C
Credo AI
Credo AI is a Los Altos, California company selling an AI governance platform that inventories the AI an organisation runs and holds it against regulatory obligations. Its modules cover an AI registry with agent cards, dependency graphs and shadow AI discovery; risk intelligence with an agentic risk and control library, aggregate risk scoring, automated red-teaming and drift detection; a compliance and policy engine with pre-built policy packs for the EU AI Act, the NIST AI Risk Management Framework, ISO 42001 and SOC 2, governance workflows with approval gates and automated evidence generation; and production monitoring that ingests agent traces, evaluates them continuously and escalates to a person for high-risk actions. Its own generative capability is GAIA, a set of governance agents that handle intake and registration, retrieve evidence, assess risk, draft governance plans and run remediation, which the company says reduces weeks of manual work to minutes while keeping human oversight for critical decisions; an Agent Governor is offered as a research preview. Underneath sits what Credo AI calls a governance knowledge graph connecting regulations, business context and system configuration so that controls differ by jurisdiction and sector. The platform integrates with cloud and MLOps environments, agent frameworks and GRC systems, and is sold in modules through order forms rather than at a published price. The published terms of use commit Credo.AI Corp. not to use customer data to train, develop or improve any machine learning or artificial intelligence model, and separately disclose which enterprise AI tools its own staff use to support the service. Named customers include Mastercard, Principal and AdeptID; the company states a SOC 2 Type II examination.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Generative capability is the engine of a core capability layered on a governance system of record that would function without it. The platform's spine is an inventory and a workflow: an AI registry with agent cards and dependency graphs, a risk and control library, policy packs mapped to named regulations, approval gates, audit trails and evidence generation. That is a system of record a customer could run with human analysts filling it in, and the vendor's own account of its history says as much, describing a 2020 to 2023 phase whose breakthrough was replacing spreadsheets and ad-hoc reviews with a policy engine. What the models add is GAIA, a set of governance agents that perform intake and registration, retrieve evidence, assess risk, draft governance plans and remediate, plus automated red-teaming, drift detection and shadow AI classification. Remove them and the registry, the policy packs and the workflows remain. Product page and Terms of Use read 7 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted in numbers and measured in none of them, and the agreement disclaims it outright. The product page carries 10x faster compliance, 70 per cent reduced time in engineering bottleneck, 100 per cent AI visibility and 360-degree risk coverage, none with a basis, method or test set, and a customer quote repeats the 10x figure for EU AI Act compliance. Section 8.6 of the Terms of Use states in terms that Credo AI makes no warranties or representations regarding the accuracy, reliability, timeliness or completeness of the services. Several limbs of this band do not bite and are named rather than penalised: the platform produces risk scores, control mappings and evidence artefacts rather than legal assertions citing authority, so there is no citator and no reported case to open. What does bite is the limb that matters most for a product whose output is a compliance conclusion mapped to a named statute: nothing published lets a buyer test how often GAIA's evidence retrieval or risk mapping is right, and no grounding method is described. Product page and Terms of Use read 7 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A written commitment that the agents work alongside a person, with real review surfaces, short of the threshold. The product page states that GAIA's specialised agents automate the most time-consuming governance tasks while maintaining human oversight for critical decisions, and the mechanisms are named rather than gestured at: governance workflows with approval gates in the compliance module, human-in-the-loop escalation workflows in production monitoring, and human-in-the-loop escalation specifically for high-risk actions in the agentic monitoring phase. Continuous evaluation of agent traces feeds those escalations. That is more than most records on this axis publish, and it is worth crediting on a product whose own agents can run remediation. What is not published is the control structure behind it: no statement of which actions GAIA may take unattended, no threshold or criterion that defines a critical decision or a high-risk action, and nothing on what happens after a remediation agent acts wrongly. That is precisely the limb this band names as commonly absent. Product page read 7 