Market
AI law in SA
3 binding provisions TwinEthos encodes that reach SA: 3 in force, 0 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
The guards that cover the most here
51 guards address 103 items across 1 jurisdiction with binding law: 3 binding law in force, 0 enacted but not yet applying, 67 standards and frameworks, 33 TwinEthos recommended guardrails.
AI system deployed without an AI system impact assessment
Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.
Addresses 2 items: 1 binding law in force · 1 standard
Law in force in SA.
The privacy policy does not describe the decisions computer programs make or help make with personal information
Keep an automated-decisions section in the privacy policy, generated or checked against the decision paths in code.
Addresses 1 item: 1 binding law in force
Law in force in SA.
Solely-automated significant decision without human-intervention safeguards
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
Addresses 1 item: 1 binding law in force
Law in force in SA.
Agent high-impact action without human approval
Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.
Addresses 5 items: 4 standards · 1 recommended guardrail
AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry
Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.
Addresses 5 items: 4 standards · 1 recommended guardrail
AI usage, agent steps, and spend not bounded
Cap agent steps and output tokens on every model call, set per-key and per-project budgets with usage alerts, and issue scoped, expiring model keys.
Addresses 5 items: 4 standards · 1 recommended guardrail
Model output reaches a code, query, shell, markup, or file-path interpreter without validation or encoding
Treat model output as untrusted input: validate it against a schema, encode or parameterize it for its sink, and run generated code only in a sandbox.
Addresses 5 items: 5 standards
Untrusted content influences instructions or tools
Keep fetched, retrieved, and tool-returned content out of the system prompt, pass it as delimited data, and restrict which tools a turn holding that content can call.
Addresses 5 items: 4 standards · 1 recommended guardrail
Agent tools and credentials not scoped to least privilege
Declare each agent's allowed tools and credentials explicitly, grant only what its task needs, and keep destructive operations off unless a grant names them.
Addresses 4 items: 3 standards · 1 recommended guardrail
GenAI with untracked third-party components (value chain)
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
Addresses 4 items: 3 standards · 1 recommended guardrail
The top 10 of 51; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in SA:
Laws
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.