Trustworthy AI For A Better World
Undated · The document prints no date, no version and no changelog. The only temporal marker on the page is a "Copyright © 2026 NVIDIA Corporation" footer, which dates the site rather than the framework, so no publication date is asserted here. The record id carries UNDATED rather than a year for the same reason.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
NVIDIA argues that trustworthiness is an engineering property of the stack rather than a compliance layer bolted on afterwards, and it commits the company to four named principles: privacy, safety and security, transparency, and nondiscrimination. The framing sentence is that "AI should respect privacy and data protection regulations, operate in a secure and safe way, function in a transparent and accountable manner, and avoid unwanted biases and discrimination." It accepts external, government-brokered soft law as binding on itself — "We are committed to safe and trustworthy AI, in line with the White House Voluntary Commitments and other global AI Safety initiatives" — which is notable for a company that elsewhere argues hard against binding rules on chips. Its account of transparency is unusually concrete and lay-facing: make the technology understandable to people and "explain, in non-technical language, how an AI system arrived at its output." Because NVIDIA sits upstream of the companies that deploy models, the document pushes responsibility down the supply chain rather than claiming it all: it publishes free open-source documentation templates (the NVIDIA/Trustworthy-AI GitHub repo) so that customers and partners can "responsibly develop AI and advance transparency and accountability across the AI supply chain," and it asserts that model cards are "the standard for increasing confidence in the development lifecycle, demonstrating compliance, and encouraging transparency," with a Model Card Generator to automate them. The principles are then tied to specific mechanisms rather than left abstract — NVIDIA Halos as a full-stack safety regime for physical AI (autonomous vehicles and robotics, unifying architecture, models, chips, software, tools and services), NeMo Guardrails to keep LLM applications accurate, appropriate, on topic and secure, and digital watermarking embedded directly into AI-generated audio, images, text and video "to safeguard against misinformation and misattribution." The nondiscrimination pillar is illustrated by commitments that read as data-sovereignty and accessibility positions: the Te Hiku Media Māori/NZ-English speech system "built and owned by its own language community," and the Signs Platform ASL dataset built with the American Society for Deaf Children and RIT and made publicly available. NVIDIA extends the same four principles to its research function, saying it maintains "our guiding principles of privacy, transparency, nondiscrimination, and safety and security in all research practices and methodologies." The page closes by positioning NVIDIA as a convener with regulators rather than an opponent of them, pointing to GTC sessions featuring "government leaders paving the way for AI regulation and trustworthiness," including a Foundational Concepts in AI Safety session from GTC DC.
Stated positions (14)
- Privacy pillar — "AI should comply with privacy laws and regulations, and meet societal norms for personal data and information privacy"; NVIDIA states compliance with data-protection law as a design requirement, not a jurisdictional question.
- Safety and security pillar — AI systems must "perform as intended and avoid unintended harm and malicious threats"; safety and adversarial security are treated as one obligation, not two.
- Transparency pillar — "Make AI technology understandable to people. Explain, in non-technical language, how an AI system arrived at its output." Explanation is owed to the lay public, not only to auditors or regulators.
- Nondiscrimination pillar — "Minimize bias in our AI systems and give all groups an equal opportunity to benefit from AI"; framed as equal access to benefit, not merely avoidance of harm.
- Accepts voluntary government-brokered commitments as binding on itself: "We are committed to safe and trustworthy AI, in line with the White House Voluntary Commitments and other global AI Safety initiatives."
- Trustworthiness is an engineering property, not a compliance wrapper — the principles are "foundational to our end-to-end development and essential for the technical excellence that enables partners, customers, and developers to do their best work."
- Responsibility is pushed along the supply chain: NVIDIA publishes free, open-source documentation templates (the NVIDIA/Trustworthy-AI GitHub repo) explicitly to "advance transparency and accountability across the AI supply chain."