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with named people, short of dates and method. The product page carries attributed statements from Andrew Reiskind, Chief Data Officer at Mastercard, on managing AI risk and implementing generative AI at speed and scale using the AI Registry and Vendor Registry; Renee Langeness, Director of Data Governance at Principal, on standing up an enterprise AI governance workflow; Parth Patel, Executive Director for AI and Data Science, on complementing internal processes; Kathleen Cachel, Senior Data Scientist at AdeptID, on centralised support for annual technical audits; and Brad Mallard, a CTO, on using the platform internally for compliance with its own policies and the EU AI Act. Partner statements from Microsoft's Chief Product Officer for Responsible AI and IBM add substance about what the integration does. One figure appears inside a customer quote, compliance with the EU AI Act at ten times the speed of doing it manually, with no method attached, and the page's own counters carry no basis. No deployment is dated. The customers and case studies page was not read and is the route to more. Product page read 7 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments, including one that is unusually specific, short of segregation and of a limb the agreement itself complicates. What is committed: section 6.8 of the Terms of Use bars Credo AI from using, processing or otherwise accessing User Data to train, develop or improve any machine learning or artificial intelligence model, and confines its access to providing, maintaining and supporting the service; the same clause names the enterprise AI tools Credo AI's staff may use to deliver the service, states that use is confined to Credo AI's own enterprise environment and team members, that no user data leaves it, and that such data is deleted at the end of the engagement. Section 11.3 makes User Content the customer's Confidential Information, 11.4 limits disclosure to those with a need to know under equivalent obligations, and 6.6 sets a sixty-day post-termination window followed by deletion. Two things hold it here. Nothing published addresses segregation between customers or between teams inside a tenant. And section 5.2 grants Credo AI a worldwide, sublicensable, transferable licence to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display User Content in connection with providing and improving the services: the purpose limitation is narrow but the verbs are not, and a governance platform holds a customer's AI risk assessments and incident records. Terms of Use read in full 7 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in the terms while the marketing describes regulatory conclusions, and nothing addresses where the output stops and a legal judgement begins. The product is sold on full alignment with European AI regulation including risk classification and conformity assessments, complete NIST Risk Management Framework compliance, and audit-ready documentation for every major AI regulation. Classifying a system's risk tier under the EU AI Act is a legal characterisation with consequences, and the company also sells advisory services described as strategic advisory related to AI governance. The counterweight located is section 8.6, disclaiming any representation as to accuracy, reliability, timeliness or completeness, which is a warranty disclaimer rather than a statement about advice. Nothing published says that a policy pack mapping, a risk classification or a conformity artefact is not legal advice, that counsel remains responsible for the determination, or which jurisdictions the regulatory content is maintained for. The audience is unambiguous and professional, which is recorded rather than credited. Same grade and same reasoning as the comparable records in this lane. Terms of Use and product page read 7 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Principles and a commitment are published; a governance framework for the vendor's own AI is not. Credo AI publishes an ethos page, runs an annual AI trust summit, maintains a public governance insights hub and glossary, and positions itself as the company that pioneered the category, so responsible AI language is abundant. One commitment goes further than language and is credited here as real substance: section 6.8 of the Terms of Use is a binding statement about how Credo AI handles customer data in relation to AI models, including which enterprise AI tools its own staff may use. What is still absent is the governance half. Nothing published names who inside Credo AI is accountable for GAIA's behaviour, describes what is evaluated before a governance agent ships, reports any result from such evaluation, or discloses anything about uneven output across sectors, jurisdictions or populations. The company sells ISO 42001 policy packs and does not claim the certification for itself, and the trust centre that might carry more returns no body on this channel and is named as the rebuttal route. Terms of Use, product page and trust centre attempted 7 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy across