TwinEthosRequest access

Standard or framework

EU ALTAI

European Commission — High-Level Expert Group on AI · European Union (EU) · 3 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: digital-strategy.ec.europa.eu.

Standard / soft law

AI systems should provide human oversight (HITL/HOTL/HIC) and the ability to intervene (EU ALTAI)

ALTAI / EU Ethics Guidelines — Requirement 1 (Human Agency and Oversight) · official text · Soft law or guidance (not binding law) · European Union (EU)

Per EU ALTAI Requirement 1 (Human Agency and Oversight), AI systems should be designed with proper oversight mechanisms — human-in-the-loop, human-on-the-loop, or human-in-command — allowing humans to make informed decisions, intervene, and override, especially for decisions affecting fundamental rights. Detect an AI decision path with no human-oversight/override affordance.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision, high risk
  • AI systems developed, deployed, procured, or used in the EU. Voluntary self-assessment; the EU AI Act later makes human oversight binding for high-risk systems (Art. 14). ALTAI is the AI Act's precursor checklist.

The guard to add

Give people who receive an adverse AI-influenced decision a way to see and correct the data used and to request human review that can change the outcome.

Built into the adverse-outcome path: when a decision is adverse, the system saves the personal-data inputs the model used with the decision, and the letter or screen that communicates it links to two routes. A data access and correction route (GET/PATCH /me/data, correct_input_data) shows those inputs and accepts corrections of inaccurate data, which send the decision back for re-run or review; a reconsideration route (POST /decisions/{id}/reconsideration, request_human_review) places the case in a review queue where a reviewer with authority to change the outcome records reviewer_id and override_reason.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 2 data models.

Example (FastAPI), before:

if result['decision'] == 'denied':
    applications.save(app_id, status='denied')
    send_email(applicant.email, render('denial.txt', applicant=applicant))

After:

if result['decision'] == 'denied':
    applications.save(app_id, status='denied', inputs_used=features, model_version=MODEL_VERSION)
    send_email(applicant.email, render('denial.txt', applicant=applicant,
               data_url=f'{BASE}/me/data', review_url=f'{BASE}/decisions/{app_id}/reconsideration'))

@app.patch('/me/data')
def correct_input_data(fix: DataCorrection, user=Depends(current_user)):
    corrections.create(user_id=user.id, field=fix.field, value=fix.value)
    review_queue.enqueue(user.latest_decision_id, reason='data_corrected')

@app.post('/decisions/{decision_id}/reconsideration')
def request_human_review(decision_id: str, user=Depends(current_user)):
    review_queue.enqueue(decision_id, reason='consumer_request')   # reviewer can change the outcome

Control: No human review/data-correction path after adverse ADMT decision. The same guard addresses 2 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id eu-altai.human-oversight · review status: primary source derived

Standard / soft law

AI should avoid unfair bias and be assessed for discrimination (EU ALTAI)

ALTAI / EU Ethics Guidelines — Requirement 5 (Diversity, Non-discrimination and Fairness) · official text · Soft law or guidance (not binding law) · European Union (EU)

Per EU ALTAI Requirement 5 (Diversity, Non-discrimination and Fairness), unfair bias must be avoided (which can marginalize vulnerable groups and exacerbate discrimination); AI systems should be accessible and involve relevant stakeholders across the lifecycle. Detect an AI decision system with no bias/fairness assessment or accessibility consideration.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision
  • AI systems developed, deployed, procured, or used in the EU. Voluntary self-assessment; precursor to EU AI Act Art. 10 (data governance/bias).

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.

A validation stage that runs whenever a decision model is trained, fine-tuned, or retrained (the same module or pipeline step as fit(), Trainer, xgb.train, or fine_tuning.jobs.create) and again on a recurring schedule against recent decisions: accuracy and error rates per group, selection rates and disparity metrics (fairlearn MetricFrame, demographic_parity_difference, AIF360 disparate impact), and drift. Results go to a versioned validation report alongside a datasheet or data card for the training data, and a threshold gate blocks promotion of a model version whose metrics regress until a named owner reviews and records a decision. The validation cadence and owner are written in the model's validation record.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.

What this provision adds:

  • Include an accessibility consideration and the involvement of relevant stakeholders across the lifecycle alongside the bias assessment.

Example (scikit-learn + fairlearn), before:

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
joblib.dump(clf, 'models/credit_v4.joblib')

After:

from fairlearn.metrics import MetricFrame, selection_rate, demographic_parity_difference
from sklearn.metrics import accuracy_score

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
y_pred = clf.predict(X_test)
mf = MetricFrame(metrics={'accuracy': accuracy_score, 'selection_rate': selection_rate},
                 y_true=y_test, y_pred=y_pred, sensitive_features=A_test)
dpd = demographic_parity_difference(y_test, y_pred, sensitive_features=A_test)
write_validation_report('credit_v4', mf.by_group, dpd)
if dpd > MAX_DPD:
    raise SystemExit('bias gate failed: owner review required before release')
joblib.dump(clf, 'models/credit_v4.joblib')

Control: AI decision system without regular accuracy/bias validation. The same guard addresses 4 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id eu-altai.non-discrimination-fairness · review status: primary source derived

Standard / soft law

AI should be transparent, traceable, and disclose AI interaction to users (EU ALTAI)

ALTAI / EU Ethics Guidelines — Requirement 4 (Transparency) · official text · Soft law or guidance (not binding law) · European Union (EU)

Per EU ALTAI Requirement 4 (Transparency), the data, system, and AI business model should be transparent with traceability mechanisms; AI decisions should be explainable to the affected stakeholder; and humans must be made aware they are interacting with an AI system and informed of its capabilities and limitations. Detect an AI system with no traceability/logging, no explanation capability, or no AI-interaction disclosure.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision
  • AI systems developed, deployed, procured, or used in the EU. Voluntary self-assessment; precursor to EU AI Act Art. 13 (transparency) + Art. 50 (AI-interaction disclosure).

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Also record a trace with each model output that reaches a person or a decision record: model id, prompt version, inputs, request id.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id eu-altai.transparency-traceability · review status: primary source derived