- Model cards are asserted as the industry standard — "the standard for increasing confidence in the development lifecycle, demonstrating compliance, and encouraging transparency" — with an automated Model Card Generator to remove the manual-effort excuse.
- Physical AI needs a full-stack safety regime: NVIDIA Halos "unifies architecture, AI models, chips, software, tools, and services to ensure the safe development of physical AI like autonomous vehicles and robotics."
- Runtime constraint of deployed LLMs is a named obligation — NeMo Guardrails to keep LLM-powered applications "accurate, appropriate, on topic, and secure."
- Content provenance by watermarking: NVIDIA says it is "the first external user to embed digital watermarks directly into AI-generated audio, images, text, and video content to safeguard against misinformation and misattribution without compromising video quality" (with Google DeepMind's SynthID).
- Data sovereignty as the model for language AI — the Te Hiku Media bilingual Māori/NZ-English speech system is held up because it is "built and owned by its own language community."
- Accessibility datasets as a public good — the Signs Platform ASL work with the American Society for Deaf Children, Hello Monday/DEPT and RIT is built as "a publicly available dataset for accessible technologies."
- The same four principles are asserted to bind NVIDIA Research's methods, not just shipped products: the guiding principles are maintained "in all research practices and methodologies."
About this document
A marketing hub page on nvidia.com, not a policy paper: roughly 1,000 words of body copy interleaved with product tiles, partner spotlights and event promotion. It is one of three pillars of NVIDIA's AI Trust Center (alongside Safer Physical AI and Secure AI), headed "Trustworthy AI", with the browser title "Trustworthy AI For A Better World". Eight sections run in order: an opening statement; "Our Guiding Principles for Trustworthy AI", which carries the whole normative content — four pillars (Privacy, Safety and Security, Transparency, Nondiscrimination) at one sentence each; "Methods and Technologies"; "Our Trustworthy AI Solutions" (Halos, NeMo Guardrails, Model Card Generator, NeMo Data Curator, TAO Toolkit, Confidential Computing, SteerLM); "Partnering for Trustworthy AI Technology" (Te Hiku Media, Google DeepMind's SynthID, the SIGNS ASL platform); "Trustworthy AI in the News"; "A Commitment to Research", carrying eight arXiv links plus NVIDIA's own Frontier AI Risk Assessment PDF; and a GTC conference promotion. There is no date, no version number, no "last updated" and no named author — the only temporal marker is the footer "Copyright © 2026 NVIDIA Corporation". Everything it commits is self-directed: what NVIDIA will build, publish and open-source. It asks nothing of any government, names no statute, regulator or jurisdiction, and offers no legislative position; its single external anchor is the White House Voluntary Commitments. Outbound links go to GitHub (NVIDIA/Trustworthy-AI), papareo.io and signs-ai.com.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Explanation owed to the lay public, not only to auditors
Transparency pillar: "Make AI technology understandable to people. Explain, in non-technical language, how an AI system arrived at its output." The audience named is people generally — not deployers, auditors or regulators — and the object is the individual output, not the system as a whole.
The AI Act reaches the same place by two narrower routes: Art. 13 requires high-risk providers to supply instructions enabling deployers to interpret the output, and Art. 86 gives an affected person a right to a clear and meaningful explanation of an individual decision taken with an Annex III high-risk system. NVIDIA's audience is wider and its object the same, but the pillar is one sentence with no scope, no trigger and no recipient who can demand it, where Art. 86 is a right a person exercises.
Colorado SB24-205 was the closest binding US analogue until its repeal on 14 May 2026: a deployer had to disclose the principal reasons for an adverse consequential decision and allow correction and human appeal. NVIDIA's commitment is broader in audience and weaker in force — nothing on the page attaches it to a decision, a consumer or a remedy. No federal instrument imposes an explainability duty on a private AI developer, and with Colorado repealed no state one is operative either.
Model documentation pushed along the AI supply chain
Model cards asserted as "the standard for increasing confidence in the development lifecycle, demonstrating compliance, and encouraging transparency", backed by an automated Model Card Generator and free open-source Model Card++ templates in the NVIDIA/Trustworthy-AI GitHub repo, published to "advance transparency and accountability across the AI supply chain" — that is, for other people's models, not only NVIDIA's.
Art. 53 with Annexes XI and XII requires a GPAI provider to keep technical documentation and pass specified information to downstream providers — a duty owed to its own customers and to the AI Office. NVIDIA publishes the documentation artefact and the tooling to anyone, unconditioned on being in its supply chain, which the Act neither requires nor contemplates.
America's AI Action Plan encourages an evaluation and interpretability ecosystem and federal adoption of AI documentation practice, but imposes no documentation duty on a private developer. NVIDIA ships the artefact and the generator voluntarily and open-sources the templates.
Frontier and systemic risk: present as research, absent as commitment
The four pillars contain no frontier, catastrophic or systemic-risk commitment. Frontier risk appears only as a linked paper, "NVIDIA's Frontier AI Risk Assessment", inside "A Commitment to Research". The page names no capability threshold, no pre-deployment evaluation gate, no red-teaming commitment, no incident-reporting channel and no third-party evaluation.
Art. 55 requires a provider of a GPAI model with systemic risk to perform model evaluation including adversarial testing, assess and mitigate systemic risk, track and report serious incidents to the AI Office, and ensure adequate cybersecurity — in force for GPAI models since 2 August 2025. None of these appears as a commitment; risk work is presented as published research, not as an obligation NVIDIA accepts.
SB 53 requires a large frontier developer to publish a frontier AI framework, publish a transparency report at or before deployment, and report a critical safety incident to Cal OES within 15 days. Four principles and a research paper are not a framework in SB 53's sense, and the document commits to no reporting route at all.
Safety and adversarial security fused into one obligation, discharged inside the product
One pillar covers both accident and attack: AI systems must "perform as intended and avoid unintended harm and malicious threats". It is discharged through shipped mechanisms — NeMo Guardrails to keep LLM-powered applications "accurate, appropriate, on topic, and secure", Confidential Computing, the TAO Toolkit — rather than through process or disclosure.
Art. 15 fuses the same two: high-risk systems must achieve an appropriate level of accuracy, robustness and cybersecurity and be resilient against third parties altering their use or performance by exploiting vulnerabilities, including data poisoning and adversarial examples. NVIDIA's framing matches the Act's; what the Act adds is that the level must be declared and the measures documented.
US national-security AI policy of this period treats control over who obtains frontier AI capability and the compute behind it as part of AI security. NVIDIA's security pillar is entirely product-internal — guardrails, confidential computing, secure inference — and the document says nothing about access to, or diversion of, the hardware and models it supplies, which is the security question the state asks of this company specifically.
Bias framed as equal opportunity to benefit rather than as a duty to prevent harm
Nondiscrimination pillar: "Minimize bias in our AI systems and give all groups an equal opportunity to benefit from AI." The second clause is distributive — access to benefit — not avoidance of discriminatory harm. Supported by NeMo Data Curator, SteerLM and cited research on bias in benchmarking, and illustrated by the Te Hiku Media Māori/NZ-English speech system ("built and owned by its own language community") and the SIGNS ASL dataset.
Art. 10 makes bias a procedural duty: high-risk training, validation and test datasets must be examined for possible biases likely to affect health, safety or fundamental rights, with measures to detect, prevent and mitigate them; Art. 27 adds a fundamental-rights impact assessment for certain deployers. NVIDIA states an aim and names tools but commits to no examination, no documentation and no assessment.
Colorado SB24-205 imposed a reasonable-care duty on developers and deployers of high-risk AI to protect consumers from algorithmic discrimination, with impact assessments, a risk-management programme and a duty to report known discrimination risk to the Attorney General. "Minimize bias", with no method, threshold or reporting route, does not reach that — and the equal-opportunity-to-benefit framing is an access claim Colorado never made. The act was repealed on 14 May 2026, so the comparison is with a standard the US has since let lapse.
Provenance of synthetic content by watermarking at generation
NVIDIA claims to be "the first external user to embed digital watermarks directly into AI-generated audio, images, text, and video content to safeguard against misinformation and misattribution", using Google DeepMind's SynthID — all four modalities, including text, and asserted to work "without compromising video quality".
Art. 50(2) requires providers of AI systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format detectable as artificially generated, applicable from 2 August 2026. Watermarking at generation is exactly that duty's technique and NVIDIA adopted it ahead of the date. The Act's version is enforceable and carries its own carve-outs and effectiveness conditions that a marketing claim does not engage.
No federal instrument requires provenance marking of synthetic content by a private developer. America's AI Action Plan approaches synthetic media from the evidentiary side — deepfake evaluation and forensic standards work at NIST — rather than by obliging marking at the point of generation. NVIDIA implements at generation what federal policy so far only studies.
Physical AI safety as a full-stack, open-sourced regime
NVIDIA Halos "unifies architecture, AI models, chips, software, tools, and services to ensure the safe development of physical AI like autonomous vehicles and robotics", with the Halos Outside-In Safety Blueprint published open-source on GitHub. Safety is asserted to run from silicon to service rather than being a layer added at the application.
The draft high-risk classification guidelines address when a system is high-risk, including as a safety component of an Annex I product. Road vehicles under EU type-approval are largely carved out of the AI Act's own regime and left to sectoral law, and Annex I embedded systems do not bite until 2 August 2027. NVIDIA proposes — and publishes — a stack-wide safety regime for a category the Act mostly defers.
America's AI Action Plan promotes robotics and physical AI as an industrial objective and sets no safety regime for embodied AI; US autonomous-vehicle safety sits with NHTSA and state law, outside any listed AI instrument. There is no US AI-law obligation here to measure Halos against.
The only external anchor is a voluntary commitment, and nothing is asked of government
"We are committed to safe and trustworthy AI, in line with the White House Voluntary Commitments and other global AI Safety initiatives" is the sole external regime the document binds itself to. It names no jurisdiction, statute or regulator, takes no position on federal preemption of state AI law, on regulating models versus applications, or on the EU AI Act, and makes no ask of any legislature.
NVIDIA is a GPAI-model provider and a supplier of AI components into Annex I products, so the Regulation's enforcement architecture applies to it — the AI Office and national market surveillance authorities, with penalties reaching €15M or 3% of worldwide turnover for most provider breaches. The document neither acknowledges that regime nor says how it will meet it, resting instead on a non-binding US commitment.
EO 14179 revoked EO 14110 and set a deregulatory federal posture; the White House Voluntary Commitments are a 2023 artefact of the prior administration that current federal policy has moved past. NVIDIA still holds itself to them — keeping a self-binding no current US instrument requires — while asking nothing of government in return.
NVIDIA sits further from both regimes than most peers, but in an unusual direction: this is a self-binding engineering document with no legislative agenda at all, so nearly every mapping compares a voluntary practice to a duty rather than two positions to each other. Against EU law it matches the Act's techniques — documentation down the supply chain, watermarking at generation, fused robustness-and-cybersecurity — while omitting the procedural spine of evaluation, assessment, incident reporting and declared performance levels that makes those duties enforceable, so it reads ALIGNED on method and FALLS_SHORT on obligation. Against the US the relation inverts: the current federal posture asks less than NVIDIA already volunteers, and the US pressure that actually binds this company — state discrimination and frontier-safety statutes, and national-security control over who obtains its compute — is precisely what the document does not address.
Source
https://www.nvidia.com/en-us/ai-trust-center/trustworthy-ai/- Date on the page:
- None. The page prints only a "Copyright © 2026 NVIDIA Corporation" footer.
- Source checked:
- opened and confirmed on 2026-09-18