All documentation
Artifacts
Article 50 evidence packs and Annex IV technical files: draft to final, choosing the activity window, what ships inside the download, what the signature does and does not prove, and free preview versus paid download.
An artifact is the document Clause50 builds from your record — your system description, the duties that apply to it, the status of each requirement, and the register of evidence behind them. Choose a template, press Generate, and you get a Word file and usually a PDF, along with a digital signature that proves the document has not been altered since it was produced.
The signature proves integrity, not truth. It shows the document and the evidence behind it are exactly as Clause50 produced them. It says nothing about whether the underlying facts are correct, and it is not a certification. Generating is free on every plan; the clean, signed download is what a paid plan buys.
More detail
Article 50 pack versus Annex IV technical file
- EU AI Act Article 50 Transparency Evidence PackThe one most organisations need now. It documents the transparency duties — telling people they are dealing with an AI system, marking synthetic content, notifying people subject to emotion recognition or biometric categorisation, disclosing AI-generated text published on matters of public interest — and shows, duty by duty, what you have recorded. This is the document you hand to a customer, a partner, or an authority that asks how you meet Article 50.
- Annex IV Technical DocumentationA much larger document, and a different obligation. Annex IV is the technical file a provider of a high-risk AI system must keep: system description, development process, risk management, data governance, human oversight, accuracy and robustness. It matters ahead of the 2 December 2027 deadline. Sections whose underlying duties are not yet in force for you appear with their requirements listed and unproved — the honest state, rather than a blank page.
Two smaller templates also exist: a Risk Classification Memo, recording how you classified the system and why, and an Art. 12-style Per-Call Audit Log Export. Which templates you see depends on the rule pack Clause50 has loaded.
Nothing in any of these documents is written by a language model. Every sentence is either your own text, human-authored guidance from the rule pack, or a fact read directly out of your record.
These templates are structured from the regulation and filled from your record. They are not legal advice, and producing one is not a conformity assessment. If your risk classification is wrong, Clause50 will produce a well-formed document about the wrong duties.
Draft, then final
Every run produces a draft. A draft is a complete, real, already-signed document — the status describes your intent, not the document's quality.
- Generating again makes a new versionVersion 1 becomes 2, 2 becomes 3, and the previous one is marked superseded. Nothing is overwritten: the earlier version's files and signature stay exactly as they were, which is what lets you show what you had at a past date.
- Finalize marks the one you stand behindIt records that this version is the one you are treating as issued. Only a draft that has not been superseded can be finalized — you cannot retroactively finalize a version you have already replaced.
- Each run recalculates coverage firstSo the statuses and the score inside the document are the ones true at the moment it was built, never a stale figure.
If document conversion happens to be unavailable when you generate, Clause50 produces the Word file and omits the PDF rather than failing the whole run — a missing PDF is a smaller problem than a missing pack. Generate again to retry.
Choosing what the document covers
Two choices sit next to Generate, and both change what comes out rather than how it looks.
- Activity windowWhich stretch of your record the document reports on: since your last final version (the default, and the right answer for a periodic update — it covers exactly what has happened since the last document you stood behind), the last 12 months, or a custom range you pick. The window affects the operational activity reported; your requirement statuses and score always describe today.
- Executive summaryA shorter document for a reader who needs the position rather than the evidence behind it. It is the same underlying record and the same signature — not a different, weaker document.
Where a window contains more records than a person could usefully read — months of hourly usage totals, say — the document summarises them by period and kind instead of listing every one, and ships the full detail in the pack's evidence/rollups/ folder. Nothing is dropped; it moves from the page to a file, so the document stays readable and the record stays complete.
Monthly drafts, generated for you
On a paid plan, Clause50 generates an Article 50 draft for each of your systems at the start of every month, without being asked. You will find it waiting in the artifacts list.
The point is not the document — you could have generated it yourself. It is that a month in which nothing was recorded produces a draft that visibly says so, which is a far more useful thing to discover than an empty artifacts list. One draft per system per month: if the scheduled run happens twice, you do not get two.
What the signature proves
Every artifact carries a manifest: a compact record of what was built and from what. It names the system, the template, the version of the rule pack, the coverage score and every requirement status, the identifiers and fingerprints of the evidence the document draws on, where your evidence chain stood at that instant, and a fingerprint of the exact text the Word and PDF files were produced from.
That manifest is then digitally signed: sealed with a private key held by Clause50 in a way that anyone holding the matching published key can check, without being able to produce a signature themselves. The signature travels with the download.
