Recommended guardrail
Add disclosures in code after any output limit, so truncation never removes them
When an AI output is meant to carry a disclosure (an AI-interaction notice, a 'not medical advice' disclaimer, an AI-generated label), add it in code after truncating the model's text, with room reserved for it, instead of truncating text that already contains it or asking the model to write it at the end of a capped reply. Detect slicing or shortening applied to a string that holds the disclosure, and prompts that leave the closing disclosure to the model.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Trust and provenance
- Lane
- TwinEthos recommendation (not law) TwinEthos recommendation, not law
- Official source
- TwinEthos's own derivation record (from the corpus gap analysis and the incident registry), not an official source. The law, standards and incidents it cites are listed on this page with their own links.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
- Legal review
- Not reviewed by a lawyer. Written by TwinEthos as its own recommendation: opinion, never law. No TwinEthos rule has been legally reviewed yet.
- Audit standard
- Audit-grade: meets all 11 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Disclosures held in variables whose names do not mark them as a disclaimer, notice or label; truncation in a downstream SMS or push library.
- A truncation limit that already reserves room for the disclosure (the slice is longer than the text can be) is compliant; check how the limit is computed.
- The code may also add the disclosure itself; then the prompt sentence is redundant, not harmful.
Evidence grade
Related law in force in 3 jurisdictions · 0 graded incidents.
TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law on this control itself is in force in the corpus; binding law in provisions cited as convergence, which cover part of the control or a related one, is in force in 3 jurisdictions (CN, EU, US-CA). 0 graded incidents cited.
Related law in force (cited as convergence; not on this control itself)
- GenAI patient communications require an AI disclaimer (California (US-CA); Cal. Health & Safety Code 1339.75(a); cited)
- AI chat systems must disclose they are AI at first interaction (European Union (EU); Article 50(1); cited)
- Companion chatbots must disclose they are not human (California (US-CA); Cal. Bus. & Prof. Code 22602(a); cited)
- AI-generated content must carry both explicit and implicit labels (China) (China (CN); 人工智能生成合成内容标识办法 第四条 (Art. 4); cited)
Family “AI controls are not preserved under cost, latency, or model-change pressure”: binding law on related controls is in force in Illinois (US-IL). Context only: it does not change this guardrail's grade.
The guard to add
Add required disclosures in code after any truncation, and reserve room for them in the length limit.
Where an output is cut to a limit (an SMS segment, a push notification, a UI preview, a max_tokens budget), truncate the model's text first to the limit minus the disclosure's length and then add the disclosure in code, at the position the disclosure is meant to have (the beginning, for disclaimers that must come first). Do not ask the model to append the disclosure itself when its output is token-limited or truncated; the code that sends the message owns the disclosure.
Example (Python SMS reply), before:
message = f"{answer}\n\n{AI_DISCLAIMER}"
sms.send(to=phone, body=message[:MAX_SMS_CHARS])After:
room = MAX_SMS_CHARS - len(AI_DISCLAIMER) - 2
message = f"{answer[:room]}\n\n{AI_DISCLAIMER}" # the disclaimer always survives
sms.send(to=phone, body=message)Control: Output limits or truncation cut off a disclosure the output is meant to carry. Engineering guidance, not legal advice.
Why
Disclosure laws in the corpus put notices and disclaimers into the conversation or the generated content itself, and the cheapest way to lose one is length: a reply cut to an SMS limit, a preview cut to a line, or a model told to sign off with a disclaimer that runs out of tokens first. The control is to make the code that sends the output own the disclosure and add it after truncation. No published standard in the corpus addresses it; the binding disclosure rules cited as convergence are why it matters.
Class: operational integrity · set: operational integrity · maturity: reviewed · confidence: medium · id guardrail.opint-disclosures-survive-output-limits
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.