Why a questionnaire cannot be your evidence
Most EU AI Act tooling is a questionnaire: you answer a set of questions about your systems, and it produces a readiness score or a gap report. That is genuinely useful for working out which duties apply to you. It is not evidence, and the difference matters on the day someone asks you to prove something.
What a questionnaire actually measures
A self-assessment measures your understanding of your own systems at the moment you filled it in. That is a real thing to measure, and for scoping duties it is the right tool: whether you are a provider or a deployer, whether your system is high-risk, whether Article 50 engages at all. No crawler can answer those.
But every answer is an assertion by the party with the most to lose from answering badly. "Does your chatbot disclose that it is an AI?" is answered by the person who configured it, from memory, often months before anyone checks. It is not that people lie. It is that a setting was changed in a vendor update, or the disclosure only shows on desktop, or someone renamed the assistant to something friendlier and nobody connected that to a legal duty.
Where questionnaires and reality come apart
The gap is not hypothetical, and it is not exotic. These are the ordinary ways a truthful answer stops being true:
- A widget vendor ships an update that changes the default greeting, and the AI line goes with it.
- The disclosure renders on desktop but is cut from the compact mobile view, which is where most first interactions happen.
- A cookie wall sits in front of the widget, so a first-time EU visitor never sees the greeting the questionnaire describes.
- Marketing renames the assistant to a human first name and gives it an avatar, which is exactly the pattern the duty targets.
- A CMS migration strips C2PA metadata from published images at optimisation time, silently undoing machine-readable marking.
What a regulator does
Supervisory authorities inspect by looking. Article 50 duties are unusual in that they are almost entirely observable from outside: the disclosure is either shown to a user or it is not. There is no conformity file to produce, no notified body, no certificate. The question is simply what a visitor saw, and when.
That is why the useful artefact is a dated record of what the site actually showed, not a document describing what you intended it to show. A questionnaire answers "what do you believe?" A scan answers "what did it do?"
Use both, for different jobs
This is not an argument that self-assessment is worthless. Scope your duties with a questionnaire, because that part depends on facts about your organisation that no scanner can reach. Then check the observable half from outside, and keep the record.
For the duties that genuinely cannot be observed from outside, such as emotion recognition or biometric categorisation under Article 50(3), we do use a fixed questionnaire, and the answers are sealed alongside the scan and labelled self-attested wherever they appear. Your statement carries your name; our observation carries ours. Keeping those two things visibly separate is the point.
Side by side
| Self-assessment | DisclosureProof | |
|---|---|---|
| Source of the answer | Your recollection of your configuration | What the live site showed a visitor |
| Good at | Scoping which duties apply to you | Checking the duties that are visible from outside |
| Catches silent drift | No: it is a snapshot of a belief | Yes: scheduled re-scans, with alerts |
| Produces evidence | A document about your intentions | Timestamped screenshots and a hashed manifest |
| Third party can verify it | No | Yes: recompute the hashes yourself |
| Covers Art. 50(3) | Yes, and this is the right tool | Via a sealed attestation, labelled self-attested |