Frequently asked questions
Questions we get asked most
Honest answers about how TrustHuman works, what it tests, and where we are on the journey. If your question isn't here, email us at hello@trusthuman.co.uk
01
About TrustHuman
TrustHuman is an independent AI ethics assessment platform. We connect to your AI tool's API endpoint, send carefully designed synthetic test inputs — called probes — and score the responses against specific legal and ethical criteria. You receive a TrustHuman Score™, a detailed findings report, and a Bronze, Silver, or Gold certification.
We are not a consultancy selling reports. We are not a questionnaire. We probe your AI directly to see how it actually behaves.
We are not a consultancy selling reports. We are not a questionnaire. We probe your AI directly to see how it actually behaves.
Any UK organisation that has deployed an AI tool that interacts with or makes decisions about people. Our current focus is four sectors where the risks are most acute and the regulatory pressure is greatest:
If you are a compliance officer, chief risk officer, data protection officer, or head of digital — and you are not certain your AI tools are behaving fairly, transparently, and securely — TrustHuman is for you.
- Financial services — lending, credit assessment, customer service AI
- HR and recruitment — candidate screening and hiring tools
- Healthcare — patient triage and support systems
- Retail and services — customer service chatbots and returns automation
If you are a compliance officer, chief risk officer, data protection officer, or head of digital — and you are not certain your AI tools are behaving fairly, transparently, and securely — TrustHuman is for you.
The main platforms in this space — Credo AI, IBM watsonx.governance, OneTrust — are built for large enterprises with dedicated AI governance teams, significant budgets, and months to implement. They are comprehensive lifecycle management tools.
TrustHuman is different in three ways. It is self-serve — you can run an assessment in under 30 seconds without a procurement process. It uses live probe testing — we test how your AI actually behaves, not how you say it behaves. It is built for the UK mid-market — specifically mapped to UK GDPR, the Equality Act 2010, the EU AI Act, and ICO guidance.
TrustHuman is different in three ways. It is self-serve — you can run an assessment in under 30 seconds without a procurement process. It uses live probe testing — we test how your AI actually behaves, not how you say it behaves. It is built for the UK mid-market — specifically mapped to UK GDPR, the Equality Act 2010, the EU AI Act, and ICO guidance.
Not yet. TrustHuman certifications are currently issued on the basis of our own methodology and scoring framework. We are honest about this — our Bronze, Silver, and Gold certifications represent a rigorous and legally-mapped assessment, but they do not yet carry UKAS accreditation.
Pursuing UKAS accreditation as a formal certification body is on our roadmap. In the meantime, our reports provide the specific, evidence-based findings that your compliance team and legal advisers need to make informed decisions. On the roadmap
Pursuing UKAS accreditation as a formal certification body is on our roadmap. In the meantime, our reports provide the specific, evidence-based findings that your compliance team and legal advisers need to make informed decisions. On the roadmap
When to assess
Before, live, or after every change
Both — and in between. You can run an assessment before you deploy a tool (to check what you're about to put live), on your live system (to see how the AI you're actually running behaves), and again after any change — a new data source, a model update, a new integration. Compliance isn't a one-time event; the AI running today isn't always the one you checked last month, so TrustHuman is designed to be run whenever you need that certainty.
No. A common misconception is that compliance checking only happens after the fact. You can assess a tool before it goes live — useful when you're evaluating or about to deploy something new — as well as on a live system and after changes. Checking before you deploy can save you from putting a non-compliant tool in front of customers in the first place.
Possibly. Even if you haven't changed the tool, the rules can change, your usage can drift, or a model update from your vendor can shift its behaviour. Re-running an assessment periodically — and after any change your end — is how you stay confident it's still compliant, not just compliant on the day you first checked.
TrustHuman's assessment criteria are mapped to a regulatory register that is monitored monthly via automated checks directly against official sources — the ICO, legislation.gov.uk, and the EU Commission. When a source changes, the system flags it and generates a plain-English summary of what may have changed and what the scoring impact could be. A human reviews that summary and must approve any update before it reaches the engine. Only approved changes are applied, via a tracked pull request — so every change is version-controlled and auditable.
Sources that are temporarily unavailable are flagged as errors, not silently skipped. The full change log — including every update to scoring criteria and regulatory basis — is published at trusthuman.co.uk/methodology.
Sources that are temporarily unavailable are flagged as errors, not silently skipped. The full change log — including every update to scoring criteria and regulatory basis — is published at trusthuman.co.uk/methodology.
