Nine questions, answered the way we would answer them on a call. If yours is not here, ask it — tamsin@nethumanco.com.
AI governance is the set of decisions, evidence and accountabilities that determine how an organisation deploys artificial intelligence: who signs it off, what it is optimised for, what gets disclosed, and what happens when it goes wrong.
Most governance work stops at risk and compliance — the harms you must avoid. We add the half almost nobody documents: what the people on the receiving end of the deployment actually got back from it. Both halves belong in the same paper, at the same board meeting.
A net human score is a single figure for what an AI deployment gives back to the people it touches, minus what it takes from them — a net number, in the same sense as carbon or cash. On one side sits Human Return: hours genuinely handed back, skill kept alive, human contact created, agency preserved. On the other sits what the deployment cost those same people.
It is calculated from evidence and verified, never self-declared. Each of the eight Guardrails names the evidence it requires, and the score falls out of that evidence once it is in. Which is why a deployment can save a great deal of money and still score badly — that is precisely the point of having the number. How Human Return is measured →
The Human Interaction Standard is our certifiable standard for what technology returns to people. An organisation is assessed against the eight Guardrails of The Net Human Standard v1.0 — naming a human goal beside the business goal, disclosing when a person is dealing with a machine, keeping a human within reach when money, health or a livelihood is at stake, counting efficiency in hours given back.
Assessment is independent, the evidence is documented Guardrail by Guardrail, and the resulting net human score is published rather than self-declared. A certification is valid twelve months from issue, and results are published in full including the ones that lapse. Certification is at waitlist stage ahead of launch; the assessment itself is already available inside a consultancy engagement. Read the eight Guardrails →
Any organisation that has put AI into a process touching people — customers, citizens, patients, students or its own staff — and cannot currently say what those people got back from it.
In practice the trigger is one of three things: a board asking for the evidence behind an AI business case, a regulator or enterprise client asking about disclosure and human oversight, or a workforce that has quietly stopped trusting the rollout. The simplest test: if your AI business case has savings on it and nothing else, the audit is for you.
Often, yes. The Act reaches beyond the EU: obligations follow the deployment, not the head office. It applies to providers, deployers, importers and distributors that place AI on the EU market, and to those whose AI outputs are used inside the European Union — which can catch you with no EU entity at all.
A US company with EU customers, EU employees or an EU-facing assistant is the ordinary case, not the edge case. The practical test is not where you are incorporated; it is where the system's output lands. Breaching the transparency rules carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The longer answer, with the four scenarios →
Article 50 is the EU AI Act's transparency obligation, and it has applied since 2 August 2026. It covers four situations. People must be told when they are interacting with an AI system rather than a person, unless that is already obvious. Providers of systems generating synthetic audio, image, video or text must mark the output in a machine-readable format so it is detectable as AI-generated. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest. And deployers of emotion-recognition or biometric-categorisation systems must inform the people subject to them.
Two details matter commercially. The obligations are not limited to high-risk systems — they attach to the situation, not the risk tier. And when the Digital Omnibus deferred the Annex III high-risk timeline, Article 50 was left out of that deferral: it applied on schedule, and national market surveillance authorities can enforce it now. Guardrail 05 of the Net Human Standard sets the same test, and treats it as a point of pride rather than a compliance box.
It depends on how many deployments are in scope and how much evidence already exists — a single customer-facing assistant is a different exercise from an AI programme running across eleven departments.
What is fixed is the shape: a Human Return baseline first, then assessment against the eight Guardrails, then something a board can actually read. We agree the timetable with you in writing before anything begins, and we would rather quote honestly on your scope than publish an average that turns out to be wrong for you.
An organisation is assessed against all eight Guardrails of the Net Human Standard. Each Guardrail names the evidence it requires, and the net human score — the single figure for what a deployment gives back minus what it takes — is calculated from that evidence and verified, never self-declared.
Results are published in full, including the ones that lapse, and a certification is valid twelve months from issue. Certification is at waitlist stage ahead of launch; the assessment itself is already available inside a consultancy engagement. Read the eight Guardrails →
Nothing is published, because nothing is standard. Cost follows the number of AI deployments in scope, how much evidence already exists, and whether you need a one-off board-ready audit or an ongoing governance function.
Scope and price are set in the first conversation and given to you in writing before any work begins. Email tamsin@nethumanco.com with what you are deploying, buying or governing, and you will get a straight answer on both.