AI law changes monthly. Your coding agent was trained last year.
TwinEthos gives your agent the current, citable map of what AI law and responsible practice require of your code — so every finding names the exact provision and nothing newer than the model slips through.
Informational data, not legal advice. Rules have not yet been reviewed by a lawyer.
How TwinEthos works
- TwinEthos
Official law, captured
Laws, regulations and standards from 30+ jurisdictions, quoted from the official text and re-checked every week.
- TwinEthos
Turned into checks for code
Each rule says who it applies to, what to look for in code, and the exact provision to cite. Recommended guardrails sit alongside, labeled as opinion.
- Your coding agent
Asks what applies
Claude Code, GitHub Copilot or Cursor calls TwinEthos over MCP with your repository's AI patterns and markets.
- Your machine
Pinpoints the code
Local triage runs the detectors on your repository and points at the files and lines to check. Your code never leaves your machine.
- Your pull request
Findings you can act on
Each finding names the file and line, the exact provision, and its lane: law in force, law coming, standard, or recommended guardrail.
Blind, paired tests on 17 synthetic apps, one run per configuration; method and limits. Informational data, not legal advice.
The problem
Ask a model which law your chatbot breaks and it will usually name the right topic, guess the section number, and miss anything passed after its training. That is not evidence you can put in front of an auditor, a customer's security review, or a regulator.
- Plausible citations aren't exact ones. Alone, reviewers cited the exact provision on 0–57% of the legal issues they found.
- Models can't know recent law. On law newer than the model's training, reviewers alone cited none of it exactly.
What TwinEthos does
Maps obligations to code.
Each rule names the files, SDK calls, data flows, and missing artifacts that trigger it — detectors a coding agent can act on, not paragraphs of legal prose.
Keeps every rule tied to official text.
Every legal rule quotes the official source, checked by hash, and a weekly watcher re-verifies it against the live document.
Knows when a law doesn't apply.
Who is covered, which uses are excluded, which kinds of systems are in scope — so a companion-chatbot law isn't applied to your support bot.
Separates law from advice.
Findings arrive in four lanes: law in force, law enacted but not yet in force (with its date), standards and frameworks, and TwinEthos recommended guardrails — clearly labeled as our opinion.
The evidence
Blind, paired tests: the same reviewer model with and without TwinEthos, scored by a separate judge that doesn't know which report is which.
| Measure | Alone | With TwinEthos |
|---|---|---|
| Exact provision cited | 0–57% | 83–100% |
| Law newer than the model: exact citation | 0% | 100% |
| Seeded issues found (Claude Haiku) | 65% | 87% |
| Seeded issues found (Claude Sonnet) | 92% | 97% |
Works with reviewers from different model families — and with small, cheap ones: a full 17-app review cost about $2 of model usage.
Small synthetic test apps written by the TwinEthos team; one run per configuration. Full results and method: the evidence page.
Beyond the law
Law sets a floor. TwinEthos recommended guardrails cover what a responsible AI integration does anyway, each backed by graded real incidents:
- Agent security — permission-aware retrieval, tool-server authentication, memory-write controls, AI-generated code provenance.
- Operational integrity — the controls that quietly disappear under cost pressure: scoped caches, guards that fail closed, re-evaluation on every model change.
- Ethical use (opt-in) — engagement design, sycophancy, substantiated capability claims, training consent, age signals.
Recommended guardrails are TwinEthos's opinion of good practice. Where binding law applies, the law governs. Browse the recommended guardrails.
Where it runs
In your coding agent's review, through MCP — Claude Code, GitHub Copilot, Cursor. Versioned data releases and a change feed tell you when a rule touching your controls changes.
Who it's for
- Agent and developer-tool builders adding a review step on every pull request.
- AI product teams in regulated sectors — HR tech, insurance, health, fintech, companion apps — preparing for audits, customer security reviews, and launches in new states.
- Compliance teams supporting engineering who need findings they can verify in minutes.
Become a design partner.
We run an assisted review of one of your repositories and walk your team through the findings.
TwinEthos is published by FloatingKey LLC. Informational data, not legal advice.