// trust

What we comply with, and how you can check it.

Last updated: August 2026 · Versión en español

Our commitment European framework United States framework Our practices What we do not claim

Our commitment

At NHAI.AI we build artificial-intelligence agents for fields where mistakes are expensive: law and personal finance. That is why we voluntarily adopt, ahead of mandatory deadlines where applicable, the obligations of the leading AI regulatory frameworks in Europe and the United States. This page explains, in plain language, what we comply with and how it can be verified.

European framework

EU Artificial Intelligence Act — Regulation (EU) 2024/1689

We apply the transparency obligations of the EU AI Act ahead of schedule and across all our markets: anyone talking to our agents always knows they are talking to an AI; each agent's limits are declared in writing; and consequential decisions always remain with humans. Our systems perform none of the practices prohibited by the Regulation and do not operate in its high-risk categories.

GDPR — data protection

Data minimization (we neither request nor keep more than necessary), access and deletion rights handled through our corporate contact, and one simple rule: our users' conversations are not used to train AI models. We build on Anthropic's commercial API under its enterprise terms. Full details in our privacy policy.

United States framework

NIST AI Risk Management Framework — voluntary alignment

We organize risk management for our agents following the NIST AI RMF functions (govern, map, measure, manage): a risk inventory per agent, declared limitations, measurement through test batteries and a named human owner for every system.

Truth in advertising

Honest descriptions of what the technology does and does not do. No agent presents itself as a lawyer, a financial advisor or a substitute for a licensed professional.

How to verify: our practices

  • Traceable sources — every claim in our knowledge bases is traceable to its official source (official gazettes, consolidated statutes, regulator publications), with the date of the last update visible.
  • Declared gaps — when a question falls outside its base, the agent says so and refers you to a professional; it does not improvise.
  • Active guardrails — language, jurisdiction and misuse guardrails, tested against real adversarial inputs.
  • Dual-seal certification — no agent ships without passing two consecutive independent evaluations, with batteries of more than one hundred conversations per agent.
  • Technical security — API keys isolated server-side, encryption in transit and no unnecessary storage of personal data.

What we do not claim

We display no badges we do not hold. NHAI.AI LLC currently holds no third-party audited certifications (such as ISO/IEC 42001 or SOC 2); they are part of our roadmap as the operation grows. What this page describes are real, verifiable practices, not insignia.

Questions about our compliance posture? Write to info@nhai.ai and we will answer plainly.