TwinEthos homeRequest access

Law

Kazakhstan AI Law (No. 230-VIII)

Parliament of the Republic of Kazakhstan; the authorized body in the field of AI (central executive body, Art. 1(10)) leads and coordinates the field · KZ · 7 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: old.adilet.zan.kz.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 7 of 7 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 7
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 7 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 7.
Audit standard
7 of 7 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
8 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 7 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Users must be told that goods, works or services are produced or provided using AI (Kazakhstan AI Law Art. 21(1))

Art. 21(1) (users informed of AI use) · official text · In force: applies since 18 Jan 2026 · KZ

Kazakhstan's Law No. 230-VIII On Artificial Intelligence, in force since 2026-01-18, requires that users be informed that goods, works and services are produced or provided using AI systems (Art. 21(1)). The article names no duty bearer; the Law's duties toward users fall on the owners and holders of AI systems (Arts. 15, 21(3)). A user is anyone using an AI system for a specific function or task (Art. 1(7)). Detect an AI-backed service that returns model output to a person, or an AI chat surface, with no notice that AI is used.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 21(1) (users informed of AI use) · captured 3 Oct 2026 · anchor hash (SHA-256) d439e9661c2f… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Notice shown only in the terms or the app-store listing
  • Services that use AI with no model call in the repository
  • The notice may be rendered by a shared layout or onboarding screen in another file; check the entry point before reporting.

1 more known limit in the data release.

Who it applies to

  • Duty falls on: provider, deployer
  • Owners and holders of AI systems, and whoever provides goods, works or services produced or provided using an AI system (Art. 1(5): a digital object working on one or more AI models), toward users in Kazakhstan. In force from 2026-01-18 (Art. 31: 60 calendar days after first official publication, which was on 18.11.2025). Art. 21(1) names no duty bearer and sets no form or timing for the notice; who must inform, how, and whether a foreign provider is covered are counsel questions.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Tell users that the good, work or service is produced or provided using an AI system; the Law sets no form or moment, so show it where the AI output is delivered.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 29 items with binding law in 22 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id kz-ai-law.ai-use-notice · review status: primary source derived

Binding law — in force

Users may obtain an explanation of AI results that affect them and information on the data behind an AI decision (Kazakhstan AI Law Arts. 7(2), 16(1))

Art. 16(1) (rights of users) · official text · In force: applies since 18 Jan 2026 · KZ

Kazakhstan's AI Law gives users the right to obtain from the owner or holder of an AI system explanations of its results that affect their rights, freedoms and legitimate interests, in the manner set by the user agreement and the law (Art. 16(1)(4)), and to request information on the data on which the AI system based a decision, to the extent the user agreement provides and subject to personal-data, confidentiality and trade-secret law (Art. 16(1)(5)). A user subject to AI decisions has the right to be informed of the automated processing and its consequences and of the possibility to object (Art. 7(2)). Detect a model output that becomes a decision about a person with no stored reasons or explanation route.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 16(1) (rights of users) · captured 3 Oct 2026 · anchor hash (SHA-256) 4f3364a63d63… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Results that affect a person without a status change (e.g. a ranking shown to a third party)
  • The explanation may live in a separate letters or portal module; follow the decision id before reporting.

Who it applies to

  • Duty falls on: provider, deployer
  • Systems covered: automated decision, consequential decision
  • Owners and holders of AI systems whose results affect a user's rights, freedoms or legitimate interests, or that take decisions about users, in Kazakhstan. In force from 2026-01-18. Art. 7(2) is placed among the Law's principles; Art. 16(1)(4)-(5) are user rights exercised under the user agreement. How far the user agreement may narrow the rights is a counsel question.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.

Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • On request, explain the AI system's results that affect the user's rights and give information on the data the decision was based on, within the user agreement and personal-data, confidentiality and trade-secret limits.
  • Tell a user subject to AI decisions about the automated processing, its consequences and how to object (Art. 7(2)).

Example (Python + OpenAI SDK + Pydantic), before:

resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
    application.status = 'denied'
    send_email(applicant.email, 'Your application was declined.')