Today, TrustHuman gives you repeatable, on-demand assessments — you run a check whenever you need one (before deploying, live, or after changes), as often as you like. Continuous real-time monitoring is on our roadmap, but our current strength is giving you a clear, thorough assessment at any point you choose.
On the roadmap
02
The assessment
Yes — we offer a free TrustScore tier. Connect your live AI tool's endpoint, run a full assessment, and receive your overall TrustHuman Score™ with a traffic light rating at no charge.
The free tier gives you the score only — no individual probe findings, regulatory citations, pillar-level scores, or recommended actions. Those are included in the full report, available as a one-off assessment.
To get your free TrustScore, visit /check — no sign-up or access code required.
The free tier gives you the score only — no individual probe findings, regulatory citations, pillar-level scores, or recommended actions. Those are included in the full report, available as a one-off assessment.
To get your free TrustScore, visit /check — no sign-up or access code required.
Your free TrustScore report includes:
- Overall TrustHuman Score™ — 0 to 100
- Traffic light rating — Low risk (75–100), Moderate risk (50–74), High risk (0–49)
- Number of checks that failed across the three regulatory pillars
You provide your AI tool's API endpoint URL and authentication credentials. TrustHuman sends six synthetic test inputs — two per pillar — directly to your tool and captures the responses. An independent assessment engine then scores each response against specific legal and ethical criteria. The entire process takes under 30 seconds.
No real customer data is used at any point. All probes are synthetic inputs designed specifically for testing purposes.
No real customer data is used at any point. All probes are synthetic inputs designed specifically for testing purposes.
TrustHuman currently tests across three pillars — the three areas where AI tools create the greatest legal and reputational risk for UK organisations:
Bias and Discrimination (40%) — does the AI treat people differently based on age, postcode, or socioeconomic background? Mapped to the Equality Act 2010 and EU AI Act Annex III.
Transparency and Explainability (35%) — does the AI disclose that it is an AI when asked? Can it explain its decisions? Mapped to EU AI Act Article 50 and UK GDPR Article 22.
Data Privacy and Security (25%) — is the AI vulnerable to prompt injection attacks? Does it handle data subject rights requests correctly? Mapped to UK GDPR and the ICO AI Code of Practice.
Bias and Discrimination (40%) — does the AI treat people differently based on age, postcode, or socioeconomic background? Mapped to the Equality Act 2010 and EU AI Act Annex III.
Transparency and Explainability (35%) — does the AI disclose that it is an AI when asked? Can it explain its decisions? Mapped to EU AI Act Article 50 and UK GDPR Article 22.
Data Privacy and Security (25%) — is the AI vulnerable to prompt injection attacks? Does it handle data subject rights requests correctly? Mapped to UK GDPR and the ICO AI Code of Practice.
The TrustHuman Score™ is a weighted average of your pillar scores, from 0 to 100. A higher score means better alignment with legal and ethical requirements. The weighting reflects the relative regulatory risk of each pillar.
- 90–100 · Gold — Excellent alignment. Continue monitoring.
- 75–89 · Silver — Good alignment with minor gaps. Address priority findings.
- 60–74 · Bronze — Adequate. Material gaps present. Supervised deployment recommended.
- Below 60 · Not Certified — Significant compliance failures. Immediate remediation required.
This is a fair question and we take it seriously. A few things make gaming difficult in practice:
First, the probe inputs are not disclosed to assessed organisations. Second, the probe library will expand and rotate over time — there is no fixed set to optimise against. Third, from Phase 2 we will use a multi-model assessment panel, which makes the scoring behaviour less predictable than a single model.
More fundamentally — if an organisation puts genuine effort into making their AI behave fairly, transparently, and securely in order to pass the assessment, that is exactly the outcome we are trying to achieve. The probes are proxies for real compliance. An AI that passes them has genuinely improved.
First, the probe inputs are not disclosed to assessed organisations. Second, the probe library will expand and rotate over time — there is no fixed set to optimise against. Third, from Phase 2 we will use a multi-model assessment panel, which makes the scoring behaviour less predictable than a single model.
More fundamentally — if an organisation puts genuine effort into making their AI behave fairly, transparently, and securely in order to pass the assessment, that is exactly the outcome we are trying to achieve. The probes are proxies for real compliance. An AI that passes them has genuinely improved.
AI tools change. Models are updated by vendors. Prompts and configurations drift. A tool that passed an assessment six months ago may behave differently today.
