The method is published because the report is the product.
A compliance vendor asking you to trust an unexplained process would be selling the exact problem it claims to fix. So here is the whole thing: what gets inventoried, what it gets mapped against, how jurisdictions stack, and what you receive at the end. Limits included.
Every scan runs the same sequence.
Fixed scope is what makes a fixed price honest. The stages below are worked through in order, against a versioned internal checklist, for every engagement.
Touchpoint inventory
We list every point where model output reaches a person: chat interfaces, generated emails and documents, voice features, AI-written answer boxes, anything synthetic your users see or hear. The inventory works from what you show us — a product walkthrough, public URLs, your description of how the features are wired — plus what is visible from outside.
Just as important is what leaves the list. Retrieval-only search, internal-facing tools, and classic automation without generative output are recorded as out of Article 50 scope, with the reason stated. A report that marks four of six touchpoints "no obligation applies" is doing its job.
Output: a numbered touchpoint register, each entry tied to a product surface.Obligation mapping
Each touchpoint is tested against the Article 50 duties that can attach to it: the interaction disclosure of 50(1), machine-readable marking of synthetic content under 50(2), and the labelling duties of 50(4) where they reach a deployer. The mapping states whether your company acts as deployer or provider for that surface, because the duties differ and the distinction is where most self-assessments go wrong.
Every finding carries a status — gap, partial, covered, or not applicable — and cites the provision it rests on.
Output: a findings table, one row per touchpoint-obligation pair, each with a citation.Jurisdiction overlay
The EU baseline is then overlaid with the US state laws that actually bind companies your size: California SB 243 for companion-style chatbots, Utah's UAIPA, and Colorado's SB 26-189. Where a law is in the news but does not apply to you — California SB 942 and AB 853 bind providers above one million monthly users — the report says so instead of borrowing its urgency.
Disclosure copy in the fix list is drafted per locale you serve, because "You are chatting with an AI" is not one sentence when your bot speaks three languages.
Output: a per-jurisdiction applicability matrix, including the laws ruled out.Prioritized fixes
Findings become a fix list ordered by exposure, not by ease. Obligations already enforceable come first; deadline-bound items — machine-readable marking is due 2 December 2026 for systems that were on the market before 2 August 2026 — are dated; evidence gaps that stall procurement questionnaires are flagged as such. Each fix names the change, the surface it lands on, and draft disclosure text where text is the fix.
Output: the written report — findings, fixes, draft copy, citations. Yours to hand to counsel.Mapped against the Commission's own guidance, cited by section.
The scan does not measure your product against our opinion of Article 50. It measures against the Commission's final guidelines on Article 50, published 20 July 2026 as C(2026)5054, which set out how the Commission reads the interaction-disclosure, marking, and labelling duties. Where the Code of Practice on Transparency of 10 June 2026 is stricter than the binding minimum, the report notes it — the Code is voluntary, but it is the benchmark enterprise procurement teams are starting to quote.
Findings cite the specific guideline passage they rest on. That is what lets your counsel check the work in minutes rather than re-deriving it, and it is why the report survives being forwarded: an unsourced compliance claim is just a slower email.
Where the guidelines are genuinely ambiguous — and in places they are — the report says "this is unsettled," states the conservative reading, and marks the point for counsel. Papering over ambiguity would make the document look better and be worth less.
What the scan is not.
- Not legal advice. The report is compliance-engineering analysis. It maps published rules to your product and drafts the implementation; a qualified lawyer signs off on the result. Every engagement is built around that handoff, not as a substitute for it.
- Not a certification. Nothing we issue says "compliant" as a verdict. It says: these are your surfaces, these duties attach, here is what is missing and how to close it.
- A point-in-time exercise. The report describes your product on the day of the scan. Ship a new AI feature next quarter and the mapping is stale for that feature — continuous tracking is what the evidence log exists for, and it is priced separately precisely so the scan doesn't quietly become a subscription.
- Bounded by what we can see. The inventory covers the surfaces you show us and what is publicly visible. It is not a code audit or a penetration test, and it cannot find a touchpoint nobody mentions.
- Only for custom-built AI. If your bot lives inside Intercom, Zendesk, or another platform's widget, the platform's own disclosure controls are the right tool and we will decline the engagement — before the invoice, not after.
One person, on the record.
DeployerProof is a solo compliance-engineering practice operated by Amiya Krishna Bera, working from West Bengal, India. Thirteen years of B2B field experience precede it — years spent on the buying and selling side of business deals, which is where the conviction behind this product comes from: deals stall on unanswered questionnaires far more often than they stall on law.
What the practice is not: a law firm, a certification body, or a team pretending to be bigger than it is. There are no invented credentials on this page because there are no credentials to invent — the qualification on offer is the artifact itself. The sample report is public, the FAQ tells you when not to buy, and the operator's legal identity and trading address are printed in the terms, the privacy policy, and on every invoice.
If that trade — a named individual, a published method, a checkable document — beats an anonymous team page with stock photos, we should talk.