After:

a = Assessment.model_validate_json(resp.choices[0].message.content)   # decision, reason_codes
if a.decision == 'deny':
    decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
                     model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
    send_email(applicant.email, render('adverse_action_notice.txt',
        reasons=a.reason_codes,
        role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
        correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))

Control: Adverse AI decision without explanation/appeal. The same guard addresses 12 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id kz-ai-law.explanation-and-decision-data-on-request · review status: primary source derived

Binding law — in force

AI systems may not classify people by biometric data to infer race, political views or religion for discrimination (Kazakhstan AI Law Art. 17(3)(5))

Art. 17(3) (prohibited functional capabilities) · official text · In force: applies since 18 Jan 2026 · KZ

Kazakhstan's AI Law prohibits creating and operating, on its territory, AI systems capable of classifying natural persons on the basis of their biometric data to draw conclusions about their race, political views, religious affiliation or any other circumstances (criteria) for use in any discrimination against a person (Art. 17(3)(5)). Detect code that infers race, ethnicity, religion, political views or sexual orientation from face or voice data.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 17(3) (prohibited functional capabilities) · captured 3 Oct 2026 · anchor hash (SHA-256) a4f6a25d1eb0… · 2 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • The prohibition is for use in discrimination; research or bias-auditing code that labels such traits may be outside it, but report it for review.

Who it applies to

  • Duty falls on: any person
  • Systems covered: prohibited
  • Anyone creating or operating an AI system on the territory of Kazakhstan. In force from 2026-01-18. The prohibition is tied to the purpose of use in discrimination; whether inference of a sensitive trait without that purpose is caught is a counsel question.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Remove any model, prompt, or label set that infers race, political opinion, union membership, religion or beliefs, sex life, or sexual orientation from biometric data.

In biometric pipelines (face, voice, gait, iris), the code computes only the attributes the feature needs and never a sensitive-trait category: no classifier heads or labels for race or ethnicity, political opinion, trade-union membership, religious or philosophical belief, sex life, or sexual orientation, and no attribute API used for those traits (for example DeepFace.analyze with the 'race' action). Prompts that send a person's photo or voice to a multimodal model instruct it not to guess these traits, and an output check strips any such inference. The data model has no columns for these traits derived from biometric input.

Where it goes: 1 application source code, 2 data models, 7 prompt construction, 9 AI output handling.

What this provision adds:

  • Do not compute race, political views, religion or similar categories from biometric data; strip such heads, labels and prompt instructions from biometric pipelines.

Example (Python DeepFace), before:

result = DeepFace.analyze(img_path=photo, actions=['age', 'gender', 'race'])
profile.update(age=result[0]['age'], ethnicity=result[0]['dominant_race'])

After:

result = DeepFace.analyze(img_path=photo, actions=['age'])   # no 'race' action
profile.update(age=result[0]['age'])

Control: Biometric categorisation of sensitive traits. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id kz-ai-law.no-biometric-categorisation-for-discrimination · review status: primary source derived

Binding law — in force

Users may refuse to interact with an AI system unless a law makes the interaction mandatory (Kazakhstan AI Law Art. 16(1)(6))

Art. 16(1) (rights of users) · official text · In force: applies since 18 Jan 2026 · KZ

Kazakhstan's AI Law gives users the right to refuse interaction with an AI system where the laws of Kazakhstan do not make such interaction mandatory (Art. 16(1)(6)). In code, an AI-only channel with no way to decline the AI and reach a person or a non-AI path leaves the right without effect. Detect an AI conversation or assistant surface that calls a model and offers no human hand-off or AI opt-out.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 16(1) (rights of users) · captured 3 Oct 2026 · anchor hash (SHA-256) 4f3364a63d63… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Phone or IVR channels configured outside the repository
  • A hand-off button rendered elsewhere in the UI; a channel the law makes mandatory.

Who it applies to

  • Duty falls on: provider, deployer
  • Users of AI systems in Kazakhstan, against the owners and holders of the systems they are offered. In force from 2026-01-18. The Law does not say what refusing entails (a human channel, a non-AI process, or simply not using the service): counsel question.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Give people a way to decline the AI and reach a person or a non-AI path, store the choice, and skip the model for anyone who declined.

On every AI conversation or assistant entry point, offer a visible option to talk to a person or use a non-AI process (a hand-off button, a 'talk to an operator' command, a form). Store the choice as a per-user ai_opt_out preference, and at the top of the handler route opted-out users to the human queue or non-AI flow without calling the model. The hand-off reaches a real channel (support queue, operator, callback), not a dead end.

Where it goes: 1 application source code, 3 config and feature flags, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Let users decline the AI system: offer a human hand-off or a non-AI path, store the choice, and do not call the model for a user who declined.

