Market
AI law in EC
2 binding provisions TwinEthos encodes that reach EC: 2 in force, 0 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
The guards that cover the most here
40 guards address 55 items across 1 jurisdiction with binding law: 2 binding law in force, 0 enacted but not yet applying, 29 standards and frameworks, 24 TwinEthos recommended guardrails.
AI system deployed without an AI system impact assessment
Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.
Addresses 2 items: 1 binding law in force · 1 standard
Law in force in EC.
People whose data an AI feature processes are not told about that processing in plain language, or not told how to object
Describe the AI processing in the notice at collection in plain language, and wire an objection route that stops it for the person.
Addresses 1 item: 1 binding law in force
Law in force in EC.
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 3 items: 2 standards · 1 recommended guardrail
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 3 items: 2 standards · 1 recommended guardrail
Untrusted content influences instructions or tools
Keep fetched, retrieved, and tool-returned content out of the system prompt, pass it as delimited data, and restrict which tools a turn holding that content can call.
Addresses 3 items: 2 standards · 1 recommended guardrail
Agent actions not traceable to identity and owner
Give each agent its own credential and a registry entry naming an accountable owner, and log every tool action with agent_id, owner, action, target, and timestamp.
Addresses 2 items: 1 standard · 1 recommended guardrail
Agent high-impact action without human approval
Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.
Addresses 2 items: 1 standard · 1 recommended guardrail
AI usage, agent steps, and spend not bounded
Cap agent steps and output tokens on every model call, set per-key and per-project budgets with usage alerts, and issue scoped, expiring model keys.
Addresses 2 items: 1 standard · 1 recommended guardrail
GenAI in consequential decisions without confabulation/output-validation controls
Validate GenAI output against a schema and its cited sources, and send unverifiable claims to review, before it drives a consequential decision or record.
Addresses 2 items: 1 standard · 1 recommended guardrail
GenAI with untracked third-party components (value chain)
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
Addresses 2 items: 1 standard · 1 recommended guardrail
The top 10 of 40; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in EC:
- Chat or assistant
- Answers from your documents (RAG)
- Agents that use tools or take actions
- Decisions about people (hiring, credit, insurance, health)
- Generated text, images, audio or video
- Embeddings and vector search
Laws
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.