most of the ground, short of the security detail and the subprocessor list. What is published in the Terms of Use: retention and deletion are specific, with User Data retained as long as needed to provide the services, a sixty-day post-termination window for export using standard export features, and deletion after it (6.6); access is confined by 6.8 to providing, maintaining and supporting the service, with the enterprise AI tools used by staff named and their data deleted at the end of the engagement; incident practice is stated, with notice without undue delay after becoming aware, reasonable steps to mitigate and minimise damage, and an express statement that notification is not an admission of fault (6.9); aggregated and anonymised use is permitted but conditioned on non-attribution (6.7); and confidential information must be returned or destroyed on request with written certification (11.7). What is missing is the specificity the top band needs. Security is described only as reasonable administrative, technical and physical safeguards, with no encryption standard, access control, testing regime or logging commitment; no subprocessor list was located; and the data processing agreement is provided on request rather than published. The Vanta-hosted trust centre would be the route to the security detail and returns no body on this channel. Terms of Use read in full 7 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published and specific, including the places where it stands behind nothing. Section 10.1 of the Terms of Use gives a defence and indemnity against third-party claims that the services infringe or misappropriate intellectual property rights, with six named exclusions at 10.2 and the mitigation ladder at 10.3 of obtaining the right, modifying or replacing the services with substantially equivalent functionality, or terminating with a pro-rated refund. Section 9.2 caps each party's aggregate liability at the total paid in the twelve months preceding the incident, and 9.3 lifts the cap and the exclusion of indirect damages for breach of confidentiality and for the customer's breach of the licence and acceptable use terms. Two express warranties carry stated remedies: the SaaS products will perform materially in accordance with the documentation, remedied by correction or termination with a pro-rated refund (8.4), and advisory services will be performed in a professional and workmanlike manner, remedied by re-performance or refund (8.5), each declared the exclusive remedy. Section 8.6 disclaims everything else and states plainly that no representation is made about the accuracy, reliability, timeliness or completeness of the services, and 14.1 gives a termination right with a pro-rated refund if a change materially reduces functionality. No insurance is stated, the indemnity is not carved out of the cap, and the service level agreement is referred to as mutually agreed rather than published. Terms of Use read in full 7 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Named integrations across the systems the work actually lives in, short of an implementer's description. The product page lists them by category: cloud and AI operations with AWS, Azure, GCP, Databricks and Snowflake; agent platforms with Azure AI Foundry, LangChain, CrewAI and AutoGen; governance, risk and security with ServiceNow, Archer, OneTrust and Qualys; development and MLOps with GitHub, MLflow, Jira, Confluence and Slack; and custom APIs, webhooks, SDKs and connectors, with a separate SDK documentation site and a stated ecosystem of more than thirty partners. One integration is described in enough detail to see what moves, and by the counterparty: Microsoft's Chief Product Officer for Responsible AI states that it delivers prescriptive guidance to governance leaders on what to evaluate and lets developers run governance-aligned evaluations inside their own workflow. The registry also governs MCP servers and platform connections. What is not published on the page read is per-integration depth, direction or configuration; the SDK documentation was not read and is not credited by its title. Product page read 7 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Nothing published on where the software runs or where customer data sits was located on any readable surface. The Terms of Use describe SaaS products accessed through a browser or API and say nothing about hosting region, data residency, tenancy or a deployment choice; the product page describes architecture in functional layers rather than infrastructure; no region selector, residency commitment or single-tenant option appears anywhere read. Two things are recorded so this reads as what it is. First, the vendor's trust centre at trust.credo.ai is a Vanta-hosted portal that returns page metadata with no body on this channel, so the surface most likely to carry hosting and residency detail could not be read; that is a retrieval limit under the standing convention, it is named here as the rebuttal route, and it would move this grade on a read. Second, the agreement does disclose one adjacent fact, at 15.9, that