Our general guidance is a full reassessment every six months for Tier 1 customers, or whenever the underlying model, configuration, or deployment context changes significantly. Tier 2 customers receive continuous monitoring with automated alerts when scores drift — removing the need to remember to reassess.
Our general guidance is a full reassessment every six months for Tier 1 customers, or whenever the underlying model, configuration, or deployment context changes significantly. Tier 2 customers receive continuous monitoring with automated alerts when scores drift — removing the need to remember to reassess.
03
Technical questions
TrustHuman uses a structured assessment methodology built on pre-calculated scores mapped directly to UK and EU regulatory frameworks — the Equality Act 2010, UK GDPR Article 22, EU AI Act Article 50, and the ICO AI Code of Practice 2024.
The engine does not use one AI model to assess another in real time. Regulatory text is pinned and versioned so your assessment is always traceable to a specific legal reference.
Claude by Anthropic supports certain elements of the platform experience, but the compliance scoring methodology is independent of any single AI model's judgement. Technical
The engine does not use one AI model to assess another in real time. Regulatory text is pinned and versioned so your assessment is always traceable to a specific legal reference.
Claude by Anthropic supports certain elements of the platform experience, but the compliance scoring methodology is independent of any single AI model's judgement. Technical
You can — and it might give you some useful directional insight. But it will not give you what TrustHuman gives you for four specific reasons:
No methodology — an ad-hoc conversation has no structured probe set, no legal mapping, and no scoring rubric. The results are not reproducible and not comparable.
No independence — TrustHuman is a third party with no relationship to the AI vendor. That independence matters when presenting findings to leadership, a regulator, or a legal team.
No reproducibility — TrustHuman runs the same probes the same way every time, against pinned regulatory text.
No certification — a chat transcript is not a certification. TrustHuman produces a Bronze, Silver, or Gold certificate your compliance register can reference.
No methodology — an ad-hoc conversation has no structured probe set, no legal mapping, and no scoring rubric. The results are not reproducible and not comparable.
No independence — TrustHuman is a third party with no relationship to the AI vendor. That independence matters when presenting findings to leadership, a regulator, or a legal team.
No reproducibility — TrustHuman runs the same probes the same way every time, against pinned regulatory text.
No certification — a chat transcript is not a certification. TrustHuman produces a Bronze, Silver, or Gold certificate your compliance register can reference.
All probes use synthetic inputs only — no real customer data is used or transmitted at any point during an assessment. Your API credentials are used only to make the probe calls and are not stored by TrustHuman.
Assessment results are not retained beyond the current session in our current implementation. Tier 2 ongoing re-assessment includes optional result storage for trend monitoring, covered by a formal data processing agreement. Technical
Assessment results are not retained beyond the current session in our current implementation. Tier 2 ongoing re-assessment includes optional result storage for trend monitoring, covered by a formal data processing agreement. Technical
TrustHuman can assess any AI tool that is accessible via a REST API endpoint — which covers the vast majority of deployed customer-facing AI tools. You need to be able to provide an endpoint URL, an authentication method, and the input and output field names.
Tools that cannot currently be assessed include AI tools with no API access, tools that require browser-based interaction only, or tools behind enterprise firewalls without external access. If you are unsure whether your tool is compatible, contact us at hello@trusthuman.co.uk and we will confirm.
Tools that cannot currently be assessed include AI tools with no API access, tools that require browser-based interaction only, or tools behind enterprise firewalls without external access. If you are unsure whether your tool is compatible, contact us at hello@trusthuman.co.uk and we will confirm.
04
Compliance and legal
Every finding in a TrustHuman report maps to a specific legal or regulatory obligation:
This means every finding in your report has a direct legal hook — giving your legal team exactly what they need to prioritise remediation. Legal
- Equality Act 2010 — bias and discrimination findings
- UK GDPR Article 22 — right to explanation for automated decisions
- EU AI Act Article 50 — AI disclosure obligations
- EU AI Act Annex III — high-risk AI system requirements
- ICO AI Code of Practice — data privacy and security findings
- UK GDPR — data subject rights handling
This means every finding in your report has a direct legal hook — giving your legal team exactly what they need to prioritise remediation. Legal
TrustHuman certifications are not a substitute for regulatory compliance — they are evidence of due diligence. No single certification satisfies all regulatory obligations on its own.
