Your AI chatbot has new disclosure duties. Your model vendor can't handle them for you.
Enterprise security questionnaires now carry an AI-compliance section. If your bot runs on the OpenAI, Anthropic or Google API, the answers are yours to give — and most teams can't give them yet.
Under Article 50, disclosure obligations sit on the deployer — the company that put the bot in front of users. OpenAI, Anthropic and Google state this in their own terms. There is no toggle upstream that discharges it.
€249 fixed · written report in 48h · scoped by email, invoiced on confirmation
Three steps from "we should look into this" to "here's our written answer."
Start with the scan. Everything after it is optional and priced separately — the report tells you exactly which pieces you actually need.
Gap-scan
We inventory every point where AI touches your users — chat, generated content, voice — and map each one against the Commission's July 2026 Article 50 guidelines plus the US state chatbot laws that apply to you. You get a written report: what's covered, what's missing, in what order to fix it.
Fix pack
Jurisdiction-mapped disclosure texts, a drop-in React/JS disclosure component you host in your own bot UI, a transparency-policy page template, and an implementation checklist. Your engineers close the gaps in an afternoon, not a sprint.
Evidence on demand
A hash-chained, independently timestamped record of your disclosure configuration and every change to it. When a procurement team asks "since when, and prove it," you export a dated evidence pack instead of writing an essay.
Read the full method — what gets checked, against what, and by whom →
Compliance gap report — excerpt
| Touchpoint | Obligation | Status |
|---|---|---|
| Support chat assistant | Art. 50(1) interaction disclosure | GAP |
| Marketing-site chatbot | Art. 50(1) interaction disclosure | GAP |
| AI-drafted onboarding emails | Art. 50(2) marking · due 2 Dec 2026 | PARTIAL |
| Docs semantic search (retrieval only) | Out of Art. 50 scope | N/A |
Four rows from an eleven-row findings table. Each gap ships with a fix instruction, draft disclosure text in every locale served, and the guideline reference. This is a self-scan of a demonstration product we built, labeled as such — real anonymized excerpts replace it after first client deliveries.
A report you can hand to your lawyer, your engineers, and your customer's procurement team.
The scan produces one written document. It lists your AI touchpoints, states which obligation applies to each — interaction disclosure, machine-readable marking, AI-generated-text labelling — and marks every gap with a concrete fix, including draft disclosure copy for each jurisdiction.
Most clients forward it directly to counsel for sign-off. The mapping work is done; the billable hours it replaces are the discovery, not the judgment.
Request the full sample →Fixed prices. Buy only the layer you need.
Compliance gap-scan
- Full AI touchpoint inventory
- Per-touchpoint Article 50 mapping
- EU + CA + UT + CO overlay
- Prioritized fix list, in writing
Invoice payable by bank transfer (SEPA) after scope confirmation — no card required.
Disclosure pack
- Jurisdiction-mapped disclosure texts
- Self-hosted React/JS component
- Transparency-policy template
- Implementation checklist
Evidence log
- Hash-chained config history
- RFC 3161 timestamps
- Exportable evidence pack
- Regulatory-change monitor
Procurement trust report
- Answers the AI section of security questionnaires
- Dated, hash-referenced PDF
- Optional hosted trust page
The evidence log runs on EU-region infrastructure (Supabase, Frankfurt) and stores configuration metadata only — no chat content, no screenshots, no end-user personal data, by design. Where everything else sits, including what we have not verified, is set out plainly in the privacy policy. Delivery windows and the refund policy are in the terms of service.