TwinEthos homeAPI access

Market

AI law in SA

3 binding provisions TwinEthos encodes that reach SA: 3 in force, 0 enacted but not yet applying. Start from the guards to add.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Get the build plan for SA

The guards that cover the most here

51 guards address 103 items across 1 jurisdiction with binding law: 3 binding law in force, 0 enacted but not yet applying, 67 standards and frameworks, 33 TwinEthos recommended guardrails.

  1. AI system deployed without an AI system impact assessment

    Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.

    Addresses 2 items: 1 binding law in force · 1 standard

    Law in force in SA.

  2. The privacy policy does not describe the decisions computer programs make or help make with personal information

    Keep an automated-decisions section in the privacy policy, generated or checked against the decision paths in code.

    Addresses 1 item: 1 binding law in force

    Law in force in SA.

  3. Solely-automated significant decision without human-intervention safeguards

    Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

    Addresses 1 item: 1 binding law in force

    Law in force in SA.

  4. Agent high-impact action without human approval

    Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.

    Addresses 5 items: 4 standards · 1 recommended guardrail

  5. AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry

    Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.

    Addresses 5 items: 4 standards · 1 recommended guardrail

  6. AI usage, agent steps, and spend not bounded

    Cap agent steps and output tokens on every model call, set per-key and per-project budgets with usage alerts, and issue scoped, expiring model keys.

    Addresses 5 items: 4 standards · 1 recommended guardrail

  7. Model output reaches a code, query, shell, markup, or file-path interpreter without validation or encoding

    Treat model output as untrusted input: validate it against a schema, encode or parameterize it for its sink, and run generated code only in a sandbox.

    Addresses 5 items: 5 standards

  8. Untrusted content influences instructions or tools

    Keep fetched, retrieved, and tool-returned content out of the system prompt, pass it as delimited data, and restrict which tools a turn holding that content can call.

    Addresses 5 items: 4 standards · 1 recommended guardrail

  9. Agent tools and credentials not scoped to least privilege

    Declare each agent's allowed tools and credentials explicitly, grant only what its task needs, and keep destructive operations off unless a grant names them.

    Addresses 4 items: 3 standards · 1 recommended guardrail

  10. GenAI with untracked third-party components (value chain)

    Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.

    Addresses 4 items: 3 standards · 1 recommended guardrail

The top 10 of 51; the build plan ranks all of them and lets you narrow by AI feature.

By AI feature

Plans for one feature in SA:

Laws

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.