Skip to content
Clause50EU AI Act evidence — starting with Article 50.EU AI Act evidence, starting with Article 50

What Clause50 covers today — and where it stops

Clause50 evaluates your systems against a versioned rule pack: a machine-readable model of the obligations, where each rule cites the article it comes from. The lists below are read from that pack as it is loaded right now — not written on this page — so they cannot drift from what the product actually evaluates.

Clause50 is an EU AI Act evidence platform. It classifies an AI system against the whole Act from one intake — prohibited practices under Article 5 are refused, high-risk systems are screened against all eight Annex III areas and documented across the nine sections of the Annex IV technical file, and the four Article 50 transparency duties are evidenced — and it answers every obligation that applies with append-only, Ed25519-signed evidence that anyone can verify without an account. It records evidence against the 2027 high-risk obligations today, so the file exists on the day they bind — or on the day a significant change brings a legacy system into scope. It pre-fills the EU declaration of conformity and refuses to sign it. It is not the quality management system, conformity assessment, EU database registration or the fundamental rights impact assessment — those stay yours, whichever tool you use.

The obligations we model

Rule pack eu-ai-act version 2026.27 — 24 obligations modelled, 6 of them in force today. Content hash 4e4fbd66874d. Every artifact Clause50 signs names the pack version it was evaluated against, so a claim made months ago can still be traced to the exact rules that produced it.

In force now

Evaluated against every system you record today.

In force now
6rules
Art.5Art.50(1)Art.50(2)Art.50(3)Art.50(4)Art.50(4)-text

Modelled, not yet in force

Already in the pack, already visible in your obligations view, and not yet counted against you.

From 2 December 2026 and 2 December 2027
18rules
Art.5(1a)AnnexIV.1AnnexIV.2AnnexIV.3AnnexIV.6AnnexIV.7Art.10Art.12Art.12(3)Art.13Art.14Art.14(5)Art.15Art.26Art.47Art.6(4)Art.72Art.9

One intake. 24 obligations modelled — 6 in force today, 18 recorded now for 2 December 2026 and 2 December 2027. Rule pack 2026.27.

Article 50 — in force now
  • Art. 50(1)Disclosure of AI interactionin force
  • Art. 50(2)Machine-readable marking and detection of synthetic contentin force
  • Art. 50(3)Notice of emotion recognition / biometric categorisationin force
  • Art. 50(4)Disclosure of deep fakesin force
  • Art. 50(4)-textDisclosure of AI-generated text published on matters of public interestin force
Article 5 — refused, not upsold
  • Art. 5Prohibited AI practicesscreened · refused
  • Art. 5(1a)Safeguards against prohibited sexual contentscreened · refused
High-risk — Annex III systems, evidence recorded now
  • Annex IV · 1General description of the systemfrom 2 Dec 2027
  • Annex IV · 2Detailed description of system elements and development processfrom 2 Dec 2027
  • Annex IV · 3Monitoring, functioning and controlfrom 2 Dec 2027
  • Annex IV · 6Lifecycle changesfrom 2 Dec 2027
  • Annex IV · 7Harmonised standards appliedfrom 2 Dec 2027
  • Art. 6(4)Assessment and registration of an Annex III system its provider considers not high-riskfrom 2 Dec 2027
  • Art. 9Risk management systemfrom 2 Dec 2027
  • Art. 10Data and data governancefrom 2 Dec 2027
  • Art. 12Record-keeping — automatic logging over system lifetimefrom 2 Dec 2027
  • Art. 12(3)Record-keeping — minimum logging for remote biometric identificationfrom 2 Dec 2027
  • Art. 13Transparency and provision of information to deployersfrom 2 Dec 2027
  • Art. 14Human oversightfrom 2 Dec 2027
  • Art. 14(5)Human oversight — two-person verification for remote biometric identificationfrom 2 Dec 2027
  • Art. 15Accuracy, robustness and cybersecurityfrom 2 Dec 2027
  • Art. 26Obligations of deployers of high-risk AI systemsfrom 2 Dec 2027
  • Art. 47EU declaration of conformityfrom 2 Dec 2027
  • Art. 72Post-market monitoring planfrom 2 Dec 2027

A tile is an obligation the product can evidence, not a box it ticks for you — coverage is computed per system after the intake, and the signed document shows it. A minimal-risk system has no obligation in this rule pack, and the memo says so; general-purpose AI models are a separate regime — why GPAI is not Article 50.

Of Annex IV’s 9 points — the contents of the technical file, fixed by the regulation — the pack currently models 5 directly by number (points 1, 2, 3, 6, 7), alongside the Chapter III articles above that several of the remaining points are built from. What each point contains is a fact about the regulation and lives on the high-risk page, not here.

Where Clause50 stops — what stays yours, whichever tool you use

Clause50 assembles evidence toward your obligations. It is not the compliance programme, and no tool can be. Saying so plainly is the point of this section — the obligations below stay yours, whatever software you buy:

  • Not the quality management system (Article 17). A provider of a high-risk system must operate a documented QMS covering its whole organisation. Clause50 does not run one for you. It records your QMS documentation now, once for your organisation, against the thirteen elements of Article 17(1); the duty applies from 2 December 2027.
  • Not conformity assessment (Article 43). Whether by internal control or through a notified body, the assessment itself is a procedure you complete — not an output of this product.
  • Not EU database registration (Articles 49 and 71). Registering the system in the EU database is your filing.
  • Not the fundamental rights impact assessment (Article 27). Where a deployer owes a FRIA, it is a substantive assessment about the people affected, not a document template.
  • Post-market monitoring is a process, not a file (Article 72). The pack carries the rule and Clause50 evidences what you did; running the monitoring is yours.
  • Article 4 AI literacy: recorded, not judged. Clause50 keeps a record of the measures your organisation takes to support AI literacy — once, on its own tamper-evident trail — and tells you when it is due for renewal. Running those measures stays yours, and Clause50 assesses no one's level of AI literacy.
  • Article 26 deployer duties: recorded, not run. If you deploy someone else’s high-risk system, Clause50 classifies it as high-risk for you and records your evidence against Article 26’s core duties — the provider’s instructions for use, human oversight, input data, monitoring, log retention and telling workers — for the duty that applies from 2 December 2027. Following them stays yours, and the fundamental rights impact assessment (Article 27) is not modelled.
  • Not legal advice. Clause50 is an evidence platform and does not by itself make any system compliant. Verify obligations against the primary regulation or your counsel.

What the score does and does not say

A coverage percentage is not a compliance percentage. Some evidence Clause50 collects automatically and re-verifies continuously — logs, versions, changes. Other evidence is a document you attached — design choices, data governance, risk management, human oversight. Both count toward coverage; only the first is continuously true.

We would rather you knew which is which than have a bigger number. The obligations view inside the product separates them, and every signed artifact records the distinction rather than flattening it.

See where your system actually stands

The applicability check tells you which of the obligations above apply to a given system, in about two minutes, with no account and nothing to install.

This page explains Regulation (EU) 2024/1689 in simplified form and has not yet been reviewed by counsel. It is not legal advice, and the obligations described here remain yours — check the primary regulation or your own counsel before relying on it.