Jogorku Kenesh of the Kyrgyz Republic; sector regulators of the national digital ecosystem · KG · 5 provisions encoded · verified against the official source as of 2026-10-03.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 5 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 5.
Audit standard
5 of 5 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
5 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.03.3 (3 Oct 2026): 5 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — in force
Consumers must be told they are interacting with an AI system unless it is obvious (Kyrgyz Digital Code Art. 197(1))
Art. 197(1) (informing consumers of interaction with AI) · official text · In force: applies since 6 Feb 2026 · KG
Kyrgyzstan's Digital Code requires owners and users of AI systems that design, develop or apply them to interact with consumers to inform those consumers of the fact of interaction with an AI system, unless it is obvious from the circumstances; information on the use of AI systems in digital-environment relations is public and is posted on the users' websites and the sector regulator's website (Art. 197(1)). Defence, national security and law-enforcement functions are excepted where informing would prevent their lawful use, with protective measures (Art. 197(3), (6)). Detect a consumer-facing AI chat surface with no AI-interaction notice.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 6 Feb 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Voice channels
Notice posted only on the website (the public information duty is separate)
Interaction that is obvious from the circumstances needs no notice; the notice may be rendered by a parent component.
Who it applies to
Duty falls on: provider, deployer
Owners and users of AI systems (Art. 1(63)) that design, develop or apply them to interact with consumers (Art. 1(47): natural persons using a digital system or service for personal, non-profit purposes) in the Kyrgyz Republic. In force from 2026-02-06 (Law No. 179, Art. 1: six months from official publication of that Law on 5 August 2025) for relations arising after that date (Art. 3(1)). The Code states no territorial clause; whether it reaches a foreign provider is a counsel question.
Not covered:
Interaction that is obvious from the circumstances (Art. 197(1))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Inform the consumer at the interaction that they are dealing with an AI system unless that is obvious, and publish information on the AI use on your website (and it appears on the sector regulator's site).
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message
Control: AI chat interaction without disclosure. The same guard addresses 29 items with binding law in 22 jurisdictions. Engineering guidance, not legal advice.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id kg-digital-code.ai-interaction-notice · review status: primary source derived
Binding law — in force
Users of AI systems for deepfakes must disclose the artificial origin or alteration of the material (Kyrgyz Digital Code Art. 197(4))
Art. 197(4) (deepfake disclosure) · official text · In force: applies since 6 Feb 2026 · KG
Kyrgyzstan's Digital Code requires users of AI systems who use them for deepfakes (creating or altering images, audio or video closely resembling existing persons, objects, places or events and able to give a false impression of authenticity, Art. 1(15)) to disclose the artificial origin or alteration of the materials (Art. 197(4)). The duty does not apply to lawful use to protect the protected interests or to exercise freedom of scientific, technical, artistic and other creativity, teaching and learning, and only with measures protecting affected rights (Art. 197(5)-(6)). Detect face-swap, voice-clone or lip-sync output saved, served or published with no disclosure.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 6 Feb 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Generic image generation that resembles a real person without a face-swap or clone call
Creative, educational or protective uses are excepted (Art. 197(5)); the disclosure may be added by a publishing service elsewhere.
Who it applies to
Duty falls on: deployer
Systems covered: limited risk
Users of AI systems who use them to create or alter deepfakes in the Kyrgyz Republic. In force from 2026-02-06 (Law No. 179, Art. 1: six months from official publication of that Law on 5 August 2025) for relations arising after that date (Art. 3(1)). Whether a tool provider that generates the deepfake for its users bears the duty is a counsel question.
Not covered:
Lawful use to protect the protected interests of Art. 197(3) (Art. 197(5))
Lawful use for scientific, technical, artistic and other creativity, teaching and learning (Art. 197(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Attach a visible 'AI-generated or manipulated' disclosure to face-swapped, voice-cloned, or likeness-generated media on every path that publishes or returns it.
In the handler that publishes or serves the output of a face-swap, voice-clone, lip-sync, or likeness model, add the disclosure to the content itself (an overlay or caption on image and video, a spoken or on-screen statement for audio) and to the post text where it is published; the publish function refuses media that lacks the disclosure. In an evidently artistic or satirical work the disclosure can be adapted so it does not spoil the work, but it is still present. Pair it with machine-readable marking so the label survives re-sharing.
Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.
What this provision adds:
Disclose on the material itself that it was artificially created or altered (for example an on-screen caption or spoken notice), and keep a machine-readable mark so the disclosure survives sharing.
Control: Deepfake content not disclosed. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Rule id kg-digital-code.deepfake-disclosure · review status: primary source derived
Binding law — in force
People must be told when an emotion-recognition or biometric-classification AI system is applied to them (Kyrgyz Digital Code Art. 197(2))
Art. 197(2) (informing persons of emotion recognition or biometric classification) · official text · In force: applies since 6 Feb 2026 · KG
Kyrgyzstan's Digital Code requires users of AI systems designed to recognise emotions or classify natural persons by biometric features to inform those persons of the application of such systems to them (Art. 197(2)), save for defence, national security and law-enforcement functions where informing would prevent their lawful use, with protective measures (Art. 197(3), (6)). Detect emotion recognition or biometric classification in a file with no notice to the person.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 6 Feb 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
The notice may be shown in the capture UI in another file; a defence, security or law-enforcement function may be excepted.
Who it applies to
Duty falls on: deployer
Systems covered: limited risk
Users (deployers) of AI systems designed for emotion recognition or biometric classification of natural persons in the Kyrgyz Republic. In force from 2026-02-06 (Law No. 179, Art. 1: six months from official publication of that Law on 5 August 2025) for relations arising after that date (Art. 3(1)).
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Show people a notice that emotion recognition or biometric categorisation is running before the analysis touches their face, voice, or video, and gate the analysis on it.
A notice gate in the module that calls the emotion or categorisation model (DeepFace.analyze with actions=['emotion'], FER().detect_emotions, Hume expression measurement, Rekognition detect_faces with Attributes=['ALL']). For app flows, an interstitial tells the person the system is operating, what it infers, and why, and the analysis function refuses to run until that acknowledgment is recorded for the session. For cameras or kiosks that analyse passers-by, the deployment config names the on-screen banner or physical signage at the capture point, and the pipeline does not start for a site with no notice configured.
Where it goes: 1 application source code, 3 config and feature flags, 14 user-facing text.
What this provision adds:
Inform each person that an emotion-recognition or biometric-classification system is being applied to them before or at the analysis.
Example (Python DeepFace), before:
def analyse_frame(frame):
result = DeepFace.analyze(img_path=frame, actions=['emotion'])
return result[0]['dominant_emotion']
After:
def analyse_frame(frame, session):
# notice shown in the capture UI; acknowledgment stored per session
if not session.get('emotion_notice_shown_at'):
raise NoticeRequired('inform the person that emotion recognition is running')
result = DeepFace.analyze(img_path=frame, actions=['emotion'])
return result[0]['dominant_emotion']
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id kg-digital-code.emotion-biometric-notice · review status: primary source derived
Binding law — in force
High-danger AI users must publish how the system works and, on request, explain how a result about a person was obtained (Kyrgyz Digital Code Art. 196(2))
Art. 196(2) (information and explanation where a result is used for a decision affecting rights) · official text · In force: applies since 6 Feb 2026 · KG
Under Kyrgyzstan's Digital Code, where a high-danger AI system (one whose use raises the risk of harm to protected interests to a level requiring risk management, as classified by the owner's hazard assessment, Arts. 193(1), 194(1), (3)) produces a result used for a decision that may infringe the rights, freedoms or legitimate interests of natural or legal persons, its user must (1) for systems interacting with consumers, post on its website, and otherwise provide, accessible general information on the system's characteristics, how it works and how the result is obtained and applied, and (2) on request of persons affected by the decision, provide free of charge accessible information allowing them to understand and check the premises and methods of obtaining the result concerning them (Art. 196(2)). Detect a model output that becomes a decision about a person with no stored explanation or explanation route.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 6 Feb 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
The website publication duty of Art. 196(2)(1) is a document outside the decision path
Only high-danger systems are covered; the explanation may be served by a separate portal module.
