TwinEthos homeAPI access

Law

Texas H.B. 581 (2025): Civ. Prac. & Rem. Code ch. 129B, artificial sexual material tools

Texas Attorney General (civil penalty and injunction) · Texas (US-TX) · 2 provisions encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: tcss.legis.texas.gov.

Trust and provenance 1 official source · last verified 4 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Verify users are 18+ before access to a tool that creates artificial sexual material, keeping no identity data (Texas CPRC 129B.002(a-1), (b))

Tex. Civ. Prac. & Rem. Code 129B.002(b) · official text · In force: applies since 1 Sep 2025 · Texas (US-TX)

From 2025-09-01, a commercial entity that operates an Internet website with a publicly accessible tool for creating artificial sexual material harmful to minors, or otherwise makes publicly available an application for creating such material, must use reasonable age verification methods (digital identification, or a commercial age verification system using government-issued identification or transactional data, 129B.003) to verify that an individual attempting to access the tool is 18 or older (Civ. Prac. & Rem. Code 129B.002(a-1)). The entity or its third-party verifier may not retain any identifying information of the individual (129B.002(b)). The duty does not apply to an entity whose acknowledged terms prohibit generating such material and which takes affirmative technological steps to limit its creation (129B.002(a-2)). Detect explicit or adult generation modes switched on with no age gate.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Sep 2025
Official source
Tex. Civ. Prac. & Rem. Code 129B.002(b) · captured 4 Oct 2026 · anchor hash (SHA-256) 3218187d35fb… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Provider-side moderation settings configured outside the repository
  • The age gate may sit in middleware or the settings route that controls the flag; follow the flag before reporting. An entity relying on the 129B.002(a-2) exception (acknowledged terms prohibiting the material, plus filt…

Who it applies to

  • Duty falls on: provider, operator
  • Commercial entities that operate a website with a publicly accessible tool, or make publicly available an application, for creating artificial sexual material harmful to minors (computer-generated sexual material in which a person is recognizable as an actual person, produced with AI or other software), where Texas law governs. Applies from 2025-09-01. Not applicable to an entity relying on the (a-2) terms-and-filters exception; whether a tool is one 'for creating' such material and whether the exception's steps suffice are human determinations.
  • Not covered:
    • A commercial entity whose terms and conditions or use policies, acknowledged before access, prohibit generating artificial sexual material harmful to minors, and which takes affirmative technological steps to limit its creation (such as training the application to identify likely sexual material, effective reporting tools, filtering likely sexual material or AI-generated sexually explicit content before it is shown, or filtering sexually explicit images from training datasets) (129B.002(a-2); 129B.0045(b))
    • Bona fide news or public interest broadcasts, website videos, reports or events; the rights of a news-gathering organization (129B.005(a))
    • Internet service providers, search engines and cloud service providers solely for providing access or connection to content not under their control, to the extent not responsible for creating it (129B.005(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Gate every explicit or adult generation mode behind an age-assurance result, keep only the result, and delete the documents or images used for the check.

Where a setting or request turns on an explicit, adult, or unfiltered mode (enable_safety_checker off, nsfw or spicy mode, adult role-play), the server checks a stored age-assurance result first and refuses the change or request without one; a client flag alone never unlocks it. The age-assurance step (age estimation, account-based assurance, or an identity check where necessary) stores only the outcome and its method and date on the account; uploaded identity documents or face images are deleted as soon as the check completes (a scheduled purge enforces the limit), are never sent to analytics or advertising, and are never sold or used for anything else.

Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 6 API calls and integrations.

What this provision adds:

  • Use a reasonable age verification method: digital identification, or a commercial age verification system relying on government-issued identification or public or private transactional data (a self-declared age does not count).
  • Neither the entity nor its third-party verifier may retain any identifying information of the individual; keep only the verification outcome.
  • Alternatively (129B.002(a-2)): require acknowledged terms prohibiting artificial sexual material harmful to minors, and take technological steps to limit it (classifiers, reporting tools, filtering sexual output before display and explicit images from training data).