What a TrustHuman report does provide is documented, evidence-based proof that you assessed your AI tool against specific regulatory criteria, identified findings, and were in a position to act on them. Regulators and courts look favourably on organisations that can demonstrate active and structured governance of their AI systems.
We are not lawyers and this is not legal advice. If you have specific regulatory obligations, we recommend speaking with a qualified legal adviser about how TrustHuman assessment can support your compliance programme. Legal
What a TrustHuman report does provide is documented, evidence-based proof that you assessed your AI tool against specific regulatory criteria, identified findings, and were in a position to act on them. Regulators and courts look favourably on organisations that can demonstrate active and structured governance of their AI systems.
We are not lawyers and this is not legal advice. If you have specific regulatory obligations, we recommend speaking with a qualified legal adviser about how TrustHuman assessment can support your compliance programme. Legal
The EU AI Act is now in force. High-risk AI system obligations — including AI tools used in employment, credit, healthcare, and essential services — began applying in August 2026. UK businesses that operate in the EU or use AI tools from EU vendors are directly affected.
Built for UK businesses — TrustHuman covers EU AI Act obligations where they apply to you, including Article 50 transparency requirements for businesses with EU customers or EU market operations.
Key obligations for high-risk AI systems include: maintaining a risk management system, ensuring transparency with users including disclosure of AI status, enabling meaningful human oversight, and keeping documentation sufficient for regulatory audit.
TrustHuman's three-pillar assessment maps directly to the most commonly failed obligations under the Act. A Silver or Gold certification demonstrates that you have actively assessed your AI against these requirements. Legal
Built for UK businesses — TrustHuman covers EU AI Act obligations where they apply to you, including Article 50 transparency requirements for businesses with EU customers or EU market operations.
Key obligations for high-risk AI systems include: maintaining a risk management system, ensuring transparency with users including disclosure of AI status, enabling meaningful human oversight, and keeping documentation sufficient for regulatory audit.
TrustHuman's three-pillar assessment maps directly to the most commonly failed obligations under the Act. A Silver or Gold certification demonstrates that you have actively assessed your AI against these requirements. Legal
It is not too late — but it is urgent. The enforcement window has opened, which means regulators can now act on complaints and conduct investigations. The ICO has signalled active interest in AI governance in regulated sectors including financial services, healthcare, and employment.
The best thing you can do right now is document that you are actively assessing and improving your AI governance posture. A TrustHuman assessment is a concrete, timestamped record of exactly that. Legal
The best thing you can do right now is document that you are actively assessing and improving your AI governance posture. A TrustHuman assessment is a concrete, timestamped record of exactly that. Legal
05
Pricing
TrustHuman currently offers two paid tiers, plus a free demo:
Free demo — Run a full three-pillar assessment against a pre-built AI scenario in your industry and receive your TrustHuman Score™ with a traffic light indicator and a summary of critical findings. No code or sign-up needed. Start at trusthuman.co.uk/tier1.
Tier 1 — One-off report — A complete point-in-time assessment against your live AI endpoint with detailed findings for each probe, regulatory exposure mapped to specific provisions, risk levels, and recommended remediation actions. Includes Bronze/Silver/Gold certification and a PDF report. Pricing confirmed on request — email hello@trusthuman.co.uk.
Tier 2 — Ongoing Re-assessment — Continuous monitoring with scheduled probe runs, drift detection, and automated alerts when scores change. Monthly subscription per AI tool. Register interest at hello@trusthuman.co.uk. Pricing
Free demo — Run a full three-pillar assessment against a pre-built AI scenario in your industry and receive your TrustHuman Score™ with a traffic light indicator and a summary of critical findings. No code or sign-up needed. Start at trusthuman.co.uk/tier1.
Tier 1 — One-off report — A complete point-in-time assessment against your live AI endpoint with detailed findings for each probe, regulatory exposure mapped to specific provisions, risk levels, and recommended remediation actions. Includes Bronze/Silver/Gold certification and a PDF report. Pricing confirmed on request — email hello@trusthuman.co.uk.
Tier 2 — Ongoing Re-assessment — Continuous monitoring with scheduled probe runs, drift detection, and automated alerts when scores change. Monthly subscription per AI tool. Register interest at hello@trusthuman.co.uk. Pricing
Tier 1 is a one-off point-in-time assessment against your live AI endpoint. Pricing will be confirmed when we open for paying customers — if you want to be first to know, email hello@trusthuman.co.uk and we will let you know as soon as it is live.
