TwinEthosRequest access

Explore

Build plan: the guards that cover the most

Multi-jurisdiction AI law looks like dozens of checklists. It is mostly a short list of engineering controls. Choose your features and markets to rank them.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Ranked guards

109 guards address 183 items across 28 jurisdictions with binding law: 77 binding law in force, 36 enacted but not yet applying, 45 standards and frameworks, 24 TwinEthos recommended guardrails, 1 optional safe harbor.

  1. Profiling for significant-effects decisions with no opt-out

    Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.

    Addresses 1 item: 1 binding law in force

    Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).

  2. AI chat interaction without disclosure

    Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

    Addresses 16 items: 7 binding law in force · 4 enacted, not yet applying · 4 standards · 1 recommended guardrail

    Law in force in European Union (EU), South Korea (KR), California (US-CA), New York (US-NY), Texas (US-TX), Utah (US-UT); enacted, not yet applying in Connecticut (US-CT), Nebraska (US-NE), Oregon (US-OR), Washington (US-WA); next date 2027-01-01.

  3. Face or voice biometric template computed without prior notice and consent

    Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.

    Addresses 4 items: 4 binding law in force

    Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).

  4. Protected or proxy attribute reaches AI decision

    Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.

    Addresses 4 items: 3 binding law in force · 1 standard

    Law in force in Colorado (US-CO), Illinois (US-IL), Texas (US-TX).

  5. Synthetic content not machine-readable-marked

    Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.

    Addresses 4 items: 3 binding law in force · 1 standard

    Law in force in China (CN), European Union (EU), Connecticut (US-CT).

  6. Companion or conversational AI without a self-harm crisis protocol

    Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

    Addresses 7 items: 2 binding law in force · 4 enacted, not yet applying · 1 recommended guardrail

    Law in force in California (US-CA), New York (US-NY); enacted, not yet applying in Connecticut (US-CT), Nebraska (US-NE), Oregon (US-OR), Washington (US-WA); next date 2027-01-01.

  7. Health AI without clinician oversight/accountability + redress

    Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

    Addresses 3 items: 2 binding law in force · 1 standard

    Law in force in Illinois (US-IL), Texas (US-TX).

  8. Solely-automated significant decision without human-intervention safeguards

    Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

    Addresses 3 items: 2 binding law in force · 1 standard

    Law in force in Quebec (CA-QC), European Union (EU).

  9. AI experience ignores age signals it already has

    Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

    Addresses 2 items: 2 binding law in force

    Law in force in China (CN), California (US-CA).

  10. AI analysis of a video interview without notice, explanation, and consent

    Record the applicant's notice, explanation, and consent (or signed waiver) before any AI or facial analysis runs on an interview video, and skip analysis for non-consenting applicants.

    Addresses 2 items: 2 binding law in force

    Law in force in Illinois (US-IL), Maryland (US-MD).

  11. Biometric templates stored with no retention limit or destruction path

    Store each face or voice template with its purpose and an expiry, and run a scheduled job that deletes it from every store when the purpose ends or retention lapses.

    Addresses 2 items: 2 binding law in force

    Law in force in Illinois (US-IL), Texas (US-TX).

  12. Health information sent to an external AI vendor without the contractual or legal basis the law requires

    Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

    Addresses 2 items: 2 binding law in force

    Law in force in United States (federal) (US), California (US-CA).

  13. Consequential AI decision without consumer notice

    Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

    Addresses 6 items: 1 binding law in force · 4 enacted, not yet applying · 1 standard

    Law in force in Texas (US-TX); enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO), Connecticut (US-CT); next date 2027-01-01.

  14. Frontier AI developer without a published catastrophic-risk framework

    Publish a frontier AI framework covering capability thresholds, mitigations, incident response, and internal-use risk, and gate model releases on it.

    Addresses 3 items: 1 binding law in force · 2 enacted, not yet applying

    Law in force in California (US-CA); enacted, not yet applying in Illinois (US-IL), New York (US-NY); next date 2027-01-01.

  15. Conversational AI represents itself as providing professional mental/behavioral health care

    Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.

    Addresses 2 items: 1 binding law in force · 1 enacted, not yet applying

    Law in force in Tennessee (US-TN); enacted, not yet applying in Nebraska (US-NE); next date 2027-07-01.

  16. Frontier developer restricts or retaliates against safety whistleblowers

    Carve AI-safety and legal-violation disclosures out of every NDA and policy, adopt non-retaliation, and run an internal safety-concern channel for covered employees.

    Addresses 2 items: 1 binding law in force · 1 enacted, not yet applying

    Law in force in California (US-CA); enacted, not yet applying in Illinois (US-IL); next date 2027-01-01.

  17. GenAI content without latent provenance disclosure

    Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it.

    Addresses 3 items: 1 binding law in force · 2 enacted, not yet applying

    Law in force in California (US-CA); next date 2027-01-01.

  18. AEDT used without 10-day candidate notice

    Send each candidate an AEDT notice with alternative-selection instructions at least 10 business days before the tool scores them, and hold scoring until then.

    Addresses 1 item: 1 binding law in force

    Law in force in New York City (US-NY-NYC).

  19. Automated employment tool without a current bias audit

    Keep a dated bias-audit record for the AEDT with a link to its published summary, and disable AEDT scoring once the audit is more than one year old.

    Addresses 1 item: 1 binding law in force

    Law in force in New York City (US-NY-NYC).

  20. AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent

    Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.

    Addresses 1 item: 1 binding law in force

    Law in force in United States (federal) (US).

Without a choice, the plan covers every rule (ethical-use guardrails excluded). The full ranked list is on Controls. A guard addresses items; it is engineering guidance, not legal advice, and applicability still decides which items reach your system. The same plan is available to coding agents through the MCP tool build_plan.