TwinEthos homeRequest access

Control

AI product released without a recorded review of whether it is high-impact AI

Before an AI product or service is provided, the provider reviews and records whether it falls in a high-impact category the law defines (the sectors and decisions listed), with the reasons, and, where the answer is unclear, asks the regulator for a determination and keeps the reply; the review is repeated when the system's purpose or use changes.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Control id cond.ai-system-high-impact-status-not-reviewed

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in South Korea (KR).

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — in force 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Review and record, before release, whether each AI product or service is high-impact under the law; ask the regulator when unclear; re-review when its purpose or use changes.

A classification record per AI product or service, owned by the product's accountable lead with legal input, completed before release: the use and sector, each statutory high-impact category checked (for Korea: energy supply, drinking water, health care, medical devices, nuclear, biometric analysis for criminal investigation, hiring and loan screening and other decisions with major effects on rights, transport, public-body decisions, student evaluation, and any category the Decree adds), the conclusion with reasons, and, where the answer is unclear, the determination request to the ministry (product overview, training-data overview, material showing how the system is used and its outputs) with the reply and any re-confirmation request. A release checklist links the record, and a material change of purpose or use reopens it. This is an organizational record; a repository can hold its index.

Where it goes: 11 CI/CD pipeline, 12 repository artifacts.

What reviewers look for: for each AI product or service, a classification record dated before its release, with the categories considered and reasons; any determination request and reply; and a re-review after each material change of purpose or use.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Classification record (repo index)), before:

# governance/ai-inventory.yaml
loan-assistant: {owner: credit-team}

After:

# governance/ai-inventory.yaml
loan-assistant:
  owner: credit-team
  high_impact_review:
    date: 2026-02-10            # before release
    categories_checked: [art2_4_sa_hiring_and_loan_screening, art2_4_da_health_care]
    conclusion: high_impact      # loan screening affects rights and duties
    reasons: drafts the credit decision shown to the underwriter
    ministry_confirmation: not requested (clear)
  rereview_on_change: true

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.