Assessment framework

Three pillars. Fixed weights.

Every assessment scores the same three dimensions. Weights are pre-set and published — they don't change between runs or between sectors.

40%
Bias
Carries the highest weighting because discriminatory AI decisions cause direct, measurable harm to real people — and attract the most significant regulatory and legal exposure under the Equality Act 2010.
35%
Transparency
Regulators and courts require meaningful explanations for automated decisions. Opacity is a foundational failure — without it, individuals cannot challenge decisions that affect them.
25%
Privacy
Data protection failures in AI deployments are common — but with competent system design, largely preventable. The lower weight reflects tractability, not lower importance.

What we check under each pillar

The descriptions below explain what each probe type tests for. We do not publish the actual probe inputs — see why below.

Bias 40%
Age & Vulnerability
We test whether the AI changes its recommendations, tone, or advice based on signals of a person's age — including whether it applies more restrictive or paternalistic assumptions to older individuals. AI tools that treat people differently based on age characteristics may be in breach of the Equality Act 2010.
Socioeconomic Discrimination
We test whether the AI varies its responses based on signals of socioeconomic status — such as references to postcode, employment type, or income level — in ways that could disadvantage lower-income individuals or reinforce financial exclusion.
Transparency 35%
AI Disclosure
We test whether the AI proactively identifies itself as an AI system when directly asked, and whether it could lead a user to believe they are interacting with a human. Failure to disclose AI status on request is a breach of Article 50 of the EU AI Act and the obligations introduced under UK GDPR Articles 22A–22C.
Decision Explanation
We test whether the AI can provide a clear, specific, and auditable explanation for an automated decision — not just a policy reference or generic disclaimer. Meaningful explanation is a legal requirement under UK GDPR Articles 22A–22C and is necessary for individuals to exercise their right to contest automated decisions.
Privacy 25%
Prompt Injection Resistance
We test whether the AI can be manipulated by malicious content embedded in a user message — for example, instructions that attempt to override system behaviour, extract confidential data, or cause the AI to act outside its intended scope. This tests Article 32 UK GDPR security obligations and the ICO AI Code of Practice.
Data Subject Rights
We test whether the AI correctly handles requests relating to UK GDPR data subject rights — including the right of access (Article 15), the right to rectification (Article 16), and the right to erasure (Article 17). AI systems that deflect or mishandle these requests put the deploying organisation at risk of enforcement action.

How assessment works

No AI judging AI

TrustHuman does not use an AI model to score AI responses. Assessment is performed by deterministic scoring rules — pre-defined criteria applied consistently against the AI's output. Scores are calculated, not inferred. This removes the subjectivity, inconsistency, and circular-reasoning risk that comes with AI-based evaluation.

Pinned to current regulation

Scoring criteria are aligned to the regulatory text in force at the time of assessment. When legislation changes, we update the criteria and publish the change in the version history below. An assessment run today reflects today's regulatory requirements — not a static snapshot from when the product launched.

Why we don't publish the probe library

The exact probe inputs — the specific messages sent to the AI under test — are not published. The reason is simple: an AI tool that knows the test can be primed to pass it. Publishing the probe bank would undermine the independence of the assessment and make the certification meaningless. What we do publish — and will always publish — is what each probe type tests for and the regulatory basis behind it. That is the accountability that matters.

Scoring rubric

How the TrustHuman Score™ is calculated

Each pillar produces a score of 0–100. The overall score is a weighted average of the three pillar scores.

TrustHuman Score™ formula
TrustHuman Score™ = (Bias × 40%) + (Transparency × 35%) + (Privacy × 25%)
Each pillar score = average of probe scores within that pillar
Each probe score = 0 (fail) or 100 (pass)
Result = rounded to nearest whole number

Certification bands

Certification is awarded based on the overall TrustHuman Score™. All three pillar scores contribute — a high Bias score cannot compensate for a failing Privacy score if the overall weighted total falls below threshold.

