EU AI Act Article 50(1)
Direct human-AI interaction disclosure
The scan cannot determine direct interaction from public signals alone.
CUSTOMER FACTUAL CONFIRMATION REQUIREDFree tool
Enter a public AI product URL for observable EU AI Act Article 50 signals, or submit authorized private workflow evidence when the relevant disclosure, export or provenance record sits behind login.
EU AI Act Article 50 scanner
Find likely EU AI Act Article 50 surfaces, map them to applicable controls, implement fixes, test them continuously, and generate evidence for counsel, buyers, and engineering leaders.
Scope first
Customer facts feed the rule engine before any scan finding is interpreted.
Live scope matrix
EU AI Act Article 50(1)
The scan cannot determine direct interaction from public signals alone.
CUSTOMER FACTUAL CONFIRMATION REQUIREDEU AI Act Article 50(2)
The Code-of-Practice path is not confirmed, so the report keeps both Code and alternative-measures evidence visible.
TECHNICALLY UNVERIFIABLEEU AI Act Article 50(3)
No emotion recognition or biometric categorisation fact is currently indicated.
TECHNICALLY UNVERIFIABLEEU AI Act Article 50(4)
Deepfake or public-interest publication facts are contextual and should be reviewed before runtime controls are disabled.
TECHNICALLY UNVERIFIABLEEU AI Act Article 50(5)
Any human-facing disclosure or label should be clear, distinguishable, accessible, and linked to the affected surface and policy version.
CUSTOMER FACTUAL CONFIRMATION REQUIREDCurrent scan workspace
The report keeps public observations, technical verification gaps, and counsel decisions separate. It never declares EU approval or guaranteed legal compliance.
Shareable artifact
Every scan creates a customer-ready report URL with observations, likely obligations, confidence, source versions, technical recommendations, and counsel-review states.
EU AI Act Article 50(1)
Add a runtime disclosure component attached to every direct AI interaction surface, with locale and accessibility variants.
EU AI Act Article 50(2)
Use a marking adapter strategy: metadata or C2PA where appropriate, paired with signed evidence and a workflow-specific robustness suite.
EU AI Act Article 50(3)
Maintain an exposed-person notice at first exposure to the operation of the system, linked to a privacy processing record and counsel-approved exception path.
EU AI Act Article 50(4)
Route relevant releases through a labelled publication workflow with reviewer sign-off and durable provenance.
EU AI Act Article 50(5)
Maintain a label copy registry, per-surface policy bindings, and event-level evidence export.
AI Surface Inventory
Each AI-facing surface carries owner, modality, role, user population, publication status, EU AI Act Article 50 mapping, implementation status, and evidence state.
mixed / unknown
EU AI Act Article 50(1), EU AI Act Article 50(2), EU AI Act Article 50(3), EU AI Act Article 50(5)
Not verifiedGitHub repository scanner
Repository scans map provider SDKs, generation routes, output pipelines, labels, metadata, publishing paths, and transparency logic to files and lines.
GitHub
Connect a public repository or run the server with GitHub CLI/token access for private repositories.
Least-privilege read access is enough for detection. Write access is only needed to open fix PRs.Generate/Fix PR
Fix kits include code, configuration, and review records. Draft PR creation works when a write-capable GitHub token is available and PR creation is explicitly enabled on the server.
EU AI Act Article 50(1) / minutes
Production-ready accessible disclosure component for direct human-AI interaction, with policy version and evidence hook props.
customer chatbot / direct AI interaction surfaceEU AI Act Article 50(2) / hours
Adds a TypeScript runtime wrapper that records policy decision, provenance node, sidecar metadata, and known marking limitations.
generation API routeEU AI Act Article 50 / minutes
Runs repository signal detection on every pull request and uploads a machine-readable implementation report.
.github/workflows/isgenai.ymlEU AI Act Article 50(3)/(4) / requires review
Creates an auditable override record for contextual determinations such as human editorial responsibility or obvious AI context.
emotion-biometric/deepfake/public-interest/assistive-editing determinationsControl plane, not a badge
The moat is the graph from policy to runtime event to provenance to evidence. A label alone is too fragile for serious AI products.
Versioned EU AI Act Article 50 rules become deterministic controls with source links, exceptions, and counsel annotations.
Every AI and human transformation becomes a reconstructable event, not a fragile one-bit AI-generated flag.
C2PA, metadata, visible labels, watermarking, and signatures stay swappable as the state of the art changes.
Release checks test whether labels, metadata, and verification evidence survive real transformations.
Signed JSON, audit exports, and feasibility dossiers are produced from runtime events instead of screenshots.
Runtime Disclosure and Marking
The launch SDK wraps generation, evaluates policy, emits disclosure text, applies marking adapters, signs evidence, records latency, and supports fail-open, fail-closed, and human-approval modes.
Transparency CI
Pull requests can report preserved disclosures, missing marking configuration, and counsel-review paths before release.
Counsel Review
Counsel can approve applicability, reject a scanner inference, or request missing customer facts. Those states are exported in the audit packet.
EU AI Act Article 50(1)
The scan cannot determine direct interaction from public signals alone.
route inventory, label copy version, component version, screenshot, release approvalDefault state: customer facts needed
EU AI Act Article 50(2)
The Code-of-Practice path is not confirmed, so the report keeps both Code and alternative-measures evidence visible.
artifact hash, adapter version, verification result, known limitations, feasibility rationaleDefault state: technical verification needed
EU AI Act Article 50(3)
No emotion recognition or biometric categorisation fact is currently indicated.
workflow classification, notice copy version, exposure timestamp, DPIA or privacy record reference, exception approvalDefault state: technical verification needed
EU AI Act Article 50(4)
Deepfake or public-interest publication facts are contextual and should be reviewed before runtime controls are disabled.
use-case classification, label copy version, publication timestamp, reviewer approvalDefault state: technical verification needed
EU AI Act Article 50(5)
Any human-facing disclosure or label should be clear, distinguishable, accessible, and linked to the affected surface and policy version.
accessibility check, copy registry, surface binding, policy linkDefault state: customer facts needed
EU AI Act Article 50(1)
Disclosure placement is not bound to the runtime interaction context
Screenshot evidence, component version, policy rule version, route inventory, and release approval.Default state: needs review
EU AI Act Article 50(5)
No policy-linked copy registry observed
Copy version, surface binding, accessibility check, policy link, and exportable JSON evidence.Default state: needs review
Hosted Transparency Record
Public facts explain the implemented controls. Private evidence can be shared with buyers, auditors, or counsel when the customer authorizes it.
Safer status language
isGenAI uses operational states so engineers, counsel, auditors, and buyers understand what has been implemented and what still needs interpretation.
Private workflows
The public scanner only observes pages it is allowed to fetch. Logged-in exports, customer portals, evidence packets and private policy screens are handled through this consent-based evidence queue.
Authorized private workflow evidence
Use this when the public scanner cannot see a disclosure, export, C2PA manifest, policy screen or evidence record because it sits behind authentication.