TwinEthosRequest access

Control

General-purpose model without downstream documentation

Providers of general-purpose AI models should maintain model documentation for downstream integrators.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: Developers do not give deployers, users, or the public the documentation they need · control id cond.gpai-no-model-documentation

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Maintain versioned model documentation for each general-purpose model covering intended uses, training, and limitations, and publish it where downstream providers get the model.

Model documentation for each general-purpose model version (a model card or documentation page, such as model_card.md or the Hugging Face model card README) written for downstream integrators: intended and out-of-scope uses, architecture and technical specifications, how and on what data the model was trained, evaluation results, and known limitations. The provider's documentation owner revises it with each released version and keeps earlier versions retrievable. The repository holds its source, and the release pipeline publishes it alongside the weights or API so integrators receive it at the point of integration.

Where it goes: 12 repository artifacts, 14 user-facing text, 11 CI/CD pipeline.

What reviewers look for: a model card or documentation page per released model version with sections on intended uses, technical specifications, training data, and limitations, published where integrators obtain the model (model hub, API docs, download page), and a release step that ships it with the version rather than documentation that trails the release.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Hugging Face Hub release script), before:

from huggingface_hub import HfApi
HfApi().upload_folder(folder_path='out/', repo_id='org/base-7b')

After:

from huggingface_hub import HfApi, ModelCard
card = ModelCard.load('out/README.md')
required = ['## Uses', '## Training Details', '## Bias, Risks, and Limitations', '## Technical Specifications']
missing = [s for s in required if s not in card.text]
if missing:
    raise SystemExit(f'model card incomplete: {missing}')
HfApi().upload_folder(folder_path='out/', repo_id='org/base-7b')

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)