TwinEthosRequest access

Control

Autonomous system without designed, testable transparency for affected stakeholders

An autonomous/AI system should have transparency deliberately designed in and specified at a testable level for each affected stakeholder group (users, bystanders/public, safety certifiers, incident investigators, legal).

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: Developers do not give deployers, users, or the public the documentation they need · control id cond.autonomous-system-no-stakeholder-transparency

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Specify a testable transparency target for each stakeholder group and build in an action log that lets investigators reconstruct what the system did.

A transparency specification kept with the system (for example docs/transparency-spec.yaml) that names each affected stakeholder group (users, bystanders and the public, safety certifiers, incident investigators, lawyers and expert witnesses), states what each group can learn about the system and through which channel, and sets a target the team can test. Transparency is built into the runtime rather than assumed: the agent or decision loop writes an append-only record of each observation, model version, output, and action with its rationale, so an incident can be reconstructed after the fact, and user-facing explanations are produced from that same record. Tests in CI assert that every action path writes the record and that each stakeholder's explanation can be generated.

Where it goes: 12 repository artifacts, 10 logs and telemetry, 9 AI output handling, 13 tests and evals.

What reviewers look for: a stakeholder transparency specification in the repository listing each group with a testable target; an append-only action or decision log (the 'black box') written on every path where the system acts, carrying inputs, model version, output, and action; explanations wired to users; and tests that fail if an action path skips the log.

Example (Python agent loop), before:

def act(step):
    return TOOLS[step.name](**step.args)

After:

def act(step, run_id):
    result = TOOLS[step.name](**step.args)
    flight_recorder.append({          # append-only, kept for incident investigation
        'run_id': run_id, 'ts': time.time(), 'model': MODEL_VERSION,
        'observation': step.observation, 'tool': step.name, 'args': step.args,
        'rationale': step.rationale, 'result': summarize(result)})
    return result

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)