We load your pages in a real browser, open your chat widget the way a visitor does, sample the images you actually serve, and record what was on screen with a SHA-256 hash and a timestamp. Reading the findings is free. The sealed record is €79.
We are not a law firm, and we never call a site compliant. Two of the nine checks cannot be observed from outside a site at all — we ask you those, and label the answer as yours.
Scan your site → See a finished report →
The free scan reads your homepage. Evidence Pack €79 per scan, monitoring from €20/month, 7-day trial on both.
We swept 1,088 EU-facing sites, homepage only, each in a real browser.
The disclosure has to land at the first interaction. Not in your terms, not in the cookie banner, and not implied by calling the bot "Assistant". The exception is where it would already be obvious to a reasonably well-informed person, which a support bot writing fluent natural language is not. In practice this is one line in the opening message, plus a label that stays on the window.
AI-generated audio, image, video, and text must be marked in a machine-readable, detectable format. Systems already on the market before 2 August 2026 have until 2 December 2026 for this one.
Tell the people exposed to it.
Clear disclosure that content was AI-generated or manipulated, including news-style text published to inform the public.
Paste a URL. Nothing to install. We dismiss the cookie wall first, because on real EU sites that is what stops the widget opening at all.
Nine checks, each tied to one obligation and graded separately. Free, always.
€79 re-runs the scan at full depth: up to 100 pages, root causes, and the raw appendix. The result is sealed — SHA-256 over every artefact, signed, kept 365 days, and checkable by anyone at /verify/ without taking our word for it.
Disclosures disappear without anyone deciding to remove them. A widget ships an update, a CMS migration drops metadata. Re-scans on a schedule, diffed against the last one.
| Self-assessmentquestionnaires, checklists | Disclosure widgeta script that adds a banner | DisclosureProofan outside check | |
|---|---|---|---|
| Where the answer comes from | What you tell it | The vendor's own logs | What your live site showed a visitor |
| Fixes the gap | – | Yes — that is what it is for | No. We record it and tell you where |
| Covers 50(3), which nothing outside a site can observe | Yes | – | Only from your own sealed answer |
| Cost to start | Nothing, and about an hour | A monthly fee | Free scan; €79 to seal one |
| Opens the chat widget like a visitor | – | – | Yes |
| Gets past a cookie wall first | – | n/a | Yes |
| Works on a site you do not control | – | – | Any public URL |
| Evidence a third party can check | – | Vendor-held logs | Hashed and signed; verifiable by anyone |
| Tells you when it silently changes | – | – | Scheduled re-scans, diffed |
| Says "compliant" about you | Often | Often | Never, and here is why |
A widget and a scan are not really alternatives: one changes what your site shows, the other records what it showed. Plenty of people should buy the widget and never buy us. The longer comparisons →
One rulebook today. The others are on a list, not in the product — we would rather say so than put three equal-looking cards here.
2026.10. Applies to anyone whose chatbot or
AI content reaches people in the EU, wherever the company is registered.Article 50 is the EU AI Act's transparency rulebook. It sets four disclosure duties: AI systems that interact with people must reveal they are AI; AI-generated image, audio, video, and text must be machine-readable as synthetic; anyone put in front of emotion-recognition or biometric-categorisation systems must be told; and deepfakes and AI-written public-interest text must be labeled. It binds both the provider that builds the AI and the deployer that puts it in front of users, and it applies from 2 August 2026.
Yes, it can. The duties attach to where your users are. If your website, chatbot, or AI-generated content reaches people in the EU, they can apply, because the Act expressly covers providers and deployers outside the EU whenever the system's output is used in the Union. A UK or US business whose AI output reaches people in the EU can be in scope.
It took effect on 2 August 2026. No, the 2025 “Digital Omnibus” did not move that date. The Omnibus, the EU's package to simplify the AI Act, pushed the high-risk system deadlines out to 2027–2028, and a lot of headlines shortened that to “the AI Act is delayed.” The Article 50 transparency duties stayed in place: they have applied since 2 August 2026, and the power to issue fines started the same day. The only part with a later date is machine-readable marking of AI content for generative systems already on the market before 2 August 2026, which has until 2 December 2026.
Up to €15 million or 3% of worldwide annual turnover, whichever is higher. Fines are issued by national market-surveillance authorities and can be levied since 2 August 2026; there is no separate enforcement grace period. Small businesses and start-ups are capped at the lower of those two figures rather than the higher, but the exposure is still real. And because Article 50 is not part of the high-risk regime, there is no conformity paperwork involved. The duty is only to disclose, and to be able to show that you did.
The user has to be told they are dealing with AI clearly and at the first interaction. It cannot sit in your terms or your cookie banner, and a name like “Assistant” does not carry it. In practice that means something visible in the conversation itself: an opening line such as “You're chatting with an AI assistant,” ideally alongside a persistent “AI” label on the chat window. There is a narrow exception when it is already obvious to a reasonable person, but a human-sounding support bot does not qualify. Whatever your chat shows on screen is what a regulator would judge.
Partly the vendor's, but not entirely. The Act splits the duties: providers build the AI, deployers put it in front of users. How the widget is configured on your site, under your brand, is a deployer responsibility that sits with you. Most major widgets already support an AI disclosure; it is often just switched off, worded too weakly, or hidden until someone clicks. “The vendor handles it” is worth confirming rather than assuming. A scan answers it.
Yes. Article 50 has no general small-business exemption. A two-person company running an AI chatbot for EU visitors carries the same disclosure duty as a large enterprise. The AI Act gives SMEs lighter supporting measures, such as priority access to regulatory sandboxes, and a lower maximum fine, but not a pass on transparency itself. Small teams are often more exposed, because the disclosure is missing for the simple reason that nobody turned it on.
Two separate duties. Article 50(2) covers synthetic media: AI-generated or AI-edited image, audio, video, and text, which must carry a machine-readable marking a detector can read. Article 50(4) covers what a person sees: deepfakes, and AI-generated text published to inform the public on matters of public interest, must be clearly labeled as artificial. An AI image, an AI voiceover, or an AI-written news explainer can each trigger these; a private draft you never publish generally does not.
Article 50 is unusually easy to check: a regulator or a competitor does not need your code, only your live site, and user or competitor complaints are a common trigger. Enforcement sits with national market-surveillance authorities, and the burden is on you to show you complied: authorities expect documented evidence: screenshots, configurations and timestamps. That is the gap DisclosureProof fills: it records what your site displayed, and when, so “the notice was there” is something you can prove rather than assert.
No. DisclosureProof is an informational scanning and evidence tool, not a law firm, and a scan is not a certification or a guarantee of compliance. It is built to surface disclosure gaps and preserve timestamped proof of what your site displayed; for how the law applies to your specific circumstances, use qualified counsel.
No account, no card. Capture is capped at 90 seconds, and you get the findings plus the screenshots they were read from.
Scan your site →