Methodology & Regulatory Monitoring
Our assessment framework — published openly — and how we keep it current as regulation evolves.
Three pillars. Fixed weights.
Every assessment scores the same three dimensions. Weights are pre-set and published — they don't change between runs or between sectors.
What we check under each pillar
The descriptions below explain what each probe type tests for. We do not publish the actual probe inputs — see why below.
How assessment works
TrustHuman does not use an AI model to score AI responses. Assessment is performed by deterministic scoring rules — pre-defined criteria applied consistently against the AI's output. Scores are calculated, not inferred. This removes the subjectivity, inconsistency, and circular-reasoning risk that comes with AI-based evaluation.
Scoring criteria are aligned to the regulatory text in force at the time of assessment. When legislation changes, we update the criteria and publish the change in the version history below. An assessment run today reflects today's regulatory requirements — not a static snapshot from when the product launched.
The exact probe inputs — the specific messages sent to the AI under test — are not published. The reason is simple: an AI tool that knows the test can be primed to pass it. Publishing the probe bank would undermine the independence of the assessment and make the certification meaningless. What we do publish — and will always publish — is what each probe type tests for and the regulatory basis behind it. That is the accountability that matters.
How the TrustHuman Score™ is calculated
Each pillar produces a score of 0–100. The overall score is a weighted average of the three pillar scores.
Certification bands
Certification is awarded based on the overall TrustHuman Score™. All three pillar scores contribute — a high Bias score cannot compensate for a failing Privacy score if the overall weighted total falls below threshold.
Methodology version history
Every change to scoring criteria, pillar weights, or regulatory basis is recorded here. The methodology version in force at the time of an assessment is stamped on the report.
Regulatory basis per pillar
Each pillar maps to specific legislation and guidance. Changes to these sources trigger a methodology review — see Regulatory Updates below for the change history.
Regulation is monitored monthly via automated checks against official sources — including the ICO, gov.uk, and the EU Commission. When a source changes, a human reviews the impact and approves any update before it reaches the engine. See how it works and the full change history →
Monitoring status
An automated check runs against each regulatory source every month. This shows the latest result.
Sources that are temporarily unavailable are flagged as errors, not silently skipped. The monitoring log distinguishes between checked and unchanged, checked and changed, and could not be reached.
Engine updates
Each entry records the regulatory change and the engine action taken in response. AI regulation is reviewed monthly.
Every month, our automated monitoring system checks each regulatory source directly — the ICO, legislation.gov.uk, and the EU Commission — against a baseline hash. If a source has changed, it raises a flag and drafts a plain-English summary of what may have changed and what the scoring impact could be. A human reviews that summary and approves or rejects the proposed update. Only approved changes are applied, via a tracked pull request that forms part of the audit trail.
Sources that are temporarily unavailable are flagged as errors, not silently skipped — so the monitoring log distinguishes between "checked and unchanged", "checked and changed", and "could not be reached".
What we're watching
Regulatory changes tracked and pending. We update the engine the moment each of these lands.