Example (FastAPI + OpenAI SDK), before:

@app.post('/chat')
def chat(req: ChatRequest):
    reply = client.chat.completions.create(model=MODEL, messages=req.messages)
    return {'reply': reply.choices[0].message.content}

After:

@app.post('/chat')
def chat(req: ChatRequest):
    if prefs.get(req.user_id, 'ai_opt_out'):
        return route_to_human_agent(req)          # the model never runs
    reply = client.chat.completions.create(model=MODEL, messages=req.messages)
    return {'reply': reply.choices[0].message.content, 'actions': ['talk_to_human']}

Control: AI interaction offers no way to decline the AI. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Microsoft retires Azure Face emotion and identity-attribute inference (2022-06; disclosed by the operator). On June 21, 2022 Microsoft said it would retire Azure Face capabilities that infer emotional states and identity attributes such as gender, age, smile, facial hair, hair, and makeup: unavailable to new customers from that day, with existing customers given until June 30, 2023 to stop using them. Microsoft cited privacy, the lack of consensus on a definition of 'emotions', and the inability to generalize the link between facial expression and emotional state across use cases, regions, and demographics, and said that access to capabilities predicting sensitive attributes opens ways to misuse them, including stereotyping, discrimination, or unfair denial of services. It kept these capabilities for controlled accessibility scenarios such as Seeing AI. Source: Microsoft Azure Blog (2022-06-21) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Hungarian regulator fines a bank for AI analysis of callers' emotions without notice or a way to object (2017-05; confirmed). In decision NAIH-85-3/2022 of 8 February 2022, Hungary's data protection authority found that Budapest Bank's speech-analysis software, which the bank said it introduced on 26 May 2017, automatically analysed recorded customer-service calls for keywords and for the emotional state of the caller and the employee, and that the results were used to rank calls and to select dissatisfied customers to call back. The Authority found that callers were not told at the start of calls about the voice analysis, the automatic evaluation of their emotions, or the resulting possible callback, and could not object; it rejected the bank's statement that the software contained no artificial intelligence. It found infringements of GDPR Articles 5(1)(a)-(b), 6(1), 6(4), 12(1), 13, 21(1)-(2), 24(1) and 25(1), ordered the bank not to analyse emotions in the voice analysis, and imposed a fine of HUF 250 million. The decision also records, from the bank's own technical file, that the emotion was unrecognisable in 91.96% of cases. Source: Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian data protection authority), decision NAIH-85-3/2022, English version · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in

Rule id kz-ai-law.refuse-ai-interaction · review status: primary source derived

Binding law — in force

Synthetic AI outputs may be distributed only with a machine-readable mark and a perceivable warning (Kazakhstan AI Law Art. 21(2)-(3))

Art. 21(2) (synthetic results: machine-readable marking and perceivable warning) · official text · In force: applies since 18 Jan 2026 · KZ

Under Kazakhstan's AI Law, synthetic results of AI systems (images, video, audio, texts or combinations created or modified by an AI system that imitate a natural person's appearance, voice or behaviour, or events that did not happen, Art. 1(4)) may be distributed only if they are marked in machine-readable form and accompanied by a visual or other warning the user can perceive without methods that make perception harder (Art. 21(2)). The owners or holders of the AI systems are responsible for informing users about synthetic results (Art. 21(3)). Detect generated or face- or voice-synthesised media saved, served or published with no visible warning or no machine-readable mark.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 21(2) (synthetic results: machine-readable marking and perceivable warning) · captured 3 Oct 2026 · anchor hash (SHA-256) 6c890fac3403… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Text outputs
  • Marks added by a separate post-processing service
  • Only results that imitate a person's appearance, voice or behaviour, or events that did not happen, are synthetic results (Art. 1(4)); a generated illustration of nothing real may be outside the duty.

Who it applies to

  • Duty falls on: provider, deployer
  • Owners and holders of AI systems that produce synthetic results (Art. 1(4): content that imitates a real person's appearance, voice or behaviour, or events that did not happen), and anyone distributing such results in Kazakhstan. In force from 2026-01-18. The Law sets no format for the machine-readable mark; Art. 22(3) leaves machine-readable forms to the authorized body (no act found). Whether ordinary generated content that imitates no person or event is covered, and who 'distributes', are counsel questions.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.

