Key takeaways
- • CERTavia delivers deterministic infrastructure evidence under Art. 50 EU AI Act. Art. 9, 10, and 14 remain fully with the institution.
- • The evidence gap: CERTavia verifies whether an llms.txt is present and cryptographically intact. Whether its content matches the internal AI Ethics Policy remains open.
- • A binary CERTIFIED signal creates false precision. It is not a certification of lawfulness and not a substitute for internal control systems.
- • The single largest risk in the risk matrix is misinterpreting the technical evidence as complete AI Act conformity.
The regulatory landscape for the European banking sector is converging through the EU AI Act, DORA, and NIS2 into a single demand: technical proof of infrastructure integrity. CERTavia delivers machine-readable evidence based on its deterministic validation engine. Ultimate responsibility for compliance with the AI Act, in particular Art. 9, 10, and 14, remains fully with the institution. CERTavia positions itself as a building block toward audit-ready status, not as a substitute for compliance.
This first part clarifies what CERTavia technically delivers, where the line to supervisory duties lies, and what risk arises from a misinterpretation of the signal.
Functional Distinction: Technical Evidence and Supervisory Duties
For audit-readiness, a strict separation between infrastructure data and organizational governance is required. CERTavia is a deterministic verifier. The engine addresses precisely the requirements of Art. 50 EU AI Act for machine-readable transparency and provenance of data sources, and leaves substantial parts of the overall regulatory framework untouched.
| Technical Infrastructure Evidence (CERTavia) | Formal Supervisory Duties (Bank Management) |
|---|---|
| Focus Art. 50 — Validation of technical transparency and integrity: DNSSEC, TLS, CAA. | Risk Management (Art. 9) — Identification and assessment of systemic risks. |
| Cryptographic signature — Proof of immutability via Ed25519 DNS anchor. | Human Oversight (Art. 14) — Ensuring effective human oversight mechanisms. |
| Infrastructure parameters — Scan of 80+ parameters across six clusters: robots.txt, ai.txt, llms.txt. | Data Governance (Art. 10) — Review of training data quality and bias avoidance. |
| Deterministic check — Binary CERTIFIED/FAILED signal with no discretionary margin. | Organizational control — Establishing an internal control system (ICS) and audit function. |
CERTavia technically verifies, for example, whether an llms.txt is present and cryptographically intact. The system does not assess whether the values declared within it match the bank's internal AI Ethics Policy. This gap can only be closed by internal governance.
The Danger of False Precision
A binary CERTIFIED signal creates a precision that appears tempting for the audit function. A technical infrastructure scan is not a certification of lawfulness. CERTavia does not act as a Notified Body. Interpreting the signal as a substitute for internal control systems represents a significant audit risk. Without organizational embedding, the technical signal remains worthless for the supervisory authority.
A CERTIFIED signal proves the integrity of the measured infrastructure at the time of measurement. It does not prove the conformity of the organization operating that infrastructure.
Bank-Standardized Risk Matrix
The assessment uses a 5-point scale, where 1 stands for very low and 5 for critical. The weighting prioritizes regulatory relevance and reputational damage over purely technical operational aspects.
| Risk | Prob. | Impact | Control | Reg. | Reputation | Total |
|---|---|---|---|---|---|---|
| Incorrect compliance interpretation | 4 | 5 | 3 | 5 | 5 | 5.0 |
| Missing internal governance coverage | 4 | 5 | 2 | 5 | 4 | 4.8 |
| Marketing leakage (overstated promises) | 3 | 5 | 4 | 5 | 5 | 4.6 |
| Liability and expectation risk | 3 | 5 | 2 | 5 | 5 | 4.5 |
| Inconsistent results (200+ locations) | 4 | 4 | 2 | 4 | 4 | 4.2 |
| Outdated / inconsistent evidence | 4 | 4 | 2 | 4 | 3 | 4.0 |
Top 3 Criticalities from the Supervisory Perspective (BaFin/ECB)
The remaining three risks in the matrix — liability and expectation risk, inconsistent results across 200+ locations, and outdated evidence — are directly tied to the operational scaling of the rollout. Part 2 of this series places these risks in the context of concrete implementation.
Continue with Part 2
The 200+ Location Rollout: Scaling, Liability, and Recommendations
Operational entropy, the 90-day validity of CERTavia evidence, the liability demarcation line between service provider, institution, and association, plus five prioritized steps for safe implementation.
Read Part 2 →CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.