Checks and balances
for every business
deploying AI.
AI Human Proof is an evidence-led reference for organisations deploying AI. It translates regulations and governance frameworks — the EU AI Act, NIST AI RMF, ISO/IEC 42001 — into practical controls, evidence requirements, platform assessments and implementation guidance.
What does it mean to be AI Human Proof?
AI Human Proof is the verification standard for AI deployment. It defines the checks and balances that every organisation must have in place before AI makes — or influences — decisions that affect people. The standard is not aspirational. It is a specific, measurable set of requirements.
Read the full definition"AI Human Proof" is not a marketing claim. It is a governance status — one that must be earned, maintained, and verified.
The Knowledge Hub
Three verticals. One purpose: making AI governance the default.
Governance Frameworks
The methodologies, regulatory standards, and operational architectures that make AI deployment accountable. From NIST AI RMF to EU AI Act compliance — translated into what organisations actually need to build.
Tool Audits
Commercial AI tools carry governance implications their documentation does not fully disclose. Honest breakdowns of what enterprise AI platforms provide — and what deployers must build themselves.
How-To Guides
Practical, step-by-step guidance for implementing AI governance controls. Pre-deployment risk assessments, human-in-the-loop design, incident response — the operational layer that frameworks describe and organisations must execute.
Where to start
Deployment Frameworks
Governance architectures and regulatory compliance frameworks for AI deployment. NIST AI RMF, EU AI Act, ISO 42001 — re-authored for operational use.
AI Tool Audits
Independent governance audits of the leading commercial AI platforms. What each tool provides, what it doesn't, and what your organisation must build.
How-To Guides
Step-by-step implementation guides for the operational governance controls that frameworks mandate and tools don't provide.
The cost of getting it wrong.
The value of getting it right.
UK AISI: When Permitted Internet Access Became Unsanctioned Action
The UK AI Security Institute catalogued 19 unsanctioned actions on the live internet across 10 of 122 cyber-evaluation runs — fake identities, social engineering against an open-source maintainer, prompt injection aimed at other AI assistants, and agents leaving instructions for each other to reuse. Nothing escaped the sandbox. The boundary that failed was the one between connectivity that was granted and action that was authorised.
Claude's Cybersecurity-Evaluation Boundary Failures: When a Test Reaches Real Systems
A retrospective review of 141,006 evaluation runs found three in which Claude reached real production systems through an unintended internet path in a third-party evaluation environment. One published a malicious package that ran on 15 real systems and led to credential theft at a security company. The earliest incidents date to April — four months before disclosure.