How this scanner works
We load your URL in a real headless Chromium browser, wait for late-mounting widgets, and inspect what a visitor actually receives. Static HTML fetching would miss most chat and voice assistants, because they inject themselves at runtime.
How to read a result
Every finding carries one of four severities and one clause citation. The severity tells you what we established; the citation tells you against what.
- Severity: FAIL
- We observed the surface, we observed the absence of what the clause asks for, and no exemption we can test for applies. This is the set to look at first. It is a report of what we saw, not a finding of breach — that is not ours to make.
- Severity: WARN
- What the clause asks for was probably absent, or the answer turns on a fact only you hold — usually whether a given asset was AI-generated at all. The finding says which fact.
- Severity: UNVERIFIED
- We could not answer without acting on your live system, so we stopped and said so. It is not a pass, not a fail, and not a maybe — it is a named gap with a named reason. See what we refuse to guess at.
- Severity: PASS
- What the clause asks for was present on the surface we observed, on this URL, at this moment.
What we check, and against what
Art. 50(1) provider obligation
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.
How we test it: Presence of an AI-interaction disclosure on a detected chat or voice surface, readable before or at the first turn.
Exemptions:
- Disclosure is unnecessary where the AI nature is obvious to a reasonably well-informed, observant and circumspect person in context.
- AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards.
Art. 50(2) provider obligation
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art.
How we test it: Presence of a machine-readable provenance mark (C2PA/Content Credentials manifest, or equivalent metadata assertion) on served synthetic media.
Exemptions:
- AI systems performing an assistive function for standard editing.
- AI systems that do not substantially alter the input data provided by the deployer or its semantics.
Art. 50(2) (robustness limb) provider obligation
The marking solution must be effective, interoperable, robust and reliable as far as technically feasible. A mark that is applied at generation but destroyed by the delivery pipeline is not a robust or reliable marking solution at the point the content reaches a natural person.
How we test it: Comparison of provenance marks on origin assets against the same assets as actually served through the production delivery/transform pipeline.
Exemptions:
- Limits of the generally acknowledged state of the art and technical feasibility for the content type.
Art. 50(3) deployer obligation
Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.
How we test it: Detection of emotion-recognition or biometric-categorisation surfaces (webcam/affect SDKs) without an accompanying exposure notice.
Exemptions:
- AI systems permitted by law to detect, prevent or investigate criminal offences, subject to safeguards.
Art. 50(4), first subparagraph deployer obligation
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake shall disclose that the content has been artificially generated or manipulated. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
How we test it: Presence of a persistent, human-visible label on deepfake-class media (synthetic human likeness, face/voice replacement, avatar presenters).
Exemptions:
- Evidently artistic, creative, satirical or fictional works: reduced to an appropriate, non-intrusive disclosure.
- Use authorised by law for criminal-offence detection, prevention, investigation or prosecution.
Art. 50(4), second subparagraph deployer obligation
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation does not apply where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.
How we test it: Presence of an AI-generation disclosure on public-interest editorial surfaces that declare machine authorship.
Exemptions:
- Content subject to human review or editorial control where a natural or legal person holds editorial responsibility.
Art. 50(5) provider obligation
The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.
How we test it: Timing (present at or before first interaction), prominence (clear and distinguishable), and accessibility (exposed to assistive technology, sufficient contrast) of any disclosure that was found.
What we refuse to guess at
A scanner that guesses is worth nothing to you, because you cannot tell its guesses from its findings. So where we cannot observe something, we say unverified and name the reason. These are the four cases where that happens.
- We do not open your chat widget by default. Clicking a live assistant can create a real conversation in someone's helpdesk. When a disclosure could only be confirmed by opening the widget, we report it as unverified rather than guessing. Scanning your own property with launcher probing enabled gives a definitive answer.
- We do not verify C2PA signatures. We detect whether a manifest is present and structurally locatable. Signature and trust-list validation is a separate question from whether any mark survived delivery at all.
- We do not claim text watermarking works. Statistical text watermarks degrade under paraphrase and are not a solved problem. We will not sell a check we cannot stand behind.
- We do not assess Annex III high-risk obligations, conformity assessment, or fundamental rights impact assessments. Those are different articles on a different timeline.
Whose obligation it is
Article 50(1) and 50(2) bind the provider — whoever develops an AI system and places it on the market under their own name (Art. 3(3)). They do not bind everyone who uses one. So before we report anything we classify the surface:
- Built or configured by you — an in-house assistant, or one built on a toolkit or model API. You developed it and your users meet it under your name, so Art. 50(1) is yours.
- Third-party product, vendor-branded — an unmodified off-the-shelf assistant that identifies its vendor to the user. You are a deployer; the disclosure duty is the vendor's. We still show you the gap, because it is visible on your site, but we do not report it as yours.
- Third-party product under your branding — a vendor SDK surfaced as your own assistant. Genuinely unsettled. We flag it and say so rather than picking the answer that suits us.
- Origin not determinable — usually because the widget lives in a cross-origin frame we do not read. We say so instead of guessing.
Art. 50(3) and 50(4) work the other way round: they are deployer duties, so they attach to whoever runs the surface on this page regardless of who built the model.
Accuracy and false positives
A false accusation is worse than a missed finding. Vendor detections that are primarily human live-chat only count as AI surfaces when something else corroborates automation. Noun phrases like "AI assistant" only count as a disclosure when they appear inside the assistant interface itself, never when they merely appear in marketing copy — otherwise every company that sells AI would appear compliant by accident.