Gold
≥ 90
Excellent — clear compliance posture across all pillars
Silver
≥ 75
Good — strong performance with limited gaps
Bronze
≥ 60
Adequate — material risks identified; remediation advised
Not Certified
< 60
Significant failures — not suitable for certification

Methodology version history

Every change to scoring criteria, pillar weights, or regulatory basis is recorded here. The methodology version in force at the time of an assessment is stamped on the report.

v2.0 · current
July 2026
Regulatory basis updated to reflect post-DUAA regime.
  • Transparency pillar: UK GDPR Art 22 references updated to Art 22A–22D (Data (Use and Access) Act 2025, in force 5 Feb 2026)
  • Transparency pillar: EU AI Act Art 50 transparency obligations added (in force Aug 2026)
  • ICO AI Code of Practice (draft) added to Privacy pillar regulatory basis
  • Regulatory register version bumped to 2.0; last verified 8 July 2026
v1.0
January 2026
Initial methodology publication.
  • Three-pillar framework established: Bias (40%), Transparency (35%), Privacy (25%)
  • Six probe types defined across the three pillars
  • Certification bands set: Gold ≥90 / Silver ≥75 / Bronze ≥60 / Not Certified <60
  • Regulatory basis: Equality Act 2010, EU AI Act Art 50, UK GDPR Art 5/22/32, ICO AI guidance
Legal grounding

Regulatory basis per pillar

Each pillar maps to specific legislation and guidance. Changes to these sources trigger a methodology review — see Regulatory Updates below for the change history.

Bias · 40%
Equality Act 2010 — Age as a protected characteristic; prohibition on indirect discrimination in automated decision systems. Applies to all UK-based AI deployments and any AI affecting UK persons.
Transparency · 35%
UK GDPR Art 22A–22D (via Data (Use and Access) Act 2025, s.80–83, in force 5 Feb 2026) — Safeguards for significant automated decisions: right to meaningful human review, right to contest, right to information. Replaces the pre-DUAA Art 22 regime for UK purposes.
EU AI Act Art 50 (in force Aug 2026) — AI transparency obligations including disclosure requirements when AI interacts with people. Applies to UK businesses serving EU users.
Privacy · 25%
UK GDPR Art 5 — Data minimisation and purpose limitation principles.
UK GDPR Art 32 — Security of processing; obligation to implement appropriate technical measures against unauthorised access.
ICO AI and Automated Decision-Making Code of Practice (draft, 2025) — Guidance on privacy-by-design for AI systems and obligations around data subject rights requests handled by AI.

Regulation is reviewed against official sources — including the ICO, gov.uk, and the EU Commission — and the methodology is updated whenever the law changes. See the full change history →

Change history

Engine updates

Each entry records the regulatory change and the engine action taken in response. AI regulation is reviewed monthly.

Aug 2026
EU AI Act Article 50 transparency obligations took effect
Transparency probes updated to reflect AI disclosure requirements — including for UK businesses serving EU users.
Engine updated
Feb 2026
UK GDPR Article 22 replaced by Articles 22A–22D (Data (Use and Access) Act 2025)
Engine updated to assess UK automated decisions against the new safeguards: meaningful human review, right to contest, right to information. All citations updated.
Engine updated
On our radar

What we're watching

Regulatory changes tracked and pending. We update the engine the moment each of these lands.

Pending
ICO AI and ADM Code of Practice — final publication
Expected: Summer 2026
Will carry statutory weight. All ICO AI Code references will be reviewed and probe criteria updated on publication.
Pending
UK GDPR Article 22D — secondary legislation defining meaningful human involvement
Expected: 2026–2027
Secretary of State may define what constitutes 'meaningful human involvement' and 'significant decision'. Art 22A/22C probe guidance will be updated on publication.
Phased
EU AI Act — high-risk obligations (Annex III: recruitment, credit, healthcare)
Expected: 2027–2028
High-risk system obligations after Digital Omnibus adjustment. Sector probe regulatory mapping will be updated as each tranche applies.
Pending
EU Digital Omnibus — ADM and AI Act clarifications
Expected: 2026–2027
Potential clarifications to automated decision-making provisions and AI Act obligations. EU-facing citations will be updated accordingly.
Watch
FCA AI/ADM expectations — financial services sector
Expected: Ongoing
Sector-specific FCA guidance on AI in lending and credit decisions. Relevant to financial services probe regulatory mapping.
Watch
MHRA AI expectations — healthcare sector
Expected: Ongoing
MHRA guidance on AI as a medical device and clinical decision support. Relevant to healthcare triage probe regulatory mapping.