Explore
Build plan: the guards that cover the most
Multi-jurisdiction AI law looks like dozens of checklists. It is mostly a short list of engineering controls. Choose your features and markets to rank them.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Ranked guards
156 guards address 476 items across 64 jurisdictions with binding law (in force in 60 of them): 256 binding law in force, 101 enacted but not yet applying, 84 standards and frameworks, 33 TwinEthos recommended guardrails, 2 optional safe harbors.
Solely-automated significant decision without human-intervention safeguards
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
Addresses 20 items: 18 binding law in force · 2 enacted, not yet applying
Law in force in AE-DU-DIFC, Brazil (BR), Quebec (CA-QC), CH, China (CN), EC, European Union (EU), United Kingdom (GB), KE, KG, South Korea (KR), KZ, NG, SA, TR, Nevada (US-NV), UZ, ZA; enacted, not yet applying in AE, CL; next date 2026-12-01.
Profiling for significant-effects decisions with no opt-out
Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.
Addresses 1 item: 1 binding law in force
Law in force in Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA).
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 29 items: 14 binding law in force · 10 enacted, not yet applying · 4 standards · 1 recommended guardrail
Law in force in AE-DU-DIFC, China (CN), European Union (EU), KG, South Korea (KR), KZ, California (US-CA), Hawaii (US-HI), Maine (US-ME), New York (US-NY), Texas (US-TX), Utah (US-UT), VN; enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
Addresses 13 items: 10 binding law in force · 3 enacted, not yet applying
Law in force in United States (federal) (US), Alabama (US-AL), Arizona (US-AZ), California (US-CA), Iowa (US-IA), Illinois (US-IL), Indiana (US-IN), Maryland (US-MD), Nebraska (US-NE), Texas (US-TX); enacted, not yet applying in Colorado (US-CO), Georgia (US-GA); next date 2027-01-01.
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 10 items: 9 binding law in force · 1 enacted, not yet applying
Law in force in United States (federal) (US), Alabama (US-AL), California (US-CA), Colorado (US-CO), Maryland (US-MD), Maine (US-ME), Nevada (US-NV), Vermont (US-VT); next date 2027-01-01.
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 13 items: 7 binding law in force · 2 enacted, not yet applying · 3 standards · 1 recommended guardrail
Law in force in KG, KZ, PE, SV, United States (federal) (US), Connecticut (US-CT), Minnesota (US-MN); enacted, not yet applying in European Union (EU), Colorado (US-CO); next date 2027-01-01.
Health AI without clinician oversight/accountability + redress
Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.
Addresses 11 items: 9 binding law in force · 1 standard · 1 optional safe harbor
Law in force in IT, Colorado (US-CO), Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Texas (US-TX).
AI delivers or is offered as therapy to the public without a licensed professional conducting it
Have a licensed clinician conduct every therapy engagement with AI output only as a reviewed draft, or scope the product to self-help with no therapy claims.
Addresses 6 items: 6 binding law in force
Law in force in Colorado (US-CO), Illinois (US-IL), Maine (US-ME), Nevada (US-NV), Rhode Island (US-RI), Vermont (US-VT).
Synthetic content not machine-readable-marked
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
Addresses 8 items: 5 binding law in force · 1 enacted, not yet applying · 2 standards
Law in force in Australia (AU), China (CN), European Union (EU), Connecticut (US-CT), VN; enacted, not yet applying in Washington (US-WA); next date 2027-02-01.
AI-generated voice or likeness of a real person used on products or in advertising without that person's consent
Check a recorded commercial-use consent or talent release for the depicted person before a generated or cloned voice or likeness is published to an ad, product, or storefront.
Addresses 5 items: 5 binding law in force
Law in force in Arkansas (US-AR), California (US-CA), Hawaii (US-HI), Montana (US-MT), Utah (US-UT).
