TwinEthosRequest access

Control

GenAI with untracked third-party components (value chain)

GAI systems should inventory third-party components (models, datasets, libraries) and review their transparency artifacts (model/system cards).

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: An AI agent's authority, reach, inputs, and components are not bounded and accountable · control id cond.genai-no-third-party-component-provenance

Reach

3items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
2standards and frameworks on the same control

The guard to add

Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.

An AI bill of materials in the repository (aibom.yaml or a third-party AI component registry) lists each component: publisher and source, pinned version or digest, license, a link to the reviewed model or system card or the vendor due-diligence record, the approving owner, and a re-review date. The code matches it: AI SDK and agent-framework dependencies pinned exactly with a committed lockfile, MCP servers launched from pinned versions (pkg@1.2.3, uvx pkg==1.2.3) or vendored, and skills or plugins taken only from vetted sources. A CI step fails when a dependency, model id, or tool server appears that the inventory does not list, and updates trigger re-review.

Where it goes: 12 repository artifacts, 5 dependencies, 11 CI/CD pipeline, 15 agent action surface.

What reviewers look for: a current inventory file covering the models, datasets, packages, and tool servers actually used in code, each with a review record; exact pins and a lockfile for AI dependencies (no >=, ^, ~, or bare names); MCP server commands with an explicit version (no npx -y pkg, pkg@latest, or uvx pkg without ==); a CI check comparing code to the inventory.

Example (requirements.txt), before:

openai>=1.0
anthropic
langchain

After:

openai==1.109.1
anthropic==0.69.0
langchain==0.3.27
# installed in CI with: pip install --require-hashes -r requirements.lock

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (2)

TwinEthos recommendation (not law) (1)

Related incidents