TwinEthos homeAPI access

Explore

Build plan: the guards that cover the most

Multi-jurisdiction AI law looks like dozens of checklists. It is mostly a short list of engineering controls. Choose your features and markets to rank them.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Ranked guards

Plan for every AI feature and every market; TwinEthos recommended guardrails included, ethical-use guardrails excluded.

135 guards address 363 items across 59 jurisdictions with binding law (in force in 56 of them): 204 binding law in force, 87 enacted but not yet applying, 46 standards and frameworks, 24 TwinEthos recommended guardrails, 2 optional safe harbors.

  1. Profiling for significant-effects decisions with no opt-out

    Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.

    Addresses 1 item: 1 binding law in force

    Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).

  2. Solely-automated significant decision without human-intervention safeguards

    Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

    Addresses 15 items: 14 binding law in force · 1 enacted, not yet applying

    Law in force in AE-DU-DIFC, Brazil (BR), Quebec (CA-QC), CH, China (CN), European Union (EU), United Kingdom (GB), KE, KG, South Korea (KR), KZ, TR, UZ, ZA; enacted, not yet applying in CL; next date 2026-12-01.

  3. AI chat interaction without disclosure

    Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

    Addresses 29 items: 14 binding law in force · 10 enacted, not yet applying · 4 standards · 1 recommended guardrail

    Law in force in AE-DU-DIFC, China (CN), European Union (EU), KG, South Korea (KR), KZ, California (US-CA), Hawaii (US-HI), Maine (US-ME), New York (US-NY), Texas (US-TX), Utah (US-UT), VN; enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.

  4. AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding

    Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.

    Addresses 9 items: 7 binding law in force · 2 enacted, not yet applying

    Law in force in Alabama (US-AL), California (US-CA), Iowa (US-IA), Illinois (US-IL), Maryland (US-MD), Nebraska (US-NE), Texas (US-TX); enacted, not yet applying in Georgia (US-GA); next date 2027-01-01.

  5. Health information sent to an external AI vendor without the contractual or legal basis the law requires

    Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.

    Addresses 8 items: 8 binding law in force

    Law in force in United States (federal) (US), Alabama (US-AL), California (US-CA), Maryland (US-MD), Maine (US-ME), Nevada (US-NV), Vermont (US-VT).

  6. Adverse AI decision without explanation/appeal

    Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.

    Addresses 12 items: 6 binding law in force · 2 enacted, not yet applying · 3 standards · 1 recommended guardrail

    Law in force in KG, KZ, PE, SV, Connecticut (US-CT), Minnesota (US-MN); enacted, not yet applying in European Union (EU), Colorado (US-CO); next date 2027-01-01.

  7. Health AI without clinician oversight/accountability + redress

    Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

    Addresses 9 items: 7 binding law in force · 1 standard · 1 optional safe harbor

    Law in force in IT, Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Texas (US-TX).

  8. Synthetic content not machine-readable-marked

    Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.

    Addresses 7 items: 5 binding law in force · 2 standards

    Law in force in Australia (AU), China (CN), European Union (EU), Connecticut (US-CT), VN.

  9. AI delivers or is offered as therapy to the public without a licensed professional conducting it

    Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.

    Addresses 5 items: 5 binding law in force

    Law in force in Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Vermont (US-VT).

  10. Companion or conversational AI without a self-harm crisis protocol

    Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.

    Addresses 15 items: 4 binding law in force · 10 enacted, not yet applying · 1 recommended guardrail

    Law in force in China (CN), California (US-CA), Hawaii (US-HI), New York (US-NY); enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.

  11. AI decision system without regular accuracy/bias validation

    Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.

    Addresses 8 items: 4 binding law in force · 1 enacted, not yet applying · 3 standards

    Law in force in IT, Alabama (US-AL), California (US-CA), Maryland (US-MD); enacted, not yet applying in European Union (EU); next date 2027-12-02.

  12. Insurer AI decision system without a written AIS Program / consumer notice

    Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.

    Addresses 5 items: 4 binding law in force · 1 standard

    Law in force in Alabama (US-AL), California (US-CA), Maryland (US-MD), Nebraska (US-NE).

  13. Face or voice biometric template computed without prior notice and consent

    Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.

    Addresses 4 items: 4 binding law in force

    Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).

  14. AI experience ignores age signals it already has

    Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.

    Addresses 11 items: 4 binding law in force · 7 enacted, not yet applying

    Law in force in China (CN), California (US-CA), Hawaii (US-HI); enacted, not yet applying in Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.

  15. Consequential AI decision without consumer notice

    Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

    Addresses 8 items: 3 binding law in force · 4 enacted, not yet applying · 1 standard

    Law in force in IT, PE, Texas (US-TX); enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO), Connecticut (US-CT); next date 2027-01-01.

  16. Conversational AI represents itself as providing professional mental/behavioral health care

    Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.

    Addresses 6 items: 3 binding law in force · 3 enacted, not yet applying

    Law in force in Hawaii (US-HI), Nevada (US-NV), Tennessee (US-TN); enacted, not yet applying in Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE); next date 2027-07-01.

  17. Data erasure does not reach embeddings, vector stores or AI chat history

    Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.

    Addresses 4 items: 3 binding law in force · 1 enacted, not yet applying

    Law in force in China (CN), European Union (EU), Washington (US-WA); enacted, not yet applying in Illinois (US-IL).

  18. High-risk AI system without automatic event logging (traceability)

    Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.

    Addresses 4 items: 3 binding law in force · 1 enacted, not yet applying

    Law in force in KG, Maryland (US-MD), VN; enacted, not yet applying in European Union (EU); next date 2027-12-02.

  19. GenAI content lacking explicit and implicit labels

    Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.

    Addresses 4 items: 4 binding law in force

    Law in force in China (CN), India (IN), KZ.

  20. GenAI training data without lawful source / IP / consent controls

    Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.

    Addresses 4 items: 4 binding law in force

    Law in force in China (CN), IT, KZ.

Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9. Without a choice, the plan covers every rule (ethical-use guardrails excluded). The full ranked list is on Controls. Each guard links to its control page: every provision it addresses with the exact citation and official text, the dates, the standards that agree, one before/after example, and a trust panel. A guard addresses items; it is engineering guidance, not legal advice, and applicability still decides which items reach your system. The same plan is available to coding agents through the MCP tool build_plan.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.