EU AI Act Article 50 Scanner

Enter a public AI product URL for observable EU AI Act Article 50 signals, or submit authorized private workflow evidence when the relevant disclosure, export or provenance record sits behind login.

EU AI Act Article 50 applies from 2 Aug 2026Technical evidence, not legal advice

Implement, test and prove your EU AI Act Article 50 transparency controls.

Find likely EU AI Act Article 50 surfaces, map them to applicable controls, implement fixes, test them continuously, and generate evidence for counsel, buyers, and engineering leaders.

Scan my AI product
Implementation reportexample-ai-product-com
Counsel review
Surfaces1
Controls0/5
Review7
CI pass2/5
1 AI surfaces mapped. 0 controls implemented. 7 awaiting counsel.Evidence record ready to share after runtime execution.

EU AI Act Article 50 applicability wizard

Customer facts feed the rule engine before any scan finding is interpreted.

Generated modalities

No single green badge. Just the EU AI Act Article 50 state.

The scanner separates observed facts, missing signals, externally unverifiable controls, and legal interpretation.

EU AI Act Article 50(1)

Direct human-AI interaction disclosure

CUSTOMER FACTS REQUIRED

The scan cannot determine direct interaction from public signals alone.

CUSTOMER FACTUAL CONFIRMATION REQUIRED

EU AI Act Article 50(2)

Machine-readable marking and detection

NOT INDICATED

The Code-of-Practice path is not confirmed, so the report keeps both Code and alternative-measures evidence visible.

TECHNICALLY UNVERIFIABLE

EU AI Act Article 50(3)

Emotion recognition and biometric categorisation notice

NOT INDICATED

No emotion recognition or biometric categorisation fact is currently indicated.

TECHNICALLY UNVERIFIABLE

EU AI Act Article 50(4)

Deepfake and public-interest content labelling

NOT INDICATED

Deepfake or public-interest publication facts are contextual and should be reviewed before runtime controls are disabled.

TECHNICALLY UNVERIFIABLE

EU AI Act Article 50(5)

Accessible and context-appropriate labels

CUSTOMER FACTS REQUIRED

Any human-facing disclosure or label should be clear, distinguishable, accessible, and linked to the affected surface and policy version.

CUSTOMER FACTUAL CONFIRMATION REQUIRED

URL Scan to Scope Matrix to GitHub findings.

The report keeps public observations, technical verification gaps, and counsel decisions separate. It never declares EU approval or guaranteed legal compliance.

AI surfaces1
Code findings0
Fix kits4
Evidence readiness14%

Observed signals

  • Sample scan loaded

Limits of this scan

  • Public scanning cannot determine contractual role, private runtime behavior, or counsel interpretation.

Technical receipt

HTTP
not fetched
Content
unknown
Bytes / files
sample

EU AI Act Article 50 Implementation Report

Every scan creates a customer-ready report URL with observations, likely obligations, confidence, source versions, technical recommendations, and counsel-review states.

EU AI Act Article 50Transparency Controls
0 / 5implemented
Last checked 06 Sept 2026, 20:31View evidence at isgenai.com/report/example-ai-product-com
Open reportTrust RecordBadge SVG

EU AI Act Article 50(1)

Direct interaction disclosure

Requires legal interpretationCounsel reviewmedium risk

Add a runtime disclosure component attached to every direct AI interaction surface, with locale and accessibility variants.

EU AI Act Article 50(2)

Machine-readable marking of generated or manipulated content

Unable to verify externallyOut of scopelow risk

Use a marking adapter strategy: metadata or C2PA where appropriate, paired with signed evidence and a workflow-specific robustness suite.

EU AI Act Article 50(3)

Emotion recognition and biometric categorisation notice

Unable to verify externallyOut of scopelow risk

Maintain an exposed-person notice at first exposure to the operation of the system, linked to a privacy processing record and counsel-approved exception path.

EU AI Act Article 50(4)

Deepfake and public-interest content labelling

Unable to verify externallyOut of scopemedium risk

Route relevant releases through a labelled publication workflow with reviewer sign-off and durable provenance.

EU AI Act Article 50(5)

Accessible and machine-readable labelling context

Requires legal interpretationCounsel reviewmedium risk

Maintain a label copy registry, per-surface policy bindings, and event-level evidence export.

Canonical map of EU AI Act Article 50 exposure.

Each AI-facing surface carries owner, modality, role, user population, publication status, EU AI Act Article 50 mapping, implementation status, and evidence state.

mixed / unknown

Unclassified AI surface candidate

Counsel review
Owner
Needs assignment
Role
unknown
User population
unknown
Evidence
Unable to verify externally

EU AI Act Article 50(1), EU AI Act Article 50(2), EU AI Act Article 50(3), EU AI Act Article 50(5)

Not verified

Specific code findings, not questionnaire prose.

Repository scans map provider SDKs, generation routes, output pipelines, labels, metadata, publishing paths, and transparency logic to files and lines.

GitHub

No file-level findings yet

Unable to verify externally

Connect a public repository or run the server with GitHub CLI/token access for private repositories.

Least-privilege read access is enough for detection. Write access is only needed to open fix PRs.

Every finding gets an implementation path.

Fix kits include code, configuration, and review records. Draft PR creation works when a write-capable GitHub token is available and PR creation is explicitly enabled on the server.

EU AI Act Article 50(1) / minutes

Add EU AI Act Article 50 first-interaction disclosure

Production-ready accessible disclosure component for direct human-AI interaction, with policy version and evidence hook props.

customer chatbot / direct AI interaction surface
create: src/components/Article50Disclosure.tsx

EU AI Act Article 50(2) / hours

Wrap generation with runtime evidence and marking configuration

Adds a TypeScript runtime wrapper that records policy decision, provenance node, sidecar metadata, and known marking limitations.

generation API route
create: isgenai.runtime.ts

EU AI Act Article 50 / minutes

Add Transparency CI report to pull requests

Runs repository signal detection on every pull request and uploads a machine-readable implementation report.

