Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
Resources · Coverage

What Clause50 covers today — and where it stops

Clause50 evaluates your systems against a versioned rule pack: a machine-readable model of the obligations, where each rule cites the article it comes from. The lists below are read from that pack as it is loaded right now — not written on this page — so they cannot drift from what the product actually evaluates.

The obligations we model

Rule pack eu-ai-act version 2026.1918 obligations modelled, 5 of them in force today. Content hash c6a037527b1c. Every artifact Clause50 signs names the pack version it was evaluated against, so a claim made months ago can still be traced to the exact rules that produced it.

In force now

Evaluated against every system you record today.

In force now
5rules
Art.5Art.50(1)Art.50(2)Art.50(3)Art.50(4)

Modelled, not yet in force

Already in the pack, already visible in your obligations view, and not yet counted against you.

From 2 December 2027
13rules
AnnexIV.1AnnexIV.2AnnexIV.3AnnexIV.6AnnexIV.7Art.10Art.12Art.13Art.14Art.15Art.47Art.72Art.9

Of Annex IV’s 9 points — the contents of the technical file, fixed by the regulation — the pack currently models 5 directly by number (points 1, 2, 3, 6, 7), alongside the Chapter III articles above that several of the remaining points are built from. What each point contains is a fact about the regulation and lives on the high-risk page, not here.

Where Clause50 stops

Clause50 assembles evidence toward your obligations. It is not the compliance programme, and no tool can be. Saying so plainly is the point of this section — the obligations below stay yours, whatever software you buy:

  • Not the quality management system (Article 17). A provider of a high-risk system must operate a documented QMS covering its whole organisation. Clause50 does not run one for you.
  • Not conformity assessment (Article 43). Whether by internal control or through a notified body, the assessment itself is a procedure you complete — not an output of this product.
  • Not EU database registration (Articles 49 and 71). Registering the system in the EU database is your filing.
  • Not the fundamental rights impact assessment (Article 27). Where a deployer owes a FRIA, it is a substantive assessment about the people affected, not a document template.
  • Post-market monitoring is a process, not a file (Article 72). The pack carries the rule and Clause50 evidences what you did; running the monitoring is yours.
  • Not legal advice. Clause50 is a documentation tool and does not by itself make any system compliant. Verify obligations against the primary regulation or your counsel.

What the score does and does not say

A coverage percentage is not a compliance percentage. Some evidence Clause50 collects automatically and re-verifies continuously — logs, versions, changes. Other evidence is a document you attached — design choices, data governance, risk management, human oversight. Both count toward coverage; only the first is continuously true.

We would rather you knew which is which than have a bigger number. The obligations view inside the product separates them, and every signed artifact records the distinction rather than flattening it.

See where your system actually stands

The applicability check tells you which of the obligations above apply to a given system, in about two minutes, with no account and nothing to install.

Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.