EU AI Act · Art. 50 · Enforceable since 2 Aug 2026

Your AI chatbot has new disclosure duties. Your model vendor can't handle them for you.

Enterprise security questionnaires now carry an AI-compliance section. If your bot runs on the OpenAI, Anthropic or Google API, the answers are yours to give — and most teams can't give them yet.

Under Article 50, disclosure obligations sit on the deployer — the company that put the bot in front of users. OpenAI, Anthropic and Google state this in their own terms. There is no toggle upstream that discharges it.

€249 fixed · written report in 48h · scoped by email, invoiced on confirmation

disclosure evidence logdemo-bot.example
2026-08-02 09:14:03Z interaction_disclosure · en/de · live
sha256 4f0c…a913 ← 00e2…77bd · RFC3161 attested
2026-08-02 09:14:20Z jurisdiction added · CA SB 243
sha256 b8d1…02fe ← 4f0c…a913 · RFC3161 attested
2026-08-05 16:40:11Z disclosure text v2 · de revised
sha256 91aa…c4d0 ← b8d1…02fe · RFC3161 attested
Layer 3 preview: every disclosure change hash-chained and independently timestamped. Metadata only — never your users' conversations. Shown here on our own demo bot.
How it works

Three steps from "we should look into this" to "here's our written answer."

Start with the scan. Everything after it is optional and priced separately — the report tells you exactly which pieces you actually need.

STEP 1 · 48 HOURS

Gap-scan

We inventory every point where AI touches your users — chat, generated content, voice — and map each one against the Commission's July 2026 Article 50 guidelines plus the US state chatbot laws that apply to you. You get a written report: what's covered, what's missing, in what order to fix it.

STEP 2 · SAME WEEK

Fix pack

Jurisdiction-mapped disclosure texts, a drop-in React/JS disclosure component you host in your own bot UI, a transparency-policy page template, and an implementation checklist. Your engineers close the gaps in an afternoon, not a sprint.

STEP 3 · ONGOING

Evidence on demand

A hash-chained, independently timestamped record of your disclosure configuration and every change to it. When a procurement team asks "since when, and prove it," you export a dated evidence pack instead of writing an essay.

Read the full method — what gets checked, against what, and by whom →

SAMPLE

Compliance gap report — excerpt

Subject: Acme Support AI — demonstration product (self-scan) · Scope: EU · California

TouchpointObligationStatus
Support chat assistantArt. 50(1) interaction disclosureGAP
Marketing-site chatbotArt. 50(1) interaction disclosureGAP
AI-drafted onboarding emailsArt. 50(2) marking · due 2 Dec 2026PARTIAL
Docs semantic search (retrieval only)Out of Art. 50 scopeN/A

Four rows from an eleven-row findings table. Each gap ships with a fix instruction, draft disclosure text in every locale served, and the guideline reference. This is a self-scan of a demonstration product we built, labeled as such — real anonymized excerpts replace it after first client deliveries.

The deliverable

A report you can hand to your lawyer, your engineers, and your customer's procurement team.

The scan produces one written document. It lists your AI touchpoints, states which obligation applies to each — interaction disclosure, machine-readable marking, AI-generated-text labelling — and marks every gap with a concrete fix, including draft disclosure copy for each jurisdiction.

Most clients forward it directly to counsel for sign-off. The mapping work is done; the billable hours it replaces are the discovery, not the judgment.

Request the full sample →
Pricing

Fixed prices. Buy only the layer you need.

Layer 1 · Start here

Compliance gap-scan

€249
one-time · report in 48h
  • Full AI touchpoint inventory
  • Per-touchpoint Article 50 mapping
  • EU + CA + UT + CO overlay
  • Prioritized fix list, in writing
Book the scan →

Invoice payable by bank transfer (SEPA) after scope confirmation — no card required.

Layer 2

Disclosure pack

€49
one-time
  • Jurisdiction-mapped disclosure texts
  • Self-hosted React/JS component
  • Transparency-policy template
  • Implementation checklist
Ships with scan follow-up
Layer 3

Evidence log

€19
per month
  • Hash-chained config history
  • RFC 3161 timestamps
  • Exportable evidence pack
  • Regulatory-change monitor
Opening shortly
Layer 4

Procurement trust report

€399
per year
  • Answers the AI section of security questionnaires
  • Dated, hash-referenced PDF
  • Optional hosted trust page
For teams with a live enterprise deal

The evidence log runs on EU-region infrastructure (Supabase, Frankfurt) and stores configuration metadata only — no chat content, no screenshots, no end-user personal data, by design. Where everything else sits, including what we have not verified, is set out plainly in the privacy policy. Delivery windows and the refund policy are in the terms of service.

FAQ

Questions buyers actually ask

Is this legal advice?
No. DeployerProof is a compliance-engineering service. The report maps the Commission's published Article 50 guidelines and US state statutes to your product and tells you what to implement. Your counsel signs off on the result — most clients hand our report to their lawyer and save the discovery hours.
We run our bot on Intercom / Zendesk / another platform. Should we buy this?
No — and we'll tell you so on a discovery call rather than take your money. Platform vendors ship their own disclosure controls for bots built inside their products. DeployerProof exists for the case those toggles don't cover: bots and generative features you built yourself on a foundation-model API.
Can't we just add "You're chatting with AI" to the widget ourselves?
You can, and the report may confirm that's most of what you need — in which case you're done for €249. But the banner is one of up to four obligations: interaction disclosure, machine-readable marking of generated content, AI-generated-text labelling in some cases, and jurisdiction variants. Procurement questionnaires also ask for dated evidence of when disclosures went live, which a banner alone can't produce.
What data do you store?
For the scan: what you show us — public URLs and the product walkthrough you give us. For the evidence log: configuration metadata only — disclosure texts, version history, hashes, timestamps. Never conversation content, never screenshots containing user data, never end-user personal data. The evidence log sits on EU-region infrastructure (Supabase, Frankfurt). Correspondence sits with our mail provider in a region we have not verified, so we do not claim one — the privacy policy says exactly that, and the scan is built not to need your users' data in the first place.
Nobody has been fined yet. Why act now?
Correct, and we don't sell fine-fear. The live cost today is deal velocity: the AI-compliance section appearing in enterprise vendor questionnaires. A blank answer there stalls procurement for weeks. Article 50 has been enforceable since 2 August 2026; the questionnaires arrived first.
How does payment work?
You email to book, we agree the scope in writing, and then you get an invoice payable by bank transfer — SEPA for EU clients. No card details change hands and there is no checkout page to click through. One thing worth knowing when you plan: the 48-hour delivery window runs from the payment landing, not from the invoice date, so allow a day or two for the transfer. If the report doesn't arrive inside that window, the fee comes back in full — that promise is written into the terms.
Who is behind this?
A solo compliance-engineering practice. You're buying a written artifact judged on its content — request the full sample report before paying anything. No retainers, no invented client logos, no testimonials we don't have. The longer answer, including who the operator is, lives on the method page.