.github/workflows/isgenai.yml
configure: .github/workflows/isgenai.yml

EU AI Act Article 50(3)/(4) / requires review

Record counsel determination before disabling controls

Creates an auditable override record for contextual determinations such as human editorial responsibility or obvious AI context.

emotion-biometric/deepfake/public-interest/assistive-editing determinations
create: isgenai.counsel-review.json

Five engines for operational AI transparency.

The moat is the graph from policy to runtime event to provenance to evidence. A label alone is too fragile for serious AI products.

Policy Engine

Versioned EU AI Act Article 50 rules become deterministic controls with source links, exceptions, and counsel annotations.

Provenance Graph

Every AI and human transformation becomes a reconstructable event, not a fragile one-bit AI-generated flag.

Marking Adapters

C2PA, metadata, visible labels, watermarking, and signatures stay swappable as the state of the art changes.

Transparency CI

Release checks test whether labels, metadata, and verification evidence survive real transformations.

Evidence Engine

Signed JSON, audit exports, and feasibility dossiers are produced from runtime events instead of screenshots.

TypeScript runtime, provenance graph, ledger, and fail-mode controls.

The launch SDK wraps generation, evaluates policy, emits disclosure text, applies marking adapters, signs evidence, records latency, and supports fail-open, fail-closed, and human-approval modes.

AI-generated or manipulated content
Runtime event feed
AI generationPolicy evaluated18 ms
ProvenanceInput/output hash linked41 ms
MarkingSidecar and signature adapters62 ms
LedgerEvidence entry hash chainedready
Evidence artifacts
Policy decision envelopeJSON
Implementable
Provenance event chainSigned hash chain
Implementable
Feasibility dossierPDF dossier
Counsel review
Audit exportOSCAL-ready JSON
Implementable
Security and privacy
Repository accessRead-only scan by default
Source retentionNo source persisted by scanner
EvidenceHash-chained local ledger
Runtime outagePer-surface fail mode

Robustness testing belongs in every release.

Pull requests can report preserved disclosures, missing marking configuration, and counsel-review paths before release.

TransformationDetectionEvidence lossGate
Original artifact verification100%0%pass
JPEG compression or text minification96%4%pass
Resize, crop, or layout conversion84%13%watch
Screenshot, copy-paste, or social repost68%28%watch
Heavy paraphrase or adversarial laundering42%49%fail

Legal determinations become auditable policy overrides.

Counsel can approve applicability, reject a scanner inference, or request missing customer facts. Those states are exported in the audit packet.

EU AI Act Article 50(1)

EU AI Act Article 50(1): Direct human-AI interaction disclosure

The scan cannot determine direct interaction from public signals alone.

route inventory, label copy version, component version, screenshot, release approval

Default state: customer facts needed

EU AI Act Article 50(2)

EU AI Act Article 50(2): Machine-readable marking and detection

The Code-of-Practice path is not confirmed, so the report keeps both Code and alternative-measures evidence visible.

artifact hash, adapter version, verification result, known limitations, feasibility rationale

Default state: technical verification needed

EU AI Act Article 50(3)

EU AI Act Article 50(3): Emotion recognition and biometric categorisation notice

No emotion recognition or biometric categorisation fact is currently indicated.

workflow classification, notice copy version, exposure timestamp, DPIA or privacy record reference, exception approval

Default state: technical verification needed

EU AI Act Article 50(4)

EU AI Act Article 50(4): Deepfake and public-interest content labelling

Deepfake or public-interest publication facts are contextual and should be reviewed before runtime controls are disabled.

use-case classification, label copy version, publication timestamp, reviewer approval

Default state: technical verification needed

EU AI Act Article 50(5)

EU AI Act Article 50(5): Accessible and context-appropriate labels

Any human-facing disclosure or label should be clear, distinguishable, accessible, and linked to the affected surface and policy version.

accessibility check, copy registry, surface binding, policy link

Default state: customer facts needed

EU AI Act Article 50(1)

Direct interaction disclosure

Disclosure placement is not bound to the runtime interaction context

Screenshot evidence, component version, policy rule version, route inventory, and release approval.

Default state: needs review

EU AI Act Article 50(5)

Accessible and machine-readable labelling context

No policy-linked copy registry observed

Copy version, surface binding, accessibility check, policy link, and exportable JSON evidence.

Default state: needs review

Share your transparency records.

Public facts explain the implemented controls. Private evidence can be shared with buyers, auditors, or counsel when the customer authorizes it.

Need help implementing this?
isgenai.com/trust/example-ai-product-comCounsel review

Public facts

  • EU AI Act Article 50 scope has been assessed from observable product and declared workflow signals.
  • Implementation states separate technical controls from legal interpretation.
  • Trust Record is not an EU certification and should not be presented as one.

Private evidence

  • Runtime policy decisions
  • Artifact hashes and provenance graph
  • Robustness CI results
  • Counsel review notes and approved exceptions

Never reduce EU AI Act Article 50 to a single badge.

isGenAI uses operational states so engineers, counsel, auditors, and buyers understand what has been implemented and what still needs interpretation.

Implementable
Implemented
Verified
Counsel review
Technical limit

Authenticated surfaces can be reviewed with authorized evidence.

The public scanner only observes pages it is allowed to fetch. Logged-in exports, customer portals, evidence packets and private policy screens are handled through this consent-based evidence queue.

Submit logged-in or customer-only evidence for review.

Use this when the public scanner cannot see a disclosure, export, C2PA manifest, policy screen or evidence record because it sits behind authentication.