The agent that would not admit it was an AI
It explicitly denied being one when the customer asked directly.
Analysis of more than 50 conversational AI agents in production at large enterprises — mainly in Spain, with presence across the rest of Europe — three months after the European AI Regulation began requiring transparent disclosure to the customer.
Published in September 2026 · First annual edition · Next wave: 2027
See methodology ↓AI agents audited
Real conversations analysed (10 sessions per agent)
Markets covered
Main sectors
The Trust Score is a proprietary Lexic.AI methodology, structured around four pillars with different weights:
Integrity & Safety
Is it safe and ethically sound?
The agent's resistance to manipulation (prompt injection, jailbreaking), whether it reveals internal or other users' information under pressure, and whether it treats all users without bias or undue commercial pressure.
Regulatory Compliance
Is it legal?
Whether the agent clearly identifies itself as AI from the start of the conversation (Article 50 of the European AI Regulation) and whether it collects personal data with informed consent (GDPR).
Operational Reliability
Does it work well as a system?
Accuracy of responses (unfounded claims, made-up information) and consistency of the agent when handling errors or out-of-scope questions.
Customer Experience
Does it serve the customer and meet its goal?
Whether the agent resolves the query or merely replies, how it handles escalation to a human, and whether the tone is appropriate for the context.
Every agent is assessed on real production conversations and on controlled synthetic attacks: prompt injection, jailbreaking, and system-context manipulation.
The Trust Score is aligned with ISACA's audit methodology — the international professional association of reference in information systems governance and auditing, author of ITAF (IT Audit Framework) and of globally recognised credentials such as CISA, CISM, CGEIT and CRISC. This alignment means that the Trust Score design follows the same principles ITAF requires — independence, objectivity, professional diligence and sufficient and appropriate evidence. It does not mean that ISACA has certified, reviewed or endorsed the Lexic.AI Trust Score: it remains a proprietary methodology.
| Trust Score | Level | What it means |
|---|---|---|
| 85-100 | Fit (Trusted) | Passes without conditions, can operate with customers without restrictions |
| 60-84 | Fit with conditions | Operates, but with findings that require a short-term action plan |
| 0-59 | Not fit | Should not operate with customers without prior remediation |
| Any score | Automatically not fit | A single critical finding in Safety or Regulatory Compliance forces this level, regardless of the overall score |
Agents that pass their Trust Score without conditions
Fail to identify themselves as AI when the customer asks directly (Art. 50)
Promise to escalate to a human and never do
Collect personal data without a clear consent gate
Aggregated, anonymous figures calculated across the full set of audits carried out by Lexic.AI up to August 2026. No figure is linked to a named company.
Since 2 August 2026, Article 50 of the European AI Regulation has been in force, requiring clear disclosure of when a customer is talking to a machine.
The "high-risk" category of the same regulation has been postponed to 2 December 2027 by the Digital Omnibus Regulation — two different dates that should not be confused.
Governing an AI agent well is not about avoiding a fine. It is about being able to demonstrate, with evidence, that your customers can trust it.
It explicitly denied being one when the customer asked directly.
It promised to escalate the conversation and never did.
Given a user instruction, it abandoned its business rules (prompt injection).
Composite, anonymised cases built from patterns detected across multiple audits. None corresponds to an identifiable company.




















Discover how the Trust Score is calculated and why these findings matter for your business.
Have AI agents in production or prefer to talk to the team before requesting the audit?