TwinEthosRequest access

Control

Feature that can generate sexually explicit content opens without age assurance, or age-assurance data is kept or reused

Before a user can reach a feature or mode that may generate sexually explicit content, the product applies an age-assurance check proportionate to the risk, and the data collected for it is minimized, used only for age assurance, never sold, and deleted promptly.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI design that manipulates, misleads, or neglects the people who use it · control id cond.sexual-content-feature-without-age-assurance

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in Georgia (US-GA); next date 2027-07-01.

The guard to add

Gate every explicit or adult generation mode behind an age-assurance result, keep only the result, and delete the documents or images used for the check.

Where a setting or request turns on an explicit, adult, or unfiltered mode (enable_safety_checker off, nsfw or spicy mode, adult role-play), the server checks a stored age-assurance result first and refuses the change or request without one; a client flag alone never unlocks it. The age-assurance step (age estimation, account-based assurance, or an identity check where necessary) stores only the outcome and its method and date on the account; uploaded identity documents or face images are deleted as soon as the check completes (a scheduled purge enforces the limit), are never sent to analytics or advertising, and are never sold or used for anything else.

Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 6 API calls and integrations.

What reviewers look for: the explicit-mode setting or request handler reads an age_assurance result server-side before enabling the mode (and minors are refused); the age-assurance flow persists only the result, deletes documents or images after the check with a purge job or TTL, and does not forward them to analytics, marketing or third parties. A client-side checkbox ('I am 18') with no server-side check does not count.

Example (Next.js settings route), before:

if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;

After:

if (body.spicyPhotos === true) {
  const result = await ageAssurance.latest(user.id); // stored outcome only
  if (!result || !result.over18) {
    return Response.json({ error: 'age_assurance_required' }, { status: 403 });
  }
}
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet