All guides

Aug 19, 2026 · 10 min read

Free AI Readiness Check for Article 50: A 7-Signal Rubric

Free AI Readiness Check for Article 50: A 7-Signal Rubric

A free AI readiness check for Article 50 is worth your time only if it asks *which* AI surface you mean and whether you are the provider or the deployer of that surface — before it returns anything. Regulation (EU) 2024/1689 assigns its transparency duties per system and per role, so a questionnaire that scores your company ("do you use AI?", "do you have a policy?") returns a number nobody can act on (Article 50, EUR-Lex).

What follows is the nine-field intake that decides the answer, a lane-by-role map, and a seven-signal test for telling a usable check from a lead magnet. This is operational guidance, not legal advice; the last section marks the point where the questions stop being operational.

What a ten-minute check can settle, and what it cannot

A good check settles scope. It tells you which of your AI surfaces plausibly fall into which of the four transparency lanes, which role you occupy for each one, and which date applies to each lane. That list — surfaces, lanes, roles, dates — is the deliverable. The score is decoration.

It cannot settle wording or edge cases. Whether a notice reads as clear and distinguishable in your particular onboarding flow, whether the carve-out in Article 50(1) for interaction that is obvious to a reasonably well-informed person covers your case, whether rebranding a third-party model makes your team the provider of that system — these turn on facts a form never sees. A rules engine can flag them. It cannot close them.

So read the output as a to-do list with open questions attached. If a free check returns a green badge and no open questions, it has told you something about the vendor, not about your product.

The nine inputs that decide the answer

Run these per surface, not per product. A surface is one place where a person meets AI output: the chat widget, the autocomplete, the ticket summariser, the voice line, the generated hero image.

#InputWhy the answer moves
1Surface name and where it appears in the UIDuties attach to systems in use, not to your company or brand
2Your role for that surface: provider, deployer, or bothDecides which paragraph of Article 50 you read first
3Does it interact directly with a natural person?The trigger condition in Article 50(1)
4Output modality: text, image, audio, video, noneArticle 50(2) marking runs on synthetic output, not on classification
5Emotion recognition or biometric categorisation?A separate lane under Article 50(3), with GDPR duties on top
6Does image, audio or video output resemble existing persons, objects, places, entities or events and could it falsely appear authentic?The deepfake definition (Article 3(60)) behind Article 50(4)
7Is text published to inform the public on matters of public interest?The second half of Article 50(4), and it is narrower than "our blog"
8Human review or editorial control, with a natural or legal person holding editorial responsibility for the publication?The condition the text-disclosure exception in Article 50(4) turns on
9First EU availability date of the surfaceDecides which deadline and which transition you are arguing about

Field 2 is the one that breaks most self-assessments. A team can be the deployer of a chat surface and the provider of a summariser it built on top of the same model, in the same product, in the same sprint. A check that asks for one company-wide role has already lost the thread.

Four lanes, two roles

LaneTriggerArticle assigns the duty toUsual owner on a SaaS team
Interaction notice — Art. 50(1)System intended to interact directly with natural personsProvider, at design timeProduct + engineering
Machine-readable marking — Art. 50(2)System generates synthetic audio, image, video or textProvider of the generating systemYour platform team if the generating system is yours; the vendor only if it provides that system
Emotion recognition / biometric categorisation — Art. 50(3)Persons are exposed to such a systemDeployer, who informs those personsWhoever runs the feature
Deepfake and public-interest text — Art. 50(4)Deepfake output, or text published to inform the public on matters of public interest, unless it underwent human review or editorial control with editorial responsibilityDeployer, who disclosesMarketing and comms

On timing: Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026. Article 111(4), inserted by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026), gives providers of generative AI systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Confirm that your system is eligible before you plan around it — the transition does not move the other three lanes, it does not cover systems placed on the market on or after 2 August 2026, and a check that quietly applies the later date to everything is giving you four months you do not have.

Where teams misassign the lane

The recurring error is treating the model vendor's marking as covering the whole product. Marking under Article 50(2) sits with the provider of the generating system; the disclosure in Article 50(4) sits with you as deployer when your team publishes a synthetic presenter video. Two duties, two parties, one of them yours. The early tell is a compliance note that names a vendor but no internal owner — if nobody on your side has the ticket, nobody on your side is doing the disclosure.

Seven signals that separate a usable check from a lead magnet

1. It accepts more than one surface, and asks the questions per surface. 2. It asks role per surface and allows the answer "both". 3. It returns lane-by-lane verdicts rather than one aggregate percentage. 4. Each verdict names the paragraph it came from and the date of the text version used. 5. It prints its assumptions and states what it did not assess. 6. The result is dated, exportable and stable enough to attach to a decision record. 7. It names its own limits and says which questions need counsel.

Score one point per signal. At six or seven, the output is worth filing as a scoping artefact. At three to five, treat it as a lead on where to look, and redo the intake yourself. Below three, you have filled in a marketing form. The signal that fails most often is number four: a verdict with no article reference cannot be checked by the colleague who inherits it in November.

What "free" is doing in the offer

Scoping is cheap to automate and operating is not, which is why the assessment is the part that tends to be given away and the widget, verification and evidence log tend to be the part that is not. That is a reasonable trade — it only becomes a problem when the free step is scored as if it were the finished work.

Five things to confirm on the vendor's own pricing page, because terms change and no article should be your source for them:

  • whether results require an account, and what happens to the product details you typed in
  • whether re-running after a product change is limited by count or by time window
  • the export format, and whether export sits on the free tier at all
  • the retention window for any evidence or audit log
  • whether the disclosure widget and marking API are priced separately from the check

DiscloseKit, the tool behind this blog, is a deterministic rules engine plus a disclosure widget, a verification step and a hash-chained evidence log; its pricing page carries the current terms for each part. If you are comparing several tools rather than one, the 24-cell control matrix in our EU AI Act Article 50 Compliance Tool: 2026 Guide is a harder test than any vendor's own questionnaire.

Run the check yourself in about 20 minutes

Budget roughly four minutes per surface for the nine fields. A five-surface B2B product takes about twenty minutes of intake, plus ten for writing down the open questions — which is less time than most teams spend deciding whether to run a tool.

Here is the shape of the output, using a fictional five-surface product:

SurfaceLikely laneRole to confirmOpen question
In-app support chat on a third-party model50(1) interaction noticeProvider or deployer?Does our branding change who the provider is?
Draft-email generator50(2) marking of synthetic textProvider of the generating systemWhich party emits the marking, and can we verify it?
Sentiment scoring on support tickets50(3), if it is emotion recognitionDeployerAre the persons scored end users, agents, or both?
Marketing video with a synthetic presenter50(4) deepfake disclosureDeployerWho signs off placement of the label?
Generated release-note summariesProbably not 50(4)DeployerIs this "public interest" text, or just product comms?

Four of those five rows end in a question rather than a verdict, which is what an honest intake looks like on the first pass. The chat row is the one teams get wrong twice — first on who owes the notice, then on when it has to appear; Chatbot disclosure requirement under EU AI Act Article 50 works through both. Once the lanes are assigned, the remaining work is placement, timing, accessibility and evidence, and that is the subject of Article 50 Disclosure Widget Embed: An Operational Guide.

The arithmetic that decides whether to run it at all

A twenty-minute check is cheap. What makes it worth doing is the alternative.

Run the checkSkip it
Intake, 5 surfaces × 4 min20 min0
Writing down the open questions10 min0
Legal review, scoped to 4 named questions60 min–
Legal review, unscoped ("does the AI Act apply to us?")–3 to 5 hours
Total to a decision1.5 hours3 to 5 hours

The saving is not the twenty minutes. It is that counsel receives four specific questions about five named surfaces instead of an open-ended one — and an unscoped question is what turns a one-hour review into an afternoon.

The other number worth stating: the transparency obligations in Article 50 have applied since 2 August 2026, and the penalty ceiling for breaching them is €15 million or 3 % of worldwide annual turnover, whichever is higher (Art. 99(4)(g)); for SMEs including start-ups, and small mid-cap enterprises, the lower of the two applies (Art. 99(6) and (6a), the latter inserted by Regulation (EU) 2026/1744). Against that, ninety minutes to know which of your surfaces are in scope is not a budget decision.

What the check still cannot settle: whether you are provider or deployer for a given surface. That turns on contracts and on whose branding the system carries, and no intake form resolves it.

The question no questionnaire can answer

Whether your team is the provider of a system you did not build is a legal question about your specific facts. The definition in Article 3(3) of Regulation (EU) 2024/1689 turns on developing a system or having it developed and placing it on the market or putting it into service under your own name or trademark — and a wrapper around someone else's model, sold under your brand, is exactly the fact pattern that definition was written to reach. No free check can resolve it for you, and any that claims to has overstated what a rules engine does.

That single question is worth an hour of a lawyer's time. The other nine fields are worth twenty minutes of yours, and they are the twenty minutes that make the lawyer's hour cheap.

See exactly what applies to your product

Run the free check

Sources

This is compliance tooling, not legal advice. Consult counsel for your specific case.