All guides

Aug 19, 2026 · 9 min read

Free AI Readiness Check for Article 50: A 7-Signal Rubric

Free AI Readiness Check for Article 50: A 7-Signal Rubric

A free AI readiness check for Article 50 is worth your time only if it asks *which* AI surface you mean and whether you are the provider or the deployer of that surface — before it returns anything. Regulation (EU) 2024/1689 assigns its transparency duties per system and per role, so a questionnaire that scores your company ("do you use AI?", "do you have a policy?") returns a number nobody can act on (Article 50, EUR-Lex).

What follows is the nine-field intake that decides the answer, a lane-by-role map, and a seven-signal test for telling a usable check from a lead magnet. This is operational guidance, not legal advice; the last section marks the point where the questions stop being operational.

What a ten-minute check can settle, and what it cannot

A good check settles scope. It tells you which of your AI surfaces plausibly fall into which of the four transparency lanes, which role you occupy for each one, and which date applies to each lane. That list — surfaces, lanes, roles, dates — is the deliverable. The score is decoration.

It cannot settle wording or edge cases. Whether a notice reads as clear and distinguishable in your particular onboarding flow, whether the carve-out in Article 50(1) for interaction that is obvious to a reasonably well-informed person covers your case, whether rebranding a third-party model makes your team the provider of that system — these turn on facts a form never sees. A rules engine can flag them. It cannot close them.

So read the output as a to-do list with open questions attached. If a free check returns a green badge and no open questions, it has told you something about the vendor, not about your product.

The nine inputs that decide the answer

Run these per surface, not per product. A surface is one place where a person meets AI output: the chat widget, the autocomplete, the ticket summariser, the voice line, the generated hero image.

#InputWhy the answer moves
1Surface name and where it appears in the UIDuties attach to systems in use, not to your company or brand
2Your role for that surface: provider, deployer, or bothDecides which paragraph of Article 50 you read first
3Does it interact directly with a natural person?The trigger condition in Article 50(1)
4Output modality: text, image, audio, video, noneArticle 50(2) marking runs on synthetic output, not on classification
5Emotion recognition or biometric categorisation?A separate lane under Article 50(3), with GDPR duties on top
6Does output depict real persons, objects, places or events?The deepfake condition in Article 50(4)
7Is text published to inform the public on matters of public interest?The second half of Article 50(4), and it is narrower than "our blog"
8Human editorial review, with a named person responsible for publication?The condition the text-disclosure exception in Article 50(4) turns on
9First EU availability date of the surfaceDecides which deadline and which transition you are arguing about

Field 2 is the one that breaks most self-assessments. A team can be the deployer of a chat surface and the provider of a summariser it built on top of the same model, in the same product, in the same sprint. A check that asks for one company-wide role has already lost the thread.

Four lanes, two roles

LaneTriggerArticle assigns the duty toUsual owner on a SaaS team
Interaction notice — Art. 50(1)System intended to interact directly with natural personsProvider, at design timeProduct + engineering
Machine-readable marking — Art. 50(2)System generates synthetic audio, image, video or textProvider of the generating systemPlatform team, or the model vendor
Emotion recognition / biometric categorisation — Art. 50(3)Persons are exposed to such a systemDeployer, who informs those personsWhoever runs the feature
Deepfake and public-interest text — Art. 50(4)Deepfake output, or public-interest text published without human review and editorial responsibilityDeployer, who disclosesMarketing and comms

On timing: Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026. A limited transition that may extend provider-side machine-readable marking to 2 December 2026 for eligible systems has been proposed by the European Commission but is not yet adopted law. Confirm that transition's status and scope before you plan around it — even as proposed it does not move the other three lanes, and a check that quietly applies the later date to everything is giving you four months you do not have.

