Market
AI law in FR
1 binding provision TwinEthos encodes that reach FR: 1 in force, 0 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
The guards that cover the most here
50 guards address 105 items across 1 jurisdiction with binding law: 1 binding law in force, 0 enacted but not yet applying, 67 standards and frameworks, 37 TwinEthos recommended guardrails.
Commercial-influence content showing an AI-produced face or silhouette is published without a virtual-image mention
Mark every AI-produced face or silhouette in influencer content and publish it with a legible 'Images virtuelles' (or equivalent) mention.
Addresses 1 item: 1 binding law in force
Law in force in FR.
Model output reaches a code, query, shell, markup, or file-path interpreter without validation or encoding
Treat model output as untrusted input: validate it against a schema, encode or parameterize it for its sink, and run generated code only in a sandbox.
Addresses 6 items: 5 standards · 1 recommended guardrail
Agent high-impact action without human approval
Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.
Addresses 5 items: 4 standards · 1 recommended guardrail
AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry
Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.
Addresses 5 items: 4 standards · 1 recommended guardrail
AI usage, agent steps, and spend not bounded
Cap agent steps and output tokens on every model call, set per-key and per-project budgets with usage alerts, and issue scoped, expiring model keys.
Addresses 5 items: 4 standards · 1 recommended guardrail
Untrusted content influences instructions or tools
Pass untrusted content as data outside the system channel with an unclosable boundary, and while it is in context, hold only low-impact tools or require approval for the rest.
Addresses 5 items: 4 standards · 1 recommended guardrail
Agent tools and credentials not scoped to least privilege
Declare each agent's allowed tools and credentials explicitly, grant only what its task needs, and keep destructive operations off unless a grant names them.
Addresses 4 items: 3 standards · 1 recommended guardrail
GenAI with untracked third-party components (value chain)
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
Addresses 4 items: 3 standards · 1 recommended guardrail
Model, version, or serving change reaches users without re-running behavior and safety evaluations
Pin dated model versions and run a blocking behavior and safety eval in CI whenever model ids, prompts, or inference settings change, then keep monitoring quality in production.
Addresses 4 items: 3 standards · 1 recommended guardrail
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 3 items: 2 standards · 1 recommended guardrail
The top 10 of 50; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in FR:
Laws
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.