The evidence that holds up to auditors.
From August 2, 2026, the transparency obligations under Art. 50 of the EU AI Act apply. By that date, boards and decision-makers need evidence that stands up to auditors, investors, and their own supervisory board. CERTavia delivers exactly that evidence: cryptographically signed, DNS-anchored, in 90 to 120 seconds.
What that means in concrete terms
The EU AI Act requires companies with AI systems to have a demonstrable technical foundation. Art. 50 defines the requirements for transparency and provenance — the machine-readable labeling of AI-generated content (para. 2) applies only to providers who develop a system or offer it under their own brand; deployers of third-party AI tools are subject to the disclosure obligations under para. 4. An audit process begins with the question: where is the evidence?
CERTavia generates this evidence as an audit-ready document. The result is binary, deterministic, and carries a tamper-proof cryptographic signature. Boards receive a document they can hand directly to an external auditor.
Four deliverables, one validation procedure
PDF audit report with cluster-based Art. 50 assessment
A structured document with a cluster-based infrastructure assessment referencing the infrastructure-relevant aspects of Art. 50 of the EU AI Act. Ready for internal compliance documentation and external auditors.
Independently verifiable
Every certificate carries a cryptographic signature that immutably documents the check timestamp and result. The signature is independently verifiable.
Sovereign Vault link
The certificate resides in the Sovereign Vault as a publicly verifiable evidence record, retrievable at any time. The link can be forwarded to auditors, investors, and the supervisory board.
Verifiable without system access
In the Pro package and above, CERTavia delivers a machine-readable verification URL. External systems and auditors can query the status in an automated way.
What the audit report looks like
The PDF audit report contains an executive summary, the strategic assessment with cluster evaluation, the Art. 50 relevance assessment, and the Sovereign Vault link as a verifiable anchor. The document is readable for decision-makers without a technical background and fully traceable for auditors with one.
- Executive summary (1 page, ready to hand to auditors and the supervisory board)
- Strategic assessment: 4 evaluation areas with Art. 50 reference
- Art. 50 relevance assessment per cluster (critical / relevant / informative)
- Prioritized action items for FAILED or partial findings
- Cryptographic signature + timestamp (Ed25519, tamper-proof)
- Sovereign Vault link — permanently retrievable via token (Pro) / available for 90 days (Basic)
- Machine-readable verification URL for auditors (from Pro)
- JSON + CSV log output for GRC systems
- Legal disclaimer
What's at stake
Art. 99 of the EU AI Act sets the fine framework for violations of the requirements for high-risk AI systems and the transparency obligations under Art. 50 at up to €15 million or 3% of worldwide annual turnover (Art. 99 para. 4) — whichever is higher. The higher framework of €35 million or 7% applies exclusively to the prohibited practices under Art. 5 (Art. 99 para. 3). For financial service providers, the DORA fine regime accumulates on top.
Relevant for boards: BaFin and the national market surveillance authorities can impose sanctions directly on responsible individuals if a company has systematically violated compliance requirements. Personal board liability is not a hypothetical scenario — it is an explicit instrument.
CERTavia delivers demonstrable evidence that your company has actively reviewed and documented its technical compliance foundation — an essential element of the board's duty of care.
August 2, 2026: Art. 50 becomes applicable
The EU AI Act's transparency obligations (Art. 50) apply from August 2, 2026. The comprehensive high-risk obligations were postponed via the AI Omnibus (Annex III to December 2027, Annex I to August 2028) — Art. 50 remained in place. Companies that can demonstrate an audit-ready compliance foundation by this date position themselves as prepared organizations to regulators, customers, and investors.
CERTavia delivers the technical foundation for this position. The validation procedure takes 90 to 120 seconds. Documentation is available from the first scan.
Decision-makers in regulated sectors
Companies with production AI in the following areas have an immediate need for verifiable infrastructure documentation.
Financial services
DORA and the EU AI Act overlap in their requirements for infrastructure integrity. CERTavia delivers the technical evidence for both frameworks in a single validation procedure.
Healthcare
AI systems in diagnostics and patient management fall under Annex III No. 2. The CERTavia report forms the technical building block for the conformity assessment dossier.
HR and recruiting
Systems for candidate selection and employee evaluation fall under Annex III No. 4. Enterprise customers and clients increasingly demand a demonstrable compliance status across the supply chain.
Public sector
Authorities and municipal clients deploying AI-powered processes face direct audit pressure. A verified infrastructure status strengthens their position toward regulators and audit courts.
A document that answers questions
Supervisory boards and investors repeatedly ask a recurring question in AI-related due-diligence processes: What technical evidence do you have for the integrity of your AI infrastructure?
CERTavia delivers the answer as a hand-off-ready document. The PDF audit report contains an executive summary, the strategic assessment across four strategic evaluation areas of the executive summary, and the Sovereign Vault link as a verifiable anchor. The document is readable for decision-makers without a technical background and fully traceable for auditors with one.
Infrastructure evidence in 90 seconds
Enter a domain, the scan runs automatically, the finding is available immediately. No form, no registration. For enterprise inquiries, the contact form is available.
Pricing for decision-makers
PDF audit report, cryptographic signature, Sovereign Vault available for 90 days (local archiving required afterward). Suitable for initial audit-ready documentation.
Sovereign Vault with no automatic expiration date, machine-readable verification URL, API output. Suitable as a technical building block for the conformity assessment dossier.
Quarterly re-scans, annual evidence, change notifications. Up to 25 domains. Suitable for companies with ongoing compliance requirements.
Annual Subscription automatically activates customer portal access (login via email link, no account needed); Basic and Pro can add portal access on request.
Further reading
The deterministic validation process and the check procedure explained.
EU AI Act quick assessment →Evaluate your company's Annex III risk in two minutes.
Plans and pricing →All packages from Basic to Enterprise at a glance.
NIS2 obligations and recommendations (blog) →What NIS2 specifically requires of high-risk AI operators — and how to demonstrate evidence-readiness at board level.
Evidence and benchmark →Verified scan results from practice — cryptographically signed and verifiable via the Sovereign Vault.
Whitepaper: EU AI Act infrastructure compliance →What Art. 50 means technically, what infrastructure evidence auditors expect, and how the validation process works — free download.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.