Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
Resources · Blog

Evidence is not a checklist

“We have a compliance checklist” and “we can prove compliance” sound like the same claim. Under the EU AI Act's transparency duties, they are not — and the gap between them is exactly what an inspection tests.

What a checklist actually proves

A checklist proves that, at the moment someone filled it in, they believed a statement to be true. It is a snapshot of a belief, not a record of a fact. It cannot show what a disclosure said six months ago, whether it was live for every user who saw the system in that window, or that nobody quietly reverted it the week after the review.

Article 50 does not ask whether you believe you are compliant. It asks whether the information was actually given, clearly and distinguishably, at the time of first interaction — a question about what happened, not about what someone currently thinks.

The three questions that come up every time

  • “Show me the disclosure as it was on the day.” A screenshot proves what a page looked like when the screenshot was taken. What is wanted is a dated, tamper-evident record tied to the system version that was live.
  • “Show me it was machine-readable.” For 50(2), a visible label is not the obligation — the marking must be in a machine-readable format. Which mechanism was used, and for which output modality, is the fact worth recording.
  • “Show me nothing was edited afterwards.” This is the only question a proper evidence trail uniquely answers. A hash-chained, signed record can be checked by the reader; a folder of exported PDFs cannot — the reader has to trust the folder's owner instead.

Why the gap is the whole point

A checklist and a hash-chained evidence record can describe the exact same underlying reality and still answer an inspection completely differently. The checklist says "someone confirmed this was true." The evidence record says "here is what was actually shown, dated, and unedited since." Only the second one is the kind of proof Article 50 contemplates — the duty is to inform, and the burden that follows is to show that information was actually given, not merely that someone signed off on a form saying it was.

The duty is to inform. The problem is proving you informed — six months ago, on the version of the system that was live then, for every user who saw it.

What good evidence actually looks like

Key takeaways

  • Dated to when it happened, not to when someone got around to writing it down.
  • Tied to the specific system version that was live — a disclosure that changed last month is a different fact from the one in force during an incident six months ago.
  • Tamper-evident, so the record can be checked by a reader rather than merely trusted on the word of whoever compiled it.

None of this requires exotic tooling — it requires treating a disclosure the way any other operational fact is treated: recorded when it happens, never silently edited after the fact. The disclosure generator produces compliant notice text for each of the four Article 50 duties, and is a reasonable place to start even before deciding how evidence will be kept.

Evidence, not screenshots

Clause50 turns disclosures like these into versioned, hash-chained, auditor-ready evidence — dated when it happens, never edited afterwards.

Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.