We show you how your AI can be misused — before the market, the CNIL, or your users find out.
Red Team audit for European publishers, integrators and deployers. The AI Act applies in stages: for high-risk systems, the rules on risk management, human oversight and robustness will apply from 2 December 2027 (Annex III areas) and 2 August 2028 (Annex I products), according to the timeline published by the European Commission. From then on, you will have to demonstrate them — not just claim them.
B2H — Business to Human
B2C dopamine-oriented. B2B cold-performance-oriented. B2H: the human as ultimate beneficiary — the institution as a support, never as the goal.
A reciprocal, win-win relationship of trust between a product and its user: the product never tries to change the user. This is AIAME's formalized framework — coded as a structural constraint, not marketing talk — and it is the benchmark of every Aiame Red audit: we measure your product against it.
If the user feels they must progress, compare, perform — B2H is dead. It's a test, not a slogan.
What we deliver
- Drift sheets per capability: plausible abusive readings, realistic malicious actor, semantic-drift test, GDPR & dignity test.
- Misuse simulation played against the description of your product — intent, exposed labels, data, outputs, autonomy — not against the running product: every finding is deterministic, reproducible and traced to the exact field that produced it. No slides.
- AI Act evidence pack (art. 9, 10, 13, 14, 15, 26, 50) and GDPR (art. 5, 22, 25, 35) — what your auditor, your DPO or your enterprise client needs to be able to show.
- Kill switches: stop conditions defined, tested, with real authority and real timelines.
Our method comes from our own internal rule: every visible capability has its adversarial counter-reading before any public release. A good Red Team result is: "here is exactly where your system no longer knows what it's doing."
On demand, automated
Offer reserved for professionals — publishers, integrators, DPOs, public or private organizations acting within the scope of their activity. It is not offered to consumers.
The audit is an engine, not a consulting firm. You describe your product, the engine runs the adversarial battery — abusive readings, semantic drift, dignity, AI Act mapping — and produces an actionable drift sheet. No quote, no sales cycle, no billed person-days for what a machine does better.
Scan
Product
Continuous monitoring
Pulled from sale on 2026-08-19: no infrastructure for scheduled re-scans, alerting or history exists yet (internal decision of 2026-08-19, not published). Put back on sale when — and only when — the infrastructure exists and an e2e proof is written.
A human review remains possible as an option when the stakes justify it (heavy regulatory context, product arbitration) — it builds on the engine's output instead of replacing it. On request, case by case.
Pricing communicated during scoping, before any order and with no commitment — net prices, VAT not applicable (article 293 B of the French CGI). Our rule stays the same: a price set from real costs, never from what the client can pay. The 24 h Scan turnaround starts from scoping: the engine that produces the drift sheet is genuinely automated, but pricing scoping is a human conversation, not a checkbox.
The engine runs on us first
Our internal rule requires that every visible capability have its adversarial counter-reading before any public release. We couldn't hold ourselves to it by hand: so the engine was built for our own needs, and it runs on us once a week (Mondays, 06:17 UTC) — a scheduled pass, not a trigger on every deployment. It re-reads the description of each of our tracked products and flags any drift from a versioned reference state (for instance a missing stop condition). It also checks, read-only, that two live services respond as expected: the copy of this site published on aiame-fr.github.io (HTTP status codes only, not content) and our sov.services.aiame.fr service.
What you buy isn't a service improvised for you: it's the tool we hold ourselves to, opened up to others. Our own sheets are not published at this time.
What we will never do
- Audit people (employees, candidates, customers) — we audit systems.
- Produce a scoring of individuals, even "for guidance", even "to help".
- Sell, retain or reuse your data or your users' data.
- A complacent report. House rule: if we don't know, we write "we don't know".
The audit is a technical service, not legal advice. The AI Act / GDPR mapping documents evidence usable by your DPO, your counsel or your auditor; it is neither legal advice nor a certification of compliance.
These commitments follow AIAME's B2H (Business to Human) framework: a relationship where the product never tries to change the user, dated in our internal doctrine (not published to date). aiame.fr practices it: European Union hosting administered directly, controlled certificate, zero tracker, zero third party. (A deliberate exception to this "zero third party", disclosed rather than hidden: a copy of this page is also published on aiame-fr.github.io for public versioning purposes — hosted by GitHub, not by our own infrastructure.)
Request a scan