the services may be subject to United States and other export laws, which places the vendor in the US but is not a residency statement. This grade records what is establishable on the date. Terms of Use and product page read, trust centre attempted, 7 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A certification is named by the vendor and no scope, date or reachable report was located. The trust centre at trust.credo.ai states, in the vendor's own words, that Credo AI maintains a SOC 2 Type II examination and invests continuously in its security program so that the platform its customers rely on meets the same governance standards it helps them achieve. The platform's own compliance module lists SOC 2 among the frameworks it supports for customers, which is a product capability and is not counted here. What is missing is everything that would make the attestation checkable: no auditor, no examination period, no report date, no scope statement, and no route to the report that could be established, since the trust centre is a Vanta-hosted portal returning page metadata with no body on this channel. That is recorded as a retrieval limit rather than as an absence, the portal is the rebuttal route, and the lower tier is graded with the reason stated. Trust centre attempted and Terms of Use read 7 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor describes a proprietary intelligence layer and governance agents without identifying what sits underneath them. GAIA is presented as a set of AI agents performing evidence retrieval, risk assessment, incident response and remediation, powered by what the product page calls a proprietary governance knowledge graph; no model, provider, hosting location or change-notification commitment for those agents was located anywhere. Two adjacent facts are deliberately not credited here, because each belongs to a different arrow. The models named on the site, ChatGPT, Claude and Gemini, are the customer's deployments that the product governs through generative AI guardrails, not Credo AI's supply chain. And the enterprise AI tools named in clause 6.8 of the Terms of Use are the tools Credo AI's own staff use to support the service, which is a statement about internal operations and is credited on the training and confidentiality rows instead. No subprocessor list was located. The trust centre is the likely route to a supply chain disclosure and returns no body on this channel. Product page, Terms of Use and trust centre attempted 7 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The shape is partly visible and no number is published at any level. There is no pricing page; every path ends at Talk to an Expert or a personalised demo, offered without a credit card. What a buyer can see before that conversation is the modular structure, which the vendor makes a selling point: AI Registry and Discovery, Risk Intelligence, Compliance and Policy Engine, and Governance are named as modules that work independently, with the advice to land with the registry and add the others as adoption grows, alongside separately sold advisory services. The Terms of Use add the mechanics: fees are set in an order form or statement of work, based on services purchased rather than actual usage, non-cancellable and non-refundable, invoiced in advance and payable within thirty days, with 1.5 per cent monthly interest on late amounts, automatic renewal unless either party gives thirty days' notice, and price changes effective at renewal on reasonable prior notice. Section 3.4 confirms account tiers exist with varying features and usage limitations, and 4.3 warns that exceeding them may incur charges at then-current rates, though neither the tiers nor the limits are named publicly. No VendorPricing row is written, since a row belongs to vendors graded A or B on this axis. Terms of Use and product page read 7 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance across buyers and regulations, and the boundaries are left open. The platform architecture names five stakeholder types it connects, the governance lead, the business user, product and engineering, legal and compliance, and information security and third-party risk management, which is a published account of who sits in the workflow. Regulatory coverage is named rather than gestured at, with pre-built policy packs for the EU AI Act, the NIST AI Risk Management Framework, ISO 42001 and SOC 2, and the knowledge graph described as distinguishing a model used in EU healthcare from one used in US financial services. The customer evidence spans payments, insurance, professional services and a technology vendor, and the vendor states Fortune 500 adoption. What is not stated is any limit: no jurisdiction, regulation, sector or organisation size is named as out of scope, no coverage boundary is given for the regulatory content, and nothing describes what a law firm rather than an in-house function would do with the platform. Product page read 7 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published terms prohibit training on customer content. Not a policy page, the agreement.
