“We have a compliance checklist” and “we can prove compliance” sound like the same claim. Under the EU AI Act's transparency duties, they are not — and the gap between them is exactly what an inspection tests.
What a checklist actually proves
A checklist proves that, at the moment someone filled it in, they believed a statement to be true. It is a snapshot of a belief, not a record of a fact. It cannot show what a disclosure said six months ago, whether it was live for every user who saw the system in that window, or that nobody quietly reverted it the week after the review.
Article 50 does not ask whether you believe you are compliant. It asks whether the information was actually given, clearly and distinguishably, at the time of first interaction — a question about what happened, not about what someone currently thinks.
The three questions that come up every time
- “Show me the disclosure as it was on the day.” A screenshot proves what a page looked like when the screenshot was taken. What is wanted is a dated, tamper-evident record tied to the system version that was live.
- “Show me it was machine-readable.” For 50(2), a visible label is not the obligation — the marking must be in a machine-readable format. Which mechanism was used, and for which output modality, is the fact worth recording.
- “Show me nothing was edited afterwards.” This is the only question a proper evidence trail uniquely answers. A hash-chained, signed record can be checked by the reader; a folder of exported PDFs cannot — the reader has to trust the folder's owner instead.
Why the gap is the whole point
A checklist and a hash-chained evidence record can describe the exact same underlying reality and still answer an inspection completely differently. The checklist says "someone confirmed this was true." The evidence record says "here is what was actually shown, dated, and unedited since." Only the second one is the kind of proof Article 50 contemplates — the duty is to inform, and the burden that follows is to show that information was actually given, not merely that someone signed off on a form saying it was.
The duty is to inform. The problem is proving you informed — six months ago, on the version of the system that was live then, for every user who saw it.
What good evidence actually looks like
Key takeaways
- Dated to when it happened, not to when someone got around to writing it down.
- Tied to the specific system version that was live — a disclosure that changed last month is a different fact from the one in force during an incident six months ago.
- Tamper-evident, so the record can be checked by a reader rather than merely trusted on the word of whoever compiled it.
None of this requires exotic tooling — it requires treating a disclosure the way any other operational fact is treated: recorded when it happens, never silently edited after the fact. The disclosure generator produces compliant notice text for each of the four Article 50 duties, and is a reasonable place to start even before deciding how evidence will be kept.