Back to Blog

ISO 42001: A New Standard of Trust in AI Development

Nissim Maatouk
,
Head Of Security
,
,
November 11, 2024
Blog posts

In a meaningful step toward greater trust and transparency in AI, AI21 Labs has become the first company that develops and operates AI cloud platforms to achieve the new ISO42001 certification. 

This certification, designed specifically for companies that develop AI, recognizes not just the responsible use of AI but also the responsible creation of AI technology from the ground up. For our customers and partners, it’s a new level of assurance that the AI systems we develop are built with both high ethical and security standards in mind.

This new ISO42001 certification joins AI21’s extensive collection of certifications, including ISO27001, ISO27017, and ISO27018, reinforcing our commitment to robust security, privacy, and responsible AI practices across all our offerings. Nissim Maatouk, our Head of Security, spearheaded the efforts to achieve not only the ISO42001 certification, but also our second SOC2 and our full suite of ISO certifications. His leadership has been instrumental in establishing the security and compliance foundation that underpins all of AI21's offerings.

What ISO 42001 Means for AI Companies

The ISO42001 certification introduces a framework that recognizes the unique responsibilities of companies that develop AI, particularly large language models. In contrast to the ISO42001 certification previously awarded to companies using AI systems, the ISO42001 certification marks a shift in focus to those who build the systems, such as AI21, whose models can be deployed and trusted across various platforms.

Achieving ISO42001 means that our development processes meet stringent standards for quality, transparency, and security. It’s a new layer of accountability designed specifically for companies whose work focuses on creating AI, ensuring that the models we produce are aligned with ethical considerations, rigorous testing, and data privacy requirements.

Certified Product Portfolio for Business Flexibility

The ISO42001 certification encompasses AI21’s entire expanded product portfolio, underscoring our commitment to responsible AI across every tool and service we offer. Beyond the Jamba model suite, AI21 provides a robust set of solutions, including APIs, SDKs, browser plugins, and the Studio platform, designed to allow businesses to customize, deploy, and integrate AI capabilities seamlessly across diverse environments – from desktop applications to web services.

Our AI cloud platform, which operates on major providers such as Google Cloud Platform (GCP) and is supported by scalable Kubernetes architecture, ensures that customers have secure, flexible options for deployment. The Studio platform enables customers to upload data directly into Retrieval Augmented Generation (RAG) workflows, while API key integration provides a streamlined and secure way to manage client identification, usage, and billing. This certification validates the security, reliability, and ethical standards of our entire portfolio, giving businesses added assurance that every aspect of our offerings meets stringent international criteria for quality and responsible AI development.

Building Trust Through Rigorous Standards

As part of its commitment to transparency, Technical Director Daniel Gissin shared insights into AI21’s model training and benchmarking approach. AI21’s models are continually evaluated and refined based on extensive benchmarks, including comparisons with other commercial and academic models such as Meta’s Llama. Gissin referenced research conducted across 500 test cases, designed to test the models’ robustness on complex, real-world tasks. In one example, the Jamba model was tasked with authoring a 30-paragraph article on aluminum in food storage, showcasing the model’s capability to handle specific, in-depth requests.

During pre-training, AI21's data team, led by CTO Barak Lenz, carefully considers a wide range of factors to enhance the model’s effectiveness and resilience. Decisions around supported programming languages, preferred architectures, and the most efficient machine targets are balanced to ensure portability and performance. Data security also plays a crucial role, with protections against potential vulnerabilities like data poisoning and inversion attacks. This careful preparation enables AI21’s models to work seamlessly on customer infrastructure, with Docker-based setup for ease of deployment.

Responsible Model Design 

Our product team also explained some of the model’s specifications designed to address customer concerns. AI21’s models operate in traceless mode, enhancing privacy, and can be wrapped with code for augmentation. To prevent hallucinations – a known challenge in generative AI – Jamba models employ verification by cross-referencing results before delivering outputs. Part of AI21’s development lifecycle also includes rigorous alignment benchmarking to ensure the model’s responses remain reliable and consistent.

Why It’s Important to Our Customers

At AI21 Labs, we understand that trust is paramount when it comes to adopting AI. Earning ISO42001 certification reflects our commitment to helping our customers feel confident in the technology we develop. As we create AI models that will be integrated into various business and consumer applications, we want our partners to know that we adhere to the highest standards from the very start – from data handling to model transparency and ongoing safety evaluations.

ISO42001 is more than just a label – it’s a promise that the technology we build is designed with a forward-looking commitment to ethical and secure development. It reassures our customers that when they use our models, they’re using tools that have undergone rigorous checks to mitigate risk and enhance reliability.

Setting a Standard for Responsible AI Creation

Being the first AI-building company to achieve ISO42001 is not a distinction we take lightly. We see this as a step toward a more accountable industry, where the developers of AI technologies are held to high standards that benefit end users and society at large. By leading in this area, we hope to contribute to a broader shift, encouraging other AI-building organizations to uphold similar commitments.

If you're interested in learning more about our approach to responsible AI, including private AI deployment options tailored to your needs, reach out to us – we’d be glad to discuss how we can support your journey with secure, flexible AI solutions.

Discover more