EU AI Act · Article 50 applies 2 August 2026
Compare · Self-assessment vs an outside check

Why a questionnaire cannot be your evidence

An honest comparisonLast reviewed July 2026

Most EU AI Act tooling is a questionnaire: you answer a set of questions about your systems, and it produces a readiness score or a gap report. That is genuinely useful for working out which duties apply to you. It is not evidence, and the difference matters on the day someone asks you to prove something.

What a questionnaire actually measures

A self-assessment measures your understanding of your own systems at the moment you filled it in. That is a real thing to measure, and for scoping duties it is the right tool: whether you are a provider or a deployer, whether your system is high-risk, whether Article 50 engages at all. No crawler can answer those.

But every answer is an assertion by the party with the most to lose from answering badly. "Does your chatbot disclose that it is an AI?" is answered by the person who configured it, from memory, often months before anyone checks. It is not that people lie. It is that a setting was changed in a vendor update, or the disclosure only shows on desktop, or someone renamed the assistant to something friendlier and nobody connected that to a legal duty.

Where questionnaires and reality come apart

The gap is not hypothetical, and it is not exotic. These are the ordinary ways a truthful answer stops being true:

What a regulator does

Supervisory authorities inspect by looking. Article 50 duties are unusual in that they are almost entirely observable from outside: the disclosure is either shown to a user or it is not. There is no conformity file to produce, no notified body, no certificate. The question is simply what a visitor saw, and when.

That is why the useful artefact is a dated record of what the site actually showed, not a document describing what you intended it to show. A questionnaire answers "what do you believe?" A scan answers "what did it do?"

Use both, for different jobs

This is not an argument that self-assessment is worthless. Scope your duties with a questionnaire, because that part depends on facts about your organisation that no scanner can reach. Then check the observable half from outside, and keep the record.

For the duties that genuinely cannot be observed from outside, such as emotion recognition or biometric categorisation under Article 50(3), we do use a fixed questionnaire, and the answers are sealed alongside the scan and labelled self-attested wherever they appear. Your statement carries your name; our observation carries ours. Keeping those two things visibly separate is the point.

Side by side

Self-assessmentDisclosureProof
Source of the answerYour recollection of your configurationWhat the live site showed a visitor
Good atScoping which duties apply to youChecking the duties that are visible from outside
Catches silent driftNo: it is a snapshot of a beliefYes: scheduled re-scans, with alerts
Produces evidenceA document about your intentionsTimestamped screenshots and a hashed manifest
Third party can verify itNoYes: recompute the hashes yourself
Covers Art. 50(3)Yes, and this is the right toolVia a sealed attestation, labelled self-attested
If you have already filled in a readiness questionnaire, a scan is the cheapest way to find out whether the answers still hold. It takes about ninety seconds and costs nothing. Run the free scan →