Explore
Build plan: the guards that cover the most
Multi-jurisdiction AI law looks like dozens of checklists. It is mostly a short list of engineering controls. Choose your features and markets to rank them.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Ranked guards
131 guards address 322 items across 55 jurisdictions with binding law (in force in 51 of them): 166 binding law in force, 85 enacted but not yet applying, 46 standards and frameworks, 24 TwinEthos recommended guardrails, 1 optional safe harbor.
Profiling for significant-effects decisions with no opt-out
Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.
Addresses 1 item: 1 binding law in force
Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).
Solely-automated significant decision without human-intervention safeguards
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
Addresses 15 items: 14 binding law in force · 1 enacted, not yet applying
Law in force in AE-DU-DIFC, Brazil (BR), Quebec (CA-QC), CH, China (CN), European Union (EU), United Kingdom (GB), KE, KG, South Korea (KR), KZ, TR, UZ, ZA; enacted, not yet applying in CL; next date 2026-12-01.
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 29 items: 14 binding law in force · 10 enacted, not yet applying · 4 standards · 1 recommended guardrail
Law in force in AE-DU-DIFC, China (CN), European Union (EU), KG, South Korea (KR), KZ, California (US-CA), Hawaii (US-HI), Maine (US-ME), New York (US-NY), Texas (US-TX), Utah (US-UT), VN; enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 12 items: 6 binding law in force · 2 enacted, not yet applying · 3 standards · 1 recommended guardrail
Law in force in KG, KZ, PE, SV, Connecticut (US-CT), Minnesota (US-MN); enacted, not yet applying in European Union (EU), Colorado (US-CO); next date 2027-01-01.
Synthetic content not machine-readable-marked
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
Addresses 7 items: 5 binding law in force · 2 standards
Law in force in Australia (AU), China (CN), European Union (EU), Connecticut (US-CT), VN.
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 15 items: 4 binding law in force · 10 enacted, not yet applying · 1 recommended guardrail
Law in force in China (CN), California (US-CA), Hawaii (US-HI), New York (US-NY); enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
Face or voice biometric template computed without prior notice and consent
Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.
Addresses 4 items: 4 binding law in force
Law in force in European Union (EU), Illinois (US-IL), Texas (US-TX), Washington (US-WA).
AI experience ignores age signals it already has
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
Addresses 11 items: 4 binding law in force · 7 enacted, not yet applying
Law in force in China (CN), California (US-CA), Hawaii (US-HI); enacted, not yet applying in Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.
Consequential AI decision without consumer notice
Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.
Addresses 8 items: 3 binding law in force · 4 enacted, not yet applying · 1 standard
Law in force in IT, PE, Texas (US-TX); enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO), Connecticut (US-CT); next date 2027-01-01.
Data erasure does not reach embeddings, vector stores or AI chat history
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Addresses 4 items: 3 binding law in force · 1 enacted, not yet applying
Law in force in China (CN), European Union (EU), Washington (US-WA); enacted, not yet applying in Illinois (US-IL).
GenAI content lacking explicit and implicit labels
Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.
Addresses 4 items: 4 binding law in force
Law in force in China (CN), India (IN), KZ.
GenAI training data without lawful source / IP / consent controls
Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.
Addresses 4 items: 4 binding law in force
Law in force in China (CN), IT, KZ.
Health AI without clinician oversight/accountability + redress
Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.
Addresses 4 items: 3 binding law in force · 1 standard
Law in force in IT, Illinois (US-IL), Texas (US-TX).
Protected or proxy attribute reaches AI decision
Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.
Addresses 4 items: 3 binding law in force · 1 standard
Law in force in Colorado (US-CO), Illinois (US-IL), Texas (US-TX).
Biometric categorisation of sensitive traits
Remove any model, prompt, or label set that infers race, political opinion, union membership, religion or beliefs, sex life, or sexual orientation from biometric data.
Addresses 3 items: 3 binding law in force
Law in force in European Union (EU), KZ, PE.
Deepfake content not disclosed
Attach a visible 'AI-generated or manipulated' disclosure to face-swapped, voice-cloned, or likeness-generated media on every path that publishes or returns it.
Addresses 3 items: 3 binding law in force
Law in force in European Union (EU), KG, VN.
High-impact AI without risk management, explanations, and human oversight
Put human supervision and a per-decision explanation record between high-impact model output and the action it triggers, backed by a documented risk-management plan.
Addresses 3 items: 3 binding law in force
Law in force in South Korea (KR), PE, VN.
User content used for model training without purpose-limited consent
Prefer checking a training-specific, unwithdrawn consent record before user content enters any training, fine-tuning, or evaluation dataset, and record lineage per model.
Addresses 3 items: 3 binding law in force
Law in force in China (CN), Singapore (SG), Washington (US-WA).
AI conversation designed to maximize time spent or discourage leaving
Remove retention and guilt tactics from AI prompts and personas, and do not select or train AI variants on session length without wellbeing guardrails that can veto them.
Addresses 9 items: 4 binding law in force · 5 enacted, not yet applying
Law in force in China (CN), Hawaii (US-HI); enacted, not yet applying in California (US-CA), Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.
Companion or conversational AI account without user or parental controls for privacy, settings and screen time
Give account holders, and parents of minor account holders, controls for privacy, account settings, notifications, engagement features and screen time.
Addresses 7 items: 2 binding law in force · 5 enacted, not yet applying
Law in force in China (CN), Hawaii (US-HI); enacted, not yet applying in California (US-CA), Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9. Without a choice, the plan covers every rule (ethical-use guardrails excluded). The full ranked list is on Controls. Each guard links to its control page: every provision it addresses with the exact citation and official text, the dates, the standards that agree, one before/after example, and a trust panel. A guard addresses items; it is engineering guidance, not legal advice, and applicability still decides which items reach your system. The same plan is available to coding agents through the MCP tool build_plan.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.