How this is verified.
Anyone can publish an opinion about AI regulation. This page sets out the method behind what is published here, what has been checked against the source text, what has not, and how to get something corrected.
The sourcing standard
Every factual claim is built from primary material — the regulation as published in the Official Journal, the standard itself, the vendor's own documentation, the regulator's own guidance. Not commentary about those things.
Three rules follow from that, and they are applied without exception:
- Clause-level citation. A claim about a legal obligation cites the article or clause that creates it, not the instrument in general. "Under the EU AI Act" is not a citation.
- Read, not inferred. Article numbers and headings are read in the source text before they are cited. Where a paragraph is cited, that paragraph is read individually.
- Paywalled standards are never verified second-hand.Where a standard sits behind a paywall, the citation is either checked against the purchased text or marked unverified on the page. It is not reconstructed from blog posts, consultancy summaries or training material, however confident those sources sound.
Verification record
The assessment's clause mappings were checked line by line and the result recorded. As at 28 July 2026: 58 distinct citations across 27 questions.
| Regime | Citations | Status |
|---|---|---|
| EU AI Act | 20 | Verified against the Official Journal text |
| GDPR | 4 | Verified against the Official Journal text |
| NIST AI RMF | 23 | Identifiers verified against NIST AI 100-1; 6 mappings corrected |
| ISO/IEC 42001 | 11 | Unverified — the standard is paywalled and the free preview truncates before Annex A |
Two things in that table are worth reading twice. Six NIST mappings were wrong and were corrected — the record says so rather than quietly fixing them. And eleven ISO/IEC 42001 citations remain unverified, because ISO sells its standards and the free preview stops before Annex A. Those eleven are marked as unverified wherever they appear. They will be verified against the purchased text or removed; they will not be verified against somebody's summary of it.
How the assessment scores
The readiness assessment is a deterministic rule set: a fixed question bank, fixed weights, and arithmetic. The questions, the weights and the clause mappings are published, which means a disputed result can be traced to the rule that produced it.
It is not an AI system, and that is a design decision rather than a limitation. Under Article 3(1) of the EU AI Act an AI system is one that infers from its input how to generate outputs, and Recital 12 states that the definition does not extend to systems based on rules defined solely by natural persons. Nothing here infers anything. A governance tool that could not explain its own output completely would be a poor advertisement for the argument it is making.
Corrections policy
Corrections are welcome and are the most useful message this site receives. If something is wrong, out of date or insufficiently sourced, write to info@aihumanproof.com with the page URL.
- Every correction request is read and answered.
- A substantive correction — anything that changes what a reader would do — is made on the page and dated, so the change is visible rather than silent.
- Typographical and formatting fixes are made without a dated note.
- Where a claim turns out to be unsupportable, it is removed rather than softened.
What this site is, and is not
Being specific about scope is part of being useful. AI Human Proof is an operational reference: it sets out the controls a deploying organisation must implement and the evidence needed to show they exist.
It is not, and does not hold itself out as:
- A law firm, or a source of legal advice.
- An accredited certification or assurance body.
- A conformity assessment under the EU AI Act.
- A formal audit opinion.
- Proof that an organisation is legally compliant.
- A guarantee that any AI system is safe.
Where a system is high-risk under the EU AI Act, formal conformity assessment and — for certain deployers — a fundamental rights impact assessment remain separate obligations. See EU AI Act compliance for what those involve.
Independence
AI Human Proof takes no money from the vendors it audits, and the funding model is stated in full on the About page — including the commercial handoff at the end of the assessment, and the conflict that creates.