Control
AI service gives users no information for proper use (how it works, limits, prohibited uses, data policy, reliability) and no sources for its answers
Users of an AI service can find, where they use it, what they need to use it properly: how it works and its limits, what uses are prohibited, the policy for the data it collects and learns from, and a caution on how far its output can be relied on; and generated answers show the sources (for example web pages or retrieved documents) they relied on.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- Standard / soft law 1
- Verification
- Sources last verified 3 Oct 2026; each provision states how.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Link a use-information notice from the AI feature and return the sources each generated answer relied on to the user.
Two pieces. In the AI feature's interface, a short notice or link (an 'About this AI' panel, help page or terms section) that states how the service works and its limits, the uses it must not be put to, the policy for the data it collects and trains or learns on, a caution that output can be wrong and how far to rely on it, and where to send questions. In the answer path, when the reply is built from retrieved documents or web search, return the source list with the answer (citations, URLs or document ids from the retriever or the model's annotations) and render it next to the reply instead of discarding it.
Where it goes: 9 AI output handling, 14 user-facing text.
What reviewers look for: the AI feature's UI links or renders the use-information notice with all four elements; the response schema of a retrieval or web-search answer carries sources and the UI renders them.
Example (FastAPI + OpenAI Responses (web search)), before:
@app.post('/ask')
def ask(body: AskIn):
r = client.responses.create(model=M, tools=[{'type': 'web_search'}], input=body.question)
return {'answer': r.output_text}After:
@app.post('/ask')
def ask(body: AskIn):
r = client.responses.create(model=M, tools=[{'type': 'web_search'}], input=body.question)
sources = [a.url for item in r.output if item.type == 'message'
for c in item.content for a in (c.annotations or []) if a.type == 'url_citation']
return {'answer': r.output_text, 'sources': sources, 'about_ai': '/help/about-this-ai'}Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Standard / soft law (1)
- Japan (JP)
- Businesses providing AI should tell users its limits, prohibited uses, data policy and reliability, and show the sources of answers (Japan, soft law) 人工知能関連技術の研究開発及び活用の適正性確保に関する指針 2(2) ステークホルダーとの信頼関係の構築に向けた透明性の確保 (transparency to stakeholders), to the page break
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.