A free AI readiness check for Article 50 is worth your time only if it asks *which* AI surface you mean and whether you are the provider or the deployer of that surface — before it returns anything. Regulation (EU) 2024/1689 assigns its transparency duties per system and per role, so a questionnaire that scores your company ("do you use AI?", "do you have a policy?") returns a number nobody can act on (Article 50, EUR-Lex).
What follows is the nine-field intake that decides the answer, a lane-by-role map, and a seven-signal test for telling a usable check from a lead magnet. This is operational guidance, not legal advice; the last section marks the point where the questions stop being operational.
What a ten-minute check can settle, and what it cannot
A good check settles scope. It tells you which of your AI surfaces plausibly fall into which of the four transparency lanes, which role you occupy for each one, and which date applies to each lane. That list — surfaces, lanes, roles, dates — is the deliverable. The score is decoration.
It cannot settle wording or edge cases. Whether a notice reads as clear and distinguishable in your particular onboarding flow, whether the carve-out in Article 50(1) for interaction that is obvious to a reasonably well-informed person covers your case, whether rebranding a third-party model makes your team the provider of that system — these turn on facts a form never sees. A rules engine can flag them. It cannot close them.
So read the output as a to-do list with open questions attached. If a free check returns a green badge and no open questions, it has told you something about the vendor, not about your product.
The nine inputs that decide the answer
Run these per surface, not per product. A surface is one place where a person meets AI output: the chat widget, the autocomplete, the ticket summariser, the voice line, the generated hero image.
| # | Input | Why the answer moves |
|---|---|---|
| 1 | Surface name and where it appears in the UI | Duties attach to systems in use, not to your company or brand |
| 2 | Your role for that surface: provider, deployer, or both | Decides which paragraph of Article 50 you read first |
| 3 | Does it interact directly with a natural person? | The trigger condition in Article 50(1) |
| 4 | Output modality: text, image, audio, video, none | Article 50(2) marking runs on synthetic output, not on classification |
| 5 | Emotion recognition or biometric categorisation? | A separate lane under Article 50(3), with GDPR duties on top |
| 6 | Does image, audio or video output resemble existing persons, objects, places, entities or events and could it falsely appear authentic? | The deepfake definition (Article 3(60)) behind Article 50(4) |
| 7 | Is text published to inform the public on matters of public interest? | The second half of Article 50(4), and it is narrower than "our blog" |
| 8 | Human review or editorial control, with a natural or legal person holding editorial responsibility for the publication? | The condition the text-disclosure exception in Article 50(4) turns on |
| 9 | First EU availability date of the surface | Decides which deadline and which transition you are arguing about |
Field 2 is the one that breaks most self-assessments. A team can be the deployer of a chat surface and the provider of a summariser it built on top of the same model, in the same product, in the same sprint. A check that asks for one company-wide role has already lost the thread.
Four lanes, two roles
| Lane | Trigger | Article assigns the duty to | Usual owner on a SaaS team |
|---|---|---|---|
| Interaction notice — Art. 50(1) | System intended to interact directly with natural persons | Provider, at design time | Product + engineering |
| Machine-readable marking — Art. 50(2) | System generates synthetic audio, image, video or text | Provider of the generating system | Your platform team if the generating system is yours; the vendor only if it provides that system |
| Emotion recognition / biometric categorisation — Art. 50(3) | Persons are exposed to such a system | Deployer, who informs those persons | Whoever runs the feature |
| Deepfake and public-interest text — Art. 50(4) | Deepfake output, or text published to inform the public on matters of public interest, unless it underwent human review or editorial control with editorial responsibility | Deployer, who discloses | Marketing and comms |
On timing: Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026. Article 111(4), inserted by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026), gives providers of generative AI systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Confirm that your system is eligible before you plan around it — the transition does not move the other three lanes, it does not cover systems placed on the market on or after 2 August 2026, and a check that quietly applies the later date to everything is giving you four months you do not have.
Where teams misassign the lane
The recurring error is treating the model vendor's marking as covering the whole product. Marking under Article 50(2) sits with the provider of the generating system; the disclosure in Article 50(4) sits with you as deployer when your team publishes a synthetic presenter video. Two duties, two parties, one of them yours. The early tell is a compliance note that names a vendor but no internal owner — if nobody on your side has the ticket, nobody on your side is doing the disclosure.
Seven signals that separate a usable check from a lead magnet
1. It accepts more than one surface, and asks the questions per surface. 2. It asks role per surface and allows the answer "both". 3. It returns lane-by-lane verdicts rather than one aggregate percentage. 4. Each verdict names the paragraph it came from and the date of the text version used. 5. It prints its assumptions and states what it did not assess. 6. The result is dated, exportable and stable enough to attach to a decision record. 7. It names its own limits and says which questions need counsel.