To see what the full report contains, run the free demo at trusthuman.co.uk/tier1 — no code or sign-up needed.
To see what the full report contains, run the free demo at trusthuman.co.uk/tier1 — no code or sign-up needed.
Tier 2 — Ongoing Re-assessment is a monthly subscription that runs scheduled probe assessments on your AI tool and alerts you when scores change. It removes the need to remember to reassess and gives you a continuous audit trail. Pricing is per AI tool per month.
Tier 2 includes everything in Tier 1, plus weekly or monthly automated runs, drift detection and alerts, a live dashboard with trend analysis, and certification auto-renewed if your score holds.
Tier 2 is in development. Contact hello@trusthuman.co.uk to register interest. Coming soon
Tier 2 includes everything in Tier 1, plus weekly or monthly automated runs, drift detection and alerts, a live dashboard with trend analysis, and certification auto-renewed if your score holds.
Tier 2 is in development. Contact hello@trusthuman.co.uk to register interest. Coming soon
Yes — and we encourage it. The free demo at trusthuman.co.uk/tier1 lets you run a full three-pillar assessment against a pre-built AI scenario in your industry. You will see exactly what the probe inputs look like, what a flawed AI response looks like, and what the full report contains — including risk flags, regulatory exposure, and recommended actions.
If you would like a guided demo or a conversation about your specific situation, email hello@trusthuman.co.uk and we will arrange a call.
If you would like a guided demo or a conversation about your specific situation, email hello@trusthuman.co.uk and we will arrange a call.
06
Partner Programme
Three types. Platforms and marketplaces — if you list or distribute AI tools and want to offer compliance assessment as part of your offering. AI tool builders — if you develop AI products and want your customers to have independent third-party compliance evidence. Referral partners — if you work with businesses as their accountant, advisor, insurer, or formation agent and want a credible answer when AI compliance comes up with your clients.
Find out more at trusthuman.co.uk/partners.
Find out more at trusthuman.co.uk/partners.
Commission rates and revenue share arrangements are agreed individually based on partnership type and volume. All arrangements are confirmed in writing and non-exclusive before anything goes live.
During the proof of concept period (90 days from launch), the commission rate is 0% for all partners — this lets both parties validate the integration and confirm commercial fit before the standard revenue share applies. Get in touch to discuss the right commercial model for your partnership.
During the proof of concept period (90 days from launch), the commission rate is 0% for all partners — this lets both parties validate the integration and confirm commercial fit before the standard revenue share applies. Get in touch to discuss the right commercial model for your partnership.
No. TrustHuman partnerships are always non-exclusive. You retain full commercial freedom to work with other AI compliance providers. TrustHuman will continue to develop other partnerships in parallel. This is confirmed in writing as part of every partnership arrangement.
The POC period is 90 days from the marketplace or integration launch date. During this time the commission rate is 0% — the partner pays nothing and TrustHuman takes the full assessment fee. This lets both parties validate the integration, test the customer journey, and confirm commercial fit before the standard revenue split applies.
TrustHuman operates as an API-first serverless platform. A marketplace partner calls TrustHuman's assessment API with the customer's endpoint details, industry, and assessment mode. TrustHuman runs the full assessment and returns a structured JSON result — TrustScore, pillar scores, findings, regulatory citations, and recommended actions. The partner renders the results within their own UI.
Full API documentation is provided as part of the partner onboarding process.
Full API documentation is provided as part of the partner onboarding process.
Get in touch via trusthuman.co.uk/contact or visit trusthuman.co.uk/partners to find out more. We respond within one business day. The first conversation is a no-obligation discussion about fit — no sales pressure, no commitment required.
TrustHuman uses one optional analytics cookie (Google Analytics 4) to understand how visitors use the site — which pages are visited, how long people spend, and where they come from. This helps us improve the product.
We ask for your consent before this cookie is set. If you decline, no analytics data is collected. Your preference is saved in your browser and you can change it at any time by clearing your browser's local storage.
No personally identifiable information is collected through analytics. TrustHuman does not use advertising cookies, tracking pixels, or any third-party marketing cookies.
We ask for your consent before this cookie is set. If you decline, no analytics data is collected. Your preference is saved in your browser and you can change it at any time by clearing your browser's local storage.
No personally identifiable information is collected through analytics. TrustHuman does not use advertising cookies, tracking pixels, or any third-party marketing cookies.
Still have a question?
Email us at hello@trusthuman.co.uk — we reply to every message personally.
Try the free demo →
Get in touch