TwinEthos homeAPI access

Recommended guardrail

Record every AI call and tool call as redacted, retained security telemetry

Emit a security event for every model call and agent tool call on a user-facing path (caller, time, model, tool calls and arguments, guard verdicts, token counts) to a trace or audit pipeline, with prompt and output content redacted or kept out of general logs, bounded retention, restricted access, and tamper-evident storage for security events. Detect raw prompts, messages or completions written to application logs, GenAI message-content capture switched on, and repositories that call models with no AI tracing or audit record.

TwinEthos recommendation — not law

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Trust and provenance

Lane
TwinEthos recommendation (not law) TwinEthos recommendation, not law
Official source
TwinEthos's own derivation record (from the corpus gap analysis and the incident registry), not an official source. The law, standards and incidents it cites are listed on this page with their own links.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
Not reviewed by a lawyer. Written by TwinEthos as its own recommendation: opinion, never law. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 11 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

3 detectors (code pattern, configuration setting, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Log calls that span several lines, and structured loggers that receive the prompt through a variable with another name.
  • A logger that is itself the access-restricted, retention-bounded AI audit sink is acceptable; confirm where the handler writes.
  • Telemetry configured outside the repository (a gateway, a cloud-provider invocation log) is invisible here; ask for it before reporting.

Evidence grade

Related law coming in 1 jurisdiction

Related law coming in 1 jurisdiction · 8 standards and frameworks · 0 graded incidents.

TwinEthos recommendation, not law. Where binding law applies, the law governs. Binding law in provisions cited as convergence is enacted but not yet applicable, or stayed, in 1 jurisdiction (EU). 8 standards and frameworks recommend it (MITRE ATLAS, NIST AI 100-2, NIST AI 600-1, NIST AI RMF, NIST SP 800-218A, OWASP ACS, OWASP ASI 2026, OWASP LLM 2026). 0 graded incidents cited. Context: binding law on related controls in the family “AI decisions cannot be reconstructed after the fact” is in force in 3 jurisdictions (KG, US-MD, VN).

Law enacted, not yet applying

Standards and frameworks

Published AI security standards mapping to this control

  • OWASP LLM 2026 LLM02: Sensitive Information Disclosure · crosswalk status: covered
  • OWASP ASI 2026 ASI09: Human-Agent Trust Exploitation · crosswalk status: covered
  • OWASP ASI 2026 ASI10: Rogue Agents · crosswalk status: covered
  • OWASP ACS ACS-Core session context: Append-only context chain with a rolling hash, replay protection, and a signed envelope · crosswalk status: covered
  • OWASP ACS ACS-Trace: OpenTelemetry and OCSF events for every step, decisions recorded as span events · crosswalk status: covered
  • MITRE ATLAS AML.M0024: AI Telemetry Logging · crosswalk status: covered
  • NIST AI 600-1 MS-2.6-005: Verify the system architecture can monitor outputs and performance and handle detected security anomalies · crosswalk status: covered
  • NIST AI 100-2 3.3.3 monitoring: Monitor and log user activity to detect and respond to prompt injection · crosswalk status: covered
  • NIST SP 800-218A RV.1.1: Log, monitor, and analyze all AI inputs and outputs · crosswalk status: covered
  • NIST AI RMF MEASURE 2.4: Functionality and behavior monitored in production · crosswalk status: covered

Item ids and titles from the published standards; the mapping is TwinEthos's (standards crosswalk, docs/COVERAGE.md Part 4). Cited by id, never quoted.

Family “AI decisions cannot be reconstructed after the fact”: binding law on related controls is in force in KG, Maryland (US-MD), VN; enacted, not yet applying in European Union (EU). Context only: it does not change this guardrail's grade.

The guard to add

Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.

Instrument the model client and the agent's tool executor once, where every call passes: OpenTelemetry GenAI instrumentation (opentelemetry-instrumentation-openai-v2, OpenLLMetry Traceloop.init(), OpenInference), Langfuse (@observe or langfuse.openai) or LangSmith tracing, or an audit-log call in the tool dispatcher. Record the caller (user or agent identity), time, model, tool names and arguments, guard verdicts and token counts. Turn message content capture off or pass it through a redaction step (OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false, Langfuse mask=, LangSmith hide_inputs), never write raw prompts, messages or completions to application loggers or print statements, set a retention period on the telemetry store, restrict who can read it, and write security events to append-only or signed storage so an attacker who gains access cannot erase their trail.

Example (Python + OpenAI + OpenTelemetry), before:

logger.info(f"prompt={messages} reply={completion.choices[0].message.content}")

After:

# once at startup
from opentelemetry.instrumentation.openai_v2 import OpenAIInstrumentor
OpenAIInstrumentor().instrument()   # gen_ai.* spans for every call
# environment: OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false

logger.info('chat call', extra={'user': user_id, 'model': MODEL,
            'tokens': completion.usage.total_tokens})

Control: AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry. Engineering guidance, not legal advice.

Why

Security telemetry is how an operator sees prompt injection, credential abuse, data exfiltration through tools and runaway agents at all, and it is the record an investigation starts from. The same telemetry is a leak when raw prompts and outputs, which carry personal data and sometimes secrets, land in ordinary logs and third-party dashboards. The control is both halves: trace every AI call and tool call, and minimise what the trace keeps. Published AI security standards from NIST, OWASP and MITRE converge on it.

Class: agent security · set: ai security · maturity: reviewed · confidence: high · id guardrail.sec-ai-security-telemetry

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.