June 14, 2026 Regulation & Banking
Series · Part 1 of 2

The Evidence Gap: What CERTavia Delivers for Banks under Art. 50 EU AI Act and Where the Line Is Drawn

By Thorsten Litzki · Litzki Systems LLC

This is Part 1 of our series on the bank rollout of technical verification systems. Part 2 covers scaling across 200+ locations, the liability demarcation line, and the recommendations for the association.

tl;dr

Key takeaways

  • •  CERTavia delivers deterministic infrastructure evidence under Art. 50 EU AI Act. Art. 9, 10, and 14 remain fully with the institution.
  • •  The evidence gap: CERTavia verifies whether an llms.txt is present and cryptographically intact. Whether its content matches the internal AI Ethics Policy remains open.
  • •  A binary CERTIFIED signal creates false precision. It is not a certification of lawfulness and not a substitute for internal control systems.
  • •  The single largest risk in the risk matrix is misinterpreting the technical evidence as complete AI Act conformity.
Thesis Technical evidence and regulatory conformity are two different levels. Whoever conflates them creates an explanation problem on audit day instead of proof.

The regulatory landscape for the European banking sector is converging through the EU AI Act, DORA, and NIS2 into a single demand: technical proof of infrastructure integrity. CERTavia delivers machine-readable evidence based on its deterministic validation engine. Ultimate responsibility for compliance with the AI Act, in particular Art. 9, 10, and 14, remains fully with the institution. CERTavia positions itself as a building block toward audit-ready status, not as a substitute for compliance.

This first part clarifies what CERTavia technically delivers, where the line to supervisory duties lies, and what risk arises from a misinterpretation of the signal.

Functional Distinction: Technical Evidence and Supervisory Duties

For audit-readiness, a strict separation between infrastructure data and organizational governance is required. CERTavia is a deterministic verifier. The engine addresses precisely the requirements of Art. 50 EU AI Act for machine-readable transparency and provenance of data sources, and leaves substantial parts of the overall regulatory framework untouched.

Technical Infrastructure Evidence (CERTavia) Formal Supervisory Duties (Bank Management)
Focus Art. 50 — Validation of technical transparency and integrity: DNSSEC, TLS, CAA. Risk Management (Art. 9) — Identification and assessment of systemic risks.
Cryptographic signature — Proof of immutability via Ed25519 DNS anchor. Human Oversight (Art. 14) — Ensuring effective human oversight mechanisms.
Infrastructure parameters — Scan of 80+ parameters across six clusters: robots.txt, ai.txt, llms.txt. Data Governance (Art. 10) — Review of training data quality and bias avoidance.
Deterministic check — Binary CERTIFIED/FAILED signal with no discretionary margin. Organizational control — Establishing an internal control system (ICS) and audit function.
The Evidence Gap
CERTavia technically verifies, for example, whether an llms.txt is present and cryptographically intact. The system does not assess whether the values declared within it match the bank's internal AI Ethics Policy. This gap can only be closed by internal governance.

The Danger of False Precision

A binary CERTIFIED signal creates a precision that appears tempting for the audit function. A technical infrastructure scan is not a certification of lawfulness. CERTavia does not act as a Notified Body. Interpreting the signal as a substitute for internal control systems represents a significant audit risk. Without organizational embedding, the technical signal remains worthless for the supervisory authority.

A CERTIFIED signal proves the integrity of the measured infrastructure at the time of measurement. It does not prove the conformity of the organization operating that infrastructure.

Bank-Standardized Risk Matrix

The assessment uses a 5-point scale, where 1 stands for very low and 5 for critical. The weighting prioritizes regulatory relevance and reputational damage over purely technical operational aspects.

Risk Prob. Impact Control Reg. Reputation Total
Incorrect compliance interpretation 4 5 3 5 5 5.0
Missing internal governance coverage 4 5 2 5 4 4.8
Marketing leakage (overstated promises) 3 5 4 5 5 4.6
Liability and expectation risk 3 5 2 5 5 4.5
Inconsistent results (200+ locations) 4 4 2 4 4 4.2
Outdated / inconsistent evidence 4 4 2 4 3 4.0

Top 3 Criticalities from the Supervisory Perspective (BaFin/ECB)

5.0
Incorrect compliance interpretation If the technical evidence is mistakenly interpreted as complete AI Act conformity, sanctions can follow. The AI Act provides for fines of up to EUR 15 million or 3% of worldwide annual turnover for violations of high-risk requirements (Art. 99(4)); the higher ceiling of EUR 35 million or 7% applies to prohibited practices under Art. 5.
4.8
Missing internal governance coverage The supervisory authority measures banks against processes and accountability. A system that validates only the infrastructure leaves management's procedural responsibility open. A CERTIFIED stamp does not heal gaps in risk management.
4.6
Marketing leakage / reputational risk If the association communicates the system as a comprehensive certification, an expectation gap arises. Correction by the supervisory authority leads to loss of trust among customers and regulators.

The remaining three risks in the matrix — liability and expectation risk, inconsistent results across 200+ locations, and outdated evidence — are directly tied to the operational scaling of the rollout. Part 2 of this series places these risks in the context of concrete implementation.

Continue with Part 2

The 200+ Location Rollout: Scaling, Liability, and Recommendations

Operational entropy, the 90-day validity of CERTavia evidence, the liability demarcation line between service provider, institution, and association, plus five prioritized steps for safe implementation.

Read Part 2 →
Infrastructure evidence

Your SOVP evidence in 90 seconds

Free scan — no account required. CERTIFIED or FAILED with a complete cluster report.