TwinEthosRequest access

Recommended guardrail

Keep AI analysis of people's stored photos, files, and messages off until they opt in

Advisory. Background AI features that run over content people have stored with a service (face grouping or recognition in a photo library, tagging, summarising or indexing documents, email, messages, or recordings for an assistant, extracting interests) start off, are explained when the user turns them on, and stop and delete what they derived when turned off. A request the user makes about one item at that moment, and malware, spam, or abuse screening, are not covered. Detect background, on-upload, or batch AI jobs over stored content with no per-user opt-in check, and settings that default such features to on. Where biometric-consent law applies, face and voice templates are reported under that law in its own lane.

TwinEthos recommendation — not law · advisory, opt-in

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs. Ethical-use guardrails are optional practices, never reported as violations.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Evidence grade

Related law in force in 4 jurisdictions

Related law in force in 4 jurisdictions · 4 graded incidents.

Advisory ethical-use recommendation, not law: an optional practice, never reported as a violation. Where binding law applies, the law governs. No binding law on this control itself is in force in the corpus; binding law in provisions cited as convergence, which cover part of the control or a related one, is in force in 4 jurisdictions (EU, US-IL, US-TX, US-WA). 4 graded incidents cited.

Related law in force (cited as convergence; not on this control itself)

Family “Biometric data from AI features is collected, kept, or disclosed without consent or limits”: binding law on related controls is in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA). Context only: it does not change this guardrail's grade.

Graded incidents

The guard to add

Default each AI feature over stored content to off, check the user's opt-in inside every job that runs it, and delete derived data when it is turned off.

Consider giving each AI feature that runs over stored content (face grouping, auto-tagging, inbox or document summaries, an assistant's index of the user's files) its own per-user setting that defaults to false in the settings model and migration, set to true only from an opt-in screen that says what is analysed and why. Check that setting inside every background, on-upload, and batch job (Celery or queue tasks, storage-event handlers, cron indexers) before calling a vision, face, embedding, or language model, and filter batch jobs to opted-in users in the query itself. When the user turns the feature off, stop the job and delete what it produced (face collection entries, embeddings in the vector store, tags, summaries). A request the user makes on one item at that moment ('summarise this file') needs no separate opt-in.

Example (Django + Celery + Amazon Rekognition), before:

class UserSettings(models.Model):
    user = models.OneToOneField(User, on_delete=models.CASCADE)
    face_grouping = models.BooleanField(default=True)

@shared_task
def index_new_photo(photo_id):
    photo = Photo.objects.get(id=photo_id)
    rekognition.index_faces(CollectionId=f'user-{photo.owner_id}',
                            Image={'S3Object': {'Bucket': BUCKET, 'Name': photo.key}})

After:

class UserSettings(models.Model):
    user = models.OneToOneField(User, on_delete=models.CASCADE)
    face_grouping = models.BooleanField(default=False)   # set only from the opt-in screen

@shared_task
def index_new_photo(photo_id):
    photo = Photo.objects.select_related('owner__settings').get(id=photo_id)
    if not photo.owner.settings.face_grouping:
        return
    rekognition.index_faces(CollectionId=f'user-{photo.owner_id}',
                            Image={'S3Object': {'Bucket': BUCKET, 'Name': photo.key}})

def disable_face_grouping(user):
    user.settings.face_grouping = False
    user.settings.save()
    rekognition.delete_collection(CollectionId=f'user-{user.id}')

Control: AI analysis of users' stored photos, files, or messages runs without their opt-in. Engineering guidance, not legal advice.

Why

People store photos, documents, and messages with a service to keep them, not to have them mined. Switching AI analysis on for everyone by default creates face templates, profiles, and other derived data most people never knew were made, and turning it off later does not undo what was derived. Asking first, explaining what is analysed, and deleting derived data when people say no is what a responsible integration does even where no law requires it. The FTC alleged that a photo app enabled face recognition by default for most users and, in a separate complaint, that Facebook's face recognition stayed on by default for tens of millions of users while its data policy suggested they had to opt in; both companies settled without the allegations being adjudicated. A putative class action alleges that Google switched on Gemini analysis of Gmail, Chat, and Meet content by default under a setting worded as an opt-in; the court dismissed the first amended complaint with leave to amend without reaching the merits, the plaintiffs filed a second amended complaint in August 2026, and Google moved to dismiss it in September 2026. Before releasing Recall, which analyzes screen snapshots with on-device AI, Microsoft made it off unless the user turns it on.

Class: ethical use · set: ethical use · maturity: reviewed · confidence: high · id guardrail.ethics-stored-content-analysis-opt-in