The published agreement prohibits training, in the agreement rather than on a policy page. Section 6.8 of the Terms of Use, effective 21 April 2026, states that Credo AI will not use, process or otherwise access User Data to train, develop or improve any machine learning or artificial intelligence models, and that its access to User Data is solely to provide, maintain and support the services. The same clause discloses something no other record in this index carries: it names the enterprise AI tools Credo AI's own staff use in delivering the service, including ChatGPT Enterprise and custom GPTs, Gemini Enterprise, Claude Enterprise and Microsoft Copilot, and commits that such use stays inside Credo AI's enterprise account environment and team, that no User Data leaves that environment, and that the data is deleted at the end of the engagement. Two qualifiers travel with the value and are recorded rather than smoothed over. Section 5.2 grants a broad content licence over User Content, including rights to modify, publish, distribute and create derivative works, scoped to providing and improving the services. And section 6.7 permits Credo AI to use aggregated and anonymised data derived from use of the services for its own business purposes, including developing new products, provided it cannot be attributed to the customer. Neither displaces 6.8, which is the specific clause and names the thing. Terms of Use read in full 7 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
A specific period is published for the end of the relationship and the customer cannot change it. Section 6.6 of the Terms of Use sets a sixty-day window after termination or expiry during which the customer may export using standard export features, after which Credo AI may delete User Data except as required by law or for its legitimate business purposes, and it recommends regular customer-side backups. Two limits on that are stated here so the row is not read as more than it is. In-term retention is not a period at all but a standard, User Data kept as long as needed to provide the services and to meet legal, dispute and enforcement needs, so a customer cannot read off how long a GAIA prompt or a generated governance artefact persists while the subscription runs. And no zero-retention or customer-configurable window is offered anywhere located. Section 6.7 separately permits indefinite use of aggregated and anonymised derivatives. A reader could hold the vaguer value on the in-term half; the specific published period is what the value records. Terms of Use read in full 7 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located public material addresses segregation between users, teams or customers. The Terms of Use put administrative users in charge of managing access levels and permissions for their organisation at 3.3, which is a customer-side control over its own people rather than a statement about how the platform separates one organisation's governance records from another's, or whether a business user registering an AI system can see assessments belonging to a different part of the enterprise. The product page describes connecting every stakeholder to every AI system, which is the opposite emphasis. Nothing read describes tenancy, isolation or permission enforcement at retrieval time, including for GAIA's evidence retrieval across a customer's records. The trust centre would be the likely route and returns no body on this channel. Terms of Use and product page checked 7 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
The agreement commits to prior written notice where legally permitted, with minimisation. Section 11.6 of the Terms of Use permits disclosure of confidential information to the extent required by law, regulation or court order only on condition that the receiving party gives prior written notice so the disclosing party may seek a protective order or other appropriate remedy, and discloses only the portion legally required; if no protective order is obtained, it must furnish only what is legally required and use commercially reasonable efforts to obtain assurance of confidential treatment. Section 11.3 makes User Content the customer's confidential information, so the clause reaches the governance records and assessments a customer holds in the platform rather than only account data. No transparency report, request statistics or law-enforcement guidelines page was located, which is what separates this from the top value, and there is no separate law-enforcement protocol of the kind some records in this pull carry. Terms of Use read in full 7 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the licence or rights basis.
The sources behind the product's compliance content are identified by name and no licence or rights basis is stated for any of them. The compliance and policy engine ships pre-built policy packs for the EU AI Act, the NIST AI Risk Management Framework, ISO 42001 and SOC 2, and the governance knowledge graph is described as connecting regulations, risks, controls and business context into a proprietary intelligence layer, with a separately published regulatory insights hub and risk and control library. So a buyer can see which instruments the content derives from, which is more than the signal's lowest value describes. What is absent is the rest: no statement of the licence or rights basis for the standards content, which matters because ISO 42001 and the SOC 2 trust services criteria are copyrighted works rather than public law; no update cadence for the packs as regulations change, in a domain where the EU framework has been amended; and no statement of jurisdictional coverage depth. Product page and Terms of Use read 7 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