A labeling step between the generator call and every save, return, or download path does two things: it adds an explicit label users can perceive (text drawn onto images or video frames, an audible notice in audio, a label beside generated text in the UI), and it writes implicit metadata into the file (a PNG text chunk, XMP block, or C2PA manifest) carrying the AI-generated attribute, the provider's name or code, and a unique content ID. Export and download routes go through the same step so files leave with both labels; a digital watermark can complement the metadata.

Where it goes: 9 AI output handling, 1 application source code.

What this provision adds:

  • Before distributing a synthetic result, attach a machine-readable mark (e.g. a C2PA manifest or metadata field) and a visual or other warning the user perceives without effort.
  • The owner or holder of the AI system informs users about synthetic results (Art. 21(3)).

Example (OpenAI Images + Pillow), before:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64)))
img.save(path)

After:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64))).convert('RGB')
font = ImageFont.truetype('NotoSansCJK-Regular.ttc', 24)
ImageDraw.Draw(img).text((12, img.height - 36), 'AI生成 / AI-generated', fill=(255, 255, 255), font=font)
meta = PngInfo()
# implicit label: AI-generated attribute, provider name or code, content reference (Art. 5);
# take the exact metadata field names from the national standard GB 45438-2025 (not encoded here)
meta.add_text('ai_generated_label', json.dumps({'ai_generated': True, 'provider': PROVIDER_CODE,
                                                'content_id': str(uuid.uuid4())}))
img.save(path, format='PNG', pnginfo=meta)

Control: GenAI content lacking explicit and implicit labels. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id kz-ai-law.synthetic-output-label-and-warning · review status: primary source derived

Binding law — in force

Works may be used to train AI models only if the author or rights holder has not prohibited it in machine-readable form (Kazakhstan AI Law Art. 23(5))

Art. 23(5) (training only absent a machine-readable prohibition) · official text · In force: applies since 18 Jan 2026 · KZ

Kazakhstan's AI Law allows the use of works to train AI models only where the author or rights holder has not prohibited it in machine-readable form (Art. 23(5)). A training-data pipeline that crawls or ingests works must therefore read and honour machine-readable reservations (robots.txt rules, TDM reservation protocols, noai metadata) before a work enters a training set. Detect a crawler or page fetch that feeds a training or dataset-building step with no machine-readable opt-out check.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 18 Jan 2026
Official source
Art. 23(5) (training only absent a machine-readable prohibition) · captured 3 Oct 2026 · anchor hash (SHA-256) 8f42f50c4de6… · 2 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Licensed or first-party corpora loaded from storage
  • Crawling in one service and training in another
  • The opt-out filter may run in a separate ingestion stage; check the pipeline before reporting.

Who it applies to

  • Duty falls on: developer
  • Anyone who uses works to train AI models, where the copyright law of Kazakhstan applies to the works. In force from 2026-01-18. The Law does not name the machine-readable formats that count as a prohibition, and Art. 23(3)-(4) (read) say training is not free use and not an exercise of the author's rights; which formats bind and whether the duty reaches training abroad on works of Kazakh authors are counsel questions.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.

A gate in the data pipeline between collection (load_dataset, crawlers, Common Crawl WARC readers, exports of user chats) and training (Trainer, SFTTrainer, fine_tuning.jobs.create) that keeps only records whose source and licence are on an allowlist, checks robots.txt before crawling, drops user content without a training-consent flag, and runs PII detection and anonymisation on the rest. It writes a provenance manifest per shard (source, licence, retrieval date, consent basis, filters applied) kept with the model version, alongside the IP clearance record and the data-quality measures applied. Base models you fine-tune get the same source and licence entry.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts.

What this provision adds:

  • Before a work enters a training set, read the machine-readable reservations the author or rights holder may have set (robots.txt, TDM reservation, noai metadata) and exclude reserved works.

Example (Hugging Face datasets + TRL + Presidio), before:

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

After:

ALLOWED_LICENSES = {'cc-by-4.0', 'cc0-1.0', 'apache-2.0', 'licensed-by-contract'}
analyzer, anonymizer = AnalyzerEngine(), AnonymizerEngine()

def scrub(row):
    hits = analyzer.analyze(text=row['text'], language=LANG)
    row['text'] = anonymizer.anonymize(text=row['text'], analyzer_results=hits).text
    return row

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
ds = ds.filter(lambda r: r['license'] in ALLOWED_LICENSES).map(scrub)
write_provenance_manifest(ds, out='manifests/shard-000.json')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

Control: GenAI training data without lawful source / IP / consent controls. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id kz-ai-law.training-respects-machine-readable-opt-out · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.