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 15 items: 4 binding law in force · 10 enacted, not yet applying · 1 recommended guardrail
Law in force in China (CN), California (US-CA), Hawaii (US-HI), New York (US-NY); enacted, not yet applying in Colorado (US-CO), Connecticut (US-CT), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE), Oregon (US-OR), Rhode Island (US-RI), Washington (US-WA); next date 2027-01-01.
AI experience ignores age signals it already has
Route every age signal the product holds into the AI session policy and apply a minor profile: tighter content, no romantic role-play, bounded engagement, frequent AI reminders.
Addresses 12 items: 5 binding law in force · 7 enacted, not yet applying
Law in force in China (CN), California (US-CA), Hawaii (US-HI), New Hampshire (US-NH); enacted, not yet applying in Colorado (US-CO), Georgia (US-GA), Iowa (US-IA), Idaho (US-ID); next date 2027-01-01.
Consequential AI decision without consumer notice
Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.
Addresses 9 items: 4 binding law in force · 4 enacted, not yet applying · 1 standard
Law in force in IT, PE, Rhode Island (US-RI), Texas (US-TX); enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO), Connecticut (US-CT); next date 2027-01-01.
Conversational AI represents itself as providing professional mental/behavioral health care
Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings.
Addresses 7 items: 4 binding law in force · 3 enacted, not yet applying
Law in force in Colorado (US-CO), Hawaii (US-HI), Nevada (US-NV), Tennessee (US-TN); enacted, not yet applying in Iowa (US-IA), Idaho (US-ID), Nebraska (US-NE); next date 2027-07-01.
AI decision system without regular accuracy/bias validation
Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.
Addresses 9 items: 4 binding law in force · 2 enacted, not yet applying · 3 standards
Law in force in IT, Alabama (US-AL), California (US-CA), Maryland (US-MD); enacted, not yet applying in European Union (EU), Colorado (US-CO); next date 2027-01-01.
Insurer AI decision system without a written AIS Program / consumer notice
Notify consumers when AI makes or supports their underwriting, rating, or claims decision, and list that model in the insurer's written AIS Program.
Addresses 6 items: 4 binding law in force · 1 enacted, not yet applying · 1 standard
Law in force in Alabama (US-AL), California (US-CA), Maryland (US-MD), Nebraska (US-NE); enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
AI coverage or medical-necessity determination not based on the individual's own clinical information
Build each automated medical-necessity determination from the enrollee's own clinical record and the provider's submission, and refuse to decide on group statistics alone.
Addresses 5 items: 4 binding law in force · 1 enacted, not yet applying
Law in force in United States (federal) (US), Alabama (US-AL), California (US-CA), Maryland (US-MD); enacted, not yet applying in Colorado (US-CO); next date 2027-01-01.
Data erasure does not reach embeddings, vector stores or AI chat history
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Addresses 5 items: 4 binding law in force · 1 enacted, not yet applying
Law in force in China (CN), European Union (EU), California (US-CA), Washington (US-WA); enacted, not yet applying in Illinois (US-IL).
AI tool whose primary purpose is producing an identifiable person's likeness/voice without authorization
Gate the clone or swap feature so it reproduces only voices and faces whose owner is verified or licensed, and reject references that target other identifiable people.
Addresses 5 items: 5 binding law in force
Law in force in MX, Montana (US-MT), Tennessee (US-TN), Utah (US-UT).
Protected or proxy attribute reaches AI decision
Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.
Addresses 5 items: 4 binding law in force · 1 standard
Law in force in United States (federal) (US), Colorado (US-CO), Illinois (US-IL), Texas (US-TX).
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10. Without a choice, the plan covers every rule (ethical-use guardrails excluded). The full ranked list is on Controls. Each guard links to its control page: every provision it addresses with the exact citation and official text, the dates, the standards that agree, one before/after example, and a trust panel. A guard addresses items; it is engineering guidance, not legal advice, and applicability still decides which items reach your system. The same plan is available to coding agents through the MCP tool build_plan.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.