.png)
Safety and Responsibility
Tavus builds models that see, hear, speak and look the way people do, so that talking to a machine can feel like talking to a person. Griffin, our first Human Interaction Model, is the clearest example of where that work is going, and of why it has to be done carefully. We believe this is how technology becomes more accessible and more useful, and we recognize this carries a particular responsibility. Read a note from our CEO on the impact of this technology.
The mechanics of talking to a machine should disappear. The fact that it is a machine should not. This page covers how we evaluate what is built on Tavus, how we release new models and run them in production, and how we respond when something falls short.
Evaluations
Evaluation on Tavus runs at two levels: on our models before they are released, and on what people build with them once they are. Both are continuous, and both end in a decision made by a person.
Human evaluation
Automated systems do the first pass with human reviews following. Our team reviews what the systems flag, evaluates the behavior of each new model before it moves toward release, and decides what action to take on an account.
Continuous monitoring
We monitor how the platform is used on an ongoing basis, track emerging patterns of misuse, and update our detection systems and our policies as those patterns change. Before any model moves to a wider stage of release, it goes through an extensive evaluation that detects misuse including impersonation and deception, and the results determine whether it proceeds. What we observe in production feeds back into both the detection systems and the release gates.
Automated systems to flag content
Every PAL created on Tavus is evaluated by systems that screen how it is configured and the instructions it is given for scams, impersonation, attempts to conceal that it is an AI, and other prohibited uses. Anything that trips a guardrail is flagged for human review. We dedicate a fixed share of our compute to this evaluation, and the systems improve as new forms of misuse are identified.
Releases and production
Our models are served through our platform rather than distributed as weights, so access to them can be governed, monitored and withdrawn. That is what makes the controls below possible:
Gated releases
When our research produces a model that could be mistaken for a real person, we hold the full version back and widen access only as disclosure and safety measures are in place.
That is where Griffin is today. The full model is not released, Griffin-Lite is limited to a small group of trusted testers, and it will reach the platform in stages, each gated on the safeguards built for the one before it.
Access to our most capable models is limited to vetted customers and use cases. We review who is building on these models and what they intend to build before access is granted, and we retain the ability to withdraw it.
Audio and video watermarking
Every conversation We are implementing audio and video watermarking across the media our models generate. The watermark is embedded in the generated frames and audio, so that content created on Tavus can be identified as AI-generated after the fact, outside a live conversation as well as within one. Watermarking and disclosure solve different problems: disclosure tells a person they are speaking with an AI in the moment, and watermarking allows a recording to be identified as synthetic later, whoever is holding it.
Disclosure requirements
People have a right to know when the person on the other side of the screen is an AI. We build for that to be clear in the experience itself, where the conversation happens, rather than buried in terms of service. Every experience Tavus builds identifies itself as AI in two ways: a visible indicator in the video feed, and a spoken statement from the model itself. This is on by default in every market, not only where the law requires it.
Our platform exists so that businesses and builders can deploy AI openly. It is not available for impersonating real people, or for deceiving anyone about who, or what, they are talking to.
We are also aligning the platform with the transparency requirements of the EU AI Act ahead of their enforcement, so that disclosure is the standard wherever Tavus is used.
Limiting use
A replica of a real person requires that person's explicit, informed consent, and may only be used within the scope of the consent they have given. Anyone may withdraw consent at any time and request that their likeness be removed from the platform.
Our platform may not be used to run scams or solicit money under false pretenses, to impersonate real people, or to conceal that something is AI in order to deceive. It may not be used to covertly record, locate or manipulate anyone, for sexual coercion or any sexual content involving minors, or for credible threats, harassment or hate.
We also limit sensitive uses. Political advertising requires our prior approval, and our stock replicas cannot be used in political campaigns, news broadcasts or content about polarizing current events. These rules apply to everything built on Tavus, from the API to PALs, and they are written into our Acceptable Use Policy. They are enforced in three places: in the policy itself, in the automated systems that evaluate every PAL, and in human review. Accounts that violate them are warned, and repeated violations result in suspension.
Safety doesn't stop
Policies and release gates are the starting point, not the finish line. We monitor how the platform is used, we enforce our Acceptable Use Policy, and we update both as our models and the rules around them change.
If you believe a Tavus replica is being used without consent, or to deceive someone, write to support@tavus.io. We will look into it and act.
Building AI that feels human is a way to make technology more humane. We will keep holding our work, and ourselves, to that standard.