Score one point per signal. At six or seven, the output is worth filing as a scoping artefact. At three to five, treat it as a lead on where to look, and redo the intake yourself. Below three, you have filled in a marketing form. The signal that fails most often is number four: a verdict with no article reference cannot be checked by the colleague who inherits it in November.
What "free" is doing in the offer
Scoping is cheap to automate and operating is not, which is why the assessment is the part that tends to be given away and the widget, verification and evidence log tend to be the part that is not. That is a reasonable trade — it only becomes a problem when the free step is scored as if it were the finished work.
Five things to confirm on the vendor's own pricing page, because terms change and no article should be your source for them:
- whether results require an account, and what happens to the product details you typed in
- whether re-running after a product change is limited by count or by time window
- the export format, and whether export sits on the free tier at all
- the retention window for any evidence or audit log
- whether the disclosure widget and marking API are priced separately from the check
DiscloseKit, the tool behind this blog, is a deterministic rules engine plus a disclosure widget, a verification step and a hash-chained evidence log; its pricing page carries the current terms for each part. If you are comparing several tools rather than one, the 24-cell control matrix in our EU AI Act Article 50 Compliance Tool: 2026 Guide is a harder test than any vendor's own questionnaire.
Run the check yourself in about 20 minutes
Budget roughly four minutes per surface for the nine fields. A five-surface B2B product takes about twenty minutes of intake, plus ten for writing down the open questions — which is less time than most teams spend deciding whether to run a tool.
Here is the shape of the output, using a fictional five-surface product:
| Surface | Likely lane | Role to confirm | Open question |
|---|---|---|---|
| In-app support chat on a third-party model | 50(1) interaction notice | Provider or deployer? | Does our branding change who the provider is? |
| Draft-email generator | 50(2) marking of synthetic text | Provider of the generating system | Which party emits the marking, and can we verify it? |
| Sentiment scoring on support tickets | 50(3), if it is emotion recognition | Deployer | Are the persons scored end users, agents, or both? |
| Marketing video with a synthetic presenter | 50(4) deepfake disclosure | Deployer | Who signs off placement of the label? |
| Generated release-note summaries | Probably not 50(4) | Deployer | Is this "public interest" text, or just product comms? |
Four of those five rows end in a question rather than a verdict, which is what an honest intake looks like on the first pass. The chat row is the one teams get wrong twice — first on who owes the notice, then on when it has to appear; Chatbot disclosure requirement under EU AI Act Article 50 works through both. Once the lanes are assigned, the remaining work is placement, timing, accessibility and evidence, and that is the subject of Article 50 Disclosure Widget Embed: An Operational Guide.
The arithmetic that decides whether to run it at all
A twenty-minute check is cheap. What makes it worth doing is the alternative.
| Run the check | Skip it | |
|---|---|---|
| Intake, 5 surfaces × 4 min | 20 min | 0 |
| Writing down the open questions | 10 min | 0 |
| Legal review, scoped to 4 named questions | 60 min | – |
| Legal review, unscoped ("does the AI Act apply to us?") | – | 3 to 5 hours |
| Total to a decision | 1.5 hours | 3 to 5 hours |
The saving is not the twenty minutes. It is that counsel receives four specific questions about five named surfaces instead of an open-ended one — and an unscoped question is what turns a one-hour review into an afternoon.
The other number worth stating: the transparency obligations in Article 50 have applied since 2 August 2026, and the penalty ceiling for breaching them is €15 million or 3 % of worldwide annual turnover, whichever is higher (Art. 99(4)(g)); for SMEs including start-ups, and small mid-cap enterprises, the lower of the two applies (Art. 99(6) and (6a), the latter inserted by Regulation (EU) 2026/1744). Against that, ninety minutes to know which of your surfaces are in scope is not a budget decision.
What the check still cannot settle: whether you are provider or deployer for a given surface. That turns on contracts and on whose branding the system carries, and no intake form resolves it.
The question no questionnaire can answer
Whether your team is the provider of a system you did not build is a legal question about your specific facts. The definition in Article 3(3) of Regulation (EU) 2024/1689 turns on developing a system or having it developed and placing it on the market or putting it into service under your own name or trademark — and a wrapper around someone else's model, sold under your brand, is exactly the fact pattern that definition was written to reach. No free check can resolve it for you, and any that claims to has overstated what a rules engine does.
That single question is worth an hour of a lawyer's time. The other nine fields are worth twenty minutes of yours, and they are the twenty minutes that make the lawyer's hour cheap.
