THE GLOBAL TRUSTED TECH STANDARD

The xGTT Standard

Trusted technology is technology whose design, development, and supply chains are rooted in democratic values that advance both innovation and freedom, and whose adoption fosters accountable, contestable, and governable relationships between trusted partners, rather than coercive or unaccountable dependency.

The xGTT Standard translates that definition into something that can be examined against evidence, built on two dimensions of trust. The first is technological excellence: the practices developed across technologically advanced democracies to produce secure, resilient, innovative, and competitive technologies that deliver real-world impact. The second is compatibility with democratic values: whether the companies behind those technologies operate in ways consistent with the rule of law, human rights, intellectual property protections, integrity, transparency, accountability, reciprocity, and national sovereignty.


xGTT’s definition of trust is grounded in the laws, regulations, government programs, international standards, and established practices across 18 technologically advanced democracies: the United States, United Kingdom, Germany, France, Japan, South Korea, Taiwan, the Netherlands, Sweden, Switzerland, Israel, Denmark, Finland, India, Estonia, Canada, Australia, and New Zealand.

The xGTT Methodology

Around the world, governments, companies, and international institutions are converging around the idea that critical technology must be trusted. What has been missing is a common definition of what “trusted technology” actually means in practice. xGTT was built to provide one.

That definition is expressed through the Standard itself. Taken together, xGTT’s Red-Line Disqualifiers and criteria define the conditions that make the organization behind a critical technology worthy of trust. They look beyond technical performance to security, accountability, transparency, rule of law, intellectual property protection, human rights, and other factors that matter when governments, companies, and institutions decide whom to depend on.


The criteria are grounded in a comprehensive analysis of 18 technologically advanced democracies at the forefront of both critical technology innovation and governance. xGTT examines their laws, regulations, standards, government programs, procurement practices, and other authoritative frameworks, identifying the practices that recur across different democratic systems and translating them into a common methodology.


The methodology was then deliberately stress-tested. Over 16 testing rounds, more than 20 companies across seven critical technology sectors were evaluated by six different AI systems, producing more than 250 reports. Difficult cases exposed ambiguities, weak evidence rules, and inconsistencies that were corrected before launch. The process ultimately led xGTT to abandon numerical scoring in favor of transparent, criterion-level findings backed by public evidence.


In aggregate, the 10 Red-Line Disqualifiers and 21 criteria define what “trusted technology” means in methodological terms, filling a gap the free world has long lacked. Applied through xGTT’s evidence-based evaluation process, they enable a deliberate, structured assessment of company trustworthiness across critical and emerging technologies.

RED LINE CRITERIA

The Evaluation Process

Before any criterion is evaluated, every company is checked against 10 Red-Line threshold conditions. Any single trigger immediately disqualifies the company from further evaluation. A confirmed Red-Line finding cannot be offset by good performance elsewhere in the xGTT Standard, and disqualification lifts only upon formal resolution of the underlying matter.

An allegation alone does not trigger a Red-Line finding. Unadjudicated allegations are disclosed in the evaluation record, but only a confirmed, adjudicated, or formally designated finding closes the gate. Disqualification is lifted only upon formal resolution documented by the issuing government authority or court.

10 RED LINE DISQUALIFIERS

A company that clears the Red-Line Gate proceeds to evaluation against the applicable criteria in the four dimensions of trust.

01

Sanctioned Entity

the company is subject to an active government sanctions designation

02

Conduct-Based Export Control Violation

an adjudicated violation of export control law.

03

State Ownership or Control by an Adversarial Authoritarian Jurisdiction

the company is owned or controlled by a government designated as adversarial and authoritarian.

04

Active Espionage or IP Theft Conviction

a conviction for espionage or intellectual property theft.

05

Critical Infrastructure Sabotage Finding

an adjudicated finding of sabotaging critical infrastructure.

06

Terrorism Financing Designation

a formal government designation for financing terrorism.

07

Systematic Human Rights Abuse Finding

an adjudicated finding of systematic human rights abuse.

08

Prohibited Military End-Use Transfer

a confirmed transfer to a prohibited military end use.

09

Unauthorized Model Weight Acquisition or Distribution

knowingly building on another company's stolen AI model weights.

10

Prohibited Non-Consensual or CSAM-Generating AI

developing or deploying AI systems designed to generate non-consensual intimate imagery or child sexual abuse material.

CET SECTORS COVERED

The Four Dimensions Of Trust

Before any criterion is evaluated, every company is checked against 10 Red-Line threshold conditions. Any single trigger immediately disqualifies the company from further evaluation. A confirmed Red-Line finding cannot be offset by good performance elsewhere in the xGTT Standard, and disqualification lifts only upon formal resolution of the underlying matter.

An allegation alone does not trigger a Red-Line finding. Unadjudicated allegations are disclosed in the evaluation record, but only a confirmed, adjudicated, or formally designated finding closes the gate. Disqualification is lifted only upon formal resolution documented by the issuing government authority or court.

1

Legal & Regulatory Compliance

Whether the company has a record of major legal or regulatory violations.

  • No Major Corruption Conviction: free of a criminal corruption conviction, guilty plea, or deferred prosecution agreement within five years.

  • No Major Fraud Enforcement Action: free of a major securities or financial fraud enforcement action within five years.

  • No Repeated Privacy Enforcement: free of a confirmed pattern of repeated, significant data-protection penalties within five years.

  • No Adjudicated Large-Scale IP Infringement: free of a judicial finding of large-scale, willful intellectual-property infringement within five years.

2

Democratic Government Trust

A democratic government's decision to contract with or invest in a company is an indicator of trustworthiness.

3

Transparency & Documentation

Whether the company discloses the information decision-makers need to evaluate it.

4

Technical Security Practices

The company's security, safety, and governance practices for the technology it builds.

Example Evaluation

To show what an xGTT evaluation looks like in practice, you can review a complete, criterion-by-criterion evaluation of a fictional company.

The example walks through the full evaluation sequence:


  • Entity confirmation: establishing which legal entity is being evaluated.

  • Applicability determination: identifying which criteria apply, based on the company's sector and business model.

  • Red-Line check: screening against the ten automatic disqualifiers.

  • Criterion-by-criterion findings: for each applicable criterion, a PASS, FAIL, UNCLEAR, or N/A finding, with an Evidence Block showing the specific public record the finding rests on and a link to the source.