users: inventory Texas exposure first. TRAIGA is live, one resident is enough, and the 60-day cure only helps if intake already exists.

  • TRAIGA punishes intent, outcome-focused, in force January 2026
  • RAISE limits to frontier models, capability-based supervision, January 2027, USD 500M × 10²⁶ FLOPs thresholds
  • Penalty correction: RAISE amended max USD 3M (first USD 1M); USD 30M is outdated
  • Japanese impact fully asymmetric: TRAIGA many; RAISE effectively none
  • 72-hour reporting triggers on reasonable belief. Watch it as a future global standard

Red states and blue states face AI with different logic. Bundle them as one "US AI regulation" and compliance design drifts. Reading philosophy state by state is the skill Japanese AI counsel need most.

Further reading: California's three AI statutes, Colorado CAIA repeal and ADMT replacement, US federal AI policy 2026.

References

Footnotes

  1. New York Amends the RAISE Act to Align More Closely with SB 53 - Morrison Foerster

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles