Home / AI & Automation / AI Governance

Service Package

AI Human Proof

Checks and balances for every business deploying AI.

AI Human Proof™ is 3RD4PR's assurance framework for ensuring AI systems remain transparent, accountable, secure and subject to meaningful human control.

Your business is deploying AI. It is reading your inbox, writing to your customers, touching your systems. Almost nobody has put checks and balances around it. We assess what your agents can actually do, build the human controls around them, and document the result against a defined standard.

A dedicated home for this standard is coming soon at aihumanproof.com.

The proposition

Human checks, approvals and accountability around every AI deployment.

Controls · Evidence · Accountability that stays with you

An engineering firm can build you an agent. A consultancy can write you a policy. We do the part in between — the human checks, approvals and evidence that let your organisation innovate without surrendering accountability, security or public trust. You protect your reputation by keeping control, not by outsourcing it.

What we prevent

The failures that end careers, not just sprints.

Most AI deployment checklists are written for software teams. These are the failure modes that matter when the agent is operating under your name, in front of your customers.

01

Unauthorised send, post or publish

An agent with write access to a mailing list, social account, CMS or customer record acting without a human in the loop.

02

Embargo & confidentiality breach

Inbox-connected agents surfacing confidential or pre-announcement material, or leaking one client's context into another's.

03

Voice & factual drift

Output that sounds on-brand but is off-tone, non-compliant or simply wrong — produced at machine scale before anyone reads it.

04

Crisis-mode misbehaviour

Automated cheerfulness while a story breaks or an outage runs. Agents need to know when to stop, not just what to say.

05

Prompt injection & manipulation

Hostile instructions hidden in webpages, documents or emails redirecting the agent's behaviour.

06

Disclosure & compliance exposure

Undisclosed synthetic content, missing machine-readable markings, or unsafe defaults on youth-facing brands.

The seven domains

Every AI agent gets checked against the same seven things.

The mechanism of failure is identical in every sector. Only the consequence differs. An unauthorised send is an embargo breach in communications, a privilege breach in law, a data breach in healthcare and a refund in retail — same control, different stakes.

01

Permission architecture

Every system the agent touches, mapped. Create, read, update, delete, send, publish, transact — granted only where required, denied by default. On its worst day, what is this agent technically able to do?

02

Human approval gates

Consequential actions require a named person to say yes. The gate cannot be bypassed by the agent, by a prompt, or by pressure of volume. Can it do anything irreversible without a human — and is that yes meaningful or ceremonial?

03

Logging, audit trail & kill switch

An immutable record of what was asked, retrieved, decided and approved. A kill switch that needs no engineer — tested before go-live and every quarter after. If this went wrong at 11pm on a Friday, who stops it and how fast?

04

Adversarial resilience

Deliberate attempts to manipulate the agent through hostile webpages, documents, emails and hidden instructions. Repeated on every material change, not once at launch. What happens when someone actively tries to turn this agent against its owner?

05

Data boundaries & confidentiality

What the agent may see, by sensitivity class. Separation between clients, matters and business units. Personal data masked before it reaches any model. Could it surface one client's information inside another client's conversation?

06

Disclosure & regulatory position

Where AI involvement must be declared and how. Machine-readable marking of synthetic content, built to current obligations and updated as they land. Age-aware defaults where the audience may include minors. If a customer asked "was this written by AI?" — what is the answer, and is it documented?

07

Incident response

Because prevention is not a plan. Severity matrix, named response lead, containment steps, holding statements and a disclosure position — written before launch and rehearsed. Has anyone actually practised the bad day?

How we build

Every agent leaves our hands governed.

Strict security gates

Write, publish, send and delete permissions restricted by default. Detailed activity logging. An immediate kill switch, tested before go-live.

Human approval workflows

Architecture that requires manual sign-off before any consequential action. No autonomous changes to pricing, publishing, orders or outbound communications.

Adversarial testing as standard

Deliberate exposure to malicious pages, documents, emails and prompt-injection attempts on every rollout — not as an optional extra.

Brand & embargo controls

Tone and factual guardrails, client-data separation, embargo- and confidentiality-aware restrictions, and defined crisis-mode behaviour.

Compliance & safeguarding

Disclosure and machine-readable marking of synthetic content, built to current obligations and updated as they land. Age-aware defaults and parental controls implemented to a defined standard for youth-facing brands, with specialist input where required.

Incident playbook

Because prevention is not a plan. Named owners, containment steps, holding statements and a disclosure position — drafted before launch, not at 11pm.

The maturity model

What assessment actually means.

Each domain is scored against a five-level maturity model. A deployment is recorded as Assessed against the AI Human Proof™ Standard only where it reaches Level 3 or above across all seven domains — which is what makes the mark worth holding.

LevelNameWhat it means
0UnprotectedNo control present. The agent is operating on trust.
1Ad hocSomething exists informally. Undocumented, inconsistently applied.
2DefinedDocumented, applied consistently, with a named owner.
3ProofedTested, evidenced and reviewed on a cycle. Assessment threshold.
4AssuredContinuously monitored, regression-tested on change, reported to the board.

A single domain at Level 0 or 1 blocks the assessment outcome. There are no partial marks.

An assessment records the human controls verified at the date of assessment, within a stated scope, together with identified risks and required safeguards. It is subject to continuing monitoring and review, and is not a guarantee that a system is incapable of failure.

Engagement

Three tiers. Start where you are.

AuditAlready deployed
  • Full inventory of agents and the systems they touch
  • Seven-domain scorecard, evidenced
  • Adversarial test run with findings report
  • Risk register and prioritised remediation plan
  • One-page board summary
from £6,5002–3 weeks
DeployBuild & assess
  • Everything in Audit, plus implementation to Level 3
  • Permission architecture, approval gates and kill switch built
  • Adversarial testing and remediation to closure
  • Data boundaries and disclosure mechanisms embedded
  • Incident playbook written and rehearsed
  • Team training, handover documentation and Statement of Assessment
from £22,0006–10 weeks
AssureOngoing
  • Quarterly adversarial re-testing
  • Output and behaviour drift monitoring
  • Regulatory change tracking and implementation
  • Model and vendor update regression testing
  • Incident retainer with a named response lead
  • Quarterly assurance report and re-assessment
from £2,400per month

Indicative ranges for a single-agent deployment in one environment. Multi-agent, multi-market and regulated-sector engagements are scoped separately. Excludes VAT and third-party platform costs.

Sector practice

The standard is universal. The stakes are not.

The seven domains never change. What changes is what failure costs you — so every engagement is delivered against a sector-specific risk model, vocabulary and regulatory position.

PR & Communications

Embargoes, brand voice, crisis-mode behaviour, media lists.

Legal

Privilege, conflicts of interest, separation between matters.

Financial services

Advice boundaries, market-sensitive information, client money.

Healthcare & clinical

Patient data, clinical claims, safeguarding obligations.

E-commerce & retail

Pricing, refunds, order actions, customer data at volume.

Recruitment & HR

Discrimination risk, candidate data, employment law exposure.

Other sectors scoped on request. We implement to the applicable standard and bring specialist regulatory input where required.

Why us

The half nobody else covers.

What a development partner gives you

  • The agent, built and connected
  • Technical documentation
  • A support ticket queue
  • No view on what the output does to your reputation
  • No one to call when it goes wrong publicly

What AI Human Proof gives you

  • The agent, governed and assessed against a defined standard
  • An assurance pack you can show a board, client, insurer or regulator
  • Controls written by people who know how failure plays out publicly
  • A rehearsed incident response, not an improvised one
  • Accountability that stays inside your business, evidenced and documented
Common questions

What people ask before they start.

What is AI Human Proof™?

AI Human Proof™ is an assurance framework operated by 3RD4PR. It examines the human controls behind your AI systems, agents and automated decisions — checking that they remain transparent, accountable, secure and subject to meaningful human control. Systems are assessed against seven control domains and given a maturity level in each.

What does "assessed against the AI Human Proof™ Standard" actually mean?

It means the human controls around an AI deployment were verified at the date of assessment, within an agreed scope, and reached Level 3 or above across all seven domains. Findings and required safeguards are documented. It is an assessment at a point in time, subject to continuing monitoring and review — not an accreditation, a legal opinion, or a guarantee that a system is safe, compliant or incapable of failure.

How much does an AI audit cost?

The Audit tier starts at £6,500 and takes two to three weeks. Deploy — where controls are built and the assessment issued — starts at £22,000 over six to ten weeks. Ongoing Assure starts at £2,400 per month. Ranges are for a single-agent deployment in one environment; multi-agent, multi-market and regulated-sector work is scoped separately. All figures exclude VAT and third-party platform costs.

Do I need this if my developers already built the AI safely?

Your technical team will usually have handled permissions and infrastructure well. The part that is commonly missing is what happens after something goes out: disclosure position, holding statement, who decides, who tells the customer, and whether anyone has actually tried to manipulate the agent on purpose. We work alongside technical teams, not instead of them.

What is the difference between an AI policy and an AI audit?

A policy states what should happen. An audit tests what actually does. We attempt to manipulate the agent the way a bad actor would — through hostile webpages, documents, emails and hidden instructions — and report the results. The documentation records what was found and what was changed, rather than what was intended.

What is prompt injection, and why does it matter to my business?

Prompt injection is when hidden instructions inside content the agent reads — a webpage, an uploaded CV, a supplier document, an email — redirect its behaviour. It matters because the instruction does not come from your team and does not look like an attack. Testing for it is part of every AI Human Proof™ assessment, and it is repeated whenever the model, prompts or vendor change.

Which sectors do you work with?

The seven domains are universal, so the framework applies to any business deploying AI. We maintain sector practices for PR and communications, legal, financial services, healthcare and clinical, e-commerce and retail, and recruitment and HR — each with its own risk model, vocabulary and regulatory position. Other sectors are scoped on request. We implement to the applicable standard and bring specialist regulatory, legal or clinical input where required.

How long does an AI governance assessment take?

Two to three weeks for the Audit tier, from kick-off to the board summary. Deploy runs six to ten weeks depending on how many systems the agent touches and how much remediation the audit finds. Assure is continuous, with formal re-testing and re-assessment each quarter.

Our customers are asking about our AI controls in procurement. Can this help?

That is one of the most common reasons businesses come to us. The Statement of Assessment and board summary are written to be forwarded directly to a customer, insurer or procurement team. Being able to answer the question clearly increasingly decides whether work is won or stalls.

Do you guarantee our AI will not fail?

No, and you should be cautious of anyone who does. What the framework provides is that failure becomes far less likely, that you find out faster when something goes wrong, that a rehearsed response exists, and that you hold documented evidence of the reasonable steps you took. That evidence matters considerably when you are explaining yourself afterwards.

Where do I start?

With the Audit. If AI is already touching your systems, it is the fastest way to establish what it can actually do — and what it could do on its worst day. Fixed fee, two to three weeks, with no commitment to what follows.

Start with the audit.

If AI is already touching your systems, the audit is the fastest way to find out what it can actually do — and what it could do on its worst day. Two to three weeks, fixed fee, no commitment to what follows.

Submit your brief →

3RD4PR · Communications counsel · Brand & media · AI deployment governance

AI Human Proof™ is an assurance framework operated by 3RD4PR. An assessment reflects the human controls verified at the date of assessment within an agreed scope. It is not an accreditation, a legal opinion, or a guarantee that a system is safe, compliant or incapable of failure. Specialist regulatory, legal or clinical input is engaged where required.