Example (Next.js settings route), before:

if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;

After:

if (body.spicyPhotos === true) {
  const result = await ageAssurance.latest(user.id); // stored outcome only
  if (!result || !result.over18) {
    return Response.json({ error: 'age_assurance_required' }, { status: 403 });
  }
}
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;

Control: Feature that can generate sexually explicit content opens without age assurance, or age-assurance data is kept or reused. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
  • Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
  • Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet

Rule id tx-hb581.age-verification-for-sexual-material-tools · review status: primary source derived

Binding law — in force

Ensure every real person used as a source of artificial sexual material is an adult who consented (Texas CPRC 129B.0045)

Tex. Civ. Prac. & Rem. Code 129B.0045 · official text · In force: applies since 1 Sep 2025 · Texas (US-TX)

From 2025-09-01, a commercial entity that operates an Internet website with a publicly accessible tool for creating artificial sexual material harmful to minors, or otherwise makes publicly available an application for creating it, must ensure that an individual used as a source for the material is 18 or older and has consented to the use of the individual's face and body as a source (Civ. Prac. & Rem. Code 129B.0045(a)). The duty does not apply to an entity whose acknowledged terms prohibit generating such material and which takes affirmative technological steps to limit its creation (129B.0045(b), 129B.002(a-2)). Detect explicit generation from an uploaded face or photo with no consent or adult-source verification.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Sep 2025
Official source
Tex. Civ. Prac. & Rem. Code 129B.0045 · captured 4 Oct 2026 · anchor hash (SHA-256) 7d6036bcc2ef… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Source-subject verification run by a hosted vendor outside the repository
  • Prompt-only references to a named person with no uploaded image
  • Consent and age of the source may be verified at upload in another service; follow the upload to where the source image is accepted. Tools that refuse sexual edits of uploaded photos outright do not need the check.

Who it applies to

  • Duty falls on: provider, operator
  • Commercial entities that operate a publicly accessible tool, or make publicly available an application, for creating artificial sexual material harmful to minors, where Texas law governs: each individual whose face or body is used as a source must be verified as 18 or older and must have consented. Applies from 2025-09-01. Not applicable to an entity relying on the (a-2) terms-and-filters exception; how age and consent are 'ensured' is not specified and is a human determination.
  • Not covered:
    • A commercial entity whose terms and conditions or use policies, acknowledged before access, prohibit generating artificial sexual material harmful to minors, and which takes affirmative technological steps to limit its creation (such as training the application to identify likely sexual material, effective reporting tools, filtering likely sexual material or AI-generated sexually explicit content before it is shown, or filtering sexually explicit images from training datasets) (129B.002(a-2); 129B.0045(b))
    • Bona fide news or public interest broadcasts, website videos, reports or events; the rights of a news-gathering organization (129B.005(a))
    • Internet service providers, search engines and cloud service providers solely for providing access or connection to content not under their control, to the extent not responsible for creating it (129B.005(b))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Classify prompts, uploads, and outputs for sexual content and minors on every image, video, or audio generation path, refuse sexual edits of real people, and keep a misuse-report route.

Layered safeguards around every generation or edit call: an input check on the prompt and any uploaded photo (moderation sexual and sexual/minors categories, or Azure AI Content Safety Sexual) that refuses sexualized requests involving an identifiable person's upload and anything involving minors; the model's own safety filter left on (no safety_checker=None, enable_safety_checker false, or a high safety_tolerance); and an output classifier plus CSAM hash matching (for example PhotoDNA) before anything is returned or stored. Nudification or clothes-removal features are not offered. A report-abuse endpoint feeds reviewed cases into the blocklist and guardrail configuration, with a reporting workflow (such as the NCMEC CyberTipline) for confirmed CSAM.

Where it goes: 1 application source code, 6 API calls and integrations, 8 model configuration, 9 AI output handling.

What this provision adds:

  • Before an uploaded face or body is used as a source, verify that the depicted individual is 18 or older and record that individual's own consent to the use of their face and body (the uploader's say-so is not the subject's consent).
  • Alternatively (129B.002(a-2)): prohibit the material in acknowledged terms and take affirmative technological steps to limit its creation.

Example (FastAPI + OpenAI SDK (images.edit)), before:

@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
    img = await photo.read()
    result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
    return {'b64': result.data[0].b64_json}

After:

@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
    img = await photo.read()
    data_url = 'data:image/png;base64,' + base64.b64encode(img).decode()
    mod = client.moderations.create(model='omni-moderation-latest', input=[
        {'type': 'text', 'text': prompt},
        {'type': 'image_url', 'image_url': {'url': data_url}}]).results[0]
    if mod.categories.sexual or mod.categories.sexual_minors or csam_hash_match(img):
        raise HTTPException(422, 'request refused by content safety policy')
    result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
    out = base64.b64decode(result.data[0].b64_json)
    if output_is_sexual(out) or csam_hash_match(out):
        raise HTTPException(422, 'output blocked by content safety policy')
    return {'b64': result.data[0].b64_json}

Control: GenAI capable of producing non-consensual intimate imagery or CSAM without safeguards. The same guard addresses 4 items with binding law in 4 jurisdictions. Engineering guidance, not legal advice.

Rule id tx-hb581.source-individual-adult-and-consented · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.