Where teams misassign the lane

The recurring error is treating the model vendor's marking as covering the whole product. Marking under Article 50(2) sits with the provider of the generating system; the disclosure in Article 50(4) sits with you as deployer when your team publishes a synthetic presenter video. Two duties, two parties, one of them yours. The early tell is a compliance note that names a vendor but no internal owner — if nobody on your side has the ticket, nobody on your side is doing the disclosure.

Seven signals that separate a usable check from a lead magnet

1. It accepts more than one surface, and asks the questions per surface. 2. It asks role per surface and allows the answer "both". 3. It returns lane-by-lane verdicts rather than one aggregate percentage. 4. Each verdict names the paragraph it came from and the date of the text version used. 5. It prints its assumptions and states what it did not assess. 6. The result is dated, exportable and stable enough to attach to a decision record. 7. It names its own limits and says which questions need counsel.

Score one point per signal. At six or seven, the output is worth filing as a scoping artefact. At three to five, treat it as a lead on where to look, and redo the intake yourself. Below three, you have filled in a marketing form. The signal that fails most often is number four: a verdict with no article reference cannot be checked by the colleague who inherits it in November.

What "free" is doing in the offer

Scoping is cheap to automate and operating is not, which is why the assessment is the part that tends to be given away and the widget, verification and evidence log tend to be the part that is not. That is a reasonable trade — it only becomes a problem when the free step is scored as if it were the finished work.

Five things to confirm on the vendor's own pricing page, because terms change and no article should be your source for them:

  • whether results require an account, and what happens to the product details you typed in
  • whether re-running after a product change is limited by count or by time window
  • the export format, and whether export sits on the free tier at all
  • the retention window for any evidence or audit log
  • whether the disclosure widget and marking API are priced separately from the check

DiscloseKit, the tool behind this blog, is a deterministic rules engine plus a disclosure widget, a verification step and an append-only evidence log; its pricing page carries the current terms for each part. If you are comparing several tools rather than one, the 24-cell control matrix in our EU AI Act Article 50 Compliance Tool: 2026 Guide is a harder test than any vendor's own questionnaire.

Run the check yourself in about 20 minutes

Budget roughly four minutes per surface for the nine fields. A five-surface B2B product takes about twenty minutes of intake, plus ten for writing down the open questions — which is less time than most teams spend deciding whether to run a tool.

Here is the shape of the output, using a fictional five-surface product:

SurfaceLikely laneRole to confirmOpen question
In-app support chat on a third-party model50(1) interaction noticeProvider or deployer?Does our branding change who the provider is?
Draft-email generator50(2) marking of synthetic textProvider of the generating systemWhich party emits the marking, and can we verify it?
Sentiment scoring on support tickets50(3), if it is emotion recognitionDeployerAre the persons scored end users, agents, or both?
Marketing video with a synthetic presenter50(4) deepfake disclosureDeployerWho signs off placement of the label?
Generated release-note summariesProbably noneDeployerIs this "public interest" text, or just product comms?

Four of those five rows end in a question rather than a verdict, which is what an honest intake looks like on the first pass. The chat row is the one teams get wrong twice — first on who owes the notice, then on when it has to appear; Chatbot disclosure requirement under EU AI Act Article 50 works through both. Once the lanes are assigned, the remaining work is placement, timing, accessibility and evidence, and that is the subject of Article 50 Disclosure Widget Embed: An Operational Guide.

The question no questionnaire can answer

Whether your team is the provider of a system you did not build is a legal question about your specific facts. The definition in Article 3(3) of Regulation (EU) 2024/1689 turns on developing a system or having it developed and placing it on the market or putting it into service under your own name or trademark — and a wrapper around someone else's model, sold under your brand, is exactly the fact pattern that definition was written to reach. No free check can resolve it for you, and any that claims to has overstated what a rules engine does.

That single question is worth an hour of a lawyer's time. The other nine fields are worth twenty minutes of yours, and they are the twenty minutes that make the lawyer's hour cheap.

See exactly what applies to your product

Run the free check

Sources

This is compliance tooling, not legal advice. Consult counsel for your specific case.