TwinEthosRequest access

Control

High-impact AI without risk management, explanations, and human oversight

High-impact AI operators must run a risk-management plan, provide explanations of AI outputs (key criteria + training-data overview), maintain user-protection measures, ensure human management/supervision, and document safety measures.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.high-impact-ai-without-risk-management-and-oversight

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in South Korea (KR).

The guard to add

Put human supervision and a per-decision explanation record between high-impact model output and the action it triggers, backed by a documented risk-management plan.

On the high-impact path (credit, hiring, healthcare, essential services), model output becomes a pending decision rather than an action: a person can approve, override, or stop it (review queue with override, LangGraph interrupt, a kill switch checked before acting). Each decision stores the final result, the main criteria or reason codes, the model version, and the reviewer, and an explanation endpoint returns that record to the affected user. Alongside the code, keep the risk-management plan, user-protection measures, an overview of the training data used for explanations, and documentation of these measures in the repository.

Where it goes: 9 AI output handling, 15 agent action surface, 2 data models, 12 repository artifacts.

What reviewers look for: no direct write from model output to set_status(, applications.save( or a decision letter without a pending_review step or interrupt; decision rows with reason codes and model version; an explanation endpoint for users; risk-management and oversight documents present and referenced from the service.

Example (Python + scikit-learn), before:

score = model.predict_proba([features])[0][1]
status = 'approved' if score > 0.7 else 'denied'
applications.save(app_id, status=status)

After:

if settings.HIGH_IMPACT_AI_PAUSED:            # kill switch
    raise ServiceUnavailable('automated scoring paused')
score = model.predict_proba([features])[0][1]
proposed = 'approved' if score > 0.7 else 'denied'
decisions.insert(app_id=app_id, proposed=proposed, score=score,
                 reason_codes=top_reason_codes(features, k=3), model_version=MODEL_VERSION,
                 status='pending_review')
# applications.save runs from the reviewer's approve/override handler

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)