Art. 50 EU AI Act

Art. 50 requires machine-readable transparency. CERTavia delivers it in 90 seconds.

The transparency obligations under Art. 50 EU AI Act apply from August 2, 2026 — broadly, not just for high-risk systems. Providers must demonstrate that their AI outputs and their infrastructure are machine-readably labeled and traceable. CERTavia delivers this evidence: cryptographically signed, DNS-anchored, attachable to the Conformity Assessment Dossier.

Golden verification column penetrating three glass layers — Art. 50 Layer-0 evidence
What Art. 50 specifically requires

Four requirements. One machine-readable layer.

Art. 50 EU AI Act is not a process paragraph — it requires that AI outputs and the supporting infrastructure are machine-readably labeled and recognizable as such. And it requires evidence that goes far beyond generic ISO certifications.

Machine-readable labeling

Art. 50 para. 2 requires providers of generative AI systems to label AI-generated content in a machine-readable format and make it recognizable as artificially generated — the obligation applies to whoever develops a system or offers it under their own brand, not to whoever uses third-party AI tools (deployers instead fall under Art. 50 para. 4). ai.txt, agent-card.json and llms.txt do not label AI-generated content within the meaning of para. 2 — they are crawler-access and well-known declarations of the domain for agentic readiness (Cluster E) and thus a separate, independent verification parameter.

Traceable provenance

The origin and authenticity of the labeling must be verifiable. Cryptographic signature, DNS anchoring and TLS integrity make the provenance robust — directly visible in the audit, not only on request.

Transparency toward users and reviewers

Art. 50 requires clear, recognizable disclosure of AI use; the law leaves open what this disclosure technically looks like. CERTavia translates this disclosure obligation into a machine-readable declaration of data sources, AI access configuration and governance policies as technical evidence.

Documentation and evidence obligation

Fulfillment of the Art. 50 requirements must be demonstrable in the Conformity Assessment Dossier; the legislator does not prescribe a specific evidence format for this. Generic ISO certificates document management processes but not a verifiable, machine-readable transparency state at the time of the check. Auditors need both.

ISO 27001 certifies your management system. Art. 50 additionally requires the technical, machine-readable transparency evidence — precise, cryptographically signed, at the time of the check. CERTavia closes this gap.

The solution

CERTavia — the machine-readable transparency building block for Art. 50

The Sovereign Validation Protocol (SOVP) deterministically checks over 80 technical parameters and delivers a cryptographically signed CES score with a CERTIFIED/FAILED verdict — in 90 seconds, without manual intervention.

80+ parameters — deterministically checked

DNSSEC, CAA records, TLS certificate chain, HTTP security headers, AI access configuration, machine-readable governance declarations and more. The SOVP scan covers all infrastructure-relevant parameters that Art. 50 addresses at the transparency and provenance level.

Cryptographic signature — immutable

Every scan result is cryptographically signed and timestamped. The CES score document and the CERTIFIED/FAILED verdict cannot be altered afterward — that is the core of audit readiness.

Sovereign Vault — DNS-anchored

The evidence is stored in the Sovereign Vault and anchored via a DNS entry. Auditors and clients can independently verify authenticity and timestamp via a public URL — without credentials, without contacting your server.

Attachable to the audit dossier

The SOVP evidence is designed as technical proof for internal compliance teams, external auditors and conformity assessment bodies. Includes PDF report and machine-readable evidence file.

The process

Audit-ready evidence in 3 steps

No form. No waiting time. No call required.

1
Scan your domain — free

Enter your domain and start the SOVP quick scan without registration. The free scan delivers the Layer-0 result and immediately shows you whether your infrastructure technically meets the Art. 50 requirements.

2
CERTIFIED / FAILED — in 90 seconds

The SOVP scan deterministically checks 80+ parameters. After 90 seconds, you receive a CES score, a clear CERTIFIED/FAILED verdict, and a list of the checked parameters — reproducible and auditable.

3
Order and forward the evidence

Order the full SOVP evidence (Basic or Pro). The cryptographically signed report is stored in the Sovereign Vault. You receive the Sovereign Vault URL and the PDF report — directly forwardable to auditors, clients, or your compliance documentation.

Plans

One-time. No subscription. Available immediately.

Choose the package that fits your audit needs. Basic for individual audit periods, Pro for permanent vault anchoring and complete audit documentation.

Basic

EUR 490 one-time

SOVP evidence with 90-day validity. Cryptographically signed, Sovereign Vault URL, PDF report. Suitable for individual audit cycles.

Order Basic

Pro

EUR 1,490 one-time

SOVP evidence with Sovereign Vault permanently retrievable via token. DNS-anchored, cryptographically signed, complete PDF report. Recommended for Conformity Assessment Dossiers.

Order Pro
Frequently asked questions

Questions about Art. 50 evidence

Does CERTavia replace an ISO 27001 certification?

No — CERTavia complements ISO 27001 but does not replace it. ISO 27001 certifies management systems and processes. Art. 50 EU AI Act requires transparency and labeling but does not prescribe an evidence format. CERTavia delivers the verifiable, machine-readable infrastructure evidence for this at the specific point in time of the check. Both forms of evidence work together and can be used jointly in the Conformity Assessment Dossier.

How long is the evidence valid?

With Basic evidence, the Sovereign Vault is available for 90 days (local archiving required afterward). With Pro evidence, the Sovereign Vault is permanently retrievable via token — the cryptographic timestamp immutably documents the infrastructure state at the time of issuance. For the ongoing transparency obligations under Art. 50 EU AI Act, we recommend re-scans at least annually and after substantial infrastructure changes.

Can I pass the evidence directly to auditors?

Yes. The Sovereign Vault URL is publicly accessible and independently verifiable by any party — without credentials, without registration. Auditors can view authenticity, timestamp and scan result directly. A PDF report is additionally available for inclusion in audit dossiers.

Act now

Art. 50 transparency starts with the first scan.

Start for free — in 90 seconds you'll know where your infrastructure stands.