Article 50 Scanner EU AI Act transparency check

How this scanner works

We load your URL in a real headless Chromium browser, wait for late-mounting widgets, and inspect what a visitor actually receives. Static HTML fetching would miss most chat and voice assistants, because they inject themselves at runtime.

What we check, and against what

Art. 50(1) provider obligation

Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.

How we test it: Presence of an AI-interaction disclosure on a detected chat or voice surface, readable before or at the first turn.

Exemptions:

  • Disclosure is unnecessary where the AI nature is obvious to a reasonably well-informed, observant and circumspect person in context.
  • AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards.

Art. 50(2) provider obligation

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art.

How we test it: Presence of a machine-readable provenance mark (C2PA/Content Credentials manifest, or equivalent metadata assertion) on served synthetic media.

Exemptions:

  • AI systems performing an assistive function for standard editing.
  • AI systems that do not substantially alter the input data provided by the deployer or its semantics.

Art. 50(2) (robustness limb) provider obligation

The marking solution must be effective, interoperable, robust and reliable as far as technically feasible. A mark that is applied at generation but destroyed by the delivery pipeline is not a robust or reliable marking solution at the point the content reaches a natural person.

How we test it: Comparison of provenance marks on origin assets against the same assets as actually served through the production delivery/transform pipeline.

Exemptions:

  • Limits of the generally acknowledged state of the art and technical feasibility for the content type.

Art. 50(3) deployer obligation

Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.

How we test it: Detection of emotion-recognition or biometric-categorisation surfaces (webcam/affect SDKs) without an accompanying exposure notice.

Exemptions:

  • AI systems permitted by law to detect, prevent or investigate criminal offences, subject to safeguards.

Art. 50(4), first subparagraph deployer obligation

Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake shall disclose that the content has been artificially generated or manipulated. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.

How we test it: Presence of a persistent, human-visible label on deepfake-class media (synthetic human likeness, face/voice replacement, avatar presenters).

Exemptions:

  • Evidently artistic, creative, satirical or fictional works: reduced to an appropriate, non-intrusive disclosure.
  • Use authorised by law for criminal-offence detection, prevention, investigation or prosecution.

Art. 50(4), second subparagraph deployer obligation

Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation does not apply where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.

How we test it: Presence of an AI-generation disclosure on public-interest editorial surfaces that declare machine authorship.

Exemptions:

  • Content subject to human review or editorial control where a natural or legal person holds editorial responsibility.

Art. 50(5) provider obligation

The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.

How we test it: Timing (present at or before first interaction), prominence (clear and distinguishable), and accessibility (exposed to assistive technology, sufficient contrast) of any disclosure that was found.

What we deliberately do not do

Accuracy and false positives

A false accusation is worse than a missed finding. Vendor detections that are primarily human live-chat only count as AI surfaces when something else corroborates automation. Noun phrases like "AI assistant" only count as a disclosure when they appear inside the assistant interface itself, never when they merely appear in marketing copy — otherwise every company that sells AI would appear compliant by accident.

Run a scan