No located public material addresses whether the authority behind the product's outputs is checked for currency. The signal's ordinary subject, subsequent history of reported cases, does not bite for a platform whose outputs are risk classifications and control mappings rather than citations to case law, and that is recorded rather than penalised. The analogue that would bite is whether the policy packs and control library track amendments to the instruments they encode, and nothing read commits to it: the vendor publishes regulatory intelligence and an explainer on changes to the EU framework, which shows the content is being maintained, but no statement describes how a customer learns that a pack has changed, when it was last aligned, or what happens to an assessment completed under a superseded version. Product page, Terms of Use and regulatory materials checked 7 September 2026.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located public material describes what the governance agents do when they cannot ground an answer. The published material addresses oversight rather than uncertainty: human oversight is maintained for critical decisions, workflows carry approval gates, and high-risk actions escalate to a person. Those are controls over what an agent is allowed to finish, not a description of what it does when the evidence it needs is missing or ambiguous. Nothing read exposes a confidence or grounding score, describes an abstention path for GAIA's evidence retrieval or risk assessment, or reports any evaluation in which the system declined. The distinction matters on a product whose agents draft governance plans and remediate incidents. Product page and Terms of Use checked 7 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming Credo AI or GAIA was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names alongside a general search of the sanctions coverage; the decisions naming specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product. Exposure is structurally remote for a platform whose outputs are internal governance artefacts rather than filings, though the artefacts it generates are designed to be shown to regulators and auditors, which is a different audience carrying its own accuracy expectations.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No located public material engages with bar or ethics guidance, or with lawyers' professional obligations in general terms. Credo AI engages regulation heavily and at a high level of specificity, publishing policy packs, a regulatory insights hub, an explainer on changes to the EU AI framework and an annual trust summit, and it names legal and compliance as a stakeholder group in the platform. All of that concerns the obligations of the organisations that buy the product. Nothing names an ethics opinion, a bar association guidance document or a regulator's guidance on lawyers' use of AI, and nothing addresses the duties of a lawyer relying on a governance artefact the platform generated. The lower value was tested before this one was taken: a generic reference would need some engagement with professional responsibility as such, and none was located. Product page, Terms of Use, legal pages and resource listings checked 7 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
The product does not touch a fee between a lawyer and a client. Credo AI is licensed by an enterprise to govern its own AI systems, and the stakeholders named in the platform are governance leads, business users, engineering, legal and compliance, and information security, all of them internal functions that bill no client for the work. The efficiency claims on the product page, ten times faster compliance and seventy per cent less time in engineering bottlenecks, are aimed at the buyer's own cost and cycle time, which the value text records as not making the row a savings claim. Advisory services are sold alongside the platform but are Credo AI's own consulting engagement rather than a lawyer-to-client matter. Nothing addresses billing, fee or disclosure treatment because there is no client invoice for it to address. Product page and Terms of Use checked 7 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The material exists behind a sales conversation or an executed agreement.
The material exists and sits behind a request. Section 6.4 of the Terms of Use states that where a customer is subject to data protection laws requiring one, Credo AI will enter into its standard data processing agreement upon request, so the artefact a buyer would forward is not published. No subprocessor list was located on any surface, and no model provider behind the platform's own governance agents is named anywhere, so the question a client's AI clause actually asks, whose models see our content, has no published answer. What is public and forwardable is narrower but real and should not be overlooked: the Terms of Use themselves carry the no-training commitment at 6.8, the named list of enterprise AI tools Credo AI staff may use with the confinement and deletion conditions attached, the sixty-day retention position, and the breach notification commitment. The trust centre, which is where a subprocessor list would ordinarily sit, returns page metadata with no body on this channel and is the rebuttal route. Terms of Use read in full and trust centre attempted 7 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
No located public material addresses court disclosure of AI use or a verification certification. The platform generates a great deal of evidence, including automated evidence generation, audit trails, audit-ready documentation and conformity artefacts, and it is worth being precise about whose that evidence is: it records what the customer's AI systems are and how they were governed, for regulators and auditors, not what Credo AI's own governance agents did to produce a given output. Crediting it here would credit the customer's own mechanism to the vendor. Nothing read offers a per-item export covering which model or agent produced an assessment, what it retrieved and what a person verified, and nothing addresses a court's standing order on AI use or a disclosure a filer could attach. Product page and Terms of Use checked 7 September 2026.