Who it applies to
Duty falls on: deployer
Systems covered: high risk, consequential decision
Users of AI systems classified as high-danger by the owner's hazard assessment (Arts. 193-194), when a result is used for a decision that may infringe the rights or legitimate interests of natural or legal persons in the Kyrgyz Republic. In force from 2026-02-06 (Law No. 179, Art. 1: six months from official publication of that Law on 5 August 2025) for relations arising after that date (Art. 3(1)). Whether a given system is high-danger depends on the owner's assessment and the Cabinet of Ministers requirements (not captured): human determination.
Not covered:
A system whose use is purely auxiliary and does not raise the risk of harm is not high-danger (Art. 194(3))
Use solely for personal or family needs, save joint liability where third parties' rights are infringed (Art. 196(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
For consumer-facing high-danger systems, publish on your website plain general information on the system's characteristics, how it works and how results are obtained and used.
On request of an affected person, provide free of charge information that lets them understand and check the premises and methods of the result about them.
Example (Python + OpenAI SDK + Pydantic), before:
resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
application.status = 'denied'
send_email(applicant.email, 'Your application was declined.')
After:
a = Assessment.model_validate_json(resp.choices[0].message.content) # decision, reason_codes
if a.decision == 'deny':
decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
send_email(applicant.email, render('adverse_action_notice.txt',
reasons=a.reason_codes,
role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))
UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id kg-digital-code.high-danger-ai-information-and-explanation · review status: primary source derived
Binding law — in force
Owners and users of high-danger AI systems must keep its operation logs while it is under their control (Kyrgyz Digital Code Arts. 194(5)(4), 196(1)(5))
Art. 194(5) (duties of the owner of a high-danger AI system) · official text · In force: applies since 6 Feb 2026 · KG
Kyrgyzstan's Digital Code requires the owner of a high-danger AI system to keep the system's operation logs while it is under the owner's control (Art. 194(5)(4)), and the user of such a system to keep the logs while it is under the user's control (Art. 196(1)(5)), alongside duties of conformity, risk management, documentation and effective human control (Arts. 194(5), 196(1)). Users applying the system solely for personal or family needs are relieved of the user's logging duty (Art. 196(5)). Detect a model output that becomes a decision with no audit event recorded.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 6 Feb 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Log retention configured in infrastructure code
Logging may be done by middleware or a decorator defined elsewhere; only high-danger systems are covered.
Who it applies to
Duty falls on: provider, deployer
Systems covered: high risk
Owners and users of AI systems classified as high-danger (Arts. 193-194) in the Kyrgyz Republic. In force from 2026-02-06 (Law No. 179, Art. 1: six months from official publication of that Law on 5 August 2025) for relations arising after that date (Art. 3(1)). The Code sets no log content or retention period; the Cabinet of Ministers requirements (not captured) may.
Not covered:
A system whose use is purely auxiliary and does not raise the risk of harm is not high-danger (Art. 194(3))
A user applying the system solely for personal or family needs is relieved of Art. 196(1)(2)-(6), including logging (Art. 196(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.
An audit event emitted automatically by the service at the decision boundary, where model output becomes a status change, score, or response, rather than left to callers: decision_id, timestamp, model and resolved model_version, an input reference (a pointer rather than raw personal data where possible), the output, the operator or user identity, and any human verification. Events go to a central store (CloudWatch Logs, Log Analytics, Cloud Logging, Loki) whose retention is set explicitly in IaC, not left to a console default, and monitoring queries over those events flag risk situations and drift.
Where it goes: 1 application source code, 4 infrastructure-as-code, 10 logs and telemetry.
What this provision adds:
Keep the system's operation logs for as long as the system is under your control, as owner or as user.
Example (Python + OpenAI SDK + structlog), before:
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Court compelled discovery on how nH Predict works (2026-03-09; confirmed). A federal magistrate judge in the District of Minnesota ordered UnitedHealth to produce documents on how nH Predict works, including whether it was designed to supplant physician decision-making. Plaintiffs needed litigation discovery to learn how the model was designed and used. Source: U.S. District Court, D. Minn. (Order, Doc. 162) · evidence grade: primary · cited by Record enough at decision time to reproduce and explain every consequential AI decision
Rule id kg-digital-code.high-danger-ai-logs · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.