Explore
Build plan: the guards that cover the most
Multi-jurisdiction AI law looks like dozens of checklists. It is mostly a short list of engineering controls. Choose your features and markets to rank them.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Ranked guards
135 guards address 363 items across 59 jurisdictions with binding law (in force in 56 of them): 204 binding law in force, 87 enacted but not yet applying, 46 standards and frameworks, 24 TwinEthos recommended guardrails, 2 optional safe harbors.
Profiling for significant-effects decisions with no opt-out
Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.
Addresses 1 item: 1 binding law in force
Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).
Solely-automated significant decision without human-intervention safeguards
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
Addresses 15 items: 14 binding law in force · 1 enacted, not yet applying
Law in force in AE-DU-DIFC, Brazil (BR), Quebec (CA-QC), CH, China (CN), European Union (EU), United Kingdom (GB), KE, KG, South Korea (KR), KZ, TR, UZ, ZA; enacted, not yet applying in CL; next date 2026-12-01.
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 29 items: 14 binding law in force · 10 enacted, not yet applying · 4 standards · 1 recommended guardrail
Law in force in AE-DU-DIFC, China (CN), European Union (EU), KG, South Korea (KR), KZ, California (US-CA), Hawaii (US-HI), Maine (US-ME), New York (US-NY), Texas (US-TX), Utah (US-UT), VN; enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
Addresses 9 items: 7 binding law in force · 2 enacted, not yet applying
Law in force in Alabama (US-AL), California (US-CA), Iowa (US-IA), Illinois (US-IL), Maryland (US-MD), Nebraska (US-NE), Texas (US-TX); enacted, not yet applying in Georgia (US-GA); next date 2027-01-01.
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 8 items: 8 binding law in force
Law in force in United States (federal) (US), Alabama (US-AL), California (US-CA), Maryland (US-MD), Maine (US-ME), Nevada (US-NV), Vermont (US-VT).
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 12 items: 6 binding law in force · 2 enacted, not yet applying · 3 standards · 1 recommended guardrail
Law in force in KG, KZ, PE, SV, Connecticut (US-CT), Minnesota (US-MN); enacted, not yet applying in European Union (EU), Colorado (US-CO); next date 2027-01-01.
Health AI without clinician oversight/accountability + redress
Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.
Addresses 9 items: 7 binding law in force · 1 standard · 1 optional safe harbor
Law in force in IT, Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Texas (US-TX).
Synthetic content not machine-readable-marked
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
Addresses 7 items: 5 binding law in force · 2 standards
Law in force in Australia (AU), China (CN), European Union (EU), Connecticut (US-CT), VN.
AI delivers or is offered as therapy to the public without a licensed professional conducting it
Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.
Addresses 5 items: 5 binding law in force
Law in force in Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Vermont (US-VT).
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 15 items: 4 binding law in force · 10 enacted, not yet applying · 1 recommended guardrail
Law in force in China (CN), California (US-CA), Hawaii (US-HI), New York (US-NY); enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
AI decision system without regular accuracy/bias validation
Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.
Addresses 8 items: 4 binding law in force · 1 enacted, not yet applying · 3 standards
Law in force in IT, Alabama (US-AL), California (US-CA), Maryland (US-MD); enacted, not yet applying in European Union (EU); next date 2027-12-02.
Insurer AI decision system without a written AIS Program / consumer notice
Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.
Addresses 5 items: 4 binding law in force · 1 standard
Law in force in Alabama (US-AL), California (US-CA), Maryland (US-MD), Nebraska (US-NE).
Face or voice biometric template computed without prior notice and consent
Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.
Addresses 4 items: 4 binding law in force
Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).
AI experience ignores age signals it already has
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
Addresses 11 items: 4 binding law in force · 7 enacted, not yet applying
Law in force in China (CN), California (US-CA), Hawaii (US-HI); enacted, not yet applying in Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.
Consequential AI decision without consumer notice
Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.
Addresses 8 items: 3 binding law in force · 4 enacted, not yet applying · 1 standard
Law in force in IT, PE, Texas (US-TX); enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO), Connecticut (US-CT); next date 2027-01-01.
Conversational AI represents itself as providing professional mental/behavioral health care
Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.
Addresses 6 items: 3 binding law in force · 3 enacted, not yet applying
Law in force in Hawaii (US-HI), Nevada (US-NV), Tennessee (US-TN); enacted, not yet applying in Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE); next date 2027-07-01.
Data erasure does not reach embeddings, vector stores or AI chat history
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Addresses 4 items: 3 binding law in force · 1 enacted, not yet applying
Law in force in China (CN), European Union (EU), Washington (US-WA); enacted, not yet applying in Illinois (US-IL).
High-risk AI system without automatic event logging (traceability)
Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.
Addresses 4 items: 3 binding law in force · 1 enacted, not yet applying
Law in force in KG, Maryland (US-MD), VN; enacted, not yet applying in European Union (EU); next date 2027-12-02.
GenAI content lacking explicit and implicit labels
Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.
Addresses 4 items: 4 binding law in force
Law in force in China (CN), India (IN), KZ.
GenAI training data without lawful source / IP / consent controls
Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.
Addresses 4 items: 4 binding law in force
Law in force in China (CN), IT, KZ.
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9. Without a choice, the plan covers every rule (ethical-use guardrails excluded). The full ranked list is on Controls. Each guard links to its control page: every provision it addresses with the exact citation and official text, the dates, the standards that agree, one before/after example, and a trust panel. A guard addresses items; it is engineering guidance, not legal advice, and applicability still decides which items reach your system. The same plan is available to coding agents through the MCP tool build_plan.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.