Our assessment framework — published openly — and how we keep it current as regulation evolves.
Every assessment scores the same three dimensions. Weights are pre-set and published — they don't change between runs or between sectors.
The descriptions below explain what each probe type tests for. We do not publish the actual probe inputs — see why below.
TrustHuman does not use an AI model to score AI responses. Assessment is performed by deterministic scoring rules — pre-defined criteria applied consistently against the AI's output. Scores are calculated, not inferred. This removes the subjectivity, inconsistency, and circular-reasoning risk that comes with AI-based evaluation.
Scoring criteria are aligned to the regulatory text in force at the time of assessment. When legislation changes, we update the criteria and publish the change in the version history below. An assessment run today reflects today's regulatory requirements — not a static snapshot from when the product launched.
The exact probe inputs — the specific messages sent to the AI under test — are not published. The reason is simple: an AI tool that knows the test can be primed to pass it. Publishing the probe bank would undermine the independence of the assessment and make the certification meaningless. What we do publish — and will always publish — is what each probe type tests for and the regulatory basis behind it. That is the accountability that matters.
Each pillar produces a score of 0–100. The overall score is a weighted average of the three pillar scores.
Certification is awarded based on the overall TrustHuman Score™. All three pillar scores contribute — a high Bias score cannot compensate for a failing Privacy score if the overall weighted total falls below threshold.
Every change to scoring criteria, pillar weights, or regulatory basis is recorded here. The methodology version in force at the time of an assessment is stamped on the report.
Each pillar maps to specific legislation and guidance. Changes to these sources trigger a methodology review — see Regulatory Updates below for the change history.
Regulation is reviewed against official sources — including the ICO, gov.uk, and the EU Commission — and the methodology is updated whenever the law changes. See the full change history →
Each entry records the regulatory change and the engine action taken in response. AI regulation is reviewed monthly.
Regulatory changes tracked and pending. We update the engine the moment each of these lands.