TwinEthosRequest access

Control

High-impact AI deployed without an ethical/impact assessment

AI systems that may significantly affect people should undergo an ethical impact assessment identifying benefits, risks, and mitigation, with oversight (auditability, traceability, explainability) and external review.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.high-impact-ai-no-impact-assessment

Reach

2items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
1standards and frameworks on the same control

enacted, not yet applying in European Union (EU); next date 2027-12-02.

The guard to add

Complete an impact assessment of a high-impact AI deployment's benefits, risks to affected people, mitigations, and oversight before first use, and keep it current.

A deployment-level assessment owned by the deploying business owner with legal and ethics input: how and where the system is used, who is affected and which groups are most exposed, benefits and specific risks of harm, mitigations and what happens if a risk materialises, and oversight provisions (decision logs for traceability, explanations, human oversight, complaint handling, external review). It is completed before first use, updated when any of those elements change, and published or shared with reviewers where appropriate. The deploy pipeline can check that a current, signed assessment exists for each high-impact deployment.

Where it goes: 12 repository artifacts, 15 agent action surface.

What reviewers look for: a dated assessment per high-impact deployment covering affected persons and groups, specific harms, mitigations, and oversight mechanisms (auditability, traceability, explainability, external review), signed off before go-live and updated after material changes; a link from the deployment config or release record.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Deployment impact assessment (docs/impact/)), before:

# Benefits eligibility assistant
DPIA done in 2024.

After:

# Impact assessment: benefits eligibility assistant (2026-07-15)
- Use: caseworkers see an AI eligibility recommendation; weekly batch + on demand
- Affected: applicants; most exposed: non-native speakers, people with irregular income
- Risks: wrongful denial, delayed payment, opaque reasons
- Oversight: caseworker decides; every recommendation logged with model version and reasons
- If harm occurs: pause switch, re-review affected cases, complaint route via /appeals
- External review: annual review by independent auditor; DPIA cross-referenced
- Sign-off: service owner, DPO (2026-07-20)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)

Standard / soft law (1)