Recommended guardrail
Tell people when they are interacting with AI — everywhere, not only where required
Disclose clearly and at the start of an interaction that the user is dealing with an AI system, repeat the disclosure in long sessions, never let the system claim to be human when asked, and label AI agents that act or communicate on a user's behalf toward third parties. Apply this regardless of jurisdiction. Detect conversational or agent interfaces with no disclosure or that can claim to be human.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Law in force in 6 jurisdictions, coming in 4 more
Law in force in 6 jurisdictions · law coming in 4 more · 4 standards and frameworks · 1 graded incident.
TwinEthos recommendation, not law. Where binding law applies, the law governs. Binding law on this control, or in provisions cited as convergence, is in force in 6 jurisdictions (EU, KR, US-CA, US-NY, US-TX, US-UT). Such law is enacted but not yet applicable, or stayed, in 4 more (US-CT, US-NE, US-OR, US-WA). 4 standards and frameworks recommend it (CoE AI Framework Convention (CETS 225), EU ALTAI, Japan AI Guidelines for Business, OECD AI Principles). 1 graded incident cited.
Law in force on this control or cited as convergence
- Companion chatbots must disclose they are not human (California (US-CA); Cal. Bus. & Prof. Code 22602(a); same control)
- AI chat systems must disclose they are AI at first interaction (European Union (EU); Article 50(1); same control)
- High-impact and generative AI must give advance AI-use notice and label generative outputs (South Korea) (South Korea (KR); 인공지능기본법 제31조 (Art. 31); same control)
- AI companions must tell users they are not talking to a human, at the start and every three hours (New York) (New York (US-NY); N.Y. Gen. Bus. Law 1702; same control)
- Government AI systems must disclose AI interaction to consumers (Texas (US-TX); Tex. Bus. & Com. Code 552.051(b); same control)
- GenAI in a consumer transaction must disclose on a consumer's clear request (Utah (US-UT); Utah Code 13-77-103(1); same control)
- Mental health chatbots must disclose they are AI, not human, before access, after 7 days away, and when asked (Utah HB 452) (Utah (US-UT); Utah Code 13-72a-203(1)-(2); same control)
Law enacted, not yet applying
- AI companions must disclose they are not human (Connecticut) (Connecticut (US-CT); Conn. PA 26-15 Sec. 5(b); applies from 2027-01-01; same control)
- AI companions must disclose non-human interaction (Oregon) (Oregon (US-OR); Oregon SB 1546 (2026), Section 1(2); applies from 2027-01-01; same control)
- AI companion chatbots must disclose they are not human (Washington) (Washington (US-WA); Washington HB 2225 (2026), Section 3; applies from 2027-01-01; same control)
- Conversational AI must disclose it is not human when a user could be misled (Nebraska) (Nebraska (US-NE); Nebraska LB 525, Sec. 15 (Conversational AI Safety Act); applies from 2027-07-01; same control)
Standards and frameworks
- Persons should be notified they are interacting with an AI system (CoE Framework Convention) (CoE AI Framework Convention (CETS 225); CoE Framework Convention on AI (CETS 225), Article 15(2); same control)
- AI should be transparent, traceable, and disclose AI interaction to users (EU ALTAI) (European Union (EU); ALTAI / EU Ethics Guidelines — Requirement 4 (Transparency); same control)
- AI operators should provide verifiable transparency information and maintain accountability (Japan) (Japan (JP); Japan AI Guidelines for Business Ver1.1 (MIC/METI) — Common Guiding Principles 6) Transparency and 7) Accountability; same control)
- People should be made aware they are interacting with AI (OECD AI Principles; OECD/LEGAL/0449 — Principle 1.3; same control)
Family “People are not told they are interacting with, or being processed by, an AI system”: binding law on related controls is in force in European Union (EU), South Korea (KR), California (US-CA), Illinois (US-IL), New York (US-NY), Texas (US-TX), Utah (US-UT); enacted, not yet applying in Connecticut (US-CT), Nebraska (US-NE), Oregon (US-OR), Washington (US-WA). Context only: it does not change this guardrail's grade.
Graded incidents
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)) U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });After:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant messageControl: AI chat interaction without disclosure. Engineering guidance, not legal advice.
Why
Telling people they are dealing with an AI is the most widely converged AI control in the corpus and is recommended by every major framework. A builder should not have to track which of their users' locations require it.
Class: law derived · set: universal baseline · maturity: reviewed · confidence: high · id guardrail.baseline-ai-interaction-disclosure