Market
AI law in European Union
22 binding provisions TwinEthos encodes that reach European Union (EU): 14 in force, 8 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Get the build plan for European Union
The guards that cover the most here
58 guards address 79 items across 1 jurisdiction with binding law: 14 binding law in force, 8 enacted but not yet applying, 33 standards and frameworks, 24 TwinEthos recommended guardrails.
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 5 items: 1 binding law in force · 3 standards · 1 recommended guardrail
Law in force in European Union (EU).
Synthetic content not machine-readable-marked
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
Addresses 2 items: 1 binding law in force · 1 standard
Law in force in European Union (EU).
AI inputs and outputs retained or exposed by default
Turn off prompt and completion content capture in GenAI tracing, send store=False to the provider, and set a retention limit on stored conversations by default.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
AI-generated public-interest text published without disclosure
Label AI-generated public-interest text as artificially generated where it is published, or hold it as a draft until a named editor reviews it and takes responsibility.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
AI providers not named as recipients when personal data is collected
Show a notice at each AI input (chat box, upload, voice capture) that names the AI providers receiving the data and any transfer abroad, linked to the full privacy notice.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
Biometric categorisation of sensitive traits
Remove any model, prompt, or label set that infers race, political opinion, union membership, religion or beliefs, sex life, or sexual orientation from biometric data.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
Face or voice biometric template computed without prior notice and consent
Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
Deepfake content not disclosed
Attach a visible 'AI-generated or manipulated' disclosure to face-swapped, voice-cloned, or likeness-generated media on every path that publishes or returns it.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
Emotion-recognition/biometric-categorisation system without notice to exposed persons
Show people a notice that emotion recognition or biometric categorisation is running before the analysis touches their face, voice, or video, and gate the analysis on it.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
Emotion recognition in workplace or education
Remove emotion inference from workplace and education features, or confine it to a documented medical or safety purpose behind an explicit, default-off gate.
Addresses 1 item: 1 binding law in force
Law in force in European Union (EU).
The top 10 of 58; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in European Union:
- Chat or assistant
- Answers from your documents (RAG)
- Agents that use tools or take actions
- Decisions about people (hiring, credit, insurance, health)
- Generated text, images, audio or video
- Classification, scoring or biometrics
- Embeddings and vector search
Laws
- EU AI Act European Union (EU)
- EU GDPR (articles applied to AI data flows) European Union (EU)
- EU GDPR Art. 22 (ADM) European Union (EU)
Coming into force
- : AI generating non-consensual intimate imagery or CSAM is prohibited (EU AI Act Art. 5(1)(ba),(bb)) (European Union (EU))
- : Synthetic AI output must be machine-readably marked as artificial (European Union (EU))
- : High-risk AI training data must be governed and examined for bias (EU AI Act Art. 10) (European Union (EU))
- : High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12) (European Union (EU))
- : High-risk AI systems must be designed for effective human oversight with override and stop (EU AI Act Art. 14) (European Union (EU))
- : High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15) (European Union (EU))
- : Deployers must inform people they are subject to a high-risk AI decision (EU AI Act Art. 26(11)) (European Union (EU))
- : Public-sector and essential-service deployers must run a fundamental rights impact assessment (EU AI Act Art. 27) (European Union (EU))
- : High-risk AI training data must be governed and examined for bias (EU AI Act Art. 10) (European Union (EU))
- : High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12) (European Union (EU))
- : High-risk AI systems must be designed for effective human oversight with override and stop (EU AI Act Art. 14) (European Union (EU))
- : High-risk AI systems must be accurate, robust, and secure against AI-specific attacks (EU AI Act Art. 15) (European Union (EU))
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.