Market
AI law in Iowa
10 binding provisions TwinEthos encodes that reach Iowa (US-IA): 3 in force, 7 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Includes US federal law, which applies in every state. See also United States (federal).
The guards that cover the most here
50 guards address 68 items across 2 jurisdictions with binding law (in force in 1 of them): 3 binding law in force, 7 enacted but not yet applying, 34 standards and frameworks, 24 TwinEthos recommended guardrails.
AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent
Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
More health information than the task needs is sent to an AI model
Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 4 items: 1 enacted, not yet applying · 2 standards · 1 recommended guardrail
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 2 items: 1 enacted, not yet applying · 1 recommended guardrail
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
AI conversation designed to maximize time spent or discourage leaving
Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
AI experience ignores age signals it already has
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
AI persona claims to be real, alive, or sentient, claims feelings or a relationship, or proposes meeting in person
Prefer persona prompts that answer 'are you real?' truthfully and do not claim sentience, feelings, love, or a romantic role, or propose meeting in person.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
Conversational AI represents itself as providing professional mental/behavioral health care
Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
Companion or conversational AI account without user or parental controls for privacy, settings and screen time
Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.
Addresses 1 item: 1 enacted, not yet applying
enacted, not yet applying in Iowa (US-IA); next date 2027-07-01.
The top 10 of 50; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in Iowa:
Laws
- FTC Impersonation Rule (16 CFR Part 461) United States (federal) (US)
- HIPAA Privacy Rule (45 CFR 160, 164 Subpart E) United States (federal) (US)
- Iowa SF 2417 (Iowa Code ch. 554J, conversational AI) Iowa (US-IA)
Coming into force
- : Conversational AI must disclose it is AI: persistently or every three hours, and at each start for minors (Iowa) (Iowa (US-IA))
- : Conversational AI must give minor account holders, and parents of those under 13, privacy and account-setting tools (Iowa) (Iowa (US-IA))
- : Conversational AI must block sexual depictions, sexual suggestions and sexual objectification for minor account holders (Iowa) (Iowa (US-IA))
- : Conversational AI must not give minors points or rewards at unpredictable intervals to drive engagement (Iowa) (Iowa (US-IA))
- : Conversational AI must not claim to be sentient or human, simulate emotional dependence or romance, or role-play adult-minor romance (Iowa) (Iowa (US-IA))
- : Conversational AI must not be presented as providing licensed psychology or behavioral health services (Iowa) (Iowa (US-IA))
- : Conversational AI must have a suicide and self-harm protocol with crisis referrals (Iowa) (Iowa (US-IA))
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.