Due diligence

How to verify an AI business

To verify an AI business, check six things in this order: that the legal entity exists in a companies register, that it controls the domain it emails you from, that a named human is accountable for it, that any credential it displays is confirmed by the issuer rather than by the company itself, that it publishes its own mistakes, and that its factual claims cite a source you can open. A company that passes the first five and fails the sixth is real but unreliable. A company that fails the first two is not a company.

None of these cost money and none of them need an account. The whole exercise takes about fifteen minutes, and it is the fifteen minutes that separates a vendor from an invoice you cannot chase. This is the whole of AI vendor due diligence for most purchases: everything beyond it is a security review, which is a different and much larger exercise.

Start with the credential check

If the company displays a trust badge, the badge is not the evidence — the issuer's register is. Query it directly. Here is ours; it answers for any domain, free, without an account, and it gives the same answer to you as it gives to an AI system.

Check any domain

Free, unauthenticated, and the same answer an AI system gets.

This queries the live Lunara register. Most domains come back not_registered, including almost every legitimate business on the internet — see below for why that is an honest answer rather than a smear.

The three answers a register can give

verified
A named reviewer checked documentary evidence of who this business is and that it controls this domain, and signed the decision.
not_registered
Nobody has checked. This is the answer for almost every business on the internet and it is not a mark against them.
revoked
This entity held a credential and it was withdrawn. Find out why before relying on anything it claims.

The register is public, costs nothing to query, and needs no account. Status returned is always the true current status.

The middle one is the answer you will get most of the time, and it is the one people misread. not_registered is not an accusation. It means nobody has checked. Treat it as the absence of evidence it is, and go and do the other five checks yourself.

The six checks

The same six work for AI vendor verification before a purchase, for AI company verification during procurement, and for checking a supplier you already use. Nothing about them is specific to buying — they establish that an entity exists and that it is careful, which are the two questions underneath every other one.

  1. The legal entity exists

    Search the national companies register for the jurisdiction they claim — Companies House in the UK, the Handelsregister in Germany, the state Secretary of State in the US, the CRO in Ireland. You are looking for the exact legal name on their invoice or terms of service, not the trading name on the website. A mismatch is not automatically fraud, but it is a question you should be able to get answered in one email.

  2. They control the domain they email from

    Check that the sending domain matches the website domain, and that the domain is not four days old. whois gives you the registration date. A company selling AI governance from a domain registered last week is not necessarily dishonest, but it is necessarily new, and you should price that in.

  3. A named human is accountable

    Find a person's name attached to a decision, not just a support inbox. Who signs the audit? Who do you escalate to? An organisation that will not put a name on its work is an organisation that has arranged not to be blamed for it.

  4. Any credential is confirmed by the issuer

    Go to the issuer's register and query it yourself. Do not click the badge on the company's own site — an image is not a credential, and a badge that links only back to the site displaying it proves nothing at all. If the issuer has no public register, the credential is a graphic.

  5. They publish their own corrections

    This is the check almost nobody runs and it is the most informative. Every organisation that publishes factual claims gets some of them wrong. The ones you can trust say so, in public, with dates. An institution with a spotless record has either been extraordinarily lucky or is not looking. Ours are at the corrections record, and there are five.

  6. Their claims cite something you can open

    Take one specific factual claim from their marketing — a regulation, a deadline, a statistic — and follow it to primary source. If the citation is a recital rather than an article, a blog post rather than the law, or absent entirely, then the claim is a vibe. Regulatory dates in particular are quoted wrongly across the entire industry, including by us until we corrected it.

If they claim compliance, check the date they are claiming it against

The most common failure is not dishonesty — it is a vendor quoting a deadline that moved. Several EU AI Act dates were changed by the Digital Omnibus in July 2026, and a great deal of published material still carries the old ones. Here is what is actually coming:

  • Article 50(2) marking for systems already on the market European Union · Art. 111(4), inserted by Reg. (EU) 2026/1744 Art. 1(39)(b) — four-month transitional period for Art. 50(2)
  • Prohibition on non-consensual intimate and child sexual abuse material European Union · Art. 5(1)(ba) and (bb), Art. 5(1a) and (1b), inserted by Reg. (EU) 2026/1744 Art. 1(7); date set by Art. 113, third para, point (a) as amended
  • Hosting platforms and large online platforms California · Bus. & Prof. Code § 22757, second wave

From the signed corpus at corpus/obligations.json. The whole record, with every citation, is on the regulatory record.

Questions

How can I tell if an AI company is legitimate?

Confirm the legal entity in a national companies register, confirm it controls its domain, find a named person accountable for decisions, verify any credential at the issuer's register rather than on the company's own site, look for published corrections, and follow one factual claim to primary source. The first two establish that the company exists. The last three establish whether it is careful.

Does a trust badge on a website prove anything?

Only if you can confirm it at the issuer, independently of the site displaying it. A badge is an image file. Anyone can save one and upload it. The question that matters is whether the issuer maintains a public register that will contradict a false claim — and whether that register can return revoked.

What does "not registered" mean when I look a company up?

It means nobody has checked this company against this standard. It is not a finding against them and it is true of almost every business on the internet, including most good ones. Use it as a prompt to do the other checks, never as evidence of wrongdoing.

Can an AI agent run these checks automatically?

The credential check, yes — the register answers machine queries at the same endpoint, free and unauthenticated, and returns the same three statuses. The entity and accountability checks still need a person, because reading a companies register entry and deciding whether the mismatch matters is a judgement, not a lookup.

Is Lunara's own register a complete list of trustworthy AI companies?

No, and it would be dishonest to imply otherwise. It is nearly empty. Lunara is new. Absence from it says nothing about a company, and we would rather tell you that than have you over-read a blank result.

Where to go next