So anyone with the pack and the published key can confirm:
- The document has not been alteredsince Clause50 produced it. Change a word in the Word file and its fingerprint no longer matches the signed manifest.
- The evidence behind it has not been swappedThe manifest lists the exact evidence, by identifier and fingerprint.
- The figures are the ones that were generatedThe score and every requirement status sit inside the signed record, so the numbers cannot be quietly improved afterwards.
Checking any of this does not require trusting Clause50 at the moment of checking. The manifest and the signature are inside the downloadable pack, and verifying them needs only the published key.
And what it does not prove
This is the part that matters most, and Clause50 would rather say it than have an auditor discover it.
- It does not prove the underlying facts are trueA signature proves integrity, not truth. If you state that your chatbot discloses its nature and it does not, Clause50 will faithfully record that statement, faithfully include it, and faithfully sign the result. The document proves you stated it on a given date and that the statement has not been altered since. It proves nothing about the world.
- It is not a certification or a conformity assessmentClause50 is not a notified body and issues no compliance verdict. An artifact is organised evidence, which is what an assessment consumes — not the assessment.
- It does not prove your record is completeThe chain proves that the evidence in it has not been altered, removed, or reordered. It cannot prove everything relevant was ever recorded, and it cannot defend against a party holding both the database and the signing key — which today is Clause50 itself. Closing that last gap needs customer-held keys or external anchoring, neither of which exists yet. Anyone who tells you a signed export is “provably complete” is overselling it.
What is in the download
Download pack assembles one self-contained ZIP file, named for your organisation, the version, and the date:
- The plain-text source of the documentThe exact text the other files were produced from, and the thing the signature anchors.
- The Word documentCarrying your organisation name and the time it was generated.
- The PDFWhen one was produced.
manifest-bundle.jsonThe manifest, its signature, and the identifier of the key that signed it. This file keeps its conventional name so an auditor's tooling can find it.- An
evidence/folder — the documents themselvesEvery uploaded file the document cites, shipped inside the pack rather than merely referenced by fingerprint. Alongside them,evidence/README.mdmaps each row of the evidence register to its file and its hash, so a reader can go from a line in the document to the actual document behind it without asking you for anything. Where the pack summarises high-volume records rather than listing them individually,evidence/rollups/carries the detail those summaries were computed from. VERIFY-THIS-PACK.mdInstructions for checking the signature, written for someone who has never heard of Clause50, with the signature in copy-pasteable form. It is a convenience file and is not itself signed —manifest-bundle.jsonis the authority. See Verification.
The evidence/ folder is the part worth insisting on. A pack that cited every document by hash and shipped none of them would be internally consistent and practically useless: the auditor would hold a list of fingerprints with nothing to compare them against, and you would hold a document that describes your evidence instead of containing it. A hash is a reference to evidence, never evidence.
Free preview versus paid download
Generating is free. Every plan, including the free one, can create a system, complete the intake, see full coverage, and produce documents. What a paid plan buys is the clean, signed download — and it is the signature, not the formatting, that is the line. A free plan never receives the signature, because a watermark-only distinction would still be handing out usable evidence.
| Feature | Free | Paid |
|---|---|---|
| Track AI systems | Yes (1) | Yes (per-plan limit — see Pricing) |
| Coverage dashboard & gap analysis | Yes | Yes |
| Plain-English EU AI Act guidance | Yes | Yes |
| Signed, auditor-ready evidence packs | — | Yes |
| Verifiable export bundle (ZIP + manifest) | — | Yes |
| Connectors (OpenAI / Anthropic / GitHub) | — | Yes |
| Automatic alerts when things change | — | Yes |
| Vendor-questionnaire exports | — | Yes, on Growth |
| White-label artifact branding | — | Yes, on Growth |
| Priority support | — | Yes, on Growth |
| Annex IV high-risk technical-file templates | — | Yes, on Annex IV readiness |
What “preview only” looks like in practice depends on a setting Clause50 operates globally: on the free plan you will either see a watermarked draft on screen, or be able to download a watermarked DRAFT — NOT VALID EVIDENCE version, or be asked to upgrade at the point of download. In all three cases the signature is withheld. Your current plan is shown on the Billing page inside the app.
One boundary worth being precise about, because it is easy to assume the wrong thing in either direction. A file you have already downloaded is yours to keep — Clause50 cannot reach into your systems, and its signature stays valid forever. Re-downloading from Clause50 is checked against your plan at the moment you ask, so if a plan lapses, the signed copy you hold still verifies, but fetching a fresh one requires a current entitlement. Keep a copy of anything you have issued.