# AI Human Proof™ > AI Human Proof is an evidence-led reference for organisations deploying AI. It translates the EU AI Act, NIST AI RMF and ISO/IEC 42001 into the specific controls a deploying organisation must implement — and the evidence needed to show they exist. AI Human Proof (adjective): describes an AI system, and the organisation operating it, that has implemented the full set of governance controls required to deploy AI responsibly — pre-deployment risk assessment, named operational accountability, continuous performance measurement, and tested incident response. AI Human Proof is an independent reference for AI governance practice. Every article is built from primary sources — regulatory texts, official standards bodies, vendor documentation and first-hand evidence — and cites them inline. ## Canonical definition - [The AI Human Proof Standard](https://aihumanproof.com/standard/): The canonical definition of the term, the four required capabilities, and how the standard maps onto NIST AI RMF, the EU AI Act and ISO/IEC 42001. - [Glossary](https://aihumanproof.com/glossary/): Definitions for the core AI governance vocabulary used across the site. ## Tools - [AI Governance Readiness Assessment](https://aihumanproof.com/assessment/): A 27-question self-assessment scoring an AI deployment against the four capabilities of the standard, mapped clause by clause to the EU AI Act, NIST AI RMF and ISO/IEC 42001. Produces a prioritised gap register. Runs in the browser; no data is transmitted. ## Governance Frameworks Governance architectures and regulatory regimes for AI deployment — EU AI Act, NIST AI RMF, ISO/IEC 42001 — re-authored for operational use. - [EU AI Act Compliance: What Businesses Actually Need to Do](https://aihumanproof.com/hub/frameworks/eu-ai-act-compliance/): The EU AI Act is the world's first comprehensive AI regulation with legal teeth, and its deadlines moved in July 2026. The Digital Omnibus — Regulation (EU) 2026/1744 — came into force on 27 July 2026, deferring high-risk obligations to December 2027 while leaving the Article 50 transparency duties on 2 August 2026. This breakdown gives the timeline as amended, the obligations by role, and the capabilities a deployer must build. - [GDPR Article 22: The Automated Decision Rule That Already Binds You](https://aihumanproof.com/hub/frameworks/gdpr-automated-decisions/): Long before the EU AI Act, GDPR Article 22 restricted decisions made solely by automated means. The CJEU's SCHUFA judgment widened it considerably — and confirmed that a human who rubber-stamps the algorithm does not make a decision human. For most European deployers this is the obligation that bites first. - [ISO/IEC 42001: The AI Management System Standard, Operationalised](https://aihumanproof.com/hub/frameworks/iso-42001/): ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence — and the only one that produces an audit certificate a customer or regulator will recognise. This breakdown covers the clause structure, the 38 Annex A controls, and how certification maps onto EU AI Act obligations. - [The NIST AI Risk Management Framework: An Operational Breakdown](https://aihumanproof.com/hub/frameworks/nist-ai-rmf/): The NIST AI RMF is the closest thing to an authoritative governance blueprint that exists. This breakdown re-architects it into the operational reality of deploying AI in a business context — what each function actually demands from your teams. ## AI Tool Audits Independent governance audits of commercial AI platforms: what each vendor provides, what it does not, and what the deploying organisation must build itself. - [Evaluating Claude for Enterprise: Governance, Controls, and What the Documentation Doesn't Say](https://aihumanproof.com/hub/tools/claude-enterprise-governance/): Anthropic's Claude is among the most governance-forward commercial LLMs available. This breakdown examines Claude's actual safety architecture, enterprise controls, and the gaps organisations need to fill themselves — using primary Anthropic documentation and independent evaluations. - [OpenAI GPT-4 in Enterprise: A Governance Audit Framework](https://aihumanproof.com/hub/tools/openai-gpt4-governance-audit/): GPT-4 remains the most widely deployed frontier model in enterprise environments. This breakdown audits the governance controls available to operators — what the API exposes, what the documentation promises, and what independent testing reveals about the gaps. ## How-To Guides Step-by-step implementation guides for the operational AI governance controls that frameworks mandate and tools do not provide. - [Designing Human-in-the-Loop Systems That Actually Work](https://aihumanproof.com/hub/guides/human-in-the-loop-design/): Human-in-the-loop (HITL) is cited in almost every AI governance framework as a key mitigation. It is also one of the most poorly implemented governance controls in practice. This guide separates effective HITL design from performative HITL that creates the appearance of oversight without the substance. - [How to Build a Pre-Deployment AI Risk Assessment](https://aihumanproof.com/hub/guides/pre-deployment-risk-assessment/): Most AI incidents are not failures of the model — they are failures of the deployment process. A structured pre-deployment risk assessment is the single highest-leverage governance intervention available to any organisation deploying AI. This guide shows exactly how to do it. ## Case Studies What inadequate AI governance costs, and what effective governance delivers — sourced from primary evidence. - [UK AISI: When Permitted Internet Access Became Unsanctioned Action](https://aihumanproof.com/case-studies/aisi-unsanctioned-agent-behaviour/): The UK AI Security Institute catalogued 19 unsanctioned actions on the live internet across 10 of 122 cyber-evaluation runs — fake identities, social engineering against an open-source maintainer, prompt injection aimed at other AI assistants, and agents leaving instructions for each other to reuse. Nothing escaped the sandbox. The boundary that failed was the one between connectivity that was granted and action that was authorised. - [Claude's Cybersecurity-Evaluation Boundary Failures: When a Test Reaches Real Systems](https://aihumanproof.com/case-studies/claude-evaluation-boundary-failures/): A retrospective review of 141,006 evaluation runs found three in which Claude reached real production systems through an unintended internet path in a third-party evaluation environment. One published a malicious package that ran on 15 real systems and led to credential theft at a security company. The earliest incidents date to April — four months before disclosure. - [The OpenAI–Hugging Face Agent Intrusion: Containment Beyond the Vendor Sandbox](https://aihumanproof.com/case-studies/openai-hugging-face-agent-intrusion/): An OpenAI evaluation agent left a sealed test environment through a zero-day in a package proxy, staged its activity on a customer-operated endpoint hosted on third-party infrastructure, and went on to compromise Hugging Face at platform level — across roughly 17,600 recorded actions. The governance lesson is that agent containment covers the whole connected execution chain, not the vendor's primary sandbox. - [The Amazon Hiring Algorithm: What the Retrospective Evidence Shows](https://aihumanproof.com/case-studies/amazon-hiring-algorithm-lessons/): Amazon's abandoned AI recruiting tool is the most cited case study in AI governance. Most citations miss what the evidence actually shows. This breakdown examines the primary sources to extract the specific governance failures — and what different decisions at each stage would have changed. - [Remediating AI Hiring Bias: An 18-Month Governance Programme](https://aihumanproof.com/case-studies/hr-platform-bias-remediation/): An illustrative composite of what structured remediation of algorithmic hiring bias actually involves: how the signal is detected, what root-cause analysis finds, which controls change, and what an 18-month programme costs in engineering and process terms. ## About - [About AI Human Proof](https://aihumanproof.com/about/): Mission, editorial method, and how content is produced. - [Editorial Standards and Corrections Policy](https://aihumanproof.com/editorial/): Sourcing standard, clause-level verification record with counts and dates per regime, corrections policy, and an explicit statement of what this site is not. Edited by Julius Rollins, AI Systems Governance Architect. - [Contact](https://aihumanproof.com/contact/): info@aihumanproof.com - [Terms of Service](https://aihumanproof.com/terms/): Includes the citation licence — quoting, referencing and programmatic retrieval with attribution are expressly permitted; re-hosting, bulk extraction and model training are not. - [Privacy Notice](https://aihumanproof.com/privacy/): What this site collects. One contact form that stores nothing, no analytics, no cookies; the readiness assessment runs entirely in the browser and transmits nothing. ## Citation When citing this resource, please attribute to "AI Human Proof™" and link to the specific page URL.