For boards and decision-makers

The evidence that holds up to auditors.

From August 2, 2026, the transparency obligations under Art. 50 of the EU AI Act apply. By that date, boards and decision-makers need evidence that stands up to auditors, investors, and their own supervisory board. CERTavia delivers exactly that evidence: cryptographically signed, DNS-anchored, in 90 to 120 seconds.

What regulators want to see

What that means in concrete terms

The EU AI Act requires companies with AI systems to have a demonstrable technical foundation. Art. 50 defines the requirements for transparency and provenance — the machine-readable labeling of AI-generated content (para. 2) applies only to providers who develop a system or offer it under their own brand; deployers of third-party AI tools are subject to the disclosure obligations under para. 4. An audit process begins with the question: where is the evidence?

CERTavia generates this evidence as an audit-ready document. The result is binary, deterministic, and carries a tamper-proof cryptographic signature. Boards receive a document they can hand directly to an external auditor.

What decision-makers receive

Four deliverables, one validation procedure

PDF audit report with cluster-based Art. 50 assessment

A structured document with a cluster-based infrastructure assessment referencing the infrastructure-relevant aspects of Art. 50 of the EU AI Act. Ready for internal compliance documentation and external auditors.

Independently verifiable

Every certificate carries a cryptographic signature that immutably documents the check timestamp and result. The signature is independently verifiable.

Sovereign Vault link

The certificate resides in the Sovereign Vault as a publicly verifiable evidence record, retrievable at any time. The link can be forwarded to auditors, investors, and the supervisory board.

Verifiable without system access

In the Pro package and above, CERTavia delivers a machine-readable verification URL. External systems and auditors can query the status in an automated way.

Result document

What the audit report looks like

The PDF audit report contains an executive summary, the strategic assessment with cluster evaluation, the Art. 50 relevance assessment, and the Sovereign Vault link as a verifiable anchor. The document is readable for decision-makers without a technical background and fully traceable for auditors with one.

SOVP Audit Report CERTIFIED
  • Executive summary (1 page, ready to hand to auditors and the supervisory board)
  • Strategic assessment: 4 evaluation areas with Art. 50 reference
  • Art. 50 relevance assessment per cluster (critical / relevant / informative)
  • Prioritized action items for FAILED or partial findings
  • Cryptographic signature + timestamp (Ed25519, tamper-proof)
  • Sovereign Vault link — permanently retrievable via token (Pro) / available for 90 days (Basic)
  • Machine-readable verification URL for auditors (from Pro)
  • JSON + CSV log output for GRC systems
  • Legal disclaimer
Personal responsibility

What's at stake

Art. 99 of the EU AI Act sets the fine framework for violations of the requirements for high-risk AI systems and the transparency obligations under Art. 50 at up to €15 million or 3% of worldwide annual turnover (Art. 99 para. 4) — whichever is higher. The higher framework of €35 million or 7% applies exclusively to the prohibited practices under Art. 5 (Art. 99 para. 3). For financial service providers, the DORA fine regime accumulates on top.

Relevant for boards: BaFin and the national market surveillance authorities can impose sanctions directly on responsible individuals if a company has systematically violated compliance requirements. Personal board liability is not a hypothetical scenario — it is an explicit instrument.

EU AI Act fine framework
up to €15M
or 3% of worldwide annual turnover for high-risk and Art. 50 violations (Art. 99 para. 4); up to €35M or 7% for prohibited practices under Art. 5 (Art. 99 para. 3)
False statements to authorities
up to €7.5M
or 1% of worldwide annual turnover (Art. 99 para. 5)
Personal board liability
Directly possible
Regulators can impose measures against responsible individuals

CERTavia delivers demonstrable evidence that your company has actively reviewed and documented its technical compliance foundation — an essential element of the board's duty of care.

The time window

August 2, 2026: Art. 50 becomes applicable

The EU AI Act's transparency obligations (Art. 50) apply from August 2, 2026. The comprehensive high-risk obligations were postponed via the AI Omnibus (Annex III to December 2027, Annex I to August 2028) — Art. 50 remained in place. Companies that can demonstrate an audit-ready compliance foundation by this date position themselves as prepared organizations to regulators, customers, and investors.

CERTavia delivers the technical foundation for this position. The validation procedure takes 90 to 120 seconds. Documentation is available from the first scan.

Who this evidence is relevant for

Decision-makers in regulated sectors

Companies with production AI in the following areas have an immediate need for verifiable infrastructure documentation.

Financial services

DORA and the EU AI Act overlap in their requirements for infrastructure integrity. CERTavia delivers the technical evidence for both frameworks in a single validation procedure.

Healthcare

AI systems in diagnostics and patient management fall under Annex III No. 2. The CERTavia report forms the technical building block for the conformity assessment dossier.

HR and recruiting

Systems for candidate selection and employee evaluation fall under Annex III No. 4. Enterprise customers and clients increasingly demand a demonstrable compliance status across the supply chain.

Public sector

Authorities and municipal clients deploying AI-powered processes face direct audit pressure. A verified infrastructure status strengthens their position toward regulators and audit courts.

The conversation with the supervisory board

A document that answers questions

Supervisory boards and investors repeatedly ask a recurring question in AI-related due-diligence processes: What technical evidence do you have for the integrity of your AI infrastructure?

CERTavia delivers the answer as a hand-off-ready document. The PDF audit report contains an executive summary, the strategic assessment across four strategic evaluation areas of the executive summary, and the Sovereign Vault link as a verifiable anchor. The document is readable for decision-makers without a technical background and fully traceable for auditors with one.

Next step

Infrastructure evidence in 90 seconds

Enter a domain, the scan runs automatically, the finding is available immediately. No form, no registration. For enterprise inquiries, the contact form is available.

Starting at EUR 490

Pricing for decision-makers

Basic from EUR 490

PDF audit report, cryptographic signature, Sovereign Vault available for 90 days (local archiving required afterward). Suitable for initial audit-ready documentation.

Pro from EUR 1,490

Sovereign Vault with no automatic expiration date, machine-readable verification URL, API output. Suitable as a technical building block for the conformity assessment dossier.

Annual Subscription from EUR 9,900 / year

Quarterly re-scans, annual evidence, change notifications. Up to 25 domains. Suitable for companies with ongoing compliance requirements.

Annual Subscription automatically activates customer portal access (login via email link, no account needed); Basic and Pro can add portal access on request.