Policy version: 2026-07-13 · EN

Acceptable Use Policy (AUP)

Version: 0.1 · Date: 2026-06-16
Status: Draft skeleton. Incorporated by reference in MSA Section 3.4 and public Terms.


1. Purpose

TrustOriginality.ai provides probabilistic AI-content detection and documentation tooling. This policy defines permitted uses and prohibited high-risk scenarios under the EU AI Act (Annex III) and similar frameworks.

2. Permitted use

  • Content screening before publication (media, marketing, education)
  • Trust & safety workflows with human review in the loop
  • Compliance documentation (EU AI Act Art. 50, DSA audit trails)
  • KYC / insurance fraud screening where Customer holds valid legal basis and consent
  • Research and internal audit with documented retention policies

3. Prohibited uses — EU AI Act Annex III (high-risk)

Do not use the Services as the sole or automated basis for decisions in:

Annex III area Examples (non-exhaustive)
Employment Hiring, firing, promotion, task allocation based solely on analysis scores
Education Student admission, exam grading, disciplinary action without human review
Law enforcement Criminal risk profiling, evidence authentication without qualified expert review
Migration / border Visa or asylum decisions
Justice / democracy Sentencing, parole, judicial outcome prediction
Critical infrastructure Safety-critical operational control without human override
Biometric categorisation Inferring sensitive attributes (race, political views) from content
Credit / insurance (standalone) Sole automated denial without adjuster review and lawful basis

TrustOriginality is a decision-support tool. Customer must:

  1. Keep a qualified human in the loop for consequential decisions.
  2. Not represent scores as definitive proof of authenticity or guilt.
  3. Comply with sector-specific rules (FCA, HIPAA, etc.) where applicable.

4. Prohibited conduct (general)

  • Uploading unlawful content or content without rights/permissions
  • Reverse engineering except as permitted by law
  • Resale or white-label except as agreed in writing
  • Circumventing rate limits, security, or access controls
  • Using outputs to harass, defraud, or mislead consumers (FTC Section 5 risk)
  • Claiming “EU-approved detector”, “government certified”, or “100% accuracy”
  • Representing Verifiable Credentials as QEAA, eIDAS qualified attestations, or official EU wallet credentials

5. Verifiable Credentials (non-qualified issuer)

TrustOriginality may issue W3C Verifiable Credentials (JWT format) for analysis and provenance attestations.

  • These credentials are cryptographically signed by TrustOriginality.ai using published issuer keys.
  • They are not Qualified Electronic Attestations of Attributes (QEAA) or other qualified trust services under eIDAS 2 unless explicitly agreed in a separate written contract.
  • VC outputs are decision-support documentation — not legal advice, not government certification, and not sole proof in court without qualified review.
  • Customers must not misrepresent VC outputs to end users, regulators, or partners as “EU-approved” or “officially certified”.

6. Enforcement

We may suspend or terminate access for AUP violations without refund. Customer indemnifies Provider for claims arising from prohibited use (see MSA).

  • MSA-TEMPLATE.md Section 3.4
  • ANNEX-IV-TECHNICAL-DOCUMENTATION.md — known limitations
  • docs/MODEL-BENCHMARK-TRANSPARENCY.md — accuracy disclosure
  • Public Terms: /terms-conditions